{"schedule": {"version": "1.0", "base_url": "https://cfp.owaspukraine.org/owaspkyivwinter2019/schedule/", "conference": {"acronym": "owaspkyivwinter2019", "title": "OWASP Kyiv Winter 2019 Meetup", "start": "2019-02-02", "end": "2019-02-02", "daysCount": 1, "timeslot_duration": "00:05", "days": [{"index": 1, "date": "2019-02-02", "day_start": "2019-02-02T04:00:00+02:00", "day_end": "2019-02-03T03:59:00+02:00", "rooms": {"Innohub (https://innohub.innovecs.com)": [{"id": 31, "guid": "d380e4a7-646d-5a02-becb-6357f4d23acb", "logo": "", "date": "2019-02-02T10:00:00+02:00", "start": "10:00", "duration": "01:30", "room": "Innohub (https://innohub.innovecs.com)", "slug": "7MBSWZ", "url": "https://cfp.owaspukraine.org/owaspkyivwinter2019/talk/7MBSWZ/", "title": "Web Application Firewall bypass techniques Workshop", "subtitle": "", "track": null, "type": "Workshop", "language": "en", "abstract": "A short demonstration of essential Web Application Firewall bypass techniques with 3 practical examples related to SQL Injection and XSS attacks.", "description": "\u0414\u043b\u044f \u0432\u043e\u0440\u043a\u0448\u043e\u043f\u0430 \u043d\u0443\u0436\u043d\u043e: \u0434\u043e\u0441\u043a\u0430, \u043c\u0430\u0440\u043a\u0435\u0440, \u0441\u0442\u0430\u043a\u0430\u043d \u0432\u043e\u0434\u044b, \u0432\u0430\u0439\u0444\u0430\u0439(\u0438\u043d\u0442\u0435\u0440\u043d\u0435\u0442) (\u0436\u0435\u043b\u0430\u0442\u0435\u043b\u044c\u043d\u043e \u0447\u0442\u043e\u0431\u044b \u043f\u0440\u043e\u043f\u0443\u0441\u043a\u0430\u043b \u0442\u0440\u0430\u0444\u0438\u043a \u043a \u0442\u0430\u043a\u0438\u043c \u0440\u0435\u0441\u0443\u0440\u0441\u0430\u043c \u043a\u0430\u043a ngrok), \u0437\u0430 \u043f\u0430\u0440\u0443 \u0434\u043d\u0435\u0439 \u0434\u043e \u043d\u0430\u0447\u0430\u043b\u043e \u0438\u0432\u0435\u043d\u0442\u0430 \u0440\u0430\u0437\u043e\u0441\u043b\u0430\u0442\u044c \u0443\u0447\u0430\u0441\u043d\u0438\u043a\u043e\u043c \u043f\u0438\u0441\u044c\u043c\u0430 \u0441 \u0442\u0440\u0435\u0431\u043e\u0432\u0430\u043d\u0438\u0435\u043c \u0434\u043b\u044f \u0443\u0447\u0430\u0441\u0442\u0438\u044f \u0432 \u0432\u043e\u0440\u043a\u0448\u043e\u043f\u0435.\r\n\r\n\u0422\u0440\u0435\u0431\u043e\u0432\u0430\u043d\u0438\u044f:\r\n\r\n- \u0417\u0430\u0439\u0442\u0438 \u043d\u0430 \u0422\u0413 \u043a\u0430\u043d\u0430\u043b \u0434\u043e \u043d\u0430\u0447\u0430\u043b\u043e \u0432\u043e\u043a\u0440\u0448\u043e\u043f\u0430: https://t.me/joinchat/AAAAAFA3ZGkcrhwb7JSrPA\r\n\r\n- \u041f\u043e\u043d\u0438\u043c\u0430\u043d\u0438\u0435 \u0447\u0442\u043e \u0442\u0430\u043a\u043e\u0435 XSS \u0438 SQL injection\r\n\r\n- Kali Linux \r\n\r\n- \u0420\u0435\u0433\u0438\u0441\u0442\u0440\u0430\u0446\u0438\u044f \u043d\u0430 \u0442\u0430\u043a\u0438\u0445 \u0440\u0435\u0441\u0443\u0440\u0441\u0430\u0445 \u043a\u0430\u043a https://www.root-me.org & https://lab.pentestit.ru\r\n\r\n- \u0425\u043e\u0440\u043e\u0448\u043e\u0435 \u043d\u0430\u0441\u0442\u0440\u043e\u0435\u043d\u0438\u0435", "recording_license": "", "do_not_record": false, "persons": [{"id": 44, "code": "JTSLET", "public_name": "Bohdan Lukin", "biography": "WTF ? )", "answers": []}], "links": [], "attachments": [], "answers": []}, {"id": 29, "guid": "ab9ec214-8b08-58e1-87ec-5c7bba0217dd", "logo": "", "date": "2019-02-02T11:40:00+02:00", "start": "11:40", "duration": "01:30", "room": "Innohub (https://innohub.innovecs.com)", "slug": "VA9UAK", "url": "https://cfp.owaspukraine.org/owaspkyivwinter2019/talk/VA9UAK/", "title": "Subdomain discovering as an essential part of the reconnaissance phase", "subtitle": "", "track": null, "type": "Workshop", "language": "en", "abstract": "In this presentation, I will talk about: DNS, DNS scrapping, DNS enumeration, and subdomain takeover.", "description": "As a penetration tester or a bug bounty hunter, most of the times you are given a single domain or a set of domains when you start a security assessment. You\u2019ll have to perform extensive reconnaissance to find interesting assets like servers, web applications, domains that belong to the target organization so that you can increase your chances of finding vulnerabilities.