OWASP Belgium
Welcome to the Belgium chapter homepage. The chapter leaders are Sebastien Deleersnyder, Lieven Desmet and Bart De Win.
With the Belgium chapter, we aim to organize 4 local chapter meetings per year and co-organize the yearly BeNeLux Day. Any suggestions for speakers or venue? Feel free to reach out to us!
Upcoming events
To kickstart 2021, we plan a series of virtual chapter meetings with renowned, international speakers!
Join us every 3rd Thursday of the month, from 17:00 until 18:00 CET.
Next confirmed events:
- May 20th: Jeremiah Grossman with Why Attack Surface Management is Hard
- June 17th: Marc Curphey with Upcoming open-source AWS Discovery tool
- September 16th: Andrew van der Stock with The OWASP Top 10 2021
- October 21st: Steven Springett with Component Analysis vs SCA - How SBOMs are the driving force for change
Past events of 2021:
- February 18th: Jim Manicode and Philippe De Ryck with JWT’s - sign em like it’s hot
- March 18th: Christian Folini with The adventurous tale of online voting in Switzerland
- April 15th: Simon Bennetts with ZAP Intro and Latest Features
Registration: https://owasp-belgium-virtual-chapter-meetings-2021.eventbrite.com/
More info: on the ‘Chapter Meetings’ tab.
Chapter sponsors
OWASP Belgium thanks its structural chapter supporters for 2019 and the OWASP BeNeLux Days 2018
Example
Put whatever you like here: news, screenshots, features, supporters, or remove this file and don’t use tabs at all.
OWASP Belgium Virtual Chapter Meeting Series 20201
To kickstart 2021, we plan a series of virtual chapter meetings. Every 3rd Thursday of the month, we invite a renowned, international speaker to join us in a focused evening session.
Previous events of 2021:
- February 18th: Jim Manicode and Philippe De Ryck with JWT’s - sign em like it’s hot [Video] [Slides]
- March 18th: Christian Folini with The adventurous tale of online voting in Switzerland [Video] [Slides]
- April 15th: Simon Bennetts with ZAP Intro and Latest Features [Video] [Slides]
Upcoming events:
- May 20th: Jeremiah Grossman with Why Attack Surface Management is Hard
- June 17th: Marc Curphey with Upcoming open-source AWS Discovery tool
- September 16th: Andrew van der Stock with The OWASP Top 10 2021
- October 21st: Steven Springett with Component Analysis vs SCA - How SBOMs are the driving force for change
Our chapter meetings are open for everyone, and attendance is free of charge. We ask you to register on Eventbrite in order to provide you with last-minute updates, if needed.
20 May 2021: Why Attack Surface Management is Hard (by Jeremiah Grossman)
This virtual chapter meeting will host Jeremiah Grossman!
- When? From 17:00 until 18:00 CEST.
- Registration? via https://owasp-belgium-virtual-chapter-meetings-2021.eventbrite.com/ (attendence free of charge)
- Where? Online! YouTube Livestream - Zoom session via Eventbrite
- Price? Free of charge!
Why Attack Surface Management is Hard
Everyone agrees that attack surface management is critically important, as it is the very first step of any information security program. While enterprise interest and market traction for attack surface management is building, it’s curious why every organization doesn’t already have an up-to-date attack surface map. They should! It may sound strange, but I believe it’s because attack surface management is technologically a hard problem to solve – extremely hard. This is harder to solve than most any another other problem across the entire IT and IT security industry, and harder than any other problem I’ve personally worked on. Let’s dive into the technical details of the many challenges and explore statistics of attack surface maps across the industries.
Jeremiah Grossman
Jeremiah Grossman’s career spans nearly 20 years and has lived a literal lifetime in computer security to become one of the industry’s biggest names. And since Jeremiah earned a Brazilian Jiu-Jitsu black belt, the media has described him as “the embodiment of converged IT and physical security.” Preventing attacks from the scariest cyber-criminals is all in a day’s work for Jeremiah, but staying a keystroke ahead of the bad guys isn’t easy. In 2001, Jeremiah founded WhiteHat Security, which today has one of the largest professional hacking armies on the planet. Let it sink in. Professional. Hacker. Army.
Jeremiah has received a number of industry awards, been publicly thanked by Microsoft, Mozilla, Google, Facebook, and many others for privately informing them of weaknesses in their systems – a polite way of saying, ‘hacking them’. His research included ways to surreptitiously turn on anyone’s computer video camera and microphone from anywhere across the Internet, sidestep firewalls, abuse online advertising networks to take any website offline, hijack the email and bank accounts of millions, silently rip out saved passwords and surfing history from web browsers, and many other cyber-attack techniques – some so insidious and fundamental that many still have not been fixed to this day.
Collectively, it’s no surprise Jeremiah has been featured in the Wall Street Journal, Forbes, NY Times and hundreds of other media outlets around the world who rely upon his expertise. Just type “Jeremiah Grossman” into your favorite search engine, you’ll see. He also serves on the advisory board of several hot start-ups including Kenna Security, BugCrowd, SentinelOn, Arkose Labs, and LifeDNA. Of course, all of this was after Mr. Grossman served as information security officer at Yahoo!
