
Sign up to save your podcasts
Or


Attendees
Guest: Or Kamara
Guest Title: Senior team lead
Company: Synk
Abstract
Cloud computing can bring interesting and new attack vectors. In this episode, we talk with Or Kamara, Senior team lead at Synk, about the Capital-one hacking and what can be learned from the event in order to better protect our networks. We will analyze the attack step by step and add mitigating controls that can help in preventing the next attack.
Timing:
0:35 Introducing our guest
4:10 introducing the story the capital one hack
5:45 The phases of the Capital One hack
7:50 The first misconfiguration - servers exposed to the internet unintentionally
11:05 the SSRF vulnerability and understanding meta-data service
19:38 Using API keys for browsing S3 and how to mitigate it
26:00 things that Capital One did right and additional insights
28:00 how should developers and IT
30:50 shifting from traditional security to new cloud security mindset
36:00 summary and final words
Attendees
Guest: Bar Hofesh
Guest Title: Co-Founder
Company: Neurolegion
Abstract
Application security is among the hardest things to get right. In this episode we are talking with Bar Hofesh from Neurolegion about the world of automated security testing - what are the challenges, what are the different stages of integration and delivery and how to perform each stage correctly.
Timing:
0:50 - introducing our guest
2:58 - the need to automate security testing - the challenge of developing faster
7:15 - so what is testing automation - describing the process - the code integration stage
13:50 - security testing the packing and delivery stage
18:50 - testing live application stage
20:20 - appsec finding strategy - what do when found an alert
22:20 - Static analysis vs. dynamic analysis
24:58 - emerging technologies - RASP, IAST
30:50 - Is there still room for manual penetration testing?
34:05 - summary and last words
Attendees
Guest: Oz Avenstein
Guest Title: Founder
Company: Avensec
Abstract
Penetration tests are one of the strongest controls that we use. It is testing the overall resilience of our application and allows us to be more confident in our workloads. But in the cloud era, cloud applications pen testing needs to be coordinated with the providers. In this episode we talk with Oz Avenstein, an application security expert, about the challenges of cloud penetration testing and how to do it correctly.
Timing:
0.50 introducing our guest
3.40 How is cloud penetration tests different from regular pen tests?
5.01 elaborating about IaaS/PaaS particular pen test policies
8.45 pen testing SaaS applications
11.05 relaying on 3rd party pen testing
12.02 cloud pen test considerations and phases
17.35 the actual pen testing
21.20 the reporting phase
23.40 incorporating pen test into applications development cycle
34:00 Summary and last words
From the publisher's feed