
The OWASP Podcast Series
The OWASP Podcast Series is a recorded series of discussions with thought leaders and practitioners who are working on securing the future for coming generations.
Latest episodes

May 10, 2017 • 7min
Less than 10 Minutes Series: Defect Dojo Project
This segment of the "Less than 10 Minutes" series was recorded live at AppSec EU 2017 in Belfast. It is an update of the Defect Dojo Project with project lead Greg Anderson. The Defect Dojo is an open source vulnerability management tool that streamlines the testing process by offering templating, report generation, metrics, and baseline self-service tools.

May 10, 2017 • 9min
Less than 10 Minutes Series: Virtual Village Project
This segment of the "Less than 10 Minutes" series was recorded live at AppSec EU 2017 in Belfast. It is an update of the Virtual Village Project with project lead Evin Hernandez. The Virtual Village provides users with access to numerous operating system's Desktop as well as Servers. Users are able to create custom apps for other OWASP projects, as well as be able to request test environments , or honey pots , etc.

May 10, 2017 • 8min
Less than 10 Minutes Series: The Juice Shop Project
This segment of the "Less than 10 Minutes" series was recorded live at AppSec EU 2017 in Belfast. It is an update of the Juice Shop Project with project lead Bjoern Kimminich. The Juice Shop is an intentionally insecure webapp for security training, written entirely in Javascript which encompasses the entire OWASP Top Ten and other severe security flaws.
Bjoern Kimminich (Project Leader OWASP Juice Shop)
Personal Twitter: http://twitter.com/bkimminich
OWASP Juice Shop
Project Twitter: http://twitter.com/owasp_juiceshop
Project Wiki Page: https://www.owasp.org/index.php/OWASP_Juice_Shop_Project
Main Github Project: https://github.com/bkimminich/juice-shop
Juice Shop CTF-Extension Project: https://github.com/bkimminich/juice-shop-ctf

Mar 22, 2017 • 18min
AppSec EU 2017, Belfast Keynote Preview with Jaya Baloo
"Why does OWASP even exist? Why do we even have this idea of understanding common issues, common problems. There are resources to help us do it better next time. I feel we are not learning at the curve where we should be, considering the resources available to us." -- Jaya Baloo
As CISO of KPN, the largest telecom in the Netherlands, Jaya Baloo has a lot on her mind, but maybe not what you'd think. In this free wheeling discussion, we begin with what Jaya will be talking about during her keynote at AppSec EU 2017 in Belfast, and then move into cryptography, quantum technologies, and her concerns with the way software is currently built.

Mar 10, 2017 • 20min
Struts 2 Vulnerability Analysis
Brian Fox and Shannon Lietz talk about the recent announcement of the struts 2 vulnerability: What is it, how can it affect you, what you can do about it. You can view this broadcast as video on YouTube:
https://www.youtube.com/watch?v=EzRKOudJPtQ

Feb 18, 2017 • 21min
AppSec EU 2017 Belfast - What to Expect
In mid-May I'll be joining the organizing team of AppSec EU 2017 in Belfast for a week of security and DevOps sessions. Listen in as Gary Robinson, Michelle Simpson and Owen Pendlebury talk about what's planned for the week.

Feb 15, 2017 • 37min
Culture Hacker: How to Herd CATTs and Inspire Rebels to Change the World
In preparation for her keynote session at AppSec EU 2017 in Belfast, Shannon Lietz continues to explore the integration of DevOps and security. This is a recording of her session at RSAC 2017 in San Francisco.

Jan 17, 2017 • 9min
Shannon Lietz - Keynote Preview for AppSec EU 2017, Belfast
Shannon Lietz, DevSecOps Lead at Intuit, will be giving a keynote presentation at AppSec EU 2017, Belfast. I talked with Shannon about what she will be presenting and why she is so excited to return to Ireland.

Nov 30, 2016 • 14min
2016 AppSec USA - An Update on the WebGoat Project
WebGoat is a deliberately insecure web application maintained by OWASP designed to teach web application security lessons. It is one of the most used projects at OWASP.
With the current team headed by Bruce Mayhew, Nanne Baars and Jason White, work is moving forward on the creation of new content for creating training lessons for application security. I talked with Bruce and team about what they've done with the latest update and what they hope to accomplish in the coming year.

Oct 12, 2016 • 10min
2016 AppSec USA: The Core Rule Set Project w/ Chaim Sanders
The OWASP ModSecurity Core Rule Set Project's goal is to provide an easily "pluggable" set of generic attack detection rules that provide a base level of protection for any web application. Chaim Sanders,Ryan Barnett, Christian Folini and Walter Hop are the team coordinating the project.
During 2016 AppSec USA, I spoke with Chaim about the purpose of the project, the work work done in the past year, the upcoming release and what the team hopes to accomplish in 2017.
https://www.owasp.org/index.php/Category:OWASP_ModSecurity_Core_Rule_Set_Project