Meeting archive
- 2020 chapter meetings
- 2019 chapter meetings
- 2018 chapter meetings
- 2017 chapter meetings
- 2016 chapter meetings
- 2015 chapter meetings
- 2014 chapter meetings
- 2013 chapter meetings
- 2012 chapter meetings
- 2011 chapter meetings
- 2010 chapter meetings
- 2009 chapter meetings
- 2008 chapter meetings
- 2007 chapter meetings
- 2006 chapter meetings
- 2005 chapter meetings
2020 chapter meetings
23-27 November 2020: OWASP BeNeLux Days
Block your agenda for 4 online evening sessions - more info will follow soon (see https://www.owaspbenelux.eu/)!!
28 October 2020: OWASP BE Local virtual security day
This virtual security day / conference is free to join for everybody and we have an amazing line up of interesting speakers and topics. Also we have multiple workshops you can attend for free.
Agenda Talks
- 9h - 9h15: OWASP Kickoff (by Sebastien Deleersnyder & Glenn ten Cate)
- 9h15 - 10h: OWASP SAMM (by Sebastien Deleersnyder)
- 10h - 11h: Making the web secure by design (by Riccado ten Cate)
- 11h - 11h45: Zerologon - taking over an AD domain in three seconds (by Tom Tervoort)
- 11h45 - 12h45 break
- 12h45 - 13h30: Phoenix - Proactively detect and fight phishing attacks (by Davide Cioccia and Stefan Petrushevski)
- 13h30 - 14h15: Using oldschool techniques to turn software to malware (by Hidde Westerhof)
- 14h15 - 15h State of the internet (by Peter Massini)
- 15h - 15h05: OWASP Closing word
Agenda Workshops
- Workshop Malware general (by Zsombor Kovacs)
- Workshop OWASP-SKF (by Riccardo ten Cate)
- Workshop OWASP-SAMM (by Sebastien Deleersnyder)
- Workshop Malware / Red Teaming (by Tom Kallo)
6-7 June 2020: OWASP Chapters All Day (24 conference)
Leaders from OWASP Chapters throughout the world invite you to join us for 24 hours of non-stop AppSec!
This OWASP Chapters All Day conference is scheduled for June 6-7, and features among others 2 local speakers: chapter lead Seba Deleersnyder (on OPEN SAMM v2) and PhD researcher Victor Le Pochat (on the Avalanche botnet takedown).
The festivities will kick off with Welcoming Remarks and a Keynote presentation at 2pm local time (12:00 noon UTC) on Saturday, 6 June. Then, each hour, the (virtual) floor will be handed over to a leader from another OWASP Chapter, who will introduce speakers from their chapter/region. At 2pm local time (12:00 noon UTC) on Sunday, 7 June, a brief recap and closing remarks will wrap up the Chapters All Day conference.
The OWASP Belgium time slot (with Sebastian and Victor) is scheduled at 3pm local time on Saturday!!
The full schedule and details are available at https://owasp.org/www-community/social/chapters_all_day/ .
29 April 2020: OWASP - ING Open security conference (Brussels)
POSTPONED Due to the COVID-19 related restrictions, the chapter meeting will be postponed.
ING Belgium is proud to organize an open security conference in collaboration with OWASP.
Venue
The event will take place @ at ING Brussels on 29th of April 2020
- A couple of workshops will be hosted during the day
- The event will be for 300 people max
- No marketing pitches
11 March 2020 meeting (Leuven)
CANCELLED Due to the COVID-19 related cancellation of the Secure Application Development course, the chapter meeting will be cancelled as well.
Venue
Hosted by DistriNet Research Group (KU Leuven)
Both speakers are faculty of the Secure Application Development, a unique AppSec course held in Leuven from 2020-03-09 to 2020-03-13.
Agenda
- 18h00 - 18h50: Welcome & sandwiches
- 18h50 - 19h00: OWASP Update
- 19h00 - 20h00: The hitchhikers guide to secrets for cloud environments by Abhay Bhargav (CEO we45)
- 20h00 - 20h10: Break
- 20h10 - 21h10: Blueprint for secure JavaScript development by Marcin Hoppe (Senior Manager, Product Security, Auth0)
2019 chapter meetings
25 November 2019 meeting (Leuven)
Venue
Hosted by DistriNet Research Group (KU Leuven)
The event is co-located with a briefing and industry opportunity meeting of the Flanders Cyber Security impuls program. Feel free to register for this co-located event if interested.
Agenda
- 18h00 - 19h00: Welcome & networking
- 19h00 - 19h10: OWASP Update by Lieven Desmet (OWASP BE)
- 19h10 - 20h00: Recent evolutions in the OAuth 2.0 and OpenID Connect landscape by Philippe De Ryck (Founder of Pragmatic Web Security and Google Developer Expert)
- 20u00 - 20u50: Detection and Prevention of DNS abuse in .eu TLD by Lieven Desmet (DistriNet, KU Leuven)
23-27 September 2019: Global AppSec Amsterdam
Together with the OWASP staff and the OWASP Netherlands chapter, the OWASP Belgium chapter supports and contributes to the organisation of the Global AppSec Amsterdam 2019. We kindly invite all our chapter members to join us in Amsterdam in September!
Due to focusing our efforts on the Global AppSec Amsterdam conference, we decided to skip this year’s edition of the OWASP BeNeLux Days. Mark your agenda for next year: 26 and 27 November 2020 in the Netherlands.
Summit working session on OWASP SAMM
OWASP Belgium presents a summit working session on OWASP SAMM in Antwerp on 30 April.
