<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Psiinon</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Psiinon"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Psiinon"/>
		<updated>2026-05-26T08:51:02Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Zed_Attack_Proxy_Project&amp;diff=256643</id>
		<title>OWASP Zed Attack Proxy Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Zed_Attack_Proxy_Project&amp;diff=256643"/>
				<updated>2020-01-15T16:50:15Z</updated>
		
		<summary type="html">&lt;p&gt;Psiinon: Changed to link to the new ZAP website&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;div style=&amp;quot;width:100%;height:90px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File: flagship_big.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
{{ReviewProject|projectname=zaproxy|language=en}}&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
For more details about ZAP see the new ZAP website at [https://www.zaproxy.org zaproxy.org][[Image:Zap-website.png | link=https://www.zaproxy.org/]]&lt;br /&gt;
&lt;br /&gt;
{{Social Media Links}}&lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;padding-left:25px;width:200px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
[https://github.com/zaproxy/zaproxy/wiki/Downloads Download OWASP ZAP!]&lt;br /&gt;
&lt;br /&gt;
== Donate to ZAP ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div class=&amp;quot;center&amp;quot; style=&amp;quot;width: auto; margin-left: auto; margin-right: auto;&amp;quot;&amp;gt;{{#widget:PayPal Donation&lt;br /&gt;
|target=_blank&lt;br /&gt;
|budget=Zed Attack Proxy }}&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
Please see the [https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project#News News] and [https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project#Talks Talks] tabs&lt;br /&gt;
&lt;br /&gt;
== Change Log ==&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/commits/develop zaproxy]&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/commits/master zap-extensions]&lt;br /&gt;
&lt;br /&gt;
== Code Repo ==&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/ zaproxy]&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/ zap-extensions]&lt;br /&gt;
&lt;br /&gt;
== Email List ==&lt;br /&gt;
&lt;br /&gt;
Questions? Please ask on the [http://groups.google.com/group/zaproxy-users ZAP User Group]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
Project Leader&amp;lt;br /&amp;gt;[https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @]&lt;br /&gt;
&lt;br /&gt;
Co-Project Leaders&amp;lt;br /&amp;gt;[https://www.owasp.org/index.php/User:Ricardo.Pereira Ricardo Pereira] [mailto:ricardo.pereira@owasp.org @]&lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/index.php/User:Rick.mitchell Rick Mitchell] [mailto:rick.mitchell+wiki@owasp.org @]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_Web_Testing_Environment_Project OWASP WTE]&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_OWTF OWASP OWTF]&lt;br /&gt;
&lt;br /&gt;
== Open Hub Stats ==&lt;br /&gt;
&lt;br /&gt;
*https://www.openhub.net/p/zaproxy&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Mature projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Flagship_Projects]]&lt;br /&gt;
   | width=&amp;quot;50%&amp;quot; valign=&amp;quot;center&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Owasp-builders-small.png|link=]]&lt;br /&gt;
   |&lt;br /&gt;
   |-&lt;br /&gt;
   | width=&amp;quot;50%&amp;quot; valign=&amp;quot;center&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Owasp-breakers-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [http://www.apache.org/licenses/LICENSE-2.0 Apache 2 License]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_TOOL.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
[[Category:OWASP Project|Zed Attack Proxy Project]]&lt;br /&gt;
[[Category:OWASP_Tool]]&lt;br /&gt;
[[Category:OWASP Release Quality Tool|OWASP Release Quality Tool]]&lt;br /&gt;
[[Category:OWASP_Download]]&lt;br /&gt;
[[Category:Popular]]&lt;br /&gt;
[[Category:SAMM-ST-2]]&lt;br /&gt;
[[Category:Flagship Projects|Zap]]&lt;br /&gt;
[[Category:OWASP Zed Attack Proxy|Zap]]&lt;/div&gt;</summary>
		<author><name>Psiinon</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:Zap-website.png&amp;diff=256641</id>
		<title>File:Zap-website.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:Zap-website.png&amp;diff=256641"/>
				<updated>2020-01-15T16:32:53Z</updated>
		
		<summary type="html">&lt;p&gt;Psiinon: Screenshot of the ZAP website&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Screenshot of the ZAP website&lt;/div&gt;</summary>
		<author><name>Psiinon</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Zed_Attack_Proxy_Project&amp;diff=256598</id>
		<title>OWASP Zed Attack Proxy Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Zed_Attack_Proxy_Project&amp;diff=256598"/>
				<updated>2020-01-09T16:54:13Z</updated>
		
		<summary type="html">&lt;p&gt;Psiinon: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Main = &lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:90px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File: flagship_big.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
{{ReviewProject|projectname=zaproxy|language=en}}&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
The OWASP Zed Attack Proxy (ZAP) is one of the world’s most popular free security tools and is actively maintained by hundreds of international volunteers[[#Justification|*]]. It can help you automatically find security vulnerabilities in your web applications while you are developing and testing your applications. Its also a great tool for experienced pentesters to use for manual security testing.&lt;br /&gt;
&lt;br /&gt;
[[Image:ZAP-Download.png | link=https://github.com/zaproxy/zaproxy/wiki/Downloads]]&lt;br /&gt;
&lt;br /&gt;
====ZAP in Ten - Video series====&lt;br /&gt;
An ongoing series of up to 10 minute videos about ZAP, starting with the basics. &lt;br /&gt;
&lt;br /&gt;
The first episode and the full series are available via:&lt;br /&gt;
&lt;br /&gt;
[[Image:01-ZAP-in-Ten-small.png | link=http://play.sonatype.com/watch/RyTy22GZV6UccW41UCghC8?]]&lt;br /&gt;
&lt;br /&gt;
[[Image:02-ZAP-in-Ten-small.png | link=https://www.alldaydevops.com/zap-in-ten]]&lt;br /&gt;
&lt;br /&gt;
====Please help us to make ZAP even better for you by answering the [https://docs.google.com/forms/d/e/1FAIpQLSeJDCJg0M_H0sC666yx4PZwfyBTwnh0HwzTUKdYB7zmSBE0Nw/viewform ZAP User Questionnaire]!====&lt;br /&gt;
&lt;br /&gt;
Interested in a ZAP talk or training event? See the [https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project#tab=Talks talks] tab. Not one near you? Contact a [https://github.com/zaproxy/zaproxy/wiki/ZapEvangelists Zap Evangelist] to arrange one!&lt;br /&gt;
&lt;br /&gt;
For general information about ZAP:&lt;br /&gt;
* [https://twitter.com/zaproxy Twitter] - official ZAP announcements (low volume)&lt;br /&gt;
* [https://zaproxy.blogspot.co.uk/ Blog] - official ZAP blog&lt;br /&gt;
&lt;br /&gt;
For help using ZAP:&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/releases/download/v2.8.0/ZAPGettingStartedGuide-2.8.pdf Getting Started Guide (pdf)] - an introductory guide you can print&lt;br /&gt;
* [https://www.youtube.com/playlist?list=PLEBitBW-Hlsv8cEIUntAO8st2UGhmrjUB Tutorial Videos]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki User Guide] - online version of the User Guide included with ZAP&lt;br /&gt;
* [https://groups.google.com/group/zaproxy-users User Group] - ask questions about using ZAP&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/wiki Add-ons] - help for the optional add-ons you can install&lt;br /&gt;
* [https://stackoverflow.com/questions/tagged/zap StackOverflow] - because some people use this for all everything ;)&lt;br /&gt;
&lt;br /&gt;
To learn more about ZAP development:&lt;br /&gt;
* [https://github.com/zaproxy Source Code] - for all of the ZAP related projects&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/wiki/Introduction Wiki] - lots of detailed info&lt;br /&gt;
* [https://groups.google.com/group/zaproxy-develop Developer Group] - ask questions about the ZAP internals&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap Crowdin (GUI)] - help translate the ZAP GUI&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap-help Crowdin (User Guide)] - help translate the ZAP User Guide&lt;br /&gt;
* [https://www.openhub.net/p/zaproxy OpenHub]	- FOSS analytics&lt;br /&gt;
* [https://www.bountysource.com/teams/zap/issues BountySource] - Vote on ZAP issues (you can also donate money here, but 10% taken out)&lt;br /&gt;
&lt;br /&gt;
===Justification===&lt;br /&gt;
Justification for the statements made in the tagline at the top;)&lt;br /&gt;
&lt;br /&gt;
Popularity:&lt;br /&gt;
* ToolsWatch Annual Best Free/Open Source Security Tool Survey:&lt;br /&gt;
** 2016 [http://www.toolswatch.org/2017/02/2016-top-security-tools-as-voted-by-toolswatch-org-readers/ 2nd]&lt;br /&gt;
** 2015 [http://www.toolswatch.org/2016/02/2015-top-security-tools-as-voted-by-toolswatch-org-readers/ 1st]&lt;br /&gt;
** 2014 [http://www.toolswatch.org/2015/01/2014-top-security-tools-as-voted-by-toolswatch-org-readers/ 2nd]&lt;br /&gt;
** 2013 [http://www.toolswatch.org/2013/12/2013-top-security-tools-as-voted-by-toolswatch-org-readers/ 1st]&lt;br /&gt;
&lt;br /&gt;
Contributors:&lt;br /&gt;
* [https://www.openhub.net/p/zaproxy Code Contributors]&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap ZAP core i18n Contributors]&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap-help ZAP help i18n Contributors]&lt;br /&gt;
&lt;br /&gt;
{{Social Media Links}}&lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;padding-left:25px;width:200px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
[https://github.com/zaproxy/zaproxy/wiki/Downloads Download OWASP ZAP!]&lt;br /&gt;
&lt;br /&gt;
== Donate to ZAP ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div class=&amp;quot;center&amp;quot; style=&amp;quot;width: auto; margin-left: auto; margin-right: auto;&amp;quot;&amp;gt;{{#widget:PayPal Donation&lt;br /&gt;
|target=_blank&lt;br /&gt;
|budget=Zed Attack Proxy }}&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
Please see the [https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project#News News] and [https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project#Talks Talks] tabs&lt;br /&gt;
&lt;br /&gt;
== Change Log ==&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/commits/develop zaproxy]&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/commits/master zap-extensions]&lt;br /&gt;
&lt;br /&gt;
== Code Repo ==&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/ zaproxy]&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/ zap-extensions]&lt;br /&gt;
&lt;br /&gt;
== Email List ==&lt;br /&gt;
&lt;br /&gt;
Questions? Please ask on the [http://groups.google.com/group/zaproxy-users ZAP User Group]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
Project Leader&amp;lt;br /&amp;gt;[https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @]&lt;br /&gt;
&lt;br /&gt;
Co-Project Leaders&amp;lt;br /&amp;gt;[https://www.owasp.org/index.php/User:Ricardo.Pereira Ricardo Pereira] [mailto:ricardo.pereira@owasp.org @]&lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/index.php/User:Rick.mitchell Rick Mitchell] [mailto:rick.mitchell+wiki@owasp.org @]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_Web_Testing_Environment_Project OWASP WTE]&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_OWTF OWASP OWTF]&lt;br /&gt;
&lt;br /&gt;
== Open Hub Stats ==&lt;br /&gt;
&lt;br /&gt;
*https://www.openhub.net/p/zaproxy&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| cellpadding=&amp;quot;2&amp;quot; width=&amp;quot;200&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; | [[File:Mature projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Flagship_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; width=&amp;quot;50%&amp;quot; valign=&amp;quot;center&amp;quot; | [[File:Owasp-builders-small.png|link=]]&lt;br /&gt;
   |&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; width=&amp;quot;50%&amp;quot; valign=&amp;quot;center&amp;quot; | [[File:Owasp-breakers-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [http://www.apache.org/licenses/LICENSE-2.0 Apache 2 License]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_TOOL.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Screenshots =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotAddAlert.png|||400px|ZAP Add Alert Screen Shot]] &lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotHelp.png||400px|left|ZAP Help Screen Shot]]&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotHistoryFilter.png|thumb|400px|left|ZAP History Filter Screen Shot]]&lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotSearchTab.png|thumb|400px|left|ZAP Search Tab Screen Shot]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Talks =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
{{:Projects/OWASP Zed Attack Proxy Project/Pages/Talks | Talks}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
= News =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
{{:Projects/OWASP Zed Attack Proxy Project/Pages/News | News}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
= ZAP Gear =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Yes, you can now buy ZAP related gear!&lt;br /&gt;
&lt;br /&gt;
All of the artwork for ZAP swag is released under the Creative Common License and can be downloaded from the [https://github.com/zaproxy/zap-swag zap-swag] repo.&lt;br /&gt;
&lt;br /&gt;
You can of course use the artwork from this repo with any other online store that you like.&lt;br /&gt;
&lt;br /&gt;
A range of products can be purchased from [http://www.redbubble.com/people/zaproxy Redbubble]&lt;br /&gt;
&lt;br /&gt;
T-shirts can be purchased from [http://www.cafepress.com/zaproxy Cafepress]&lt;br /&gt;
&lt;br /&gt;
[[Image:zap-tshirt-cp.PNG | link=http://www.cafepress.com/zaproxy]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Supporters =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
ZAP is developed by a worldwide [https://github.com/zaproxy/zap-core-help/wiki/HelpCredits team] of volunteers.&lt;br /&gt;
&lt;br /&gt;
But we have also been helped by many organizations, either financially or by encouraging their employees to work on ZAP:&lt;br /&gt;
&lt;br /&gt;
* [http://www.mozilla.org Mozilla]&lt;br /&gt;
* [http://www.linuxfoundation.org/ The Linux Foundation]&lt;br /&gt;
* [https://segment.com/ Segment]&lt;br /&gt;
* [http://www.owasp.org OWASP]&lt;br /&gt;
* [http://www.sage.co.uk Sage]&lt;br /&gt;
* [http://www.google.com Google]&lt;br /&gt;
* [http://www.microsoft.com Microsoft]&lt;br /&gt;
* [http://www.hacktics.com/ Hacktics, Ernst &amp;amp; Young]&lt;br /&gt;
* [http://www.dinosec.com/ DinoSec]&lt;br /&gt;
* [http://www.denimgroup.com Denim Group]&lt;br /&gt;
* [http://www.aspectsecurity.com/ Aspect Security]&lt;br /&gt;
* [http://secureideas.net SecureIdeas]&lt;br /&gt;
* [http://utilisec.com UtiliSec]&lt;br /&gt;
* [http://www.encription.co.uk/ encription]&lt;br /&gt;
* [https://www.accenture.com/us-en/digital-index.aspx Accenture Digital]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Functionality =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
'''Some of ZAP's functionality:'''&lt;br /&gt;
