<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>cat slave diary &#187; Conferences and Travel</title>
	<atom:link href="http://www.greebo.net/category/conferences-and-travel/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.greebo.net</link>
	<description>mostly useless crap from me</description>
	<lastBuildDate>Fri, 23 Jul 2010 20:10:16 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>OSCON 2010 Wrap Up</title>
		<link>http://www.greebo.net/2010/07/24/oscon-2010-wrap-up/</link>
		<comments>http://www.greebo.net/2010/07/24/oscon-2010-wrap-up/#comments</comments>
		<pubDate>Fri, 23 Jul 2010 20:10:16 +0000</pubDate>
		<dc:creator>vanderaj</dc:creator>
				<category><![CDATA[Conferences and Travel]]></category>

		<guid isPermaLink="false">http://www.greebo.net/?p=671</guid>
		<description><![CDATA[Well, OSCON is over for another year. It&#8217;s been a great conference. Shame there were essentially no security talks (1/216 talks is not good enough). I will have to talk to them next year about including a Security track or let OWASP organize a Security Camp, like Scala and the cloud folks had this year.
I ]]></description>
			<content:encoded><![CDATA[<p>Well, OSCON is over for another year. It&#8217;s been a great conference. Shame there were essentially no security talks (1/216 talks is not good enough). I will have to talk to them next year about including a Security track or let OWASP organize a Security Camp, like Scala and the cloud folks had this year.</p>
<p>I went to a great number of interesting sessions. Most were not that well attended, which probably means that I&#8217;m a freak who loves odd ball stuff. That&#8217;s a shame, because I got a heap out of the conference overall.</p>
<p>Some highlights:</p>
<p>Cloud talks were everywhere. This is the new Ajax. I went to enough cloud talks to be all clouded out. A common theme is who owns the data and how open are cloud systems, really? Open core versus open source was a huge meme.</p>
<p><a title="Breaking it open" href="http://www.oscon.com/oscon2010/public/schedule/detail/13959" target="_blank">Breaking it open: How one consulting firm took it open</a>. This was easily the most thought provoking session I attended in all of OSCON. It&#8217;s a shame only about 20 others caught it too. Rob and Alexandra were totally engaging and gave heaps of insights to what worked, and more importantly some of the hiccups that hit them unexpectedly, like the Excel spreadsheet from hell.</p>
<p>Moving to the cloud with NYTimes. This was one of those cloudy talks I told you about. I didn&#8217;t learn a lot that I didn&#8217;t already know, but it was interesting to learn how it went down at NYT.</p>
<p>Deploying an open source cloud on a shoestring. This topic was close to my heart as we&#8217;re doing it, but I sank a little when I learnt of the exact scale of the AT&amp;T Labs deployment. In the end, I think different folks have different meanings for &#8220;shoe string&#8221;. Good talk, as I learnt a fair amount about realistic cloud architecture.</p>
<p>Eucalyptus: the open source infrastructure for cloud systems. Another cloud talk.</p>
<p>Data center automation with Puppet. I went to the latter part of the Puppet tutorial, so I didn&#8217;t learn much new at this session, but that&#8217;s okay. Puppet will probably end up as part of our infrastructure (need to talk to the guys).</p>
<p>Driving Apache Traffic Server. This talk rocked. Lots of cool information about how Yahoo does their CDN, and the resurrection of a really old (and closed) code base into what is ATS today. I&#8217;m going to try it out, but it may not suit our needs as it doesn&#8217;t do true SSL load balancing (today).</p>
<p>The hall way track was also pretty dang fine. I met and introduced myself to many folks I&#8217;d only seen on Twitter or the blogosphere. I took in the latter half of the phpBB BoF and met the guys, which was cool as I could finally put names to faces. I ran the OWASP BoF session on Thursday night, which had a few folks turn up, including the Portland Chapter Leader.</p>
<p>Internet sucked big time most days. I think the next time I come, I&#8217;ll bring a smaller laptop or an iPad or something with a long battery life as finding space near power all the time sucked. This is partially because my Mac&#8217;s battery or logic board is failing, but it is also partially a home truth &#8211; there&#8217;s only so much coding I did during the days as I found most of the talks so engaging and relevant to my interests.</p>
<p>It&#8217;s interesting to see the latest fads. For those who had &gt; 13&#8243; laptops, Macs were about 20 to 1 the favorite choice. Netbooks were very common (probably about 15-20% of the crowd), but I saw more iPads than netbooks, which surprised me as it&#8217;s so read only, and this conference is not a read only crowd.</p>
<p>All in all, a satisfying and interesting conference let down by the complete lack of security talks.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.greebo.net/2010/07/24/oscon-2010-wrap-up/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OSCON 2010 &#8211; Day 2</title>
		<link>http://www.greebo.net/2010/07/21/oscon-2010-day-2/</link>
		<comments>http://www.greebo.net/2010/07/21/oscon-2010-day-2/#comments</comments>
		<pubDate>Wed, 21 Jul 2010 05:16:04 +0000</pubDate>
		<dc:creator>vanderaj</dc:creator>
				<category><![CDATA[Conferences and Travel]]></category>

		<guid isPermaLink="false">http://www.greebo.net/?p=667</guid>
		<description><![CDATA[Woke up at 5.55 am. Mr Body is seriously confused. I finished breakfast by 7 am. This is not right.
