<H3> About The Podcast </H3> |
<H3> The Hosts </H3> |
<H4> [email protected] | </H4> |
<H5> Episode #138 - Ransomware </H5> |
<H5> | |
|
Episode #138 - Ransomware |
</H5> |
<H5> | |
|
Episode #137 - CSRF, GraphQL, Kubernetes, Docker, NoSQL Injection |
</H5> |
<H5> | |
|
Episode #136 - AppSec Nihilism and Breaches |
</H5> |
<H5> | |
|
Episode #135 - GoSDL, Language Choice, Kenna, Dependency Confusion |
</H5> |
<H5> | |
|
Episode #134 - Legal Protections, Browser Sanitization APIs, Burnout |
</H5> |
<H5> | |
|
Episode #133 - Rob Shavell - Privacy |
</H5> |
<H5> | |
|
Episode #132 - Supply Chain Attacks, What I Wish I Knew Starting in Security |
</H5> |
<H5> | |
|
Episode #131 - Jeevan Singh - Threat Modeling |
</H5> |
<H5> | |
|
Episode #130 - Facebook 'Breach', Data Privacy |
</H5> |
<H5> | |
|
Episode #129 - Rey Bango - JQuery, Developer Relations, Security Education |
</H5> |
<H5> | |
|
Episode #128 - Stefan Edwards/David Coursey - PHP, Backdoors, and AppSec Nihilism |
</H5> |
<H5> | |
|
Episode #127 - Regexes, WAFs, Secondary Contexts |
</H5> |
<H5> | |
|
Episode #126 - Junior AppSec Positions, Phishing Site Detection, Client-side JavaScript |
</H5> |
<H5> | |
|
Episode #125 - Interviews, SQLi, Concurrency, Wordpress |
</H5> |
<H5> | |
|
Episode #124 - 2020 Top 10 Web Hacking Techniques, Development vs. Security |
</H5> |
<H5> | |
|
Episode #123 - Client-Side Controls, Dependency Confusion |
</H5> |
<H5> | |
|
Episode #122 - Brian Glas - OWASP Top 10 2021 |
</H5> |
<H5> | |
|
Episode #121 - Stefan Edwards - Formal Specification, Fuzzing, LangSec |
</H5> |
<H5> | |
|
Episode #120 - OWASP Top 10 2021, Researcher Attacks, Parler, Phishing |
</H5> |
<H5> | |
|
Episode #119 - Bugtraq, Web Cache Poisoning, and Blind SSRF |
</H5> |
<H5> | |
|
Episode #118 - Parler, Twitter, and IDOR |
</H5> |
<H5> | |
|
Episode #117 - Solarwinds, Timing Attacks, Threat Dragon |
</H5> |
<H5> | |
|
Episode #116 - Lewis Ardern & pwnfunction - Client-Side JavaScript Security |
</H5> |
<H5> | |
|
Episode #115 - Clint Gibler - Static Analysis with Semgrep |
</H5> |
<H5> | |
|
Episode #114 - Account Enumeration, Github Actions |
</H5> |
<H5> | |
|
Episode #113 - Jacob Salassi - Modeling Threats, Risk Assessment |
</H5> |
<H5> | |
|
Episode #112 - Mark Feferman - Static Analysis Tools |
</H5> |
<H5> | |
|
Episode #111 - Bug Bounties, Detection as Code |
</H5> |
<H5> | |
|
Episode #110 - Reserved Words, Authentication, Developer Patterns |
</H5> |
<H5> | |
|
Episode #109 - Threat Modeling & Social Media apps |
</H5> |
<H5> | |
|
Episode #108 - Sean Poris - Bug Bounty Programs and H1-2010 |
</H5> |
<H5> | |
|
Episode #107 - Markus Schirp - Ruby & Dynamic Languages |
</H5> |
<H5> | |
|
Episode #106 -Justin Massey - Logging & Monitoring |
</H5> |
<H5> | |
|
Episode #105 - Laura Migus - Diversity & Inclusion |
</H5> |
<H5> | |
|
Episode #104 - Leif Dreizler - Authentication & SCIM |
</H5> |
<H5> | |
|