Registration is free but mandatory (via EventBrite): https://www.eventbrite.com/e/open-security-summit-working-session-tickets-60456102831
20 February 2019 Meeting
Venue
Hosted by DistriNet Research Group (KU Leuven)
Both speakers are faculty of the Secure Application Development course held in Leuven from 2019-02-18 to 2019-02-22.
Agenda
- 18h15 - 19h00: Welcome & sandwiches
- 19h00 - 19h10: OWASP Update by Sebastien Deleersnyder (OWASP)
- 19h10 - 20h00: CSP in the age of Script Gadgets by Prof. Martin Johns (TU Braunschweig)
- 20h00 - 20h10: Break
- 20h10 - 21h00: Zero to DevSecOps - security in a DevOps world by Jimmy Mesta (CTO, Manicode Security)
2018 chapter meetings
OWASP BeNeLux Days 2018
This conference has its own page: OWASP_BeNeLux-Days_2018.
23 October 2018 Meeting (Bruges)
Hosted by Secure Code Warrior
Agenda
- 18h00 - 18h50: Welcome & pizzas
- 18h50 - 19h00: OWASP Update by Sebastien Deleersnyder (OWASP BE)
- 19h00 - 19h30: Effectively Distribute Software Security Knowledge by Pieter De Cremer and Nathan Desmet (Secure Code Warrior)
- 19h30 - 19h45: Beers from Bruges break
- 19h45 - 20h25: Common API Security Pitfalls by Philippe De Ryck (Pragmatic Web Security)
- 20h25 - 22h00: Networking and more beers from Bruges
7 September 2018 Meeting (Brussels)
Hosted by the European Commission
Agenda
- 18h00 - 18h50: Welcome & sandwiches
- 18h50 - 19h00: OWASP Update by Sebastien Deleersnyder (OWASP BE)
- 19h00 - 19h10: Intro by the EC by Miguel Soria Machado (Head of Sector CSIRC, DIGIT IT Security Directorate, European Commission)
- 19h10 - 20h00: Docker Threat Modeling and Top 10 by Dirk Wetter
- 20h00 - 20h10: Break
- 20h10 - 21h00: Securing Containers on the High Seas by Jack Mannino (nVisium)
- 21h00 - 21h30: Networking drink
19 March 2018 Meeting (Brussels)
Hosted by ING Belgium
Agenda
- 18h15 - 19h00: Welcome & sandwiches
- 19h00 - 19h10: OWASP Update by Sebastien Deleersnyder (OWASP BE)
- 19h10 - 20h00: KRACKing WPA2 in Practice Using Key Reinstallation Attacks by Mathy Vanhoef (DistriNet, KU Leuven)
- 20h00 - 20h10: Break
- 20h10 - 21h00: Making the web secure by design by Glenn Ten Cate (ING Belgium) and Riccardo Ten Cate (Xebia)
- 21h00 - 21h30: Networking drink
20 February 2018 Meeting (Leuven)
Hosted by DistriNet Research Group (KU Leuven)
Both speakers are faculty of the Secure Application Development course held in Leuven from 2018-02-19 to 2018-02-23.)
Agenda
- 18h15 - 19h00: Welcome & sandwiches
- 19h00 - 19h10: OWASP Update by Sebastien Deleersnyder (OWASP BE)
- 19h10 - 20h00: Developers are not the enemy – Usable Security for Experts by Prof. Matthew Smith (University of Bonn)
- 20h00 - 20h10: Break
- 20h10 - 21h00: The Code Behind The Vulnerability by Barry Dorrans (Microsoft)
2017 chapter meetings
19 June 2017 Meeting (Brussels)
Hosted by NVISO
Agenda
- 18h00 - 18h50: Welcome & sandwiches
- 18h50 - 19h00: OWASP Update by Sebastien Deleersnyder (OWASP BE)
- 19h00 - 19h45: OWASP Summit Debrief by Sebastien Deleersnyder (OWASP BE)
- 19h45 - 20h30: Threat modeling lessons from Star Wars (BruCON Video) by Adam Shostack (freelance security consultant)
- 20h30 - … : Reception
29 May 2017 Meeting (Machelen)
Hosted by Ernst & Young
Agenda
- 18h00 - 18h50: Welcome & sandwiches
- 18h50 - 19h00: OWASP Update by Lieven Desmet (OWASP BE)
- 19h00 - 19h45: HTTP for the Good or the Bad by Xavier Mertens (freelance security consultant)
- 19h45 - 20h30: Reverse engineering with Panopticon: a Libre Cross-Platform Disassembler by Kai Michaelis
- 20h30 - … : Reception
28 February 2017 Meeting (Leuven)
Hosted by DistriNet Research Group (KU Leuven)
Both speakers are faculty of the Secure Application Development course held in Leuven from 2017-02-27 to 2017-03-03.
