Ken Johnson and Seth Law
Absolute AppSec
A weekly podcast of all things application security related. Hosted by Ken Johnson and Seth Law.
Author
Ken Johnson and Seth Law
Category
Podcast website
Latest episode
Jul 7, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Episode 175 - Web3, JWT Security, Public App Attacks 14.06.2022
Late night edition. Now we are tired. Seth and Ken get back to the podcast and dig into Web3 security a bit. A review of the recent blog post from portswigger on JWT security. Finally discussion on public attacks against applications coming from nation states against US-based systems. Come to LocomocoSec ... and Defcon.
Episode 174 - Smart Contracts, Code Review Lessons Learned 31.05.2022
If there were a magical world where mensch-y podcasters (@cktricky and @sethlaw) discuss smart contract vulnerabilities, secure code review experiences, and package takeover attacks, wouldn't you like to know about it?! Such a world exists for your pleasure in this episode of Absolute AppSec.
Episode 173 - Enumeration Attacks! 24.05.2022
Yet ANOTHER episode of Absolute AppSec with Seth and Ken! User enumeration vulnerabilities are the order of the day. Seth digs in on an interesting #talesfromconsulting where security questions, and the different way they appeared for real users and invalid users, revealed valid user accounts on an application. Further enumeration flaws using WAF bypasses in production systems. A story from Ken on...
Episode 172 - Jimmy Mesta - Kubernetes, Startup Adventures 17.05.2022
Jimmy Mesta (@jimmesta) of KSOC joins Ken and Seth to talk about Kubernetes Security and startup adventures with KSOC. This leads to a discussion on the OWASP's Top 10 Kubernetes Project and how all old security principles are seen in new technologies. Jimmy breaks down his experience in funding a startup, gaining partners, and ultimately building a team.
Episode 171 - Ruby Deserialization Walkthrough, Domain Takeovers 10.05.2022
Ken and Seth are back to talk about potential of package hijacking based on DNS takeovers due to domain expirations. Ken provides a walkthrough of Ruby Deserialization techniques based on recent news articles.
Episode 170 - Security Basics, Social Engineering, Plan for Failure 03.05.2022
Seth and Ken return with a discussion of security basics and failures resulting from lack of security hygiene. As a developer, security engineer, or a CISO, i's important to recognize that breaches will happen, so security planners should "plan for failure." "It's not a matter of if but when."
Episode 169 - Finding Security Bugs 26.04.2022
Seth and Ken return to the podcast and spend the episode reviewing the recent keynote from Mark Dowd at OffensiveCon 22 about the process he uses to find bugs in software.
Episode 168 - Secure Code Review, Package Confusion, Privacy Acts 19.04.2022
What's that sound?! Could it be the Absolute AppSec train coming 'round the bend, set to deliver @cktricky and @sethlaw's timely takes on Application Security news?! This episode starts with an in-depth discussion about secure code review techniques based on a recent twitter thread. Further topics include more software supply chain attacks based on package confusion, the proliferation of state pri...
Episode 167 - Ken Toler - Cryptocurrency, Spring4Shell 05.04.2022
A pair of Kens. A quick discussion on Spring4Shell and how the exploit takes advantage of Java's dynamic configuration options along with a data binding aka mass assignment vulnerabilities. Ken Toler (@relotnek) joins the show to discus the current web3 security landscape and how security can be involved in cryptocurrency projects. "There is a place for you in crypto" - @relotnek
Episode 166 - Web App Firewalls, ProtestWare, CSP Level 3 22.03.2022
As sands through the hourglass, another episode is falls on a Tuesday in late March. It was not _the_ first episode, but it was an episode as Ken and Seth talk about the origins of web application firewalls (WAFs) to go along with an article describing current WAF usage patterns. A heated discussion on recent software supply issues related to ProtestWare (or the changing of open source packages to...
Episode 165 - Portswigger 2021 Top 10, Supply Chain Attacks, TLS Certs 15.03.2022
Welcome to the latest nihilism and bitch session. In this episode, Seth and Ken review Portswigger's Top 10 list of the "most significant web security research released in the last year". Discussion of weak links in the NPM supply chain and what developers can look at to ascertain the security of packages they depend on. Finally, Russia has begun issuing its own TLS certificates, which always lead...
Episode 164 - Supply Chain Security, Cyber Attacks, 2FA, AutoWarp 08.03.2022
What now? Another episode? You have to be kidding me. Now I get to write another summary per my job description. At least this episode covers some security topics like as Software Supply Chain Security using socket.dev and protecting yourself with security basics as a package maintainer. And the discussion of recent cyber attacks against Toyota hardware suppliers and AutoWarp vulnerability for Azu...
