In this episode, Kevin Johnson and James Jardine talk about a number of different flaws that many penetration testers and application developers miss. They talk about how username harvesting and password resets can cause issues. They also discuss the exposure that APIs and web services bring to applications.