\r\n\r\n#####Requirements:\r\n* Linux based os (Kali Linux is Ok)\r\n* API Keys for: VirusTotal, Censys (use https://temp-mail.org)\r\n* Good mood\r\n#####Telegeram channel\r\nhttps://t.me/subd_enum", "recording_license": "", "do_not_record": false, "persons": [{"id": 41, "code": "8PAVKZ", "public_name": "Kostiantyn Sanduliak", "biography": "LinkedIn: www.linkedin.com/in/kostiantyn-sanduliak\r\nTwitter: @sk3c75", "answers": []}], "links": [], "attachments": [], "answers": []}, {"id": 25, "guid": "92b5b219-d02d-54e3-80b4-7be9c24a4971", "logo": "", "date": "2019-02-02T13:20:00+02:00", "start": "13:20", "duration": "00:40", "room": "Innohub (https://innohub.innovecs.com)", "slug": "ZEVVV7", "url": "https://cfp.owaspukraine.org/owaspkyivwinter2019/talk/ZEVVV7/", "title": "Introduction lstio Service Mesh", "subtitle": "", "track": null, "type": "Talk", "language": "en", "abstract": "We will talk about Service Mesh and Istio.", "description": "Istio is an open platform for providing a uniform way to integrate microservices, manage traffic flow across microservices, enforce policies and aggregate telemetry data. Istio's control plane provides an abstraction layer over the underlying cluster management platform, such as Kubernetes, Mesos, etc.", "recording_license": "", "do_not_record": false, "persons": [{"id": 34, "code": "RR88SD", "public_name": "Stanislav Kolenkin", "biography": "Senior DevOps.", "answers": []}], "links": [], "attachments": [], "answers": []}, {"id": 26, "guid": "c5c1c26c-082f-5497-9bc1-68bf7f1c9b82", "logo": "", "date": "2019-02-02T14:50:00+02:00", "start": "14:50", "duration": "00:40", "room": "Innohub (https://innohub.innovecs.com)", "slug": "EY33C3", "url": "https://cfp.owaspukraine.org/owaspkyivwinter2019/talk/EY33C3/", "title": "OWASP Top-10 A2: Broken Authentication", "subtitle": "", "track": null, "type": "Talk", "language": "en", "abstract": "Broken Authentication and what attack vectors it has.", "description": "In this talk, I will demonstrate how important it is to put time and effort into security testing. I will introduce you to the Broken Authentication risk that is included in the OWASP Top-10. I will describe what attack vectors it has, how to understand if you are vulnerable to such attacks, and how to protect against them. The talk will be accompanied by practical examples of how to use the following tools to test the application against the Broken Authentication attacks:\r\n\r\n- Burp Suite\r\n\r\n- BeEF\r\n\r\n- Rainbowcrack", "recording_license": "", "do_not_record": false, "persons": [{"id": 37, "code": "GLHLBN", "public_name": "Svyat Login", "biography": "Overall experience in testing for more than 6 years\r\nBeen searching for Web vulnerabilities for more than 3 years\r\nSpeaker of multiple testing conferences\r\nCurrently working at Evo.company, on a Prom + project on the Core team, which is\r\ndeveloping:\r\n- CMS for sellers\r\n- Online chat buyer-seller\r\n- API for those who need to connect to their CRM system\r\n- API for mobile applications on IOS and Android", "answers": []}], "links": [], "attachments": [], "answers": []}, {"id": 27, "guid": "678177b2-cabe-5008-aba9-2daa67a33826", "logo": "", "date": "2019-02-02T15:40:00+02:00", "start": "15:40", "duration": "00:40", "room": "Innohub (https://innohub.innovecs.com)", "slug": "NUZV8K", "url": "https://cfp.owaspukraine.org/owaspkyivwinter2019/talk/NUZV8K/", "title": "Email as an initial attack vector", "subtitle": "", "track": null, "type": "Talk", "language": "en", "abstract": "Email as an element of attack kill-chain. Some interesting examples of phishing