Intro to ZAP
A Fanboy’s Perspective
What is ZAP?
Zed Attack Proxy
Breakers
Builders
Project Overview
Apache 2 License
Free + Open Source
Enduring
OWASP Flagship
Simon Bennetts (psiinon)�Ricardo Pereira (thc202)�Rick Mitchell (kingthorin)
Great Community
Over 10 Years old!
First Steps
What is a Proxy
Browser
Proxy
Application
TLS Connection to application
TLS Connection to proxy
ZAP issued Certificate
Twitter issued Certificate
Start Intercepting Traffic
Start Intercepting Traffic
Start Intercepting Traffic
Start Intercepting Traffic
Understanding ZAP’s Layout
Common Manual Testing Tasks
Targeting an Application
Intercepting Requests
Intercepting Requests
Repeating a Request
Sending a Lot of Requests
Decoding and Encoding Data
Decoding and Encoding Data But make it Fancy
Scripting in ZAP
HTTP Sender Scripts
Extender Scripts
Custom Scan Rules
Dealing with Callback Traffic
Payload triggers on backend
SSH Port Forwarding
Dealing with Callback Traffic
Dealing with Callback Traffic
Deploying as a Scanner
Deployment Options
API Features
Github Actions
Final Thoughts
Nice
Not Nice
More ZAP Resources
Thanks!