<?xml version='1.0' encoding='utf-8' ?>
<!-- Made with love by pretalx v1.1.2. -->
<schedule>
    <generator name="pretalx" version="1.1.2" />
    <version>0.1</version>
    <conference>
        <acronym>okspring2021</acronym>
        <title>OWASP Kyiv Spring 2021 ONLINE Meetup</title>
        <start>2021-04-24</start>
        <end>2021-04-24</end>
        <days>1</days>
        <timeslot_duration>00:05</timeslot_duration>
        <base_url>https://cfp.owaspukraine.org/okspring2021/schedule/</base_url>
    </conference>
    <day index='1' date='2021-04-24' start='2021-04-24T04:00:00+03:00' end='2021-04-25T03:59:00+03:00'>
        <room name='ZOOM'>
            <event guid='eab4e57d-2370-5ebb-8078-f37357e93ef1' id='118'>
                <date>2021-04-24T10:00:00+03:00</date>
                <start>10:00</start>
                <duration>01:00</duration>
                <room>ZOOM</room>
                <slug>okspring2021-118-a9-using-components-with-known-vulnerabilities</slug>
                <url>https://cfp.owaspukraine.org/okspring2021/talk/LXCAJZ/</url>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <title>A9:Using Components with Known Vulnerabilities</title>
                <subtitle></subtitle>
                <track></track>
                <type>Workshop</type>
                <language>en</language>
                <abstract>Known Security Vulnerabilities are those gaps in security that have been identified, either by the developer/vendor of the products used, by the user/developer, or by the hacker/intruder. To exploit known security vulnerabilities, hackers identify a weak component in the system by scanning the system using automated tools (more common because these hacking tools are available online) or by analyzing the components manually (less common, because it takes more advanced skills).</abstract>
                <description></description>
                <logo></logo>
                <persons>
                    <person id='37'>Svyat Login</person>
                </persons>
                <links></links>
                <attachments></attachments>
            </event>
            <event guid='26d89b49-be33-5eee-aa38-276f658ce0c3' id='122'>
                <date>2021-04-24T11:30:00+03:00</date>
                <start>11:30</start>
                <duration>00:30</duration>
                <room>ZOOM</room>
                <slug>okspring2021-122-information-security-academic-minors-in-modern-ukrainian-higher-education</slug>
                <url>https://cfp.owaspukraine.org/okspring2021/talk/UMMPFM/</url>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <title>Information security academic minors in modern Ukrainian higher education</title>
                <subtitle></subtitle>
                <track></track>
                <type>Talk</type>
                <language>en</language>
                <abstract>Nowadays higher education in Ukraine takes new challenges: required knowledge level for employment is low, knowledge sometimes are outdated, student oriented on self-education. Also, education in Ukraine mostly doesn&apos;t orient on lifelong education, so it doesn&apos;t prepare wide specialists. How modern education in Ukraine can compete with these factors and being attractive and useful for students and several other questions will be discussed around this topic.</abstract>
                <description></description>
                <logo></logo>
                <persons>
                    <person id='183'>Trokhym Babych</person>
                </persons>
                <links></links>
                <attachments></attachments>
            </event>
            <event guid='eab3d7ad-0cc6-5282-8d35-18b93a5b4cc7' id='121'>
                <date>2021-04-24T12:30:00+03:00</date>
                <start>12:30</start>
                <duration>00:30</duration>
                <room>ZOOM</room>
                <slug>okspring2021-121-responsible-disclosure-it-s-not-all-about-the-money-</slug>
                <url>https://cfp.owaspukraine.org/okspring2021/talk/GHF9EC/</url>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <title>Responsible disclosure: it&apos;s not all about the money.</title>
                <subtitle></subtitle>
                <track></track>
                <type>Talk</type>
                <language>en</language>
                <abstract>Starting from an introduction to &quot;Responsible Disclosure&quot; model, we will see this process in detail, pointing out the differences with &quot;Full Disclosure&quot; model, bug bounty programs and black market.
Lastly, three CVEs will be publicly disclosed and presented to the audience, in order to show a real case about the responsible disclosure model.
This is the detailed agenda of the talk:

1 - Intro -&gt; total 5 minutes, divided in:
     Who am I? -&gt; 1 minute
     Introduction to responsible disclosure -&gt; 4 minutes
     
2 - Responsible disclosure in detail and differences with full disclosure, bug bounty programs and black marcket -&gt; total 10 minutes

3 - Real case: how to report vulnerabilities to a non-cooperative vendor, gaining the glory and avoiding to be jailed. Analysis of 3 CVEs -&gt; total 10 minutes

4 - Q&amp;A -&gt; 5 minutes</abstract>
                <description></description>
                <logo>/media/okspring2021/images/GHF9EC/resp_disclosure_Q5k4sy5.png</logo>
                <persons>
                    <person id='180'>Carlo Di Dato</person>
                </persons>
                <links></links>
                <attachments></attachments>
            </event>
            
        </room>
        
    </day>
    
</schedule>
