<?xml version='1.0' encoding='utf-8' ?>
<iCalendar xmlns:pentabarf='http://pentabarf.org' xmlns:xCal='urn:ietf:params:xml:ns:xcal'>
    <vcalendar>
        <version>2.0</version>
        <prodid>-//Pentabarf//Schedule//EN</prodid>
        <x-wr-caldesc></x-wr-caldesc>
        <x-wr-calname></x-wr-calname>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>7MBSWZ@@cfp.owaspukraine.org</uid>
            <pentabarf:event-id>1150643799</pentabarf:event-id>
            <pentabarf:event-slug>-7MBSWZ</pentabarf:event-slug>
            <pentabarf:title>Web Application Firewall bypass techniques Workshop</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20190202T100000</dtstart>
            <dtend>20190202T113000</dtend>
            <duration>1.03000</duration>
            <summary>Web Application Firewall bypass techniques Workshop</summary>
            <description>Для воркшопа нужно: доска, маркер, стакан воды, вайфай(интернет) (желательно чтобы пропускал трафик к таким ресурсам как ngrok), за пару дней до начало ивента разослать учасником письма с требованием для участия в воркшопе.

Требования:

- Зайти на ТГ канал до начало вокршопа: https://t.me/joinchat/AAAAAFA3ZGkcrhwb7JSrPA

- Понимание что такое XSS и SQL injection

- Kali Linux 

- Регистрация на таких ресурсах как https://www.root-me.org &amp; https://lab.pentestit.ru

- Хорошое настроение</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Workshop</category>
            <url>https://cfp.owaspukraine.org/owaspkyivwinter2019/talk/7MBSWZ/</url>
            <location>Innohub (https://innohub.innovecs.com)</location>
            
            <attendee>Bohdan Lukin</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>VA9UAK@@cfp.owaspukraine.org</uid>
            <pentabarf:event-id>864355081</pentabarf:event-id>
            <pentabarf:event-slug>-VA9UAK</pentabarf:event-slug>
            <pentabarf:title>Subdomain discovering as an essential part of the reconnaissance phase</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20190202T114000</dtstart>
            <dtend>20190202T131000</dtend>
            <duration>1.03000</duration>
            <summary>Subdomain discovering as an essential part of the reconnaissance phase</summary>
            <description>As a penetration tester or a bug bounty hunter, most of the times you are given a single domain or a set of domains when you start a security assessment. You’ll have to perform extensive reconnaissance to find interesting assets like servers, web applications, domains that belong to the target organization so that you can increase your chances of finding vulnerabilities.

#####Requirements:
* Linux based os (Kali Linux is Ok)
* API Keys for: VirusTotal, Censys (use https://temp-mail.org)
* Good mood
#####Telegeram channel
https://t.me/subd_enum</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Workshop</category>
            <url>https://cfp.owaspukraine.org/owaspkyivwinter2019/talk/VA9UAK/</url>
            <location>Innohub (https://innohub.innovecs.com)</location>
            
            <attendee>Kostiantyn Sanduliak</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>ZEVVV7@@cfp.owaspukraine.org</uid>
            <pentabarf:event-id>1051129507</pentabarf:event-id>
            <pentabarf:event-slug>-ZEVVV7</pentabarf:event-slug>
            <pentabarf:title>Introduction lstio Service Mesh</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20190202T132000</dtstart>
            <dtend>20190202T140000</dtend>
            <duration>0.04000</duration>
            <summary>Introduction lstio Service Mesh</summary>
            <description>Istio is an open platform for providing a uniform way to integrate microservices, manage traffic flow across microservices, enforce policies and aggregate telemetry data. Istio&#39;s control plane provides an abstraction layer over the underlying cluster management platform, such as Kubernetes, Mesos, etc.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://cfp.owaspukraine.org/owaspkyivwinter2019/talk/ZEVVV7/</url>
            <location>Innohub (https://innohub.innovecs.com)</location>
            
            <attendee>Stanislav Kolenkin</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>EY33C3@@cfp.owaspukraine.org</uid>
            <pentabarf:event-id>212112220</pentabarf:event-id>
            <pentabarf:event-slug>-EY33C3</pentabarf:event-slug>
            <pentabarf:title>OWASP Top-10 A2: Broken Authentication</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20190202T145000</dtstart>
            <dtend>20190202T153000</dtend>
            <duration>0.04000</duration>
            <summary>OWASP Top-10 A2: Broken Authentication</summary>
            <description>In this talk, I will demonstrate how important it is to put time and effort into security testing. I will introduce you to the Broken Authentication risk that is included in the OWASP Top-10. I will describe what attack vectors it has, how to understand if you are vulnerable to such attacks, and how to protect against them. The talk will be accompanied by practical examples of how to use the following tools to test the application against the Broken Authentication attacks:

