Crash Course in Brain Surgery
Crash Course in Brain Surgery (by "brain" I mean "application",
and by "surgery" I mean "security").
Since Codebits is mainly a coder/developer conference, this presentation will be about developing applications securely, primarly Web applications. As we have seen this year, most "standard" flaws, such as XSS and SQLinjection are still being found and exploited in low and high profile applications (remember the Heartland Payment Systems breach, using SQLinjection, where millions of CC numbers were stolen, or the BarackObama.com website ?), even though these vulnerabilities have been known for almost a decade. My talk focuses on raising awareness on the need for developers to think about security, and integrating security throughout the software development lifecycle, helping developers understand the problems, and how these can be avoided. In the talk I'll try to show different types of flaws (language agnostic), from technical flaws (XSS/CSRF/SQLi/etc), to design flaws, business logic flaws, access control flaws, etc, as well as sharing real world examples and experiences from different applications which have #failed.
Portuguese
Geek. Security evangelist. Security professional. PenTester. Auditor. Consultant.
Been using computers for as long as I can remember. And I remember a lot.
Working in computer security for over 10 years. Did almost everything in security, from development (in C, Perl and Python), to R&D of security products, to exploit writing, to training and teaching.
Speaker @ Codebits 2009, and loved every bit (pun intended). (more)
Friday, 4 of December of 2009, from 12:00 to 13:00
Alexandre Amaral de Carvalho
André Cruz
Andreia Gaita
Bernardo Raposo
Bruno Miguel Bota Barreto
Bruno Morisson
Bruno Silva
Carla Vanessa F. A. Leite
Carlos Moutinho
Carlos Rodrigues
Cátia Nunes
David Emanuel da Silva
David José Vaz cruz
David Júlio
Dinis Correia
Filipe Cruz
Filipe Varela
Francisco Ascençao
Jean Figueiredo
João Miguel Forte Oliveirinha
João Paulo Carvalho
João Paulo Martins Machado
João Pedro Pereira
João Poupino
joão ramos
João Rui Martins
Jorge Miguel Ferreira Alves
José Manuel Canelas
José Rodrigues da Mata Fernandes
José Vasco Fidalgo Patrício
Luís Couto
Luis Nabais
Luís Pedro Zamith de Passos Machado Ferreira
Márcio Moreira
Marco Neves
Nuno Dantas
Nuno Cardoso
Paula Valenca
Pedro Cavaco
Pedro Diogo
Pedro Frazão
Pedro Moura Pinheiro
Renato Lourenço
Ricardo Augusto
Ricardo Dias Marques
Ricardo Santos
Rogério Machado
Rui Lopes
Tiago Boldt Sousa
Tiago Henriques
Tiago Mendo
Tiago Serra
Tomás Senart
Wilson Manuel Sousa Alberto
Estimated head count: 93 people
(based on the total of persons interested in this talk and the universe of people attending Codebits)