emails.", "description": "Email as an initial (an in some occasions one and only) attack vector. With good preparation of the attacker and the lack of knowledge of the target, the attack has great chances for success. In this talk, we will discuss some key markers of dangerous emails, and some interesting examples of phishing emails.", "recording_license": "", "do_not_record": false, "persons": [{"id": 40, "code": "VDYWRB", "public_name": "Artur Hil", "biography": "At this time I'm nothing to tell", "answers": []}], "links": [], "attachments": [], "answers": []}, {"id": 30, "guid": "eec94184-2b05-5665-9c9f-bdb6b8f70cf3", "logo": "", "date": "2019-02-02T16:30:00+02:00", "start": "16:30", "duration": "00:40", "room": "Innohub (https://innohub.innovecs.com)", "slug": "CHTFRS", "url": "https://cfp.owaspukraine.org/owaspkyivwinter2019/talk/CHTFRS/", "title": "Building SQL firewall: insights from developers", "subtitle": "", "track": null, "type": "Talk", "language": "en", "abstract": "How SQL firewalls can help to protect databases from SQL injections: the main difference from WAFs, common usage scenarios, pros, and cons. Developing SQL firewall is a hard task \u2013 we will share insights about parsing SQL protocols, matching rules, hidden dangers of logging, best of configuration and usage patterns.", "description": "Our general plan for talk:\r\n\r\n1. SQL injections: what's that and how to protect against them.\r\n\r\n2. Typical scenarios of fighting with injections: OWASP guide, WAF, SQL firewall.\r\n\r\n3. WAF: pros, cons, why WAF is not enough.\r\n\r\n4. SQL firewall: what is this, what are the main features of it.\r\n\r\n5. How we built SQL firewall:\r\n\r\n    - configuration and rules (allow, deny, ignore);\r\n\r\n    - parsing SQL protocols;\r\n\r\n    - pattern matching (WHERE, EQUAL, VALUE etc);\r\n\r\n    - logging and masking requests;\r\n\r\n6. SQL Firewall vs WAF.\r\n\r\n7. Best use cases for SQL firewall.\r\n\r\n8. Future improvements of SQL firewalls.\r\n\r\n9. Outro.", "recording_license": "", "do_not_record": false, "persons": [{"id": 43, "code": "FM38FZ", "public_name": "Artem Storozhuk", "biography": "Security software engineer at Cossack Labs", "answers": []}], "links": [], "attachments": [], "answers": []}, {"id": 28, "guid": "c52ce88a-bf9f-5402-b80c-978a499ec89e", "logo": "", "date": "2019-02-02T17:20:00+02:00", "start": "17:20", "duration": "00:40", "room": "Innohub (https://innohub.innovecs.com)", "slug": "9YNHDA", "url": "https://cfp.owaspukraine.org/owaspkyivwinter2019/talk/9YNHDA/", "title": "Application Threat Modeling", "subtitle": "", "track": null, "type": "Talk", "language": "en", "abstract": "In this talk, I am going to walk the audience through the Threat Modeling introduction. The program will consist of the overview of popular Threat Modeling methodologies and available tools.", "description": "Threat Modeling is an essential part of a secure software development process of any maturity. Building up a map of threats that are relevant for an application or system, measuring the impact and probability of these threats, and mapping existing and planned security controls to the related risks \u2013\u00a0is a crucial exercise that must be performed before the team hits the code and regularly after that.\r\n\r\nDuring the talk, we will design an imaginary piece of software that implements a business idea, and build a Threat Model that maps all planned security activities throughout the software development project that implements it.", "recording_license": "", "do_not_record": false, "persons": [{"id": 1, "code": "BP9LP7", "public_name": "Vlad Styran", "biography": "Founder and VP of Development in [Berezha Security Group](https://bsg.tech/). OSCP, CISSP, CISA. Trainer and consultant in the field of Secure Software Development.", "answers": []}], "links": [], "attachments": [], "answers": []}]}}]}}}