Björn Kimminich — JuiceShop — 5 minute AppSec episode artwork

EPISODE · May 26, 2019 · 4 MIN

Björn Kimminich — JuiceShop — 5 minute AppSec

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

What makes OWASP Juice Shop useful to developers when many intentionally vulnerable applications feel dated? Project creator Björn Kimminich explains that he built Juice Shop because older training targets did not represent modern front ends, REST APIs, or the technologies his students used. The project turns web vulnerabilities, business-logic flaws, validation failures, and design problems into hands-on challenges with a scoreboard and gamification. Teams can use it for developer training, awareness demonstrations, capture-the-flag events, security-tool testing, and customized management exercises. This short introduction shows why learning through a realistic application can make the OWASP Top 10 and other security weaknesses more concrete, memorable, and relevant to everyday development work.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Björn Kimminich:→ Björn Kimminich on LinkedIn→ OWASP Juice ShopMentioned in this episode:→ OWASP Juice Shop→ OWASP Top 10→ Open Security SummitFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 What is OWASP Juice Shop?00:19 A modern vulnerable application for developers01:36 Challenges, gamification, and hands-on learning03:01 Training, CTFs, and management demonstrations04:20 Continue with the full Juice Shop interview

Episode metadata supplied by the publisher feed · Published May 26, 2019

Embed this episode

What makes OWASP Juice Shop useful to developers when many intentionally vulnerable applications feel dated? Project creator Björn Kimminich explains that he built Juice Shop because older training targets did not represent modern front ends, REST APIs, or the technologies his students used. The project turns web vulnerabilities, business-logic flaws, validation failures, and design problems into hands-on challenges with a scoreboard and gamification. Teams can use it for developer training, ...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Björn Kimminich — JuiceShop — 5 minute AppSec

0:00 4:45

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 4 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on May 26, 2019.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!