Discover this podcast and so much more

Podcasts are free to enjoy without a subscription. We also offer ebooks, audiobooks, and so much more for just $11.99/month.

26 : Ruby on Rails Security & OWASP RailsGoat

26 : Ruby on Rails Security & OWASP RailsGoat

FromThe Web Platform Podcast


26 : Ruby on Rails Security & OWASP RailsGoat

FromThe Web Platform Podcast

ratings:
Length:
67 minutes
Released:
Jan 22, 2015
Format:
Podcast episode

Description

While working to secure Rails applications in a truly Agile development environment, it became clear to Ken Johnson (@cktricky), CTO of nVisium Security, and Mike McCabe (@mccabe615) that the Rails community needed attention to security in the form of free and open training. The events that have transpired this past year have only reinforced that belief. RailsGoat, an OWASP project, is an attempt to bring attention to both the problems that most frequently occur in Rails, solutions for remediation, and common attack scenarios. Ken, Mike, and their contributors built a vulnerable Rails application that aligns with the OWASP Top 10 and can be used as a training tool for Rails-based development shops.
Resources
 


Brakeman -  http://brakemanscanner.org/


RailsGoat - http://railsgoat.cktricky.com/


OWASP - https://www.owasp.org/


OWASP NoVA - http://www.meetup.com/OWASP-Northern-Virginia-Chapter/


Rails Security Guide - http://guides.rubyonrails.org/security.html


RoR Security Google Group - https://groups.google.com/forum/#!forum/rubyonrails-security


DevOops Video - https://www.youtube.com/watch?v=1kPw3tHt2oo


DevOops Slides - http://www.slideshare.net/chrisgates/lascon-2014-devooops


Ensnare Gem - https://github.com/ahoernecke/ensnare
Released:
Jan 22, 2015
Format:
Podcast episode

Titles in the series (100)

A weekly show covering the latest in browser features, standards, and the tools developers use to build for the Web of today and beyond. Each week, hosts Danny, Amal, Leon, and Justin are joined by a special guest to discuss the latest developments and features that you may just want to use in your next project.