The Main Features All the essentials for web application testing
7
How can you use ZAP?
8
Security Regression Tests
9
Enhanced Sessions
10
SAML 2.0
11
CMS Scanner
12
Dynamic actions
13
Plug-n-Hack - Phase 1
14
Scripting
15
Zest - Overview
16
Zest - Use cases
17
Zest - Passive Scan Rule
18
Zest - Statements
19
Zest - Runtime
20
Plug-n-Hack - Phase 2
21
ZAP Hackathon!
22
Conclusion
Description:
Explore the OWASP Zed Attack Proxy (ZAP) in this comprehensive 51-minute conference talk by Simon Bennetts. Gain insights into one of OWASP's most popular projects, designed for users with varying levels of security experience. Learn about ZAP's versatility as a tool for developers, functional testers new to penetration testing, and experienced pen testers alike. Discover the latest features, including those developed during Google Summer of Code, Plug-n-Hack, and the Zest scripting language. Get a sneak peek at upcoming capabilities not yet available in similar tools. Delve into topics such as security regression tests, enhanced sessions, SAML 2.0, CMS scanner, dynamic actions, and more. Understand ZAP's principles, main features, and various use cases through practical demonstrations and explanations from Simon Bennetts, the OWASP ZAP Project Leader and Mozilla Security Automation Engineer.
OWASP Zed Attack Proxy: Latest Features and Developments - Lecture