&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsIntercept Man-in-the-middle Proxy]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsSpider Traditional] and AJAX spiders&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsAscan Automated scanner]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsPscan Passive scanner]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsBruteforce Forced browsing]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsFuzz Fuzzer]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpUiDialogsOptionsDynsslcert Dynamic SSL certificates]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/SmartCards Smartcard and Client Digital Certificates support]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpAddonsWebsocketIntroduction Web sockets] support&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpAddonsScriptsScripts Support for a wide range of scripting languages]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki//HelpAddonsPlugnhackPlugnhack Plug-n-Hack support]&lt;br /&gt;
* Authentication and session support&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsApi Powerful REST based API]&lt;br /&gt;
* Automatic updating option&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/wiki Integrated and growing marketplace of add-ons]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
= Features =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
'''Some of ZAP's features:'''&lt;br /&gt;
&lt;br /&gt;
* [http://www.apache.org/licenses/LICENSE-2.0 Open source]&lt;br /&gt;
* Cross platform (it even runs on a [https://github.com/zaproxy/zaproxy/wiki/zappi Raspberry Pi!])&lt;br /&gt;
* Easy to install (using a [https://www.ej-technologies.com/products/install4j/overview.html multi-platform installer builder])&lt;br /&gt;
* Completely free (no paid for 'Pro' version)&lt;br /&gt;
* Ease of use a priority&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpIntro Comprehensive help pages]&lt;br /&gt;
* Fully internationalized&lt;br /&gt;
* Translated into over 20 languages&lt;br /&gt;
* Community based, with involvement actively encouraged&lt;br /&gt;
* Under active development by an international team of volunteers&lt;br /&gt;
&lt;br /&gt;
ZAP is a fork of the well regarded [http://www.parosproxy.org/ Paros Proxy].&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Languages =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''ZAP supports the following languages:'''&lt;br /&gt;
&lt;br /&gt;
* English&lt;br /&gt;
* Arabic&lt;br /&gt;
* Bosnian&lt;br /&gt;
* Brazilian Portuguese&lt;br /&gt;
* Chinese&lt;br /&gt;
* Danish&lt;br /&gt;
* Filipino&lt;br /&gt;
* French&lt;br /&gt;
* German&lt;br /&gt;
* Greek&lt;br /&gt;
* Hungarian&lt;br /&gt;
* Indonesian&lt;br /&gt;
* Italian&lt;br /&gt;
* Japanese&lt;br /&gt;
* Korean&lt;br /&gt;
* Persian&lt;br /&gt;
* Polish&lt;br /&gt;
* Russian&lt;br /&gt;
* Sinhala&lt;br /&gt;
* Spanish&lt;br /&gt;
* Urdu &lt;br /&gt;
&lt;br /&gt;
You can use [http://crowdin.net/project/owasp-zap Crowdin] to help improve these translations or add new ones right now!&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Release 2.6.0==&lt;br /&gt;
ZAP 2.6.0 has been released, this is a bug fix and enhancement release&lt;br /&gt;
&lt;br /&gt;
For more details see https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_6_0&lt;br /&gt;
&lt;br /&gt;
==Release 2.7.0==&lt;br /&gt;
ZAP 2.7.0 has been released (Nov 2017), this is a bug fix and enhancement release&lt;br /&gt;
&lt;br /&gt;
For more details see https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_7_0&lt;br /&gt;
&lt;br /&gt;
It requires Java 8 (minimum) and supports Selenium 3.&lt;br /&gt;
&lt;br /&gt;
==Release 2.8.0==&lt;br /&gt;
ZAP 2.8.0 has been released (June 2019), this is a bug fix and enhancement release&lt;br /&gt;
&lt;br /&gt;
For more details see https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_8_0&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Get Involved =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Involvement in the development of ZAP is actively encouraged!&lt;br /&gt;
&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
&lt;br /&gt;
Some of the ways you can help:&lt;br /&gt;
&lt;br /&gt;
==Feature Requests==&lt;br /&gt;
&lt;br /&gt;
Please raise new feature requests as enhancement requests here: https://github.com/zaproxy/zaproxy/issues&lt;br /&gt;
&lt;br /&gt;
If there are existing requests you are also interested in then please 'star' them - that way we can see which features people are most interested in and can prioritize them accordingly. &lt;br /&gt;
&lt;br /&gt;
==Feedback==&lt;br /&gt;
&lt;br /&gt;
Please use the [http://groups.google.com/group/zaproxy-users zaproxy-users Google Group] for feedback:&lt;br /&gt;
* What do like?&lt;br /&gt;
* What don't you like?&lt;br /&gt;
* What features could be made easier to use?&lt;br /&gt;
* How could the help pages be improved? &lt;br /&gt;
&lt;br /&gt;
==Log issues==&lt;br /&gt;
&lt;br /&gt;
Have you had a problem using ZAP?&lt;br /&gt;
&lt;br /&gt;
If so and its not already been logged then please [https://github.com/zaproxy/zaproxy/issues report it]&lt;br /&gt;
&lt;br /&gt;
==Localization==&lt;br /&gt;
&lt;br /&gt;
Are you fluent in another language? Can you help translate ZAP into that language?&lt;br /&gt;
&lt;br /&gt;
You can use [http://crowdin.net/project/owasp-zap Crowdin] to do that!&lt;br /&gt;
&lt;br /&gt;
==Development==&lt;br /&gt;
&lt;br /&gt;
If you fancy having a go at adding functionality to ZAP then please get in touch via the [http://groups.google.com/group/zaproxy-develop zaproxy-develop Google Group].&lt;br /&gt;
&lt;br /&gt;
Again, you do not have to be a security expert to contribute code - working on ZAP could be great way to learn more about web application security!&lt;br /&gt;
&lt;br /&gt;
If you actively contribute to ZAP then you will be invited to join the project. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project|Zed Attack Proxy Project]]&lt;br /&gt;
[[Category:OWASP_Tool]]&lt;br /&gt;
[[Category:OWASP Release Quality Tool|OWASP Release Quality Tool]]&lt;br /&gt;
[[Category:OWASP_Download]]&lt;br /&gt;
[[Category:Popular]]&lt;br /&gt;
[[Category:SAMM-ST-2]]&lt;br /&gt;
[[Category:Flagship Projects|Zap]]&lt;br /&gt;
[[Category:OWASP Zed Attack Proxy|Zap]]&lt;/div&gt;</summary>
		<author><name>Psiinon</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Zed_Attack_Proxy_Project&amp;diff=256597</id>
		<title>OWASP Zed Attack Proxy Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Zed_Attack_Proxy_Project&amp;diff=256597"/>
				<updated>2020-01-09T16:53:03Z</updated>
		
		<summary type="html">&lt;p&gt;Psiinon: Updated the questionnaire link&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Main = &lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:90px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File: flagship_big.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
{{ReviewProject|projectname=zaproxy|language=en}}&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
The OWASP Zed Attack Proxy (ZAP) is one of the world’s most popular free security tools and is actively maintained by hundreds of international volunteers[[#Justification|*]]. It can help you automatically find security vulnerabilities in your web applications while you are developing and testing your applications. Its also a great tool for experienced pentesters to use for manual security testing.&lt;br /&gt;
&lt;br /&gt;
[[Image:ZAP-Download.png | link=https://github.com/zaproxy/zaproxy/wiki/Downloads]]&lt;br /&gt;
&lt;br /&gt;
====ZAP in Ten - Video series====&lt;br /&gt;
An ongoing series of up to 10 minute videos about ZAP, starting with the basics. &lt;br /&gt;
&lt;br /&gt;
The first episode and the full series are available via:&lt;br /&gt;
&lt;br /&gt;
[[Image:01-ZAP-in-Ten-small.png | link=http://play.sonatype.com/watch/RyTy22GZV6UccW41UCghC8?]]&lt;br /&gt;
&lt;br /&gt;
[[Image:02-ZAP-in-Ten-small.png | link=https://www.alldaydevops.com/zap-in-ten]]&lt;br /&gt;
&lt;br /&gt;
====Please help us to make ZAP even better for you by answering the [https://docs.google.com/forms/d/e/1FAIpQLSeJDCJg0M_H0sC666yx4PZwfyBTwnh0HwzTUKdYB7zmSBE0Nw/viewform]!====&lt;br /&gt;
&lt;br /&gt;
Interested in a ZAP talk or training event? See the [https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project#tab=Talks talks] tab. Not one near you? Contact a [https://github.com/zaproxy/zaproxy/wiki/ZapEvangelists Zap Evangelist] to arrange one!&lt;br /&gt;
&lt;br /&gt;
For general information about ZAP:&lt;br /&gt;
* [https://twitter.com/zaproxy Twitter] - official ZAP announcements (low volume)&lt;br /&gt;
* [https://zaproxy.blogspot.co.uk/ Blog] - official ZAP blog&lt;br /&gt;
&lt;br /&gt;
For help using ZAP:&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/releases/download/v2.8.0/ZAPGettingStartedGuide-2.8.pdf Getting Started Guide (pdf)] - an introductory guide you can print&lt;br /&gt;
* [https://www.youtube.com/playlist?list=PLEBitBW-Hlsv8cEIUntAO8st2UGhmrjUB Tutorial Videos]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki User Guide] - online version of the User Guide included with ZAP&lt;br /&gt;
* [https://groups.google.com/group/zaproxy-users User Group] - ask questions about using ZAP&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/wiki Add-ons] - help for the optional add-ons you can install&lt;br /&gt;
* [https://stackoverflow.com/questions/tagged/zap StackOverflow] - because some people use this for all everything ;)&lt;br /&gt;
&lt;br /&gt;
To learn more about ZAP development:&lt;br /&gt;
* [https://github.com/zaproxy Source Code] - for all of the ZAP related projects&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/wiki/Introduction Wiki] - lots of detailed info&lt;br /&gt;
* [https://groups.google.com/group/zaproxy-develop Developer Group] - ask questions about the ZAP internals&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap Crowdin (GUI)] - help translate the ZAP GUI&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap-help Crowdin (User Guide)] - help translate the ZAP User Guide&lt;br /&gt;
* [https://www.openhub.net/p/zaproxy OpenHub]	- FOSS analytics&lt;br /&gt;
* [https://www.bountysource.com/teams/zap/issues BountySource] - Vote on ZAP issues (you can also donate money here, but 10% taken out)&lt;br /&gt;
&lt;br /&gt;
===Justification===&lt;br /&gt;
Justification for the statements made in the tagline at the top;)&lt;br /&gt;
&lt;br /&gt;
Popularity:&lt;br /&gt;
* ToolsWatch Annual Best Free/Open Source Security Tool Survey:&lt;br /&gt;
** 2016 [http://www.toolswatch.org/2017/02/2016-top-security-tools-as-voted-by-toolswatch-org-readers/ 2nd]&lt;br /&gt;
** 2015 [http://www.toolswatch.org/2016/02/2015-top-security-tools-as-voted-by-toolswatch-org-readers/ 1st]&lt;br /&gt;
** 2014 [http://www.toolswatch.org/2015/01/2014-top-security-tools-as-voted-by-toolswatch-org-readers/ 2nd]&lt;br /&gt;
** 2013 [http://www.toolswatch.org/2013/12/2013-top-security-tools-as-voted-by-toolswatch-org-readers/ 1st]&lt;br /&gt;
&lt;br /&gt;
Contributors:&lt;br /&gt;
* [https://www.openhub.net/p/zaproxy Code Contributors]&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap ZAP core i18n Contributors]&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap-help ZAP help i18n Contributors]&lt;br /&gt;
&lt;br /&gt;
{{Social Media Links}}&lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;padding-left:25px;width:200px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
[https://github.com/zaproxy/zaproxy/wiki/Downloads Download OWASP ZAP!]&lt;br /&gt;
&lt;br /&gt;
== Donate to ZAP ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div class=&amp;quot;center&amp;quot; style=&amp;quot;width: auto; margin-left: auto; margin-right: auto;&amp;quot;&amp;gt;{{#widget:PayPal Donation&lt;br /&gt;
|target=_blank&lt;br /&gt;
|budget=Zed Attack Proxy }}&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
Please see the [https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project#News News] and [https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project#Talks Talks] tabs&lt;br /&gt;
&lt;br /&gt;
== Change Log ==&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/commits/develop zaproxy]&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/commits/master zap-extensions]&lt;br /&gt;
&lt;br /&gt;
== Code Repo ==&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/ zaproxy]&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/ zap-extensions]&lt;br /&gt;
&lt;br /&gt;
== Email List ==&lt;br /&gt;
&lt;br /&gt;
Questions? Please ask on the [http://groups.google.com/group/zaproxy-users ZAP User Group]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
Project Leader&amp;lt;br /&amp;gt;[https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @]&lt;br /&gt;
&lt;br /&gt;
Co-Project Leaders&amp;lt;br /&amp;gt;[https://www.owasp.org/index.php/User:Ricardo.Pereira Ricardo Pereira] [mailto:ricardo.pereira@owasp.org @]&lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/index.php/User:Rick.mitchell Rick Mitchell] [mailto:rick.mitchell+wiki@owasp.org @]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_Web_Testing_Environment_Project OWASP WTE]&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_OWTF OWASP OWTF]&lt;br /&gt;
&lt;br /&gt;
== Open Hub Stats ==&lt;br /&gt;
&lt;br /&gt;
*https://www.openhub.net/p/zaproxy&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| cellpadding=&amp;quot;2&amp;quot; width=&amp;quot;200&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; | [[File:Mature projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Flagship_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; width=&amp;quot;50%&amp;quot; valign=&amp;quot;center&amp;quot; | [[File:Owasp-builders-small.png|link=]]&lt;br /&gt;
   |&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; width=&amp;quot;50%&amp;quot; valign=&amp;quot;center&amp;quot; | [[File:Owasp-breakers-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [http://www.apache.org/licenses/LICENSE-2.0 Apache 2 License]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_TOOL.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Screenshots =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotAddAlert.png|||400px|ZAP Add Alert Screen Shot]] &lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotHelp.png||400px|left|ZAP Help Screen Shot]]&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotHistoryFilter.png|thumb|400px|left|ZAP History Filter Screen Shot]]&lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotSearchTab.png|thumb|400px|left|ZAP Search Tab Screen Shot]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Talks =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
{{:Projects/OWASP Zed Attack Proxy Project/Pages/Talks | Talks}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
= News =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
{{:Projects/OWASP Zed Attack Proxy Project/Pages/News | News}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
= ZAP Gear =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Yes, you can now buy ZAP related gear!&lt;br /&gt;
&lt;br /&gt;
All of the artwork for ZAP swag is released under the Creative Common License and can be downloaded from the [https://github.com/zaproxy/zap-swag zap-swag] repo.&lt;br /&gt;
&lt;br /&gt;
You can of course use the artwork from this repo with any other online store that you like.&lt;br /&gt;
&lt;br /&gt;
A range of products can be purchased from [http://www.redbubble.com/people/zaproxy Redbubble]&lt;br /&gt;
&lt;br /&gt;
T-shirts can be purchased from [http://www.cafepress.com/zaproxy Cafepress]&lt;br /&gt;
&lt;br /&gt;
