Category · Conferences

Down the Rabbithole Podcast

posted on Oct 12, 2011 by Rohit Sethi Comments:0

I had the privilege of sitting down with Rafal Los & Glenn Leifheit at OWASP AppSecUSA 2011 in Minneapolis to talk about how we can embed security in QA. Raf was nice enough to record our conversation on his popular Podcast series, Down the Rabbithole. We are big fans of finding practical, repeatable ways to build…

Mobile Security Presentations from ToorCon and MISTI

posted on Oct 11, 2011 by seccom Comments:0

Max Veytsman and Subu Ramanathan have just returned from presenting mobile security talks at ToorCon in San Diego and the MISTI Mobile and Smart Device Conference in Atlanta. The talks were entitled “Bust a Cap in an Android App” and “DEEP DIVE: Pentesting the Android and iPhone” Both slide decks are available below: Download “DEEP…

JSF Security Presentation

posted on Aug 31, 2011 by Krishna Raja Comments:0

Recently, my colleague Rohit Sethi and I presented JSF Security at Source Conference in Seattle. Among other things, we discussed JSF input validation using the Reference Implementation (Mojarra), Apache MyFaces, and using JSF 2.0.  We also covered integrating OWASP ESAPI into a JSF application to protect against authorization attacks and CSRF. Presentation slides and a video have now been posted.  Enjoy!

Security Compass at RSA

posted on Jan 14, 2010 by Rohit Sethi Comments:0

This year we’ll be returning to RSA to deliver a couple of 1 day training classes: application security hands on anddatabase security hands on. Both are introductory courses that aim to get students ramped up quickly on these important topics. Know anyone who’s interested?

OWASP DC

posted on Aug 24, 2009 by Rohit Sethi Comments:0

Come check us out at OWASP DC. We’ll be speaking on theSecurity Analysis of Core J2EE Patterns and teaching classes on Threat Model Express and Java Source Code Review