← All cheat sheets

ZAPROXY

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

OWASP ZAP (Zed Attack Proxy) is the world's most widely used web
application security scanner. It acts as a man-in-the-middle proxy
and provides automated scanners and tools for finding security
vulnerabilities in web applications.

LAUNCHING#

zaproxy                          # Launch GUI
zap.sh                           # Launch (alternative)
zap.sh -daemon                   # Headless daemon mode
zap.sh -cmd                      # Command-line mode

PROXY SETUP#

# Default: localhost:8080
# Configure browser proxy settings to 127.0.0.1:8080
# Import ZAP CA certificate for HTTPS interception:
# Tools → Options → Dynamic SSL Certificates → Save

SCAN MODES#

# Standard Mode     - Full functionality
# Safe Mode         - No potentially dangerous actions
# Protected Mode    - Can only scan in-scope targets
# ATTACK Mode       - Active scan on every request

AUTOMATED SCAN#

# Quick Start tab:
# 1. Enter target URL
# 2. Click "Attack"
# ZAP automatically spiders and active scans

SPIDER (CRAWLER)#

# Traditional Spider:
# Right-click URL → Attack → Spider
# Follows links to discover pages

# AJAX Spider:
# Right-click URL → Attack → AJAX Spider
# Uses browser to handle JavaScript-heavy apps

ACTIVE SCAN#

# Right-click URL → Attack → Active Scan
# Tests for vulnerabilities:
# - SQL Injection
# - XSS (Reflected, Stored)
# - Path Traversal
# - Remote File Inclusion
# - Command Injection
# - CRLF Injection
# - Parameter Tampering
# - And many more...

PASSIVE SCAN#

# Runs automatically on all proxied traffic
# Checks for:
# - Missing security headers
# - Cookie flags (HttpOnly, Secure)
# - Information disclosure
# - Weak authentication
# - Content Security Policy issues
# - CORS misconfiguration

MANUAL TESTING TOOLS#

# Intercepting Proxy:
# Break → Enable Break on all requests
# Modify requests/responses in real-time

# Fuzzer:
# Select parameter → Right-click → Fuzz
# - Built-in payload lists
# - Custom payloads
# - Multiple injection points

# Manual Request Editor:
# Tools → Manual Request Editor
# Craft and send custom HTTP requests

# Encode/Decode/Hash:
# Tools → Encode/Decode/Hash
# Base64, URL, HTML, Hex, etc.

CONTEXT & SCOPE#

# Define scope to limit scanning:
# Right-click URL → Include in Context

# Authentication:
# Context → Authentication
# - Form-based
# - Script-based
# - HTTP/NTLM
# - JSON-based
# - Manual

# Session Management:
# Context → Session Management
# - Cookie-based
# - HTTP Auth
# - Script-based

# Users:
# Context → Users
# Add test user credentials

AUTOMATION FRAMEWORK#

# ZAP automation via YAML:
# zap.sh -autorun automation.yaml

# Automation YAML structure:
# env:
#   contexts:
#     - name: "target"
#       urls: ["https://target.com"]
#   parameters:
#     failOnError: true
# jobs:
#   - type: spider
#     parameters:
#       maxDuration: 5
#   - type: activeScan
#     parameters:
#       maxRuleDurationInMins: 5

API#

# REST API available at: http://localhost:8080
# API Key in: Tools → Options → API

# Example API calls:
curl "http://localhost:8080/JSON/spider/action/scan/?url=<target>&apikey=<key>"
curl "http://localhost:8080/JSON/ascan/action/scan/?url=<target>&apikey=<key>"
curl "http://localhost:8080/JSON/core/view/alerts/?apikey=<key>"

# Python API client:
pip install python-owasp-zap-v2.4

CLI OPTIONS#

zap.sh -daemon -port 8090        # Daemon on custom port
zap.sh -daemon -host 0.0.0.0    # Listen on all interfaces
zap.sh -quickurl <url>           # Quick scan URL
zap.sh -quickout report.html     # Quick scan output
zap.sh -cmd -quickurl <url> -quickprogress
                                 # CLI quick scan with progress

REPORT GENERATION#

# Report → Generate Report
# Formats: HTML, XML, JSON, Markdown, PDF
# Customizable templates
# Risk levels: High, Medium, Low, Informational

ADD-ONS (MARKETPLACE)#

# Manage Add-ons → Marketplace
# Popular add-ons:
# - Active Scan Rules
# - Passive Scan Rules
# - Wappalyzer (Technology detection)
# - FuzzDB (Fuzzing payloads)
# - Retire.js (JS library vulnerabilities)
# - GraphQL Support
# - OpenAPI Support
# - Selenium (Browser integration)

KEYBOARD SHORTCUTS#

# Ctrl+L             - Show Sites panel
# Ctrl+H             - Show History panel
# Ctrl+B             - Toggle breakpoint
# Ctrl+Shift+B       - Toggle break on all
# Ctrl+F             - Find in response
# Ctrl+R             - Resend request
# F2                 - Toggle break

DOCKER#

# Stable image:
docker run -u zap -p 8080:8080 zaproxy/zap-stable zap.sh -daemon

# Baseline scan:
docker run zaproxy/zap-stable zap-baseline.py -t <url>

# Full scan:
docker run zaproxy/zap-stable zap-full-scan.py -t <url>

# API scan:
docker run zaproxy/zap-stable zap-api-scan.py -t <openapi_url> -f openapi

EXAMPLES#

# Quick automated scan:
# 1. Launch ZAP
# 2. Quick Start → Enter URL → Attack

# Authenticated scan:
# 1. Configure Context with auth
# 2. Add test users
# 3. Spider with authentication
# 4. Active Scan with authentication

# CI/CD integration:
zap.sh -cmd -quickurl https://target.com -quickout report.html -quickprogress

NOTES#

- Java-based (cross-platform)
- Open source (Apache 2.0 license)
- Active OWASP flagship project
- Large community and plugin ecosystem
- Excellent for CI/CD integration
- HUD (Heads Up Display) for in-browser testing
- Docker images available for automation
- Regular updates with new scan rules
- Best free alternative to Burp Suite Professional