Saturday, September 15, 2012

in2securITy - Secure Software Development

in2securITy is a non-profit educational group run by security folk in NZ, with the aim of helping those new to the security profession get enthusiastic and gain the skills to find a job.

Kirk spoke at the Wellington leg of the in2securITy national tour on the topic of Secure Software Development.

This was a 30 minute talk discussing the typical software development lifecycle, and different security tasks and discussions that could fit in along the way. He also advocated the role of "Security Champion" within project teams, and encouraged folks to speak up when they security issues in the making.

Download the slides here: 2012-09-08-in2securITy.pdf (5mb)

The Microsoft Security Development Lifecycle is a well regarded process used by large companies such as Microsoft and Adobe to add security into their software product lifecyle.

Friday, September 7, 2012

TechEd 2012 - Hack-Ed: Mobile Security

Andy Prow and Kirk Jackson presented at Microsoft TechEd NZ. The third talk was titled: Hack-Ed - Mobile Security
With millions of devices with more features, and more apps with more functions, and more users with more needs, and more developers with more ideas, and more tools with more power, and more hackers with more to gain... we need to make sure we get mobile app security nailed! Come along and see what security is being provided for you, and what things you need to take care of!
Download the PDF: 2012-SIA302-MobileSecurity-AndyProw-KirkJackson.pdf (20.6mb)

Thursday, September 6, 2012

TechEd 2012 - Hack-Ed: Design for Attack

Andy Prow and Kirk Jackson presented at Microsoft TechEd NZ. The second talk was titled: Hack-Ed - Design for Attack
Whether mobile, web, Windows client or server app; whether banking software or social app; whether internal corporate users only or open to all on the internet; your apps will be attacked. So, how do you design and architect the applications from the ground up to stop attacks, log and monitor attacks, and alert those who need to know? This session will ensure you're correctly considering all components so you can confidently know if you've been compromised, when, by whom, and what they did.
Download the PDF: 2012-ARC401-DesignForAttack-AndyProw-KirkJackson.pdf (18.7mb)

Wednesday, September 5, 2012

TechEd 2012 - Hack-Ed: From the Trenches

Andy Prow and Kirk Jackson presented at Microsoft TechEd NZ. The first talk was titled: Hack-Ed - From the Trenches

We all know that we need to make sure our apps are secure. We all hear about hacks in the news, whether privacy breaches, denial-of-service attacks or credit card fraud. But often those stories are a little detached from the day-to-day development that we do. This session will uncover some stories from the trenches to try and highlight the real attacks that go on in the real world, and why none of our systems are immune. It will also uncover some very real mistakes we see people making in the wild!

2012 Speakers - Day 1

Download the over-sized PDF: 2012-SIA201-FromTheTrenches-AndyProw-KirkJackson.pdf (20.5mb)

Friday, August 31, 2012

OWASP NZ - Down to the Wire

Presented by Mark Haworth and Kirk Jackson at the OWASP NZ Day 2012, on 31 August 2012.
You've built the flashiest web app your cow-orkers have ever seen. Your boss loves you, and nominates you for a promotion next financial year. You've leveraged the latest hip web framework, and have jaxed your ajax to the max. But have you done everything you can to make your application secure? Are you perhaps, in fact, doing a little _too much_? A common issue we've come across in the past few years is applications that share too much information over the wire, or trust too much of what they receive. In this talk we'll look at some common pitfalls and techniques to counter them in modern web applications. Let's go down to the wire.
PDF (5.2mb)

Sunday, November 6, 2011

Kiwicon 5 - X-Excess

Mike Haworth and Kirk Jackson presented a talk at Kiwicon 5 titled "X-Excess":
Mobile applications are the new hotness and it seems everyone wants to build one. Unfortunately you have to build new app for each platform, so frameworks are popping up to bridge that gap. We look at some abuses of one framework and the implication for your shiny new gadget. Surely we can't bug a phone using XSS? Seems also there is a little known crowd out of Washington that have been swept up in the enthusiasm of exposing JavaScript APIs so now the same issues apply to your desktop too.
Download the presentation here: x-excess_v1.1.pdf (1mb)

Sunday, August 28, 2011

Code Camp Auckland 2011 - Web Security: The latest 'n' greatest

In this talk at Code Camp Auckland, Kirk discussed the latest protections that have been added to web browsers to combat the common threats to your web applications.

