Absolute AppSec

Episode 173 - Enumeration Attacks!


Listen Later

Yet ANOTHER episode of Absolute AppSec with Seth and Ken! User enumeration vulnerabilities are the order of the day. Seth digs in on an interesting #talesfromconsulting where security questions, and the different way they appeared for real users and invalid users, revealed valid user accounts on an application. Further enumeration flaws using WAF bypasses in production systems. A story from Ken on a case where an application only checked that password-reset token was valid, but not tied to an account, allowing for unauthorized password reset of _any_ user account.
...more
View all episodesView all episodes
Download on the App Store

Absolute AppSecBy Ken Johnson and Seth Law

  • 4.9
  • 4.9
  • 4.9
  • 4.9
  • 4.9

4.9

17 ratings


More shows like Absolute AppSec

View all
Stuff You Should Know by iHeartPodcasts

Stuff You Should Know

78,688 Listeners

Planet Money by NPR

Planet Money

30,609 Listeners

Risky Business by Risky Business Media

Risky Business

371 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,077 Listeners

Application Security Weekly (Audio) by Mike Shema

Application Security Weekly (Audio)

13 Listeners