Hamish M · @hmoffatt
9 followers · 192 posts · Server mastodon.au

I'm trying to run some scans in . I've loaded in my swagger API definition, but ZAP's active scan only does GET requests and never POST or PATCH or any other action I've defined, though they're all listed in the site tree. Is there a way to scan those methods too?

#zaproxy

Last updated 2 years ago

OWASP ZAP · @zaproxy
659 followers · 15 posts · Server infosec.exchange
OWASP ZAP · @zaproxy
610 followers · 13 posts · Server infosec.exchange
kingthorin_rm · @kingthorin_rm
104 followers · 197 posts · Server infosec.exchange

I have some ideas for the
@zaproxy
Form Handler add-on. So, why not tackle some SAST findings first? (Gave me a reason to start reading and familiarizing myself with the code 😉Plus helps the project.)

github.com/zaproxy/zap-extensi

#owasp #zaproxy #development #opensource

Last updated 3 years ago

OWASP ZAP · @zaproxy
607 followers · 12 posts · Server infosec.exchange

How to configure ZAP to handle difficult authentication use cases: zaproxy.org/blog/2023-02-01-au

#zaproxy #owasp #dast

Last updated 3 years ago

OWASP ZAP · @zaproxy
592 followers · 10 posts · Server infosec.exchange

Having problems configuring ZAP to handle authentication?
Help is on its way: zaproxy.org/blog/2023-01-19-au

#owasp #zaproxy

Last updated 3 years ago

kingthorin_rm · @kingthorin_rm
102 followers · 164 posts · Server infosec.exchange
Simon Bennetts ⚡ :verified: · @psiinon
540 followers · 120 posts · Server infosec.exchange
OWASP ZAP · @zaproxy
577 followers · 8 posts · Server infosec.exchange

Do you find ZAP useful?
You can show your appreciation by just starring the main repo: github.com/zaproxy/zaproxy
Every star counts⭐

#owasp #zaproxy #appsec

Last updated 3 years ago

kingthorin_rm · @kingthorin_rm
100 followers · 160 posts · Server infosec.exchange

Never a dull moment in

Some of my 2022 stats:

#opensource #owasp #zaproxy #webappsec #appsec

Last updated 3 years ago

OWASP ZAP · @zaproxy
554 followers · 6 posts · Server infosec.exchange

All of the core team are now on Mastodon!
See zaproxy.org/docs/team/

#owasp #zaproxy

Last updated 3 years ago

c0nsid3rate 🌱 · @c0nsid3rate
370 followers · 893 posts · Server infosec.exchange

33 machines rooted in the PEN-200 lab to-date...and still going. Note: 100% of web proxying I've done for training, learning, rooting in this platform has been done with @zaproxy .

#zaproxy #oscp #infosec #pentesting #learning

Last updated 3 years ago

kingthorin_rm · @kingthorin_rm
91 followers · 127 posts · Server infosec.exchange

My @hacktoberfest tree has been planted 😁

#opensource #owasp #zaproxy #hacktoberfest

Last updated 3 years ago

kingthorin_rm · @kingthorin_rm
86 followers · 121 posts · Server infosec.exchange

I did a thing:

Last week version 1.0.0 of the @zaproxy Encode/Decode/Hash add-on was released with a bunch of work I completed.

github.com/zaproxy/zap-extensi

#zaproxy #appsec #webappsec #redteam #purpleteam #owasp #bugbountytips #pentesting

Last updated 3 years ago

sumgr0 · @sumgr0
146 followers · 65 posts · Server infosec.exchange

RT @zaproxy@twitter.com

Version 1.0.0 of the Encode/Decode/Hash add-on was released earlier today with a bunch of work from @kingthorin_rm@twitter.com. Thanks!!!!

github.com/zaproxy/zap-extensi

🐦🔗: twitter.com/zaproxy/status/160

#zaproxy #appsec #webappsec #redteam #purpleteam #owasp #bugbountytips #pentesting

Last updated 3 years ago

Arg!!
Its Monday, time for the @zaproxy weekly build..

xvfb is seg faulting on debian:unstable-slim😞​
Why are we using `unstable` again?
Lets try with `stable` ... and xvfb works😀​
Great, we can now build the @zaproxy weekly build..

Except that debian:stable only directly supports firefox-esr .. which will not work with the latest webdrivers.
So now we have to install directly..

Anyway, thats why there is no new weekly release yet .. hows your week going so far?

#firefox #owasp #zaproxy

Last updated 3 years ago

Ooops!
Just realised we had not updated the roadmap in a while!
Looking better now: zaproxy.org/docs/roadmap/

#owasp #zaproxy

Last updated 3 years ago

magikh0e :valid: · @magikh0e
145 followers · 155 posts · Server infosec.exchange

cool, you can colorize @zaproxy output using addon

Works with tag or arbitrary assignments

#neonmarker #bugbounty #bugbountytips #zaproxy #owasp #appsec

Last updated 3 years ago

kingthorin_rm · @kingthorin_rm
73 followers · 65 posts · Server infosec.exchange

Did you know you can color history items in w/ the Neonmarker add-on? Which now support coloring based on tags as well as arbitrary assignments.

#zaproxy #owasp #appsec #webappsec #bugbountytip #redteam #purpleteam #pentesting #pentest

Last updated 3 years ago