狠狠撸

狠狠撸Share a Scribd company logo
OWASP ZAP
Introduction
Simon Bennetts
ZAP Project Lead
OWASP Thailand 2020 July 2
This Talk
●
Overview
●
Desktop
●
Heads Up Display
●
Automation
What is ZAP?
●
A tool for finding vulnerabilities in web applications
●
An OWASP Flagship Project
●
Free and Open Source
●
Cross platform
●
Well maintained
●
And ...
The worlds most widely used web scanner
●
> 85,000 direct downloads
●
> 220,000 Docker pulls
●
> 1 million runs
●
In March 2020 alone!
Who is ZAP For?
●
Developers and functional testers (QA)
●
Students
●
Security Professionals
How often is ZAP released?
●
Full releases – averaging 2 a year
●
Add-ons – released as and when required
●
Weekly releases (zip and docker image)
●
Live docker image
ZAP Overview
Any Questions
so far?
The ZAP Desktop
The ZAP HUD
ZAP Automation
●
Command line scan
●
Packaged Scans
●
GitHub actions
●
Daemon + API
Find Out More
●
www.zaproxy.org
●
www.alldaydevops.com/zap-in-ten

More Related Content

2020 OWASP Thailand - ZAP intro