PodParley PodParley
Hacking with James Kettle

EPISODE · Jun 3, 2020 · 28 MIN

Hacking with James Kettle

from Easy Prey · host Easy Prey

Have you ever wondered how hackers find vulnerabilities and how companies can find and fix their own? You will find out today! On average 30,000 new websites are hacked every day. Our guest for this episode is James Kettle. James is the Director of Research at PortSwigger Web Security where he explores new ways to attack websites and designs and refines vulnerability detection techniques for the Burp Suites scanner.  James shares his hacking experience and hard work helping companies keep their websites secure from all the crazy stuff going on out there.  On today's episode, James shares his expertise to help you be more aware of possible red flags and prevention measures to take to protect yourself and your website. Show Notes: [00:40] - When James was at university he saw that Google said they would pay anybody that could hack their website. He thought that sounded like fun and spent a huge amount of time doing that.  [01:02] - Now James works at PortSwigger and researches new techniques to hack websites.  [01:11] - Bounty programs are where a company wants to make sure their product or website doesn't get hacked by malicious people so they go out and publicly say that anyone is welcome to try and hack their website. If you are successful and you don't do any damage, but you tell them how you did it they will pay you for it and then fix it.  [03:45] - Pen testing is the classic approach to securing your website where you pay a consultant to spend one or two weeks trying to hack your website.  [05:14] - It is totally worth it to get that third party view. Developers often can't find problems with their own products.  [06:13] - If you want to find a vulnerability on a website you need to use an attack technique.   [07:15] - These days they see a lot of cross-site scripting vulnerabilities and it's the most common one they see.  [07:37] - One of the most common causes of high impact breaches is access control issues.   [08:45] - James shares the biggest data breach they were able to do during their testing.  [10:31] - Try to use a framework whenever possible, because it makes things like sequel injection less likely to happen.   [11:01] - The standard approach after you make the website is to try to get someone else to look at it.  [11:27] - With Wordpress, it is very important to keep it up to date, install as few plug-ins as possible, and choose a good password.  [14:08] - Use as few browser extensions as possible to avoid possible malware issues.  [15:25] - Most people are not being personally targeted by hackers so the threats that most people need to watch out for are things that can be automated.  [16:10] - If you are using the same password on multiple websites you are going to get hacked.  [17:02] - A common misconception is that if you have a strong unique password then it doesn't matter if you reuse it.  [18:03] - James uses websites with the assumption that all the data I give this website is going to end up public at some point.  [18:45] - Provide the minimum information possible.  [20:19] - James shares his all-time favorite story.  [22:33] - If an entity builds their security around detecting when people are attacking them then running a bug bounty would be harmful because they have no idea who is legitimate or hostile. If your website is on the internet, it is being attacked. [23:35] - When you are being attacked, it is important to know that it most likely isn't personal. Thanks for joining us on Easy Prey. Be sure to subscribe to our podcast on iTunes and leave a nice review.  Links and Resources: Podcast Web Page Facebook Page whatismyipaddress.com Easy Prey on Instagram Easy Prey on Twitter Easy Prey on LinkedIn Easy Prey on YouTube Easy Prey on Pinterest Have I Been Pwned PortSwigger Burp Suite Web Security Academy BurpSuite on Twitter

NOW PLAYING

Hacking with James Kettle

0:00 28:31

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

Français avec Pierre Pierre - Français avec Pierre Learn French listening to French podcasts made by French teacher Pierre. You can often have the podcast transcripts in the BLOG http://francaisavecpierre.com . Whenever there is a transcript available, I will put the blog post URL in the podcast episode description, please check it out. You can learn and improve your French listening to the podcasts with lots of interesting topics, French lessons and a lot more. Learn French the fun and easy way!Aprender francés es muy fácil con los podcasts en francés de Pierre. Muchos de ellos vienen con la trasncripción, así que busca la url del post del blog http://francaisavecpierre.com en la descripción del podcast cuando esté disponible. Aprende y mejora tu francés con estas clases de francés de la mano de Pierre, profesor de francés en las Escuelas Oficiales de Idiomas de Madrid.Apprendre le français c’est facile avec Pierre. Ecoute ces podcasts en français et regarde la transcription quand c’est disponible (je m TomCattt Thomas Patton From the beginning music has prowled with accordion lessons at a young age, followed by sax, blues harp and more recently piano, vocals, song writing and recording. Thomas Patton (AKA TomCattt) credits his mother for his stage name "TomCattt” as she was big on nick names for those she held close to her heart. TomCattt's music is best described as easy listening and sometimes retro, yet with a contemporary mix and feel. Accompanied by the creative tracks of a number of gifted musicians, his first album Hiiyaaaaaaaaaaa inspires imagination and finds a way to impress with a unique vocal sound, compelling harmony and gripping melody. The lyrical content is in fact a living reflection of this artists emotional journey that followed leaving love, finding a new love only to lose love once again. Hiiyaaaaaaaaaaa was released on June 1st, 2013 and all are invited to Soundcloud, Bandcamp, ReverbNation and Cdbaby where "A Question" is free download and to enjoy TomCattt's website tomcattt.com. Thriving Mom Tribe | Practical Health Solutions for Moms Lindsay Rattay, Nutritional Therapy Practitioner The Go-To Podcast for all Moms who want to have a Thriving home. Do you struggle to find the balance between holistic health and living in the world?Are you tired of trying every diet yourself and still not feeling good?Do you find yourself researching for hours how to find the best remedy for your child’s sickness but end up feeling defeated?You want to be metabolically healthy but don’t know where to start?Do you wish you could feel confident in how you feed your family during the week knowing that you have to eat out because life is busy?You just enjoy going to a restaurant and don’t want to feel guilty about it?Do you want a cookie and a healthy salad?I am Lindsay Rattay, I am so excited that you are here on the Thriving Mom Tribe Podcast. I remember being the mom who researched everything from nutrition to exercise. To feeling tired and depressed. Trying to find the balance of wanting more holistic options for my family while still raising busy kids. But I discovered easy AI Daily News Podcast Really Easy AI AI Daily News: Your premier source for cutting-edge artificial intelligence updates! Dive into the world of machine learning, deep learning, and data science with our daily tech briefings. From neural networks to natural language processing, we cover groundbreaking AI research, innovative applications, and industry trends. Explore the latest in computer vision, robotics, autonomous systems, and the Internet of Things. Stay informed on AI ethics, machine learning algorithms, and the transformative impact of AI on business, healthcare, and society. https://www.youtube.com/@AINewsFresh
URL copied to clipboard!