SlideShare a Scribd company logo
Tabara de Testare
2013

The OWASP Foundation
http://www.owasp.org

ZAP Quick Intro
OWASP
Zed Attack Proxy
Simon Bennetts
OWASP ZAP Project Lead
Mozilla Security Team
psiinon@gmail.com

Copyright © The OWASP Foundation
Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License.
What is ZAP?
•
•
•
•
•
•
•
•
•

An easy to use webapp pentest tool
Completely free and open source
An OWASP flagship project
Ideal for beginners
But also used by professionals
Ideal for devs, esp. for automated security tests
Becoming a framework for advanced testing
Included in all major security distributions
Not a silver bullet!
2
ZAP Principles

•

Free, Open source

•

Involvement actively encouraged

•

Cross platform

•

Easy to use

•

Easy to install

•

Internationalized

•

Fully documented

•

Work well with other tools

•

Reuse well regarded components
3
Statistics
• Released September 2010, fork of Paros
• V 2.2.2 released in Sept 2013
• V 2.1.0 downloaded > 25K times
• Translated into 20+ languages
• Over 50 translators
• Mostly used by Professional Pentesters?
• Paros code: ~20%

ZAP Code: ~80%

4
The Main Features
All the essentials for web application testing

• Intercepting Proxy
• Active and Passive Scanners
• Traditional and Ajax Spiders
• WebSockets support
• Forced Browsing (using OWASP DirBuster
code)

• Fuzzing (using fuzzdb & OWASP JBroFuzz)
• Online Add-ons Marketplace
5
Some Additional Features
•

Auto tagging

•

Port scanner

•

Script Console

•

Report generation

•

Smart card support

•

Contexts and scope

•

Session management

•

Invoke external apps

•

Dynamic SSL Certificates
6
How can you use ZAP?
•
•
•
•
•
•

Point and shoot – the Quick Start tab
Proxying via ZAP, and then scanning
Manual pentesting
Automated security regression tests
As a debugger
As part of a larger security program

7
SecurityRegression Tests

http://code.google.com/p/zaproxy/wiki/SecRegTests
8
Questions?
http://www.owasp.org/index.php/ZAP
Questions?
http://www.owasp.org/index.php/ZAP

More Related Content

PPTX
ZAP @FOSSASIA2015
ODP
OWASP 2013 Limerick - ZAP: Whats even newer
ODP
OWASP 2013 EU Tour Amsterdam ZAP Intro
ODP
JoinSEC 2013 London - ZAP Intro
ODP
OWASP 2015 AppSec EU ZAP 2.4.0 and beyond..
ODP
OWASP 2013 AppSec EU Hamburg - ZAP Innovations
ODP
OWASP 2014 AppSec EU ZAP Advanced Features
ODP
BSides Manchester 2014 ZAP Advanced Features
ZAP @FOSSASIA2015
OWASP 2013 Limerick - ZAP: Whats even newer
OWASP 2013 EU Tour Amsterdam ZAP Intro
JoinSEC 2013 London - ZAP Intro
OWASP 2015 AppSec EU ZAP 2.4.0 and beyond..
OWASP 2013 AppSec EU Hamburg - ZAP Innovations
OWASP 2014 AppSec EU ZAP Advanced Features
BSides Manchester 2014 ZAP Advanced Features

What's hot (20)

ODP
OWASP 2012 AppSec Dublin ZAP Intro
ODP
BlackHat 2014 OWASP ZAP Turbo Talk
ODP
Automating OWASP ZAP - DevCSecCon talk
PPT
AppSec EU 2011 - An Introduction to ZAP by Simon Bennetts
ODP
OWASP 2013 APPSEC USA Talk - OWASP ZAP
PPTX
Security testing using zap
ODP
2014 ZAP Workshop 1: Getting Started
PDF
ODP
OWASP Zed Attack Proxy Demonstration - OWASP Bangalore Nov 22 2014
ODP
OWASP 2013 APPSEC USA ZAP Hackathon
ODP
JavaOne 2014 Security Testing for Developers using OWASP ZAP
ODP
2014 ZAP Workshop 2: Contexts and Fuzzing
PDF
Intro to DefectDojo at OWASP Switzerland
ODP
OWASP WTE - Now in the Cloud!
PDF
N Different Strategies to Automate OWASP ZAP - Cybersecurity WithTheBest - Oc...
ODP
AllDayDevOps ZAP automation in CI
PDF
N Different Strategies to Automate OWASP ZAP - OWASP APPSec BUCHAREST - Oct 1...
PPTX
Security workflow with ansible
PPTX
OpenSourceSecurityTools - UPDATED
PPTX
Automated tools for penetration testing
OWASP 2012 AppSec Dublin ZAP Intro
BlackHat 2014 OWASP ZAP Turbo Talk
Automating OWASP ZAP - DevCSecCon talk
AppSec EU 2011 - An Introduction to ZAP by Simon Bennetts
OWASP 2013 APPSEC USA Talk - OWASP ZAP
Security testing using zap
2014 ZAP Workshop 1: Getting Started
OWASP Zed Attack Proxy Demonstration - OWASP Bangalore Nov 22 2014
OWASP 2013 APPSEC USA ZAP Hackathon
JavaOne 2014 Security Testing for Developers using OWASP ZAP
2014 ZAP Workshop 2: Contexts and Fuzzing
Intro to DefectDojo at OWASP Switzerland
OWASP WTE - Now in the Cloud!
N Different Strategies to Automate OWASP ZAP - Cybersecurity WithTheBest - Oc...
AllDayDevOps ZAP automation in CI
N Different Strategies to Automate OWASP ZAP - OWASP APPSec BUCHAREST - Oct 1...
Security workflow with ansible
OpenSourceSecurityTools - UPDATED
Automated tools for penetration testing
Ad

