[01:13.650 --> 01:14.210] Check, check. [01:14.770 --> 01:16.870] Okay, I think we are going to get started in about a minute, folks. [01:17.070 --> 01:22.150] We are trying to stay on time with what the conference asked us to stay on time for, so just about ready to get started. [01:32.060 --> 01:44.680] The last time, somebody came up and told them to make a few announcements, to make some of these announcements, just as they were in line, and then a green line for them. [01:45.860 --> 01:47.460] This is important, I'm too sure. [01:47.560 --> 01:48.400] Did they get enough to do that? [01:49.640 --> 01:50.040] Yeah. [01:50.360 --> 01:51.120] To make them look at the end. [01:52.320 --> 01:53.980] I'm doing that was a fluff before everybody answered. [01:54.280 --> 01:55.260] Maybe it's the reality trick? [01:57.800 --> 02:01.860] So, the house asked us to make a couple of announcements, so we are going to make those. [02:02.300 --> 02:06.280] First one is, sign up for the fourth track in zoos if you want to speak. [02:07.760 --> 02:09.520] So, yeah, I don't know what that means. [02:10.180 --> 02:13.180] Next one is, please set your cell phones to vibrate. [02:14.060 --> 02:18.500] The next one is, there are lots to see and do in the pavilion. [02:23.120 --> 02:25.880] Please use restraint and don't mess with the hotel. [02:26.840 --> 02:27.320] Okay. [02:27.960 --> 02:31.020] DVD sales of all tracks are for sale in the vendor area. [02:32.560 --> 02:34.680] And, fourth track over the zoos room. [02:36.260 --> 02:38.240] Well, two and three has already passed. [02:38.360 --> 02:43.240] So, if you don't want to be here, you can go see Solar Compass for Human Domain over in the zoos room. [02:45.720 --> 02:48.660] Okay, with that great news, we're going to get started with the presentation. [02:49.220 --> 02:50.400] So, how many people here... [02:51.000 --> 02:52.320] Can you hear me okay, first? [02:52.760 --> 02:52.960] Yeah? [02:53.180 --> 02:53.280] Okay. [02:53.680 --> 02:56.160] So, how many people here are familiar with OWASP? [02:56.540 --> 02:57.360] Can I show of hands? [02:57.560 --> 02:58.100] Okay, good, good. [02:58.480 --> 03:03.640] So, the other people, I'm assuming you don't hack web applications because OWASP is a great resource. [03:04.060 --> 03:08.740] Because the mission of OWASP is really to evangelize the message of application security. [03:09.480 --> 03:15.200] And, through that message of application security, or through that message, there's a whole project surrounding it. [03:15.460 --> 03:19.660] And, with that project, there includes several different components, which we're going to go into today. [03:19.920 --> 03:30.240] But, a lot of different things that are going to help you, or as an attacker, or as a pen-tester, or as somebody just trying to test your own applications in your lab. [03:30.860 --> 03:33.720] It helps you kind of attack those different things. [03:33.840 --> 03:36.620] And, there's tools, and resources, and documents available. [03:37.060 --> 03:38.800] So, OWASP is a really great organization. [03:39.880 --> 03:44.740] For those of you that don't know, OWASP stands for the Open Web Application Security Project. [03:45.040 --> 03:47.410] And, it's a 501c3 nonprofit organization. [03:47.960 --> 03:48.740] So, we are global. [03:48.980 --> 03:51.760] We have several hundred chapters worldwide. [03:51.940 --> 03:52.560] 120 now. [03:52.660 --> 03:52.800] Okay. [03:52.920 --> 03:54.340] So, 120 chapters worldwide. [03:54.420 --> 03:55.360] So, we're all over the place. [03:55.740 --> 03:59.560] And, if you'd like to start your own chapter in your town, you can. [03:59.560 --> 04:00.660] If there's not one already. [04:01.360 --> 04:03.780] So, OWASP.org is a great resource for that information. [04:05.580 --> 04:06.800] So, that's my bio. [04:07.260 --> 04:08.140] It's not true. [04:08.340 --> 04:09.240] I stole it from LinkedIn. [04:09.480 --> 04:10.220] Somebody else's. [04:10.520 --> 04:11.800] So, I'm actually just a janitor. [04:12.120 --> 04:14.100] And, I know nothing about web application security. [04:14.280 --> 04:16.320] So, that's why I'm going to hand this over to Tom. [04:16.540 --> 04:19.000] He's going to help explain the OWASP mission. [04:19.580 --> 04:19.840] Okay. [04:20.480 --> 04:21.400] Does this work? [04:21.920 --> 04:22.580] No, you're going. [04:23.060 --> 04:23.440] Okay. [04:23.740 --> 04:24.140] Great. [04:24.320 --> 04:24.720] Thank you, Steve. [04:25.060 --> 04:25.460] Okay. [04:25.660 --> 04:36.080] So, the reason why I'm doing this talk is because, November 2007, I was nominated and asked to join the OWASP Foundation Board of Directors worldwide. [04:36.640 --> 04:40.960] And, I accepted that nomination after running the New York, New Jersey chapter since 2004. [04:41.860 --> 04:47.360] Now, I have the luxury of working with over 10,000 members, 120 sites around the world. [04:47.600 --> 04:51.640] So, if you haven't heard of OWASP, this talk is to help educate you about that. [04:51.640 --> 04:55.480] So, in summary, web application security, that's kind of the focus. [04:55.660 --> 05:01.100] Our mission is relative to the shortcomings sometimes of the software security of web applications. [05:01.400 --> 05:05.760] You can probably all agree that a web application is fairly complex. [05:05.760 --> 05:17.280] And at various different levels of a web application, there could potentially be problems with the application that could result in application compromise, which could get somebody on the news for their, you know, 15 minutes of fame on CNN. [05:18.000 --> 05:30.720] So, really, the focus here is to kind of give you a whirlwind tour of the open web application security project, have you understand a little bit more about how the organization works, some of the things that we're working on, and then that will give you, [05:30.760 --> 05:31.780] obviously, some enlightenment. [05:32.180 --> 05:34.160] We also have some other talks going on tomorrow. [05:34.540 --> 05:39.100] There's a talk happening tomorrow about man in the middle of tacky web applications that we're doing. [05:39.220 --> 05:43.700] And also, on Sunday, we're doing a full-scope application assessment review. [05:43.880 --> 05:47.700] So, if you look at more hands-on sort of stuff, you can look at the other two talks that are going on. [05:48.900 --> 05:49.260] Okay. [05:49.480 --> 05:50.120] So, here we go. [05:51.340 --> 05:51.700] Okay. [05:51.940 --> 05:55.820] So, the website, if you have your laptop out by chance, is OWASP.org. [05:55.820 --> 05:59.220] And the application security space kind of goes like this. [06:00.080 --> 06:07.340] I have a hypothetical associate that, in January of 2008, kind of knocked on his door in the morning. [06:07.620 --> 06:14.480] And the knock on the door was from his senior management, CEO, and says, you