Absolute AppSec

By Ken Johnson and Seth Law

Listen to a podcast, please open Podcast Republic app. Available on Google Play Store and Apple App Store.


Category: Technology

Open in Apple Podcasts


Open RSS feed


Open Website


Rate for this podcast

Subscribers: 16
Reviews: 0
Episodes: 243

Description

A weekly podcast of all things application security related. Hosted by Ken Johnson and Seth Law.

Episode Date
Episode 243 - w/ Bryan Schmidt
Apr 30, 2024
Episode 242 - LLMs Exploiting Vulns, State of DevSecOps
Apr 23, 2024
Episode 241 - Secure Defaults, Using LLMs for Code Review
Apr 16, 2024
Episode 240 - Code Smells, XZ Backdoor, Hallucinations
Apr 09, 2024
Episode 239 - AppSec Intel, CVEs, Authorization
Mar 26, 2024
Episode 238 - AppSec vs. Enterprise Sec, Supply Chain Tool Analysis
Mar 19, 2024
Episode 237 - Security 101, Nation State Hackers, Malicious Code
Mar 12, 2024
Episode 236 - Memory Safe Languages, LLM Supply Chain Security
Mar 05, 2024
Episode 235 - 2023 Top 10 Web Hacking Techniques, LLM Agent Hacking
Feb 20, 2024
Episode 234 - Password Analysis, GitHub Copilot
Feb 13, 2024
Episode 233 - Scammers, Deep Fakes, Data Exposure
Feb 06, 2024
Episode 232 - Security Jobs, Surveillance, Prompt Injection
Jan 30, 2024
Episode 231 - FlowMate, State of Software Supply Chain Security
Jan 23, 2024
Episode 230 - False Positives vs. Negatives, Scaling Vuln Management
Jan 09, 2024
Episode 229 - Software Supply Chain Security, 2024 Predictions
Jan 02, 2024
Episode 228 w/ Chime Security Engineering - Monocle
Dec 19, 2023
Episode 227 - Token Leakage, Cybersecurity Isn't Special
Dec 14, 2023
Episode 226 - Security Reviews, CVE-2023-46214
Dec 05, 2023
Episode 225 w/ Brian C Reed
Nov 28, 2023
Episode 224 w/ Jeevan Singh
Nov 14, 2023
Episode 223 w/Stefan Edwards - OWASP, Privacy
Nov 07, 2023
Episode 222 w/ Leif Dreizler
Oct 23, 2023
Episode 221 - Interviews, Breach, AI Tools
Oct 19, 2023
Episode 220 w/ Erik Cabetas (Include Security)
Oct 10, 2023
Episode 219 w/Jason Haddix - Discovery Tools, Security Research
Oct 03, 2023
Episode 218 w/ Cole Cornford - Security Startups, Developer Training
Sep 19, 2023
Episode 217 w/ Shlomi Shaki - Security Tooling
Sep 07, 2023
Episode 216 - Security SDLC, Time Management
Aug 29, 2023
Episode 215 - Learning Machine Learning, DEF CON 31 Recap
Aug 22, 2023
Episode 214 - Artificial Intelligence and Security with @lojikil
Aug 08, 2023
Episode 213 - Brian Joe of Impart Security
Jul 25, 2023
Episode 212 - Evan Johnson of RunReveal
Jul 11, 2023
Episode 211 - Brian Walter of OpenContext
Jun 20, 2023
Episode 210 - Approaching Scans, AppSec Research, Threat Modeling
Jun 13, 2023
Episode 209 - James Wickett, Contextual Security Analysis
Jun 06, 2023
Episode 208 - Zip TLD, PyPI 2FA, AI Poisoning
May 30, 2023
Episode 207 - Watering Hole Attacks, Adversarial AI, Cookie Security
May 23, 2023
Episode 206 - RSA, Artificial Intelligence, Spidering Tools
May 04, 2023
Episode 205 - Decline of AppSec, Death of Code Review
Apr 18, 2023
Episode 204 - Logging, Edge Cases, Client API Exposure
Mar 28, 2023
Episode 203 w/ Shlomi Shaki - Security Tools
Mar 21, 2023
Episode 202 w/ Haseeb Awan - Mobile Security
Mar 14, 2023
Episode 201 - Breaches, Package Managers, Audit Logs
Mar 07, 2023
Episode 200 w/ Jerry Gamblin - Startups, CVEs
Feb 28, 2023
