SilverLining IL

SilverLining IL

Download on the App Store

SilverLining IL episodes

  • Episode 19: Understanding Cloud Attack Vectors

    Attendees

    Guest: Or Kamara

    Guest Title:  Senior team lead 

    Company:  Synk

    Abstract

    Cloud computing can bring interesting and new attack vectors. In this episode, we talk with Or Kamara, Senior team lead at Synk, about the Capital-one hacking and what can be learned from the event in order to better protect our networks. We will analyze the attack step by step and add mitigating controls that can help in preventing the next attack.

    Timing:

    0:35 Introducing our guest

    4:10 introducing the story the capital one hack 

    5:45 The phases of the Capital One hack

    7:50 The first misconfiguration - servers exposed to the internet unintentionally

    11:05 the SSRF vulnerability and understanding meta-data service

    19:38 Using API keys for browsing S3 and how to mitigate it

    26:00 things that Capital One did right and additional insights

    28:00 how should developers and IT 

    30:50 shifting from traditional security to new cloud security mindset

    36:00 summary and final words

    41 min
  • Episode 18: Testing Cloud Application

    Attendees

    Guest: Bar Hofesh

    Guest Title:  Co-Founder

    Company:  Neurolegion

    Abstract

    Application security is among the hardest things to get right. In this episode we are talking with Bar Hofesh from Neurolegion about the world of automated security testing - what are the challenges, what are the different stages of integration and delivery and how to perform each stage correctly.

    Timing:

    0:50 - introducing our guest

    2:58 - the need to automate security testing - the challenge of developing faster

    7:15 - so what is testing automation - describing the process - the code  integration stage

    13:50  - security testing the packing and delivery stage

    18:50 - testing live application stage

    20:20 - appsec finding strategy - what do when found an alert

    22:20 - Static analysis vs. dynamic analysis

    24:58 - emerging technologies - RASP, IAST

    30:50 - Is there still room for manual penetration testing?

    34:05 - summary and last words

    39 min
  • Episode 17: How to do penetration testing in cloud application

    Attendees

    Guest: Oz Avenstein

    Guest Title:  Founder

    Company:  Avensec

    Abstract

    Penetration tests are one of the strongest controls that we use. It is testing the overall resilience of our application and allows us to be more confident in our workloads. But in the cloud era, cloud applications pen testing needs to be coordinated with the providers. In this episode we talk with Oz Avenstein, an application security expert, about the challenges of cloud penetration testing and how to do it correctly.

    Timing:

    0.50 introducing our guest

    3.40 How is cloud penetration tests different from regular pen tests?

    5.01 elaborating about IaaS/PaaS particular pen test policies 

    8.45 pen testing SaaS applications 

    11.05 relaying on 3rd party pen testing

    12.02 cloud pen test considerations and phases

    17.35 the actual pen testing 

    21.20 the reporting phase

    23.40 incorporating pen test into applications development cycle 

    34:00 Summary and last words

     

    38 min
  • 021 Building the next generation of cloud services
    In this episode we talk with Eran Feigenbaum, CISO of Oracle cloud about the next generation of cloud services - how can we build cloud that is more secure,, immuned to miss-configuration and other pitfalls that are relevant to today's cloud services.
    27 min
  • 020 The dark side of Privacy
    In this episode we talk with Menny about Privacy - why it is so hard to define what exactly is privacy in the modern age, what people miss about the concepts of privacy and how this affects our everyday lives. This talk will make you laugh, will make you sad and definitely will make you think. We hope you will enjoy listening to it as much as we enjoyed recording it.
    53 min
  • 019 Understanding Cloud Attack Vectors
    In this episode we talk with Or Kamara, Senior team lead at Synk, about the Capital-one hacking and what can be learned from to better protect our networks. We will analyze the attack step by step and add mitigating controls that can help preventing the next attack.
    41 min
  • 018 Testing Cloud Application
    In this episode we are talking with Bar Hofesh from Neurolegion about the world of automated security testing - what are the challenges, what are the different stages of integration and delivery and how to perform each stage correctly.
    39 min
  • 017 How to do penetration testing in cloud application
    Penetration tests are one of the strongest controls that we use. It is testing the overall resilience of our application and allows us to be more confident in our workloads. But in the cloud era, cloud applications pen testing needs to be coordinated with the providers. In this episode, we talk with Oz Avenstein, an application security expert, about the challenges of cloud penetration testing and how to do it correctly.
    38 min

About SilverLining IL

From the publisher's feed

The podcast for Security Architecture