<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Paco Hope &#187; Conferences</title>
	<atom:link href="http://paco.to/category/conferences/feed" rel="self" type="application/rss+xml" />
	<link>http://paco.to</link>
	<description>My Random Musings and Rants</description>
	<lastBuildDate>Mon, 06 Feb 2012 13:11:24 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Video interview: What Is Risk Based Security Testing</title>
		<link>http://paco.to/2008/video-interview-what-is-risk-based-security-testing</link>
		<comments>http://paco.to/2008/video-interview-what-is-risk-based-security-testing#comments</comments>
		<pubDate>Thu, 12 Jun 2008 00:53:43 +0000</pubDate>
		<dc:creator>paco</dc:creator>
				<category><![CDATA[Conferences]]></category>
		<category><![CDATA[Software Testing]]></category>

		<guid isPermaLink="false">http://paco.to/?p=225</guid>
		<description><![CDATA[I gave a video interview on Risk Based Security Testing.]]></description>
			<content:encoded><![CDATA[<p>I gave a video interview on <a href="http://www.cmcrossroads.com/component/option,com_seyret/Itemid,600/task,videodirectlink/id,47/" target="_blank">Risk Based Security Testing</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://paco.to/2008/video-interview-what-is-risk-based-security-testing/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Speaking at STAR East</title>
		<link>http://paco.to/2008/speaking-at-star-east</link>
		<comments>http://paco.to/2008/speaking-at-star-east#comments</comments>
		<pubDate>Fri, 18 Apr 2008 13:51:17 +0000</pubDate>
		<dc:creator>paco</dc:creator>
				<category><![CDATA[Conferences]]></category>
		<category><![CDATA[Software Testing]]></category>

		<guid isPermaLink="false">http://paco.to/?p=218</guid>
		<description><![CDATA[I'll be speaking at STAR East in Orlando on May 6, 2008. My talk is Risk Based Security Testing, and it's a one-day tutorial.]]></description>
			<content:encoded><![CDATA[<p>I'll be speaking at <a href="http://www.sqe.com/StarEast/" title="STAR East" target="_blank">STAR East</a> in Orlando on May 6, 2008. My talk is <a href="http://www.sqe.com/STAREAST/Tutorials/Default.aspx?Day=Tuesday#TD" title="Risk Based Security Testing" target="_blank">Risk Based Security Testing</a>, and it's a one-day tutorial.</p>
]]></content:encoded>
			<wfw:commentRss>http://paco.to/2008/speaking-at-star-east/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Speaking at Software Test and Performance</title>
		<link>http://paco.to/2007/speaking-at-software-test-and-performance</link>
		<comments>http://paco.to/2007/speaking-at-software-test-and-performance#comments</comments>
		<pubDate>Wed, 29 Aug 2007 15:50:44 +0000</pubDate>
		<dc:creator>paco</dc:creator>
				<category><![CDATA[Conferences]]></category>
		<category><![CDATA[Software Testing]]></category>

		<guid isPermaLink="false">http://paco.to/?p=198</guid>
		<description><![CDATA[I'll be speaking at Software Test &#38; Performance in Boston in October 2007.Wednesday, October 3, 10:15 am - 11:15 am 103 Web Application Security By Paco Hope For security efforts to take root and bear fruit, security testing has to become a regular part of testing software. Just as we test its functionality, we must [...]]]></description>
			<content:encoded><![CDATA[<p>I'll be speaking at <a href="http://www.stpcon.com/wed_am.htm" target="_blank">Software Test &amp; Performance</a> in Boston in October 2007.<span id="more-198"></span><font color="#0000ff">Wednesday, October 3, 10:15 am - 11:15 am</font><br />
<strong>103 Web Application Security<br />
By Paco Hope<br />
</strong><br />
For security efforts to take root and bear fruit, security testing has to become a regular part of testing software. Just as we test its functionality, we must begin testing our Web software for security as a matter of course. Fortunately, Web applications submit readily to automated testing. There are many free tools that let us impersonate a browser, parse the response and report on results.</p>
<p>In this class, we’ll explore two flexible and powerful tools useful in automated Web security tests: cUrl and Perl. CUrl is a free program that helps us automate basic requests. Perl is a well-known programming language ideally suited for writing scripts that test Web applications. We’ll look at the basics of automating tests in both ways, and also explore some of the more complicated concerns that arise during automation: authentication, session state and parsing responses.</p>
<p>The techniques in this class apply regardless of whether your Web platform is Java EE, .NET or something custom. The techniques are also independent of whether your test platform is Windows, Mac OS X, Linux or Unix. You’ll leave with an understanding of the basics and a long list of resources you can turn to for learning more about Web security test automation.</p>
]]></content:encoded>
			<wfw:commentRss>http://paco.to/2007/speaking-at-software-test-and-performance/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Speaking at STAR WEST 2007</title>
		<link>http://paco.to/2007/speaking-at-star-west-2007</link>
		<comments>http://paco.to/2007/speaking-at-star-west-2007#comments</comments>
		<pubDate>Mon, 30 Jul 2007 19:24:36 +0000</pubDate>
		<dc:creator>paco</dc:creator>
				<category><![CDATA[Conferences]]></category>
		<category><![CDATA[Technical]]></category>