Episode 199 - OWASP, Phishing, Eurostar
Feb 14, 2023
Episode 198 with Laura Bell Main - Training
Feb 07, 2023
Episode 197 with Sal Olivares - Exposed API Tokens
Jan 31, 2023
Episode 196 - API Reviews, Web App Security Features
Jan 24, 2023
Episode 195 - 2022 CVEs, CORS, GraphQL
Jan 17, 2023
Episode 194 - Frank Wang (dbtlabs) - Organization Security, AI/ML
Jan 10, 2023
Episode 193 - Security Metrics, End-User Security
Dec 20, 2022
Episode 192 - Blogs, GoLang Security, ChatGPT
Dec 13, 2022
Episode 191 - DNS Attacks, Organizational Risk, Mastadon
Nov 29, 2022
Episode 190 - Immutable Laws of Security
Nov 08, 2022
Episode 189 - Security Bypasses, AppMap, Dastardly
Nov 01, 2022
Episode 188 - Security Training, Zero Trust, Rating of IoT Security
Oct 18, 2022
Episode 187 - Hacking your Health, Fortinet, Secrets in Source
Oct 11, 2022
Episode 186 - Security Trainings, Web3 Bounties, MFA
Oct 04, 2022
Episode 185 - Daniel Ting (hoodiepony) - Breaches, Optus, Uber
Sep 27, 2022
Episode 184 - Sources, Payloads, Patreon, Ethereum, Starbucks
Sep 15, 2022
Episode 183 - Information Warfare w/LegendaryPatMan
Sep 06, 2022
Episode 182 - Twitter, LastPass, Testing Edge Cases
Aug 30, 2022
Episode 181 - (Post DEFCON)
Aug 23, 2022
Episode 180 - Logging! Attacks!
Aug 10, 2022
Episode 179 - Starting in AppSec, Threat Modeling
Aug 02, 2022
Episode 178 - Wallet Attacks(!) and Data Privacy
Jul 26, 2022
Episode 177 - That Post-LocoMocoSec Glow
Jul 05, 2022
Episode 176 - Exposed Secrets, Semgrep Rules, IoT Security Failures
Jun 21, 2022
Episode 175 - Web3, JWT Security, Public App Attacks
Jun 14, 2022
Episode 174 - Smart Contracts, Code Review Lessons Learned
May 31, 2022
Episode 173 - Enumeration Attacks!
May 24, 2022
Episode 172 - Jimmy Mesta - Kubernetes, Startup Adventures
May 17, 2022
Episode 171 - Ruby Deserialization Walkthrough, Domain Takeovers
May 10, 2022
Episode 170 - Security Basics, Social Engineering, Plan for Failure
May 03, 2022
Episode 169 - Finding Security Bugs
Apr 26, 2022
Episode 168 - Secure Code Review, Package Confusion, Privacy Acts
Apr 19, 2022
Episode 167 - Ken Toler - Cryptocurrency, Spring4Shell
Apr 05, 2022
Episode 166 - Web App Firewalls, ProtestWare, CSP Level 3
Mar 22, 2022
Episode 165 - Portswigger 2021 Top 10, Supply Chain Attacks, TLS Certs
Mar 15, 2022
Episode 164 - Supply Chain Security, Cyber Attacks, 2FA, AutoWarp
Mar 08, 2022
Episode 163 - IT Army, Secrets, Access Control
Mar 01, 2022
Episode 162 - Mike McCabe (@mccabe615) - Cloud Security
Feb 22, 2022
Episode 161 - Language Semantics, Blockchain Validations, Pentest Stories
Feb 08, 2022
Episode 160 - Mental Health, Open Source Bug Bounties, IDOR
Feb 01, 2022
Episode 159 - Neil Matatall - CSP, Infosec Hiring, Languages + Framework Security
Jan 25, 2022
Episode 158 - More Supply Chains, 2021 Top Ten, CORS + CSRF
Jan 18, 2022
Episode 157 - 2022 Predictions, Schema Libraries, NPM and Open Source Packages
Jan 11, 2022
Episode 156 - Stefan Edwards (@lojikil) - Open Source Software, Software Bill of Materials
Dec 21, 2021
Episode 155 - Log4Hell, Boring AppSec, Crocs and SOCs
Dec 17, 2021
Episode 154 - Conferences, Cloud Security, Software Supply Chain
Dec 07, 2021
Episode 153 - Fuzzing, Authentication, Browser Wars (again)
Nov 30, 2021
Episode 152 - Breaches, Symbolic Execution, Dynamic vs. Static Assessments
Nov 23, 2021
