OWASP Pittsburgh Chapter Q2 2018 MeetUp
Details
Primary Speaker
Robert Seacord - Secure Coding in Java
Robert C. Seacord will discuss common programming errors that lead to software vulnerabilities, how these errors can be exploited, and effective mitigation strategies for preventing the introduction of these errors.
30 Minute Lightning Talk
Ryan Reid - Introducing SpyDir - a BurpSuite Extension
"The problem? Too much code, huge dynamic environments, and far too little time. The answer? Automation!
During web application assessments, testers often leverage tools like DirBuster to identify valid endpoints/pages through brute force. But what about when they have the source code sitting in front of them? Will they use it to their advantage and automate forced browsing?