Episode 163 - IT Army, Secrets, Access Control 01.03.2022
And we are live, with our 163 episode of Absolute AppSec. Say hi to Ken and Seth once again as they start out with a discussion on the IT Cyber Army and issues with enlisting to help in cyber attacks. Next up is a series of opinions on the security of environment variables and inclusion of secrets within application architectures and the cloud. Finally, a discussion on authorization and access con...
Episode 162 - Mike McCabe (@mccabe615) - Cloud Security 22.02.2022
After a week's hiatus, the Absolute AppSec-ers return with guest Mike McCabe (@mccabe615) to talk about all things Cloud Security. Discussions on cloud security tools, various differences between AWS and Azure, infrastructure as code (IaC), and predictions on cloudsec merging with appsec in the future.
Episode 161 - Language Semantics, Blockchain Validations, Pentest Stories 08.02.2022
A blast from the past as Ken and Seth reminisce about past penetration testing and security stories. A discussion of language semantics and how programming language basics are similar to spoken language basics.
Episode 160 - Mental Health, Open Source Bug Bounties, IDOR 01.02.2022
The duplicitous duo returns with another episode that starts out in left field away from security topics by addressing mental health and how to keep sane when life gets busy, in both good and bad ways. Security does eventually become a topic in a discussion around bug bounties in the news as the European Government announces bug bounties for multiple open source projects. Finally, a discussion on...
Episode 159 - Neil Matatall - CSP, Infosec Hiring, Languages + Framework Security 25.01.2022
Ken and Seth are back to talk with a blast from the past. Neil Matatall (@ndm) of Twitter, Github, and now TikTok fame joins the discussion (again) to talk about CSP. The conversation wanders from there to hiring people in information security and tech jobs. Opinions on language and framework security defaults and why Ruby cannot be beat, errr, or is so good. Finally getting back to CSP and misund...
Episode 158 - More Supply Chains, 2021 Top Ten, CORS + CSRF 18.01.2022
Yet another episode. Always something to discuss. Ken and Seth talk about a recent article covering *theoretical* software supply chain exploits and how this will be a big thing this year. A review of Portswigger's nominations for Top Ten Web Hacking techniques of 2021. Finally, a discussion on the upcoming Chrome changes to do pre-flight requests for non-routable IP address CSRF requests.
Episode 157 - 2022 Predictions, Schema Libraries, NPM and Open Source Packages 11.01.2022
NEW YEAR, NEW SECURITY MADNESS! The duo is back with their application security predictions for 2022. A discussion on 3rd party library differences, in particular how URL/URI Schema libraries and parsing can lead to security flaws. Finally, a discussion on recent NPM news where a developer pushed package versions that undermine the trust developers and corporations have with open source maintainer...
Episode 156 - Stefan Edwards (@lojikil) - Open Source Software, Software Bill of Materials 21.12.2021
As we get ready for the holidays, we only want to talk about log4hell and bill of materials. Please let it end, please, oh please. A surprise visit by Stefan Edwards (@lojikil) to address all things Open Source Software and Software Bill of Materials. Why this matters so much and how asset, application, and software inventory management is death by a thousand cuts. Also, happy holidays!
Episode 155 - Log4Hell, Boring AppSec, Crocs and SOCs 17.12.2021
Tis the season... for 0 days. Discussions on the ever-present Log4j issue that the whole industry is dealing with. Kernelcon training announcements, dealing with varying expectations of clients and developers on industry terms, further appsec resources, and why crocs and socks matter.
Episode 154 - Conferences, Cloud Security, Software Supply Chain 07.12.2021
It's one of those days, must be Q4. View of tech conferences as an outsider. An analysis of data from Google's "Threat Horizons" report and what it tells us about Cloud Security. A few items related security of the software supply chain, including an academic white paper comparing different SCA tools.
Episode 153 - Fuzzing, Authentication, Browser Wars (again) 30.11.2021
Our last episode before its December!!! Where oh where did 2021 go? Seth and Ken wrap up a conversation on fuzzing strategies for HTTP Requests. A discussion on the difficulty of authentication and why that is. Finally, Google Chrome has taken over the web and how it comes back to the browser wars of the early 2000s.
Episode 152 - Breaches, Symbolic Execution, Dynamic vs. Static Assessments 23.11.2021
Gobble gobble! It is that time of the year again to stuff our faces... WITH APPSEC! A discussion on breach notification related to the recent GoDaddy disclosure. Understanding symbolic execution with trail of bits. The differences of dynamic and static assessments and why both are important.
Episode 151 - Secure Code Review, Software Interdependency 16.11.2021
Ahem, Seth and Ken return with a live code review of a recently seen authentication routine. A discussion of software interdependence and the issues it creates (such as SSRF). In other words, 151 and not even the rum... sigh. Well somehow these clowns are still allowed on YouTube so stay tuned for another episode I guess or whatever. Or don't, who cares. Worst. Internship. Ever.
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.