Address
- 18h15 - 19h00: Welcome & sandwiches
- 19h00 - 19h10: OWASP Update by Lieven Desmet (OWASP BE)
- 19h10 - 20h00: XSS defense strategies by Jim Manico (Manicode Security)
- 20h00 - 20h10: Break
- 20h10 - 21h00: Why traditional Web security technologies no longer suffice by Philippe De Ryck (DistriNet, KU Leuven)
2016 chapter meetings
18 October 2016 Meeting (Ghent)
Hosted by UGent
Agenda
- 18h15 - 19h00: Welcome & sandwiches
- 19h00 - 19h10: OWASP Update
- 19h15 - 19h45: Find and fix software security problems… wait, do not make security mistakes in the first place! by Matias Madou (Sensei)
- 19h45 - 19h55: Break
- 19h55 - 20h30: Exploit mitigation using Multi-Variant Execution by Stijn Volckaert (University of California, Irvine)
- 20h30 - 20h40: Break
- 20h40 - 21h15: ASPIRE: Advanced Software Protection: Integration, Research, and Exploitation by Bjorn De Sutter (University of Ghent))
- 21h15 - …: drink and networking event
8 September 2016 Meeting (Zaventem)
Hosted by PwC
Agenda
- 18h15 - 19h00: Welcome & sandwiches
- 19h00 - 19h15: OWASP Update
- 19h15 - 20h00: CloudPiercer: Bypassing Cloud-based Security Providers by Thomas Vissers (DistriNet, KU Leuven)
- 20h00 - 20h15: Break
- 20h15 - 21h15: Hackers! Do we shoot or do we hug? by Edwin van Andel (Zerocopter)
23 May 2016 Meeting (Mechelen)
Hosted by is4u at Moonbeat (Mechelen)
Agenda
- 18h00 - 19h00: Welcome & sandwiches
- 19h00 - 19h10: OWASP Update
- 19h10 - 20h00: All Your Biases Belong to Us: Breaking RC4 in WPA-TKIP and TLS by Mathy Vanhoef (DistriNet, KU Leuven)
- 20h00 - 20h10: Break
- 20h10 - 21h00: Docker Security by Nils De Moor (CTO at WooRank)
- 21h00 - … : Networking drink
8 March 2016 Meeting (Leuven)
Hosted by DistriNet Research Group (KU Leuven)
Both speakers are faculty of the Secure Application Development course held in Leuven from 7-11 March 2016.
Agenda
- 18h15 - 19h00: Welcome & sandwiches
- 19h00 - 19h15: OWASP Update
- 19h15 - 20h15: Writing robust client-side code using Modern JavaScript by Tom Van Cutsem (Bell Labs, Nokia)
- 20h15 - 20h30: Break
- 20h30 - 21h30: Internet Censorship: Studies from China and Turkey by prof. Dan Wallach (Rice University)
2015 chapter meetings
24 February 2015 Meeting (Leuven)
Hosted by DistriNet Research Group (KU Leuven)
Both speakers are faculty of the Secure Application Development course held in Leuven from 23 to 27 February 2015.
Agenda
- 18h15 - 19h00: Welcome & sandwiches
- 19h00 - 19h15: OWASP Update by Sebastien Deleersnyder (OWASP Belgium Board)
- 19h15 - 20h15: Why Code Reviews and Pen-Tests Are Not Enough by Jim DelGrosso (Cigital)
- 20h15 - 20h30: Break
- 20h30 - 21h30: An analysis of exploitation behaviors on the web and the role of web hosting providers in detecting them by prof. Aurélien Francillon (EURECOM)
2014 chapter meetings
17 December 2014 Meeting (Mechelen)
Hosted by is4u at Moonbeat (Mechelen)
Agenda
- 18h00 - 18h45: Welcome & sandwiches
- 18h45 - 19h00: OWASP Update by Sebastien Deleersnyder (OWASP Belgium Board)
- 19h00 - 20h00: OWASP Top 10 Mobile Risks / demos by Erwin Geirnaert
- 20h00 - 20h15: Break
- 20h15 - 20h30: Investigating software security practices by Koen Yskout and Laurens Sion (DistriNet, KU Leuven)
- 20h30 - 21h30: OpenSAMM Best Practices: Lessons from the Trenches by Sebastien Deleersnyder and Bart De Win
20 May 2014 Meeting (Brussels)
Hosted by NVISO
Agenda
- 18h00 - 18h45: Welcome & sandwiches
- 18h45 - 19h00: OWASP Update by Bart De Win (OWASP Belgium Board)
- 19h00 - 20h00: Securing Password Storage – Increasing Resistance to Brute Force Attacks by Tiago Teles
- 20h00 - 20h15: Break
- 20h15 - 21h15: A history of ATM violence - From blowing up safes over jackpotting to all-round malware by Daan Raman and Erik Van Buggenhout (Nviso)
12 February 2014 Meeting (Leuven)
Hosted by DistriNet Research Group (KU Leuven)
Both speakers are faculty of the Secure Application Development course held in Leuven from 10 to 14 February 2014.
Agenda
- 18h00 - 18h45: Welcome & sandwiches
- 18h45 - 19h00: OWASP Update by Sebastien Deleersnyder (OWASP Belgium Board)
- 19h00 - 20h00: Smart metering privacy by George Danezis
- 20h00 - 20h15: Break
- 20h15 - 21h15: Securing Complex Forms by Jim Manico
2013 chapter meetings
17 December 2013 Meeting (Leuven)
Jointly organized with (ISC)2
Hosted by DistriNet Research Group (KU Leuven)
Agenda
- 18h00 - 18h45: Welcome drink and Pizza (sponsored by F5 Networks)
- 18h45 - 19h00: OWASP / ISC2 Update by Sebastien Deleersnyder (OWASP Belgium Board) & Lode Vanstechelman (ISC2 Belgium Board)
- 19h00 - 20h00: Augmented reality in your Web Proxy by Roberto Suggi Liverani
- 20h00 - 20h15: Break
- 20h15 - 21h15: If You Tolerate This, Your Child Processes Will Be Next by Bart Leppens
8 October 2013 Meeting (Diegem)
Hosted by Ernst & Young
Agenda
- 17h30 - 18h15: Welcome & sandwiches
- 18h15 - 18h30: OWASP Update by Sebastien Deleersnyder (OWASP Belgium Board)
- 18h30 - 19h30: NoScript for Developers by Giorgio Maone
- 19h30 - 19h45: Break
- 19h45 - 20h45: JSMVCOMFG - To sternly look at JavaScript MVC and Templating Frameworks by Mario Heiderich
6 June 2013 Meeting (Leuven)
Hosted by DistriNet Research Group (KU Leuven)
Agenda
- 17h30 - 18h15: Welcome & sandwiches
- 18h15 - 18h30: OWASP Update by Sebastien Deleersnyder (OWASP Belgium Board)
- 18h30 - 19h30: Needles in haystacks, we we are not solving the appsec problem & html hacking the browser, CSP is dead. by Eoin Keary (CTO and founder of BCC Risk Advisory Ltd.)
