<?xml version='1.0' encoding='utf-8' ?>
<!-- Made with love by pretalx v1.1.2. -->
<schedule>
    <generator name="pretalx" version="1.1.2" />
    <version>0.5</version>
    <conference>
        <acronym>okwinter2022</acronym>
        <title>OWASP Kyiv Winter 2022 ONLINE Meetup</title>
        <start>2022-02-26</start>
        <end>2022-02-26</end>
        <days>1</days>
        <timeslot_duration>00:05</timeslot_duration>
        <base_url>https://cfp.owaspukraine.org/okwinter2022/schedule/</base_url>
    </conference>
    <day index='1' date='2022-02-26' start='2022-02-26T04:00:00+02:00' end='2022-02-27T03:59:00+02:00'>
        <room name='ZOOM'>
            <event guid='b18294c4-047d-505a-a32d-402131e9d99c' id='134'>
                <date>2022-02-26T10:15:00+02:00</date>
                <start>10:15</start>
                <duration>00:30</duration>
                <room>ZOOM</room>
                <slug>okwinter2022-134-red-blue-purple-specifics-of-offensive-and-defensive-teams-cooperation</slug>
                <url>https://cfp.owaspukraine.org/okwinter2022/talk/QRNLAF/</url>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <title>Red+Blue = Purple: specifics of offensive and defensive teams cooperation</title>
                <subtitle></subtitle>
                <track></track>
                <type>Talk</type>
                <language>en</language>
                <abstract>Red team operations can be effectively performed in close cooperation with the defensive (blue) team - this format differs in some key points from the classical redteaming or penetration testing. Organizational faults or wrong understanding of what is going on can decrease the overall effectiveness of the operation dramatically for both sides. 
Looking from the side of red team, discussing, what purple teaming really is, how it should be carried out to be really effective and what are the main constraints on this way.</abstract>
                <description>Red team operations can be effectively performed in close cooperation with the defensive (blue) team - this format differs in some key points from the classical redteaming or penetration testing. Organizational faults or wrong understanding of what is going on can decrease the overall effectiveness of the operation dramatically for both sides. 
Looking from the side of red team, discussing, what purple teaming really is, how it should be carried out to be really effective and what are the main constraints on this way.</description>
                <logo></logo>
                <persons>
                    <person id='198'>Roman Draguntsov</person>
                </persons>
                <links></links>
                <attachments></attachments>
            </event>
            <event guid='fa52339a-3f69-52ee-80b3-728f114b932f' id='132'>
                <date>2022-02-26T10:50:00+02:00</date>
                <start>10:50</start>
                <duration>01:00</duration>
                <room>ZOOM</room>
                <slug>okwinter2022-132-how-to-make-php-web-applications-less-vulnerable-</slug>
                <url>https://cfp.owaspukraine.org/okwinter2022/talk/VGHGDC/</url>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <title>How to make PHP WEB applications less vulnerable?</title>
                <subtitle></subtitle>
                <track></track>
                <type>Talk 60</type>
                <language>en</language>
                <abstract>Hi, I&apos;m Kostia. Currently, I work as a Software Engineer at GOG.com. And I&apos;d like to share some of my knowledge about WEB apps security.</abstract>
                <description>At the presentation, I&apos;d like to share my point of view on the WEB applications security. I classified the most common threats with examples and solutions. As a result, the listener obtains a holistic understanding of these threats and the correct mindset for building relatively secure applications.</description>
                <logo>/media/okwinter2022/images/VGHGDC/picture_f1Gq7Qw.jpg</logo>
                <persons>
                    <person id='197'>Deleted User</person>
                </persons>
                <links></links>
                <attachments></attachments>
            </event>
            <event guid='b76422f8-0f99-5dc3-89e2-741a77d8a647' id='140'>
                <date>2022-02-26T12:00:00+02:00</date>
                <start>12:00</start>
                <duration>00:30</duration>
                <room>ZOOM</room>
                <slug>okwinter2022-140----winter-2021-2022</slug>
