Episode 19: "IDOR, APIs, and Passwords OH My!" ft. Jullian Gerhart
This week, Zac sits down with Jullian Gerhart. Jullian is a Managing Consultant at NCC Group, which specializes in application security and application security pentesting. Jullian is also a contributor to the Application Defense Alliance (appdefensealliance.dev) working to create a standardized framework for securing applications in the Google Play and Apple App Stores. Zac and Jullian discuss the current state of application security, their favorite web application security vulnerability (LOVE LIVE IDOR), and we get a great story from Jullian about compromising extremely sensitive information from an unsecured API.