The OWASP WebSpa Project with Yiannis Pavlosoglou and Jim Manico

The OWASP WebSpa Project with Yiannis Pavlosoglou and Jim Manico

The OWASP WebSpa Project The OWASP WebSpa project is a tool implementing the novel idea of web knocking. The term web knocking stems from port knocking, If port knocking is defined as "a form of host-to-host communication in which information flows across closed ports" then we define web knocking as a form of host-to-host communication in which information flows across erroneous URLs. In this podcast we present this web knocking tool for sending a single HTTP/S request to your web server, in order to authorise the execution of a preselected Operating System (O/S) command on it. About Yiannis Pavlosoglou There is a world of numbers, hiding behind letters, inside computers, this is what stimulates my work. I am currently employed in IT risk management within the financial industry, running a team of technical risk assessors. Prior to this, I spent 5 years in the world of professional penetration testing. I focused my career evolution on assisting large scale projects actually implement secure development practices. This included teaching developers how to write secure code. For OWASP, I was the project leader for JBroFuzz and used to chair the Global Industry Committee. I am on the Application Security Advisory Board of the (ISC)2. My academic qualifications include a PhD in information security, designing routing protocols for ad-hoc networks. I am a certified scrum master and hold the CISSP certification.

Det här avsnittet är hämtat från ett öppet RSS-flöde och publiceras inte av Podme. Det kan innehålla reklam.

Avsnitt(191)

ep2024-12 Tanya Janca: Happy Holidays are Secure Code

ep2024-12 Tanya Janca: Happy Holidays are Secure Code

Some production issues caused this one to slip to December so the intro is a bit off but this is still a great episode. So, learn some lessons on creating secure code from one of my favorite guests: T...

23 Dec 20241h

ep2024-10 Don't be Scared, It's just a Pen Test with Brad Causey

ep2024-10 Don't be Scared, It's just a Pen Test with Brad Causey

There's no reason to be scared about a pen test - especially when it's run by a professional like Brad Causey. I catch up with Brad in this episode to discuss what's recently changed in pen testing in...

31 Okt 202437min

ep2024-09 Threat Modeling with Takaharu

ep2024-09 Threat Modeling with Takaharu

What happens when you get interested in Threat Modeling and you want to share. For some, that means you do one work shop, then another, then another. What happens when you start down this path. Takaha...

25 Sep 202436min

ep2024-08 OWASP Projects Roundup

ep2024-08 OWASP Projects Roundup

The August episode is a review of projects from a recent OWASP project showcase. We talk to the leaders of the OWASP pytm, OWASP Developer Guide, OWASP State of AppSec Survey Project. Get up on the la...

30 Aug 202436min

ep2024-07 Safety belts for AppSec with Lisa Plaggemier

ep2024-07 Safety belts for AppSec with Lisa Plaggemier

After a long and unplanned pause, the OWASP podast is back with a home run of an episode. We have Lisa Plaggemier as our guest who reprises her eloquent keynote topic from AppSec DC. All hope isn't lo...

12 Juli 202432min

ep2023-09  Vulnerable Data Gathering for AI with Arturo Buanzo Busleiman

ep2023-09 Vulnerable Data Gathering for AI with Arturo Buanzo Busleiman

After getting a ping from an old friend about a potential new OWASP project, I had to bring him on as a guest. He's got an interesting idea around potential vulnerabilities in web crawlers which just ...

2 Okt 202332min

ep2023-08 Finding Next Gen Cybersecurity Professionals with Brad Causey

ep2023-08 Finding Next Gen Cybersecurity Professionals with Brad Causey

For years we've heard talk about a shortage of cybersecurity professionals so what can be done about that? In this episode, I speak to Brad Causey who has taken one approach he's found successful. We ...

31 Aug 202332min

ep2023-07 What's Audit got to do with IT

ep2023-07 What's Audit got to do with IT

In this episode we talk with Zain Haq and take a leap and bound over the first and second line to discover more about the third line - internal audit. We discover answers to a number of questions: Wha...

31 Juli 202333min

Populärt inom Teknik

uppgang-och-fall
market-makers
skogsforum-podcast
rss-uppgang-och-fall
rss-elektrikerpodden
rss-laddstationen-med-elbilen-i-sverige
 och-bilen-gar-bra
elbilsveckan
natets-morka-sida
rss-en-ai-till-kaffet
developers-mer-an-bara-kod
bosse-bildoktorn-och-hasse-p
rss-veckans-ai
bli-saker-podden
rss-fabriken-2
rss-upplyst-entreprenordirektor
rss-jonas-jaani-podcast
rss-milpodden
hej-bruksbil
garagehang