
Daniel Ramsbrock -- Web Application Pen Testing – Part 2
Om avsnittet
Part two follows Daniel Ramsbrock into the practical workflow of a web application penetration test. He joins Chris and Robert to move from reconnaissance into active testing, explaining credentials, intercepting proxies, attack recording, automated scanners, and the human judgment required to interpret results. The conversation covers authorization failures, false positives, reporting, remediation, and retesting, then broadens into compliance and the feedback loops mature organizations build between testers and development teams. Daniel also offers a learning path through vulnerable applications, training, certifications, bug bounties, books, and hands-on practice. The episode makes clear that tools assist a penetration tester, but disciplined reasoning and communication create the lasting security improvement.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
→ Learn more about Security Journey
Connect with Daniel Ramsbrock:
→ Daniel Ramsbrock on LinkedIn
Mentioned in this episode:
→ Burp Suite
→ HCL AppScan
→ OWASP WebGoat
→ GIAC GWAPT
→ SANS SEC542
→ Bugcrowd
→ The Web Application Hacker’s Handbook
→ Kali Linux
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Continuing the web penetration testing process
01:54 Why testers need individual credentials
04:21 Moving from reconnaissance to active attack
05:41 Intercepting proxies and recording traffic
07:34 Choosing which attacks to attempt
09:20 Where automated scanners fit
10:27 Human judgment during active testing
11:40 Finding authorization failures
12:40 Interpreting false positives
13:47 Reporting findings and remediation
16:48 Retesting and proving fixes
18:53 Compliance versus meaningful security
20:44 Building feedback loops with development
22:20 Learning web application penetration testing
26:00 Bug bounties as controlled practice
28:11 Books and hands-on resources
30:52 Final advice
The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.