Episode #103 - Secrets Management, Oded Hareven, & akeyless.io |
</H5> |
<H5> | |
|
Episode #102 - Popular Programming Languages, TikTok, OWASP |
</H5> |
<H5> | |
|
Episode #101 - Mike McCabe, Ken Toler & Cloud Security |
</H5> |
<H5> | |
|
Episode #100 - Virtual content, Bots, DDoS, Ebay |
</H5> |
<H5> | |
|
Episode #99 - Contact Tracing, GnuTLS, Breaches |
</H5> |
<H5> | |
|
Episode #98 - Bug Bounty Programs, Work when World is Crazy |
</H5> |
<H5> | |
|
Episode #97 - Stefan Edwards and Brian Glas - Threat Modeling |
</H5> |
<H5> | |
|
Episode #96 - Fuzzing and Static Analysis Tools |
</H5> |
<H5> | |
|
Episode #95 - Jessica Rozhin and Lady Christina Liu - Incident Response, Lockpicking, Building an Infosec Culture |
</H5> |
<H5> | |
|
Episode #94 - Bug Bounty, Microservices vs. Monoliths, and CVE Fatigue |
</H5> |
<H5> | |
|
Episode #93 - Huntr Dev - Securing Open Source Software |
</H5> |
<H5> | |
|
Episode #92 - Working from Home, Skreen, Evolution of AppSec |
</H5> |
<H5> | |
|
Episode #91 - Stefan Edwards - More Voatz, Zoom, Code Reviews, Report Writing, Threat Models, and Risk Assessments |
</H5> |
<H5> | |
|
Episode #90 - Voatz, HackerOne, Bug Bounties, GraphQL, Shodan Network Trends |
</H5> |
<H5> | |
|
Episode #89 - Kat Sweet - Incident Response, DevOps & Developer Training, Breaking into Security |
</H5> |
<H5> | |
|
Episode #88 - Kevin Johnson - Secure Ideas, Star Wars, Passing it On |
</H5> |
<H5> | |
|
Episode #87 - Abhay Bhargav - Threat Modeling, DevSecOps, Microservices |
</H5> |
<H5> | |
|
Episode #86 - Rohan Joshi - QA Security Testing, Security Champions, Paypal Vulnerabilities |
</H5> |
<H5> | |
|
Episode #85 - David Lindner - Voting Apps, Bug Bounties, IAST/RASP/WAF |
</H5> |
<H5> | |
|
Episode #84 - Tinfoil Hat Tuesday - Backdoors, Application Libraries, Equifax |
</H5> |
<H5> | |
|
Episode #83 - Ron Perris - NPM, Developer Training, React |
</H5> |
<H5> | |
|
Episode #82 - Kelley Robinson - MFA, SHAKEN, STIR |
</H5> |
<H5> | |
|
Episode #81 - Matias Madou - Application Security Training |
</H5> |
<H5> | |
|
Episode #80 - Louis Barrett - SIRT and AppSec |
</H5> |
<H5> | |
|
Episode #79 - Live from DevSecOpsDays Austin - Next up in AppSec/DevSecops |
</H5> |
<H5> | |
|
Episode #78 - Breaches, Passwords, and Chicken Fingies |
</H5> |
<H5> | |
|
Episode #77 - Clint Gibler, DevSecOps, TLDR; Sec |
</H5> |
<H5> | |
|
Episode #76 - Guy Podjarny, Snyk, AppScan, SCA |
</H5> |
<H5> | |
|
Episode #75 - Brian Glas, OWASP Top 10, OWASPSAMM | </H5> |
<H5> | |
|
Episode #74 - Ernest Mueller, DevOps, Security & Cloud Computing | </H5> |
<H5> | |
|
Episode #73 - Kevin Cody, CORS, and Lockpicking | </H5> |
<H5> | |
|
Episode #72 - Consulting Horror Stories | </H5> |
<H5> | |
|
Episode #71 - Evan Johnson, Cloudflare, and Lastpass | </H5> |
<H5> | |
|
Episode #70 - Andrew Wilson, OWASP, and Training New AppSec Resources | </H5> |
<H5> | |
|
Episode #69 - Eric Ellett, Development vs. Security | </H5> |
<H5> | |
