BEGIN:VCALENDAR
PRODID;X-RICAL-TZSOURCE=TZINFO:-//Calagator//EN
CALSCALE:GREGORIAN
X-WR-CALNAME:Calagator
METHOD:PUBLISH
VERSION:2.0
BEGIN:VTIMEZONE
TZID;X-RICAL-TZSOURCE=TZINFO:America/Los_Angeles
BEGIN:DAYLIGHT
DTSTART:20180311T020000
RDATE:20180311T020000
TZOFFSETFROM:-0800
TZOFFSETTO:-0700
TZNAME:PDT
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
CREATED;VALUE=DATE-TIME:20180301T162223Z
DTEND;TZID=America/Los_Angeles;VALUE=DATE-TIME:20180416T193000
DTSTART;TZID=America/Los_Angeles;VALUE=DATE-TIME:20180416T180000
DTSTAMP;VALUE=DATE-TIME:20180301T162223Z
LAST-MODIFIED;VALUE=DATE-TIME:20180307T003231Z
UID:http://calagator.org/events/1250473360
DESCRIPTION:Overview&#13\;\n===&#13\;\nInsecure deserialization was recen
 tly added to OWASP's list of the top 10 most critical web application se
 curity risks\, yet it is by no means a new vulnerability category. Data 
 serialization and deserialization have been used widely in applications\
 , services and frameworks\, with many programming languages supporting t
 hem natively. Deserialization got more attention recently as a potential
  vehicle to conduct several types of attacks: data tampering\, authentic
 ation bypass\, privilege escalation\, various injections and\, finally\,
  remote code execution. Two recent vulnerabilities in Apache Commons and
  Apache Struts\, both allowing remote code execution\, helped raise awar
 eness of this risk.&#13\;\n&#13\;\nWe will discuss how data serializatio
 n and deserialization are used in software\, the dangers of deserializin
 g untrusted input\, and how to avoid insecure deserialization vulnerabil
 ities.&#13\;\n&#13\;\nSpeaker&#13\;\n===&#13\;\nAlexei Kojenov is a Seni
 or Application Security Consultant with years of prior software developm
 ent experience. During his career with IBM\, he gradually moved from wri
 ting code to breaking code. Since late 2016\, Alexei has been working as
  a consultant at Aspect Security\, helping businesses identify and fix v
 ulnerabilities and design secure applications. Aspect Security was recen
 tly acquired by Ernst&amp\;Young and joined EY Advisory cybersecurity pr
 actice.&#13\;\n&#13\;\n&#13\;\n&#13\;\nThe Open Web Application Security
  Project (OWASP) is a 501c3 not-for-profit worldwide charitable organiza
 tion focused on improving the security of application software. To sign 
 up for future meeting notes and to discuss security topics with local gu
 rus\, sign up on the OWASP Portland mailing list: https://lists.owasp.or
 g/mailman/listinfo/owasp-portland&#13\;\n&#13\;\nMeetings are free and o
 pen to the public.\n\nTags: security\, owasp\, deserialization\, remote 
 code execution\, rce\, java\n\nImported from: http://calagator.org/event
 s/1250473360
URL:https://www.owasp.org/index.php/Portland
SUMMARY:OWASP Chapter Meeting: Alexei Kojenov on Deserialization Attacks
LOCATION:Cambia Health Solutions: 100 SW Market Street\, Portland OR 9720
 1 us
SEQUENCE:3
END:VEVENT
END:VCALENDAR