know, Joe, I was really looking at the paper this morning. [06:14.520 --> 06:17.460] I realized our largest competitor down here in Manhattan had been packed. [06:17.640 --> 06:19.160] You know, they had a SQL injection to their database. [06:20.120 --> 06:23.620] Thousands of their customer data has been leaked to the street. [06:23.620 --> 06:26.040] You know, there's potentially going to be a class action suit. [06:26.300 --> 06:28.700] We certainly have some issues and some ramifications here. [06:28.800 --> 06:31.740] What are we going to do about this as it pertains to our business? [06:31.980 --> 06:32.840] Are we secure? [06:33.140 --> 06:38.460] Do we have anything I can bring to the board and kind of show them the matrix and controls within our organization? [06:39.440 --> 06:39.840] Wow. [06:40.660 --> 06:43.280] So, Joe kind of steps back and says, you know what, Chief? [06:44.120 --> 06:45.860] You know, we do network scanning. [06:46.000 --> 06:47.100] We do patching. [06:47.960 --> 06:50.040] You know, we do stuff around application security. [06:50.040 --> 06:58.820] But there's really very limited resources in our organization today that kind of help justify and show this to the board as to what we do for the organization. [06:59.040 --> 07:02.040] I think some of you may show the same opinion of that inside your own organization. [07:02.680 --> 07:07.360] So, the incident, as explained, can result from something similar to this. [07:07.960 --> 07:12.880] In January, as some of us know, geeks.com, just kind of picked because it was kind of funny and true. [07:12.880 --> 07:16.900] A $150 million a year business, you know, their website was broken into. [07:17.120 --> 07:22.380] So, in this hypothetical example, you know, Joe's business is, you know, impacted because they're a competitor. [07:22.840 --> 07:24.340] And again, it could be any industry. [07:24.580 --> 07:30.560] And in order to provide the information back to his board and management, he's able to provide information about what to do. [07:30.860 --> 07:33.920] So, the first step is Joe doesn't really know where to go, right? [07:33.920 --> 07:39.780] So, as many of us in the application security space or management responsibility or network responsibility, where do you go? [07:39.920 --> 07:40.360] What do you do? [07:40.560 --> 07:41.860] You know, where do you find this information? [07:42.120 --> 07:47.640] So, after a few Google searches trying to find things on application security, you find various vendor pieces of information. [07:47.840 --> 07:53.920] Various things that might lead you down a path to buy a product or to buy a service or buy something that's potentially not what you're looking for. [07:54.020 --> 07:55.020] You're looking for real guidance. [07:55.440 --> 07:58.380] So, Joe comes across the OWASP top 10. [07:58.580 --> 08:00.760] Again, hopefully most of us have heard of this at this point. [08:00.900 --> 08:04.680] A lot of vendors proclaim that their product is OWASP top 10 compliant. [08:05.340 --> 08:11.300] It should be really examined when they make those sort of statements because there's actually two components of the OWASP top 10 that they probably can't be complaining with. [08:11.740 --> 08:15.640] But the point of it is that he finds the OWASP top 10 and he reads through it. [08:15.800 --> 08:21.280] It's the top 10 most critical web application vulnerabilities as of 2007. [08:21.680 --> 08:30.740] There's actually about 26, 27 different classes of problems in software that result in application compromise in most cases or application problems. [08:30.980 --> 08:35.340] But the OWASP organization has narrowed them up to just simply 10, easy to be digested. [08:35.340 --> 08:37.900] So, there's certainly more, just the top 10. [08:38.220 --> 08:42.520] He also finds that on the OWASP website, he finds information about the Honeycone Project. [08:42.760 --> 08:55.060] And the Honeycone Project is a collaboration of individuals from around the world that collaborate on threats, attacks, vulnerabilities, and processes of business impact and putting metrics together to determine how this would impact your organization. [08:55.240 --> 09:01.700] Again, a guide, information that can be used within an organization that potentially didn't exist before Joe found this resource instead of reading through it. [09:02.160 --> 09:03.720] He also finds the Tools Project. [09:04.440 --> 09:05.920] OWASP is not a laboratory. [09:06.120 --> 09:12.120] OWASP is not an organization that does consumer reports on particular tools. [09:12.280 --> 09:23.120] However, there's a lot of good information there relative to the Tools Project that talks about some of the commercial products in the space and what the commercial products can do and what they can't do. [09:23.460 --> 09:40.960] There have been numerous reviews by people like Larry Suda, Dennis Cruz, Jeff Williams, and others that have gone through the exhaustive process of taking or building an application with known flaws or vulnerabilities, taking products and testing against static source code analysis or genetic testing to determine what do these tools really find. [09:41.180 --> 09:54.880] So, within your own organization, if you're looking for information about what's out there and how it can be applied or maybe what you might want to look at, the Tools Project may actually help you in making a decision process better because none of us have enough time or a big enough lab to test stuff out, [09:54.880 --> 09:55.060] right? [09:55.740 --> 09:57.620] So, we don't want the sales guy telling us that they're the best. [09:59.220 --> 10:02.920] So, as Joe goes down this process, you know, he finds a resource. [10:03.320 --> 10:12.420] He determines if the information is reputable because he's also referencing other organizations' information and statements about OWASP, right? [10:12.420 --> 10:20.820] As many as you may find out or may know, there's lots of individuals involved in OWASP that come from a kind of an open-source background that really have, you know, they do this for fun. [10:20.960 --> 10:23.280] You know, this is something that we do as a passion, not because it's their job, right? [10:23.280 --> 10:24.320] I'm not paid for OWASP. [10:24.440 --> 10:25.260] I'm a volunteer. [10:25.520 --> 10:28.880] But I happen to be involved in the organization for a bunch of years as well as HIPAA. [10:29.620 --> 10:42.660] So, the NSA, FFIC, FTC, NIST, et cetera, have all stated in their documentation how the OWASP organization, how the top ten, how the static reviews, how the components of the OWASP organization are very important to the software process. [10:43.120 --> 10:49.180] And this simply quantifies the situation relative to the organization's structure and its integrity, I believe. [10:50.040 --> 10:54.740] So, what Joe does with the resources