
Sign up to save your podcasts
Or


CMS platforms are an easy way to get content to the internet, but we still have to consider security. James talks about some of the concerns and things to think about when thinking about these security features. For a more details, check out the blog post at https://www.developsec.com.
Send us Fan Mail
For more info go to https://www.developsec.com or follow us on X (@developsec).
The DevelopSec podcast is brought to you by Jardine Software Inc.
I came across an interesting tweet https://twitter.com/suffert/status/567486188383379456 depicting a good example of a black list that didn't quite cover everything I think they wanted too. This episode discusses the difference between black and white lists and some of the things to watch out for.
Send us Fan Mail
For more info go to https://www.developsec.com or follow us on X (@developsec).
The DevelopSec podcast is brought to you by Jardine Software Inc.
James talks about the need for developers, QA, business analysts and project managers to understand the type of application they are creating and the requirements around sensitive data.
Reference Links from the podcast:
http://www.njleg.state.nj.us/2014/Bills/S1000/562_R1.PDF
http://laws.flrules.org/2014/189
Send us Fan Mail
For more info go to https://www.developsec.com or follow us on X (@developsec).
The DevelopSec podcast is brought to you by Jardine Software Inc.
James talks about the need for developers, QA, business analysts and project managers to understand the type of application they are creating and the requirements around sensitive data.
Reference Links from the podcast:
http://www.njleg.state.nj.us/2014/Bills/S1000/562_R1.PDF
http://laws.flrules.org/2014/189
I discuss the lessons learned from the recent Moonpig security disclosure. This is full of information for a developer or QA tester. For more information, visit https://www.developsec.com
Send us Fan Mail
For more info go to https://www.developsec.com or follow us on X (@developsec).
The DevelopSec podcast is brought to you by Jardine Software Inc.
I discuss the lessons learned from the recent Moonpig security disclosure. This is full of information for a developer or QA tester. For more information, visit https://www.developsec.com
Are you looking to test our your security skills? There are lots of targets that are freely available to you that can be quite helpful. The good news is you won't be getting in trouble for hacking these applications. Here is a short list of some of the targets that exist for you to practice your web hacking skills.
Vulnerable Apps:
hackazon - http://www.ntobjectives.com/hackazon/
bWAPP - http://sourceforge.net/projects/bwapp/files/bee-box/
webgoat - https://www.owasp.org/index.php/Category:OWASP_WebGoat_Project
DVWA - http://sourceforge.net/projects/dvwa/
Mutillidae - http://sourceforge.net/projects/mutillidae/
Send us Fan Mail
For more info go to https://www.developsec.com or follow us on X (@developsec).
The DevelopSec podcast is brought to you by Jardine Software Inc.
Are you looking to test our your security skills? There are lots of targets that are freely available to you that can be quite helpful. The good news is you won't be getting in trouble for hacking these applications. Here is a short list of some of the targets that exist for you to practice your web hacking skills.
Vulnerable Apps:
hackazon - http://www.ntobjectives.com/hackazon/
bWAPP - http://sourceforge.net/projects/bwapp/files/bee-box/
webgoat - https://www.owasp.org/index.php/Category:OWASP_WebGoat_Project
DVWA - http://sourceforge.net/projects/dvwa/
Mutillidae - http://sourceforge.net/projects/mutillidae/
No matter what size company you are, sooner or later you will be subject to some form of security assessment. Whether that is a penetration test, architecture review, code review or some other assessment. It is important to be prepared. Have the documentation needed when the engagement starts. Most importantly, be honest to any questions and don't try and hide things. The point is to get an accurate view of the security landscape to better help the company's risk position. James talks about all this and more in this episode.
Send us Fan Mail
For more info go to https://www.developsec.com or follow us on X (@developsec).
The DevelopSec podcast is brought to you by Jardine Software Inc.
No matter what size company you are, sooner or later you will be subject to some form of security assessment. Whether that is a penetration test, architecture review, code review or some other assessment. It is important to be prepared. Have the documentation needed when the engagement starts. Most importantly, be honest to any questions and don't try and hide things. The point is to get an accurate view of the security landscape to better help the company's risk position. James talks about all this and more in this episode.
From the publisher's feed
Curious about application security? Want to learn how to detect security vulnerabilities and protect your application. We discuss different topics and provide valuable insights into the world of…