		<guid isPermaLink="false">http://paco.to/?p=194</guid>
		<description><![CDATA[I'll be speaking at STAR WEST 2007 doing my typical 1-day tutorial: Risk Based Security Testing. Software security testing is a key element in your quality assurance strategy for protecting your applications and critical data. Organizations need applications that not only work correctly under normal use but also continue to work acceptably in the face [...]]]></description>
			<content:encoded><![CDATA[<p>I'll be speaking at STAR WEST 2007 doing my typical 1-day tutorial: <a href="http://www.sqe.com/StarWest/Tutorials/Default.aspx#B" title="Risk Based Security Testing" target="_blank">Risk Based Security Testing</a>.</p>
<p>Software security testing is a key element in your quality assurance strategy for protecting your applications and critical data. Organizations need applications that not only work correctly under normal use but also continue to work acceptably in the face of a malicious attack. Software security testing, which extends beyond basic functional requirements, is a critical part of a secure software development lifecycle. By teaching you how to use security risk information to improve your test strategy and planning, Paco Hope helps you build confidence that attackers cannot turn security risks into security failures. The goal is to teach you to think like an attacker and add test cases for non-functional—and sometimes implied—security requirements. Explore a white-box approach that looks inside your code to help you design your tests. By employing risk-based security testing, you can achieve the most benefits with less effort and avoid downstream security problems and mitigation costs. Paco offers an eye-opening experience for all QA professionals responsible for test strategies, plans, and designs. It will change the way you think about test development.</p>
]]></content:encoded>
			<wfw:commentRss>http://paco.to/2007/speaking-at-star-west-2007/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Cubes are Alive with the Sounds of Foo Camp</title>
		<link>http://paco.to/2007/the-cubes-are-alive-with-the-sounds-of-foo-camp</link>
		<comments>http://paco.to/2007/the-cubes-are-alive-with-the-sounds-of-foo-camp#comments</comments>
		<pubDate>Sun, 24 Jun 2007 16:32:28 +0000</pubDate>
		<dc:creator>paco</dc:creator>
				<category><![CDATA[Conferences]]></category>
		<category><![CDATA[Personal]]></category>

		<guid isPermaLink="false">http://paco.to/?p=182</guid>
		<description><![CDATA[So I'm off at Foo Camp with tons of cool people. It turns out that no matter how cool, smart, or hip you might be (and everybody here is a lot of that), you probably snore. These are the sounds of the cubes in Building B, Sunday morning. There's a really curious sound about 24 [...]]]></description>
			<content:encoded><![CDATA[<p>So I'm off at <a href="http://wiki.oreillynet.com/foocamp07/">Foo Camp</a> with tons of cool people. It turns out that no matter how cool, smart, or hip you might be (and everybody here is a lot of that), you probably snore.  These are the sounds of the cubes in Building B, Sunday morning. There's a really curious sound about 24 seconds in. Must have been a good dream. 45 seconds, 600Kb. Poor quality. Good humor value.<span id="more-182"></span><br />
<ibed></ibed></p>
]]></content:encoded>
			<wfw:commentRss>http://paco.to/2007/the-cubes-are-alive-with-the-sounds-of-foo-camp/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://paco.to/wp-content/uploads/2007/06/foocamp-audio.mp3" length="617502" type="audio/mpeg" />
		</item>
		<item>
		<title>Speaking at the Better Software Conference</title>
		<link>http://paco.to/2007/speaking-at-the-better-software-conference</link>
		<comments>http://paco.to/2007/speaking-at-the-better-software-conference#comments</comments>
		<pubDate>Thu, 05 Apr 2007 01:22:13 +0000</pubDate>
		<dc:creator>paco</dc:creator>
				<category><![CDATA[Conferences]]></category>
		<category><![CDATA[Technical]]></category>

