Home Google: Please Hack this Buggy Microblogging App

Google: Please Hack this Buggy Microblogging App

New Google recruits learn how to protect their web applications against security threads with the help of technical presentations and interactive tutorials. Today, Google is making its “Web Application Exploits and Defenses” tutorial available to everybody on the Internet. Part of this tutorial includes Jarlsberg, a full-featured microblogging application that was developed with a single purpose: to be hacked.

?Jarlsberg was written specifically to teach developers about security vulnerabilities and for this reason, the code is full of security flaws. According to the tutorial, “Jarlsberg has multiple security bugs ranging from cross-site scripting and cross-site request forgery, to information disclosure, denial of service, and remote code execution.?” The application is written in Python, though Google notes that the security bugs are not Python-specific.

Jarlsberg’s source code is published under the Creative Commons license and the tutorial is part of Google’s Code University.

It Takes a Hacker to Catch a Hacker

As Google’s Bruce Leban notes, “it takes a hacker to catch a hacker” and the tutorial is meant to teach programmers to think like an attacker and to learn how hackers find security vulnerabilities. Leban also points out that the security bugs in the application are very typical bugs and similar to those found in many applications today.

About ReadWrite’s Editorial Process

The ReadWrite Editorial policy involves closely monitoring the tech industry for major developments, new product launches, AI breakthroughs, video game releases and other newsworthy events. Editors assign relevant stories to staff writers or freelance contributors with expertise in each particular topic area. Before publication, articles go through a rigorous round of editing for accuracy, clarity, and to ensure adherence to ReadWrite's style guidelines.

Get the biggest tech headlines of the day delivered to your inbox

    By signing up, you agree to our Terms and Privacy Policy. Unsubscribe anytime.

    Tech News

    Explore the latest in tech with our Tech News. We cut through the noise for concise, relevant updates, keeping you informed about the rapidly evolving tech landscape with curated content that separates signal from noise.

    In-Depth Tech Stories

    Explore tech impact in In-Depth Stories. Narrative data journalism offers comprehensive analyses, revealing stories behind data. Understand industry trends for a deeper perspective on tech's intricate relationships with society.

    Expert Reviews

    Empower decisions with Expert Reviews, merging industry expertise and insightful analysis. Delve into tech intricacies, get the best deals, and stay ahead with our trustworthy guide to navigating the ever-changing tech market.