Bjorn Kimminich -- The Joy of the Vulnerable Web: JuiceShop episode artwork

EPISODE · Nov 19, 2018 · 36 MIN

Bjorn Kimminich -- The Joy of the Vulnerable Web: JuiceShop

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

Can an intentionally broken online shop help change an organization’s security culture? OWASP Juice Shop creator Björn Kimminich explains how a realistic application full of vulnerabilities gives developers, testers, and managers a shared way to experience security problems. He traces the project’s origins, describes how real incidents become challenges, and discusses the community that keeps adding new ideas. Chris asks about management awareness demonstrations, capture-the-flag events, deployment options, and the range of challenge difficulty. They also explore what was new in Juice Shop 8 and where Björn hoped to take the project next. The conversation shows how hands-on exploration can connect an abstract vulnerability to something people recognize in their own software, without requiring everyone to begin as an expert.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Björn Kimminich:→ Björn Kimminich on GitHub→ OWASP Juice ShopMentioned in this episode:→ Juice Shop project website→ Juice Shop source code→ Node.jsFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Learning security with Björn Kimminich and Juice Shop01:37 Björn’s path from development into security03:41 Why Juice Shop was created04:51 What makes an intentionally broken application05:41 Turning real vulnerabilities into challenges07:42 The community behind the project11:04 Who uses Juice Shop and why13:08 Security awareness demonstrations for managers14:56 How managers respond to seeing attacks17:04 Running Juice Shop for capture-the-flag events19:31 Deployment options20:29 Trying the demo instance23:24 Exploring with browser developer tools25:17 What was new in Juice Shop 827:26 Challenges for different skill levels29:03 The project’s future direction33:42 Sharing ideas and getting involved

Episode metadata supplied by the publisher feed · Published Nov 19, 2018

Embed this episode

Can an intentionally broken online shop help change an organization’s security culture? OWASP Juice Shop creator Björn Kimminich explains how a realistic application full of vulnerabilities gives developers, testers, and managers a shared way to experience security problems. He traces the project’s origins, describes how real incidents become challenges, and discusses the community that keeps adding new ideas. Chris asks about management awareness demonstrations, capture-the-flag events, depl...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Bjorn Kimminich -- The Joy of the Vulnerable Web: JuiceShop

0:00 36:30

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 36 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on November 19, 2018.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!