Ken Johnson and Seth Law

Absolute AppSec

A weekly podcast of all things application security related. Hosted by Ken Johnson and Seth Law.

Author

Ken Johnson and Seth Law

Category

Technology

Podcast website

absoluteappsec.com

Latest episode

Jul 7, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Episode 50: Static Analysis Tools, DevSecOps, Secure Code Training with Eric Heitzman 12.03.2019

Seth and Ken talk about number 8 in the top web hacking techniques of 2018. Discussions on static analysis tools and approach to usidng them. Eric Heitzman joins to talk about his background, DevSecOps, secure code training and more.

Episode 49: Subdomain Takeovers, DNS SSRF, Oauth Best Practices, Top 10 Web Hacking Techniques of 2019 05.03.2019

Seth and Ken talk through subdomain takeovers vulnerabilities at large companies and identification of DNS SSRF. Ken walks through a few oauth best practices. A look at the Portswigger list of Top 10 Web Hacking Techniques of 2018.

Episode 48: .dev domains, Kubernetes Secrets, Threat Modeling as Code, OWASP Glue Project and Omer Levi Hevroni 26.02.2019

Seth and Ken discuss recent events with the .dev domain and why developers should care. Omer Levi Hevroni (@omerlh) stops by to talk about the OWASP Glue Project, the Kamus project for managing Kubernetes secrets, and Threat Modeling as code. Also .Net.

Episode 47: Mapping Application Source Code, Mobile OWASP Top 10, Mobile Application Testing, and Kevin Cody 20.02.2019

Seth and Ken review steps taken during a secure code review to map out an application. Joined by Kevin Cody (@kevcody) to talk mobile application testing, OWASP Mobile Top 10, what devices to use when performing these tests and how python is awesome.

Episode 46: Fuzzing, Frameworks, Training and Daniel Miessler 13.02.2019

Seth and Ken talk about the recent release of ClusterFuzz by Google. Joined by Daniel Miessler (@Daniel Miessler) to talk about the SecLists project, how it relates to fuzzing, training developers and his path into security.

Episode 45: Making the most of Bug Bounties, managing an AppSec program, and Sean Poris 06.02.2019

Seth and Ken are joined by Sean Poris (@skp00) of Verizon Media to talk about making the most of a bug bounty program, Sean's path into application security from his budding time as a biologist, and strategies on managing a large application security program. Sean also talks about methods he has used for finding and developing application security engineers.

Episode 44: AppSec California, running a Bug Bounty program, and David Coursey 30.01.2019

Seth and Ken are joined once again by David Coursey (@dacoursey) to review topics from AppSec California 2019, including building developer relationships and the OWASP ZAP HUD. Ken and Dave answer questions about the time investment required to support a Bug Bounty program. David discusses his role at Allstate.

Episode 43: DerbyCon, pwnhead, and Keith Hoodlet 16.01.2019

Seth and Ken are joined by Keith Hoodlet (@andMyHacks) to discuss DerbyCon, pwnhead, and application security in medical devices.

Episode 42: SSRF Rebinding and Segment Team (Leif Dreizler and David Scrobonia) 09.01.2019

Seth and Ken discuss SSRF Rebinding defenses with Segment (Leif, David, and Achille). Additional topics include password complexity, password resets, and using Troy Hunt's breach database.

Episode 41: Hidden File/Dir Enumeration and Will Bengtson 19.12.2018

Seth and Ken discuss hidden file and directory enumeration. Joined by Will Bengtson to talk AWS and cloud security, including cloudtrail and trailblazer.

Episode 40: Code Reviews 12.12.2018

Seth and Ken talk through secure code reviews and assessment scoping, more on breaches, the Google congressional hearings and more.

Episode 39: Jerry Gamblin 05.12.2018

Is there such a thing as breach fatigue? When have we had enough? Seth and Ken are joined by Jerry Gamblin of Kenna Security to discuss recent breaches and AWS Re:Invent.

Episode 38: Matt Konda 28.11.2018

Seth and Ken discuss node packages and event_stream fallout. Matt Konda (@mkonda) joins to talk about OWASP, the Glue tool, Jemurai and his origin story and other topics.

Episode 37: Stefan Edwards 21.11.2018

Seth and Ken discuss security gifts for appsec peeps. Joined by Stefan Edwards (@lojikil) to talk about his origin story (Seth gets bagged on), formal verification, and a multitude of other topics.

Episode 36: Mike McCabe 14.11.2018

Seth and Ken discuss cross-site scripting and input validation/output encoding findings. Later joined by Mike McCabe's (@mccabe615) talking about cloud security, building an appsec program, interviews (both for and against) and CHRISTMAS.

Episode 35: Travis McPeak 07.11.2018

Seth and Ken discuss server side request forgery and then pick Travis McPeak's (@travismcpeak) brain about AWS security, his path into security, QA testing, and Netflix cloud security tools.

Episode 34: Stefan Edwards 31.10.2018

Seth and Ken are joined last minute by Stefan Edwards (@lojikil) to talk about security unit tests, fuzzing, and all things you will need to google later on. Blockchains and secure contracts are introduced and somewhat explained.

Episode 33: John Melton 03.10.2018

Seth and Ken go over fully vetting functions during code reviews. John Melton (@_jtmelton) talks with Ken and Seth about static analysis tools, building an appsec program, open source, and more.

Episode 32: Eric Johnson 19.09.2018

Setup tips for starting an assessment with Burp Suite Professional. Eric Johnson (@emjohn20) talks with Ken and Seth about Roslyn, building Puma Scan, SANS, and more.

Episode 31: Rob Fuller 12.09.2018

Practical advice on submitting and writing effective findings for bug bounties and reports. Rob Fuller (@mubix) talks about his path into security, CCDC, volunteerism, NoVA Hackers and more.

Episode 30: Dave Ferguson 05.09.2018

Dave Ferguson (@_sc0rn) talks about the futility of developer training, initial discovery of CSRF in on netflix.com, and application scanning with Ken and Seth.

Episode 29: Matt Tesauro 29.08.2018

Matt Tesauro (@matt_tesauro) talks OWASP, community involvement, Defect Dojo, and the AppSec Pipeline toolbox with Ken and Seth.

Episode 28: Astha Singhal 22.08.2018

Astha Singhal (@astha_singhal) joins Ken and Seth to talk automating application security and bug bounties.

Episode 27: Jim Manico 15.08.2018

Ken and Seth are joined by Jim Manico (@manicode) RAW, training, OWASP, code security, and all things AppSec.

Episode 26: Justin Larson 01.08.2018

Ken and Seth are joined by Justin Larson (@Phant0mTrav3ler) and talk about building an AppSec program from scratch.

Listen to the Absolute AppSec podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.