The Web Application Hacker's Handbook: Finding and Exploiting Security Flaws

Join myself (@shellsharks) and my guest Sukrit (@sukritdua) as we chat pentesting, training, craft beer and more!

Note: I apologize in advance as Sukrit’s audio was a little spotty. Enjoy!

Show Notes

Preshow

  • Collective Arts Brewing: https://collectiveartsbrewing.com/us/
  • Quebec Maple Coke: https://www.coca-colacanada.ca/en/specialtysoda/quebec-maple/
  • Icewine: https://mywinecanada.com/wine/ice-wine
  • Dragon Stout: https://www.ratebeer.com/Ratings/Beer/Beer-Ratings.asp?BeerID=749

Main Show

  • Kali Linux: https://www.kali.org
  • HackerOne: https://www.hackerone.com
  • BugCrowd: https://www.bugcrowd.com
  • SANS Cyber Security Blog: https://www.sans.org/blog/
  • PortSwigger Blog: https://portswigger.net/blog
  • INE / eLearnSecurity: https://ine.com/pages/elearnsecurity-pricing
  • Shellsharks: https://shellsharks.com
  • Getting Into Information Security: https://shellsharks.com/getting-into-information-security
  • Reddit Feedback: https://www.reddit.com/r/netsecstudents/comments/m0lbst/a_guide_for_those_looking_to_break_into_the/
  • PTP: https://elearnsecurity.com/blog/ptpv4-launch/
  • OSCP: https://www.offensive-security.com/pwk-oscp/
  • Try Harder: https://www.offensive-security.com/offsec/say-try-harder/
  • Web Application Hackers Handbook: https://www.amazon.com/Web-Application-Hackers-Handbook-Exploiting/dp/1118026470
  • Web Security Academy: https://portswigger.net/web-security
  • Hacker101 CTF: https://www.hackerone.com/blog/Introducing-Hacker101-CTF
  • OverTheWire: https://overthewire.org/wargames/
  • picoCTF: https://picoctf.org
  • SANS Holiday Hack Challenge: https://holidayhackchallenge.com
  • Cybrary: https://www.cybrary.it
  • PentesterAcademy: https://www.pentesteracademy.com
  • PentesterLab: https://pentesterlab.com
  • eWPT: https://elearnsecurity.com/product/ewpt-certification/
  • eWPTX: https://elearnsecurity.com/product/ewptxv2-certification/
  • SANS SEC542: https://www.sans.org/cyber-security-courses/web-app-penetration-testing-ethical-hacking/
  • INE Plans: https://ine.com/pages/plans
  • SANS Work Study Program: https://www.sans.org/work-study-program/
  • SANS Summits: https://www.sans.org/cyber-security-summit
  • SAN SEC660: https://www.sans.org/cyber-security-courses/advanced-penetration-testing-exploits-ethical-hacking/
  • Stephen Sims: https://www.sans.org/profiles/stephen-sims/
  • aCloudGuru: https://acloudguru.com
  • Pluralsight: https://www.pluralsight.com
  • Linux Academy: https://login.linuxacademy.com

Postshow

  • Untappd: https://untappd.com
  • Foursquare: https://foursquare.com
  • Mike on Untappd: @beersharks
  • Sukrit on Untappd: @AllPints
  • Hill High Marketplace: http://www.hill-high.com
  • untappdScraper: https://github.com/WebBreacher/untappdScraper
  • Captains Log: https://shellsharks.com/captains-log