Scalable Internet Architecture &#8211; Theo Schlossnagle
I&#8217;m very sorry Theo, but I couldn&#8217;t take much more hand waving and so I left at half time. I think this is more about where I am in my career ]]></description>
			<content:encoded><![CDATA[<p>Woke up at 5.55 am. Mr Body is seriously confused. I finished breakfast by 7 am. This is not right.</p>
<h2><a title="Scalable Internet Architecture" href="http://www.oscon.com/oscon2010/public/schedule/detail/12562" target="_blank">Scalable Internet Architecture &#8211; Theo Schlossnagle</a></h2>
<p>I&#8217;m very sorry Theo, but I couldn&#8217;t take much more hand waving and so I left at half time. I think this is more about where I am in my career &#8211; most folks seemed interested and what not, but this session was the wrong one for me. So I bailed.</p>
<h2><a title="Puppet Training" href="http://www.oscon.com/oscon2010/public/schedule/detail/13687" target="_blank">Using Puppet &#8211; A beginner&#8217;s tutorial &#8211; James Turnbull and Jeff McCune</a></h2>
<p>James and Greg were on song and I really should gone with my initial gut feeling and gone for this talk from the get go. Excellent hands on tute filling in the gaps in my Puppet knowledge. I&#8217;ll be taking the lessons learnt from the half tute I managed to attend back. We might even implement Puppet! <img src='http://www.greebo.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  Seems fairly straightforward.</p>
<h2><a title="Request Tracker Training" href="http://www.oscon.com/oscon2010/public/schedule/detail/13933" target="_blank">Request Tracker Bootcamp &#8211; Jesse Vincent</a></h2>
<p>This is the primary reason I plumped for OSCON 2010. There are a few talks over the next few days, but we use RT &#8230; badly &#8230; within our organization, and that needs fixing. I learnt nearly everything I needed to use it properly, including:</p>
<ul>
<li>The <a title="RTFM" href="http://bestpractical.com/rtfm/" target="_blank">RTFM</a> module &#8211; mark out a solution as the appropriate answer. This is exactly what we need</li>
<li>The <a title="RTIR" href="http://bestpractical.com/rtir/" target="_blank">RTIR</a> incident response module &#8211; a solution for CERT style incident handling. This is not quite what we do, but I will look at it anyway.</li>
<li>The PGP plugin. Definitely going to try and get this going.</li>
<li>How to fix a few niggling issues. I entered some new tickets for me to handle when I get back. <img src='http://www.greebo.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </li>
<li>How to configure custom fields &#8230; good to know for future enhancements to our use of RT</li>
</ul>
<p>I&#8217;m glad I attended &#8211; this was a great session and definitely recommended to anyone using RT. Jesse is a good tutor, and as the original author, he definitely knows his stuff.</p>
<h2>In other news</h2>
<p>I headed into Portland city for the first time to go get my Mac serviced. The light rail is eerie &#8211; it&#8217;s just like Melbourne trams, but more segregated from traffic. Getting taxis is a fools errand in Portland. Public transport is king here baby.</p>
<p>My Mac&#8217;s battery had been dying unexpectedly over the last month or so, especially at the least reasonable times. At other times, the battery would last a good two and a bit hours (like today), but the randomness of it all is distressing, especially when there&#8217;s data loss. So I made an appointment with the Apple Genius Bar yesterday, and popped in today.</p>
<p>They ran some diagnostics. My battery was found to be acceptable albeit towards the end of its working life. The power adapter is fine. That means if the issue continues, I will need a new logic board. On an out of warranty Mac. DOH! Could get expensive.</p>
<p>I came back and had dinner with an ex-colleague of mine &#8211; Paul Hanchett. They&#8217;re doing it hard in the USA. We didn&#8217;t really have much of a GFC in Australia, but here&#8230; whoa. I see on Twitter (#oscon) I missed OSCON Ignite. The in crowd liked it very much, but &#8230; I&#8217;d still rather have dinner with an old friend than do more slides today.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.greebo.net/2010/07/21/oscon-2010-day-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OSCON 2010 Day 1</title>
		<link>http://www.greebo.net/2010/07/20/oscon-2010-day-1/</link>
		<comments>http://www.greebo.net/2010/07/20/oscon-2010-day-1/#comments</comments>
		<pubDate>Mon, 19 Jul 2010 21:16:36 +0000</pubDate>
		<dc:creator>vanderaj</dc:creator>
				<category><![CDATA[Conferences and Travel]]></category>

		<guid isPermaLink="false">http://www.greebo.net/?p=663</guid>
		<description><![CDATA[Travelling to the USA was as exhausting as ever.