he's found is he's subject to conduct an analysis. [10:55.060 --> 11:02.780] His analysis, in order to provide information to the board of directors or to the people that he reports to, is to go ahead and figure out, where do I start with application security? [11:02.980 --> 11:03.680] Where do I start? [11:03.980 --> 11:05.580] My largest competitor was hacked. [11:05.580 --> 11:07.940] My manager wants to know where we're at. [11:08.080 --> 11:09.300] You know, how are we dealing with this stuff? [11:09.440 --> 11:11.360] And how do I provide this information to him? [11:11.580 --> 11:13.840] And the first place, it starts with some of the free tools. [11:14.080 --> 11:17.460] Free tools that OWASP will have created in the open source space. [11:17.600 --> 11:20.420] And I put together for you as a resource in your organization. [11:21.060 --> 11:24.140] So, one of the tools is a proxy called WebScout. [11:24.320 --> 11:26.940] And many of us have probably either seen it already or used it. [11:27.120 --> 11:38.060] But if you look at things like other products like Burp or other products in that space, Achilles, et cetera, these are just simply tools that are proxying application requests from the client to the server. [11:38.220 --> 11:45.760] So that you can manipulate the application request on the fly and potentially cause the application to puke or give you information back that it wasn't intended for, right? [11:46.080 --> 11:49.380] So OWASP has a proxy that's out there and freely available. [11:49.760 --> 12:01.840] The CAL 9000 project or application, if you will, this is another set or series of tools that is an open source collaboration of processes and procedures to conduct an assessment on applications. [12:01.840 --> 12:04.740] Again, I doubt it should be something that should be reviewed. [12:05.100 --> 12:11.660] Because Joe, of course, is trying to look for resources to do this in-house with his in-house staff as well as his third-party trusted resources, right? [12:12.300 --> 12:14.640] The OWASP directory buster is what it sounds. [12:14.820 --> 12:20.420] It's kind of like a, I think I call it kind of like a NIC2-ish kind of a tool where it's looking for pretty much unknown directories, right? [12:20.460 --> 12:21.360] That's its main focus. [12:21.600 --> 12:28.200] Because obviously if you're crawling a tree or you're crawling a site, if there's directories on that tree that aren't linked off the main site, then in many cases it's not being found. [12:28.200 --> 12:34.920] So the directory buster is a combination of things like, not a combination of things like Brutus, but it's also got its own brute force type of tool. [12:35.160 --> 12:40.420] It also has its own list of common directories that can be fuzzed to find previously unknown directors, et cetera. [12:41.500 --> 12:49.020] The lightweight application protocol project is another tool that's used in order to go ahead and to rate vulnerabilities. [12:49.360 --> 12:52.440] Again, good resources and information that's available to you today. [12:53.380 --> 13:01.500] Pantera, again, another application that's been written open source for you to use in the combination of trying to determine risk within your organization. [13:02.340 --> 13:07.000] My point here is that there's tons and tons and tons of resources that have been outlined for you. [13:07.200 --> 13:11.560] You have Ajax running in your environment and you're trying to figure out how to test it, how to fuzz it, how to work with it. [13:11.900 --> 13:15.540] Sprayjack project was a project built around being able to test this. [13:15.540 --> 13:30.000] I think what Hitman alluded to earlier was, in fact, that the OWASP application security resources are great for organizations, great for pen-testers, and certainly great for anybody who wants to play with application security. [13:31.000 --> 13:37.640] There's tons of tools like Sequelix, which is kind of a brute forcer for SQL, right? [13:37.760 --> 13:41.440] So nobody ever wants to put 1433 public-facing to the Internet, right? [13:41.740 --> 13:44.040] You don't want to have it brute force until you break into your database. [13:44.040 --> 13:45.620] Well, here's a tool that will do it for you. [13:45.820 --> 13:56.880] So if you're looking for resources and tools to do something, OWASP probably has them created on your behalf, as well as we encourage you to work with building new tools for the same purpose. [13:58.020 --> 13:58.180] Excuse me. [13:59.580 --> 14:01.640] WMS fuzzer, again, another fuzzer. [14:02.000 --> 14:10.040] And the JBRO fuzz is a Java fuzz protocol analyzer that fuzzes the Java side, OWASP interceptor. [14:10.260 --> 14:13.440] There's a few great products out there that are all tool-based. [14:14.780 --> 14:19.620] There's several new tools or products that have come online recently that should be noted. [14:20.360 --> 14:24.680] The first one, I'm going to let Steve dive into a little bit more, is the ASAPI project. [14:25.760 --> 14:41.620] This project, the Enterprise Security API project, is really good because a lot of organizations or developers within organizations or people just developing on their own oftentimes have to do common things when they're handling web applications. [14:41.800 --> 14:43.340] They have to do things like authentication. [14:43.640 --> 14:45.640] They have to do things like authorization. [14:46.300 --> 14:47.600] They have to do input validation. [14:47.620 --> 14:49.060] All those things are very important. [14:49.140 --> 14:50.280] You have to do them in all your apps. [14:50.280 --> 15:06.940] So as a developer, the ASAPI project is great because it kind of puts together all of these different things in a central repository so you can grab these APIs from OWASP and integrate them into your application so that you don't have to rewrite these things that OWASP has done for you. [15:07.060 --> 15:11.200] Things like authentication, authorization, again, input validation. [15:11.200 --> 15:14.940] So you can avoid things, common vulnerabilities that exist within applications. [15:15.320 --> 15:16.240] They're very helpful. [15:17.420 --> 15:29.840] SiteGenerator is another, is a tool, maybe applies a little bit more to the kind of corporate community, but SiteGenerator essentially builds a bunch of sites that you can test an application scanner on. [15:30.060 --> 15:32.480] So there's application scanning utilities out there. [15:32.540 --> 15:37.220] There's some free ones, but there's some commercial ones like WebInspect or AppScan. [15:37.680 --> 15:40.900] These things, in order to test them, you need a website to test them on. [15:40.900 --> 15:45.180] So this generates a bad or vulnerable website so you can test tools on. [15:45.660 --> 15:48.840] And I'll let you speak on the last topic. [15:51.000 --> 15:55.280] Another OWASP product which has