Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Thursday, March 18, 2010

Cairo Code Camp 2010 and my Security sessions

27th and 28th of Feb DotNetWork organized one of the biggest IT conferences in the Middle East, it's Cairo Code Camp 2010. I was honored to be one of the speakers in the event. My main talks were about Application Security.
Frankly the audience I had were the best I ever saw. people were really so excited about the topic, unfortunately most of them almost knew nothing -or very little- about "Application Security" which is a little bit disappointing. but the good news is my sessions -especially the second- was crowded. This means that we do have now an increased number of "Security Aware" developers :).


Here is the sessions Slides

Application Security Fundamentals



Application Security Attacks






I would like also to share some photos for the event and my sessions

This was for the audience of the second session "Application Security Attacks"















that was my special thanks to the audience -they know what does it mean :)-















This is from the first session "Application Security Fundamentals"





Sunday, April 26, 2009

CSRF session at Microsoft innovation day (22nd April, 2009)



I was invited by the CuttingEdge Club to make a presentation about "Application Security" in Microsoft Innovation Day, I thought first that most of the attendees will be professional developers so I decided to exclude common topics in application security like "XSS, SQL Injection, Input Validation".

I decided to make it about "Cross Site Request Forgery" specifically the session title was "How do I: Protect from Cross Site Request Forgery in ASP.NET". I think it was quite interesting for the audience -specially that most of the other sessions were about SharePoint-.

I found out later that most of the attendees are students so I tried to use only simple terms -I don't think I managed to do it- as CSRF is quite complicated by nature and most developers confuse it with XSS.

Anyway I think I managed to spread the awareness of application security vulnerabilities and their huge impact -either financially or from privacy prospective- on the internet today.


Here is the presentation