DevelopSec: Developing Security Awareness

DevelopSec: Developing Security Awareness

By Jardine Software Inc.NewsTechnologyEducationTech News
Download on the App Store

DevelopSec: Developing Security Awareness episodes

  • Ep. 23: 3rd Party CMS Security Thoughts

    CMS platforms are an easy way to get content to the internet, but we still have to consider security.   James talks about some of the concerns and things to think about when thinking about these security features.  For a more details, check out the blog post at https://www.developsec.com.

    Send us Fan Mail

    For more info go to https://www.developsec.com or follow us on X (@developsec).

    The DevelopSec podcast is brought to you by Jardine Software Inc. 

    22 min
  • Ep. 22: Black lists vs. White Lists

    I came across an interesting tweet https://twitter.com/suffert/status/567486188383379456  depicting a good example of a black list that didn't quite cover everything I think they wanted too.    This episode discusses the difference between black and white lists and some of the things to watch out for.

    Send us Fan Mail

    For more info go to https://www.developsec.com or follow us on X (@developsec).

    The DevelopSec podcast is brought to you by Jardine Software Inc. 

    17 min
  • Ep. 21: Sensitive Data and Storage

    James talks about the need for developers, QA, business analysts and project managers to understand the type of application they are creating and the requirements around sensitive data. 

     

    Reference Links from the podcast:

    http://www.njleg.state.nj.us/2014/Bills/S1000/562_R1.PDF

    http://laws.flrules.org/2014/189

    Send us Fan Mail

    For more info go to https://www.developsec.com or follow us on X (@developsec).

    The DevelopSec podcast is brought to you by Jardine Software Inc. 

    20 min
  • Sensitive Data and Storage

    James talks about the need for developers, QA, business analysts and project managers to understand the type of application they are creating and the requirements around sensitive data. 

     

    Reference Links from the podcast:

    http://www.njleg.state.nj.us/2014/Bills/S1000/562_R1.PDF

    http://laws.flrules.org/2014/189

    20 min
  • EP. 20: MoonPig Take-aways

    I discuss the lessons learned from the recent Moonpig security disclosure.  This is full of information for a developer or QA tester.   For more information, visit https://www.developsec.com

    Send us Fan Mail

    For more info go to https://www.developsec.com or follow us on X (@developsec).

    The DevelopSec podcast is brought to you by Jardine Software Inc. 

    24 min
  • EP. 20: MoonPig Take-aways

    I discuss the lessons learned from the recent Moonpig security disclosure.  This is full of information for a developer or QA tester.   For more information, visit https://www.developsec.com

    24 min
  • Ep. 19: Target Environments

    Are you looking to test our your security skills?  There are lots of targets that are freely available to you that can be quite helpful.  The good news is you won't be getting in trouble for hacking these applications.  Here is a short list of some of the targets that exist for you to practice your web hacking skills.

    Vulnerable Apps:

    hackazon - http://www.ntobjectives.com/hackazon/

    bWAPP - http://sourceforge.net/projects/bwapp/files/bee-box/

    webgoat - https://www.owasp.org/index.php/Category:OWASP_WebGoat_Project

    DVWA - http://sourceforge.net/projects/dvwa/

    Mutillidae - http://sourceforge.net/projects/mutillidae/

    Send us Fan Mail

    For more info go to https://www.developsec.com or follow us on X (@developsec).

    The DevelopSec podcast is brought to you by Jardine Software Inc. 

    21 min
  • Ep. 19: Target Environments

    Are you looking to test our your security skills?  There are lots of targets that are freely available to you that can be quite helpful.  The good news is you won't be getting in trouble for hacking these applications.  Here is a short list of some of the targets that exist for you to practice your web hacking skills.

    Vulnerable Apps:

    hackazon - http://www.ntobjectives.com/hackazon/

    bWAPP - http://sourceforge.net/projects/bwapp/files/bee-box/

    webgoat - https://www.owasp.org/index.php/Category:OWASP_WebGoat_Project

    DVWA - http://sourceforge.net/projects/dvwa/

    Mutillidae - http://sourceforge.net/projects/mutillidae/

    21 min
  • Ep. 18: Planning for an Assessment

    No matter what size company you are, sooner or later you will be subject to some form of security assessment.  Whether that is a penetration test, architecture review, code review or some other assessment.  It is important to be prepared.  Have the documentation needed when the engagement starts.  Most importantly, be honest to any questions and don't try and hide things.  The point is to get an accurate view of the security landscape to better help the company's risk position.  James talks about all this and more in this episode.

    Send us Fan Mail

    For more info go to https://www.developsec.com or follow us on X (@developsec).

    The DevelopSec podcast is brought to you by Jardine Software Inc. 

    19 min
  • Ep. 18: Planning for an Assessment

    No matter what size company you are, sooner or later you will be subject to some form of security assessment.  Whether that is a penetration test, architecture review, code review or some other assessment.  It is important to be prepared.  Have the documentation needed when the engagement starts.  Most importantly, be honest to any questions and don't try and hide things.  The point is to get an accurate view of the security landscape to better help the company's risk position.  James talks about all this and more in this episode.

    19 min

About DevelopSec: Developing Security Awareness

From the publisher's feed

Curious about application security? Want to learn how to detect security vulnerabilities and protect your application. We discuss different topics and provide valuable insights into the world of…