|
Episode #68 - Jerry Gamblin, DEF CON 27 Recap | </H5> |
<H5> | |
|
Episode #67 - Kubernetes Security with Stefan and Bobby | </H5> |
<H5> | |
|
Episode #66 - Capital One Breach, NPM, and Secure Code Reviews | </H5> |
<H5> | |
|
Episode #65 - Adam Baldwin, 3rd Party Dependencies, and Supply Chain Security | </H5> |
<H5> | |
|
Episode #64 - Hijacked Gems, Zoom RCE, and Marriott/Starwood Breach Fines | </H5> |
<H5> | |
|
Episode #63 - Julian Berton, AppSec Day, Developer Training, and Security Standards | </H5> |
<H5> | |
|
Episode #62 - Abdullah Munawar, Ben Pick, Global AppSec DC, and Running an OWASP Chapter | </H5> |
<H5> | |
|
Episode #61 - Tanya Janca, DevSlop, Diversity, and Inclusion | </H5> |
<H5> | |
|
Episode #60 - Stefan Edwards, Huawei, Android, and Programming Languages | </H5> |
<H5> | |
|
Episode #59 - James Wickett & DevOps | </H5> |
<H5> | |
|
Episode #58 - David Lindner, RASP, Mobile, IoT | </H5> |
<H5> | |
|
Episode #57 - OWASP WIA (Women In AppSec) Committee | </H5> |
<H5> | |
|
Episode #56 - Learn to Code / Loco Moco Sec Recap | </H5> |
<H5> | |
|
Episode #55 - Stefan Edwards ruins Infosec - Testing Edition | </H5> |
<H5> | |
|
Episode #54 - Recon-NG and Burp Suite 2 with Tim Tomes | </H5> |
<H5> | |
|
Episode #53 - Building AppSec at GitHub with Greg Ose | </H5> |
<H5> | |
|
Episode #52 - Serialization Vulns, Career Growth, and Hacking your Happiness with Chris Gates | </H5> |
<H5> | |
|
Episode #51 - XXE, Assessment Reporting and Process with Jessica Ryan | </H5> |
<H5> | |
|
Episode #50 - Static Analysis Tools, DevSecOps, Secure Code Training with Eric Heitzman | </H5> |
<H5> | |
|
Episode #49 - Subdomain Takeovers, DNS SSRF, Oauth Best Practices, Top 10 Web Hacking Techniques of 2019 | </H5> |
<H5> | |
|
Episode #48 - .dev domains, Kamus with Kubernetes Secrets, Threat Modeling as Code, OWASP Glue Project & Omer Levi Hevroni | </H5> |
<H5> | |
|
Episode #47 - Mapping Application Source, Mobile OWASP Top 10, Mobile App Testing & Kevin Cody | </H5> |
<H5> | |
|
Episode #46 - Fuzzing, Frameworks, Training & Daniel Miessler | </H5> |
<H5> | |
|
Episode #45 - Bug Bounties, Managing AppSec, & Sean Poris | </H5> |
<H5> | |
|
Episode #44 - AppSec Cali, Bug Bounties, & David Coursey | </H5> |
<H5> | |
|
Episode #43 - DerbyCon, pwnhead, & Keith Hoodlet | </H5> |
<H5> | |
|
Episode #42 - SSRF Rebinding & Segment Team (Leif Dreizler& David Scrobonia) - SSRF Rebinding, Breach Password Lists | </H5> |
<H5> | |
|
Episode #41 - Hidden File Enumeration + Will Bengtson - AWS/Cloud Security, Cloudtrail, Trailblazer | </H5> |
<H5> | |
|
Episode #40 - Secure Code Reviews, Assessment Scopes, More Breach Fatigue | </H5> |
<H5> | |
|
Episode #39 - Jerry Gamblin - Breach Fatigue, AWS Re:Invent | </H5> |
<H5> | |
|
Episode #38 - Matt Konda - event_stream, Glue Tool, OWASP, Jemerai | </H5> |
<H5> | |
|
Episode #37 - Stefan Edwards - Holiday Gifts, Getting Started with Security and Languages, Formal Verification. | </H5> |