just come out is the OWASP GUI W3AF. [15:55.520 --> 15:57.120] Show of hands, there's a few AppSec folks in here. [15:57.180 --> 15:58.620] Is anybody using W3AF today? [16:00.000 --> 16:01.520] Yeah, so we are. [16:01.680 --> 16:09.680] So W3AF is an application, an open source free application security tool that I like to kind of describe, kind of like Metasploiting. [16:10.420 --> 16:16.200] If you're familiar with Metasploit on the network side, W3AF is kind of a similar process for web apps, right? [16:16.340 --> 16:16.960] Click, click, own. [16:17.220 --> 16:19.860] So it's kind of a process that you might want to take a look at. [16:20.000 --> 16:20.680] Just Google W3AF. [16:21.640 --> 16:28.100] And because of OWASP's grant and funding, we've also just put a beautiful GUI on it, which allows you to kind of use the tool in a very interesting way. [16:28.100 --> 16:39.080] So again, what we're checking out, and the purpose again, you know, as in this scenario here, is Joe is finding information and resources that he's able to apply to his existing environment. [16:39.240 --> 16:43.640] And quite frankly, as many of you here, had no knowledge that OWASP actually existed. [16:43.820 --> 16:49.220] So again, the purpose of the talk is kind of educate you a little bit as to some of the things that we're doing and why we're doing it, and I'll get to some of that as well. [16:49.720 --> 17:02.420] The OWASP Tire project, if anyone here is in a hosted environment or runs an ISP or is in that space, there's a lot of tools that were built that were to test the ISP component in a hosted environment, right, from a security floor perspective. [17:02.680 --> 17:03.900] So what we're worth looking at. [17:04.620 --> 17:07.560] Anti-SAMI project, everybody probably is familiar with SAMI from MySpace. [17:08.440 --> 17:19.600] So this is actually a process, and this is actually a tool, if you will, that can ensure that that won't happen in those sort of environments again. [17:20.820 --> 17:28.900] Again, the OWASP code crawler project is a .NET code crawler which allows us to look for a static review in code. [17:30.280 --> 17:34.400] SQL bench projects, scavenger projects, there's a lot of other tools and products that OWASP finds. [17:34.940 --> 17:47.340] So what Joe does is he collects this information, he starts to go through it, with his third-party resources, with his in-house resources, with the tools that he finds, with information that he reads about, he puts in a kind of a plan, right? [17:47.580 --> 17:49.500] And the plan is probably pretty straightforward. [17:49.800 --> 17:52.260] Looking across the organization, how many web apps do we have? [17:52.420 --> 17:53.480] We have like 250, right? [17:53.700 --> 17:55.220] How many departments do we have, or divisions? [17:55.380 --> 17:55.880] We have several. [17:56.300 --> 18:08.980] It takes the top 3% of those organization applications across the environment, so it's putting them through a rigorous process to determine what his risk level is, apply some of the matrix to that risk level to determine for the reporter, for the information to the senior manager, [18:09.160 --> 18:09.960] where are we at? [18:09.960 --> 18:11.000] How vulnerable are we? [18:11.160 --> 18:16.340] Let's classify our external public-facing applications, let's look at our internal applications, our business partner applications, etc. [18:16.680 --> 18:20.520] Where are the critical systems to the organization that are really, really important? [18:20.700 --> 18:25.600] Let's make sure that those have been reviewed or assessed internally, so we can get a little healthy. [18:26.280 --> 18:27.580] Kind of going back to what I just said. [18:28.140 --> 18:29.580] OWASP has testing guides. [18:29.920 --> 18:34.680] Actually, in January, we released the OWASP version 2.0 testing guide I helped co-author. [18:34.680 --> 18:39.520] And this is basically a listing of how to test application security in various different components. [18:39.740 --> 18:42.520] So, you know, kind of I think a very interesting read. [18:42.800 --> 18:55.240] I want to talk about that really quick because the OWASP testing guide is very similar to other organizations have kind of developed these guides for pen-testing or attacking web applications or regular network environments. [18:55.400 --> 18:58.440] And the OWASP one is really good because it's focused on web applications. [18:58.440 --> 19:08.500] So, just going through that guide is very helpful because you learn a lot about methods, tools you can use, and things to look for within a web application that can lead to vulnerabilities. [19:09.360 --> 19:12.460] It's very important if you're kind of learning about web applications. [19:12.620 --> 19:24.420] And even if you're not learning about how to attack them and you feel like you're strong as far as your knowledge goes, take a look at that guide because it's very helpful and it kind of adds a process to the way that you're attacking the applications. [19:24.420 --> 19:30.840] It's very important to do those things because some people spend a lot of time kind of looking for one deep-rooted issue. [19:30.980 --> 19:39.900] But if you kind of can go over the entire application, you can end up finding a lot more things than you would find if you're just kind of going and hacking at something without a method. [19:40.280 --> 19:41.920] OWASP testing guide really helps with that. [19:42.080 --> 19:47.120] And, of course, you're doing this all in your lab or in your, you know, testing environment, not on anybody else's stuff. [19:48.800 --> 19:49.200] Absolutely. [19:49.860 --> 19:50.580] Good show answer. [19:50.720 --> 19:51.560] Do you want to use Backtrack? [19:51.700 --> 19:52.240] Backtrack CD? [19:52.560 --> 19:53.000] Alright, cool. [19:53.000 --> 19:54.220] So OWASP has one too. [19:54.540 --> 19:59.840] We have a kind of a bootable CD that has simply application security tools. [20:00.100 --> 20:01.280] So Backtrack's awesome. [20:01.840 --> 20:05.800] Our CD is really focused on the OWASP tool set and putting everything in one place. [20:06.040 --> 20:17.480] So it's something good or I should say in addition to the Backtrack CD that you may want to use just to keep handy for some of your application security focus items that Backtrack may not have or doesn't have some stuff on. [20:17.560 --> 20:20.620] But they're also using a lot of the OWASP stuff now as well. [20:20.620 --> 20:22.440] OWASP education project. [20:22.980 --> 20:28.140] What people don't understand is that as a 513C nonprofit, we have about $800,000 in the bank. [20:28.340 --> 20:34.720] We give away a lot of money every year to grants and people, individual researchers like you, every quarter. [20:34.720 --> 20:39.520] We actually just gave away $150,000 broken into various education projects and grants. [20:39.680 --> 