Sveriges mest populära poddar
The Application Security Podcast
The Application Security Podcast

Daniel Ramsbrock -- Web Application Pen Testing – Part 2

32 min18 oktober 2016

Om avsnittet

Part two follows Daniel Ramsbrock into the practical workflow of a web application penetration test. He joins Chris and Robert to move from reconnaissance into active testing, explaining credentials, intercepting proxies, attack recording, automated scanners, and the human judgment required to interpret results. The conversation covers authorization failures, false positives, reporting, remediation, and retesting, then broadens into compliance and the feedback loops mature organizations build between testers and development teams. Daniel also offers a learning path through vulnerable applications, training, certifications, bug bounties, books, and hands-on practice. The episode makes clear that tools assist a penetration tester, but disciplined reasoning and communication create the lasting security improvement.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Daniel Ramsbrock:
Daniel Ramsbrock on LinkedIn

Mentioned in this episode:
Burp Suite
HCL AppScan
OWASP WebGoat
GIAC GWAPT
SANS SEC542
Bugcrowd
The Web Application Hacker’s Handbook
Kali Linux

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 Continuing the web penetration testing process
01:54 Why testers need individual credentials
04:21 Moving from reconnaissance to active attack
05:41 Intercepting proxies and recording traffic
07:34 Choosing which attacks to attempt
09:20 Where automated scanners fit
10:27 Human judgment during active testing
11:40 Finding authorization failures
12:40 Interpreting false positives
13:47 Reporting findings and remediation
16:48 Retesting and proving fixes
18:53 Compliance versus meaningful security
20:44 Building feedback loops with development
22:20 Learning web application penetration testing
26:00 Bug bounties as controlled practice
28:11 Books and hands-on resources
30:52 Final advice

The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.