<H5> | |
|
Episode #36 - Mike McCabe - Input Validation vs. XSS, Cloud Security, Building AppSec Programs, Interviews | </H5> |
<H5> | |
|
Episode #35 - Travis McPeak - OWASP Bay Area, RepoKid, AWS Security, and SSRF | </H5> |
<H5> | |
|
Episode #34 - Stefan Edwards - Security Testing, Blockchain & you! | </H5> |
<H5> | |
|
Episode #33 - John Melton - Building appsec programs, static analysis tools, and contributing to open source. | </H5> |
<H5> | |
|
Episode #32 - Eric Johnson - Burp Suite Pro setup tips, Puma Scan, teaching appsec | </H5> |
<H5> | |
|
Episode #31 - Rob Fuller - Writing effective vulnerability reports, CCDC, volunteerism, NoVA Hackers | </H5> |
<H5> | |
|
Episode #30 - Dave Ferguson - CSRF, AppSec Tooling, Developer Training | </H5> |
<H5> | |
|
Episode #29 - Matt Tesauro - OWASP, Defect Dojo, AppSec Pipeline Toolbox | </H5> |
<H5> | |
|
Episode #28 - Astha Singhal - Automating application security, bug bounties | </H5> |
<H5> | |
|
Episode #27 - Jim Manico - Jim Manico RAW, Training, OWASP, Code Security | </H5> |
<H5> | |
|
Episode #26 - Justin Larson - Building an AppSec program from scratch, Ruby vs. JS | </H5> |
<H5> | |
|
Episode #25 - Scott Piper - AWS Security, Cloud Mapper, Cloud Tracker | </H5> |
<H5> | |
|
Episode #24 - Jason White - Transitioning from developer to application security | </H5> |
<H5> | |
|
Episode #23 - Ken Toler - Security programs and identifying security champions | </H5> |
<H5> | |
|
Episode #22 - Jimmy Mesta - Kubernetes and container security | </H5> |
<H5> | |
|
Episode #21 - Alex Smolen - cloudtrail-daily & webauthn | </H5> |
<H5> | |
|
Episode #20 - Authentication & JWTs | </H5> |
<H5> | |
|
Episode #19 - Submitting CFPs & More | </H5> |
<H5> | |
|
Episode #18 - Chris Gates (Purple Teaming/WeirdAAL) | </H5> |
<H5> | |
|
Episode #17 - Efail & CSRF Tokens | </H5> |
<H5> | |
|
Episode #16 - Hipster Languages/Frameworks | </H5> |
<H5> | |
|
Episode #15 - Kevin Cody (Mobile Security Testing) | </H5> |
<H5> | |
|
Episode #14 - Karthik Gaekwad | </H5> |
<H5> | |
|
Episode #13 - Charles Nwatu | </H5> |
<H5> | |
|
Episode #12 - Justin Collins | </H5> |
<H5> | |
|
Episode #11 - David Coursey & Stefan Edwards | </H5> |
<H5> | |
|
Episode 10 - Jimmy Mesta | </H5> |
<H5> | |
|
Episode 9 - Jason Haddix | </H5> |
<H5> | |
|
Episode 8 - Neil Matatal | </H5> |
<H5> | |
|
Episode 7 | </H5> |
<H5> | |
|
Episode 6 - Kevin Cody | </H5> |
<H5> | |
|
Episode 5 - Stefan Edwards & David Coursey | </H5> |
<H5> | |
|
Episode 4 - Evan Johnson | </H5> |
<H5> | |
|
Episode 3 - Jerry Gamblin | </H5> |
<H5> | |
|
Episode 2 | </H5> |
<H5> | |
|
Episode 1 - Introductions | </H5> |
<H5> Seth Law </H5> |
<H5> Ken Johnson </H5> |
Social
Social Data
Cost and overhead previously rendered this semi-public form of communication unfeasible.
But advances in social networking technology from 2004-2010 has made broader concepts of sharing possible.