== Sponsorship == We can’t do what we do alone, its takes a concerted effort and generous sponsors. If you or your company is interested in sponsoring an upcoming chapter meeting or event, please reach out to Serge Borso: serge ‘dot’ borso ‘at’ owasp.org. The OWASP foundation, as well as the Denver chapter, is a 501(c)(3) non-profit organization; your sponsorship is not only greatly appreciated but is considered a tax deductible donation.
About the chapter
The Denver OWASP chapter is comprised of Denver metro area (and beyond) professionals and is constantly evolving. In the early years, our chapter meetups consisted of 3-5 people talking about appsec in a donated meeting space. From there we have migrated to holding meetings of 15-25 people at the Hosting.com building in Denver, to 30-40 people on the Community College of Aurora campus, to maxing out capacity at the Chinook Tavern as well as Dave & Busters (on many nights). The Denver OWASP chapter is focused on our security community, and discussing advances in technology that impact us all.
Chapter Meetings are held the 3rd Wednesday of designated months, see the MeetUp.com site for regular updates and meeting information. A large part of why 100+ people regularly attend our meetings is due to our presenters (spectacular networking with intelligent individuals coupled with great food and drinks certainly helps). As such, we are always looking for talented speakers ready to share interesting information on a wide variety of topics: Please reach out to Denver OWASP President Serge Borso: serge ‘dot’ borso ‘at’ owasp.org if you are interested in presenting at one of our regular meetups.
Submit your presentation
If you are interested in presenting at a regular chapter meeting please submit the following information to serge ‘dot’ borso ‘at’ owasp.org: Presentation Title, Presentation Abstract and Speaker(s) BIO. The Information Security field is very broad and essentially any information security topic is welcome including: New and exciting research, presentations on appsec, breaches, crypto, WIFI, cloud, emerging technology/trends, etc.
Chapter Board of Directors
Here’s the team that’s putting it all together:
- Chapter President: Serge Borso
- Board Member: Aaron Cure
- Board Member: Brad Gable
- Board Member: Steve Kosten
- Board Member: Matt Shufeldt
- Board Member: Frank Vianzon
Questions can be directed to
- Serge Borso, Denver OWASP: serge ‘dot’ borso ‘at’ owasp.org
As you can tell we have been doing this for quite some time with regularity. Some of our older presentations are listed below
All meetings after July 2014 may be found on our : Denver OWASP Meetup Site
Denver January 2012 meeting January 18th, 2012| Greg Knaddison “How Does Drupal Security Stack up?”
Join the OWASP Denver Mailing List to receive meeting notifications via email
Key OWASP Resources
Chapter Management Links
2020 June: Download presentation
How to Build Awesome Security Instrumentation to Automate AppSec Testing and Protection
Modern software demands velocity, and traditional “outside in” scanning and firewalling are creating bottlenecks and slowing things down. In this talk, Jeff will approach application security from the “inside out”. We will show you how to create simple agents that get inside a running application (like a profiler or debugger) and give you access to everything you might want to know. We’ll demonstrate real agents that identify vulnerabilities without changing any code, scanning, or extra steps. We’ll identify vulnerabilities, analyze access control, and even prevent RCE attacks. Unlike scanning and firewalling, this approach establishes a safe and powerful way for development, security, and operations teams to collaborate. We’ll discuss how software security instrumentation works, how it’s being used in many organizations, and the implications for the practice of application security.
Speaker: Jeff Williams
Jeff brings more than 20 years of security leadership experience as co-founder and Chief Technology Officer of Contrast Security. He recently authored the DZone DevSecOps, IAST, and RASP refcards and speaks frequently at conferences including JavaOne (Java Rockstar), BlackHat, QCon, RSA, OWASP, Velocity, and PivotalOne. Jeff is also a founder and major contributor to OWASP, where he served as Global Chairman for 9 years, and created the OWASP Top 10, OWASP Enterprise Security API, OWASP Application Security Verification Standard, XSS Prevention Cheat Sheet, and many more popular open source projects. Jeff has a BA from Virginia, an MA from George Mason, and a JD from Georgetown. Jeff’s LinkedIn page
=================================================================================== **2020 April: Download presentation **
You got Honey in my Web App
Let’s face it, attackers seem to be holding all the advantages… but it doesn’t have to be that way… With a little bit of creativity and understanding of how attackers actually do what they do, you can mount an effective defense that will leave your attackers openly weeping wondering where it all went wrong. Turns out… it was when they mistakenly started gunning for your web apps. Attendees of this talk will learn about how each layer of a web app stack can be made into the attackers’ worst nightmare.
Speaker: Michael Douglas
Even when his job title has indicated otherwise, Mick Douglas has been doing information security work for over 10 years. He received a bachelor’s degree in communications from Ohio State University. He is the managing partner for InfoSec Innovations. He is a SANS Instructor and a member of the IANS faculty.