Show #40 - The Security Redux

Security , Interview Add comments

This show is the redo of our lost security interview with Jason Dean and Peter Freitag.  We talk all about security, and what that means.  We talk about the good, the bad, and common misconceptions.  We also talk about a blog post from Kevin Lynch , Adobe CTO that dove tails in to more talk on flash vs HTML5. 

Jason and Peter are also doing a Pre-Conference Class at cf.Objective() on application security.  If you are going you should check this class out.  Building Secure CFML Applications by Jason Dean and Pete Freitag

Course Description

Hacking a website is one of the best ways to learn about web application security. In this one-day hands-on course you will learn about a wide range of security topics essential to every ColdFusion developer.

The course will begin by covering the principles and foundations of application security. Next you will learn about vulnerabilities by exploiting them in a vulnerable example application. As you hack each vulnerability you will also dig into the source code behind it, and fix it as we discuss countermeasures to prevent these vulnerabilities from showing up in your applications.

 

Show Topic Links:

 

Jason Dean's Blog http://www.12robots.com/

http://www.hackmycf.com/

http://foundeo.com/

FuseGuard Web Application Firewall for ColdFusion

Kevin Lynch's Blog Post: Open Access to Content and Applications

 

 

11 responses to “Show #40 - The Security Redux”

  1. Cesar P Says:
    Liked the interview with Seth Rogen... I mean Jason Dean. Seriously that dude sounds just like Seth Rogen.
  2. Jason Dean Says:
    Do I?

    I always thought that I sounded terrible. But I suppose most people do.

    Maybe I should head to Hollywood and be another funny, dumpy guy ;)

    Awesome
  3. Simon Says:
    Hi all, is anyone else having trouble with podcasts 40 and 40 via iTunes subscriptions or is just me ?
  4. Izzy Says:
    I'm having difficulty downloading show #40 and #41 from itunes. According to the errors, both show files are corrupted.
  5. Dave Ferguson Says:
    I just verified shows 40 and 41 via iTunes. Both played just fine.
  6. Izzy Says:
    @Simon, did you download the mp3 files from this site? If so, did you get a message about this site is being block by openDNS.com?
  7. Simon Says:
    @Izzy and Dave - hi guys, i subscribed to the podcast a few months back now and the last two podcasts error out when I download them through iTunes. Im in the UK if that helps any ? Ill post the error I get in iTunes too later maybe that will help.

    P.S. my company proxy wont let me download the mp3s via the site :0(
  8. Simon Says:
    Hi all, hope you all had a good valentines weekend ! The error I get in iTunes is "The file might be corrupted, or a file type that iTunes can't play".
  9. Izzy Says:
    That's the same error I got on my desktop which is at work. I was able to download the older shows without any problems. I found out that openDNS.com is blocking cfhour and categorized them as "Adult Theme/Porno". LOL Anyway, I was able to download the two shows from my laptop without any problems.
  10. Simon Says:
    Thanks Izzy, I'll just have to sort my podcasts from home then :0) Have a great day !
  11. Simon Says:
    hi guys, has anyone had problems decrypting Blowfish encrypted data ? The dta is encrypted using a vb process on a sql server. I have been told the way its encrypted and applied the key to the decrypt tag in cf but keep getting the error "An error occurred while trying to encrypt or decrypt your input string: '' Can not decode string "21E3785894BD6A913860".. . " The last bit of the error is the key im passing and not the string im trying to decrypt. Any ideas ?

Leave a Reply

Leave this field empty:

Powered by Mango Blog. Design and Icons by N.Design Studio