Similar to Zed Attack Proxy (ZAP) Quick Intro - TdT@Cluj #20 (18)

ODP
Practical Security Testing for Developers using OWASP ZAP at Dot Net Bangalor...
PPTX
[Wroclaw #5] OWASP Projects: beyond Top 10
PPTX
10 Useful Testing Tools for Open Source Projects @ TuxCon 2015
PPTX
AppSec DC 2019 ASVS 4.0 Final.pptx
PPTX
AppSec DC 2019 ASVS 4.0 Final.pptx
PDF
AppSec & OWASP Top 10 Primer
PPTX
security misconfigurations
PPTX
Artifacts management with DevOps
PDF
we45 DEFCON Workshop - Building AppSec Automation with Python
PDF
Best practices for using open source software in the enterprise
PDF
Azul Systems open source guide
PDF
ISC2: AppSec & OWASP Primer
PDF
OISC 2019 - The OWASP Top 10 & AppSec Primer
PDF
Infosecurity.be 2019: What are relevant open source security tools you should...
PDF
Stackato v6
PDF
Accelerate Application development with WSO2 App Factory
ODP
Dev ops ci-ap-is-oh-my_security-gone-agile_ut-austin
PPTX
Selenium overview ppt by quontra solutions
Practical Security Testing for Developers using OWASP ZAP at Dot Net Bangalor...
[Wroclaw #5] OWASP Projects: beyond Top 10
10 Useful Testing Tools for Open Source Projects @ TuxCon 2015
AppSec DC 2019 ASVS 4.0 Final.pptx
AppSec DC 2019 ASVS 4.0 Final.pptx
AppSec & OWASP Top 10 Primer
security misconfigurations
Artifacts management with DevOps
we45 DEFCON Workshop - Building AppSec Automation with Python
Best practices for using open source software in the enterprise
Azul Systems open source guide
ISC2: AppSec & OWASP Primer
OISC 2019 - The OWASP Top 10 & AppSec Primer
Infosecurity.be 2019: What are relevant open source security tools you should...
Stackato v6
Accelerate Application development with WSO2 App Factory
Dev ops ci-ap-is-oh-my_security-gone-agile_ut-austin
Selenium overview ppt by quontra solutions
Ad

More from Tabăra de Testare (20)

ODP
The OWASP Top 10 Most Critical Web App Security Risks - TdT@Cluj #20
PDF
Robotium framework & Jenkins CI tools - TdT@Cluj #19
PPTX
Tap into mobile app testing@TDT Iasi Sept2013
PPSX
Test analysis & design good practices@TDT Iasi 17Oct2013
PPTX
Webdriver with Thucydides - TdT@Cluj #18
PDF
Mobile Web UX - TdT@Cluj #17
PPTX
Behavior Driven Development - TdT@Cluj #15
PDF
TdT@Cluj #14 - Mobile Testing Workshop
PPS
Security testing
PDF
Mobile Testing - TdT Cluj #13
PDF
Td t summary
PPTX
How to evaluate a tester
PPT
Testing, job or game
PPTX
Test Automation Techniques for Windows Applications
PPTX
Help them to help you
PDF
Learning the Agile way
PPTX
How to bring creativity in testing
PPTX
Tester with benefits
PPTX
Doing things Differently
PPTX
Testarea: Prieten sau dusman? Adrian speteanu
The OWASP Top 10 Most Critical Web App Security Risks - TdT@Cluj #20
Robotium framework & Jenkins CI tools - TdT@Cluj #19
Tap into mobile app testing@TDT Iasi Sept2013
Test analysis & design good practices@TDT Iasi 17Oct2013
Webdriver with Thucydides - TdT@Cluj #18
Mobile Web UX - TdT@Cluj #17
Behavior Driven Development - TdT@Cluj #15
TdT@Cluj #14 - Mobile Testing Workshop
Security testing
Mobile Testing - TdT Cluj #13
Td t summary
How to evaluate a tester
Testing, job or game
Test Automation Techniques for Windows Applications
Help them to help you
Learning the Agile way
How to bring creativity in testing
Tester with benefits
Doing things Differently
Testarea: Prieten sau dusman? Adrian speteanu