20:53.320] And what that allows us to do is to have people submit a proposal like, Hi, I want to work on a report generator project that's going to help solidify and put into a process a way to write reports when you're doing application security testing. [20:53.820 --> 20:55.540] OWASP says, hmm, that sounds like a really good idea. [20:55.800 --> 21:00.520] And after it goes through a board review, we issue, you know, five or six, ten grand for that work. [21:00.620 --> 21:03.580] And that person has a process that they have to meet a certain deadline. [21:03.800 --> 21:05.290] They have to have a process reviewer. [21:05.710 --> 21:07.990] And then, of course, when that's completed, they get the money. [21:08.410 --> 21:10.110] They get 50 up front and 50 when they're done. [21:10.310 --> 21:13.210] And then, of course, OWASP gets a new tool that's given away for free. [21:13.370 --> 21:15.270] So it's a very interesting process. [21:15.590 --> 21:18.110] But there's lots of grants on its assessment there. [21:18.870 --> 21:22.730] What Steve mentioned before is, you know, really an issue, right? [21:22.830 --> 21:25.210] So how do you learn about web application security? [21:25.290 --> 21:27.450] There's 14-plus million websites out there. [21:27.630 --> 21:33.450] And although many of us, you know, go to many of them, not all of them, but many of them, and we probably play with parameters. [21:33.690 --> 21:37.630] We probably, you know, do different things just to see what the application or what the website does. [21:38.090 --> 21:49.530] We all know that the way that the world is, you know, putting a traversal in or changing some information in a parameter, might actually get a phone call or knock on the door from law enforcement these days, especially for certain sites. [21:49.730 --> 21:56.110] So OWASP and many other organizations as well have contributed to a project called the OWASP WebGoat. [21:56.110 --> 22:05.290] And what WebGoat is, it's a bug-riddled application that has classes of problems in unknown or in this class-learning environment. [22:05.470 --> 22:11.250] You can literally download the WebGoat application, run it in an environment on your own laptop or such a... [22:11.250 --> 22:15.430] and test through it, and go through about 20 different lessons now. [22:15.570 --> 22:17.570] And we're kind of adding lessons as we go along. [22:17.750 --> 22:21.670] So you can actually test an application, have no fear, no one's going to knock on your door. [22:22.130 --> 22:27.350] At the same time, when you go through these processes, it helps you learn about education on Web App Security. [22:27.450 --> 22:29.490] But why is that really important in Joe's perspective? [22:29.950 --> 22:36.390] Because Joe's putting together some of this material, and he actually might have his developers as part of their education program utilize this tool. [22:36.450 --> 22:41.270] He might bring in, you know, some resources to help train up on this particular process and how this works. [22:41.450 --> 22:49.250] And of course, if developers see the common flaws that they're trying to protect against, they might become more aware of the security components of the application that they're building, right? [22:52.710 --> 22:53.590] Okay, improvement. [22:54.150 --> 22:55.330] So Joe improves the environment. [22:55.930 --> 22:57.110] He has a building guide. [22:57.270 --> 22:58.270] He gets it out to his developers. [22:58.450 --> 23:01.790] It's kind of a nice little book that talks about flaws, common issues, how to avoid them. [23:02.230 --> 23:05.190] Also speaks as to why things are the way they are. [23:05.630 --> 23:07.430] The OWASP encoding product is unique. [23:07.670 --> 23:12.150] We're seeing... I'm seeing more and more double encoding sort of injections that people should be aware of. [23:12.230 --> 23:15.710] So the encoding product simply is a way to quickly test for that. [23:15.710 --> 23:17.630] A OWASP stinger project. [23:18.870 --> 23:31.790] CLASP, which is a lightweight program designed to have you understand, in a big environment or in any environment, what the different roles and responsibilities are within an organization in the AppSec space for development. [23:31.930 --> 23:39.290] And that's really important because many people I've spoken with that come from a network background, the application guys are always over there, right? [23:39.390 --> 23:43.770] You might get the phone call first because the server went down, but it's really the application guy problem, right? [23:44.110 --> 23:51.790] So CLASP was actually a really good document which helps kind of outline, in a perfect world, who's responsible for what and how things probably should work. [23:51.890 --> 23:53.810] And it's modeled for a lot of other environments. [23:54.130 --> 23:56.230] It's also been adopted by a lot of environments. [23:56.290 --> 24:02.070] A lot of them here in the city in the financial space have actually used CLASP to help model their production, development environments against. [24:02.070 --> 24:04.370] So it's well worth taking a look at. [24:05.330 --> 24:07.270] We have a moderated AppSec news feed. [24:07.790 --> 24:13.650] Why this is important is because there's about 250 very active OWASP members that blog up quite a bit. [24:14.730 --> 24:18.010] PDP, Jeremiah, I mean, there's a lot of folks out there that you may know by name. [24:18.410 --> 24:30.350] But what we do is we basically consolidate this to an RSS feed, allowing you to grab it and stick it into a portal or stick it onto your site or somewhere so you can, again, educate the folks that are responsible for security as to what's going on in the latest, [24:30.490 --> 24:32.350] greatest stuff out there in application security. [24:33.210 --> 24:35.050] OWASP conferences, near and dear to my heart. [24:35.970 --> 24:39.430] We have OWASP conferences around the world in various regions. [24:39.790 --> 24:43.730] As I said, we have 120 sites around the world, over 10,000 members. [24:43.910 --> 24:46.390] And the cool part there is that we have regional conferences. [24:46.650 --> 24:52.130] The next one coming up here in New York City is September 24th and 25th, about five miles south of here. [24:52.230 --> 24:54.250] I'll cover it a little bit deeper shortly. [24:54.930 --> 24:58.170] Our OWASP chapters, again, are all over the world. [24:58.170 --> 24:59.310] You can go to the website. [24:59.550 --> 25:00.630] You can find the local chapter. [25:00.810 --> 25:04.170] You can see what latest, greatest topics are being talked about at that particular meeting. [25:04.790 --> 25:10.350] My first chapter meeting, which started back in 2004, was a box of pizza and some beer. [25:10.470 --> 25:12.530] We talked about sequel injection for about three hours. [25:13.050 --> 25:15.270] The second meeting, it was about