- 19h30 - 20h30: Teaching an Old Dog New Tricks: Securing Development with PMD by Justin Clarke (Director and Co-Founder of Gotham Digital Science)
- 20h30 - 21h30: Vulnerability Prediction in Android Applications by Aram Hovsepyan (DistriNet, KU Leuven)
Previous Meeting (5th of March 2013) in Leuven
Hosted by DistriNet Research Group (KU Leuven)
Both speakers are faculty of the Secure Application Development course held in Leuven from 4 March 2013 until 8 March 2013.
Agenda
- 18h00 - 18h30: Welcome & sandwiches
- 18h30 - 18h45: OWASP Update by Lieven Desmet (OWASP Belgium Board)
- 18h45 - 19h45: 25 Years of Vulnerabilities by Yves Younan (Senior Research Engineer at Sourcefire)
- 19h45 - 20h00: Break
- 20h00 - 21h00: Banking Security: Attacks and Defences by Steven Murdoch (Senior Researcher at University of Cambridge)
2012 chapter meetings
26 September 2012 Meeting (Ghent)
Hosted by PWC
Co-organized with the ISSA (Information Systems Security Association)
Address
- 18h00 - 18h20: Welcome
- 18h20 - 18h30: OWASP Update by David Mathy (OWASP BE)
- 18h30 - 19h30: Introducing the Smartphone Penetration Testing Framework by Georgia Weidman (Bulb Security LLC)
- 19h30 - 19h45: Break
- 19h45 - 20h45: Why your security products suck… [ZIP] by Joe McCray (StrategicSec)
- 20h45 - 21h15: Discussion: pentesting, legal aspects by Steven Wierckx (ps_testware)
- 21h15 - 21h45: Closing Drink
12 September 2012 Meeting (Leuven)
Hosted by DistriNet Research Group (KU Leuven)
Co-organized with the IWT-project SPION (security and privacy in online social networks)
Agenda
- 14h00 - 18h00: First SPION Technical Workshop
- 18h00 - 19h00: Pizza buffet with SPION demos on the side
- 19h00 - 19h15: OWASP Update by Sebastien Deleersnyder (SAIT Zenitel, OWASP Board)
- 19h15 - 20h00: You Are What You Include: Remote JavaScript Inclusions by Steven Van Acker (DistriNet, KU Leuven)
- 20h00 - 20h15: Break
- 20h15 - 21h00: Modern Information Gathering by Dave van Stein (KZA bv)
6 March 2012 Meeting (Leuven)
Hosted by DistriNet Research Group (KU Leuven)
Both speakers are faculty of the Secure Application Development course held in Leuven from 5 March 2012 until 9 March 2012.
Agenda
- 18h00 - 18h45: Welcome & Pizzas
- 18h45 - 19h00: OWASP Update by Sebastien Deleersnyder (SAIT Zenitel, OWASP Board)
- 19h00 - 20h00: Common iOS Pitfalls vs. OWASP’s iGoat by Ken van Wyk (KRvW Associates)
- 20h00 - 20h15: Break
- 20h15 - 21h15: Access Control Design Best Practices by Jim Manico (WhiteHat Security)
25 January 2012 Meeting (Brussels)
Hosted by Cisco Belgium
Agenda
- 18h00 - 18h30: Welcome & Sandwiches
- 18h30 - 18h45: OWASP Update by Sebastien Deleersnyder (SAIT Zenitel, OWASP Board)
- 18h45 - 19h45: devops, secops, devsec or *ops ? A gentle introduction to Devops by Kris Buytaert (Inuits)
- 19h45 - 20h00: Break
- 20h00 - 21h00: Hardening web applications against malware attacks by Erwin Geirnaert (ZION Security)
2011 chapter meetings
16 June 2011 Meeting (Brussels)
Hosted by Deloitte
Agenda
- 18h00 - 18h30: Welcome & Sandwiches
- 18h30 - 18h45: OWASP Update (by Sebastien Deleersnyder, SAIT Zenitel, OWASP Board)
- 18h45 - 19h45: The OWASP AppSensor Project (by Colin Watson, Watson Hall Ltd)
- 19h45 - 20h00: Break
- 20h00 - 21h00: How to become Twitter’s admin: An introduction to Modern Web Service Attacks (by Andreas Falkenberg, RUB)
23 May 2011 Meeting (Brussels)
Location: LCM, Brussels
Co-organized with the ISSA (Information Systems Security Association)
Agenda
- 18h00 - 18h30: Welcome & Sandwiches
- 18h30 - 18h45: OWASP Update (by Sebastien Deleersnyder, SAIT Zenitel, OWASP Board)
- 18h45 - 19h00: ISSA Update (by Clement Herssens)
- 19h00 - 19h45: Non-convential Attacks: Things your security scanners won’t find (by Tom Van Der Mussele, Verizon)
- 19h45 - 20h30: The Ghost of XSS Past, Present and Future – A Defensive Tale (by Jim Manico, Infrared Security)
- 20h30 - 21h00: Discussion: How CERT.be & OWASP can improve web application security in Belgium (by Christian Van Heurck, CERT.be)
2010 chapter meetings
21 September 2010 Meeting (Leuven)
Hosted by DistriNet Research Group (KU Leuven). Pizza’s sponsored by F5 Networks.