- Burp Suite

- BeEF

- Rainbowcrack</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://cfp.owaspukraine.org/owaspkyivwinter2019/talk/EY33C3/</url>
            <location>Innohub (https://innohub.innovecs.com)</location>
            
            <attendee>Svyat Login</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>NUZV8K@@cfp.owaspukraine.org</uid>
            <pentabarf:event-id>570205985</pentabarf:event-id>
            <pentabarf:event-slug>-NUZV8K</pentabarf:event-slug>
            <pentabarf:title>Email as an initial attack vector</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20190202T154000</dtstart>
            <dtend>20190202T162000</dtend>
            <duration>0.04000</duration>
            <summary>Email as an initial attack vector</summary>
            <description>Email as an initial (an in some occasions one and only) attack vector. With good preparation of the attacker and the lack of knowledge of the target, the attack has great chances for success. In this talk, we will discuss some key markers of dangerous emails, and some interesting examples of phishing emails.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://cfp.owaspukraine.org/owaspkyivwinter2019/talk/NUZV8K/</url>
            <location>Innohub (https://innohub.innovecs.com)</location>
            
            <attendee>Artur Hil</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>CHTFRS@@cfp.owaspukraine.org</uid>
            <pentabarf:event-id>100899674</pentabarf:event-id>
            <pentabarf:event-slug>-CHTFRS</pentabarf:event-slug>
            <pentabarf:title>Building SQL firewall: insights from developers</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20190202T163000</dtstart>
            <dtend>20190202T171000</dtend>
            <duration>0.04000</duration>
            <summary>Building SQL firewall: insights from developers</summary>
            <description>Our general plan for talk:

1. SQL injections: what&#39;s that and how to protect against them.

2. Typical scenarios of fighting with injections: OWASP guide, WAF, SQL firewall.

3. WAF: pros, cons, why WAF is not enough.

4. SQL firewall: what is this, what are the main features of it.

5. How we built SQL firewall:

    - configuration and rules (allow, deny, ignore);

    - parsing SQL protocols;

    - pattern matching (WHERE, EQUAL, VALUE etc);

    - logging and masking requests;

6. SQL Firewall vs WAF.

7. Best use cases for SQL firewall.

8. Future improvements of SQL firewalls.

9. Outro.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://cfp.owaspukraine.org/owaspkyivwinter2019/talk/CHTFRS/</url>
            <location>Innohub (https://innohub.innovecs.com)</location>
            
            <attendee>Artem Storozhuk</attendee>
            
        </vevent>
        
        <vevent>
            <method>PUBLISH</method>
            <uid>9YNHDA@@cfp.owaspukraine.org</uid>
            <pentabarf:event-id>1256635682</pentabarf:event-id>
            <pentabarf:event-slug>-9YNHDA</pentabarf:event-slug>
            <pentabarf:title>Application Threat Modeling</pentabarf:title>
            <pentabarf:subtitle></pentabarf:subtitle>
            <pentabarf:language>en</pentabarf:language>
            <pentabarf:language-code>en</pentabarf:language-code>
            <dtstart>20190202T172000</dtstart>
            <dtend>20190202T180000</dtend>
            <duration>0.04000</duration>
            <summary>Application Threat Modeling</summary>
            <description>Threat Modeling is an essential part of a secure software development process of any maturity. Building up a map of threats that are relevant for an application or system, measuring the impact and probability of these threats, and mapping existing and planned security controls to the related risks – is a crucial exercise that must be performed before the team hits the code and regularly after that.

During the talk, we will design an imaginary piece of software that implements a business idea, and build a Threat Model that maps all planned security activities throughout the software development project that implements it.</description>
            <class>PUBLIC</class>
            <status>CONFIRMED</status>
            <category>Talk</category>
            <url>https://cfp.owaspukraine.org/owaspkyivwinter2019/talk/9YNHDA/</url>
            <location>Innohub (https://innohub.innovecs.com)</location>
            
            <attendee>Vlad Styran</attendee>
            
        </vevent>
        
    </vcalendar>
</iCalendar>