another 30 people there. [25:15.510 --> 25:16.830] The fourth meeting, it was about 50 people. [25:16.930 --> 25:18.190] I mean, so it grows very rapidly. [25:18.450 --> 25:22.830] As of right now, the New York, New Jersey chapter is 1,200 individuals on the list. [25:22.870 --> 25:23.770] So that's pretty good. [25:24.150 --> 25:30.390] Our average turnout for meetings is about 150 to 200 people, depending on the venue and if they can hold a big space. [25:30.610 --> 25:33.730] So we have a lot of very interested folks, obviously, in this space. [25:33.950 --> 25:37.910] So if you're from New York or the regional area, please take a look at what we've got going on. [25:38.870 --> 25:40.910] OWASP grants, I told you earlier, we give away a lot of money. [25:41.350 --> 25:45.670] Why we do it is because OWASP is built on the foundation of a nonprofit. [25:45.890 --> 25:49.090] It's built on the foundation of helping the open source environment. [25:49.090 --> 25:52.590] And quite frankly, even at a hacker quote unquote conference, we're here for what? [25:52.730 --> 25:55.190] We're here for learn, educate, and share with peers, right? [25:55.410 --> 26:07.270] So if you're working together with the people in the room, you're collaborating with them anyway, and you're writing some code that's either to be used for good or evil, the point of it is that the contribution you can make can certainly help somebody, [26:07.530 --> 26:07.770] right? [26:07.770 --> 26:11.750] So the more people that actually contribute to OWASP, the better it is for everyone involved. [26:14.290 --> 26:15.190] Okay, which I just covered. [26:15.330 --> 26:20.310] So we give away $150,000 in the spring, excuse me, in the summer of code. [26:20.530 --> 26:22.310] The next one will be obviously the fall of code. [26:22.550 --> 26:27.810] So again, if you take a look at OWASP, people who are a little more familiar with it, you can simply submit a proposal. [26:28.050 --> 26:32.070] And sometimes we put out there a list of things that we would like for someone to work on or for someone to develop. [26:32.230 --> 26:37.430] So if you're looking for some work, then it's certainly worth getting involved in. [26:37.430 --> 26:40.570] So the call to action here is during the mission, right? [26:41.130 --> 26:45.630] So OWASP is an organization, again, has a lot of great information that's out there. [26:45.790 --> 26:46.210] It's free. [26:46.370 --> 26:47.210] It's available to you. [26:47.670 --> 26:54.290] And again, I hope, you know, this talk educates you a little bit more about OWASP that you hopefully knew about, but you may know more about now. [26:54.970 --> 27:05.470] OWASP by the numbers is quite interesting, I think, because as an organization that some people don't know about, 420,000 page views per month, 15 plus thousand downloads of our tools. [27:05.990 --> 27:07.910] 10,000 plus members are on our list. [27:08.170 --> 27:11.930] It's a fairly large organization from a virtual standpoint. [27:12.330 --> 27:16.770] We have five board members that help lead the charge here, myself being one of them. [27:16.890 --> 27:19.970] Jeff Williams, Dave White, Sebastian, and Dennis Cruz. [27:20.250 --> 27:24.950] We actually have three employees now that help do some back office administration and coordination. [27:25.490 --> 27:26.730] That's Kate and Allison. [27:27.290 --> 27:28.870] And Paulo is our project manager. [27:28.870 --> 27:35.150] He's our focal person for working with the community on projects that are actually being developed and worked on. [27:36.530 --> 27:44.670] To come back to the conference, the September 22nd through the 25th, there's a conference going to happen in Pace University downtown. [27:45.150 --> 27:46.970] Be about a thousand people in attendance. [27:46.970 --> 27:49.490] That's the max capacity we have at that facility. [27:49.690 --> 27:51.010] It's focused on AppSec. [27:51.230 --> 28:02.870] So if you're here today to look at some of the talks that are relative to men in the middle of tax, or how to break web applications, how to break crypto, the things that are out there that are in that space, you really want to take a look at this conference. [28:03.010 --> 28:04.910] This conference is going to be hard per AppSec. [28:05.490 --> 28:09.670] So there's going to be mostly tracks there that are for the developer, for the security folk. [28:10.470 --> 28:12.270] Management, if they want to come and listen, that's great. [28:12.550 --> 28:15.490] But certainly this is a technical conference that's going to be going on out there. [28:16.010 --> 28:19.130] If you're looking for training, there's a lot of training classes that are being involved there. [28:19.130 --> 28:20.850] FoundStone is putting in some time. [28:21.370 --> 28:22.430] Sigil is putting in some time. [28:22.590 --> 28:24.090] Aspect Security is putting in some time. [28:24.490 --> 28:27.170] So again, lots of good stuff relative to the conference. [28:28.170 --> 28:30.850] We also are having a web application capture the flag. [28:31.310 --> 28:35.230] So for anyone here that is going to play CTF downstairs, this is going to be a web app. [28:35.790 --> 28:37.790] And my question is, is Dan in the room? [28:38.010 --> 28:38.670] Yeah, I just got it. [28:41.910 --> 28:45.930] So Dan, if you want to just give a quick overview about the CTF project and what you are doing there. [28:48.250 --> 28:52.030] Hey, I kind of missed the beginning of this talk, so I don't know what Tom covered already. [28:52.270 --> 28:57.770] But I'm Dan Guido, and I made the CTF with my lab over at Isis Lab in Polytechnic University. [28:58.190 --> 29:00.230] Now it's NYU Poly, I guess. [29:01.670 --> 29:06.650] The challenges are, they all demonstrate common web application security flaws. [29:06.870 --> 29:08.070] Some of them are very hard. [29:08.290 --> 29:09.490] Some of them are very easy. [29:09.790 --> 29:15.850] I made them for the wide range of people who are likely to show up at Tom's conference in September. [29:17.050 --> 29:21.250] There's about 30 of them, and I wrote them in PHP, Perl, Python, Ruby. [29:21.930 --> 29:23.510] You know, everything I could get my hands on. [29:23.730 --> 29:27.770] I might even force myself to write one in Java if I have to... [29:28.470 --> 29:30.290] You know, he wants me to. [29:32.110 --> 29:37.150] If you're a professional, and you're going to be at this conference, you really should play. [29:37.150 --> 29:38.290] I think it's going to be really fun. [29:38.850 --> 29:40.850] I tried to give it a little bit of a story. [29:41.630 --> 29:45.070] And if you're a student, we have a treat for you. [29:45.130 --> 29:50.990] Because I'm putting on a similar Capture the Flag a few weeks later where you can win money. [29:52.910 --> 29:56.650] So, I have a stand downstairs, and there's that big flyer. [29:56.710 --> 29:58.810] Look for me down there, and you can ask me all the questions you want. [29:59.730 --> 30:02.090] So, hope to see you guys down there, and I'll give it back to Tom. [30:02.390 --> 30:02.510] Excellent. [30:03.150 --> 30:03.510] Thanks, Dan. [30:04.210 --> 30:09.310] So, OWASP actually will also have a Capture the Flag purse, if you will, for the treasure chest. [30:09.570 --> 30:12.770] Some more information to come on that, and that will be up on the website. [30:13.730 --> 30:17.790] Flipping through the program there, I did notice a couple of AppSec components. [30:17.970 --> 30:23.270] So, if you're here for AppSec stuff, I definitely want to point out that you definitely need to take a look at what Dino is doing. [30:23.530 --> 30:26.230] In reference to Crippling Crypto, I'm sure his talk will be very interesting. [30:26.550 --> 30:28.010] And also pen-testing with Firefox. [30:28.290 --> 30:31.630] There's a bunch of other talks that are in the space there, but these two pretty much, for me, stand out. [30:32.210 --> 30:37.650] As I mentioned, on Saturday, we're talking with Blake on cross-site scripting vector man-in-the-middle attacks. [30:37.870 --> 30:40.630] So, if you're looking for more technical how-to type stuff, that'll be a good talk. [30:41.090 --> 30:44.830] And also, Sunday will be another talk about a full scope component. [30:46.330 --> 30:50.630] One last thing I wanted to mention is, you know, a lot of people have come to me because... [30:51.230 --> 30:54.010] Not because I know anything about application security, but I know people that do. [30:54.250 --> 30:57.230] And they've come to me and said, you know, how do I start? [30:57.230 --> 30:58.230] I'm a network guy. [30:58.230 --> 31:05.550] I know a lot about running NMaps and I know a lot about, you know, maybe writing code to exploit buffer overflows or things like that. [31:05.870 --> 31:06.870] You know, how do I get started? [31:06.990 --> 31:08.310] And this is really a great starting point. [31:09.090 --> 31:12.730] Even if you don't, you know, even if you don't write code, you can still break web applications. [31:13.050 --> 31:19.630] I'm not saying that you can pen-test them, but I'm saying, you know, you can still break them and figure out how to get involved and learn about them. [31:19.630 --> 31:21.430] Especially with the WebGoat. [31:21.770 --> 31:28.450] WebGoat, again, it's like a war game almost, except it's just one application that stands alone that you run and nobody else runs. [31:28.910 --> 31:30.830] And it has web application vulnerabilities. [31:31.390 --> 31:37.630] You can go in, you can use the OWASP testing guide to guide you through how to attack WebGoat. [31:37.750 --> 31:43.550] So those things will, you know, and as well as the tools, you know, all the tools that are there that you need to break the application. [31:43.550 --> 31:44.710] So it's very good. [31:44.810 --> 31:45.490] It teaches you. [31:45.610 --> 31:46.910] And it's a really good way to get started. [31:46.990 --> 31:48.290] So I definitely recommend it. [31:48.710 --> 31:51.990] And if there are, are there any questions or... Yes? [31:52.250 --> 31:57.670] I'm sure you're aware that PCI requires a web application . [31:58.570 --> 31:59.450] PCI-66? [32:00.030 --> 32:00.290] Yeah. [32:01.190 --> 32:07.410] Do you guys evaluate those problems and maybe make recommendations of where they fall short? [32:07.610 --> 32:08.570] Well, there is actually... [32:08.570 --> 32:09.410] Any type of that information? [32:09.410 --> 32:16.010] So, so, so the question was about what application firewalls are WAFs relative to PCI-66 requirement. [32:16.530 --> 32:18.090] That's the requirement for June 30th. [32:18.390 --> 32:33.310] So under the OWASP tools product, there has been a fair amount of work by various sub-matter experts in the WAF space, either than other folks from like Bridge Security and different other organizations and individuals that have contributed to different information on WAFs, [32:33.350 --> 32:33.550] right? [32:33.950 --> 32:48.290] There's a very interesting conversation happening there that with WAFs, with 6-6, that organizations have to either A, deploy a WAF, right, to meet the requirement, B, have to do a code review, or C, buy a tool to do application assessment and or have a third party. [32:48.390 --> 32:51.670] So there's some, some question with actually how that piece gets laid out. [32:52.010 --> 32:53.810] But I'm actually, hopefully I'm answering your question. [32:54.270 --> 33:05.130] The OWASP tool information does have some comparison information, but at this point, I'm not aware, personally, of any commercial consumer reports review of the different WAFs. [33:05.590 --> 33:09.570] Imperva, you know, you have Imperva, you have the F5. [33:10.230 --> 33:13.850] You know, there's a lot of different products in the space that present the requirements and what you're looking for. [33:14.050 --> 33:14.670] Does that help? [33:15.750 --> 33:15.870] Okay. [33:16.590 --> 33:18.330] Does anyone else have any questions about Web AppSec? [33:18.570 --> 33:18.710] Yes, sir. [33:18.970 --> 33:20.370] Who pen-tests your APS? [33:21.270 --> 33:22.710] Who pen-tests your R stuff? [33:23.590 --> 33:24.580] So our, our, our... [33:24.930 --> 33:26.570] The APS is available to public. [33:26.730 --> 33:26.890] Yeah. [33:27.130 --> 33:28.190] Our APS is available to public. [33:28.370 --> 33:29.170] It's obviously open source. [33:29.430 --> 33:31.470] It's available to peer-reviewed to members of OWASP. [33:31.830 --> 33:34.650] It's going through our source code review analyzers and our external stuff. [33:35.070 --> 33:38.090] And you're welcome to review yourself and write up whatever they do. [33:38.450 --> 33:38.910] Yeah. [33:39.250 --> 33:50.750] I think to keep in mind about the OWASP tools is that since they're all open and free for everyone and they're developed by the community, there's a, there's a good amount of really talented people that get to look at them. [33:50.910 --> 34:00.610] I'm not saying that everything is 100% secure because nothing can be, but there's, there's definitely a, a, the top tier of application security professionals that look over these things. [34:00.790 --> 34:07.550] And when I say professionals, a lot of people from the hacker community, you know, kind of chuckle and say, ha ha, you know, I hack all these corporate sites all the time. [34:07.730 --> 34:09.170] So professionals stink at security. [34:09.550 --> 34:18.650] But at, at the end of the day, the organizations do really hire people that are very professional that are, that come from organizations or environments just like this. [34:19.550 --> 34:24.530] So when it, when it, when it comes to looking at OWASP and the members of OWASP, the people are very, very talented. [34:24.710 --> 34:26.730] They