> Markdown version of [/videos/1282-plants-vs-thieves-automated-tests-in-the-world-of-web-security?t=1](https://www.wearedevelopers.com/videos/1282-plants-vs-thieves-automated-tests-in-the-world-of-web-security?t=1). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Plants vs. Thieves: Automated Tests in the World of Web Security What if your standard automated tests could block active web attackers? Learn how to weaponize frameworks like Cypress to catch critical OWASP vulnerabilities before production. - **Speakers:** [Ramona Schwering](https://www.wearedevelopers.com/@ramona-schwering) - **Event:** WeAreDevelopers LIVE - **Published:** December 16, 2024 - **Duration:** 24:09 - **URL:** https://www.wearedevelopers.com/videos/1282-plants-vs-thieves-automated-tests-in-the-world-of-web-security ## Summary Drawing on the defensive strategies of the game *Plants vs. Zombies*, web security requires robust countermeasures to protect applications from active attackers and design flaws. While specialized security tools are valuable, developers can also leverage standard automated testing frameworks to build an effective first line of defense. By shifting the perspective on normal daily testing, automated tests become a crucial messenger, alerting engineering teams to potential vulnerabilities before they can be exploited in production environments. By integrating security-focused scenarios into end-to-end testing tools like Cypress, Playwright, or Selenium, teams can actively test for the OWASP Top 10 most critical web application security risks. Practical examples utilizing the OWASP Juice Shop demonstrate how to purposefully mimic attacker behavior. Test cases can be specifically designed to catch SQL injections via login forms, verify Content Security Policy (CSP) headers to prevent cross-site scripting (XSS), and ensure strict access control by asserting that unauthorized users are blocked from administrative interfaces. Furthermore, certain frameworks like Cypress inherently help flag cryptographic failures by enforcing same-origin policies and erroring out on unencrypted HTTP navigation. To build a comprehensive security testing strategy, QA engineers and developers must first analyze application risks and plan appropriate test layers across unit, integration, and end-to-end suites. Prioritizing negative tests that focus on strict error handling and executing these suites regularly—such as in nightly builds—ensures continuous monitoring without bottlenecking deployments. Ultimately, while "tests are only the messenger" and cannot replace secure coding practices or routine dependency updates, combining custom security test cases with open-source plugins provides a resilient, highly automated approach to web defense. **Keywords:** automated security testing, web security vulnerabilities, owasp top 10, end-to-end testing, cypress testing framework, sql injection prevention, content security policy validation, broken access control, cryptographic failures, owasp juice shop, negative testing strategies, continuous security monitoring, cross-site scripting mitigation, security test pipelines, application threat mitigation ## Chapters 1. **Plants vs zombies as an analogy for web security** (00:01) — Treating web security threats as zombies highlights how application defense mechanisms like testing act as protective plants. 1. **Why write security tests instead of relying on tools** (04:20) — Using normal testing frameworks for security checks offers cost benefits and deepens knowledge of application vulnerabilities. 1. **Identifying core risks with the OWASP top ten** (06:01) — Understanding broken access control, cryptographic failures, and injection provides primary targets for security automation. 1. **Writing end-to-end tests to catch SQL injection vulnerabilities** (08:08) — Mimicking an attacker with Cypress verifies that malicious input generates the expected error messages. 1. **Validating content security policy headers in automated tests** (12:56) — Configuring test requests to intercept and assert the presence of proper CSP headers protects against cross-site scripting. 1. **Testing for broken access control and unpermitted routes** (14:32) — Creating negative test cases ensures users without proper permissions are blocked from administrative pages. 1. **Detecting cryptographic failures with test runner behavior** (16:34) — Leveraging the strict same-origin policies of test runners like Cypress catches unencrypted HTTP navigation attempts. 1. **Supplementing custom tests with security tools and plugins** (17:32) — Incorporating community-driven tools and vulnerability databases uncovers risks that custom test scripts miss. 1. **Incorporating security into standard test plans and pipelines** (19:36) — Executing a mix of unit, integration, and end-to-end security tests during nightly builds provides continuous validation. 1. **Summary of security testing strategies and best practices** (21:58) — Reviewing the use of automation and negative testing reveals a complementary layer in overall application security. ## Related Moments - [Introduction to security advocacy and automation testing](https://www.wearedevelopers.com/videos/1331-wearedevelopers-live-chrome-for-sale-comet-the-upcoming-perplexity-browser-stealing-and-leaking) (from "WeAreDevelopers LIVE - Chrome for Sale? Comet - the upcoming perplexity browser Stealing and leaking") - [Deploying structural security analysis within general testing workflows](https://www.wearedevelopers.com/videos/1193-it-s-a-testing-trap-common-testing-pitfalls-and-how-to-solve-them) (from "It's a (testing) trap! - Common testing pitfalls and how to solve them") - [Evolution from manual hacking to automated security testing](https://www.wearedevelopers.com/videos/952-the-transformative-impact-of-genai-for-software-development-and-its-implications-for-cybersecurity) (from "The transformative impact of GenAI for software development and its implications for cybersecurity") - [Shifting security testing focus toward critical application logic problems](https://www.wearedevelopers.com/videos/100191-genai-is-a-junior-dev-with-root-access) (from "GenAI Is a Junior Dev With Root Access") - [Automating security and performance evaluations during the testing phase](https://www.wearedevelopers.com/videos/598-why-shifting-left-is-so-important-for-software-developers) (from "Why shifting left is so important for software developers") - [Using intentionally vulnerable applications for practical security training](https://www.wearedevelopers.com/videos/1829-how-to-defend-against-data-manipulation-attacks-bozidar-spirovski-wekoslav-stefanovski) (from "How to Defend Against Data Manipulation Attacks - Bozidar Spirovski & Wekoslav Stefanovski") ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) ## Related Jobs - [Penetration Tester / Red team Specialist](https://www.wearedevelopers.com/jobs/ext/3081075-penetration-tester-red-team-specialist) at **Raiffeisen Bank International AG** - [SoC Offensive Security Staff Engineer](https://www.wearedevelopers.com/jobs/48479-soc-offensive-security-staff-engineer) at **Arm** - [The Principal Test Engineer - Security and Provisioning](https://www.wearedevelopers.com/jobs/ext/3022499-the-principal-test-engineer-security-and-provisioning) at **ARM** - [Bank Platform Transformation - Test Execution Leader - Sr Associate](https://www.wearedevelopers.com/jobs/ext/2407777-bank-platform-transformation-test-execution-leader-sr-associate) at **PwC** - [Staff Developer Advocate, GitHub Security Lab](https://www.wearedevelopers.com/jobs/ext/2628442-staff-developer-advocate-github-security-lab) at **GitHub** - [Bank Platform Transformation - Test Execution Leader - Sr Associate](https://www.wearedevelopers.com/jobs/ext/2391699-bank-platform-transformation-test-execution-leader-sr-associate) at **PwC**