Using OWASP ZAP to Identify Web Vulnerabilities on Metasploitable

Опубликовано: 22 Март 2026
на канале: Ultra Blue Tech
909
16

Welcome to the Ultra Blue Channel! In this tutorial, we’ll show you how to use OWASP ZAP (Zed Attack Proxy) to identify web application vulnerabilities on Metasploitable, an intentionally vulnerable virtual machine designed for penetration testing and security training.

In this comprehensive guide, you'll learn:

How to set up Metasploitable and configure it for testing
How to install and launch OWASP ZAP on Kali Linux
How to use OWASP ZAP to perform automated and manual scans
How to generate reports and identify common web vulnerabilities like SQL injection, XSS, and Remote File Inclusion (RFI)
This video is perfect for both beginners who want to learn vulnerability scanning and security experts looking to sharpen their penetration testing skills.
#OWASPZAP #Metasploitable #VulnerabilityScanning #WebSecurity #EthicalHacking #CyberSecurity #PenetrationTesting #KaliLinux #UltraBlueChannel

Timestamps
0:00 – Introduction
0:30 – How to download OWASP ZAP on Kali Linux
4:43 – How to lunch OWASP ZAP on Kali Linux
6:05 – How to configure OWASP ZAP on Kali Linux
7:45 – Spidering the Target for Pages using OWASP ZAP on Kali Linux
7:20 – Scanning for Vulnerabilities with OWASP ZAP on Kali Linux
8:30 – Reviewing Vulnerability Results in OWASP ZAP on Kali Linux
9:00 – Example Vulnerabilities: SQL Injection, XSS, and RFI
10:10 – Conclusion and Disclaimer