"What I hear, I forget. What I see, I remember. What I do, I understand. - Kung Fu Tzu (Confucius)"

RSS

News
2011 Toolsmith Tool of the Year: OWASP ZAP PDF Print E-mail
The 2011 Toolsmith Tool of the Year is OWASP ZAP!
Congratulations to the OWASP ZAP team!
I ask that those of you with the wherewithal and resources to do so please visit the project page  and donate in any capacity you can.
Congratulations and thank you to all participants this year and I look forward to a strong 2012.
 
2012 Toolsmith Tool of the Year: ModSecurity for IIS PDF Print E-mail
The 2012 Toolsmith Tool of the Year is ModSecurity for IIS!
Congratulations to the ModSecurity for IIS team!
I ask that those of you with the wherewithal and resources to do so please visit the project page  and donate in any capacity you can.
Congratulations and thank you to all participants this year and I look forward to a strong 2013.
 
Presented OWASP Top 10 Tools and Tactics at SecureWorld Expo Seattle PDF Print E-mail

ISSA International Conference OWASP

 

Russ presented OWASP Top 10 Tools and Tactics at SecureWorld Expo Seattle in Bellevue, WA on Thursday, November 17, 2011 at 8:30 AM.

 

If you’ve spent any time defending web applications as a security analyst, or perhaps as a developer seeking to adhere to SDLC practices, you have likely utilized or referenced the OWASP Top 10. Intended first as an awareness mechanism, the Top 10 covers the most critical web application security flaws via consensus reached by a global consortium of application security experts. The OWASP Top 10 promotes managing risk in addition to awareness training, application testing, and remediation. To manage such risk, application security practitioners and developers need an appropriate tool kit. This presentation will explore tooling, tactics, analysis, and mitigation.

   

 
Presented Evil Though the Lens of Web Logs at RSA 2012 PDF Print E-mail

RSA

Russ presented Evil Though the Lens of Web Logs at RSA 2012, March 2, 2012, 11:20 am. 

Web logs can be analyzed with specific attention to Internet Background Radiation (IBR). Two bands of the IBR spectrum include scanning and misconfiguration where details about attacker and victim patterns are readily available. Via web application specific examples this discussion will analyze attacks exhibiting traits, trends, and tendencies from the attacker and victim perspectives.

   

 
RSA Conference 2012 Video: Evil Through The Lens of Web Logs PDF Print E-mail

A video recording of Russ' RSA Conference 2012 presentation, Evil Through The Lens of Web Logs, is available on YouTube. This is a short version, intended to be TED-like, of an hour long presentation. The slide deck for the full presentation is available here.

Web logs can be analyzed with specific attention to Internet Background Radiation (IBR). Two bands of the IBR spectrum include scanning and misconfiguration where details about attacker and victim patterns are readily available. Via web application specific examples this discussion will analyze attacks exhibiting traits, trends, and tendencies from the attacker and victim perspectives.