		<guid isPermaLink="false">http://paco.to/?p=167</guid>
		<description><![CDATA[I'm giving two talks at the Better Software Conference in Las Vegas in June 2007. My all day tutorial is: Software Security Fundamentals The key to proactive, effective computer system security is getting a risk management handle on the problem of security inside the software. Created by the experts who literally wrote the book on [...]]]></description>
			<content:encoded><![CDATA[<p>I'm giving two talks at the Better Software Conference in Las Vegas in June 2007.</p>
<p><span id="more-167"></span>My all day tutorial is:</p>
<h3><a href="http://www.sqe.com/BetterSoftwareConf/Tutorials/Default.aspx?Day=Tuesday#J">Software Security Fundamentals</a></h3>
<p>The key to proactive, effective computer system security is getting a risk management handle on the problem of security inside the software. Created by the experts who literally wrote the book on software security, this interactive session encompasses the software security awareness and best practices you need to achieve a secure and trustworthy environment. Everyone involved in software development requires baseline knowledge of software security problems and risks, along with an overall understanding of approaches for producing secure software. Join me as I define the software security problem and then describe a set of software security principles, touch points, and key concepts that can be integrated into any software development lifecycle. I describe how and why software is exploited and present an overview of architectural risk analysis, security testing, and advanced tools for code review. Learn why software security is everyone’s job, and take back an overview of next steps for adopting a comprehensive software security program.</p>
<p>On  Wednesday I'm doing a brief talk:</p>
<h3><a href="http://www.sqe.com/BetterSoftwareConf/Concurrent/Session.aspx?Day=Wednesday#W17">Static Analysis and Secure Code Reviews</a></h3>
<p>Security threats are becoming increasingly more dangerous to consumers and to your organization. I'll provide the latest on static analysis techniques for finding vulnerabilities and the tools you need for performing white-box secure code reviews. I'll provide guidance on selecting and using source code static analysis and navigation tools. You'll learn why secure code reviews are imperative and how to implement a secure code review process in terms of tasks, tools, and artifacts. In addition to describing the steps in the static analysis process, I'll explain methods for examining threat boundaries, error handling, and other “hot spots” in software. You'll find out about the analysis techniques of Attack Resistance Analysis, Ambiguity Analysis, and Underlying Framework Analysis as ways to expose risk and prioritize remediation of insecure code.</p>
<ul>
<li> Why secure code reviews are the right approach for finding security defects</li>
<li> How to prioritize critical software components for a deep security analysis</li>
<li> Techniques for source code analysis on high-risk components</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://paco.to/2007/speaking-at-the-better-software-conference/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>VERIFY 2007: Conference on Software Testing</title>
		<link>http://paco.to/2007/verify-2007-conference-on-software-testing</link>
		<comments>http://paco.to/2007/verify-2007-conference-on-software-testing#comments</comments>
		<pubDate>Mon, 19 Mar 2007 14:18:47 +0000</pubDate>
		<dc:creator>paco</dc:creator>
				<category><![CDATA[Conferences]]></category>
		<category><![CDATA[Technical]]></category>

		<guid isPermaLink="false">http://paco.to/?p=162</guid>
		<description><![CDATA[I'm chairing a conference on software testing called VERIFY 2007. We're soliciting talks on security testing, test automation, and quality testing.]]></description>
			<content:encoded><![CDATA[<p>I'm chairing a conference on software testing called <a href="http://verifyconference.com/" title="VERIFY 2007 Conference on Software Testing" target="_blank">VERIFY 2007.</a> We're soliciting talks on security testing, test automation, and quality testing.</p>
]]></content:encoded>
			<wfw:commentRss>http://paco.to/2007/verify-2007-conference-on-software-testing/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

