EPISODE · Nov 19, 2018 · 36 MIN
Bjorn Kimminich -- The Joy of the Vulnerable Web: JuiceShop
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
Can an intentionally broken online shop help change an organization’s security culture? OWASP Juice Shop creator Björn Kimminich explains how a realistic application full of vulnerabilities gives developers, testers, and managers a shared way to experience security problems. He traces the project’s origins, describes how real incidents become challenges, and discusses the community that keeps adding new ideas. Chris asks about management awareness demonstrations, capture-the-flag events, deployment options, and the range of challenge difficulty. They also explore what was new in Juice Shop 8 and where Björn hoped to take the project next. The conversation shows how hands-on exploration can connect an abstract vulnerability to something people recognize in their own software, without requiring everyone to begin as an expert.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Björn Kimminich:→ Björn Kimminich on GitHub→ OWASP Juice ShopMentioned in this episode:→ Juice Shop project website→ Juice Shop source code→ Node.jsFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Learning security with Björn Kimminich and Juice Shop01:37 Björn’s path from development into security03:41 Why Juice Shop was created04:51 What makes an intentionally broken application05:41 Turning real vulnerabilities into challenges07:42 The community behind the project11:04 Who uses Juice Shop and why13:08 Security awareness demonstrations for managers14:56 How managers respond to seeing attacks17:04 Running Juice Shop for capture-the-flag events19:31 Deployment options20:29 Trying the demo instance23:24 Exploring with browser developer tools25:17 What was new in Juice Shop 827:26 Challenges for different skill levels29:03 The project’s future direction33:42 Sharing ideas and getting involved
Embed this episode
What this episode covers
Can an intentionally broken online shop help change an organization’s security culture? OWASP Juice Shop creator Björn Kimminich explains how a realistic application full of vulnerabilities gives developers, testers, and managers a shared way to experience security problems. He traces the project’s origins, describes how real incidents become challenges, and discusses the community that keeps adding new ideas. Chris asks about management awareness demonstrations, capture-the-flag events, depl...
Ready to play
Bjorn Kimminich -- The Joy of the Vulnerable Web: JuiceShop
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.