Sveriges mest populära poddar
The Application Security Podcast
The Application Security Podcast

Bjorn Kimminich -- The Joy of the Vulnerable Web: JuiceShop

37 min19 november 2018

Om avsnittet

Can an intentionally broken online shop help change an organization’s security culture? OWASP Juice Shop creator Björn Kimminich explains how a realistic application full of vulnerabilities gives developers, testers, and managers a shared way to experience security problems. He traces the project’s origins, describes how real incidents become challenges, and discusses the community that keeps adding new ideas. Chris asks about management awareness demonstrations, capture-the-flag events, deployment options, and the range of challenge difficulty. They also explore what was new in Juice Shop 8 and where Björn hoped to take the project next. The conversation shows how hands-on exploration can connect an abstract vulnerability to something people recognize in their own software, without requiring everyone to begin as an expert.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Björn Kimminich:
Björn Kimminich on GitHub
OWASP Juice Shop

Mentioned in this episode:
Juice Shop project website
Juice Shop source code
Node.js

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 Learning security with Björn Kimminich and Juice Shop
01:37 Björn’s path from development into security
03:41 Why Juice Shop was created
04:51 What makes an intentionally broken application
05:41 Turning real vulnerabilities into challenges
07:42 The community behind the project
11:04 Who uses Juice Shop and why
13:08 Security awareness demonstrations for managers
14:56 How managers respond to seeing attacks
17:04 Running Juice Shop for capture-the-flag events
19:31 Deployment options
20:29 Trying the demo instance
23:24 Exploring with browser developer tools
25:17 What was new in Juice Shop 8
27:26 Challenges for different skill levels
29:03 The project’s future direction
33:42 Sharing ideas and getting involved

The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.