[[Image:zap-tshirt-cp.PNG | link=http://www.cafepress.com/zaproxy]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Supporters =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
ZAP is developed by a worldwide [https://github.com/zaproxy/zap-core-help/wiki/HelpCredits team] of volunteers.&lt;br /&gt;
&lt;br /&gt;
But we have also been helped by many organizations, either financially or by encouraging their employees to work on ZAP:&lt;br /&gt;
&lt;br /&gt;
* [http://www.mozilla.org Mozilla]&lt;br /&gt;
* [http://www.linuxfoundation.org/ The Linux Foundation]&lt;br /&gt;
* [https://segment.com/ Segment]&lt;br /&gt;
* [http://www.owasp.org OWASP]&lt;br /&gt;
* [http://www.sage.co.uk Sage]&lt;br /&gt;
* [http://www.google.com Google]&lt;br /&gt;
* [http://www.microsoft.com Microsoft]&lt;br /&gt;
* [http://www.hacktics.com/ Hacktics, Ernst &amp;amp; Young]&lt;br /&gt;
* [http://www.dinosec.com/ DinoSec]&lt;br /&gt;
* [http://www.denimgroup.com Denim Group]&lt;br /&gt;
* [http://www.aspectsecurity.com/ Aspect Security]&lt;br /&gt;
* [http://secureideas.net SecureIdeas]&lt;br /&gt;
* [http://utilisec.com UtiliSec]&lt;br /&gt;
* [http://www.encription.co.uk/ encription]&lt;br /&gt;
* [https://www.accenture.com/us-en/digital-index.aspx Accenture Digital]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Functionality =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
'''Some of ZAP's functionality:'''&lt;br /&gt;
&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsIntercept Man-in-the-middle Proxy]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsSpider Traditional] and AJAX spiders&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsAscan Automated scanner]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsPscan Passive scanner]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsBruteforce Forced browsing]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsFuzz Fuzzer]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpUiDialogsOptionsDynsslcert Dynamic SSL certificates]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/SmartCards Smartcard and Client Digital Certificates support]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpAddonsWebsocketIntroduction Web sockets] support&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpAddonsScriptsScripts Support for a wide range of scripting languages]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki//HelpAddonsPlugnhackPlugnhack Plug-n-Hack support]&lt;br /&gt;
* Authentication and session support&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsApi Powerful REST based API]&lt;br /&gt;
* Automatic updating option&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/wiki Integrated and growing marketplace of add-ons]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
= Features =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
'''Some of ZAP's features:'''&lt;br /&gt;
&lt;br /&gt;
* [http://www.apache.org/licenses/LICENSE-2.0 Open source]&lt;br /&gt;
* Cross platform (it even runs on a [https://github.com/zaproxy/zaproxy/wiki/zappi Raspberry Pi!])&lt;br /&gt;
* Easy to install (using a [https://www.ej-technologies.com/products/install4j/overview.html multi-platform installer builder])&lt;br /&gt;
* Completely free (no paid for 'Pro' version)&lt;br /&gt;
* Ease of use a priority&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpIntro Comprehensive help pages]&lt;br /&gt;
* Fully internationalized&lt;br /&gt;
* Translated into over 20 languages&lt;br /&gt;
* Community based, with involvement actively encouraged&lt;br /&gt;
* Under active development by an international team of volunteers&lt;br /&gt;
&lt;br /&gt;
ZAP is a fork of the well regarded [http://www.parosproxy.org/ Paros Proxy].&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Languages =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''ZAP supports the following languages:'''&lt;br /&gt;
&lt;br /&gt;
* English&lt;br /&gt;
* Arabic&lt;br /&gt;
* Bosnian&lt;br /&gt;
* Brazilian Portuguese&lt;br /&gt;
* Chinese&lt;br /&gt;
* Danish&lt;br /&gt;
* Filipino&lt;br /&gt;
* French&lt;br /&gt;
* German&lt;br /&gt;
* Greek&lt;br /&gt;
* Hungarian&lt;br /&gt;
* Indonesian&lt;br /&gt;
* Italian&lt;br /&gt;
* Japanese&lt;br /&gt;
* Korean&lt;br /&gt;
* Persian&lt;br /&gt;
* Polish&lt;br /&gt;
* Russian&lt;br /&gt;
* Sinhala&lt;br /&gt;
* Spanish&lt;br /&gt;
* Urdu &lt;br /&gt;
&lt;br /&gt;
You can use [http://crowdin.net/project/owasp-zap Crowdin] to help improve these translations or add new ones right now!&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Release 2.6.0==&lt;br /&gt;
ZAP 2.6.0 has been released, this is a bug fix and enhancement release&lt;br /&gt;
&lt;br /&gt;
For more details see https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_6_0&lt;br /&gt;
&lt;br /&gt;
==Release 2.7.0==&lt;br /&gt;
ZAP 2.7.0 has been released (Nov 2017), this is a bug fix and enhancement release&lt;br /&gt;
&lt;br /&gt;
For more details see https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_7_0&lt;br /&gt;
&lt;br /&gt;
It requires Java 8 (minimum) and supports Selenium 3.&lt;br /&gt;
&lt;br /&gt;
==Release 2.8.0==&lt;br /&gt;
ZAP 2.8.0 has been released (June 2019), this is a bug fix and enhancement release&lt;br /&gt;
&lt;br /&gt;
For more details see https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_8_0&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Get Involved =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Involvement in the development of ZAP is actively encouraged!&lt;br /&gt;
&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
&lt;br /&gt;
Some of the ways you can help:&lt;br /&gt;
&lt;br /&gt;
==Feature Requests==&lt;br /&gt;
&lt;br /&gt;
Please raise new feature requests as enhancement requests here: https://github.com/zaproxy/zaproxy/issues&lt;br /&gt;
&lt;br /&gt;
If there are existing requests you are also interested in then please 'star' them - that way we can see which features people are most interested in and can prioritize them accordingly. &lt;br /&gt;
&lt;br /&gt;
==Feedback==&lt;br /&gt;
&lt;br /&gt;
Please use the [http://groups.google.com/group/zaproxy-users zaproxy-users Google Group] for feedback:&lt;br /&gt;
* What do like?&lt;br /&gt;
* What don't you like?&lt;br /&gt;
* What features could be made easier to use?&lt;br /&gt;
* How could the help pages be improved? &lt;br /&gt;
&lt;br /&gt;
==Log issues==&lt;br /&gt;
&lt;br /&gt;
Have you had a problem using ZAP?&lt;br /&gt;
&lt;br /&gt;
If so and its not already been logged then please [https://github.com/zaproxy/zaproxy/issues report it]&lt;br /&gt;
&lt;br /&gt;
==Localization==&lt;br /&gt;
&lt;br /&gt;
Are you fluent in another language? Can you help translate ZAP into that language?&lt;br /&gt;
&lt;br /&gt;
You can use [http://crowdin.net/project/owasp-zap Crowdin] to do that!&lt;br /&gt;
&lt;br /&gt;
==Development==&lt;br /&gt;
&lt;br /&gt;
If you fancy having a go at adding functionality to ZAP then please get in touch via the [http://groups.google.com/group/zaproxy-develop zaproxy-develop Google Group].&lt;br /&gt;
&lt;br /&gt;
Again, you do not have to be a security expert to contribute code - working on ZAP could be great way to learn more about web application security!&lt;br /&gt;
&lt;br /&gt;
If you actively contribute to ZAP then you will be invited to join the project. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project|Zed Attack Proxy Project]]&lt;br /&gt;
[[Category:OWASP_Tool]]&lt;br /&gt;
[[Category:OWASP Release Quality Tool|OWASP Release Quality Tool]]&lt;br /&gt;
[[Category:OWASP_Download]]&lt;br /&gt;
[[Category:Popular]]&lt;br /&gt;
[[Category:SAMM-ST-2]]&lt;br /&gt;
[[Category:Flagship Projects|Zap]]&lt;br /&gt;
[[Category:OWASP Zed Attack Proxy|Zap]]&lt;/div&gt;</summary>
		<author><name>Psiinon</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Zed_Attack_Proxy_Project&amp;diff=256188</id>
		<title>OWASP Zed Attack Proxy Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Zed_Attack_Proxy_Project&amp;diff=256188"/>
				<updated>2019-11-26T17:53:09Z</updated>
		
		<summary type="html">&lt;p&gt;Psiinon: added nl&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Main = &lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:90px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File: flagship_big.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
{{ReviewProject|projectname=zaproxy|language=en}}&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
The OWASP Zed Attack Proxy (ZAP) is one of the world’s most popular free security tools and is actively maintained by hundreds of international volunteers[[#Justification|*]]. It can help you automatically find security vulnerabilities in your web applications while you are developing and testing your applications. Its also a great tool for experienced pentesters to use for manual security testing.&lt;br /&gt;
&lt;br /&gt;
[[Image:ZAP-Download.png | link=https://github.com/zaproxy/zaproxy/wiki/Downloads]]&lt;br /&gt;
&lt;br /&gt;
====ZAP in Ten - Video series====&lt;br /&gt;
An ongoing series of up to 10 minute videos about ZAP, starting with the basics. &lt;br /&gt;
&lt;br /&gt;
The first episode and the full series are available via:&lt;br /&gt;
&lt;br /&gt;
[[Image:01-ZAP-in-Ten-small.png | link=http://play.sonatype.com/watch/RyTy22GZV6UccW41UCghC8?]]&lt;br /&gt;
&lt;br /&gt;
[[Image:02-ZAP-in-Ten-small.png | link=https://www.alldaydevops.com/zap-in-ten]]&lt;br /&gt;
&lt;br /&gt;
====Please help us to make ZAP even better for you by answering the [https://docs.google.com/forms/d/1-k-vcj_sSxlil6XLxCFade-m-IQVeE2h9gduA-2ZPPA/viewform ZAP User Questionnaire]!====&lt;br /&gt;
&lt;br /&gt;
Interested in a ZAP talk or training event? See the [https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project#tab=Talks talks] tab. Not one near you? Contact a [https://github.com/zaproxy/zaproxy/wiki/ZapEvangelists Zap Evangelist] to arrange one!&lt;br /&gt;
&lt;br /&gt;
For general information about ZAP:&lt;br /&gt;
* [https://twitter.com/zaproxy Twitter] - official ZAP announcements (low volume)&lt;br /&gt;
* [https://zaproxy.blogspot.co.uk/ Blog] - official ZAP blog&lt;br /&gt;
&lt;br /&gt;
For help using ZAP:&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/releases/download/v2.8.0/ZAPGettingStartedGuide-2.8.pdf Getting Started Guide (pdf)] - an introductory guide you can print&lt;br /&gt;
* [https://www.youtube.com/playlist?list=PLEBitBW-Hlsv8cEIUntAO8st2UGhmrjUB Tutorial Videos]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki User Guide] - online version of the User Guide included with ZAP&lt;br /&gt;
* [https://groups.google.com/group/zaproxy-users User Group] - ask questions about using ZAP&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/wiki Add-ons] - help for the optional add-ons you can install&lt;br /&gt;
* [https://stackoverflow.com/questions/tagged/zap StackOverflow] - because some people use this for all everything ;)&lt;br /&gt;
&lt;br /&gt;
To learn more about ZAP development:&lt;br /&gt;
* [https://github.com/zaproxy Source Code] - for all of the ZAP related projects&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/wiki/Introduction Wiki] - lots of detailed info&lt;br /&gt;
* [https://groups.google.com/group/zaproxy-develop Developer Group] - ask questions about the ZAP internals&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap Crowdin (GUI)] - help translate the ZAP GUI&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap-help Crowdin (User Guide)] - help translate the ZAP User Guide&lt;br /&gt;
* [https://www.openhub.net/p/zaproxy OpenHub]	- FOSS analytics&lt;br /&gt;
* [https://www.bountysource.com/teams/zap/issues BountySource] - Vote on ZAP issues (you can also donate money here, but 10% taken out)&lt;br /&gt;
&lt;br /&gt;
===Justification===&lt;br /&gt;
Justification for the statements made in the tagline at the top;)&lt;br /&gt;
&lt;br /&gt;
Popularity:&lt;br /&gt;
* ToolsWatch Annual Best Free/Open Source Security Tool Survey:&lt;br /&gt;
** 2016 [http://www.toolswatch.org/2017/02/2016-top-security-tools-as-voted-by-toolswatch-org-readers/ 2nd]&lt;br /&gt;
** 2015 [http://www.toolswatch.org/2016/02/2015-top-security-tools-as-voted-by-toolswatch-org-readers/ 1st]&lt;br /&gt;
** 2014 [http://www.toolswatch.org/2015/01/2014-top-security-tools-as-voted-by-toolswatch-org-readers/ 2nd]&lt;br /&gt;
** 2013 [http://www.toolswatch.org/2013/12/2013-top-security-tools-as-voted-by-toolswatch-org-readers/ 1st]&lt;br /&gt;
&lt;br /&gt;
Contributors:&lt;br /&gt;
* [https://www.openhub.net/p/zaproxy Code Contributors]&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap ZAP core i18n Contributors]&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap-help ZAP help i18n Contributors]&lt;br /&gt;
&lt;br /&gt;
{{Social Media Links}}&lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;padding-left:25px;width:200px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
[https://github.com/zaproxy/zaproxy/wiki/Downloads Download OWASP ZAP!]&lt;br /&gt;
&lt;br /&gt;
== Donate to ZAP ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div class=&amp;quot;center&amp;quot; style=&amp;quot;width: auto; margin-left: auto; margin-right: auto;&amp;quot;&amp;gt;{{#widget:PayPal Donation&lt;br /&gt;
|target=_blank&lt;br /&gt;
|budget=Zed Attack Proxy }}&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
Please see the [https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project#News News] and [https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project#Talks Talks] tabs&lt;br /&gt;
&lt;br /&gt;
== Change Log ==&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/commits/develop zaproxy]&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/commits/master zap-extensions]&lt;br /&gt;
&lt;br /&gt;
== Code Repo ==&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/ zaproxy]&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/ zap-extensions]&lt;br /&gt;
&lt;br /&gt;
== Email List ==&lt;br /&gt;
&lt;br /&gt;
Questions? Please ask on the [http://groups.google.com/group/zaproxy-users ZAP User Group]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
Project Leader&amp;lt;br /&amp;gt;[https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @]&lt;br /&gt;
&lt;br /&gt;
Co-Project Leaders&amp;lt;br /&amp;gt;[https://www.owasp.org/index.php/User:Ricardo.Pereira Ricardo Pereira] [mailto:ricardo.pereira@owasp.org @]&lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/index.php/User:Rick.mitchell Rick Mitchell] [mailto:rick.mitchell+wiki@owasp.org @]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_Web_Testing_Environment_Project OWASP WTE]&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_OWTF OWASP OWTF]&lt;br /&gt;
&lt;br /&gt;
== Open Hub Stats ==&lt;br /&gt;
&lt;br /&gt;
*https://www.openhub.net/p/zaproxy&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| cellpadding=&amp;quot;2&amp;quot; width=&amp;quot;200&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; | [[File:Mature projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Flagship_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; width=&amp;quot;50%&amp;quot; valign=&amp;quot;center&amp;quot; | [[File:Owasp-builders-small.png|link=]]&lt;br /&gt;
