Ken Johnson and Seth Law

Absolute AppSec

A weekly podcast of all things application security related. Hosted by Ken Johnson and Seth Law.

Author

Ken Johnson and Seth Law

Category

Technology

Podcast website

absoluteappsec.com

Latest episode

Jul 7, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Episode 150 - Jerry Gamblin - NVD CVEs, Vulnerability Disclosure, Burp Cert 26.10.2021

Jerry Gamblin makes a return to the podcast to talk about recent events in Missouri and how _not_ to respond to responsible vulnerability disclosure. A discussion on the increase of CVEs showing up in the National Vulnerability Database, how Kenna was acquired by Cisco, and Portswigger's new Burp Suite Certificate.

Episode 149 - Burnout, AppSec News Sources 19.10.2021

Just two old men bi***ing and moaning about App Sec and the price of a good pair of New Balances. Real discussion on dealing with burnout and imposter syndrome. How to stay engaged and interested when the excitement becomes mundane.

Episode 148 - Facebook, Phrack, Paved Path 05.10.2021

Strange things are afoot at the Circle K. Facebook outage and BGP routing. A new issue of phrack released on Oct 5 results a discussion on the good ol' days, BBSes, and the commercialization of security. Finally, thoughts on paved paths and how they affect security.

Episode 147 - James Kettle (@albinowax), Security Research 21.09.2021

The one and only James Kettle (@albinowax) of Portswigger joins Seth and Ken to talk about his path into security, HTTP request smuggling, and how to perform security research.

Episode 146 - OWASP Top 10, Bug Bounties with @JHaddix, Request Smuggling 14.09.2021

Now with the latest in old people ramblings. Discussion about the OWASP Top 10 Draft list and how the Top 10 should be used as an awareness document. Discussions on bug bounties with surprise guest Jason Haddix (@JHaddix). More fun with HTTP Request Smuggling.

Episode 145 - Return of @cktricky, Burnout, Bumble Vuln, Brute-Forcing 26.08.2021

@cktricky is _back_ with a newfound lease on life (and application security). The duo discusses in-person vs. virtual conferences, DEF CON 29, burnout, vulnerabilities in dating apps. A demonstration of using Burp Suite to fuzz a user enumeration vulnerability and brute-force an account.

Episode 144 - Fuzzing, Radamsa, Property Testing 17.08.2021

With @cktricky still on hiatus, @sethlaw and @lojikil talk fuzzing, property testing, semantic analysis and demo radamsa.

Episode 143 - HTTP/2, Black Hat/DEFCON, Kubernetes 10.08.2021

With @cktricky out adventuring, @sethlaw is joined by a familiar face (@lojikil) to dive deeply into recent research presented at Black Hat/DEF CON, HTTP/2, and how everything old is new again.

Episode 142 - AI Code Generation, Puma Scan, HTTP Request Smuggling 20.07.2021

Dreamin', Beamin', and Streamin' about using artificial intelligence (AI) to generate code (*cough*, *cough*). When and where to use automated source code analysis tools, specifically Puma Scan for .Net/C# code. Also a primer on HTTP Request Smuggling and what you should know about it.

Episode 141 - print(), Cross-Site Scripting (XSS), RiskIQ, Amass Demo 13.07.2021

Just two grumpy old men with some AppSec sprinkled in. Topics this week include new research from portswigger using print to bypass new Chrome XSS iframe restrictions, how XSS is still the best (and worst) issue we deal with, and Microsoft's acquisition of RiskIQ.

Episode 140 - Naomi Buckwalter - Gatekeeping, Developing AppSec Resources 29.06.2021

Naomi Buckwalter (@ineedmorecyber) joins Ken and Seth in a discussion about security gatekeeping, how anyone can get into application security, and the relationships between development and security.

Episode CXXXIX - Return of the @lojikil (Stefan Edwards) 22.06.2021

Stefan returns and we pick his brain about information security degrees, format strings, and different testing methodologies. Then we spend most of the episode googling the words that come out of his mouth.

Episode 138: Ransomware 15.06.2021

The duo is back to talk about consulting scheduling and ransomware. Somehow this evolved to a discussion on Hipster Vulns and how auditing is the Crocs-n-SOCs of application security.

Episode 137: CSRF, GraphQL, Kubernetes, Docker, NoSQL Injection 08.06.2021

Live from their parent's basement and dripping with tin foil - Seth and Ken talk about how CSRF is a thing in GraphQL. Kubernetes gets an intentionally-vulnerable setup, and you should definitely check the security of your docker. Finally, some noise about the NoSQL Injection Cheat Sheet.

Episode 136: AppSec Nihilism and Breaches 01.06.2021

Back off of a week's break, Seth and Ken catch up on breach news. A return of security nihilism is also in order based on recent breaches and exploits.

Episode 135: GoSDL, Language Choice, Kenna, Dependency Confusion 18.05.2021

Punchy and Grumpy are back at it starting with a discussion on GoSDL and how it integrates with developer workflows. Followed by a discussion on language choice/experience, Cisco's acquisition of Kenna Security, and more dependency confusion in gem files.

Episode 134: Legal Protections, Browser Sanitization APIs, Burnout 11.05.2021

Statler and Waldorf meet again to discuss legal protections when conducting security testing, new browser APIs for sanitization of user-supplied content, how XSS is boring, and techniques for dealing with burnout.

Episode 133: Rob Shavell - Privacy 04.05.2021

Rob Shavell from Abine.com joins Seth and Ken to talk about data privacy, social media, and industry concerns with tracking.

Episode 132: Supply Chain Attacks, What I Wish I Knew Starting in Security 27.04.2021

Ken and Seth are the dynamic duo revealing what they wish they knew starting in security and as a penetration tester. Also a discussion about supply chain attacks and a tribute to the late Dan Kaminski.

Episode 131: Jeevan Singh - Threat Modeling 20.04.2021

Jeevan Singh from Segment joins Seth and Ken to discuss the recently-released, open source threat modeling training material.

Episode 130: Facebook 'Breach', Data Privacy 13.04.2021

Ken and Seth break down the Facebook 'Breach', aka data collection and different views on dealing with that data. The discussion continues with privacy data and how far we should trust any social media application.

Episode 129: Rey Bango - JQuery, Developer Relations, Security Education 06.04.2021

Rey Bango (@reybango) from Veracode joins Seth and Ken to talk about his path into security. Topics include JavaScript, JQuery, building relationships between security and relations, and how to educate the next generation of developers in security.

Episode 128: Stefan Edwards/David Coursey - PHP, Backdoors, and AppSec Nihilism 30.03.2021

Seth hosts Stefan Edwards (@lojikil) and David Coursey (@dacoursey) discussing PHP's recent backdoor, probable fixes including code commit signing and the move to GitHub. THe discussion covers ease of security, developer tendencies when securing code, and application security nihilism.

Episode 127: Regexes, WAFs, Secondary Contexts 23.03.2021

Seth and Ken discuss the role of regular expressions in routing of web application requests. Discussion covers basics of routing, exploitation of secondary contexts, and bypassing of web application firewalls.

Episode 126: Junior AppSec Positions, Phishing Site Detection, Client-side JavaScript 16.03.2021

Seth and Ken are back on another Taco Tuesday to talk through getting into application security and how to support those new to the field. Also a discussion on phishing sites that detect VMs and other tools to bypass detection and observed client-side JavaScript attacks.

Listen to the Absolute AppSec podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.