<?xml version='1.0' encoding='utf-8' ?>
<!-- Made with love by pretalx v1.1.2. -->
<schedule>
    <generator name="pretalx" version="1.1.2" />
    <version>1.0</version>
    <conference>
        <acronym>owaspkyivwinter2019</acronym>
        <title>OWASP Kyiv Winter 2019 Meetup</title>
        <start>2019-02-02</start>
        <end>2019-02-02</end>
        <days>1</days>
        <timeslot_duration>00:05</timeslot_duration>
        <base_url>https://cfp.owaspukraine.org/owaspkyivwinter2019/schedule/</base_url>
    </conference>
    <day index='1' date='2019-02-02' start='2019-02-02T04:00:00+02:00' end='2019-02-03T03:59:00+02:00'>
        <room name='Innohub (https://innohub.innovecs.com)'>
            <event guid='d380e4a7-646d-5a02-becb-6357f4d23acb' id='31'>
                <date>2019-02-02T10:00:00+02:00</date>
                <start>10:00</start>
                <duration>01:30</duration>
                <room>Innohub (https://innohub.innovecs.com)</room>
                <slug>owaspkyivwinter2019-31-web-application-firewall-bypass-techniques-workshop</slug>
                <url>https://cfp.owaspukraine.org/owaspkyivwinter2019/talk/7MBSWZ/</url>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <title>Web Application Firewall bypass techniques Workshop</title>
                <subtitle></subtitle>
                <track></track>
                <type>Workshop</type>
                <language>en</language>
                <abstract>A short demonstration of essential Web Application Firewall bypass techniques with 3 practical examples related to SQL Injection and XSS attacks.</abstract>
                <description>&#1044;&#1083;&#1103; &#1074;&#1086;&#1088;&#1082;&#1096;&#1086;&#1087;&#1072; &#1085;&#1091;&#1078;&#1085;&#1086;: &#1076;&#1086;&#1089;&#1082;&#1072;, &#1084;&#1072;&#1088;&#1082;&#1077;&#1088;, &#1089;&#1090;&#1072;&#1082;&#1072;&#1085; &#1074;&#1086;&#1076;&#1099;, &#1074;&#1072;&#1081;&#1092;&#1072;&#1081;(&#1080;&#1085;&#1090;&#1077;&#1088;&#1085;&#1077;&#1090;) (&#1078;&#1077;&#1083;&#1072;&#1090;&#1077;&#1083;&#1100;&#1085;&#1086; &#1095;&#1090;&#1086;&#1073;&#1099; &#1087;&#1088;&#1086;&#1087;&#1091;&#1089;&#1082;&#1072;&#1083; &#1090;&#1088;&#1072;&#1092;&#1080;&#1082; &#1082; &#1090;&#1072;&#1082;&#1080;&#1084; &#1088;&#1077;&#1089;&#1091;&#1088;&#1089;&#1072;&#1084; &#1082;&#1072;&#1082; ngrok), &#1079;&#1072; &#1087;&#1072;&#1088;&#1091; &#1076;&#1085;&#1077;&#1081; &#1076;&#1086; &#1085;&#1072;&#1095;&#1072;&#1083;&#1086; &#1080;&#1074;&#1077;&#1085;&#1090;&#1072; &#1088;&#1072;&#1079;&#1086;&#1089;&#1083;&#1072;&#1090;&#1100; &#1091;&#1095;&#1072;&#1089;&#1085;&#1080;&#1082;&#1086;&#1084; &#1087;&#1080;&#1089;&#1100;&#1084;&#1072; &#1089; &#1090;&#1088;&#1077;&#1073;&#1086;&#1074;&#1072;&#1085;&#1080;&#1077;&#1084; &#1076;&#1083;&#1103; &#1091;&#1095;&#1072;&#1089;&#1090;&#1080;&#1103; &#1074; &#1074;&#1086;&#1088;&#1082;&#1096;&#1086;&#1087;&#1077;.

&#1058;&#1088;&#1077;&#1073;&#1086;&#1074;&#1072;&#1085;&#1080;&#1103;:

- &#1047;&#1072;&#1081;&#1090;&#1080; &#1085;&#1072; &#1058;&#1043; &#1082;&#1072;&#1085;&#1072;&#1083; &#1076;&#1086; &#1085;&#1072;&#1095;&#1072;&#1083;&#1086; &#1074;&#1086;&#1082;&#1088;&#1096;&#1086;&#1087;&#1072;: https://t.me/joinchat/AAAAAFA3ZGkcrhwb7JSrPA

- &#1055;&#1086;&#1085;&#1080;&#1084;&#1072;&#1085;&#1080;&#1077; &#1095;&#1090;&#1086; &#1090;&#1072;&#1082;&#1086;&#1077; XSS &#1080; SQL injection