He covered Content Security Policy (CSP), HTTP Strict Transport Security (HSTS) and the X-Frame-Options headers, as well as discussing how to safely host user-generated files for download.

View the slides here: CC2011-KirkJackson.pdf (6mb)

Thursday, August 25, 2011

TechEd 2011 - Hack-Ed: Boost your Defences!

Andy Prow and Kirk Jackson presented two talks at TechEd NZ 2011. The second talk was titled "Boost your Defences!":

Running a website is a risky business. Applications within organisations and on the internet are under attack all the time, by all kinds of people. How do you make your ASP.NET WebForms, MVC or SharePoint application as secure as possible? Which protection mechanisms are built in to the platform, and what are the recommended techniques for those that aren't? Come along to this talk where we will cover techniques for protecting your application from all of the common web attacks.

Further resources:

Wednesday, August 24, 2011

TechEd 2011 - Hack-Ed: The Attackers are Coming!

Andy Prow and Kirk Jackson presented two talks at TechEd NZ 2011. The first talk was titled "The Attackers are Coming!":
The internet is a fast moving business, web applications in 2011 are being attacked in new ways, using new tools and techniques. 
This talk will cover the state of the art in web security, and have some fun sharing stories of sites that have been attacked and how well they survived.

Further resources:

Tuesday, July 26, 2011

Summer of Tech - Web Security (Gum) Bootcamp

Kirk and Andy presented a Web Security (Gum) Bootcamp session at the Wellington Summer of Tech:
Get ya boots on for a true down-and-dirty hands-on web-security session with Kirk and Andy from Aura InfoSec. 
This session will cover what's out there in the wild attacking your websites, why you should care and YES there are things you can do about it. 
For starters, if you plan to ever own, develop, design, maintain, host, work-on-in-any-way or in fact even browse-to a website at some point in your life, the you must attend this web-sec bootcamp! 
 Download the slides: 2011-07-26-SummerOfTech.pdf (4mb)

Thursday, July 14, 2011

WDCNZ - Web Security: Get Ahead(er)

Kirk Jackson presented at the inaugural WDCNZ conference in Wellington.
Web Security - Get ahead (er)
This talk covered new browser support for Content Security Policy and HTTP Strict Transport Security headers, as well as miscellaneous other web security techniques to protect your applications from XSS, man-in-the-middle and other attacks.

Download the slides: KirkJackson-WDCNZ-GetAHeader-online.pdf (1.3mb)

Thursday, July 7, 2011

OWASP NZ - File Uploads

Kirk Jackson presented at the 2011 OWASP NZ Day. The talk was titled "File Uploads are EVIL!".

Allowing users to upload files to your website and later download them is complicated to get right. In this talk, Kirk tried to distill some of the knowledge and experience collected during penetration testing client applications and give advice on how to safely receive, store and return user-generated files.

Download the whitepaper: OWASP_NZDay_2011_KirkJackson_FileUploadConsiderations.pdf

Wednesday, September 1, 2010

TechEd 2010: Hack-Ed II: Stop the hacking

At Microsoft TechEd NZ 2010, Kirk and Andy presented a talk titled "Hack-Ed II: Stop the hacking".
How do you defend your website against the attacks the bad guys will throw at it? This code-focussed talk will cover some tips and tricks, out of the box features and extensions to make your web applications as strong as possible.
https://channel9.msdn.com/Events/TechEd/NewZealand/2010/SEC302

TechEd 2010: Hack-Ed: The hacking never stops

At Microsoft TechEd NZ 2010, Kirk and Andy presented a talk titled "Hack-Ed: The hacking never stops".

Don't let down your defenses - the bad guys won't! This session focuses on the cool tricks that the bad guys use to attack your website, and will help you become a better developer.

A video of the talk is available on Channel9:

https://channel9.msdn.com/Events/TechEd/NewZealand/2010/SEC301

Wednesday, September 16, 2009

TechEd 2009: Hack-Ed: Teaching the Good Guys Bad Tricks

At Microsoft TechEd NZ 2009, Kirk and Andy presented their first Hack-Ed themed talk titled "Teaching the Good Guys Bad Tricks".

A video recording of the talk is available on Channel9:

https://channel9.msdn.com/Events/TechEd/NewZealand/2009/SEC313