Crash Course in Brain Surgery
Crash Course in Brain Surgery (by "brain" I mean "application",
and by "surgery" I mean "security").
Since Codebits is mainly a coder/developer conference, this presentation will be about developing applications securely, primarly Web applications. As we have seen this year, most "standard" flaws, such as XSS and SQLinjection are still being found and exploited in low and high profile applications (remember the Heartland Payment Systems breach, using SQLinjection, where millions of CC numbers were stolen, or the BarackObama.com website ?), even though these vulnerabilities have been known for almost a decade. My talk focuses on raising awareness on the need for developers to think about security, and integrating security throughout the software development lifecycle, helping developers understand the problems, and how these can be avoided. In the talk I'll try to show different types of flaws (language agnostic), from technical flaws (XSS/CSRF/SQLi/etc), to design flaws, business logic flaws, access control flaws, etc, as well as sharing real world examples and experiences from different applications which have #failed.
Portuguese
Bruno Morisson is a Senior Information Security Consultant at Commet, a new IT services company from the Oni Group. He currently leads the IT Security Operations teams at Commet, providing services to customers in the financial, public and energy sectors, to who he also provides consultancy, engineering, and auditing services. For the last 10 years he's been involved in several areas of Information Security, from consulting, architecture, engineering, auditing and penetration testing, as well as integration of opensource security solutions. He was one of the founders of the portuguese chapter of the Honeynet Project, and holds several certifications in Information Security (CISSP, CISA, ISO27001 Lead Auditor). (more)
Friday, 4 of December of 2009, from 12:00 to 13:00
Alexandre Amaral de Carvalho
André Cruz
Andreia Gaita
Artur Jorge Martins
Bernardo Raposo
Bruno Miguel Bota Barreto
Bruno Morisson
Bruno Silva
Carla Vanessa Ferreira Alves Leite
Carlos Moutinho
Carlos Rodrigues
Cátia Nunes
cíntia pereira
David Emanuel da Silva
David José Vaz cruz
David Júlio
Dinis Correia
Felipe Ávila da Costa
Filipe Manuel Miranda da Cruz
Filipe Varela
Francisco Ascençao
Jean Figueiredo
João Bordalo
João Miguel Forte Oliveirinha
João Paulo Carvalho
João Paulo Martins Machado
João Pedro Pereira
João Poupino
joão ramos
João Rui Martins
João Santos
Jorge Miguel Ferreira Alves
José Manuel Canelas
José Rodrigues da Mata Fernandes
José Vasco Fidalgo Patrício
Luís Couto
Luis Nabais
Luís Pedro Zamith de Passos Machado Ferreira
Manuel João Silva
Márcio Moreira
Marco Neves
Nelson Antunes
Nuno Dantas
Nuno Cardoso
Paula Valenca
Pedro Cavaco
Pedro Diogo
Pedro Frazão
Pedro Moura Pinheiro
Renato Lourenço
Ricardo Augusto
Ricardo Dias Marques
Ricardo Santos
Rogério Machado
Rui Lopes
Tiago Boldt Sousa
Tiago Henriques
Tiago Mendo
Tiago Sá
Tiago Serra
Tim Koch-Grünberg
Tomás Senart
Wilson Manuel Sousa Alberto
Estimated head count: 109 people
(based on the total of persons interested in this talk and the universe of people attending Codebits)