EPISODE · Mar 26, 2026 · 28 MIN
Episode 174: Web Application Penetration Testing Tools & Techniques with Jordan
from The Cyber Threat Perspective · host SecurIT360
In Episode 174, host Brad Causey is joined by guest Jordan Natter for a practical, tool-focused conversation on web application penetration testing. Together they break down the essential tools and Burp Suite Pro extensions that make up a modern web app pen testing toolkit.Topics covered include:Burp Suite Pro vs. OWASP ZAP — comparing capabilities, extensions, and use casesCSP Auditor — identifying unsafe Content Security Policy directivesJSON Web Token (JWT) extension — surfacing and tampering with JWTs in HTTP historyRetire.js — flagging outdated JavaScript libraries with known vulnerabilitiesCyberChef & JWT.io — encoding, decoding, and debugging tokensPostman & Swagger — API testing and documentation workflowsSQLMap — powerful SQL injection discovery (and why you should never run it in production)Proxy Forge — evading cloud-based WAFs and testing geo-blockingGraphQL Hunter — enumerating and testing GraphQL instancesHave a tool or extension you swear by? Drop it in the comments — Brad and Jordan want to hear from you!---Burp Suite is an integrated platform for attacking web applications. http://portswigger.net/burp/Blog: https://offsec.blog/Youtube: https://www.youtube.com/@cyberthreatpovTwitter: https://x.com/cyberthreatpovFollow Spencer on social ⬇Spencer's Links: https://spenceralessi.comWork with Us: https://securit360.com | Find vulnerabilities that matter, learn about how we do internal pentesting here.
Embed this episode
What this episode covers
In Episode 174, host Brad Causey is joined by guest Jordan Natter for a practical, tool-focused conversation on web application penetration testing. Together they break down the essential tools and Burp Suite Pro extensions that make up a modern web app pen testing toolkit. Topics covered include: Burp Suite Pro vs. OWASP ZAP — comparing capabilities, extensions, and use casesCSP Auditor — identifying unsafe Content Security Policy directivesJSON Web Token (JWT) extension — surfacing and tamp...
Ready to play
Episode 174: Web Application Penetration Testing Tools & Techniques with Jordan
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.