<?xml version='1.0' encoding='utf-8' ?>
<iCalendar xmlns:pentabarf='http://pentabarf.org' xmlns:xCal='urn:ietf:params:xml:ns:xcal'>
    <vcalendar>
        <version>2.0</version>
        <prodid>-//Pentabarf//Schedule//EN</prodid>
        <x-wr-caldesc></x-wr-caldesc>
        <x-wr-calname></x-wr-calname>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>SJGDXQ@@cfp.owaspukraine.org</uid>
            <pentabarf:event-id>737897492</pentabarf:event-id>
            <pentabarf:event-slug>-SJGDXQ</pentabarf:event-slug>
            <pentabarf:title>All about Subdomain Takeover attack</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20190406T100000</dtstart>
            <dtend>20190406T112000</dtend>
            <duration>1.02000</duration>
            <summary>All about Subdomain Takeover attack</summary>
            <description>This attack vector utilizes DNS entries pointing to Service Providers where the pointed subdomain is currently not in use. Depending on the DNS-entry configuration and which Service Provider it points to, some of these services will allow unverified users to claim these subdomains as their own. 
###### Requirements:
* Laptop with Linux
* Basic understanding of the Domain Name System (DNS)
* Knows how to set up a subdomain
* Valid accounts in several cloud services(amazon, microsoft azure (paid subscription), github) for practice
* EyeWiteness, SubJack
* Good mood</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Workshop</category>
            <url>https://cfp.owaspukraine.org/owaspkyivspring2019/talk/SJGDXQ/</url>
            <location>SkyPoint</location>
            
            <attendee>Kostiantyn Sanduliak</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>EQNZA9@@cfp.owaspukraine.org</uid>
            <pentabarf:event-id>200948663</pentabarf:event-id>
            <pentabarf:event-slug>-EQNZA9</pentabarf:event-slug>
            <pentabarf:title>Overview of iOS apps security assessment</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20190406T113000</dtstart>
            <dtend>20190406T125000</dtend>
            <duration>1.02000</duration>
            <summary>Overview of iOS apps security assessment</summary>
            <description>- iOS security architecture overview
- Difference between iOS and Android security assessments
- Few words about OWASP MSTG 
- OWASP Mobile TOP 10 overview
- What do you need for testing?
- Several tools demonstration</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Workshop</category>
            <url>https://cfp.owaspukraine.org/owaspkyivspring2019/talk/EQNZA9/</url>
            <location>SkyPoint</location>
            
            <attendee>Dmytro Diordiichuk</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>FAEFWJ@@cfp.owaspukraine.org</uid>
            <pentabarf:event-id>227340804</pentabarf:event-id>
            <pentabarf:event-slug>-FAEFWJ</pentabarf:event-slug>
            <pentabarf:title>Shooting yourself in the feet with php</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20190406T130000</dtstart>
            <dtend>20190406T134000</dtend>
            <duration>0.04000</duration>
            <summary>Shooting yourself in the feet with php</summary>
            <description>In this talk I&#39;m going to uncover php deserialization mechanism and how it can be used to hack web applications. Every exploitation will be demonstrated in real time using prepared lab and debugger. Minimal php knowledge required for better understanding.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://cfp.owaspukraine.org/owaspkyivspring2019/talk/FAEFWJ/</url>
            <location>SkyPoint</location>
            
            <attendee>Taras Sharkadi</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>D7WZTU@@cfp.owaspukraine.org</uid>
            <pentabarf:event-id>170527936</pentabarf:event-id>
            <pentabarf:event-slug>-D7WZTU</pentabarf:event-slug>
            <pentabarf:title>Ваше веб-приложение уязвимо!</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20190406T150000</dtstart>
            <dtend>20190406T154000</dtend>
            <duration>0.04000</duration>
            <summary>Ваше веб-приложение уязвимо!</summary>
            <description>В 2018 отшумели утечки базы данных населения Индии на 1.1 млрд человек, 330 млн паролей пользователей Twitter, 50 млн паролей и 87 мин личных переписок на Facebook, при этом десятки тысяч других утечек персональных данных и конфиденциальной информации остались за кадром или вообще не были обнаружены. Большинство инцидентов связано с простыми и хорошо изученными уязвимостями, которым легко противостоять. 

Основные тезисы:

- Векторы атак в вашем приложении
- Способы поддержания уровня безопасности
- План действий на случай обнаружения взлома
- На десерт: подборка изысканных уязвимостей, повышающих уровень паранойи</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://cfp.owaspukraine.org/owaspkyivspring2019/talk/D7WZTU/</url>
            <location>SkyPoint</location>
            
            <attendee>Dmytro Naumenko</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>R7VML7@@cfp.owaspukraine.org</uid>
            <pentabarf:event-id>715699617</pentabarf:event-id>
            <pentabarf:event-slug>-R7VML7</pentabarf:event-slug>
            <pentabarf:title>OWASP MSTG in Real Life</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20190406T160000</dtstart>
            <dtend>20190406T164000</dtend>
            <duration>0.04000</duration>
            <summary>OWASP MSTG in Real Life</summary>
            <description>I will talk about:

- How security is treated in small companies working on mobile application from scratch to release;
- What is MSTG and MASVS, how developers to propose security technics and how it helps QA team to test;
- General Testing Guide overview: Authentication, Networking, Crypto, etc.
- Short summary if iOS Testing guide: Jailbreak, Data Storage, Tampering, Reverse Engineering, etc.
- Popular third party security SDKs for e-Commerce apps</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://cfp.owaspukraine.org/owaspkyivspring2019/talk/R7VML7/</url>
            <location>SkyPoint</location>
            
            <attendee>Julia Potapenko</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>NNMNM7@@cfp.owaspukraine.org</uid>
            <pentabarf:event-id>561707735</pentabarf:event-id>
            <pentabarf:event-slug>-NNMNM7</pentabarf:event-slug>
            <pentabarf:title>Adversarial attacks on DNNs</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20190406T170000</dtstart>
            <dtend>20190406T174000</dtend>
            <duration>0.04000</duration>
            <summary>Adversarial attacks on DNNs</summary>
            <description></description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://cfp.owaspukraine.org/owaspkyivspring2019/talk/NNMNM7/</url>
            <location>SkyPoint</location>
            
            <attendee>Andrey Shalaenko</attendee>
            
        </vevent>
        
    </vcalendar>
</iCalendar>