Episode 151 - Secure Code Review, Software Interdependency
Nov 16, 2021
Episode 150 - Jerry Gamblin - NVD CVEs, Vulnerability Disclosure, Burp Cert
Oct 26, 2021
Episode 149 - Burnout, AppSec News Sources
Oct 19, 2021
Episode 148 - Facebook, Phrack, Paved Path
Oct 05, 2021
Episode 147 - James Kettle (@albinowax), Security Research
Sep 21, 2021
Episode 146 - OWASP Top 10, Bug Bounties with @JHaddix, Request Smuggling
Sep 14, 2021
Episode 145 - Return of @cktricky, Burnout, Bumble Vuln, Brute-Forcing
Aug 26, 2021
Episode 144 - Fuzzing, Radamsa, Property Testing
Aug 17, 2021
Episode 143 - HTTP/2, Black Hat/DEFCON, Kubernetes
Aug 10, 2021
Episode 142 - AI Code Generation, Puma Scan, HTTP Request Smuggling
Jul 20, 2021
Episode 141 - print(), Cross-Site Scripting (XSS), RiskIQ, Amass Demo
Jul 13, 2021
Episode 140 - Naomi Buckwalter - Gatekeeping, Developing AppSec Resources
Jun 29, 2021
Episode CXXXIX - Return of the @lojikil (Stefan Edwards)
Jun 22, 2021
Episode 138: Ransomware
Jun 15, 2021
Episode 137: CSRF, GraphQL, Kubernetes, Docker, NoSQL Injection
Jun 08, 2021
Episode 136: AppSec Nihilism and Breaches
Jun 01, 2021
Episode 135: GoSDL, Language Choice, Kenna, Dependency Confusion
May 18, 2021
Episode 134: Legal Protections, Browser Sanitization APIs, Burnout
May 11, 2021
Episode 133: Rob Shavell - Privacy
May 04, 2021
Episode 132: Supply Chain Attacks, What I Wish I Knew Starting in Security
Apr 27, 2021
Episode 131: Jeevan Singh - Threat Modeling
Apr 20, 2021
Episode 130: Facebook 'Breach', Data Privacy
Apr 13, 2021
Episode 129: Rey Bango - JQuery, Developer Relations, Security Education
Apr 06, 2021
Episode 128: Stefan Edwards/David Coursey - PHP, Backdoors, and AppSec Nihilism
Mar 30, 2021
Episode 127: Regexes, WAFs, Secondary Contexts
Mar 23, 2021
Episode 126: Junior AppSec Positions, Phishing Site Detection, Client-side JavaScript
Mar 16, 2021
Episode 125: Interviews, SQLi, Concurrency, Wordpress
Mar 09, 2021
Episode 124: 2020 Top 10 Web Hacking Techniques, Development vs. Security
Mar 02, 2021
Episode 123: Client-Side Controls, Dependency Confusion
Feb 23, 2021
Episode 122: Brian Glas (@infosecdad) - OWASP Top 10 2021
Feb 18, 2021
Episode 121: Stefan Edwards (@lojikil) - Formal Specification, Fuzzing, LangSec
Feb 02, 2021
Episode 120: OWASP Top 10 2021, Researcher Attacks, Parler, Phishing
Jan 26, 2021
Episode 119: Bugtraq, Web Cache Poisoning, and Blind SSRF
Jan 19, 2021
Episode 118: Parler, Twitter, and IDOR
Jan 12, 2021
Episode 117: Solarwinds, Timing Attacks, Threat Dragon
Dec 22, 2020
Episode 116: Lewis Ardern and Pwnfunction - Client-Side JavaScript Security
Nov 24, 2020
Episode 115: Clint Gibler - Static Analysis with Semgrep
Nov 17, 2020
Episode 114: Account Enumeration, Github Actions
Nov 10, 2020
Episode 113: Jacob Salassi - Modeling Threats, Risk Assessment
Oct 27, 2020
Episode 112: Mark Feferman - Static Analysis Tools
Oct 20, 2020
Episode 111: Bug Bounties, Detection as Code
Oct 13, 2020
Episode 110: Reserved Words, Authentication, Developer Patterns
Oct 06, 2020
Episode 109: Threat Modeling, Social Media, Imposter Syndrome
Sep 22, 2020
Episode 108: Sean Poris - Bug Bounties and H1-2010
Sep 15, 2020
Episode 107: Markus Schirp - Ruby and Dynamic Languages
Sep 01, 2020
Episode 106: Justin Massey - Logging and Monitoring
Aug 25, 2020
