Ken Johnson and Seth Law

Absolute AppSec

A weekly podcast of all things application security related. Hosted by Ken Johnson and Seth Law.

Author

Ken Johnson and Seth Law

Category

Technology

Podcast website

absoluteappsec.com

Latest episode

Jul 7, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Episode 125: Interviews, SQLi, Concurrency, Wordpress 09.03.2021

Seth and Ken discuss interviewing techniques for technical resources, SQL injection in the media and Github's recent concurrency vulnerability. Also a discussion on recent WordPress plugin vulnerabilities and why they are always so devastating.

Episode 124: 2020 Top 10 Web Hacking Techniques, Development vs. Security 02.03.2021

Seth and Ken discuss Portswigger's Top 10 Web Hacking Techniques of 2020, specifically injection attacks through images in PDFs and reverse proxies. Further discussion on creativity in development and how that affects and limits security.

Episode 123: Client-Side Controls, Dependency Confusion 23.02.2021

Seth and Ken discuss client-side controls and 3rd-party JavaScript security features. Confused deputy vulnerabilities (dependency confusion) in the news.

Episode 122: Brian Glas (@infosecdad) - OWASP Top 10 2021 18.02.2021

Seth and Ken welcome back Professor Brian Glas (@infosecdad) to dispel the recent OWASP Top 10 2021 speculation and rumor. We talk through the origins and purpose of the OWASP Top 10 as well as the 2021 call for data and upcoming release.

Episode 121: Stefan Edwards (@lojikil) - Formal Specification, Fuzzing, LangSec 02.02.2021

Stefan Edwards (@lojikil) once again joins Seth and Ken to talk all things LangSec (language security). Discussion ranges from manual vs. automated testing to fuzzing to semantic analysis to formal specification.

Episode 120: OWASP Top 10 2021, Researcher Attacks, Parler, Phishing 26.01.2021

Seth and Ken discuss the proposed 2021 OWASP Top 10 Risks, North Korean attacks against security researchers, password managers, latest in Parler de-platforming, and phishing possibilities.

Episode 119: Bugtraq, Web Cache Poisoning, and Blind SSRF 19.01.2021

Seth and Ken wax nostalgic about the old days due to the shut down of the Bugtraq Mailing List (RIP old friend). Further discussions on web cache poisoning and blind server-side request forgery (SSRF) exploits.

Episode 118: Parler, Twitter, and IDOR 12.01.2021

Seth and Ken return with a discussion about application security in the news, including relevance to the Parler "backups". Also discussions about Twitter and latest political developments and how they affect the security industry.

Episode 117: Solarwinds, Timing Attacks, Threat Dragon 22.12.2020

The dynamic duo is back for their last podcast of 2020!

Episode 116: Lewis Ardern and Pwnfunction - Client-Side JavaScript Security 24.11.2020

Lewis Ardern (@LewisArdern) and Pwnfunction (@pwnfunction) join Seth and Ken to talk client-side JavaScript security and their recent Vue JS blog post. https://portswigger.net/research/evading-defences-using-vuejs-script-gadgets

Episode 115: Clint Gibler - Static Analysis with Semgrep 17.11.2020

Clint Gibler (@clintgibler) joins Seth and Ken to talk about Static Analysis with Semgrep. Demonstrations of writing rules within Semgrep and how to use it.

Episode 114: Account Enumeration, Github Actions 10.11.2020

Seth and Ken discuss account enumeration vulnerabilities and open source tools that take advantage of them. Discussion about the recent Github Actions vulnerability.

Episode 113: Jacob Salassi - Modeling Threats, Risk Assessment 27.10.2020

Jacob Salassi (@JacobSalassi) joins us to discuss his developer-driven, standardized, threat modeling process. Also discussions on developer empathy, risk assessment, and other topics.

Episode 112: Mark Feferman - Static Analysis Tools 20.10.2020

Mark Feferman (@mfeferman) joins Seth and Ken to throw down about automated static analysis tools. Discussion of applictaion security talent (or lack thereof) and 'shifting left'.

Episode 111: Bug Bounties, Detection as Code 13.10.2020

Seth and Ken dig into strange requests when running bug bounty programs, recent revelations on Apple security research, and detection as code.

Episode 110: Reserved Words, Authentication, Developer Patterns 06.10.2020

Back at it like a phrack addict to talk reserved words, authentication flaws in apps and Grindr, and recognizing insecure patterns during development.

Episode 109: Threat Modeling, Social Media, Imposter Syndrome 22.09.2020

We are back with a Seth and Ken only episode to talk about the evolution of threat modeling, the documentary "The Social Dilemma", mental health, and imposter syndrome.

Episode 108: Sean Poris - Bug Bounties and H1-2010 15.09.2020

Sean Poris (@skp00) joins Absolute AppSec to talk about The Paranoids virtual bug bounty hacking event H1-2010, staying sane, managing a virtual team, and advice for running a bug bounty program.

Episode 107: Markus Schirp - Ruby and Dynamic Languages 01.09.2020

Markus Schirp (@_m_b_j_) joins Seth and Ken to talk about Ruby and other dynamic languages. Mutation testing, TDD weaknesses, and meta programming.

Episode 106: Justin Massey - Logging and Monitoring 25.08.2020

Justin Massey from Data Dog joins us to talk Application Logging.

Episode 105: Laura Migus - Diversity and Inclusion 18.08.2020

Seth and Ken chat with Laura Migus who is an expert in the realm of Diversity and Inclusion to learn more about the topic and how to support diversity and inclusion efforts.

Episode 104: Leif Dreizler - Authentication and SCIM 05.08.2020

Leif Drezler joins Seth and Ken to talk about recent projects, including authentication, SCIM, and how to embed within a development team.

Episode 103: Secrets Management, Oded Hareven, and akeyless.io 21.07.2020

Oded Hareven from AKEYLESS joins Seth and Ken to discuss the idea behind AKEYLESS as well as give us a chance to learn a little bit more about Oded.

Episode 102: Popular Programming Languages, TikTok, OWASP 30.06.2020

Seth and Ken talk about the popularity of various programming languages, TikTok app issues, and new changes at OWASP.

Episode 101: Mike McCabe, Ken Toler, Cloud Security 23.06.2020

Seth and Ken are joined by Mike McCabe (@mccabe615) and Ken Toler (@relotnek) to break down their talk on Cloud Security. Discussions revolves around cloud security, but touches legacy systems, application inventory, virtual conferences, and more.

Listen to the Absolute AppSec podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.