Agenda
- 18h00 - 18h30: Welcome & Pizza’s
- 18h30 - 18h45: OWASP Update (by Sebastien Deleersnyder, SAIT Zenitel, OWASP Board)
- 18h45 - 19h45: Attacking and Defending the Grid (by Justin Searle)
- 19h45 - 20h00: Break
- 20h00 - 21h00: How I Met Your Girlfriend (by Samy Kamkar)
16 June 2010 Meeting (Brussels)
Hoste by Zenitel Belgium.
Agenda
- 18h00 - 18h30: Welcome & Refreshments
- 18h30 - 18h45: OWASP Update (by Sebastien Deleersnyder, Zenitel, OWASP Board)
- 18h45 - 20h00: Advanced SQL Injection (by Joe McCray, Learn Security Online)
1 June 2010 Meeting (Brussels)
Hosted by Cisco Belgium
Agenda
- 18h00 - 18h30: Welcome & Refreshments
- 18h30 - 18h45: OWASP Update (by Sebastien Deleersnyder, Zenitel, OWASP Board)
- 19h00 - 20h00: The Belgian e-ID: hacker vs developer (by Erwin Geirnaert and Frank Cornelis)
- 20h00 - 20h15: Break
- 20h15 - 21h15: Analyzing the Accuracy Of Web Application Scanners (by Larry Suto)
1 February 2010 Meeting (Brussels)
Hosted by Ernst & Young
Co-organized with the ISSA (Information Systems Security Association)
Agenda
- 18h00 - 18h30: Welcome & Refreshments
- 18h30 - 18h45: OWASP Update (by Sebastien Deleersnyder, Zenitel, OWASP Board)
- 18h45 - 19h00: ISSA Update (by Bart Moerman, ISSA)
- 19h00 - 20h00: GreenSQL: an Open Source database firewall (by Yuli Stremovsky, VP of Research and Development at GreenSQL)
- 20h00 - 20h15: Break
- 20h15 - 21h15: MOBILE MALWARE NOW AND IN THE FUTURE (by Mikko Hypponen, Chief Research Officer at F-Secure Corp)
2009 chapter meetings
15 September 2009 Meeting (Leuven)
Hosted by DistriNet Research Group (KU Leuven). Pizza’s sponsored by F5 Networks.
Agenda
- 18h30 - 19h00: Welcome & Refreshments
- 19h00 - 19h15: OWASP Update (by Sebastien Deleersnyder, Telindus, OWASP Board)
- 19h15 - 20h00: CSRF: the nightmare becomes reality (by Lieven Desmet, DistriNet Research Group (K.U. Leuven))
- 20h00 - 21h15: Hacking Web 2.0 Streams – Cross Domain Injection and Exploits (by Shreeraj Shah, founder of Blueinfy)
4 March 2009 Meeting (Brussels)
Hosted by Telindus, Belgacom-ICT
Agenda
- 18h00 - 18h30: Welcome & Refreshments
- 18h30 - 18h45: OWASP Update (by Sebastien Deleersnyder, Telindus, OWASP Board)
- 18h45 - 20h45: A Software Security Maturity Model (by Gary McGraw, CTO of Cigital)
4 February 2009 Meeting (Brussels)
Hosted by Ernst & Young
Agenda
- 18h00 - 18h30: Welcome & Refreshments
- 18h30 - 18h40: OWASP Update (by Sebastien Deleersnyder, Telindus, OWASP Board)
- 18h40 - 19h30: Best Practices Guide Web Application Firewalls (by Alexander Meisel, CTO and founder of Art of Defence)
- 19h30 - 20h00: I thought you were my friend - Evil Markup, browser issues and other obscurities (by Mario Heiderich)
- 20h00 - 20h10: Break
- 20h10 - 21h00: Research on Belgian bank trojan attacks (by Richard Bennett, software consultant)
2008 chapter meetings
17 November 2008 Meeting (Brussels)
Hosted by Isabel, the catering was sponsored by ISSA
Co-organized with the ISSA (Information Systems Security Association)
Agenda
- 18h00 - 18h30: Welcome & Refreshments
- 18h30 - 19h00: OWASP / ISSA introduction (by Philippe Bogaerts, OWASP Belgium and Bart Moerman, ISSA Brussels-European Chapter)
- 19h00 - 20h00: Risky PDF [ZIP] (by Didier Stevens, Contraste Europe)
- 20h00 - 21h00: .NET Rootkits - Backdoors Inside Your Framework (by Erez Metula, 2BSecure)
23 October 2008 Meeting (Huizingen)
Hosted by RealDolmen
Agenda
- 18h00 - 18h30: Welcome & Refreshments
- 18h30 - 19h00: OWASP Update (by Sebastien Deleersnyder, OWASP Belgium)
- 19h00 - 20h00: Building a tool for Security consultants: A story of a customized source code scanner (by Dinis Cruz, OWASP)
