owasp

Three Areas You Need To Test When Assessing Mobile Applications

Having spoken at both at the SANS Mobile Device Security Summit as well as OWASP AppSec DC recently about testing mobile applications I’ve encountered that like the old saying goes “There are many ways to skin a cat”, there are also many ways to assess a mobile application.  I’ve seen very detailed testing methodologies, not […]

Three Areas You Need To Test When Assessing Mobile Applications Read More »

Smart Bombs: Mobile Vulnerability and Exploitation Presentation

This week I co-presented “Smart Bombs: Mobile Vulnerability and Exploitation” with John Sawyer and Kevin Johnson at OWASP AppSec DC.  We talked about the some of the current problems facing mobile applications such as flaws found in the OWASP Mobile Top 10 and various privacy issues.  We also talked about how you go about testing

Smart Bombs: Mobile Vulnerability and Exploitation Presentation Read More »

Attacking & Defending Apple iOS Devices in the Enterprise Presentation Updates

Below are links over on SlideShare to the latest version of my ever evolving presentation “Attacking & Defending Apple iOS Devices in the Enterprise”.  This is the version I presented at the SANS Mobile Device Security Summit a few weeks ago.  I include information on iOS 5, the latest jailbreaks at the time (this has

Attacking & Defending Apple iOS Devices in the Enterprise Presentation Updates Read More »

Don’t Drop the SOAP: Real World Web Service Testing for Web Hackers Presentation

Sorry for the long delay on posting the slides from the presentation that myself, Josh Abraham and Kevin Johnson did at Black Hat USA and DEF CON 19.  I’ve uploaded the slides from DEF CON to SlideShare (you can also download a copy there as well) and below are the links to the tools and

Don’t Drop the SOAP: Real World Web Service Testing for Web Hackers Presentation Read More »