come from very creative backgrounds. [34:26.730 --> 34:27.990] They have very creative mindsets. [34:28.130 --> 34:34.190] And it's not a bunch of a, a bunch of guys in suits that come over and look at the code and, you know, try and see if they can find something wrong. [34:34.370 --> 34:35.630] It's, it's really talented people. [34:35.910 --> 34:35.970] So. [34:36.510 --> 34:43.630] Going on that point, just to get to reinforce that statement of the mission, you know, when we started the chapter in New Jersey, you know, we're talking about SQL injection, peer and pizza. [34:43.630 --> 34:46.910] You know, I never thought that, that this chapter would get so large. [34:47.090 --> 34:48.870] And then we've had so much community support. [34:49.190 --> 34:54.790] If you're from New York and you haven't heard about the New York chapter, I'd be surprised when honestly, we do a lot of work with InfraGard. [34:55.230 --> 34:57.350] We do a lot of work with ISSA and ISACA. [34:57.470 --> 35:02.570] So there's a lot of collaboration there because those organizations in particular, you know, they look to us as an APSEC resource. [35:02.750 --> 35:10.330] So in many cases, you know, myself or Steve, one of the other folks on the list, we'll go to those organizations and produce or talk on proponents. [35:10.350 --> 35:13.770] I'm actually doing a training class for ISACA next month. [35:14.070 --> 35:16.690] That's going to be just on application security and how to hack web apps. [35:17.110 --> 35:27.850] And to the point that was made earlier about, you know, the hacker element, I think a good part of the OWASP organization is the hacker element, right? [35:28.090 --> 35:35.670] The problem is, or the good part of it is that none of us there are the criminal element because we're here to obviously help and educate and make sure that the things are useful. [35:35.670 --> 35:39.450] So the tools are great, the tools are fun, and it's good information. [35:39.690 --> 35:46.810] Yeah, the meetings themselves, I just want to quickly mention that, the meetings themselves are generally held either once a month or once every two months. [35:47.170 --> 35:51.130] So in New York, we have them pretty much once every month or so. [35:51.830 --> 35:53.090] And they're free to attend. [35:53.310 --> 36:01.610] So you just go to the website and you go to our chapter page, which is linked off the website, the OWASP.org website, and you can just sign up for a meeting and just show up. [36:01.710 --> 36:05.590] And there's presentations, there's people that are interested in the same topic, and it's all free. [36:05.590 --> 36:08.130] So it's like a mini hacker conference, if you will. [36:08.270 --> 36:10.350] A lot of people talking about the same thing. [36:10.490 --> 36:12.610] And these happen at all the chapters. [36:13.230 --> 36:19.470] Actually, a lot of the folks that we used to catch up with over at City Group for the 2700 meeting, you know, became kind of brutal sometimes, right? [36:19.590 --> 36:23.230] So I decided to go to the bar and just drinking over there and say, hey, let's go to an OWASP meeting and bring your laptop. [36:23.970 --> 36:25.710] So sometimes that can be very useful as well. [36:25.790 --> 36:26.950] Because it's not a corporate-run event. [36:27.170 --> 36:28.710] It's not an ice soccer event. [36:28.750 --> 36:30.470] It's not FBI-heavy with more enforcement. [36:30.770 --> 36:32.950] It's a bunch of guys that have a good time and enjoy what we do. [36:33.010 --> 36:34.150] So that's kind of the key part of it. [36:34.230 --> 36:34.750] Ma'am, you had a question? [36:35.130 --> 36:36.510] Do you have a question for New Jersey? [36:37.530 --> 36:42.830] So the New York-New Jersey metropolitan chapter meets in New York City and also meets in New Jersey. [36:43.010 --> 36:45.910] How it works is we look for a venue sponsor. [36:46.250 --> 36:52.950] Typically our venue sponsors would be somebody like DTCC Downtown, might be Ernest & Young, might be UBS, might be City Group. [36:53.470 --> 36:57.190] Typically it's a corporate sponsor that lets us use their facility to host a meeting. [36:57.610 --> 37:06.010] So if that answers your question, our meetings are posted on our website and our venues are given to us by the people that are typically working for those organizations that can get us a conference room or a space. [37:06.170 --> 37:12.030] Yeah, traditionally we've had a few meetings in Jersey City because there's a lot of organizations there that have meeting space. [37:12.850 --> 37:17.090] We are looking to have meetings sort of towards Edison and Princeton as well. [37:17.910 --> 37:20.070] But again, it's really who can donate the space. [37:20.190 --> 37:28.450] So if you work for a company that has meeting space that can host about 100 people, then donate that space to us just for one night and we can have a meeting closer to maybe wherever you are. [37:28.530 --> 37:31.150] Our last event in New Jersey, as an example, was in Basking Ridge at Verizon. [37:31.490 --> 37:33.030] So Verizon actually hosted the meeting. [37:33.030 --> 37:35.510] We had a good 250 people there at that particular event. [37:36.230 --> 37:38.990] So again, it comes down to if we have a spot, we're good to go. [37:39.690 --> 37:43.850] What started again, you know, at my little office with, you know, five people quickly grew out. [37:44.050 --> 37:45.390] We had people standing room only. [37:45.530 --> 37:46.150] It became ridiculous. [37:46.370 --> 37:47.610] We couldn't do it in the library anymore. [37:47.730 --> 37:50.890] We needed to find a place that could hold, you know, 200 people plus in a room. [37:51.410 --> 37:52.850] So I thought that answered your question. [37:53.450 --> 37:54.770] Are there any other questions on OWASP? [37:54.850 --> 37:56.210] I can help answer it for anyone in the room. [37:57.830 --> 37:58.390] All right. [37:59.250 --> 38:00.970] Well, I thank everybody for attending. [38:01.170 --> 38:03.610] And again, there are some other technical talks that I'm involved in. [38:03.670 --> 38:08.850] If you're interested in more stuff, come see us on Saturday or Sunday and we can dive into some more fun and exciting stuff. [38:08.850 --> 38:09.670] Thank you very much. [38:14.300 --> 38:15.600] Do you want to move these cards? [38:15.860 --> 38:16.140] Those panelists? [38:16.340 --> 38:16.400] Yeah. [38:17.460 --> 38:18.480] So that's what you did. [38:18.740 --> 38:18.880] Thanks. [38:19.280 --> 38:19.600] Yeah. [38:19.740 --> 38:20.380] I'm glad you did. [38:20.720 --> 38:21.560] That sounds kind of fun. [38:21.660 --> 38:23.920] Did you agree that something different? [38:24.240 --> 38:24.780] Oh, yeah. [38:24.860 --> 38:25.180] Absolutely. [38:25.780 --> 38:26.060] Yeah. [38:27.020 --> 38:27.280] Yeah. [38:27.960 --> 38:28.200] Yeah. [38:28.200 --> 38:28.460] Yeah.