- 20h00 - 21h00: Logging: not just a good idea (by Eddy Vanlerberghe)
21 April 2008 Meeting (Luxembourg, LU)
Location: Centre de Recherche Public Henri Tudor
Agenda
- 16h00 - 16h30: Welcome & Sandwiches
- 16h30 - 17h00: OWASP Introduction (by Sebastien Deleersnyder, OWASP BeLux)
- 17h00 - 18h00: How to break Web Applications (by Philippe Bogaerts, NetAppSec)
- 18h00 - 18h15: break
- 18h15 - 19h15: How to secure Web Applications (the OWASP Way) (by Sebastien Deleersnyder, Telindus)
9 April 2008 Meeting (Brussels)
Hosted by Deloitte
Agenda
- 18h00 - 18h30: Welcome & Sandwiches
- 18h30 - 18h40: OWASP Update (by Sebastien Deleersnyder, OWASP BeLux)
- 18h40 - 20h30: Exploiting Oracle databases via the Web (by Alexander Kornbrust, Red Database Security GmbH)
OWASP at infosecurity.be: 20 March 2008 (Brussels)
OWASP will be present on Infosecurity.be 2008
Agenda:
- 15h00 - 16h00: Web hacks of 2007 and how to protect your web applications in 2008 with OWASP (by Sebastien Deleersnyder, Telindus)
4 March 2008 Meeting (Leuven)
Hosted by DistriNet Research Group (KU Leuven)
Agenda
- 18h00 - 18h30: Welcome, Refreshments and drinks
- 18h30 - 18h45: OWASP Update by Sebastien Deleersnyder (OWASP BeLux)
- 18h45 - 19h00: CAcert.org and Thawte by Kenneth Van Wyck (KRvW Associates)
- 19h00 - 20h00: Development life cycle issues by Kenneth Van Wyck (KRvW Associates)
- 20h00 - 20h15: break
- 20h15 - 21h15: Structural improvements for SDLs by Bart De Win (DistriNet, KU Leuven)
2007 chapter meetings
20 November 2007 Meeting (Leuven)
Hosted by DistriNet Research Group (KU Leuven). Pizza’s and drinks sponsored by NetAppSec.
Co-organized with the ISSA (Information Systems Security Association)
Agenda
- 18h00 - 18h30: Welcome, Pizza and drinks
- 18h30 - 18h45: OWASP Update by Sebastien Deleersnyder (OWASP BeLux)
- 18h45 - 19h00: ISSA Intro by Tomas Vanhoof (ISSA)
- 19h00 - 20h00: Operational security impact on developing secure applications by Patrick Debois
- 20h00 - 20h15: break
- 20h15 - 21h15: Security awareness programs for development by Herman Stevens & Swa Frantzen (NET2S)
OWASP Day 2007: 6 September 2007 (Brussels)
On September 6th, OWASP organized OWASP Day conferences worldwide triggered by the Global Security Week idea. In Belgium we organized the mini-conference in Brussels.
Hosted by Telindus, Belgacom-ICT at the SURF House
Agenda
- 12h30: pre-event: Getting started with WebGoat & WebScarab by Erwin Geirnaert (ZION Security)
- 14h00 - 14h20: Welcome & pre-recorded video of OWASP board by Sebastien Deleersnyder (OWASP BeLux)
- 14h20 - 15h10: Key note:OWASP Evaluation and Certification Criteria Draft by Mark Curphey (OWASP Founder)
- 15h10 - 16h00: Automated Web FOO or FUD? by David Kierznowski (founder of blogsecurity.net and active member of the GNUCITIZEN group)
- 16h00 - 16h40: OWASP Pantera Unleashed by Simon Roses Femerling (Security Technologist at ACE Team Microsoft)
- 16h40 - 17h00: break
- 17h00 - 17h25: CLASP, SDL and Touchpoints Compared by Bart De Win (DistriNet, KU Leuven)
- 17h25 - 17h50: Threats of e-insecurity in Belgium and the Belgian response by Luc Beirens (FCCU)
- 17h50 - 18h40: For my next trick… hacking Web2.0 by Petko D. Petkov, a.k.a pdp (founder of the GNUCITIZEN group, co-author of the “XSS Attacks” book)
- 18h40 - 19h30: Panel Discussion: “Privacy in the 21st Century?”, moderated by André Marien (Verizon Business - Cybertrust)
- 19h30 - …: Finish - Drinks !
22 June 2007 Meeting (Diegem)
Hosted by Deloitte
F5 Networks sponsored Ivan Ristic and Dinis Cruz to come to Brussels.
