The Application Security Podcast
The Application Security Podcast is a practitioner-led show for anyone building or securing modern software—and now AI-powered applications. Hosts Chris Romeo and Robert Hurlbut talk with the people shaping application security about AI and LLM security, threat modeling, secure development, OWASP, cloud, DevSecOps, security champions, and building programs that help engineering teams move faster and safer. With more than 300 episodes, the show turns real-world experience into practical guidance for developers, architects, AppSec professionals, and security leaders.
The Application Security Podcast
Tanya Janca and Nicole Becher -- Hacking APIs and Web Services with DevSlop
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
APIs may lack a visible interface, but that does not make them hidden or safe. Tanya Janca and Nicole Becher use OWASP DevSlop and its Pixi application to explain how developers and testers can learn API security hands-on. They cover HTTP fundamentals, authentication, rate limiting, proxies, curl, ZAP, and Burp Suite before showing how intentionally vulnerable applications turn those concepts into experiments. The conversation explores Pixi’s microservices, containerized design, planned capture-the-flag mode, and inspiration from OWASP Juice Shop and WebGoat. Tanya and Nicole also discuss the limits of automated scanners and the value of beginner-friendly CTFs. Their central recommendation is simple: interact with real APIs, observe the traffic, and practice breaking safe targets.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
→ Learn more about Security Journey
Connect with Tanya Janca and Nicole Becher:
→ Tanya Janca on LinkedIn
→ Nicole Becher on LinkedIn
→ OWASP DevSlop
Mentioned in this episode:
→ OWASP DevSlop
→ Pixi
→ OWASP ZAP
→ Burp Suite
→ OWASP Juice Shop
→ OWASP WebGoat
→ Docker
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Hacking APIs and web services with DevSlop
02:15 Nicole Becher’s security origin story
04:12 Learning AppSec through vulnerable applications
06:04 APIs, web services, and HTTP basics
08:27 Why an API is not invisible
10:42 Discovering API traffic with a proxy
12:30 Rate limiting and common API weaknesses
17:15 Using curl, ZAP, and Burp Suite
22:12 Pixi and the DevSlop application family
24:05 Containers and future modules
26:11 Building a capture-the-flag mode
28:15 Scanner limitations and better test targets
30:44 Why developers should try a CTF
32:47 Hands-on learning at AppSec USA
People on this episode
Podcasts we love
Check out these other fine podcasts recommended by us, not an algorithm.
AI Security Table
Izar Tarandach, Matt Coles, and Chris Romeo