OWASP ZAP is great tool but it's not magic! When used in a CI/CD pipeline, ZAP needs some help to discover the routes through a web application. Basic authentication, user logins and form validation can all stop ZAP in its tracks. I show how to drive ZAP using Selenium scripts and increase the security coverage of a web application.
Speaker Bio: Mark Torrens works for Kainos as a Security Architect and this year is completing an MSc in Cyber Security at the University of York.
This lightning talk was presented at OWASP London Chapter Meeting on 30-Aug-2018 at Microsoft Reactor.
Presentation slides can be downloaded here: https://www.owasp.org/images/2/27/OWA...