February 15, 2012 7:00 PM. 96 attended.

LAPHP February Talk: Web App Security - Top Ten Necessary Security Controls

Coloft (map)

Selected By: Oleg Baranovsky

At our February meeting we will talk about your web application security, what do you need to know and top 10 controls to secure your application.

Citigroup, PBS, Sega, Nintendo, Gawker, AT&T, the CIA, the US Senate, NASA, Nasdaq, the NYSE, Zynga, and thousands of others have something in common ­ -- all have had their websites compromised in the last year. No company or industry is immune. It doesn't matter if a business is in financial services, retail, education, gaming, social networking, government, telecom, media or travel. Traditional security techniques from the world of operational or network security do not necessarily apply. Programmers need to learn to build websites differently. This talk will review the top coding techniques developers need to master in order to build a low-risk, high-security web application.

PRESENTER

Our guest presenter will be Jim Manico, the VP of Security Architecture at WhiteHat Security. Jim provides secure coding and developer awareness training for WhiteHat using his 7+ years of experience delivering developer-training courses for SANS, Aspect Security and others. 

Jim brings 15 years of database-driven Web software development and analysis experience to WhiteHat. He has helped deliver Web-centric software systems for Sun Microsystem, Fox Media (MySpace), several Fortune 500's, and major NGO financial institutions. He holds expertise in a variety of areas, includingWeb-based J2EE development, thick-client and applet-based Java applications, hybrid Java, C++ and Flash applications, Web-based PHP applications, rich-media Web applications using advanced Ajax techniques, Python REST Webservice development, and Database technology using Oracle, MySQL and Postgres. A host of the OWASP Podcast Series, Jim is the committee chair of the OWASP Connections Committee and is a significant contributor to various OWASP projects. He is an original contributor and manager of the popular OWASP Cheatsheet Series.

Follow him on Twitter: @manicode. You can also follow the popular @owasp security twitter feed.

Admission is free. Refreshments and drinks will be served!

SPONSORS

The food and drinks are generously sponsored by "Q" - an IT & Digital talent firm. "Q" specializes in networking and building relationships with IT and Digital Talent. They strive to get to know you so we can help with your career growth. They partner with various clients in the Los Angeles area and offer Contract, Contract-to-Hire and Direct Placement opportunities. Find out more at their web site: http://qconnects.com/

As always, our very special thanks to Coloft for hosting us.

PARKING

Street Parking is usually readily available, most of the meters are free after 6pm. Please check the street signs as some sides of the streets are permit parking only.

Give a Ride, Get a Ride

If you'd like to carpool, please post your location in the carpool thread.

Problem finding the location?

Call Oleg @ [masked]

FOLLOW US

If you want to hear about upcoming tech meetups, follow the group and organizers:

Twitter: @laphp | @olegbaranovsky | @ronpeled | @joedevon
Google+:
  Oleg
Please use these hashtags when tweeting about us:  #LAPHP 


ALSO JOIN LAPHP ON:

LinkedIn | Facebook | Plancast

 

96 attended
5.00 5.0013 (13 ratings)

Q - an IT & Digital Talent Firm

"Q" is generously sponsoring our February event

CoLoft

The CoLoft is now sponsoring our group and hosting our monthly meetings.

NoodleYard.com

NoodleYard is CoLoft's new job board!

Activo Extensions

Magento extensions for advanced merchants by Activo

IndieDesk

IndieDesk is coworking space in Downtown Los Angeles

People in this
Meetup are also in:

Log in

Not registered with us yet?

Sign up

Meetup members, Log in

or
By clicking the "Sign up using Facebook" or "Sign up" buttons above, you agree to Meetup's Terms of Service