Vulnerability Detection

ZAP – web app scanner

The Zed Attack Proxy (ZAP) is a web app scanner.

It can help you automatically find security vulnerabilities in your web applications while you are developing and testing your applications. It’s also a tool for experienced pentesters to use for manual security testing.

At its core, ZAP is what is known as a “manipulator-in-the-middle proxy.” It stands between the tester’s browser and the web application so that it can intercept and inspect messages sent between browser and web application, modify the contents if needed, and then forward those packets on to the destination. It can be used as a stand-alone application, and as a daemon process.

ZAP provides functionality for a range of skill levels – from developers, to testers new to security testing, to security testing specialists. ZAP has versions for each major OS and Docker, so you are not tied to a single OS. Additional functionality is freely available from a variety of add-ons in the ZAP Marketplace, accessible from within the ZAP client.

This is free and open source software.

Website: github.com/zaproxy/zaproxy
Support:
Developer: Checkmarx
License: Apache License 2.0

ZAP is written in Java. Learn Java with our recommended free books and free tutorials.


Related Software

Vulnerability Detection Tools
sqlmapAutomates testing and exploitation of SQL injection flaws
NucleiFast and customisable vulnerability scanner
OpenVASFull-featured vulnerability scanner
NiktoWeb server scanner
OWASP ZAPPopular web application security scanner and penetration testing proxy
VulsAgentless security scanner for Linux, FreeBSD and network environments
TsunamiExtensible network security scanner for identifying exposed services
OSV-ScannerScans projects and dependencies against the OSV database
grypeVulnerability scanner for container images and filesystems
DalfoxFast command-line tool for analysing and exploiting XSS flaws
WapitiBlack-box web application scanner with broad attack coverage
testssl.shTests TLS/SSL services, protocols, ciphers and cryptographic weaknesses
jSQL Injection Java tool for automatically testing and exploiting SQL injection flaws
sifPenetration testing suite combining reconnaissance and exploitation tools
XSSerAutomates testing, exploitation and reporting of cross-site scripting flaws
TerrapinTerrapin Vulnerability Scanner for the Terrapin attack
TrivyComprehensive and versatile security scanner

Read our verdict in the software roundup.

Security Testing
ZAPWeb app scanner
mitmproxyInteractive HTTPS proxy
WfuzzWeb application fuzzer and Python library for security assessments
sqlmapPenetration testing tool
InterceptSuiteNetwork traffic interception tool
DalfoxIdentify cross-site scripting vulnerabilities in web applications
CommixPython-based penetration testing tool
BURPAccelerate application security testing

Read our verdict in the software roundup.


Best Free and Open Source Software Explore our carefully curated directory of recommended free and open source software, covering every major software category.

The directory forms part of our extensive collection of articles for Linux enthusiasts. It includes hundreds of detailed reviews, together with free and open source alternatives to proprietary software from companies such as Google, Microsoft, Apple, Adobe, IBM, Cisco, Oracle, and Autodesk.

LinuxLinks also covers interesting projects worth exploring, Linux-compatible hardware, free programming books and tutorials, and much more.

Know a useful free and open source Linux application that we haven’t covered? Tell us about it using our submission form.
Subscribe

Please read our Comment Policy before commenting.

Notify of
guest
0 Comments
Oldest
Newest Most Voted