   |&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; width=&amp;quot;50%&amp;quot; valign=&amp;quot;center&amp;quot; | [[File:Owasp-breakers-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [http://www.apache.org/licenses/LICENSE-2.0 Apache 2 License]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_TOOL.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Screenshots =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotAddAlert.png|||400px|ZAP Add Alert Screen Shot]] &lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotHelp.png||400px|left|ZAP Help Screen Shot]]&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotHistoryFilter.png|thumb|400px|left|ZAP History Filter Screen Shot]]&lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotSearchTab.png|thumb|400px|left|ZAP Search Tab Screen Shot]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Talks =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
{{:Projects/OWASP Zed Attack Proxy Project/Pages/Talks | Talks}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
= News =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
{{:Projects/OWASP Zed Attack Proxy Project/Pages/News | News}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
= ZAP Gear =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Yes, you can now buy ZAP related gear!&lt;br /&gt;
&lt;br /&gt;
All of the artwork for ZAP swag is released under the Creative Common License and can be downloaded from the [https://github.com/zaproxy/zap-swag zap-swag] repo.&lt;br /&gt;
&lt;br /&gt;
You can of course use the artwork from this repo with any other online store that you like.&lt;br /&gt;
&lt;br /&gt;
A range of products can be purchased from [http://www.redbubble.com/people/zaproxy Redbubble]&lt;br /&gt;
&lt;br /&gt;
T-shirts can be purchased from [http://www.cafepress.com/zaproxy Cafepress]&lt;br /&gt;
&lt;br /&gt;
[[Image:zap-tshirt-cp.PNG | link=http://www.cafepress.com/zaproxy]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Supporters =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
ZAP is developed by a worldwide [https://github.com/zaproxy/zap-core-help/wiki/HelpCredits team] of volunteers.&lt;br /&gt;
&lt;br /&gt;
But we have also been helped by many organizations, either financially or by encouraging their employees to work on ZAP:&lt;br /&gt;
&lt;br /&gt;
* [http://www.mozilla.org Mozilla]&lt;br /&gt;
* [http://www.linuxfoundation.org/ The Linux Foundation]&lt;br /&gt;
* [https://segment.com/ Segment]&lt;br /&gt;
* [http://www.owasp.org OWASP]&lt;br /&gt;
* [http://www.sage.co.uk Sage]&lt;br /&gt;
* [http://www.google.com Google]&lt;br /&gt;
* [http://www.microsoft.com Microsoft]&lt;br /&gt;
* [http://www.hacktics.com/ Hacktics, Ernst &amp;amp; Young]&lt;br /&gt;
* [http://www.dinosec.com/ DinoSec]&lt;br /&gt;
* [http://www.denimgroup.com Denim Group]&lt;br /&gt;
* [http://www.aspectsecurity.com/ Aspect Security]&lt;br /&gt;
* [http://secureideas.net SecureIdeas]&lt;br /&gt;
* [http://utilisec.com UtiliSec]&lt;br /&gt;
* [http://www.encription.co.uk/ encription]&lt;br /&gt;
* [https://www.accenture.com/us-en/digital-index.aspx Accenture Digital]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Functionality =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
'''Some of ZAP's functionality:'''&lt;br /&gt;
&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsIntercept Man-in-the-middle Proxy]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsSpider Traditional] and AJAX spiders&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsAscan Automated scanner]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsPscan Passive scanner]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsBruteforce Forced browsing]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsFuzz Fuzzer]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpUiDialogsOptionsDynsslcert Dynamic SSL certificates]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/SmartCards Smartcard and Client Digital Certificates support]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpAddonsWebsocketIntroduction Web sockets] support&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpAddonsScriptsScripts Support for a wide range of scripting languages]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki//HelpAddonsPlugnhackPlugnhack Plug-n-Hack support]&lt;br /&gt;
* Authentication and session support&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsApi Powerful REST based API]&lt;br /&gt;
* Automatic updating option&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/wiki Integrated and growing marketplace of add-ons]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
= Features =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
'''Some of ZAP's features:'''&lt;br /&gt;
&lt;br /&gt;
* [http://www.apache.org/licenses/LICENSE-2.0 Open source]&lt;br /&gt;
* Cross platform (it even runs on a [https://github.com/zaproxy/zaproxy/wiki/zappi Raspberry Pi!])&lt;br /&gt;
* Easy to install (using a [https://www.ej-technologies.com/products/install4j/overview.html multi-platform installer builder])&lt;br /&gt;
* Completely free (no paid for 'Pro' version)&lt;br /&gt;
* Ease of use a priority&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpIntro Comprehensive help pages]&lt;br /&gt;
* Fully internationalized&lt;br /&gt;
* Translated into over 20 languages&lt;br /&gt;
* Community based, with involvement actively encouraged&lt;br /&gt;
* Under active development by an international team of volunteers&lt;br /&gt;
&lt;br /&gt;
ZAP is a fork of the well regarded [http://www.parosproxy.org/ Paros Proxy].&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Languages =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''ZAP supports the following languages:'''&lt;br /&gt;
&lt;br /&gt;
* English&lt;br /&gt;
* Arabic&lt;br /&gt;
* Bosnian&lt;br /&gt;
* Brazilian Portuguese&lt;br /&gt;
* Chinese&lt;br /&gt;
* Danish&lt;br /&gt;
* Filipino&lt;br /&gt;
* French&lt;br /&gt;
* German&lt;br /&gt;
* Greek&lt;br /&gt;
* Hungarian&lt;br /&gt;
* Indonesian&lt;br /&gt;
* Italian&lt;br /&gt;
* Japanese&lt;br /&gt;
* Korean&lt;br /&gt;
* Persian&lt;br /&gt;
* Polish&lt;br /&gt;
* Russian&lt;br /&gt;
* Sinhala&lt;br /&gt;
* Spanish&lt;br /&gt;
* Urdu &lt;br /&gt;
&lt;br /&gt;
You can use [http://crowdin.net/project/owasp-zap Crowdin] to help improve these translations or add new ones right now!&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Release 2.6.0==&lt;br /&gt;
ZAP 2.6.0 has been released, this is a bug fix and enhancement release&lt;br /&gt;
&lt;br /&gt;
For more details see https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_6_0&lt;br /&gt;
&lt;br /&gt;
==Release 2.7.0==&lt;br /&gt;
ZAP 2.7.0 has been released (Nov 2017), this is a bug fix and enhancement release&lt;br /&gt;
&lt;br /&gt;
For more details see https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_7_0&lt;br /&gt;
&lt;br /&gt;
It requires Java 8 (minimum) and supports Selenium 3.&lt;br /&gt;
&lt;br /&gt;
==Release 2.8.0==&lt;br /&gt;
ZAP 2.8.0 has been released (June 2019), this is a bug fix and enhancement release&lt;br /&gt;
&lt;br /&gt;
For more details see https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_8_0&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Get Involved =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Involvement in the development of ZAP is actively encouraged!&lt;br /&gt;
&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
&lt;br /&gt;
Some of the ways you can help:&lt;br /&gt;
&lt;br /&gt;
==Feature Requests==&lt;br /&gt;
&lt;br /&gt;
Please raise new feature requests as enhancement requests here: https://github.com/zaproxy/zaproxy/issues&lt;br /&gt;
&lt;br /&gt;
If there are existing requests you are also interested in then please 'star' them - that way we can see which features people are most interested in and can prioritize them accordingly. &lt;br /&gt;
&lt;br /&gt;
==Feedback==&lt;br /&gt;
&lt;br /&gt;
Please use the [http://groups.google.com/group/zaproxy-users zaproxy-users Google Group] for feedback:&lt;br /&gt;
* What do like?&lt;br /&gt;
* What don't you like?&lt;br /&gt;
* What features could be made easier to use?&lt;br /&gt;
* How could the help pages be improved? &lt;br /&gt;
&lt;br /&gt;
==Log issues==&lt;br /&gt;
&lt;br /&gt;
Have you had a problem using ZAP?&lt;br /&gt;
&lt;br /&gt;
If so and its not already been logged then please [https://github.com/zaproxy/zaproxy/issues report it]&lt;br /&gt;
&lt;br /&gt;
==Localization==&lt;br /&gt;
&lt;br /&gt;
Are you fluent in another language? Can you help translate ZAP into that language?&lt;br /&gt;
&lt;br /&gt;
You can use [http://crowdin.net/project/owasp-zap Crowdin] to do that!&lt;br /&gt;
&lt;br /&gt;
==Development==&lt;br /&gt;
&lt;br /&gt;
If you fancy having a go at adding functionality to ZAP then please get in touch via the [http://groups.google.com/group/zaproxy-develop zaproxy-develop Google Group].&lt;br /&gt;
&lt;br /&gt;
Again, you do not have to be a security expert to contribute code - working on ZAP could be great way to learn more about web application security!&lt;br /&gt;
&lt;br /&gt;
If you actively contribute to ZAP then you will be invited to join the project. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project|Zed Attack Proxy Project]]&lt;br /&gt;
[[Category:OWASP_Tool]]&lt;br /&gt;
[[Category:OWASP Release Quality Tool|OWASP Release Quality Tool]]&lt;br /&gt;
[[Category:OWASP_Download]]&lt;br /&gt;
[[Category:Popular]]&lt;br /&gt;
[[Category:SAMM-ST-2]]&lt;br /&gt;
[[Category:Flagship Projects|Zap]]&lt;br /&gt;
[[Category:OWASP Zed Attack Proxy|Zap]]&lt;/div&gt;</summary>
		<author><name>Psiinon</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Zed_Attack_Proxy_Project&amp;diff=256187</id>
		<title>OWASP Zed Attack Proxy Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Zed_Attack_Proxy_Project&amp;diff=256187"/>
				<updated>2019-11-26T17:43:25Z</updated>
		
		<summary type="html">&lt;p&gt;Psiinon: Added ZAP in Ten links&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Main = &lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:90px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File: flagship_big.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
{{ReviewProject|projectname=zaproxy|language=en}}&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
The OWASP Zed Attack Proxy (ZAP) is one of the world’s most popular free security tools and is actively maintained by hundreds of international volunteers[[#Justification|*]]. It can help you automatically find security vulnerabilities in your web applications while you are developing and testing your applications. Its also a great tool for experienced pentesters to use for manual security testing.&lt;br /&gt;
&lt;br /&gt;
[[Image:ZAP-Download.png | link=https://github.com/zaproxy/zaproxy/wiki/Downloads]]&lt;br /&gt;
&lt;br /&gt;
====ZAP in Ten - Video series====&lt;br /&gt;
An ongoing series of up to 10 minute videos about ZAP, starting with the basics. &lt;br /&gt;
&lt;br /&gt;
The first episode and the full series are available via:&lt;br /&gt;
&lt;br /&gt;
[[Image:01-ZAP-in-Ten-small.png | link=http://play.sonatype.com/watch/RyTy22GZV6UccW41UCghC8?]]&lt;br /&gt;
[[Image:02-ZAP-in-Ten-small.png | link=https://www.alldaydevops.com/zap-in-ten]]&lt;br /&gt;
&lt;br /&gt;
====Please help us to make ZAP even better for you by answering the [https://docs.google.com/forms/d/1-k-vcj_sSxlil6XLxCFade-m-IQVeE2h9gduA-2ZPPA/viewform ZAP User Questionnaire]!====&lt;br /&gt;
&lt;br /&gt;
Interested in a ZAP talk or training event? See the [https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project#tab=Talks talks] tab. Not one near you? Contact a [https://github.com/zaproxy/zaproxy/wiki/ZapEvangelists Zap Evangelist] to arrange one!&lt;br /&gt;
&lt;br /&gt;
For general information about ZAP:&lt;br /&gt;
* [https://twitter.com/zaproxy Twitter] - official ZAP announcements (low volume)&lt;br /&gt;
* [https://zaproxy.blogspot.co.uk/ Blog] - official ZAP blog&lt;br /&gt;
&lt;br /&gt;
For help using ZAP:&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/releases/download/v2.8.0/ZAPGettingStartedGuide-2.8.pdf Getting Started Guide (pdf)] - an introductory guide you can print&lt;br /&gt;
* [https://www.youtube.com/playlist?list=PLEBitBW-Hlsv8cEIUntAO8st2UGhmrjUB Tutorial Videos]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki User Guide] - online version of the User Guide included with ZAP&lt;br /&gt;
* [https://groups.google.com/group/zaproxy-users User Group] - ask questions about using ZAP&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/wiki Add-ons] - help for the optional add-ons you can install&lt;br /&gt;
* [https://stackoverflow.com/questions/tagged/zap StackOverflow] - because some people use this for all everything ;)&lt;br /&gt;
&lt;br /&gt;
To learn more about ZAP development:&lt;br /&gt;
* [https://github.com/zaproxy Source Code] - for all of the ZAP related projects&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/wiki/Introduction Wiki] - lots of detailed info&lt;br /&gt;
* [https://groups.google.com/group/zaproxy-develop Developer Group] - ask questions about the ZAP internals&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap Crowdin (GUI)] - help translate the ZAP GUI&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap-help Crowdin (User Guide)] - help translate the ZAP User Guide&lt;br /&gt;
* [https://www.openhub.net/p/zaproxy OpenHub]	- FOSS analytics&lt;br /&gt;
* [https://www.bountysource.com/teams/zap/issues BountySource] - Vote on ZAP issues (you can also donate money here, but 10% taken out)&lt;br /&gt;
&lt;br /&gt;
===Justification===&lt;br /&gt;
Justification for the statements made in the tagline at the top;)&lt;br /&gt;
&lt;br /&gt;
Popularity:&lt;br /&gt;
* ToolsWatch Annual Best Free/Open Source Security Tool Survey:&lt;br /&gt;
** 2016 [http://www.toolswatch.org/2017/02/2016-top-security-tools-as-voted-by-toolswatch-org-readers/ 2nd]&lt;br /&gt;
** 2015 [http://www.toolswatch.org/2016/02/2015-top-security-tools-as-voted-by-toolswatch-org-readers/ 1st]&lt;br /&gt;
** 2014 [http://www.toolswatch.org/2015/01/2014-top-security-tools-as-voted-by-toolswatch-org-readers/ 2nd]&lt;br /&gt;
** 2013 [http://www.toolswatch.org/2013/12/2013-top-security-tools-as-voted-by-toolswatch-org-readers/ 1st]&lt;br /&gt;
&lt;br /&gt;
Contributors:&lt;br /&gt;
* [https://www.openhub.net/p/zaproxy Code Contributors]&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap ZAP core i18n Contributors]&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap-help ZAP help i18n Contributors]&lt;br /&gt;
&lt;br /&gt;
{{Social Media Links}}&lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;padding-left:25px;width:200px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
[https://github.com/zaproxy/zaproxy/wiki/Downloads Download OWASP ZAP!]&lt;br /&gt;
&lt;br /&gt;
== Donate to ZAP ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div class=&amp;quot;center&amp;quot; style=&amp;quot;width: auto; margin-left: auto; margin-right: auto;&amp;quot;&amp;gt;{{#widget:PayPal Donation&lt;br /&gt;
|target=_blank&lt;br /&gt;
|budget=Zed Attack Proxy }}&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
Please see the [https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project#News News] and [https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project#Talks Talks] tabs&lt;br /&gt;
&lt;br /&gt;
== Change Log ==&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/commits/develop zaproxy]&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/commits/master zap-extensions]&lt;br /&gt;
&lt;br /&gt;
== Code Repo ==&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/ zaproxy]&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/ zap-extensions]&lt;br /&gt;
&lt;br /&gt;
== Email List ==&lt;br /&gt;
&lt;br /&gt;
Questions? Please ask on the [http://groups.google.com/group/zaproxy-users ZAP User Group]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