I flew on the new A380 with Qantas. Nice plane. As per usual, there&#8217;s a mix of flight attendants &#8211; the openly hostile, the &#8220;can&#8217;t see you, didn&#8217;t see you&#8221;, and my favorite, the &#8220;never around&#8221;. We were down the back of the aircraft, which is fun ]]></description>
			<content:encoded><![CDATA[<p>Travelling to the USA was as exhausting as ever.</p>
<p>I flew on the new A380 with Qantas. Nice plane. As per usual, there&#8217;s a mix of flight attendants &#8211; the openly hostile, the &#8220;can&#8217;t see you, didn&#8217;t see you&#8221;, and my favorite, the &#8220;never around&#8221;. We were down the back of the aircraft, which is fun if you like turbulence (I do), but not so fun for the elderly couple next to me. There was a party of teens in the middle section who had no in flight entertainment units. The units are ancient and have been recycled from other aircraft &#8211; and take about 10 minutes to reboot. They run Red Hat Linux from 2002 on some VIA Cyrus processor. So it was like a little party. I got like one hour of fitful sleep  in the 16 hour flight.</p>
<p>LAX is better. They ripped out the old customs hall, and replaced it with something like an airport instead of a manifestation of hell on earth. The customs folks even smiled. I&#8217;m not sure what about, but it feels more human than previous times.</p>
<p>There was a stuff up with my hotel and teknology fangummy (they&#8217;ve heard about it but don&#8217;t think it&#8217;ll catch on), but luckily, Australian business hours had just begun and I was in about 28 hours after leaving my folks place.</p>
<h2><a title="Quality Assurance in PHP Projects" href="http://www.oscon.com/oscon2010/public/schedule/detail/12516" target="_blank">PHP Quality Assistance</a> &#8211; Sebastian Bergmann</h2>
<p>My first tutorial was Sebastian Bergmann of <a title="PHP Unit" href="http://www.phpunit.de/" target="_blank">PHP Unit</a> fame.</p>
<p>This was an awesome tutorial, and I found out a lot about tools that I had only just started to scratch the surface with. I am definitely going to setup a continuous integration server for my projects whilst I&#8217;m in Portland.</p>
<p>Sebastian was a good speaker, but I would have liked more demos in the first half. The demo of Hudson was possibly more informative than the slides itself. Definitely recommend seeing more Sebastion Bergmann talks!</p>
<p><a title="Slides for Quality Assurance in PHP" href="http://bit.ly/phpqaoscon10" target="_blank">Slides</a></p>
<h2>Productive Programmer &#8211; Neal Ford</h2>
<p>I attended this session with high hopes as most Thought Works folks I&#8217;ve met have been very switched on. Neal seems very switched on, but &#8230; this talk started out very slow and covered blindly obvious things that I think we&#8217;re all familiar with (source code control, comfy chairs, etc). The tutorial was definitely looking like a hated &#8220;hand waving&#8221; tutorials.</p>
<p>I considered bailing but none of the other talks in this time slot really were yelling my name. I might have tried Chris Shiflett&#8217;s tute as he&#8217;s a friend, but I wouldn&#8217;t learn much there, so I stayed for the second half.</p>
<p>The second half was a Top 10 with a small Top 10 &#8220;Corporate Code Smells&#8221; inside. Luckily, the second half was a bit more edifying and informative, but more from a &#8220;food for thought&#8221; point of view rather than any special insights into enterprise architecture or techniques that I&#8217;ve never heard before. This could be due to the point where I am in my career, but I was hoping for more.</p>
<p>The main things I learnt were the hard lessons learnt from Neal&#8217;s career. I wish there was more war stories with solutions, and far more detail throughout. If I was Neal, I&#8217;d look hard at thinking about the OSCON audience. These guys are mostly devs looking to make the jump to architect. Refactor the talk to be about that jump, the patterns, the scalability of ideas, and so on. Then it would be a HUGE improvement over the comfy chair talk we got today.</p>
