ZAPROXY
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
OVERVIEW#
OWASP ZAP (Zed Attack Proxy) is the world's most widely used web application security scanner. It acts as a man-in-the-middle proxy and provides automated scanners and tools for finding security vulnerabilities in web applications.
LAUNCHING#
zaproxy # Launch GUI zap.sh # Launch (alternative) zap.sh -daemon # Headless daemon mode zap.sh -cmd # Command-line mode
PROXY SETUP#
# Default: localhost:8080 # Configure browser proxy settings to 127.0.0.1:8080 # Import ZAP CA certificate for HTTPS interception: # Tools → Options → Dynamic SSL Certificates → Save
SCAN MODES#
# Standard Mode - Full functionality # Safe Mode - No potentially dangerous actions # Protected Mode - Can only scan in-scope targets # ATTACK Mode - Active scan on every request
AUTOMATED SCAN#
# Quick Start tab: # 1. Enter target URL # 2. Click "Attack" # ZAP automatically spiders and active scans
SPIDER (CRAWLER)#
# Traditional Spider: # Right-click URL → Attack → Spider # Follows links to discover pages # AJAX Spider: # Right-click URL → Attack → AJAX Spider # Uses browser to handle JavaScript-heavy apps
ACTIVE SCAN#
# Right-click URL → Attack → Active Scan # Tests for vulnerabilities: # - SQL Injection # - XSS (Reflected, Stored) # - Path Traversal # - Remote File Inclusion # - Command Injection # - CRLF Injection # - Parameter Tampering # - And many more...
PASSIVE SCAN#
# Runs automatically on all proxied traffic # Checks for: # - Missing security headers # - Cookie flags (HttpOnly, Secure) # - Information disclosure # - Weak authentication # - Content Security Policy issues # - CORS misconfiguration
MANUAL TESTING TOOLS#
# Intercepting Proxy: # Break → Enable Break on all requests # Modify requests/responses in real-time # Fuzzer: # Select parameter → Right-click → Fuzz # - Built-in payload lists # - Custom payloads # - Multiple injection points # Manual Request Editor: # Tools → Manual Request Editor # Craft and send custom HTTP requests # Encode/Decode/Hash: # Tools → Encode/Decode/Hash # Base64, URL, HTML, Hex, etc.
CONTEXT & SCOPE#
# Define scope to limit scanning: # Right-click URL → Include in Context # Authentication: # Context → Authentication # - Form-based # - Script-based # - HTTP/NTLM # - JSON-based # - Manual # Session Management: # Context → Session Management # - Cookie-based # - HTTP Auth # - Script-based # Users: # Context → Users # Add test user credentials
AUTOMATION FRAMEWORK#
# ZAP automation via YAML: # zap.sh -autorun automation.yaml # Automation YAML structure: # env: # contexts: # - name: "target" # urls: ["https://target.com"] # parameters: # failOnError: true # jobs: # - type: spider # parameters: # maxDuration: 5 # - type: activeScan # parameters: # maxRuleDurationInMins: 5
API#
# REST API available at: http://localhost:8080 # API Key in: Tools → Options → API # Example API calls: curl "http://localhost:8080/JSON/spider/action/scan/?url=<target>&apikey=<key>" curl "http://localhost:8080/JSON/ascan/action/scan/?url=<target>&apikey=<key>" curl "http://localhost:8080/JSON/core/view/alerts/?apikey=<key>" # Python API client: pip install python-owasp-zap-v2.4
CLI OPTIONS#
zap.sh -daemon -port 8090 # Daemon on custom port
zap.sh -daemon -host 0.0.0.0 # Listen on all interfaces
zap.sh -quickurl <url> # Quick scan URL
zap.sh -quickout report.html # Quick scan output
zap.sh -cmd -quickurl <url> -quickprogress
# CLI quick scan with progress
REPORT GENERATION#
# Report → Generate Report # Formats: HTML, XML, JSON, Markdown, PDF # Customizable templates # Risk levels: High, Medium, Low, Informational
ADD-ONS (MARKETPLACE)#
# Manage Add-ons → Marketplace # Popular add-ons: # - Active Scan Rules # - Passive Scan Rules # - Wappalyzer (Technology detection) # - FuzzDB (Fuzzing payloads) # - Retire.js (JS library vulnerabilities) # - GraphQL Support # - OpenAPI Support # - Selenium (Browser integration)
KEYBOARD SHORTCUTS#
# Ctrl+L - Show Sites panel # Ctrl+H - Show History panel # Ctrl+B - Toggle breakpoint # Ctrl+Shift+B - Toggle break on all # Ctrl+F - Find in response # Ctrl+R - Resend request # F2 - Toggle break
DOCKER#
# Stable image: docker run -u zap -p 8080:8080 zaproxy/zap-stable zap.sh -daemon # Baseline scan: docker run zaproxy/zap-stable zap-baseline.py -t <url> # Full scan: docker run zaproxy/zap-stable zap-full-scan.py -t <url> # API scan: docker run zaproxy/zap-stable zap-api-scan.py -t <openapi_url> -f openapi
EXAMPLES#
# Quick automated scan: # 1. Launch ZAP # 2. Quick Start → Enter URL → Attack # Authenticated scan: # 1. Configure Context with auth # 2. Add test users # 3. Spider with authentication # 4. Active Scan with authentication # CI/CD integration: zap.sh -cmd -quickurl https://target.com -quickout report.html -quickprogress
NOTES#
- Java-based (cross-platform) - Open source (Apache 2.0 license) - Active OWASP flagship project - Large community and plugin ecosystem - Excellent for CI/CD integration - HUD (Heads Up Display) for in-browser testing - Docker images available for automation - Regular updates with new scan rules - Best free alternative to Burp Suite Professional