Project Leader&amp;lt;br /&amp;gt;[https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @]&lt;br /&gt;
&lt;br /&gt;
Co-Project Leaders&amp;lt;br /&amp;gt;[https://www.owasp.org/index.php/User:Ricardo.Pereira Ricardo Pereira] [mailto:ricardo.pereira@owasp.org @]&lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/index.php/User:Rick.mitchell Rick Mitchell] [mailto:rick.mitchell+wiki@owasp.org @]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_Web_Testing_Environment_Project OWASP WTE]&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_OWTF OWASP OWTF]&lt;br /&gt;
&lt;br /&gt;
== Open Hub Stats ==&lt;br /&gt;
&lt;br /&gt;
*https://www.openhub.net/p/zaproxy&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| cellpadding=&amp;quot;2&amp;quot; width=&amp;quot;200&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; | [[File:Mature projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Flagship_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; width=&amp;quot;50%&amp;quot; valign=&amp;quot;center&amp;quot; | [[File:Owasp-builders-small.png|link=]]&lt;br /&gt;
   |&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; width=&amp;quot;50%&amp;quot; valign=&amp;quot;center&amp;quot; | [[File:Owasp-breakers-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [http://www.apache.org/licenses/LICENSE-2.0 Apache 2 License]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_TOOL.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Screenshots =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotAddAlert.png|||400px|ZAP Add Alert Screen Shot]] &lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotHelp.png||400px|left|ZAP Help Screen Shot]]&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotHistoryFilter.png|thumb|400px|left|ZAP History Filter Screen Shot]]&lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotSearchTab.png|thumb|400px|left|ZAP Search Tab Screen Shot]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Talks =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
{{:Projects/OWASP Zed Attack Proxy Project/Pages/Talks | Talks}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
= News =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
{{:Projects/OWASP Zed Attack Proxy Project/Pages/News | News}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
= ZAP Gear =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Yes, you can now buy ZAP related gear!&lt;br /&gt;
&lt;br /&gt;
All of the artwork for ZAP swag is released under the Creative Common License and can be downloaded from the [https://github.com/zaproxy/zap-swag zap-swag] repo.&lt;br /&gt;
&lt;br /&gt;
You can of course use the artwork from this repo with any other online store that you like.&lt;br /&gt;
&lt;br /&gt;
A range of products can be purchased from [http://www.redbubble.com/people/zaproxy Redbubble]&lt;br /&gt;
&lt;br /&gt;
T-shirts can be purchased from [http://www.cafepress.com/zaproxy Cafepress]&lt;br /&gt;
&lt;br /&gt;
[[Image:zap-tshirt-cp.PNG | link=http://www.cafepress.com/zaproxy]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Supporters =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
ZAP is developed by a worldwide [https://github.com/zaproxy/zap-core-help/wiki/HelpCredits team] of volunteers.&lt;br /&gt;
&lt;br /&gt;
But we have also been helped by many organizations, either financially or by encouraging their employees to work on ZAP:&lt;br /&gt;
&lt;br /&gt;
* [http://www.mozilla.org Mozilla]&lt;br /&gt;
* [http://www.linuxfoundation.org/ The Linux Foundation]&lt;br /&gt;
* [https://segment.com/ Segment]&lt;br /&gt;
* [http://www.owasp.org OWASP]&lt;br /&gt;
* [http://www.sage.co.uk Sage]&lt;br /&gt;
* [http://www.google.com Google]&lt;br /&gt;
* [http://www.microsoft.com Microsoft]&lt;br /&gt;
* [http://www.hacktics.com/ Hacktics, Ernst &amp;amp; Young]&lt;br /&gt;
* [http://www.dinosec.com/ DinoSec]&lt;br /&gt;
* [http://www.denimgroup.com Denim Group]&lt;br /&gt;
* [http://www.aspectsecurity.com/ Aspect Security]&lt;br /&gt;
* [http://secureideas.net SecureIdeas]&lt;br /&gt;
* [http://utilisec.com UtiliSec]&lt;br /&gt;
* [http://www.encription.co.uk/ encription]&lt;br /&gt;
* [https://www.accenture.com/us-en/digital-index.aspx Accenture Digital]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Functionality =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
'''Some of ZAP's functionality:'''&lt;br /&gt;
&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsIntercept Man-in-the-middle Proxy]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsSpider Traditional] and AJAX spiders&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsAscan Automated scanner]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsPscan Passive scanner]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsBruteforce Forced browsing]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsFuzz Fuzzer]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpUiDialogsOptionsDynsslcert Dynamic SSL certificates]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/SmartCards Smartcard and Client Digital Certificates support]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpAddonsWebsocketIntroduction Web sockets] support&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpAddonsScriptsScripts Support for a wide range of scripting languages]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki//HelpAddonsPlugnhackPlugnhack Plug-n-Hack support]&lt;br /&gt;
* Authentication and session support&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsApi Powerful REST based API]&lt;br /&gt;
* Automatic updating option&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/wiki Integrated and growing marketplace of add-ons]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
= Features =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
'''Some of ZAP's features:'''&lt;br /&gt;
&lt;br /&gt;
* [http://www.apache.org/licenses/LICENSE-2.0 Open source]&lt;br /&gt;
* Cross platform (it even runs on a [https://github.com/zaproxy/zaproxy/wiki/zappi Raspberry Pi!])&lt;br /&gt;
* Easy to install (using a [https://www.ej-technologies.com/products/install4j/overview.html multi-platform installer builder])&lt;br /&gt;
* Completely free (no paid for 'Pro' version)&lt;br /&gt;
* Ease of use a priority&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpIntro Comprehensive help pages]&lt;br /&gt;
* Fully internationalized&lt;br /&gt;
* Translated into over 20 languages&lt;br /&gt;
* Community based, with involvement actively encouraged&lt;br /&gt;
* Under active development by an international team of volunteers&lt;br /&gt;
&lt;br /&gt;
ZAP is a fork of the well regarded [http://www.parosproxy.org/ Paros Proxy].&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Languages =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''ZAP supports the following languages:'''&lt;br /&gt;
&lt;br /&gt;
* English&lt;br /&gt;
* Arabic&lt;br /&gt;
* Bosnian&lt;br /&gt;
* Brazilian Portuguese&lt;br /&gt;
* Chinese&lt;br /&gt;
* Danish&lt;br /&gt;
* Filipino&lt;br /&gt;
* French&lt;br /&gt;
* German&lt;br /&gt;
* Greek&lt;br /&gt;
* Hungarian&lt;br /&gt;
* Indonesian&lt;br /&gt;
* Italian&lt;br /&gt;
* Japanese&lt;br /&gt;
* Korean&lt;br /&gt;
* Persian&lt;br /&gt;
* Polish&lt;br /&gt;
* Russian&lt;br /&gt;
* Sinhala&lt;br /&gt;
* Spanish&lt;br /&gt;
* Urdu &lt;br /&gt;
&lt;br /&gt;
You can use [http://crowdin.net/project/owasp-zap Crowdin] to help improve these translations or add new ones right now!&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Release 2.6.0==&lt;br /&gt;
ZAP 2.6.0 has been released, this is a bug fix and enhancement release&lt;br /&gt;
&lt;br /&gt;
For more details see https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_6_0&lt;br /&gt;
&lt;br /&gt;
==Release 2.7.0==&lt;br /&gt;
ZAP 2.7.0 has been released (Nov 2017), this is a bug fix and enhancement release&lt;br /&gt;
&lt;br /&gt;
For more details see https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_7_0&lt;br /&gt;
&lt;br /&gt;
It requires Java 8 (minimum) and supports Selenium 3.&lt;br /&gt;
&lt;br /&gt;
==Release 2.8.0==&lt;br /&gt;
ZAP 2.8.0 has been released (June 2019), this is a bug fix and enhancement release&lt;br /&gt;
&lt;br /&gt;
For more details see https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_8_0&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Get Involved =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Involvement in the development of ZAP is actively encouraged!&lt;br /&gt;
&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
&lt;br /&gt;
Some of the ways you can help:&lt;br /&gt;
&lt;br /&gt;
==Feature Requests==&lt;br /&gt;
&lt;br /&gt;
Please raise new feature requests as enhancement requests here: https://github.com/zaproxy/zaproxy/issues&lt;br /&gt;
&lt;br /&gt;
If there are existing requests you are also interested in then please 'star' them - that way we can see which features people are most interested in and can prioritize them accordingly. &lt;br /&gt;
&lt;br /&gt;
==Feedback==&lt;br /&gt;
&lt;br /&gt;
Please use the [http://groups.google.com/group/zaproxy-users zaproxy-users Google Group] for feedback:&lt;br /&gt;
* What do like?&lt;br /&gt;
* What don't you like?&lt;br /&gt;
* What features could be made easier to use?&lt;br /&gt;
* How could the help pages be improved? &lt;br /&gt;
&lt;br /&gt;
==Log issues==&lt;br /&gt;
&lt;br /&gt;
Have you had a problem using ZAP?&lt;br /&gt;
&lt;br /&gt;
If so and its not already been logged then please [https://github.com/zaproxy/zaproxy/issues report it]&lt;br /&gt;
&lt;br /&gt;
==Localization==&lt;br /&gt;
&lt;br /&gt;
Are you fluent in another language? Can you help translate ZAP into that language?&lt;br /&gt;
&lt;br /&gt;
You can use [http://crowdin.net/project/owasp-zap Crowdin] to do that!&lt;br /&gt;
&lt;br /&gt;
==Development==&lt;br /&gt;
&lt;br /&gt;
If you fancy having a go at adding functionality to ZAP then please get in touch via the [http://groups.google.com/group/zaproxy-develop zaproxy-develop Google Group].&lt;br /&gt;
&lt;br /&gt;
Again, you do not have to be a security expert to contribute code - working on ZAP could be great way to learn more about web application security!&lt;br /&gt;
&lt;br /&gt;
If you actively contribute to ZAP then you will be invited to join the project. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project|Zed Attack Proxy Project]]&lt;br /&gt;
[[Category:OWASP_Tool]]&lt;br /&gt;
[[Category:OWASP Release Quality Tool|OWASP Release Quality Tool]]&lt;br /&gt;
[[Category:OWASP_Download]]&lt;br /&gt;
[[Category:Popular]]&lt;br /&gt;
[[Category:SAMM-ST-2]]&lt;br /&gt;
[[Category:Flagship Projects|Zap]]&lt;br /&gt;
[[Category:OWASP Zed Attack Proxy|Zap]]&lt;/div&gt;</summary>
		<author><name>Psiinon</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:02-ZAP-in-Ten-small.png&amp;diff=256185</id>
		<title>File:02-ZAP-in-Ten-small.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:02-ZAP-in-Ten-small.png&amp;diff=256185"/>
				<updated>2019-11-26T16:13:17Z</updated>
		
		<summary type="html">&lt;p&gt;Psiinon: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Psiinon</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:01-ZAP-in-Ten-small.png&amp;diff=256184</id>
		<title>File:01-ZAP-in-Ten-small.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:01-ZAP-in-Ten-small.png&amp;diff=256184"/>
				<updated>2019-11-26T16:11:43Z</updated>
		
		<summary type="html">&lt;p&gt;Psiinon: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Psiinon</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Projects/OWASP_Zed_Attack_Proxy_Project/Pages/News&amp;diff=252324</id>
		<title>Projects/OWASP Zed Attack Proxy Project/Pages/News</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Projects/OWASP_Zed_Attack_Proxy_Project/Pages/News&amp;diff=252324"/>
				<updated>2019-06-10T11:02:48Z</updated>
		
		<summary type="html">&lt;p&gt;Psiinon: Added 2.8.0 release date&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Latest News:'''&lt;br /&gt;
&lt;br /&gt;
* 2019/06/07 Version [https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_8_0 2.8.0] released&lt;br /&gt;
* 2018/07/26 The [https://github.com/zaproxy/zap-hud ZAP Heads Up Display (HUD)] revealed at Bay Area OWASP meetup&lt;br /&gt;
* 2017/11/28 Version [https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_7_0 2.7.0] released&lt;br /&gt;
* 2017/03/29 Version [https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_6_0 2.6.0] released&lt;br /&gt;
* 2017/02/11 ZAP came second in the [http://www.toolswatch.org/2017/02/2016-top-security-tools-as-voted-by-toolswatch-org-readers/ Top Security Tools of 2016 as voted by ToolsWatch.org readers]&lt;br /&gt;
* 2016/06/03 Version [https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_5_0 2.5.0] released&lt;br /&gt;
* 2016/05/26 ZAP [https://bugcrowd.com/owaspzap bug bounty program] launched&lt;br /&gt;
* 2016/02/23 ZAP declared the [http://www.toolswatch.org/2016/02/2015-top-security-tools-as-voted-by-toolswatch-org-readers/ Top Security Tool of 2015 as voted by ToolsWatch.org readers]&lt;br /&gt;
* 2016/02/19 ZAP [http://zaproxy.blogspot.com/2016/02/zap-newsletter-2016-february.html February newsletter] published&lt;br /&gt;
* 2016/01/04 ZAP [http://zaproxy.blogspot.com/2016/01/zap-newsletter-2016-january.html January newsletter] published&lt;br /&gt;
* 2015/12/15 ZAP [http://zaproxy.blogspot.co.uk/2015/12/zap-newsletter-2015-december.html December newsletter] published&lt;br /&gt;
* 2015/12/04 Version [https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_4_3 2.4.3] released&lt;br /&gt;
* 2015/11/02 ZAP [http://zaproxy.blogspot.co.uk/2015/11/zap-newsletter-2015-november.html November newsletter] published&lt;br /&gt;
* 2015/09/07 Version [https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_4_2 2.4.2] released&lt;br /&gt;
* 2015/07/31 ZAP [https://www.owasp.org/index.php/2015-08-ZAP-ScriptingCompetition Scripting Competition] launched&lt;br /&gt;
* 2015/07/30 Version [https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_4_1 2.4.1] released&lt;br /&gt;
* 2015/05/05 ZAP featured in the [http://assets.thoughtworks.com/assets/technology-radar-may-2015-en.pdf ThoughtWorks Technology Radar]&lt;br /&gt;
* 2015/04/14 Version [http://owasp.blogspot.co.uk/2015/04/owasp-zap-240.html 2.4.0] released&lt;br /&gt;
* 2015/01/14 ZAP came second in the [http://www.toolswatch.org/2015/01/2014-top-security-tools-as-voted-by-toolswatch-org-readers/ Top Security Tools of 2014 as voted by ToolsWatch.org readers]&lt;br /&gt;
* 2015/01/02 ZAP [https://github.com/zaproxy/community-scripts Community Scripts] repo launched&lt;br /&gt;
* 2014/05/21 Version [https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_3_1 2.3.1] released&lt;br /&gt;
* 2014/04/10 Version [https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_3_0 2.3.0] released&lt;br /&gt;
* 2014/03/10 Hacking ZAP blog post series started: http://zaproxy.blogspot.co.uk/2014/03/hacking-zap-1-why-should-you.html&lt;br /&gt;
* 2014/02/17 ZAP included as one of the [https://sourceforge.net/blog/projects-of-the-week-february-17-2014/ SourceForge projects of the week]&lt;br /&gt;
* 2013/12/20 ZAP declared the [https://www.toolswatch.org/2013/12/2013-top-security-tools-as-voted-by-toolswatch-org-readers/ Top Security Tool of 2013 as voted by ToolsWatch.org readers]&lt;br /&gt;
* 2013/11/04 [https://github.com/zaproxy/zap-core-help/wiki/ZapEvangelists ZAP Evangelists] initiative launched&lt;br /&gt;
* 2013/10/29 Simon won Best Project Leader [https://www.owasp.org/index.php/WASPY_Awards_2013 WASPY Award]&lt;br /&gt;