<p>The thing I really didn&#8217;t like was the slamming of WebSphere (&#8220;#1 Code Smell. There&#8217;s a reason that WSAD is not WHAPPY&#8221;). Slammed not once, but twice in the same list. I don&#8217;t like WSAD that much either (it&#8217;s an overpriced Eclipse + J2EE reference container + IBM&#8217;s own special plugins and &#8220;enterprise&#8221; / cluster juice), but it&#8217;s like saying &#8220;your tool sucks&#8221;. Yes, but it didn&#8217;t need to be said twice in the same list, and I think most folks in the room who actually use it are forced to use it, and are unlikely to be able to move away from it. If you need the things WSAD can do, there&#8217;s few alternatives today.</p>
<p>Slides TBA</p>
<h2>OWASP &#8211; Birds of a Feather</h2>
<p>I&#8217;ve set up a OWASP Birds of a Feather session at 8 pm on Thursday night in D136. Hope to see you there!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.greebo.net/2010/07/20/oscon-2010-day-1/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Going to OSCON 2010</title>
		<link>http://www.greebo.net/2010/05/05/going-to-oscon-2010/</link>
		<comments>http://www.greebo.net/2010/05/05/going-to-oscon-2010/#comments</comments>
		<pubDate>Wed, 05 May 2010 06:41:10 +0000</pubDate>
		<dc:creator>vanderaj</dc:creator>
				<category><![CDATA[Conferences and Travel]]></category>

		<guid isPermaLink="false">http://www.greebo.net/?p=627</guid>
		<description><![CDATA[I know I&#8217;ve ranted about this before, and this post is no different. OSCON still doesn&#8217;t have any security talks, which is like an engineering conference that doesn&#8217;t have any structural integrity talks.
A sample of non-functional requirements in the OSCON 2010 program:

Configuration Management &#8211; check*
Deployment &#8211; check
Documentation &#8211; check
Efficiency &#8211; check*
Legal issues &#8211; check
Performance &#8211; check*
Maintainability ]]></description>
			<content:encoded><![CDATA[<p>I know I&#8217;ve ranted about this before, and this post is no different. OSCON still doesn&#8217;t have any security talks, which is like an engineering conference that doesn&#8217;t have any structural integrity talks.</p>
<p>A sample of non-functional requirements in the <a title="OSCON full schedule" href="http://www.oscon.com/oscon2010/public/schedule/full" target="_blank">OSCON 2010 program</a>:</p>
<ul>
<li>Configuration Management &#8211; check*</li>
<li>Deployment &#8211; check</li>
<li>Documentation &#8211; check</li>
<li>Efficiency &#8211; check*</li>
<li>Legal issues &#8211; check</li>
<li>Performance &#8211; check*</li>
<li>Maintainability &#8211; check*</li>
<li>Quality &#8211; check*</li>
<li>Scalability &#8211; check*</li>
<li>Testability &#8211; check*</li>
</ul>
<p>* I&#8217;m going to a few of these tutes and talks</p>
<p>And what they don&#8217;t cover:</p>
<ul>
<li>Compliance &#8211; 0 talks</li>
<li>Privacy &#8211; 0 talks</li>
<li>Safety &#8211; 0 talks</li>
<li>Security &#8211; 0 talks, 1 three hour tutorial</li>
</ul>
<p>And yet, security is the only NFR that can close your business, destroy shareholder value, get you sued, cost you dearly in compliance and remediation costs, limit your organization or project to irrelevance, and destroy privacy for millions of folks in one fell swoop of ineptitude and cluelessness.</p>
<p>One day, the papers committee will get a clue. It&#8217;s not 2010, though.</p>
<p>So all my open source chums &#8211; see you in Portland! <img src='http://www.greebo.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.greebo.net/2010/05/05/going-to-oscon-2010/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>OWASP EU 2009 Coming Soon!</title>
		<link>http://www.greebo.net/2009/04/04/owasp-eu-2009-coming-soon/</link>
		<comments>http://www.greebo.net/2009/04/04/owasp-eu-2009-coming-soon/#comments</comments>
		<pubDate>Sat, 04 Apr 2009 01:54:03 +0000</pubDate>
		<dc:creator>vanderaj</dc:creator>
				<category><![CDATA[Conferences and Travel]]></category>
		<category><![CDATA[OWASP]]></category>

		<guid isPermaLink="false">http://www.greebo.net/?p=538</guid>
		<description><![CDATA[OWASP EU 2009 is coming up! This year, it&#8217;s held in Kraków, Poland. Time to book!