                <url>https://cfp.owaspukraine.org/okwinter2022/talk/PXW8ZW/</url>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <title>&#1053;&#1086;&#1074;&#1080;&#1085;&#1080; &#1089;&#1090;&#1088;&#1072;&#1090;&#1077;&#1075;&#1110;&#1095;&#1085;&#1086;&#1111; &#1082;&#1110;&#1073;&#1077;&#1088;&#1073;&#1077;&#1079;&#1087;&#1077;&#1082;&#1080;, Winter-2021-2022</title>
                <subtitle></subtitle>
                <track></track>
                <type>Talk</type>
                <language>en</language>
                <abstract>&#1054;&#1075;&#1083;&#1103;&#1076; &#1085;&#1086;&#1074;&#1080;&#1085;&#1080; &#1089;&#1090;&#1088;&#1072;&#1090;&#1077;&#1075;&#1110;&#1095;&#1085;&#1086;&#1111; &#1082;&#1110;&#1073;&#1077;&#1088;&#1073;&#1077;&#1079;&#1087;&#1077;&#1082;&#1080; &#1059;&#1082;&#1088;&#1072;&#1111;&#1085;&#1080; &#1090;&#1072; &#1057;&#1074;&#1110;&#1090;&#1091;, &#1103;&#1082;&#1110; &#1093;&#1090;&#1086;&#1089;&#1100; &#1084;&#1110;&#1075; &#1087;&#1088;&#1086;&#1087;&#1091;&#1089;&#1090;&#1080;&#1090;&#1080;, &#1072;&#1083;&#1077; &#1103;&#1082;&#1110; &#1074;&#1072;&#1078;&#1083;&#1080;&#1074;&#1086; &#1079;&#1085;&#1072;&#1090;&#1080;.</abstract>
                <description>&#1042;&#1072;&#1078;&#1083;&#1080;&#1074;&#1110; &#1085;&#1086;&#1074;&#1080;&#1085;&#1080; &#1082;&#1110;&#1073;&#1077;&#1088;&#1073;&#1077;&#1079;&#1087;&#1077;&#1082;&#1080; &#1089;&#1090;&#1088;&#1072;&#1090;&#1077;&#1075;&#1110;&#1095;&#1085;&#1086;&#1075;&#1086; &#1093;&#1072;&#1088;&#1072;&#1082;&#1090;&#1077;&#1088;&#1091;, &#1103;&#1082;&#1110; &#1085;&#1077; &#1073;&#1072;&#1078;&#1072;&#1085;&#1086; &#1087;&#1088;&#1086;&#1087;&#1091;&#1089;&#1082;&#1072;&#1090;&#1080;, &#1097;&#1086;&#1073; &#1079;&#1072;&#1083;&#1080;&#1096;&#1072;&#1090;&#1080;&#1089;&#1103; &quot;&#1074; &#1084;&#1072;&#1090;&#1077;&#1088;&#1110;&#1072;&#1083;&#1110;&quot;, &quot;&#1074; &#1087;&#1086;&#1090;&#1086;&#1094;&#1110;&quot; &#1090;&#1072; &quot;&#1074; &#1084;&#1086;&#1084;&#1077;&#1085;&#1090;&#1110;&quot;.</description>
                <logo>/media/okwinter2022/images/PXW8ZW/Kos-OWASP-Kyiv-chapter-2021_3gduj20.jpg</logo>
                <persons>
                    <person id='24'>Kostiantyn Korsun</person>
                </persons>
                <links></links>
                <attachments></attachments>
            </event>
            <event guid='88df96f0-2292-5a14-bdca-541474beb3ac' id='133'>
                <date>2022-02-26T12:45:00+02:00</date>
                <start>12:45</start>
                <duration>00:45</duration>
                <room>ZOOM</room>
                <slug>okwinter2022-133-wordpress-hacking-and-securing</slug>
                <url>https://cfp.owaspukraine.org/okwinter2022/talk/9GATLL/</url>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <title>WordPress: Hacking and Securing</title>
                <subtitle></subtitle>
                <track></track>
                <type>Talk 45</type>
                <language>en</language>
                <abstract>WordPress is the world&apos;s most popular Content Management System, which makes it a lucrative target for cyber criminals. Thousands of WordPress-based websites get hacked daily and according to the GoDaddy report 90% of hacked websites in 2019 were running WordPress CMS. In this talk you will learn about several vulnerabilities and methods used to hack into WordPress websites (including live demo) and some of the mitigations and methods  you can use to improve the security of your WordPress websites.</abstract>
                <description>WordPress is the world&apos;s most popular Content Management System, which makes it a lucrative target for cyber criminals. Thousands of WordPress-based websites get hacked daily and according to the GoDaddy report 90% of hacked websites in 2019 were running WordPress CMS. In this talk you will learn about several vulnerabilities and methods used to hack into WordPress websites (including live demo) and some of the mitigations and methods  you can use to improve the security of your WordPress websites.</description>
                <logo></logo>
                <persons>
                    <person id='163'>Sam Stepanyan</person>
                </persons>
                <links></links>
                <attachments></attachments>
            </event>
            <event guid='8bf85467-868a-598e-b62e-90a00960f434' id='135'>
                <date>2022-02-26T13:40:00+02:00</date>
                <start>13:40</start>
                <duration>00:30</duration>
