OWASP Podcast #21, an interview with Richard Stallman, is now live!
Richard is the founder of the GNU Project and the Free Software Foundation. Created the GNU Compiler and Debugger. Emacs, too. He is one of the original (MIT Style) hackers. He also created a few licenses, like the GPL. He is the original Software Freedom Fighter. (Just don't ask him what his Skype address is, ouch my bad)
To listen to OWASP Podcast #21, you can download the OGG file directly or subscribe to the RSS feed. This podcast is only being released in OGG format only to honor Richards request.
I'm very grateful to Shpongle and Twisted Records for allowing the OWASP Podcast Series FREE use of their music for the show!
Wednesday, May 20, 2009
Tuesday, May 12, 2009
OWASP Podcast #19 - March 2009 News Part 2
OWASP Podcast #19 - Part 2 of the OWASP Newscast for March 2009 - is now live!
OWASP Podcast #19 features Arshan Dabirsiagh, Andre Gironda and Jeff Williams. Andre did all of the extensive copy editor work. We cover a variety of Web App Sec articles found here. The show lasts about 55 minutes.
To listen to OWASP Podcast #19 you can download the mp3 file directly, subscribe to the RSS feed, subscribe directly to iTunes!
Gareth Heyes was kind enough to donate some new album art for the show!

The OWASP Podcast News Commentary Show will soon be on a 2 week production cycle. I've also invited John Steven from Cigital, Alex Smollen from Foundstone, and Tom Brennan from Whitehat Security to join the show. It should make for a very interesting appsec mix!
OWASP Podcast #19 features Arshan Dabirsiagh, Andre Gironda and Jeff Williams. Andre did all of the extensive copy editor work. We cover a variety of Web App Sec articles found here. The show lasts about 55 minutes.
To listen to OWASP Podcast #19 you can download the mp3 file directly, subscribe to the RSS feed, subscribe directly to iTunes!
Gareth Heyes was kind enough to donate some new album art for the show!

The OWASP Podcast News Commentary Show will soon be on a 2 week production cycle. I've also invited John Steven from Cigital, Alex Smollen from Foundstone, and Tom Brennan from Whitehat Security to join the show. It should make for a very interesting appsec mix!
Sunday, May 3, 2009
OWASP Podcast #18 - Jeremiah Grossman
OWASP Podcast #18, an interview with Jeremiah Grossman, is now live! Jeremiah is the CTO of Whitehat Security and has been an active member of the Web Application Security community for well over 10 years.
To listen to OWASP Podcast #18, you can download the mp3 file directly, subscribe to the RSS feed or subscribe directly through iTunes!
I'm very greatful to Shpongle and Twisted Records for allowing the OWASP Podcast Series to use their music for the show! I'm a very big fan of Ambient and Down-tempo techno. Perfect coding music. Shpongle is among the best.

To listen to OWASP Podcast #18, you can download the mp3 file directly, subscribe to the RSS feed or subscribe directly through iTunes!
I'm very greatful to Shpongle and Twisted Records for allowing the OWASP Podcast Series to use their music for the show! I'm a very big fan of Ambient and Down-tempo techno. Perfect coding music. Shpongle is among the best.

Thursday, April 23, 2009
OWASP Podcast #17 - Interview with RSnake
OWASP Podcast #17, an interview with Robert Hansen, is now live! Robert achieved fame and glory in the early wild west days of web application security working for e-bay. He's also the brain behind the Google-approved security blog, http://ha.ckers.org .
Thursday, April 9, 2009
OWASP Podcast #16 - Interview with Dave Aitel
The first rule of Fight Club is: you do not talk about Fight Club.
OWASP Podcast #16, an interview with Dave Aitel, covers a wide variety of topics. Dave started working as a security researcher for the NSA at the age of 18 and has no shortage of experience to pull from in this interview.
To listen to OWASP Podcast #16, you can download the mp3 file directly, subscribe to the RSS feed or subscribe directly through iTunes!

OWASP Podcast #16, an interview with Dave Aitel, covers a wide variety of topics. Dave started working as a security researcher for the NSA at the age of 18 and has no shortage of experience to pull from in this interview.
To listen to OWASP Podcast #16, you can download the mp3 file directly, subscribe to the RSS feed or subscribe directly through iTunes!

Tuesday, April 7, 2009
Form input names with reserved words and JQuery
When you have an HTML form that contains an input field with the name of "action" or "submit" - submitting a form via javascript becomes problematic.
Normally, Jquery users would simply call $("#formid").submit() after referencing a form. However, if your form contains an input field named "submit" (like <input name="submit">) then $("#formid").submit() does not submit the form.
This is my workaround - essentially programatically clicking the submit button, instead of programatically submitting the form.
<html>
<head>
<script src="jquery-1.3.2.js"></script>
<script>
$(document).ready(function() {
alert('action=' + $("#formid").attr("action"));
alert('try to submit');
$("#sneaky").click();
});
</script>
</head>
<body>
<form action="http://www.testdomain.net/actionworksok" id="formid">
<input type=submit name=testname id=sneaky>
<input name=action value=test1>
<input name=submit value=test2>
</form>
</body>
</html>
Normally, Jquery users would simply call $("#formid").submit() after referencing a form. However, if your form contains an input field named "submit" (like <input name="submit">) then $("#formid").submit() does not submit the form.
This is my workaround - essentially programatically clicking the submit button, instead of programatically submitting the form.
<html>
<head>
<script src="jquery-1.3.2.js"></script>
<script>
$(document).ready(function() {
alert('action=' + $("#formid").attr("action"));
alert('try to submit');
$("#sneaky").click();
});
</script>
</head>
<body>
<form action="http://www.testdomain.net/actionworksok" id="formid">
<input type=submit name=testname id=sneaky>
<input name=action value=test1>
<input name=submit value=test2>
</form>
</body>
</html>
Monday, April 6, 2009
OWASP Podcast #15 - Interview with Brian Chess
Brian Chess talks about the Building Security In Maturity Model and software maturity models in general.
To listen to OWASP Podcast #15, you can download the mp3 file directly, subscribe to the RSS feed or subscribe directly through iTunes!
To listen to OWASP Podcast #15, you can download the mp3 file directly, subscribe to the RSS feed or subscribe directly through iTunes!
Subscribe to:
Posts (Atom)