Daniel Ramsbrock -- Web Application Pen Testing – Part 2 episode artwork

EPISODE · Oct 18, 2016 · 31 MIN

Daniel Ramsbrock -- Web Application Pen Testing – Part 2

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

Part two follows Daniel Ramsbrock into the practical workflow of a web application penetration test. He joins Chris and Robert to move from reconnaissance into active testing, explaining credentials, intercepting proxies, attack recording, automated scanners, and the human judgment required to interpret results. The conversation covers authorization failures, false positives, reporting, remediation, and retesting, then broadens into compliance and the feedback loops mature organizations build between testers and development teams. Daniel also offers a learning path through vulnerable applications, training, certifications, bug bounties, books, and hands-on practice. The episode makes clear that tools assist a penetration tester, but disciplined reasoning and communication create the lasting security improvement.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Daniel Ramsbrock:→ Daniel Ramsbrock on LinkedInMentioned in this episode:→ Burp Suite→ HCL AppScan→ OWASP WebGoat→ GIAC GWAPT→ SANS SEC542→ Bugcrowd→ The Web Application Hacker’s Handbook→ Kali LinuxFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Continuing the web penetration testing process01:54 Why testers need individual credentials04:21 Moving from reconnaissance to active attack05:41 Intercepting proxies and recording traffic07:34 Choosing which attacks to attempt09:20 Where automated scanners fit10:27 Human judgment during active testing11:40 Finding authorization failures12:40 Interpreting false positives13:47 Reporting findings and remediation16:48 Retesting and proving fixes18:53 Compliance versus meaningful security20:44 Building feedback loops with development22:20 Learning web application penetration testing26:00 Bug bounties as controlled practice28:11 Books and hands-on resources30:52 Final advice

Episode metadata supplied by the publisher feed · Published Oct 18, 2016

Embed this episode

Part two follows Daniel Ramsbrock into the practical workflow of a web application penetration test. He joins Chris and Robert to move from reconnaissance into active testing, explaining credentials, intercepting proxies, attack recording, automated scanners, and the human judgment required to interpret results. The conversation covers authorization failures, false positives, reporting, remediation, and retesting, then broadens into compliance and the feedback loops mature organizations build...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Daniel Ramsbrock -- Web Application Pen Testing – Part 2

0:00 31:38

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 31 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on October 18, 2016.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!