Program highlights:

Keynote: Ross Anderson from Cambridge University. I&#8217;ve wanted to meet Ross for many years. Those guys are legends!
Keynote: Bruce Schneier. I bet there are groupies
w3af &#8211; Andrés Riancho. This is one of the best free toolkits I&#8217;ve tried recently. It&#8217;s awesome.
HTTP Parameter ]]></description>
			<content:encoded><![CDATA[<p>OWASP EU 2009 is coming up! This year, it&#8217;s held in Kraków, Poland. <a href="http://guest.cvent.com/i.aspx?4W,M3,887f27a2-13e0-47dc-9220-76ed22ab0546">Time to book!</a></p>
<p>Program highlights:</p>
<ul>
<li>Keynote: Ross Anderson from Cambridge University. I&#8217;ve wanted to meet Ross for many years. Those guys are legends!</li>
<li>Keynote: Bruce Schneier. I bet there are groupies</li>
<li>w3af &#8211; Andrés Riancho. This is one of the best free toolkits I&#8217;ve tried recently. It&#8217;s awesome.</li>
<li>HTTP Parameter Pollution, Luca Carettoni, Independent Researcher &amp; Stefano Di Paola</li>
<li>OWASP Source Code Flaws Top 10 Project, Paulo Perego, Spike Reply</li>
<li>O2 Advanced Source Code Analysis Toolkit, Dinis Cruz</li>
<li>&#8230; many others!</li>
</ul>
<p>Although I would love to be there &#8211; I had a blast at OWASP EU 2006, I can&#8217;t attend this year. Which is a shame, because OWASP AU 2009 was huge fun, and I can&#8217;t imagine OWASP EU 2009 would be anything less.Don&#8217;t make the same mistake as me! Book now!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.greebo.net/2009/04/04/owasp-eu-2009-coming-soon/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Training coming along nicely</title>
		<link>http://www.greebo.net/2009/02/17/training-coming-along-nicely/</link>
		<comments>http://www.greebo.net/2009/02/17/training-coming-along-nicely/#comments</comments>
		<pubDate>Tue, 17 Feb 2009 10:06:23 +0000</pubDate>
		<dc:creator>vanderaj</dc:creator>
				<category><![CDATA[Conferences and Travel]]></category>
		<category><![CDATA[OWASP]]></category>

		<guid isPermaLink="false">http://www.greebo.net/?p=516</guid>
		<description><![CDATA[For those of you sitting on the fence about coming to OWASP AU 2009, it&#8217;s time to book.  
The training materials I&#8217;ve developed using OWASP ASVS covers all the ground in the ASVS in one day, from a developer perspective:

About the Application Security Verification Standard
What you need to verify code
About Risk 
The ASVS Levels
Verifying Architecture
Verifying ]]></description>
			<content:encoded><![CDATA[<p>For those of you sitting on the fence about coming to OWASP AU 2009, it&#8217;s time to book. <img src='http://www.greebo.net/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p>The training materials I&#8217;ve developed using OWASP ASVS covers all the ground in the ASVS in one day, from a developer perspective:</p>
<ul>
<li>About the Application Security Verification Standard</li>
<li>What you need to verify code</li>
<li>About Risk </li>
<li>The ASVS Levels</li>
<li>Verifying Architecture</li>
<li>Verifying Authentication</li>
<li>Verifying Session Management</li>
<li>Verifying Access Control</li>
<li>Verifying Input validation</li>
<li>Verifying Output encoding / canonicalization</li>
<li>Verifying Cryptography</li>
<li>Verifying Error Handling / Logging</li>
<li>Verifying Data Protection</li>
<li>Verifying Communications Security</li>
<li>Verifying HTTP Security</li>
<li>Verifying Configuration</li>
<li>Verifying Malicious Code</li>
<li>Verifying Internal security controls</li>
<li>How to write a decent report and how to communicate (good and) bad news </li>
</ul>
<p>It&#8217;s going to be a long day, so bring your game to the sunny Gold Coast, Australia. OWASP AU is a true bargain compared to commercial offerings.</p>
<p>If you have some training budget, book a ticket and come see me and have a blast!</p>
<p><a href="http://guest.cvent.com/i.aspx?4W,M3,426274ef-3d51-4c8f-adc2-49e7d8fc735d" target="_blank">Book my course now</a></p>
<p><a title="OWASP AU 2009" href="http://www.owasp.org/index.php/OWASP_AU_Conference_2009" target="_blank">All about OWASP AU 2009</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.greebo.net/2009/02/17/training-coming-along-nicely/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OWASP EU Summit</title>
		<link>http://www.greebo.net/2008/10/27/owasp-eu-summit/</link>
		<comments>http://www.greebo.net/2008/10/27/owasp-eu-summit/#comments</comments>
		<pubDate>Mon, 27 Oct 2008 16:49:33 +0000</pubDate>
		<dc:creator>vanderaj</dc:creator>
				<category><![CDATA[Conferences and Travel]]></category>
		<category><![CDATA[OWASP]]></category>

		<guid isPermaLink="false">http://www.greebo.net/?p=475</guid>
		<description><![CDATA[Although I am unable to attend, I hope you can attend the OWASP EU Summit, to be held next week in Portugal.