Episode 105: Laura Migus - Diversity and Inclusion
Aug 18, 2020
Episode 104: Leif Dreizler - Authentication and SCIM
Aug 05, 2020
Episode 103: Secrets Management, Oded Hareven, and akeyless.io
Jul 21, 2020
Episode 102: Popular Programming Languages, TikTok, OWASP
Jun 30, 2020
Episode 101: Mike McCabe, Ken Toler, Cloud Security
Jun 23, 2020
Episode 100: Virtual Conferences, Bots, DDoS, Ebay
Jun 16, 2020
Episode 99: Contact Tracing, GnuTLS, Breaches
Jun 09, 2020
Episode 98: Bug Bounty Programs, Work when World is Crazy
Jun 02, 2020
Episode 97: Stefan Edwards and Brian Glas - Threat Modeling
May 26, 2020
Episode 96: Fuzzing and Static Analysis Tools
May 19, 2020
Episode 95: Jessica Rozhin (@JessicaRozhin) and Lady Christina Liu (cliuthulu) - Incident Response, Lockpicking, Building an Infosec Culture
May 12, 2020
Episode 94: Bug Bounty, Microservices vs. Monoliths, and CVE Fatigue
May 05, 2020
Episode 93: Huntr Dev - Securing Open Source Software
Apr 21, 2020
Episode 92: Working from Home, Skreen, Evolution of AppSec
Apr 14, 2020
Episode 91: Stefan Edwards - More Voatz, Zoom, Code Reviews, Report Writing, Threat Models, and Risk Assessments
Apr 07, 2020
Episode 90: Voatz, HackerOne, Bug Bounties, GraphQL, Shodan Network Trends
Mar 31, 2020
Episode 89: Kat Sweet - Incident Response, DevOps and Developer Training, Breaking into Security
Mar 24, 2020
Episode 88: Kevin Johnson - Secure Ideas, Star Wars, Passing it On
Mar 17, 2020
Episode 87: Abhay Bhargav - Threat Modeling, DevSecOps, Microservices
Mar 03, 2020
Episode 86: Rohan Johsi - QA Security Testing, Security Champions, Paypal Vulnerabilities
Feb 25, 2020
Episode 85: David Lindner - Voting Apps, Bug Bounties, IAST/RASP/WAF
Feb 18, 2020
Episode 84: Tinfoil Hat Tuesday - Backdoors, Application Libraries, Equifax
Feb 11, 2020
Episode 83: Ron Perris - NPM, Developer Training, React
Feb 06, 2020
Episode 82: Kelley Robinson - MFA, SHAKEN, STIR
Jan 28, 2020
Episode 81: Matias Madou - Application Security Training
Jan 21, 2020
Episode 80: Louis Barratt - SIRT and AppSec
Jan 14, 2020
Episode 79: Live from DevSecOpsDays Austin - Next up in AppSec/DevSecops
Dec 17, 2019
Episode 78: Breaches, Passwords, and Chicken Fingies
Dec 10, 2019
Episode 77: Clint Gibler, DevSecOps, TLDR; Sec
Dec 03, 2019
Episode 76: Guy Podjarny, Snyk, AppScan, SCA
Nov 26, 2019
Episode 75: Brian Glas, OWASP Top 10, OWASPSAMM
Nov 19, 2019
Episode 74: Ernest Mueller, DevOps, Security and Cloud Computing
Oct 23, 2019
Episode 73: Kevin Cody, CORS, and Lockpicking
Oct 17, 2019
Episode 72: Consulting Horror Stories
Oct 01, 2019
Episode 71: Evan Johnson, Cloudflare and Lastpass
Sep 17, 2019
Episode 70: Andrew Wilson, OWASP and Training New AppSec Resources
Sep 03, 2019
Episode 69: Eric Ellett, Development vs. Security
Aug 27, 2019
Episode 68: Jerry Gamblin, DEF CON 27 Recap
Aug 13, 2019
Episode 67: Kubernetes Security with Stefan and Bobby
Aug 12, 2019
Episode 66: Capital One Breach, NPM, and Secure Code Reviews
Jul 30, 2019
Episode 65: Adam Baldwin, 3rd Party Dependencies, and Supply Chain Security
Jul 16, 2019
Episode 64: Hijacked Gems, Zoom RCE, and Marriott Fines
Jul 09, 2019
Episode 63: Julian Berton, AppSec Day, Developer Training, and Security Standards
Jul 02, 2019
Episode 62: Abdullah Munawar, Ben Pick, Global AppSec DC, and Running an OWASP Chapter
Jun 18, 2019
