Sveriges mest populära poddar
The Application Security Podcast
The Application Security Podcast

Daniel Ramsbrock -- Web Application Pen Testing – Part 1

31 min18 oktober 2016

Om avsnittet

What should developers and security teams understand before commissioning a web application penetration test? In part one, Daniel Ramsbrock joins Chris and Robert to establish the purpose, timing, and business value of testing an application from an attacker’s perspective. They compare penetration testing with earlier secure-development activities, explain why developers and testers benefit from working together, and consider how waterfall, agile, and DevOps delivery models change the engagement. Daniel discusses risk-based scoping, testing frequency, business goals, internal versus external testers, and the ethical “hat” terminology used in security. The episode ends by moving from program decisions toward the hands-on testing process continued in part two.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Daniel Ramsbrock:
Daniel Ramsbrock on LinkedIn

Mentioned in this episode:
RVAsec
DEF CON
Black Hat
Web Application Penetration Testing — Part 2

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 Web application penetration testing, part one
01:41 Daniel Ramsbrock’s security origin story
03:23 What penetration testing is
04:23 Why attackers target applications
05:29 The developer perspective on testing
06:34 Developers and penetration testers working together
07:45 Where penetration testing fits the lifecycle
09:19 Why late testing creates problems
13:18 Waterfall, agile, and DevOps considerations
16:39 How often to run a full penetration test
18:41 Using risk to set the testing schedule
20:13 Scoping services and applications
21:14 Connecting business goals to testing
22:12 Building a testing capability
24:51 Internal and external testing tradeoffs
26:24 White, gray, and black hat terminology
30:24 Preparing for the hands-on process

The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.