                <room>ZOOM</room>
                <slug>okwinter2022-135-infrastructure-as-a-code-security-scanning-in-ci-cd</slug>
                <url>https://cfp.owaspukraine.org/okwinter2022/talk/UPQJM8/</url>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <title>Infrastructure as a code security scanning in CI/CD</title>
                <subtitle></subtitle>
                <track></track>
                <type>Talk</type>
                <language>en</language>
                <abstract>Current speech is about security scanners which will help you to find misconfigurations and follow best practices for terraform and similar IAC tools in CI/CD. The main goal of topic is to teach you how to protect your project with the best suitable tool.</abstract>
                <description>Particularly will be discussed about snyk, tfsec, kics tools, vulnerable terraform project and Gitlab CI/CD</description>
                <logo></logo>
                <persons>
                    <person id='199'>Volodymyr Skorupskyi</person>
                </persons>
                <links></links>
                <attachments></attachments>
            </event>
            <event guid='a05dac03-c286-54dd-b380-860db3f4b123' id='138'>
                <date>2022-02-26T14:20:00+02:00</date>
                <start>14:20</start>
                <duration>00:30</duration>
                <room>ZOOM</room>
                <slug>okwinter2022-138-threat-modeling-all-the-things-why-do-we-need-it-how-to-achieve-it-</slug>
                <url>https://cfp.owaspukraine.org/okwinter2022/talk/ETFW8M/</url>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <title>threat modeling all the things . why do we need it. how to achieve it.</title>
                <subtitle></subtitle>
                <track></track>
                <type>Talk</type>
                <language>en</language>
                <abstract>what if i tell you that security vulnerabilities could be find before the pen test and sometimes before coding the functionality. if it sounds interesting to you - please, visit my talk and get some new information about thread modeling process and it implementation in the company</abstract>
                <description></description>
                <logo></logo>
                <persons>
                    <person id='101'>Nadia Klymenko</person>
                </persons>
                <links></links>
                <attachments></attachments>
            </event>
            <event guid='3fa7fa06-ab51-508f-aae3-1ba3488ff427' id='136'>
                <date>2022-02-26T15:00:00+02:00</date>
                <start>15:00</start>
                <duration>00:30</duration>
                <room>ZOOM</room>
                <slug>okwinter2022-136-what-i-learned-while-teaching-cybersecurity-to-ukrainian-veterans</slug>
                <url>https://cfp.owaspukraine.org/okwinter2022/talk/GKWHBH/</url>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <title>What I learned while teaching Cybersecurity to Ukrainian Veterans</title>
                <subtitle></subtitle>
                <track></track>
                <type>Talk</type>
                <language>en</language>
                <abstract>Recently Ukraine has been at the forefront of the world news due to active war phases occurring on multiple operational areas: physical, cyber, informational, etc. In this presentation I share my story and ideas about how Ukrainian veterans can we help address cybersecurity situation in Ukraine.</abstract>
                <description>There are almost half a million war veterans in Ukraine. These are people who have defended territorial integrity of their country. Many (if not all) possess critical skillsets of operating under stress, commitment to mission and teamwork. When veterans are back to civil life, they are faced with a number of problems - discrimination, lack of professional job prospects, financial hardships, PTSD and so on. Veterans are dedicated and committed individuals that deserve respect and a better life. IT and cybersecurity can be one of the ways to positively influence their lives. And how others can help as well.</description>
                <logo>/media/okwinter2022/images/GKWHBH/veteranius_im3ukhU.png</logo>
                <persons>
                    <person id='200'>Dmytro Kavun</person>
                </persons>
                <links></links>
                <attachments></attachments>
            </event>
            
        </room>
        
    </day>
    
</schedule>