- Kali Linux 

- &#1056;&#1077;&#1075;&#1080;&#1089;&#1090;&#1088;&#1072;&#1094;&#1080;&#1103; &#1085;&#1072; &#1090;&#1072;&#1082;&#1080;&#1093; &#1088;&#1077;&#1089;&#1091;&#1088;&#1089;&#1072;&#1093; &#1082;&#1072;&#1082; https://www.root-me.org &amp; https://lab.pentestit.ru

- &#1061;&#1086;&#1088;&#1086;&#1096;&#1086;&#1077; &#1085;&#1072;&#1089;&#1090;&#1088;&#1086;&#1077;&#1085;&#1080;&#1077;</description>
                <logo></logo>
                <persons>
                    <person id='44'>Bohdan Lukin</person>
                </persons>
                <links></links>
                <attachments></attachments>
            </event>
            <event guid='ab9ec214-8b08-58e1-87ec-5c7bba0217dd' id='29'>
                <date>2019-02-02T11:40:00+02:00</date>
                <start>11:40</start>
                <duration>01:30</duration>
                <room>Innohub (https://innohub.innovecs.com)</room>
                <slug>owaspkyivwinter2019-29-subdomain-discovering-as-an-essential-part-of-the-reconnaissance-phase</slug>
                <url>https://cfp.owaspukraine.org/owaspkyivwinter2019/talk/VA9UAK/</url>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <title>Subdomain discovering as an essential part of the reconnaissance phase</title>
                <subtitle></subtitle>
                <track></track>
                <type>Workshop</type>
                <language>en</language>
                <abstract>In this presentation, I will talk about: DNS, DNS scrapping, DNS enumeration, and subdomain takeover.</abstract>
                <description>As a penetration tester or a bug bounty hunter, most of the times you are given a single domain or a set of domains when you start a security assessment. You&#8217;ll have to perform extensive reconnaissance to find interesting assets like servers, web applications, domains that belong to the target organization so that you can increase your chances of finding vulnerabilities.

#####Requirements:
* Linux based os (Kali Linux is Ok)
* API Keys for: VirusTotal, Censys (use https://temp-mail.org)
* Good mood
#####Telegeram channel
https://t.me/subd_enum</description>
                <logo></logo>
                <persons>
                    <person id='41'>Kostiantyn Sanduliak</person>
                </persons>
                <links></links>
                <attachments></attachments>
            </event>
            <event guid='92b5b219-d02d-54e3-80b4-7be9c24a4971' id='25'>
                <date>2019-02-02T13:20:00+02:00</date>
                <start>13:20</start>
                <duration>00:40</duration>
                <room>Innohub (https://innohub.innovecs.com)</room>
                <slug>owaspkyivwinter2019-25-introduction-lstio-service-mesh</slug>
                <url>https://cfp.owaspukraine.org/owaspkyivwinter2019/talk/ZEVVV7/</url>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <title>Introduction lstio Service Mesh</title>
                <subtitle></subtitle>
                <track></track>
                <type>Talk</type>
                <language>en</language>
                <abstract>We will talk about Service Mesh and Istio.</abstract>
                <description>Istio is an open platform for providing a uniform way to integrate microservices, manage traffic flow across microservices, enforce policies and aggregate telemetry data. Istio&apos;s control plane provides an abstraction layer over the underlying cluster management platform, such as Kubernetes, Mesos, etc.</description>
                <logo></logo>
                <persons>
                    <person id='34'>Stanislav Kolenkin</person>
                </persons>
                <links></links>
                <attachments></attachments>
            </event>
            <event guid='c5c1c26c-082f-5497-9bc1-68bf7f1c9b82' id='26'>
                <date>2019-02-02T14:50:00+02:00</date>
                <start>14:50</start>
                <duration>00:40</duration>
                <room>Innohub (https://innohub.innovecs.com)</room>
                <slug>owaspkyivwinter2019-26-owasp-top-10-a2-broken-authentication</slug>
                <url>https://cfp.owaspukraine.org/owaspkyivwinter2019/talk/EY33C3/</url>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <title>OWASP Top-10 A2: Broken Authentication</title>
                <subtitle></subtitle>
                <track></track>
                <type>Talk</type>
                <language>en</language>
                <abstract>Broken Authentication and what attack vectors it has.</abstract>
                <description>In this talk, I will demonstrate how important it is to put time and effort into security testing. I will introduce you to the Broken Authentication risk that is included in the OWASP Top-10. I will describe what attack vectors it has, how to understand if you are vulnerable to such attacks, and how to protect against them. The talk will be accompanied by practical examples of how to use the following tools to test the application against the Broken Authentication attacks:

- Burp Suite

- BeEF

- Rainbowcrack</description>
                <logo></logo>
                <persons>
                    <person id='37'>Svyat Login</person>
                </persons>
                <links></links>
                <attachments></attachments>
            </event>
            <event guid='678177b2-cabe-5008-aba9-2daa67a33826' id='27'>
                <date>2019-02-02T15:40:00+02:00</date>
                <start>15:40</start>
                <duration>00:40</duration>
                <room>Innohub (https://innohub.innovecs.com)</room>
                <slug>owaspkyivwinter2019-27-email-as-an-initial-attack-vector</slug>
                <url>https://cfp.owaspukraine.org/owaspkyivwinter2019/talk/NUZV8K/</url>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <title>Email as an initial attack vector</title>
                <subtitle></subtitle>
                <track></track>
                <type>Talk</type>
                <language>en</language>
                <abstract>Email as an element of attack kill-chain. Some interesting examples of phishing emails.</abstract>
                <description>Email as an initial (an in some occasions one and only) attack vector. With good preparation of the attacker and the lack of knowledge of the target, the attack has great chances for success. In this talk, we will discuss some key markers of dangerous emails, and some interesting examples of phishing emails.</description>
                <logo></logo>
                <persons>
                    <person id='40'>Artur Hil</person>
                </persons>
                <links></links>
                <attachments></attachments>
            </event>
            <event guid='eec94184-2b05-5665-9c9f-bdb6b8f70cf3' id='30'>
                <date>2019-02-02T16:30:00+02:00</date>
                <start>16:30</start>
                <duration>00:40</duration>
                <room>Innohub (https://innohub.innovecs.com)</room>
                <slug>owaspkyivwinter2019-30-building-sql-firewall-insights-from-developers</slug>
                <url>https://cfp.owaspukraine.org/owaspkyivwinter2019/talk/CHTFRS/</url>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <title>Building SQL firewall: insights from developers</title>
                <subtitle></subtitle>
                <track></track>
                <type>Talk</type>
                <language>en</language>
                <abstract>How SQL firewalls can help to protect databases from SQL injections: the main difference from WAFs, common usage scenarios, pros, and cons. Developing SQL firewall is a hard task &#8211; we will share insights about parsing SQL protocols, matching rules, hidden dangers of logging, best of configuration and usage patterns.</abstract>
                <description>Our general plan for talk:

1. SQL injections: what&apos;s that and how to protect against them.

2. Typical scenarios of fighting with injections: OWASP guide, WAF, SQL firewall.

3. WAF: pros, cons, why WAF is not enough.

4. SQL firewall: what is this, what are the main features of it.

5. How we built SQL firewall:

    - configuration and rules (allow, deny, ignore);

    - parsing SQL protocols;

    - pattern matching (WHERE, EQUAL, VALUE etc);

    - logging and masking requests;

6. SQL Firewall vs WAF.

7. Best use cases for SQL firewall.

8. Future improvements of SQL firewalls.

9. Outro.</description>
                <logo></logo>
                <persons>
                    <person id='43'>Artem Storozhuk</person>
                </persons>
                <links></links>
                <attachments></attachments>
            </event>
            <event guid='c52ce88a-bf9f-5402-b80c-978a499ec89e' id='28'>
                <date>2019-02-02T17:20:00+02:00</date>
                <start>17:20</start>
                <duration>00:40</duration>
                <room>Innohub (https://innohub.innovecs.com)</room>
                <slug>owaspkyivwinter2019-28-application-threat-modeling</slug>
                <url>https://cfp.owaspukraine.org/owaspkyivwinter2019/talk/9YNHDA/</url>
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <title>Application Threat Modeling</title>
                <subtitle></subtitle>
                <track></track>
                <type>Talk</type>
                <language>en</language>
                <abstract>In this talk, I am going to walk the audience through the Threat Modeling introduction. The program will consist of the overview of popular Threat Modeling methodologies and available tools.</abstract>
                <description>Threat Modeling is an essential part of a secure software development process of any maturity. Building up a map of threats that are relevant for an application or system, measuring the impact and probability of these threats, and mapping existing and planned security controls to the related risks &#8211;&#160;is a crucial exercise that must be performed before the team hits the code and regularly after that.

During the talk, we will design an imaginary piece of software that implements a business idea, and build a Threat Model that maps all planned security activities throughout the software development project that implements it.</description>
                <logo></logo>
                <persons>
                    <person id='1'>Vlad Styran</person>
                </persons>
                <links></links>
                <attachments></attachments>
            </event>
            
        </room>
        
    </day>
    
</schedule>
