EPISODE · Oct 18, 2016 · 31 MIN
Daniel Ramsbrock -- Web Application Pen Testing – Part 2
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
Part two follows Daniel Ramsbrock into the practical workflow of a web application penetration test. He joins Chris and Robert to move from reconnaissance into active testing, explaining credentials, intercepting proxies, attack recording, automated scanners, and the human judgment required to interpret results. The conversation covers authorization failures, false positives, reporting, remediation, and retesting, then broadens into compliance and the feedback loops mature organizations build between testers and development teams. Daniel also offers a learning path through vulnerable applications, training, certifications, bug bounties, books, and hands-on practice. The episode makes clear that tools assist a penetration tester, but disciplined reasoning and communication create the lasting security improvement.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Daniel Ramsbrock:→ Daniel Ramsbrock on LinkedInMentioned in this episode:→ Burp Suite→ HCL AppScan→ OWASP WebGoat→ GIAC GWAPT→ SANS SEC542→ Bugcrowd→ The Web Application Hacker’s Handbook→ Kali LinuxFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Continuing the web penetration testing process01:54 Why testers need individual credentials04:21 Moving from reconnaissance to active attack05:41 Intercepting proxies and recording traffic07:34 Choosing which attacks to attempt09:20 Where automated scanners fit10:27 Human judgment during active testing11:40 Finding authorization failures12:40 Interpreting false positives13:47 Reporting findings and remediation16:48 Retesting and proving fixes18:53 Compliance versus meaningful security20:44 Building feedback loops with development22:20 Learning web application penetration testing26:00 Bug bounties as controlled practice28:11 Books and hands-on resources30:52 Final advice
Embed this episode
What this episode covers
Part two follows Daniel Ramsbrock into the practical workflow of a web application penetration test. He joins Chris and Robert to move from reconnaissance into active testing, explaining credentials, intercepting proxies, attack recording, automated scanners, and the human judgment required to interpret results. The conversation covers authorization failures, false positives, reporting, remediation, and retesting, then broadens into compliance and the feedback loops mature organizations build...
Ready to play
Daniel Ramsbrock -- Web Application Pen Testing – Part 2
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.