World Congress 2024 Aug 29, 2024 Session details

It's a (testing) trap! - Common testing pitfalls and how to solve them

Ramona Schwering

Your end-to-end tests are secretly your best security tools. Discover how to repurpose Cypress and Playwright into automated defenders against critical OWASP vulnerabilities.

Pause
Mute Enter Fullscreen
#1 about 6 min

Conceptualizing app security defense using gaming mechanics

Visualizing web application vulnerabilities and their mitigation measures through the strategic mechanics of tower defense games.

#2 about 2 min

Identifying common security vulnerabilities via the OWASP project

Prioritizing testing efforts by referencing open source analytics that define the most prevalent and hazardous internet threats.

#3 about 2 min

Isolating cross-site scripting issues using automated component tests

Simulating adversarial behavior by injecting script payloads into test inputs to ensure interfaces properly discard dangerous strings.

#4 about 4 min

Verifying API response rules and content security policy

Requesting forbidden actions and capturing header objects with robust tooling to check resource permissions and distinct origin validation.

#5 about 2 min

Defending against broken access control with negative testing

Covering expected authentication paths alongside intentional negative workflows to ensure private zones adequately reject unauthenticated queries.

#6 about 1 min

Executing fundamental runtime tests against cryptographic failures

Safeguarding data transit efficiently by configuring natively bundled test framework routines to explicitly fail on unencrypted connections.

#7 about 4 min

Addressing unseen code weaknesses using complementary security pipelines

Integrating standard static analysis tooling alongside codebase scanning extensions to protect backend components beyond generic end-to-end constraints.

#8 about 4 min

Deploying structural security analysis within general testing workflows

Building a comprehensive quality assurance pipeline by prioritizing typical vulnerabilities before systematically enforcing broad automated constraints.

#9 about 3 min

Bolstering test coverage consistently without specialized security frameworks

Defending expansive application requirements practically by executing simplified interactions alongside designated internal architectural mitigations.

#10 about 1 min

Encouraging broader team adoption of security automation practices

Protecting continuous delivery and developer focus by permanently migrating repeated manual vulnerability checks into scheduled automated pipeline routines.

Matching moments

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

4:00 min

Evolution from manual hacking to automated security testing

Chris Wysopal Chris Wysopal · WWC 2024

2:39 min

Shifting security testing focus toward critical application logic problems

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · WWC Europe 2026

4:48 min

Using intentionally vulnerable applications for practical security training

Bozidar Spirovski Bozidar Spirovski +1 · Coffee With Developers

4:35 min

Improving developer education with realistic security training environments

Joseph Katsioloudes Joseph Katsioloudes · WWC 2025

2:49 min

Integrating fundamental security evaluations into agile development sprints

Bozidar Spirovski Bozidar Spirovski +1 · Coffee With Developers

Upcoming sessions on this topic

Open session

World Congress 2026 North America

Secure-by-Inclusion: Preventing Accessibility Barriers from Becoming Security Vulnerabilities

Radostina (Ina) Tsvetkova

Norwegian Directorate of Labour and Welfare (NAV), Senior Advisor in Digital Accessibility and Inclusive Design

Radostina (Ina) Tsvetkova
Open session

World Congress 2026 North America

The Things Your AI Isn't Telling You

Desmond Lamptey

Lead Software Engineer @ Capital One

Desmond Lamptey
Open session

World Congress 2026 North America

Practical Threat Modeling for Software Developers

Mudassir Syed

Lead Security Software Engineer

Mudassir Syed
Open session

World Congress 2026 North America

Red Teaming Your LLM App -- A Hands-On Threat Model You Can Reuse

Saloni Garg

Senior ML Engineer at Adobe

Saloni Garg
Open session

World Congress 2026 North America

Don’t kill my Vibes - Simple Steps to Stay Secure when Vibe Coding

Isaac Evans

Co-founder & CEO of Semgrep

Isaac Evans
Open session

World Congress 2026 North America

Reinventing Testing Practices in the AI Era

Eric Deandrea

Java Champion & Senior Principal Software Engineer, IBM

Eric Deandrea