* 2013/09/27 Version [https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_2_2 2.2.2] released&lt;br /&gt;
* 2013/09/11 Version [https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_2_0 2.2.0] released&lt;br /&gt;
* 2013/07/29 New language file including support for Bosnian&lt;br /&gt;
* 2013/06/17 ZAP user questionnaire launched, now in both [https://docs.google.com/forms/d/1lUPTYHe9CS5tropNStoRK9jVeZ7tWRywhBHDIZjE4cA/viewform English] and [https://docs.google.com/forms/d/1xAKE3TCOaBrmFnyAVUr6NdTd3mKvu7g_uGriOcS2Ka4/viewform Spanish]&lt;br /&gt;
* 2013/06/05 ZAP questions can now be asked on [https://irc.lc/mozilla/websectools/zapuser??? irc]&lt;br /&gt;
* 2013/05/10 5 ZAP related projects accepted for [https://github.com/zaproxy/zap-core-help/wiki/GSoC2013 Google Summer of Code]&lt;br /&gt;
* 2013/04/18 Version [https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_1_0 2.1.0] released&lt;br /&gt;
* 2013/01/30 Version [http://owasp.blogspot.co.uk/2013/01/owasp-zed-attack-proxy-v-200.html 2.0.0] released&lt;br /&gt;
* 2012/11/27 Started a new [http://code.google.com/p/zaproxy-test/ zaproxy-test] project of unit and integrations tests&lt;br /&gt;
* 2012/10/29 Adopted [http://crowdin.net/project/owasp-zap Crowdin] for translations&lt;br /&gt;
* 2012/10/22 Started generating [https://github.com/zaproxy/zap-core-help/wiki/WeeklyReleases weekly releases]&lt;br /&gt;
* 2012/10/12 ZAP Overview tutorial [http://www.youtube.com/watch?v=eH0RBI0nmww video] published&lt;br /&gt;
* 2012/09/18 [http://www.cafepress.com/zaproxy ZAP Gear Store] goes live&lt;br /&gt;
* 2012/08/05 Version [https://github.com/zaproxy/zap-core-help/wiki/HelpReleases1_4_1 1.4.1] released&lt;br /&gt;
* 2012/07/08 Version [https://github.com/zaproxy/zap-core-help/wiki/HelpReleases1_4_0 1.4.0.1] downloaded over 15,000 times&lt;br /&gt;
* 2012/07/05 [https://github.com/zaproxy/zap-core-help/wiki/ApiPython Python API] released&lt;br /&gt;
* 2012/06/15 ZAP accepted for the [[Projects_Reboot_2012|OWASP Project Reboot]]&lt;br /&gt;
* 2012/06/13 Using ZAP for Security Regression tests [http://www.youtube.com/watch?v=ZWSLFHpg1So video] published&lt;br /&gt;
* 2012/06/04 Version [https://github.com/zaproxy/zap-core-help/wiki/HelpReleases1_4_0 1.4.0.1] downloaded over 10,000 times&lt;br /&gt;
* 2012/05/28 Simon's Introduction to ZAP talk at App Sec USA becomes the most watched OWASP video on [http://vimeo.com/owasp/videos/sort:plays vimeo]&lt;br /&gt;
* 2012/04/23 3 ZAP related [https://github.com/zaproxy/zap-core-help/wiki/GSoC2012 Google Summer of Code 2012] projects accepted. To find out how these are progressing please see their [https://github.com/zaproxy/zap-core-help/wiki/GSoC2012 wiki pages].&lt;br /&gt;
* 2012/04/23 OWASP ZAP [https://github.com/zaproxy/zap-core-help/wiki/SmartCards SmartCard Project] officially launched.&lt;br /&gt;
* 2012/04/08 Version [https://github.com/zaproxy/zap-core-help/wiki/HelpReleases1_4_0 1.4.0.1] released&lt;br /&gt;
* 2012/02/10 Version [https://github.com/zaproxy/zap-core-help/wiki/HelpReleases1_3_4 1.3.4] downloaded over 10,000 times&lt;br /&gt;
* 2012/02/01 OWASP ZAP is named the [http://holisticinfosec.blogspot.com/2012/02/2011-toolsmith-tool-of-year-owasp-zap.html Toolsmith Tool of the Year for 2011!]&lt;br /&gt;
* 2010/09/06 The very first ZAP release, 1.0.0 announced via  [https://seclists.org/bugtraq/2010/Sep/38 bugtraq]&lt;/div&gt;</summary>
		<author><name>Psiinon</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Zed_Attack_Proxy_Project&amp;diff=252323</id>
		<title>OWASP Zed Attack Proxy Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Zed_Attack_Proxy_Project&amp;diff=252323"/>
				<updated>2019-06-10T10:59:46Z</updated>
		
		<summary type="html">&lt;p&gt;Psiinon: More 2.8.0 tweaks&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Main = &lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:90px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File: flagship_big.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
{{ReviewProject|projectname=zaproxy|language=en}}&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
The OWASP Zed Attack Proxy (ZAP) is one of the world’s most popular free security tools and is actively maintained by hundreds of international volunteers[[#Justification|*]]. It can help you automatically find security vulnerabilities in your web applications while you are developing and testing your applications. Its also a great tool for experienced pentesters to use for manual security testing.&lt;br /&gt;
&lt;br /&gt;
====ZAP 2.8.0 is now available!====&lt;br /&gt;
&lt;br /&gt;
[[Image:ZAP-Download.png | link=https://github.com/zaproxy/zaproxy/wiki/Downloads]]&lt;br /&gt;
&lt;br /&gt;
====Please help us to make ZAP even better for you by answering the [https://docs.google.com/forms/d/1-k-vcj_sSxlil6XLxCFade-m-IQVeE2h9gduA-2ZPPA/viewform ZAP User Questionnaire]!====&lt;br /&gt;
&lt;br /&gt;
For a quick overview of ZAP see these tutorial videos on YouTube:&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
{{#ev:youtube|eH0RBI0nmww}}&amp;amp;nbsp;&lt;br /&gt;
{{#ev:youtube|ztfgip-UhWw}}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
For more videos see the links on the [https://github.com/zaproxy/zaproxy/wiki/Videos wiki videos page].&lt;br /&gt;
&lt;br /&gt;
Interested in a ZAP talk or training event? See the [https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project#tab=Talks talks] tab. Not one near you? Contact a [https://github.com/zaproxy/zaproxy/wiki/ZapEvangelists Zap Evangelist] to arrange one!&lt;br /&gt;
&lt;br /&gt;
{{#widget:PayPal Donation&lt;br /&gt;
|target=_blank&lt;br /&gt;
|budget=Zed Attack Proxy&lt;br /&gt;
}}  &lt;br /&gt;
&lt;br /&gt;
For general information about ZAP:&lt;br /&gt;
* [https://twitter.com/zaproxy Twitter] - official ZAP announcements (low volume)&lt;br /&gt;
* [https://zaproxy.blogspot.co.uk/ Blog] - official ZAP blog&lt;br /&gt;
&lt;br /&gt;
For help using ZAP:&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/releases/download/v2.8.0/ZAPGettingStartedGuide-2.8.pdf Getting Started Guide (pdf)] - an introductory guide you can print&lt;br /&gt;
* [https://www.youtube.com/playlist?list=PLEBitBW-Hlsv8cEIUntAO8st2UGhmrjUB Tutorial Videos]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki User Guide] - online version of the User Guide included with ZAP&lt;br /&gt;
* [https://groups.google.com/group/zaproxy-users User Group] - ask questions about using ZAP&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/wiki Add-ons] - help for the optional add-ons you can install&lt;br /&gt;
* [https://stackoverflow.com/questions/tagged/zap StackOverflow] - because some people use this for all everything ;)&lt;br /&gt;
&lt;br /&gt;
To learn more about ZAP development:&lt;br /&gt;
* [https://github.com/zaproxy Source Code] - for all of the ZAP related projects&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/wiki/Introduction Wiki] - lots of detailed info&lt;br /&gt;
* [https://groups.google.com/group/zaproxy-develop Developer Group] - ask questions about the ZAP internals&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap Crowdin (GUI)] - help translate the ZAP GUI&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap-help Crowdin (User Guide)] - help translate the ZAP User Guide&lt;br /&gt;
* [https://www.openhub.net/p/zaproxy OpenHub]	- FOSS analytics&lt;br /&gt;
* [https://www.bountysource.com/teams/zap/issues BountySource] - Vote on ZAP issues (you can also donate money here, but 10% taken out)&lt;br /&gt;
&lt;br /&gt;
===Justification===&lt;br /&gt;
Justification for the statements made in the tagline at the top;)&lt;br /&gt;
&lt;br /&gt;
Popularity:&lt;br /&gt;
* ToolsWatch Annual Best Free/Open Source Security Tool Survey:&lt;br /&gt;
** 2016 [http://www.toolswatch.org/2017/02/2016-top-security-tools-as-voted-by-toolswatch-org-readers/ 2nd]&lt;br /&gt;
** 2015 [http://www.toolswatch.org/2016/02/2015-top-security-tools-as-voted-by-toolswatch-org-readers/ 1st]&lt;br /&gt;
** 2014 [http://www.toolswatch.org/2015/01/2014-top-security-tools-as-voted-by-toolswatch-org-readers/ 2nd]&lt;br /&gt;
** 2013 [http://www.toolswatch.org/2013/12/2013-top-security-tools-as-voted-by-toolswatch-org-readers/ 1st]&lt;br /&gt;
&lt;br /&gt;
Contributors:&lt;br /&gt;
* [https://www.openhub.net/p/zaproxy Code Contributors]&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap ZAP core i18n Contributors]&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap-help ZAP help i18n Contributors]&lt;br /&gt;
&lt;br /&gt;
{{Social Media Links}}&lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;padding-left:25px;width:200px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
[https://github.com/zaproxy/zaproxy/wiki/Downloads Download OWASP ZAP!]&lt;br /&gt;
&lt;br /&gt;
== Donate to ZAP ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div class=&amp;quot;center&amp;quot; style=&amp;quot;width: auto; margin-left: auto; margin-right: auto;&amp;quot;&amp;gt;{{#widget:PayPal Donation&lt;br /&gt;
|target=_blank&lt;br /&gt;
|budget=Zed Attack Proxy }}&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
Please see the [https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project#News News] and [https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project#Talks Talks] tabs&lt;br /&gt;
&lt;br /&gt;
== Change Log ==&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/commits/develop zaproxy]&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/commits/master zap-extensions]&lt;br /&gt;
&lt;br /&gt;
== Code Repo ==&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/ zaproxy]&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/ zap-extensions]&lt;br /&gt;
&lt;br /&gt;
== Email List ==&lt;br /&gt;
&lt;br /&gt;
Questions? Please ask on the [http://groups.google.com/group/zaproxy-users ZAP User Group]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
Project Leader&amp;lt;br /&amp;gt;[https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @]&lt;br /&gt;
&lt;br /&gt;
Co-Project Leaders&amp;lt;br /&amp;gt;[https://www.owasp.org/index.php/User:Ricardo.Pereira Ricardo Pereira] [mailto:ricardo.pereira@owasp.org @]&lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/index.php/User:Rick.mitchell Rick Mitchell] [mailto:rick.mitchell+wiki@owasp.org @]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_Web_Testing_Environment_Project OWASP WTE]&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_OWTF OWASP OWTF]&lt;br /&gt;
&lt;br /&gt;
== Open Hub Stats ==&lt;br /&gt;
&lt;br /&gt;
*https://www.openhub.net/p/zaproxy&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| cellpadding=&amp;quot;2&amp;quot; width=&amp;quot;200&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; | [[File:Mature projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Flagship_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; width=&amp;quot;50%&amp;quot; valign=&amp;quot;center&amp;quot; | [[File:Owasp-builders-small.png|link=]]&lt;br /&gt;
   |&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; width=&amp;quot;50%&amp;quot; valign=&amp;quot;center&amp;quot; | [[File:Owasp-breakers-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [http://www.apache.org/licenses/LICENSE-2.0 Apache 2 License]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_TOOL.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Screenshots =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotAddAlert.png|||400px|ZAP Add Alert Screen Shot]] &lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotHelp.png||400px|left|ZAP Help Screen Shot]]&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotHistoryFilter.png|thumb|400px|left|ZAP History Filter Screen Shot]]&lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotSearchTab.png|thumb|400px|left|ZAP Search Tab Screen Shot]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Talks =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
{{:Projects/OWASP Zed Attack Proxy Project/Pages/Talks | Talks}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
= News =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
{{:Projects/OWASP Zed Attack Proxy Project/Pages/News | News}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
= ZAP Gear =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Yes, you can now buy ZAP related gear!&lt;br /&gt;
&lt;br /&gt;
All of the artwork for ZAP swag is released under the Creative Common License and can be downloaded from the [https://github.com/zaproxy/zap-swag zap-swag] repo.&lt;br /&gt;
&lt;br /&gt;
You can of course use the artwork from this repo with any other online store that you like.&lt;br /&gt;
&lt;br /&gt;
A range of products can be purchased from [http://www.redbubble.com/people/zaproxy Redbubble]&lt;br /&gt;
&lt;br /&gt;
T-shirts can be purchased from [http://www.cafepress.com/zaproxy Cafepress]&lt;br /&gt;
&lt;br /&gt;
[[Image:zap-tshirt-cp.PNG | link=http://www.cafepress.com/zaproxy]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Supporters =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
ZAP is developed by a worldwide [https://github.com/zaproxy/zap-core-help/wiki/HelpCredits team] of volunteers.&lt;br /&gt;
&lt;br /&gt;
But we have also been helped by many organizations, either financially or by encouraging their employees to work on ZAP:&lt;br /&gt;
&lt;br /&gt;
* [http://www.mozilla.org Mozilla]&lt;br /&gt;
* [http://www.linuxfoundation.org/ The Linux Foundation]&lt;br /&gt;
* [https://segment.com/ Segment]&lt;br /&gt;
* [http://www.owasp.org OWASP]&lt;br /&gt;
* [http://www.sage.co.uk Sage]&lt;br /&gt;
* [http://www.google.com Google]&lt;br /&gt;
* [http://www.microsoft.com Microsoft]&lt;br /&gt;
* [http://www.hacktics.com/ Hacktics, Ernst &amp;amp; Young]&lt;br /&gt;
* [http://www.dinosec.com/ DinoSec]&lt;br /&gt;
* [http://www.denimgroup.com Denim Group]&lt;br /&gt;
* [http://www.aspectsecurity.com/ Aspect Security]&lt;br /&gt;
* [http://secureideas.net SecureIdeas]&lt;br /&gt;
* [http://utilisec.com UtiliSec]&lt;br /&gt;
* [http://www.encription.co.uk/ encription]&lt;br /&gt;
* [https://www.accenture.com/us-en/digital-index.aspx Accenture Digital]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Functionality =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
'''Some of ZAP's functionality:'''&lt;br /&gt;
&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsIntercept Man-in-the-middle Proxy]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsSpider Traditional] and AJAX spiders&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsAscan Automated scanner]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsPscan Passive scanner]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsBruteforce Forced browsing]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsFuzz Fuzzer]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpUiDialogsOptionsDynsslcert Dynamic SSL certificates]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/SmartCards Smartcard and Client Digital Certificates support]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpAddonsWebsocketIntroduction Web sockets] support&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpAddonsScriptsScripts Support for a wide range of scripting languages]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki//HelpAddonsPlugnhackPlugnhack Plug-n-Hack support]&lt;br /&gt;
* Authentication and session support&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsApi Powerful REST based API]&lt;br /&gt;
