Главная
Study mode:
on
1
Intro
2
The Goal
3
About Me
4
Who is ZAP for
5
Demo
6
Apps
7
Documentation
8
Installing ZAP
9
Getting started with ZAP
10
Using ZAP
11
Logging in
12
Scanning the site
13
Contexts
14
Context
15
Fuzzing
16
Can Tests
17
The Marketplace
18
Conclusion
19
QA
20
Zest
21
Breakpoints
22
Scripting
Description:
Explore the powerful OWASP Zed Attack Proxy (ZAP) in this comprehensive 58-minute tutorial. Dive into this free, open-source integrated penetration testing tool for identifying vulnerabilities in web applications, comparable to commercial alternatives like IBM AppScan and HP WebInspect. Learn about ZAP's features, its recent developments, and how to leverage it effectively. Follow along with hands-on demonstrations using purposefully insecure web applications. Cover essential topics including installation, getting started, scanning websites, working with contexts, fuzzing, automated tests, the ZAP Marketplace, and advanced features like Zest, breakpoints, and scripting. Gain valuable insights into web application security testing and enhance your penetration testing skills with this OWASP volunteer-maintained tool.

Introduction to OWASP's Zed Attack Proxy - Web Application Penetration Testing

OWASP Foundation
Add to list