Agenda
- 18h00 - 18h20: Welcome, coffee & sandwiches
- 18h20 - 18h40: OWASP Update by Sebastien Deleersnyder (OWASP BeLux)
- 18h40 - 19h00: Update on Internet Attack Statistics for Belgium in 2006 by Hillar Leoste (Zone-H)
- 19h00 – 20h00: Protecting Web Applications from Universal PDF XSS by Ivan Ristic (Chief Evangelist, Breach Security)
- 20h00 - 20h15: break
- 20h15 - 21h15: Buffer Overflows on .Net and Asp.Net by Dinis Cruz (Chief Owasp Evangelist)
10 May 2007 Meeting (Leuven)
Hosted by ps_testware
Agenda
- 18h00 - 18h20: Welcome, coffee & sandwiches
- 18h20 - 18h40: OWASP Update and OWASP BeLux Board Presentation by Sebastien Deleersnyder (OWASP BeLux)
- 18h40 - 20h00: Legal Aspects of (Web) Application Security by Jos Dumortier (ICRI, KU Leuven)
- 20h00 - 20h15: break
- 20h15 - 21h15: Formal absence of implementation bugs in web applications: a case study on indirect data sharing by Lieven Desmet (DistriNet, KU Leuven)
OWASP at infosecurity.be: 21-22 March 2007 (Brussels)
OWASP will be present on Infosecurity.be 2008
Agenda
- OWASP Top 10 2007 (by Sebastien Deleersnyder, Telindus)
23 January 2007 (Brussels)
Hosted by Ernst & Young
Agenda
- 18h00 - 18h30: Welcome, get drink & sandwiches?
- 18h20 - 18h40: OWASP Update by Sebastien Deleersnyder (OWASP BeLux)
- 18h45 – 19h45: WEBGOAT and the Pantera Web Assessment Studio Project by Philippe Bogaerts
- 19h45 - 20h00: break
- 20h00 - 21h00: Security implications of AOP for secure software by Bart De Win (KU Leuven)
2006 chapter meetings
JavaPolis 2006: 15/12/2006 (Antwerp)
Stephen de Vries (project leader of the OWASP Java Project) did a talk at JavaPolis in Belgium.
Agenda
- Security Sins and their Solutions by Spehen de Vries (project lead of the OWASP Java Project)
14 September 2006 Meeting (Antwerp)
Hosted by ING Belgium
Co-organized with the ISSA (Information Systems Security Association)
Agenda
- 18h00 - 18h30: Welcome, get drink & sandwiches
- 18h20 - 18h40: OWASP 2.0 Update by Sebastien Deleersnyder (Ascure)
- 18h45 – 19h00: ISSA Introduction by Toon Mordijck (ISSA)
- 19h00 - 19h55: Business Application Security through Information Risk Management by Serge Moreno (ING)
- 20h05 - 21h00: Secure and Reliable Web Services by Guy Crets (Apogado)
8 May 2006 Meeting (Brussels)
Hosted by Deloitte
Agenda
- 18h00 - 18h30: Welcome, get drink & snack
- 18h20 - 18h40: OWASP Update by Sebastien Deleersnyder (Ascure)
- 18h45 - 19h15: Internet Attack Statistics for Belgium in 2005 by Hillar Leoste (Zone-H)
- 19h15 - 20h30: Can “Agile” Development Produce Secure Applications? by Johan Peeters (Program Director secappdev.org)
22 February 2006 (Leuven)
Hosted by DistriNet Research Group (KU Leuven). Pizza’s and drinks sponsored by BeeWare.
Agenda
- 18h00 - 18h20: Welcome, get Pizza & Drink
- 18h20 - 18h40: OWASP (Membership) and new OWASP Projects by Sebastien Deleersnyder (Ascure)
- 18h40 - 19h30: WebScarab demonstration by Philippe Bogaerts (BeeWare)
- 19h30 - 20h00: Web Application Firewalls: WAF Primer by Sebastien Deleersnyder
- 20h00 - 20h45: Web Application Firewalls: panel
- Philippe Bogaerts, BeeWare
- Jaak Cuppens, F5 Networks
- David Van der Linden, ING Belgium
- Lieven Desmet, KU Leuven
New years drink: 19 January 2006 (Leuven)
On January 19th we had a New Years Drink. It was sponsored by Zion Security
Agenda
- OWASP Update by Sebastien Deleersnyder (Ascure)
2005 chapter meetings
28 September 2005 Meeting (Leuven)
Hosted by Ubizen
Agenda
- 18h00 - 18h15: Welcome & get a drink
- 18h15 - 18h45: OWASP & OWASP Membership by Sebastien Deleersnyder (Ascure)
- 18h45 - 19h30: Securing Web Applications with ModSecurity by Emmanuel Bergmans (I-logs)
- 19h30 - 20h00: OWASP Top 10 Vulnerabilities: Introduction to the Top 10 by Sebastien Deleersnyder (Ascure)
- 20h00 - 20h45: OWASP Top 10 Vulnerabilities: Panel Discussion
- Erwin Geirnaert, Security Innovation
- Dirk Dussart, Belgian Post
- Eric Devolder, Mastercard
- Herman Stevens, Ubizen
- Frank Piessens, KU Leuven
26 May 2005 Meeting (Ghent)
On 26th of May 2005 we held the first OWASP Belgium Chapter meeting!
It was a big success: we had nearly 40 people attending, despite the Belgium-unlike hot weather.
Agenda
- 17h30 - 18h00: Welcome & get a drink
- 18h00 - 18h45: OWASP Introduction by Sebastien Deleersnyder (Ascure)
- 19h00 - 19h45: How to Break Web Application Security by Erwin Geirnaert (Security Innovation)
- 20h00 - 20h45: How to Build Secure Web Applications by professor Frank Piessens (KU Leuven)
Local sponsors
OWASP Belgium thanks its structural chapter supporters for 2019 and the OWASP BeNeLux Days 2018
If you want to support our chapter, please contact Seba Deleersnyder.