
Sign up to save your podcasts
Or


Penetration tests provide a measuring stick for security, but are you missing out on additional value? James discusses ways to use the pen test results to get more value out of a penetration test.
James will be providing a free webcast regarding Penetration Testing for Application Teams on March 18th, 2016. Here is the registration link: https://attendee.gototraining.com/r/3147075330537789954
For more info go to https://www.developsec.com or follow us on twitter (@developsec).
Presented by Jardine Software Inc. (https://www.jardinesoftware.com)
Jardine Software provides application security consulting and training to add value to your application security program. Contact us today to see how we can help.
Send us Fan Mail
For more info go to https://www.developsec.com or follow us on X (@developsec).
The DevelopSec podcast is brought to you by Jardine Software Inc.
James discusses what authentication is and some things to look out for.
For more info go to https://www.developsec.com or follow us on twitter (@developsec).
Presented by Jardine Software Inc. (https://www.jardinesoftware.com)
Jardine Software provides application security consulting and training to add value to your application security program. Contact us today to see how we can help.
Send us Fan Mail
For more info go to https://www.developsec.com or follow us on X (@developsec).
The DevelopSec podcast is brought to you by Jardine Software Inc.
In this episode, James Jardine talks about some of the things you need to consider when trying to implement a static analysis program. It is more than just a tool you drop in. To build a successful program there are other considerations.
For more info go to https://www.developsec.com or follow us on twitter (@developsec).
Presented by Jardine Software Inc. (https://www.jardinesoftware.com)
Jardine Software provides application security consulting and training to add value to your application security program. Contact us today to see how we can help.
Send us Fan Mail
For more info go to https://www.developsec.com or follow us on X (@developsec).
The DevelopSec podcast is brought to you by Jardine Software Inc.
James Jardine discusses CSRF chaining, using the combination of multiple CSRF requests to perform a task. Typically we believe that CSRF can only be done with one request, but with a little javascript it is possible to execute multiple requests. Listen in for more information.
For more info go to https://www.developsec.com or follow us on twitter (@developsec).
Presented by Jardine Software Inc. (https://www.jardinesoftware.com)
Send us Fan Mail
For more info go to https://www.developsec.com or follow us on X (@developsec).
The DevelopSec podcast is brought to you by Jardine Software Inc.
In this episode, James talks about what CSRF is, why it is a risk, and different ways to protect against it. CSRF is #8 on the OWASP Top 10 https://www.owasp.org/index.php/Top_10_2013-A8-Cross-Site_Request_Forgery_%28CSRF%29
Want to learn more about application security? Check out https://www.developsec.com. Follow us at @developsec on twitter.
Send us Fan Mail
For more info go to https://www.developsec.com or follow us on X (@developsec).
The DevelopSec podcast is brought to you by Jardine Software Inc.
James discusses Open Redirects, or on the OWASP Top 10 what is referred to as Unvalidated Redirects and Forwards (https://www.owasp.org/index.php/Top_10_2013-A10-Unvalidated_Redirects_and_Forwards) This is an introduction to what an Open Redirect is, why it is an issue, how to protect against it and how to test for it.
Send us Fan Mail
For more info go to https://www.developsec.com or follow us on X (@developsec).
The DevelopSec podcast is brought to you by Jardine Software Inc.
James discusses Hacking, what is it, why is it important. It is more than what you see in the media of the bad guys hacking computers. It is a curiosity, a hobby, an interesting in pushing limits. Some amazing things have come out of hacking. Check out this episode for more ramblings.
Send us Fan Mail
For more info go to https://www.developsec.com or follow us on X (@developsec).
The DevelopSec podcast is brought to you by Jardine Software Inc.
James discussing some things to consider this holiday season when searching for that perfect gift. It is important to understand the privacy policy (what is collected and how it is used) as well as the technologies the gift uses (Bluetooth, wifi, etc). This discussion addresses both consumers and the companies that create these gifts.
For more info go to https://www.developsec.com or follow us on twitter (@developsec).
Send us Fan Mail
For more info go to https://www.developsec.com or follow us on X (@developsec).
The DevelopSec podcast is brought to you by Jardine Software Inc.
James Jardine provides an overview of Dynamic Analysis and why it is important. Like any automation, there are pros and cons. Listen to find out why dynamic analysis is useful.
Some links to some dynamic analysis options that are available:
WhiteHat Security (http://www.whitehatsec.com)
HP - Web Inspect (http://www8.hp.com/us/en/software-solutions/webinspect-dynamic-analysis-dast/)
IBM App Scan (http://www-03.ibm.com/software/products/en/appscan)
Veracode (http://www.veracode.com)
Acunetix (https://www.acunetix.com/)
Send us Fan Mail
For more info go to https://www.developsec.com or follow us on X (@developsec).
The DevelopSec podcast is brought to you by Jardine Software Inc.
Join James Jardine as he discusses what Response Splitting/Header Injection is and how it works. He also discusses how ASP.Net helps defend against this attack.
This is a quick overview of the vulnerability and a great starting point for anyone learning security concepts.
Send us Fan Mail
For more info go to https://www.developsec.com or follow us on X (@developsec).
The DevelopSec podcast is brought to you by Jardine Software Inc.
From the publisher's feed
Curious about application security? Want to learn how to detect security vulnerabilities and protect your application. We discuss different topics and provide valuable insights into the world of…