* Automatic updating option&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/wiki Integrated and growing marketplace of add-ons]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
= Features =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
'''Some of ZAP's features:'''&lt;br /&gt;
&lt;br /&gt;
* [http://www.apache.org/licenses/LICENSE-2.0 Open source]&lt;br /&gt;
* Cross platform (it even runs on a [https://github.com/zaproxy/zaproxy/wiki/zappi Raspberry Pi!])&lt;br /&gt;
* Easy to install (using a [https://www.ej-technologies.com/products/install4j/overview.html multi-platform installer builder])&lt;br /&gt;
* Completely free (no paid for 'Pro' version)&lt;br /&gt;
* Ease of use a priority&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpIntro Comprehensive help pages]&lt;br /&gt;
* Fully internationalized&lt;br /&gt;
* Translated into over 20 languages&lt;br /&gt;
* Community based, with involvement actively encouraged&lt;br /&gt;
* Under active development by an international team of volunteers&lt;br /&gt;
&lt;br /&gt;
ZAP is a fork of the well regarded [http://www.parosproxy.org/ Paros Proxy].&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Languages =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''ZAP supports the following languages:'''&lt;br /&gt;
&lt;br /&gt;
* English&lt;br /&gt;
* Arabic&lt;br /&gt;
* Bosnian&lt;br /&gt;
* Brazilian Portuguese&lt;br /&gt;
* Chinese&lt;br /&gt;
* Danish&lt;br /&gt;
* Filipino&lt;br /&gt;
* French&lt;br /&gt;
* German&lt;br /&gt;
* Greek&lt;br /&gt;
* Hungarian&lt;br /&gt;
* Indonesian&lt;br /&gt;
* Italian&lt;br /&gt;
* Japanese&lt;br /&gt;
* Korean&lt;br /&gt;
* Persian&lt;br /&gt;
* Polish&lt;br /&gt;
* Russian&lt;br /&gt;
* Sinhala&lt;br /&gt;
* Spanish&lt;br /&gt;
* Urdu &lt;br /&gt;
&lt;br /&gt;
You can use [http://crowdin.net/project/owasp-zap Crowdin] to help improve these translations or add new ones right now!&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Release 2.6.0==&lt;br /&gt;
ZAP 2.6.0 has been released, this is a bug fix and enhancement release&lt;br /&gt;
&lt;br /&gt;
For more details see https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_6_0&lt;br /&gt;
&lt;br /&gt;
==Release 2.7.0==&lt;br /&gt;
ZAP 2.7.0 has been released (Nov 2017), this is a bug fix and enhancement release&lt;br /&gt;
&lt;br /&gt;
For more details see https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_7_0&lt;br /&gt;
&lt;br /&gt;
It requires Java 8 (minimum) and supports Selenium 3.&lt;br /&gt;
&lt;br /&gt;
==Release 2.8.0==&lt;br /&gt;
ZAP 2.8.0 has been released (June 2019), this is a bug fix and enhancement release&lt;br /&gt;
&lt;br /&gt;
For more details see https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_8_0&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Get Involved =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Involvement in the development of ZAP is actively encouraged!&lt;br /&gt;
&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
&lt;br /&gt;
Some of the ways you can help:&lt;br /&gt;
&lt;br /&gt;
==Feature Requests==&lt;br /&gt;
&lt;br /&gt;
Please raise new feature requests as enhancement requests here: https://github.com/zaproxy/zaproxy/issues&lt;br /&gt;
&lt;br /&gt;
If there are existing requests you are also interested in then please 'star' them - that way we can see which features people are most interested in and can prioritize them accordingly. &lt;br /&gt;
&lt;br /&gt;
==Feedback==&lt;br /&gt;
&lt;br /&gt;
Please use the [http://groups.google.com/group/zaproxy-users zaproxy-users Google Group] for feedback:&lt;br /&gt;
* What do like?&lt;br /&gt;
* What don't you like?&lt;br /&gt;
* What features could be made easier to use?&lt;br /&gt;
* How could the help pages be improved? &lt;br /&gt;
&lt;br /&gt;
==Log issues==&lt;br /&gt;
&lt;br /&gt;
Have you had a problem using ZAP?&lt;br /&gt;
&lt;br /&gt;
If so and its not already been logged then please [https://github.com/zaproxy/zaproxy/issues report it]&lt;br /&gt;
&lt;br /&gt;
==Localization==&lt;br /&gt;
&lt;br /&gt;
Are you fluent in another language? Can you help translate ZAP into that language?&lt;br /&gt;
&lt;br /&gt;
You can use [http://crowdin.net/project/owasp-zap Crowdin] to do that!&lt;br /&gt;
&lt;br /&gt;
==Development==&lt;br /&gt;
&lt;br /&gt;
If you fancy having a go at adding functionality to ZAP then please get in touch via the [http://groups.google.com/group/zaproxy-develop zaproxy-develop Google Group].&lt;br /&gt;
&lt;br /&gt;
Again, you do not have to be a security expert to contribute code - working on ZAP could be great way to learn more about web application security!&lt;br /&gt;
&lt;br /&gt;
If you actively contribute to ZAP then you will be invited to join the project. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project|Zed Attack Proxy Project]]&lt;br /&gt;
[[Category:OWASP_Tool]]&lt;br /&gt;
[[Category:OWASP Release Quality Tool|OWASP Release Quality Tool]]&lt;br /&gt;
[[Category:OWASP_Download]]&lt;br /&gt;
[[Category:Popular]]&lt;br /&gt;
[[Category:SAMM-ST-2]]&lt;br /&gt;
[[Category:Flagship Projects|Zap]]&lt;br /&gt;
[[Category:OWASP Zed Attack Proxy|Zap]]&lt;/div&gt;</summary>
		<author><name>Psiinon</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Zed_Attack_Proxy_Project&amp;diff=252198</id>
		<title>OWASP Zed Attack Proxy Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Zed_Attack_Proxy_Project&amp;diff=252198"/>
				<updated>2019-06-07T16:59:32Z</updated>
		
		<summary type="html">&lt;p&gt;Psiinon: Changed to say 2.8.0 is available&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Main = &lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:90px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File: flagship_big.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
{{ReviewProject|projectname=zaproxy|language=en}}&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
The OWASP Zed Attack Proxy (ZAP) is one of the world’s most popular free security tools and is actively maintained by hundreds of international volunteers[[#Justification|*]]. It can help you automatically find security vulnerabilities in your web applications while you are developing and testing your applications. Its also a great tool for experienced pentesters to use for manual security testing.&lt;br /&gt;
&lt;br /&gt;
====ZAP 2.8.0 is now available!====&lt;br /&gt;
&lt;br /&gt;
[[Image:ZAP-Download.png | link=https://github.com/zaproxy/zaproxy/wiki/Downloads]]&lt;br /&gt;
&lt;br /&gt;
====Please help us to make ZAP even better for you by answering the [https://docs.google.com/forms/d/1-k-vcj_sSxlil6XLxCFade-m-IQVeE2h9gduA-2ZPPA/viewform ZAP User Questionnaire]!====&lt;br /&gt;
&lt;br /&gt;
For a quick overview of ZAP see these tutorial videos on YouTube:&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
{{#ev:youtube|eH0RBI0nmww}}&amp;amp;nbsp;&lt;br /&gt;
{{#ev:youtube|ztfgip-UhWw}}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
For more videos see the links on the [https://github.com/zaproxy/zaproxy/wiki/Videos wiki videos page].&lt;br /&gt;
&lt;br /&gt;
Interested in a ZAP talk or training event? See the [https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project#tab=Talks talks] tab. Not one near you? Contact a [https://github.com/zaproxy/zaproxy/wiki/ZapEvangelists Zap Evangelist] to arrange one!&lt;br /&gt;
&lt;br /&gt;
{{#widget:PayPal Donation&lt;br /&gt;
|target=_blank&lt;br /&gt;
|budget=Zed Attack Proxy&lt;br /&gt;
}}  &lt;br /&gt;
&lt;br /&gt;
For general information about ZAP:&lt;br /&gt;
* [https://twitter.com/zaproxy Twitter] - official ZAP announcements (low volume)&lt;br /&gt;
* [https://zaproxy.blogspot.co.uk/ Blog] - official ZAP blog&lt;br /&gt;
&lt;br /&gt;
For help using ZAP:&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/releases/download/2.6.0/ZAPGettingStartedGuide-2.6.pdf Getting Started Guide (pdf)] - an introductory guide you can print&lt;br /&gt;
* [https://www.youtube.com/playlist?list=PLEBitBW-Hlsv8cEIUntAO8st2UGhmrjUB Tutorial Videos]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki User Guide] - online version of the User Guide included with ZAP&lt;br /&gt;
* [https://groups.google.com/group/zaproxy-users User Group] - ask questions about using ZAP&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/wiki Add-ons] - help for the optional add-ons you can install&lt;br /&gt;
* [https://stackoverflow.com/questions/tagged/zap StackOverflow] - because some people use this for all everything ;)&lt;br /&gt;
&lt;br /&gt;
To learn more about ZAP development:&lt;br /&gt;
* [https://github.com/zaproxy Source Code] - for all of the ZAP related projects&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/wiki/Introduction Wiki] - lots of detailed info&lt;br /&gt;
* [https://groups.google.com/group/zaproxy-develop Developer Group] - ask questions about the ZAP internals&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap Crowdin (GUI)] - help translate the ZAP GUI&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap-help Crowdin (User Guide)] - help translate the ZAP User Guide&lt;br /&gt;
* [https://www.openhub.net/p/zaproxy OpenHub]	- FOSS analytics&lt;br /&gt;
* [https://www.bountysource.com/teams/zap/issues BountySource] - Vote on ZAP issues (you can also donate money here, but 10% taken out)&lt;br /&gt;
&lt;br /&gt;
===Justification===&lt;br /&gt;
Justification for the statements made in the tagline at the top;)&lt;br /&gt;
&lt;br /&gt;
Popularity:&lt;br /&gt;
* ToolsWatch Annual Best Free/Open Source Security Tool Survey:&lt;br /&gt;
** 2016 [http://www.toolswatch.org/2017/02/2016-top-security-tools-as-voted-by-toolswatch-org-readers/ 2nd]&lt;br /&gt;
** 2015 [http://www.toolswatch.org/2016/02/2015-top-security-tools-as-voted-by-toolswatch-org-readers/ 1st]&lt;br /&gt;
** 2014 [http://www.toolswatch.org/2015/01/2014-top-security-tools-as-voted-by-toolswatch-org-readers/ 2nd]&lt;br /&gt;
** 2013 [http://www.toolswatch.org/2013/12/2013-top-security-tools-as-voted-by-toolswatch-org-readers/ 1st]&lt;br /&gt;
&lt;br /&gt;
Contributors:&lt;br /&gt;
* [https://www.openhub.net/p/zaproxy Code Contributors]&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap ZAP core i18n Contributors]&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap-help ZAP help i18n Contributors]&lt;br /&gt;
&lt;br /&gt;
{{Social Media Links}}&lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;padding-left:25px;width:200px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
[https://github.com/zaproxy/zaproxy/wiki/Downloads Download OWASP ZAP!]&lt;br /&gt;
&lt;br /&gt;
== Donate to ZAP ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div class=&amp;quot;center&amp;quot; style=&amp;quot;width: auto; margin-left: auto; margin-right: auto;&amp;quot;&amp;gt;{{#widget:PayPal Donation&lt;br /&gt;
|target=_blank&lt;br /&gt;
|budget=Zed Attack Proxy }}&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
Please see the [https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project#News News] and [https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project#Talks Talks] tabs&lt;br /&gt;
&lt;br /&gt;
== Change Log ==&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/commits/develop zaproxy]&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/commits/master zap-extensions]&lt;br /&gt;
&lt;br /&gt;
== Code Repo ==&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/ zaproxy]&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/ zap-extensions]&lt;br /&gt;
&lt;br /&gt;
== Email List ==&lt;br /&gt;
&lt;br /&gt;
Questions? Please ask on the [http://groups.google.com/group/zaproxy-users ZAP User Group]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
Project Leader&amp;lt;br /&amp;gt;[https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @]&lt;br /&gt;
&lt;br /&gt;
Co-Project Leaders&amp;lt;br /&amp;gt;[https://www.owasp.org/index.php/User:Ricardo.Pereira Ricardo Pereira] [mailto:ricardo.pereira@owasp.org @]&lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/index.php/User:Rick.mitchell Rick Mitchell] [mailto:rick.mitchell+wiki@owasp.org @]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_Web_Testing_Environment_Project OWASP WTE]&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_OWTF OWASP OWTF]&lt;br /&gt;
&lt;br /&gt;
== Open Hub Stats ==&lt;br /&gt;
&lt;br /&gt;
*https://www.openhub.net/p/zaproxy&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| cellpadding=&amp;quot;2&amp;quot; width=&amp;quot;200&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; | [[File:Mature projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Flagship_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; width=&amp;quot;50%&amp;quot; valign=&amp;quot;center&amp;quot; | [[File:Owasp-builders-small.png|link=]]&lt;br /&gt;
   |&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; width=&amp;quot;50%&amp;quot; valign=&amp;quot;center&amp;quot; | [[File:Owasp-breakers-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [http://www.apache.org/licenses/LICENSE-2.0 Apache 2 License]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_TOOL.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Screenshots =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotAddAlert.png|||400px|ZAP Add Alert Screen Shot]] &lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotHelp.png||400px|left|ZAP Help Screen Shot]]&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotHistoryFilter.png|thumb|400px|left|ZAP History Filter Screen Shot]]&lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotSearchTab.png|thumb|400px|left|ZAP Search Tab Screen Shot]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Talks =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
{{:Projects/OWASP Zed Attack Proxy Project/Pages/Talks | Talks}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
= News =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
{{:Projects/OWASP Zed Attack Proxy Project/Pages/News | News}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
= ZAP Gear =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Yes, you can now buy ZAP related gear!&lt;br /&gt;
&lt;br /&gt;
All of the artwork for ZAP swag is released under the Creative Common License and can be downloaded from the [https://github.com/zaproxy/zap-swag zap-swag] repo.&lt;br /&gt;
&lt;br /&gt;
You can of course use the artwork from this repo with any other online store that you like.&lt;br /&gt;
&lt;br /&gt;
A range of products can be purchased from [http://www.redbubble.com/people/zaproxy Redbubble]&lt;br /&gt;
&lt;br /&gt;
Stickers can be purchased from [https://www.stickermule.com/uk/user/1070684077/stickers Stickermule]&lt;br /&gt;
&lt;br /&gt;
T-shirts can be purchased from [http://www.cafepress.com/zaproxy Cafepress]&lt;br /&gt;
&lt;br /&gt;
[[Image:zap-tshirt-cp.PNG | link=http://www.cafepress.com/zaproxy]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Supporters =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
ZAP is developed by a worldwide [https://github.com/zaproxy/zap-core-help/wiki/HelpCredits team] of volunteers.&lt;br /&gt;
&lt;br /&gt;
But we have also been helped by many organizations, either financially or by encouraging their employees to work on ZAP:&lt;br /&gt;
&lt;br /&gt;
* [http://www.mozilla.org Mozilla]&lt;br /&gt;
* [http://www.linuxfoundation.org/ The Linux Foundation]&lt;br /&gt;
* [https://segment.com/ Segment]&lt;br /&gt;
* [http://www.owasp.org OWASP]&lt;br /&gt;
* [http://www.sage.co.uk Sage]&lt;br /&gt;
* [http://www.google.com Google]&lt;br /&gt;
* [http://www.microsoft.com Microsoft]&lt;br /&gt;
* [http://www.hacktics.com/ Hacktics, Ernst &amp;amp; Young]&lt;br /&gt;
* [http://www.dinosec.com/ DinoSec]&lt;br /&gt;
