Hacking with James Kettle
Easy Prey3 Jun 2020

Hacking with James Kettle

Have you ever wondered how hackers find vulnerabilities and how companies can find and fix their own? You will find out today! On average 30,000 new websites are hacked every day.

Our guest for this episode is James Kettle. James is the Director of Research at PortSwigger Web Security where he explores new ways to attack websites and designs and refines vulnerability detection techniques for the Burp Suites scanner.

James shares his hacking experience and hard work helping companies keep their websites secure from all the crazy stuff going on out there. On today's episode, James shares his expertise to help you be more aware of possible red flags and prevention measures to take to protect yourself and your website.

Show Notes:
  • [00:40] - When James was at university he saw that Google said they would pay anybody that could hack their website. He thought that sounded like fun and spent a huge amount of time doing that.
  • [01:02] - Now James works at PortSwigger and researches new techniques to hack websites.
  • [01:11] - Bounty programs are where a company wants to make sure their product or website doesn't get hacked by malicious people so they go out and publicly say that anyone is welcome to try and hack their website. If you are successful and you don't do any damage, but you tell them how you did it they will pay you for it and then fix it.
  • [03:45] - Pen testing is the classic approach to securing your website where you pay a consultant to spend one or two weeks trying to hack your website.
  • [05:14] - It is totally worth it to get that third party view. Developers often can't find problems with their own products.
  • [06:13] - If you want to find a vulnerability on a website you need to use an attack technique.
  • [07:15] - These days they see a lot of cross-site scripting vulnerabilities and it's the most common one they see.
  • [07:37] - One of the most common causes of high impact breaches is access control issues.
  • [08:45] - James shares the biggest data breach they were able to do during their testing.
  • [10:31] - Try to use a framework whenever possible, because it makes things like sequel injection less likely to happen.
  • [11:01] - The standard approach after you make the website is to try to get someone else to look at it.
  • [11:27] - With Wordpress, it is very important to keep it up to date, install as few plug-ins as possible, and choose a good password.
  • [14:08] - Use as few browser extensions as possible to avoid possible malware issues.
  • [15:25] - Most people are not being personally targeted by hackers so the threats that most people need to watch out for are things that can be automated.
  • [16:10] - If you are using the same password on multiple websites you are going to get hacked.
  • [17:02] - A common misconception is that if you have a strong unique password then it doesn't matter if you reuse it.
  • [18:03] - James uses websites with the assumption that all the data I give this website is going to end up public at some point.
  • [18:45] - Provide the minimum information possible.
  • [20:19] - James shares his all-time favorite story.
  • [22:33] - If an entity builds their security around detecting when people are attacking them then running a bug bounty would be harmful because they have no idea who is legitimate or hostile. If your website is on the internet, it is being attacked.
  • [23:35] - When you are being attacked, it is important to know that it most likely isn't personal.

Thanks for joining us on Easy Prey. Be sure to subscribe to our podcast on iTunes and leave a nice review.

Links and Resources:

Denne episoden er hentet fra en åpen RSS-feed og er ikke publisert av Podme. Den kan derfor inneholde annonser.

Episoder(329)

Job Recruiter Scams

Job Recruiter Scams

Job hunting is hard enough without having to stop and ask whether the recruiter in your inbox is even real. My guest today, Jay Jones, ran into that problem firsthand after being laid off in December ...

24 Jun 35min

Bail Bonds Scams

Bail Bonds Scams

Getting a call that someone you love has been arrested is scary enough. Getting that call from someone who sounds official, knows just enough to seem credible, and says you have to send money right aw...

17 Jun 36min

Confessions of a Fraudster

Confessions of a Fraudster

Technology keeps changing, but many of the most effective scams still come down to something very human: trust. My guest today is Tony Sales, co-founder of We Fight Fincrime and Underworld TV. Tony ha...

10 Jun 54min

Personal Safety

Personal Safety

Scams and safety threats don't always announce themselves. Sometimes they start quietly, with a moment of distraction, a strange feeling you ignore, or a situation that shifts just enough to test whet...

3 Jun 43min

Data For Sale

Data For Sale

Everyday conveniences ask for tiny pieces of information all the time like a phone number at checkout, a zip code at the register, an email address for a receipt, or a loyalty account for a small disc...

27 Mai 43min

Exploiting Psychology

Exploiting Psychology

Scams are often explained as a failure of judgment, but the truth is far more human. People are not fooled because they are foolish. They are manipulated at the exact moment emotion overrides logic, w...

20 Mai 45min

Investment Traps

Investment Traps

Investment losses can be confusing because they do not always tell the whole story. Sometimes money is lost because the market has changed. Other times, an investor was sold something they did not und...

13 Mai 47min

Elder Exploitation

Elder Exploitation

Aging parents often rely on the people closest to them for help, but what happens when that help becomes a way to take control? For Charles Wallace, the warning signs started small. His mother's fridg...

6 Mai 39min

Populært innen Politikk og nyheter

giver-og-gjengen-vg
aftenpodden
aftenpodden-usa
fotballpodden-2
forklart
stopp-verden
popradet
det-store-bildet
rss-espen-lee-usensurert
nokon-ma-ga
lydartikler-fra-aftenposten
dine-penger-pengeradet
rss-gukild-johaug
hanna-de-heldige
rss-penger-polser-og-politikk
rss-ness
aftenbla-bla
frokostshowet-pa-p5
e24-podden
rss-utenrikskomiteen-med-bogen-og-grasvik