Using OWASP ZAP to scan for vulnerabilities
OWASP ZAP is a tool that we have already used in this book for various tasks, and among its many features, it includes an automated vulnerability scanner. Its use and report generation will be covered in this recipe.
Before we perform a successful vulnerability scan in OWASP ZAP, we need to crawl the site:
- Open OWASP ZAP and configure the Web browser to use it as proxy.
- Navigate to
- Follow the instructions from Using ZAP's spider from Chapter 3, Crawlers and Spiders.
- Go to OWASP ZAP's Sites panel and right-click on the
- From the menu, navigate to Attack | Active Scan.
- A new window will pop up. At this point, we know what technology our application ...