In ZAP 2.16.0 we introduced a new Client Spider . This blog post and video explain why we did that, how it works, and where it’s going.
https://www.zaproxy.org/blog/2025-01-31-client-spider/
#zaproxy #appsec
Whats new in ZAP 2.16.0?
See the latest ZAP Chat video: https://youtu.be/o_IgsCaaQMo
#appsec #zaproxy
Yesterday marked 2 months of being employed by Checkmarx and working on Open Source (@zaproxy).
I'm having an absolute blast.
The team (both ZAP and CX) are very supportive. CX personnel trust our expertise, and knowledge . Being able to work fully remote is great, as everything I need to tackle can definitely be done remotely.
I've had a chance to dig into parts of ZAP's code base I haven't had an opportunity with before... (It's hard to dig into everything when it's just a "spare time" thing in evenings after a full day's work and life.) At the same time I've definitely experienced some imposter syndrome or challenges to my knowledge of Java, etc. The ZAP team is extremely supportive and just keep pushing me along, even if it has been kicking and screaming on occasion
I've been able to do some work with the Sequence add-on, the Automation Framework, Reports, and currently Authentication and Client Integration. So far the move has been great, glad I did it, and super glad that CX made it happen!!!!
ZAP 2.16.0 is coming "soon" - you can track the progress via https://github.com/zaproxy/zaproxy/issues/8706
#zaproxy #appsec
We have restarted the ZAP monthly blog posts: https://www.zaproxy.org/blog/2024-11-01-zap-updates-october-2024/
#zaproxy #appsec #dast
ZAP has joined forces with Checkmarx
This is a huge investment (and vote of confidence) in ZAP and will secure the project’s future success!
https://www.zaproxy.org/blog/2024-09-24-zap-has-joined-forces-with-checkmarx/
Want to get ZAP to perform an authenticated scan of DVWA?
With the Automation Framework its easy: https://www.zaproxy.org/faq/details/setting-up-zap-to-test-dvwa/
#zaproxy #dvwa #appsec
The polyfill domain might be down, but you should update your apps to use an alternative ASAP.
We have a new ZAP rule which will help you identify which of your sites are using scripts from that domain: https://www.zaproxy.org/blog/2024-06-27-polyfill.io-script-detection/
#zaproxy #polyfill #appsec
Do you use DAST from one of the many companies which build on top of ZAP but do not support us?
Please encourage them to support us now!
https://www.zaproxy.org/third-party-services/
#zaproxy #DAST #opensource
Should ZAP switch to a non OSI approved licence?
https://www.zaproxy.org/blog/2024-06-07-should-zap-switch-to-a-non-osi-licence/
We want your feedback!
#opensource #zaproxy
owkay! Starting this up in an hour. QmUgdGhlcmUgb3IgYmUgc3F1YXJlISA6UCA= https://twitch.tv/Ic_null #burpSUite #zaproxy #cybersecurity
We've been doing this a while. Let's SWING for the big leagues.
Tomorrow, we're doing a deep dive on #burpSuite from a #screenReader perspective. It will be mostly #blind (as in playthrough) as I've not looked at this program for a few years, and fully blind (as in sight) given ... well ... screenReader user :)
I've learned more, and hey who knows, maybe they've improved ......
If it turns out they haven't, we'll look at @zaproxy next as a more viable, generally more #accessible alternative. See you tomorrow at 3 EST over at https://twitch.tv/ic_null #infosec #cybersecurity #zaproxy #portswigger #java #programming
New @zaproxy community tip provided by yours truly (hit the GitHub link below).
#zaproxy #DAST #AppSec #WebAppSec
https://github.com/zaproxy/community-scripts/tree/main/other/tips/selenium/edge
Patch tuesday be upon us once more. That means another IC_Null stream at 3 PM EST/9 PM CEST today. Today we cover more #TryHackMe content in the #webHacking category. SOme announcements about the channel as well. Next week, we'll take a break from pure #THM to go full ham on #burpSuite #accessibility ... or the lack there of. Let's see how long it takes for us to be forced onto the far superior #zaproxy :) See you all tonight at https://twitch.tv/ic_null #infoSec #cybersecurity #blind #screenReader #a11y #twitch
New ZAP FAQ: Why does my Antivirus Tool Flag ZAP?
https://www.zaproxy.org/faq/why-does-my-antivirus-tool-flag-zap/
#zaproxy #appsec #antivirus