

Episode 108: New tales from the trenches!
Sep 18, 2024
Dive into the world of penetration testing with hands-on experiences at a financial institution, revealing how GraphQL challenges security. Discover the importance of securing JWTs and SMTP servers to prevent email vulnerabilities. Explore the complexities of API security and the advantages of certificate-based authentication for SSH. Learn about the risks institutions face from user enumeration and the need for robust identity safeguards. Finally, understand why a layered security strategy is essential, extending beyond just multi-factor authentication.
Chapters
Transcript
Episode notes
1 2 3 4 5 6
Intro
00:00 • 5min
Securing JWTs and SMTP Vulnerabilities
05:30 • 8min
Securing APIs and SSH: Challenges and Solutions
13:39 • 6min
Understanding Enumeration Vulnerabilities
20:08 • 7min
Identities at Risk: The Vulnerabilities of Institutions
26:46 • 6min
Enhancing Security: Beyond Multi-Factor Authentication
32:51 • 6min