Episode 61: Tanya Janca, DevSlop, Diversity, and Inclusion
Jun 11, 2019
Episode 60: Stefan Edwards, Huawei, Android Security, and Programming Languages
May 21, 2019
Episode 59: James Wickett on DevOps
May 14, 2019
Episode 58: David Lindner on RASP, Mobile, IoT
May 07, 2019
Episode 57: OWASP WIA (Women in AppSec) Committee
Apr 30, 2019
Episode 56: Learn to Code / Loco Moco Sec Recap
Apr 23, 2019
Episode 55: Stefan Edwards ruins Infosec - Testing Edition
Apr 18, 2019
Episode 54: Recon-NG and Burp Suite v2 with Tim Tomes
Apr 09, 2019
Episode 53: Building AppSec at Github with Greg Ose
Apr 02, 2019
Episode 52: Serialization Vulns, Managing Careers, and Hacking your Happiness with Chris Gates
Mar 26, 2019
Episode 51: XXE review and techniques, Assessment Reporting and Process with Jessica Ryan
Mar 19, 2019
Episode 50: Static Analysis Tools, DevSecOps, Secure Code Training with Eric Heitzman
Mar 12, 2019
Episode 49: Subdomain Takeovers, DNS SSRF, Oauth Best Practices, Top 10 Web Hacking Techniques of 2019
Mar 05, 2019
Episode 48: .dev domains, Kubernetes Secrets, Threat Modeling as Code, OWASP Glue Project and Omer Levi Hevroni
Feb 26, 2019
Episode 47: Mapping Application Source Code, Mobile OWASP Top 10, Mobile Application Testing, and Kevin Cody
Feb 20, 2019
Episode 46: Fuzzing, Frameworks, Training and Daniel Miessler
Feb 13, 2019
Episode 45: Making the most of Bug Bounties, managing an AppSec program, and Sean Poris
Feb 06, 2019
Episode 44: AppSec California, running a Bug Bounty program, and David Coursey
Jan 30, 2019
Episode 43: DerbyCon, pwnhead, and Keith Hoodlet
Jan 16, 2019
Episode 42: SSRF Rebinding and Segment Team (Leif Dreizler and David Scrobonia)
Jan 09, 2019
Episode 41: Hidden File/Dir Enumeration and Will Bengtson
Dec 19, 2018
Episode 40: Code Reviews
Dec 12, 2018
Episode 39: Jerry Gamblin
Dec 05, 2018
Episode 38: Matt Konda
Nov 28, 2018
Episode 37: Stefan Edwards
Nov 21, 2018
Episode 36: Mike McCabe
Nov 14, 2018
Episode 35: Travis McPeak
Nov 07, 2018
Episode 34: Stefan Edwards
Oct 31, 2018
Episode 33: John Melton
Oct 03, 2018
Episode 32: Eric Johnson
Sep 19, 2018
Episode 31: Rob Fuller
Sep 12, 2018
Episode 30: Dave Ferguson
Sep 05, 2018
Episode 29: Matt Tesauro
Aug 29, 2018
Episode 28: Astha Singhal
Aug 22, 2018
Episode 27: Jim Manico
Aug 15, 2018
Episode 26: Justin Larson
Aug 01, 2018
Episode 25: Scott Piper
Jul 25, 2018
Episode 24: Jason White
Jul 18, 2018
Episode 23: Ken Toler
Jul 11, 2018
Episode 22: Jimmy Mesta
Jun 29, 2018
Episode 21: Alex Smolen
Jun 22, 2018
Episode 20: Authentication and JWTs
Jun 20, 2018
Episode 19: CFPs and More
Jun 06, 2018
Episode 18: Chris Gates
May 30, 2018
Episode 17: Efail and CSRF
May 16, 2018
Episode 16: Hipster Languages
May 09, 2018
Episode 15: Kevin Cody
May 02, 2018
Episode 14: Karthik Gaekwad
Apr 25, 2018
Episode 13: Charles Nwatu
Apr 11, 2018
Episode 12: Justin Collins
Apr 05, 2018
Episode 11: David Coursy and Stefan Edwards
Mar 28, 2018
Episode 10: Jimmy Mesta
Mar 14, 2018
Episode 9: Jason Haddix
Mar 07, 2018
Episode 8: Neil Matatall
Feb 28, 2018
Episode 7: Current Events
Feb 21, 2018
Episode 6: Kevin Cody
Feb 14, 2018
Episode 5: Stefan Edwards and Dave Coursey
Feb 07, 2018
Episode 4: Evan Johnson
Jan 31, 2018
Episode 3: Jerry Gamblin
Jan 24, 2018
Episode 2: Current Events
Jan 17, 2018
Episode 1: Introductions
Jan 10, 2018