There&#8217;s going to be lots of discussion about OWASP&#8217;s various projects, and work out futures for all of them. It&#8217;s going to be a defining event in OWASP&#8217;s existence, and I wish I could ]]></description>
			<content:encoded><![CDATA[<p>Although I am unable to attend, I hope you can attend the OWASP EU Summit, to be held next week in Portugal.</p>
<p>There&#8217;s going to be lots of discussion about OWASP&#8217;s various projects, and work out futures for all of them. It&#8217;s going to be a defining event in OWASP&#8217;s existence, and I wish I could have been there.</p>
<p>You can find out more about the summit here:</p>
<p><a title="OWASP EU Summit" href="http://www.owasp.org/index.php/OWASP_EU_Summit_2008" target="_blank">http://www.owasp.org/index.php/OWASP_EU_Summit_2008</a></p>
<p>I&#8217;ve left my run fairly late for the projects I contribute to (the OWASP Guide, Top 10, Coding Standard, etc), which is a shame, but since chairing a session requires some dedication and time, I couldn&#8217;t find folks on the ground in time to replace me. There was talk of me presenting remotely via Skype, but I haven&#8217;t followed that up, and the calendar looks very full. We&#8217;ll see if there&#8217;s a way I contribute in other ways.</p>
<p>I still need fresh victims^H^H^H^H^H volunteers for the OWASP Developer Guide, Top 10 2009, and Coding Standard. Please e-mail me vanderaj @ owasp . org if you can help write a paragraph or two per day.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.greebo.net/2008/10/27/owasp-eu-summit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Black Hat 2008</title>
		<link>http://www.greebo.net/2008/08/11/black-hat-2008/</link>
		<comments>http://www.greebo.net/2008/08/11/black-hat-2008/#comments</comments>
		<pubDate>Tue, 12 Aug 2008 01:51:47 +0000</pubDate>
		<dc:creator>vanderaj</dc:creator>
				<category><![CDATA[Conferences and Travel]]></category>
		<category><![CDATA[OWASP]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.greebo.net/?p=470</guid>
		<description><![CDATA[Well, I&#8217;m back from another year at Black Hat. This time, I taught one of my company&#8217;s 2D Web Application Security courses.
I think I may have been one of the very few courses that concentrated on defense, which is Black Hat&#8217;s tongue in cheek slogan (&#8220;Digital Self Defense&#8221;). I taught the folks in there (about ]]></description>
			<content:encoded><![CDATA[<p>Well, I&#8217;m back from another year at Black Hat. This time, I taught one of my <a class="aligncenter" title="Aspect Security" href="http://www.aspectsecurity.com/" target="_blank">company&#8217;s</a> 2D Web Application Security courses.</p>
<p>I think I may have been one of the very few courses that concentrated on defense, which is Black Hat&#8217;s tongue in cheek slogan (&#8220;Digital Self Defense&#8221;). I taught the folks in there (about a 50/50 mix of devs and PMs/architects/designers etc) not only &#8220;this is a SQL injection&#8221; but hey, we have a complete solution for this, and this is how it works.</p>
<p>The class was originally 15 &#8211; 20 in size, but ended up being more than double that. I&#8217;m pleased with the outcome and how many folks really liked the course. Hopefully, it will lead BH into more actual digital self defense rather than just claiming that territory whilst promoting offense, offense, offense.</p>
<p>I met up with a fair number of folks, including Dinis, and all too briefly Jeremiah, RSnake, Arian Evans, the blokes from the NAB (Justin et al), my mate Justin Derry who is now at Fortify, and a bunch of others.</p>
<p>I took in almost all of the appsec 1.0 / webappsec 2.0, except for the last session of the last day. It was a good conference and well worth the visit this year. There are always a couple of weak talks, including the one from the network pen testers who have cottoned on to 0days involving web apps which I found very amusing because they thought they were so hard core and l33t. Here&#8217;s a hint guys: if you can&#8217;t get 8-20 0days out of any web app, you&#8217;re not doing it right. It&#8217;s like whack a mole or stealing candy from a sleeping baby. And authorization attacks are automatable if you have the right tools. The only interesting thing from that talk was an extension of the old file format jumble, where some file formats have headers and some have trailers, and thus you can make a valid file that is both one thing and another. They had a GIF and a JAR. Past precedents include both ELF and Win32 binaries (from <a title="Win32.Winux" href="http://www.theregister.co.uk/2001/03/28/risks_from_hybrid_linux_windows/" target="_blank">back in 2001</a>) in the one binary, <a href="http://isc.sans.org/diary.html?storyid=2997">the 1&#215;1 pixel image that is also a PHP exploit</a> (my favorite). I&#8217;m sure there&#8217;s others prior to 2001.</p>