Recently uploaded (20)

PDF
Encapsulation theory and applications.pdf
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PPTX
TLE Review Electricity (Electricity).pptx
PDF
Getting Started with Data Integration: FME Form 101
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PDF
DP Operators-handbook-extract for the Mautical Institute
PDF
Transform Your ITIL® 4 & ITSM Strategy with AI in 2025.pdf
PDF
Heart disease approach using modified random forest and particle swarm optimi...
PDF
project resource management chapter-09.pdf
PDF
Zenith AI: Advanced Artificial Intelligence
PDF
DASA ADMISSION 2024_FirstRound_FirstRank_LastRank.pdf
PDF
Microsoft Solutions Partner Drive Digital Transformation with D365.pdf
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PDF
A novel scalable deep ensemble learning framework for big data classification...
PDF
Approach and Philosophy of On baking technology
PDF
Accuracy of neural networks in brain wave diagnosis of schizophrenia
PDF
From MVP to Full-Scale Product A Startup’s Software Journey.pdf
PDF
Encapsulation_ Review paper, used for researhc scholars
PDF
WOOl fibre morphology and structure.pdf for textiles
PPTX
Group 1 Presentation -Planning and Decision Making .pptx
Encapsulation theory and applications.pdf
Agricultural_Statistics_at_a_Glance_2022_0.pdf
TLE Review Electricity (Electricity).pptx
Getting Started with Data Integration: FME Form 101
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
DP Operators-handbook-extract for the Mautical Institute
Transform Your ITIL® 4 & ITSM Strategy with AI in 2025.pdf
Heart disease approach using modified random forest and particle swarm optimi...
project resource management chapter-09.pdf
Zenith AI: Advanced Artificial Intelligence
DASA ADMISSION 2024_FirstRound_FirstRank_LastRank.pdf
Microsoft Solutions Partner Drive Digital Transformation with D365.pdf
Building Integrated photovoltaic BIPV_UPV.pdf
A novel scalable deep ensemble learning framework for big data classification...
Approach and Philosophy of On baking technology
Accuracy of neural networks in brain wave diagnosis of schizophrenia
From MVP to Full-Scale Product A Startup’s Software Journey.pdf
Encapsulation_ Review paper, used for researhc scholars
WOOl fibre morphology and structure.pdf for textiles
Group 1 Presentation -Planning and Decision Making .pptx

Zed Attack Proxy (ZAP) Quick Intro - TdT@Cluj #20

  • 1. Tabara de Testare 2013 The OWASP Foundation http://www.owasp.org ZAP Quick Intro OWASP Zed Attack Proxy Simon Bennetts OWASP ZAP Project Lead Mozilla Security Team psiinon@gmail.com Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License.
  • 2. What is ZAP? • • • • • • • • • An easy to use webapp pentest tool Completely free and open source An OWASP flagship project Ideal for beginners But also used by professionals Ideal for devs, esp. for automated security tests Becoming a framework for advanced testing Included in all major security distributions Not a silver bullet! 2
  • 3. ZAP Principles • Free, Open source • Involvement actively encouraged • Cross platform • Easy to use • Easy to install • Internationalized • Fully documented • Work well with other tools • Reuse well regarded components 3
  • 4. Statistics • Released September 2010, fork of Paros • V 2.2.2 released in Sept 2013 • V 2.1.0 downloaded > 25K times • Translated into 20+ languages • Over 50 translators • Mostly used by Professional Pentesters? • Paros code: ~20% ZAP Code: ~80% 4
  • 5. The Main Features All the essentials for web application testing • Intercepting Proxy • Active and Passive Scanners • Traditional and Ajax Spiders • WebSockets support • Forced Browsing (using OWASP DirBuster code) • Fuzzing (using fuzzdb & OWASP JBroFuzz) • Online Add-ons Marketplace 5
  • 6. Some Additional Features • Auto tagging • Port scanner • Script Console • Report generation • Smart card support • Contexts and scope • Session management • Invoke external apps • Dynamic SSL Certificates 6
  • 7. How can you use ZAP? • • • • • • Point and shoot – the Quick Start tab Proxying via ZAP, and then scanning Manual pentesting Automated security regression tests As a debugger As part of a larger security program 7