Tactical ZAP: Tips and Tricks to Using Our Favorite Open-Source Web PenTesting Tool!
Mic Whitehorn (@mic_wg) and Aaron Moss (@hotdogggitty) will explore the various features of OWASP Zed Attack Proxy (ZAP) and walk through how to use it for testing web applications and finding vulnerabilities. The webinar will consist mostly of practical examples and demonstrations so that attendees can follow-along.
Those wishing to do so will need to download and install SamuraiWTF (https://github.com/SamuraiWTF/samuraiwtf) before the webinar. Vulnerable targets will include OWASP Juice Shop and Samurai’s Dojo Basic. Attendees will learn how to use ZAP as an interception and attack proxy to identify and exploit common web application vulnerabilities in these deliberately vulnerable webapps. If you ever wanted to learn how to do some basic webapp PenTesting, here’s your chance! This webinar will run for approximately two hours.
Laptop requirements to follow along:
Desktop virtualization software (VirtualBox, VMware Workstation/Fusion, or Hyper-V)
SamuraiWTF with OWASP Juice Shop and Dojo-Basic installed
A minimum of 8GB RAM and 30GB free HD space