<p>Anyway, enough ranting for me. I had a good time, and I can hardly complain as I was sponsored there by my employer and thus bore nothing of the real costs of this trip.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.greebo.net/2008/08/11/black-hat-2008/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Feelings of Rejection</title>
		<link>http://www.greebo.net/2008/04/02/feelings-of-rejection/</link>
		<comments>http://www.greebo.net/2008/04/02/feelings-of-rejection/#comments</comments>
		<pubDate>Wed, 02 Apr 2008 06:31:03 +0000</pubDate>
		<dc:creator>vanderaj</dc:creator>
				<category><![CDATA[Conferences and Travel]]></category>
		<category><![CDATA[OWASP]]></category>
		<category><![CDATA[Rants]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.greebo.net/2008/04/02/feelings-of-rejection/</guid>
		<description><![CDATA[In other news, all my talks for OSCON were rejected again. Why did I bother? I should have paid attention my last year&#8217;s rant. Most likely, I will have to give up on submitting papers to certain open source developer&#8217;s conferences as honestly, why bother doing the work of doing the research, creating the paper ]]></description>
			<content:encoded><![CDATA[<p>In other news, all my talks for OSCON were rejected again. Why did I bother? I should have paid attention my last year&#8217;s rant. Most likely, I will have to give up on submitting papers to certain open source developer&#8217;s conferences as honestly, why bother doing the work of doing the research, creating the paper and slides only to be rejected? Luckily, two of my submissions were from colleagues, so I didn&#8217;t squander a lot of resources on those talks, even though for example, I&#8217;m working on porting ESAPI to PHP, which is the subject of one of the rejected talks.</p>
<p>I&#8217;ve identified the following security talks for those security folks still considering going to OSCON (although I&#8217;d recommend saving your money for <a href="http://www.owasp.org/index.php/OWASP_NYC_AppSec_2008_Conference">OWASP USA</a> as we already have a schedule of 45 web app sec talks in three tracks, and two full days of tutorials, including several two day courses where you&#8217;ve got an actual chance of learning something. Just saying.)</p>
<ul>
<li><a href="http://en.oreilly.com/oscon2008/public/schedule/detail/2829">Securing the PHP environment with phpsecinfo</a>, by Ed Finkler. This should be good &#8211; I&#8217;ve used it before and it&#8217;s a pretty cool way to tie down PHP properly. And Ed has contributed Inspekt to OWASP, and therefore he&#8217;s cool by me.
</li>
<li><a href="http://en.oreilly.com/oscon2008/public/schedule/detail/3133">PHP: Architecture, Scalability and Security</a>, by Rasmus. Rasmus knows what he is talking about, but I don&#8217;t know how deep the security aspect will be. Hopefully, enough as it&#8217;s a three hour talk.
</li>
<li><a href="http://en.oreilly.com/oscon2008/public/schedule/detail/3039">PHP Taint Tool: It ain&#8217;t a parser</a>, by Luke Wellings, a friend of mine from Australia who now lives with his lovely wife in Columbia MD. I&#8217;d love to see this tool in action.
</li>
<li><a href="http://en.oreilly.com/oscon2008/public/schedule/detail/2949">Hack this App! PHP security workshop</a>, the usual sort of scare the punters talk common in talks at conferences I attended about 5-10 years ago. I really hope there&#8217;s some solutions in this one. There&#8217;s no point in saying you have a problem unless you have a solution, which is what all three of my submitted talks were. Especially the one on securing PHP apps and ESAPI for Java (although we have a completed .NET and soon a PHP port now)
</li>
<li><a href="http://en.oreilly.com/oscon2008/public/schedule/detail/3049">Perl Security</a>, three hour talk by Paul Fenwick, also an Australian of my acquaintance <img src='http://www.greebo.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />
</li>
<li><a href="http://en.oreilly.com/oscon2008/public/schedule/detail/2909">How to improve quality and security automatically in your open source projects with static analysis</a>, by David Maxwell (Coverity). Hopefully, this is just not a vendor plug, but even if it is &#8230; it is about solutions, and I like that.
