Tanya Janca and Nicole Becher -- Hacking APIs and Web Services with DevSlop episode artwork

EPISODE · Sep 5, 2017 · 34 MIN

Tanya Janca and Nicole Becher -- Hacking APIs and Web Services with DevSlop

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

APIs may lack a visible interface, but that does not make them hidden or safe. Tanya Janca and Nicole Becher use OWASP DevSlop and its Pixi application to explain how developers and testers can learn API security hands-on. They cover HTTP fundamentals, authentication, rate limiting, proxies, curl, ZAP, and Burp Suite before showing how intentionally vulnerable applications turn those concepts into experiments. The conversation explores Pixi’s microservices, containerized design, planned capture-the-flag mode, and inspiration from OWASP Juice Shop and WebGoat. Tanya and Nicole also discuss the limits of automated scanners and the value of beginner-friendly CTFs. Their central recommendation is simple: interact with real APIs, observe the traffic, and practice breaking safe targets.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Tanya Janca and Nicole Becher:→ Tanya Janca on LinkedIn→ Nicole Becher on LinkedIn→ OWASP DevSlopMentioned in this episode:→ OWASP DevSlop→ Pixi→ OWASP ZAP→ Burp Suite→ OWASP Juice Shop→ OWASP WebGoat→ DockerFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Hacking APIs and web services with DevSlop02:15 Nicole Becher’s security origin story04:12 Learning AppSec through vulnerable applications06:04 APIs, web services, and HTTP basics08:27 Why an API is not invisible10:42 Discovering API traffic with a proxy12:30 Rate limiting and common API weaknesses17:15 Using curl, ZAP, and Burp Suite22:12 Pixi and the DevSlop application family24:05 Containers and future modules26:11 Building a capture-the-flag mode28:15 Scanner limitations and better test targets30:44 Why developers should try a CTF32:47 Hands-on learning at AppSec USA

Episode metadata supplied by the publisher feed · Published Sep 5, 2017

Embed this episode

APIs may lack a visible interface, but that does not make them hidden or safe. Tanya Janca and Nicole Becher use OWASP DevSlop and its Pixi application to explain how developers and testers can learn API security hands-on. They cover HTTP fundamentals, authentication, rate limiting, proxies, curl, ZAP, and Burp Suite before showing how intentionally vulnerable applications turn those concepts into experiments. The conversation explores Pixi’s microservices, containerized design, planned captu...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Tanya Janca and Nicole Becher -- Hacking APIs and Web Services with DevSlop

0:00 34:46

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 34 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on September 5, 2017.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!