</li>
<li><a href="http://en.oreilly.com/oscon2008/public/schedule/detail/3060">Security 2.0: Emerging Trends in Web Application Security</a>, by Chris Shiflett. Also a friend, but sadly, not Australian.
</li>
</ul>
<p>So five talks and two three hour longer talks. Here it is in graphical format for you:</p>
<p><img src='http://www.greebo.net/wp-content/uploads/2008/04/microsoft-powerpointscreensnapz001.png' alt='microsoft-powerpointscreensnapz001.png' /></p>
<p>A couple of the talks are likely to not offer that much in the way of solutions. Sadly, no Ruby, Python, administration, database, emerging topics, or people security talks. Worse, there are no Java security talks, which for an semi-incomplete track, I found sort of astounding, especially as I submitted two Java security talks and one PHP talk. The <a href="http://en.oreilly.com/oscon2008/public/schedule/presentations/Security">official &#8220;security&#8221; track</a> has two three hour talks, both detailed above. Even if you look at it from the point of view of OSCON having 16 tracks, hopefully with equal time for all of the tracks assuming there was a lot of competition for speaking slots, there should be 215/16 = ~ 13.4 security talks, not 7.</p>
<p>Although I am glad my friends are accepted whilst talking about security, I think OSCON needs a new program committee. This one is broken.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.greebo.net/2008/04/02/feelings-of-rejection/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>OWASP / WASC AppSec 2007</title>
		<link>http://www.greebo.net/2007/10/11/owasp-wasc-appsec-2007/</link>
		<comments>http://www.greebo.net/2007/10/11/owasp-wasc-appsec-2007/#comments</comments>
		<pubDate>Thu, 11 Oct 2007 04:50:19 +0000</pubDate>
		<dc:creator>vanderaj</dc:creator>
				<category><![CDATA[Conferences and Travel]]></category>
		<category><![CDATA[OWASP]]></category>

		<guid isPermaLink="false">http://www.greebo.net/2007/10/11/owasp-wasc-appsec-2007/</guid>
		<description><![CDATA[It&#8217;s that time of the year again! Time to register for the OWASP / WASC AppSec 2007 Conference.

Training Schedule
Conference Schedule
Secure Registration

This is the conference track I dream about when I cry to myself re: lack of web application security in other security conferences. Awesome speakers, the Breach cocktail party (register now! Breach&#8217;s OWASP / WASC ]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s that time of the year again! Time to register for the <a href="http://www.owasp.org/index.php/OWASP_%26_WASC_AppSec_2007_Conference">OWASP / WASC AppSec 2007 Conference.</a></p>
<ul>
<li><a href="http://www.owasp.org/index.php/7th_OWASP_AppSec_Conference_-_San_Jose_2007/Training">Training Schedule</a></li>
<li><a href="http://www.owasp.org/index.php/7th_OWASP_AppSec_Conference_-_San_Jose_2007/Agenda">Conference Schedule</a></li>
<li><a href="https://guest.cvent.com/EVENTS/Register/IdentityConfirmation.aspx?e=17e6e912-2dec-4de6-8946-aa005721c4dd">Secure Registration</a></li>
</ul>
<p>This is the conference track I dream about when I cry to myself re: <a href="http://www.greebo.net/2007/07/23/final-score-oscon-4234-black-hat-592-defcon-1118-appsecurity-10444-statistically-insignificant/">lack of web application security in other security conferences</a>. Awesome speakers, the Breach cocktail party (register now! Breach&#8217;s OWASP / WASC party at Blackhat&#8217;s was awesome).</p>
<p>I believe we are still looking for sponsors, so if you have a lead there, mail conferences &#8216;at&#8217; owasp.org.</p>
<p>I really appreciate the WASC folks for taking a chance on collaborating with us at OWASP. With their help on the ground and on the papers committee, I think this will be one of the best appsec conferences ever! I hope to be there, but as my wife is nearly due, I may not get a leave pass from the <a href="http://www.tansempire.com/">Minister of War and Finance</a>. </p>
]]></content:encoded>
			<wfw:commentRss>http://www.greebo.net/2007/10/11/owasp-wasc-appsec-2007/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