* [http://www.denimgroup.com Denim Group]&lt;br /&gt;
* [http://www.aspectsecurity.com/ Aspect Security]&lt;br /&gt;
* [http://secureideas.net SecureIdeas]&lt;br /&gt;
* [http://utilisec.com UtiliSec]&lt;br /&gt;
* [http://www.encription.co.uk/ encription]&lt;br /&gt;
* [https://www.accenture.com/us-en/digital-index.aspx Accenture Digital]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Functionality =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
'''Some of ZAP's functionality:'''&lt;br /&gt;
&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsIntercept Man-in-the-middle Proxy]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsSpider Traditional] and AJAX spiders&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsAscan Automated scanner]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsPscan Passive scanner]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsBruteforce Forced browsing]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsFuzz Fuzzer]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpUiDialogsOptionsDynsslcert Dynamic SSL certificates]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/SmartCards Smartcard and Client Digital Certificates support]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpAddonsWebsocketIntroduction Web sockets] support&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpAddonsScriptsScripts Support for a wide range of scripting languages]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki//HelpAddonsPlugnhackPlugnhack Plug-n-Hack support]&lt;br /&gt;
* Authentication and session support&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsApi Powerful REST based API]&lt;br /&gt;
* Automatic updating option&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/wiki Integrated and growing marketplace of add-ons]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
= Features =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
'''Some of ZAP's features:'''&lt;br /&gt;
&lt;br /&gt;
* [http://www.apache.org/licenses/LICENSE-2.0 Open source]&lt;br /&gt;
* Cross platform (it even runs on a [https://github.com/zaproxy/zaproxy/wiki/zappi Raspberry Pi!])&lt;br /&gt;
* Easy to install (using a [https://www.ej-technologies.com/products/install4j/overview.html multi-platform installer builder])&lt;br /&gt;
* Completely free (no paid for 'Pro' version)&lt;br /&gt;
* Ease of use a priority&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpIntro Comprehensive help pages]&lt;br /&gt;
* Fully internationalized&lt;br /&gt;
* Translated into over 20 languages&lt;br /&gt;
* Community based, with involvement actively encouraged&lt;br /&gt;
* Under active development by an international team of volunteers&lt;br /&gt;
&lt;br /&gt;
ZAP is a fork of the well regarded [http://www.parosproxy.org/ Paros Proxy].&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Languages =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''ZAP supports the following languages:'''&lt;br /&gt;
&lt;br /&gt;
* English&lt;br /&gt;
* Arabic&lt;br /&gt;
* Bosnian&lt;br /&gt;
* Brazilian Portuguese&lt;br /&gt;
* Chinese&lt;br /&gt;
* Danish&lt;br /&gt;
* Filipino&lt;br /&gt;
* French&lt;br /&gt;
* German&lt;br /&gt;
* Greek&lt;br /&gt;
* Hungarian&lt;br /&gt;
* Indonesian&lt;br /&gt;
* Italian&lt;br /&gt;
* Japanese&lt;br /&gt;
* Korean&lt;br /&gt;
* Persian&lt;br /&gt;
* Polish&lt;br /&gt;
* Russian&lt;br /&gt;
* Sinhala&lt;br /&gt;
* Spanish&lt;br /&gt;
* Urdu &lt;br /&gt;
&lt;br /&gt;
You can use [http://crowdin.net/project/owasp-zap Crowdin] to help improve these translations or add new ones right now!&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Release 2.6.0==&lt;br /&gt;
ZAP 2.6.0 has been released, this is a bug fix and enhancement release&lt;br /&gt;
&lt;br /&gt;
For more details see https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_6_0&lt;br /&gt;
&lt;br /&gt;
==Release 2.7.0==&lt;br /&gt;
ZAP 2.7.0 has been released (Nov 2017), this is a bug fix and enhancement release&lt;br /&gt;
&lt;br /&gt;
For more details see https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_7_0&lt;br /&gt;
&lt;br /&gt;
It requires Java 8 (minimum) and supports Selenium 3.&lt;br /&gt;
&lt;br /&gt;
==Release 2.8.0==&lt;br /&gt;
ZAP 2.8.0 does not yet have a planned release date, but is likely to be in the first half of 2019.&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Get Involved =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Involvement in the development of ZAP is actively encouraged!&lt;br /&gt;
&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
&lt;br /&gt;
Some of the ways you can help:&lt;br /&gt;
&lt;br /&gt;
==Feature Requests==&lt;br /&gt;
&lt;br /&gt;
Please raise new feature requests as enhancement requests here: https://github.com/zaproxy/zaproxy/issues&lt;br /&gt;
&lt;br /&gt;
If there are existing requests you are also interested in then please 'star' them - that way we can see which features people are most interested in and can prioritize them accordingly. &lt;br /&gt;
&lt;br /&gt;
==Feedback==&lt;br /&gt;
&lt;br /&gt;
Please use the [http://groups.google.com/group/zaproxy-users zaproxy-users Google Group] for feedback:&lt;br /&gt;
* What do like?&lt;br /&gt;
* What don't you like?&lt;br /&gt;
* What features could be made easier to use?&lt;br /&gt;
* How could the help pages be improved? &lt;br /&gt;
&lt;br /&gt;
==Log issues==&lt;br /&gt;
&lt;br /&gt;
Have you had a problem using ZAP?&lt;br /&gt;
&lt;br /&gt;
If so and its not already been logged then please [https://github.com/zaproxy/zaproxy/issues report it]&lt;br /&gt;
&lt;br /&gt;
==Localization==&lt;br /&gt;
&lt;br /&gt;
Are you fluent in another language? Can you help translate ZAP into that language?&lt;br /&gt;
&lt;br /&gt;
You can use [http://crowdin.net/project/owasp-zap Crowdin] to do that!&lt;br /&gt;
&lt;br /&gt;
==Development==&lt;br /&gt;
&lt;br /&gt;
If you fancy having a go at adding functionality to ZAP then please get in touch via the [http://groups.google.com/group/zaproxy-develop zaproxy-develop Google Group].&lt;br /&gt;
&lt;br /&gt;
Again, you do not have to be a security expert to contribute code - working on ZAP could be great way to learn more about web application security!&lt;br /&gt;
&lt;br /&gt;
If you actively contribute to ZAP then you will be invited to join the project. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project|Zed Attack Proxy Project]]&lt;br /&gt;
[[Category:OWASP_Tool]]&lt;br /&gt;
[[Category:OWASP Release Quality Tool|OWASP Release Quality Tool]]&lt;br /&gt;
[[Category:OWASP_Download]]&lt;br /&gt;
[[Category:Popular]]&lt;br /&gt;
[[Category:SAMM-ST-2]]&lt;br /&gt;
[[Category:Flagship Projects|Zap]]&lt;br /&gt;
[[Category:OWASP Zed Attack Proxy|Zap]]&lt;/div&gt;</summary>
		<author><name>Psiinon</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Zed_Attack_Proxy_Project&amp;diff=251993</id>
		<title>OWASP Zed Attack Proxy Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Zed_Attack_Proxy_Project&amp;diff=251993"/>
				<updated>2019-05-30T11:03:45Z</updated>
		
		<summary type="html">&lt;p&gt;Psiinon: Removed Jenkins video&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Main = &lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:90px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File: flagship_big.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
{{ReviewProject|projectname=zaproxy|language=en}}&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
The OWASP Zed Attack Proxy (ZAP) is one of the world’s most popular free security tools and is actively maintained by hundreds of international volunteers[[#Justification|*]]. It can help you automatically find security vulnerabilities in your web applications while you are developing and testing your applications. Its also a great tool for experienced pentesters to use for manual security testing.&lt;br /&gt;
&lt;br /&gt;
====ZAP 2.7.0 is now available!====&lt;br /&gt;
&lt;br /&gt;
[[Image:ZAP-Download.png | link=https://github.com/zaproxy/zaproxy/wiki/Downloads]]&lt;br /&gt;
&lt;br /&gt;
====Please help us to make ZAP even better for you by answering the [https://docs.google.com/forms/d/1-k-vcj_sSxlil6XLxCFade-m-IQVeE2h9gduA-2ZPPA/viewform ZAP User Questionnaire]!====&lt;br /&gt;
&lt;br /&gt;
For a quick overview of ZAP see these tutorial videos on YouTube:&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
{{#ev:youtube|eH0RBI0nmww}}&amp;amp;nbsp;&lt;br /&gt;
{{#ev:youtube|ztfgip-UhWw}}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
For more videos see the links on the [https://github.com/zaproxy/zaproxy/wiki/Videos wiki videos page].&lt;br /&gt;
&lt;br /&gt;
Interested in a ZAP talk or training event? See the [https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project#tab=Talks talks] tab. Not one near you? Contact a [https://github.com/zaproxy/zaproxy/wiki/ZapEvangelists Zap Evangelist] to arrange one!&lt;br /&gt;
&lt;br /&gt;
{{#widget:PayPal Donation&lt;br /&gt;
|target=_blank&lt;br /&gt;
|budget=Zed Attack Proxy&lt;br /&gt;
}}  &lt;br /&gt;
&lt;br /&gt;
For general information about ZAP:&lt;br /&gt;
* [https://twitter.com/zaproxy Twitter] - official ZAP announcements (low volume)&lt;br /&gt;
* [https://zaproxy.blogspot.co.uk/ Blog] - official ZAP blog&lt;br /&gt;
&lt;br /&gt;
For help using ZAP:&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/releases/download/2.6.0/ZAPGettingStartedGuide-2.6.pdf Getting Started Guide (pdf)] - an introductory guide you can print&lt;br /&gt;
* [https://www.youtube.com/playlist?list=PLEBitBW-Hlsv8cEIUntAO8st2UGhmrjUB Tutorial Videos]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki User Guide] - online version of the User Guide included with ZAP&lt;br /&gt;
* [https://groups.google.com/group/zaproxy-users User Group] - ask questions about using ZAP&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/wiki Add-ons] - help for the optional add-ons you can install&lt;br /&gt;
* [https://stackoverflow.com/questions/tagged/zap StackOverflow] - because some people use this for all everything ;)&lt;br /&gt;
&lt;br /&gt;
To learn more about ZAP development:&lt;br /&gt;
* [https://github.com/zaproxy Source Code] - for all of the ZAP related projects&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/wiki/Introduction Wiki] - lots of detailed info&lt;br /&gt;
* [https://groups.google.com/group/zaproxy-develop Developer Group] - ask questions about the ZAP internals&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap Crowdin (GUI)] - help translate the ZAP GUI&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap-help Crowdin (User Guide)] - help translate the ZAP User Guide&lt;br /&gt;
* [https://www.openhub.net/p/zaproxy OpenHub]	- FOSS analytics&lt;br /&gt;
* [https://www.bountysource.com/teams/zap/issues BountySource] - Vote on ZAP issues (you can also donate money here, but 10% taken out)&lt;br /&gt;
&lt;br /&gt;
===Justification===&lt;br /&gt;
Justification for the statements made in the tagline at the top;)&lt;br /&gt;
&lt;br /&gt;
Popularity:&lt;br /&gt;
* ToolsWatch Annual Best Free/Open Source Security Tool Survey:&lt;br /&gt;
** 2016 [http://www.toolswatch.org/2017/02/2016-top-security-tools-as-voted-by-toolswatch-org-readers/ 2nd]&lt;br /&gt;
** 2015 [http://www.toolswatch.org/2016/02/2015-top-security-tools-as-voted-by-toolswatch-org-readers/ 1st]&lt;br /&gt;
** 2014 [http://www.toolswatch.org/2015/01/2014-top-security-tools-as-voted-by-toolswatch-org-readers/ 2nd]&lt;br /&gt;
** 2013 [http://www.toolswatch.org/2013/12/2013-top-security-tools-as-voted-by-toolswatch-org-readers/ 1st]&lt;br /&gt;
&lt;br /&gt;
Contributors:&lt;br /&gt;
* [https://www.openhub.net/p/zaproxy Code Contributors]&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap ZAP core i18n Contributors]&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap-help ZAP help i18n Contributors]&lt;br /&gt;
&lt;br /&gt;
{{Social Media Links}}&lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;padding-left:25px;width:200px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
[https://github.com/zaproxy/zaproxy/wiki/Downloads Download OWASP ZAP!]&lt;br /&gt;
&lt;br /&gt;
== Donate to ZAP ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div class=&amp;quot;center&amp;quot; style=&amp;quot;width: auto; margin-left: auto; margin-right: auto;&amp;quot;&amp;gt;{{#widget:PayPal Donation&lt;br /&gt;
|target=_blank&lt;br /&gt;
|budget=Zed Attack Proxy }}&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
Please see the [https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project#News News] and [https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project#Talks Talks] tabs&lt;br /&gt;
&lt;br /&gt;
== Change Log ==&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/commits/develop zaproxy]&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/commits/master zap-extensions]&lt;br /&gt;
&lt;br /&gt;
== Code Repo ==&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/ zaproxy]&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/ zap-extensions]&lt;br /&gt;
&lt;br /&gt;
== Email List ==&lt;br /&gt;
&lt;br /&gt;
Questions? Please ask on the [http://groups.google.com/group/zaproxy-users ZAP User Group]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
Project Leader&amp;lt;br /&amp;gt;[https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @]&lt;br /&gt;
&lt;br /&gt;
Co-Project Leaders&amp;lt;br /&amp;gt;[https://www.owasp.org/index.php/User:Ricardo.Pereira Ricardo Pereira] [mailto:ricardo.pereira@owasp.org @]&lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/index.php/User:Rick.mitchell Rick Mitchell] [mailto:rick.mitchell+wiki@owasp.org @]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_Web_Testing_Environment_Project OWASP WTE]&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_OWTF OWASP OWTF]&lt;br /&gt;
&lt;br /&gt;
== Open Hub Stats ==&lt;br /&gt;
&lt;br /&gt;
*https://www.openhub.net/p/zaproxy&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| cellpadding=&amp;quot;2&amp;quot; width=&amp;quot;200&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; | [[File:Mature projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Flagship_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; width=&amp;quot;50%&amp;quot; valign=&amp;quot;center&amp;quot; | [[File:Owasp-builders-small.png|link=]]&lt;br /&gt;
   |&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; width=&amp;quot;50%&amp;quot; valign=&amp;quot;center&amp;quot; | [[File:Owasp-breakers-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [http://www.apache.org/licenses/LICENSE-2.0 Apache 2 License]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_TOOL.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Screenshots =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotAddAlert.png|||400px|ZAP Add Alert Screen Shot]] &lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotHelp.png||400px|left|ZAP Help Screen Shot]]&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotHistoryFilter.png|thumb|400px|left|ZAP History Filter Screen Shot]]&lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotSearchTab.png|thumb|400px|left|ZAP Search Tab Screen Shot]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Talks =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
{{:Projects/OWASP Zed Attack Proxy Project/Pages/Talks | Talks}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
= News =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
{{:Projects/OWASP Zed Attack Proxy Project/Pages/News | News}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
= ZAP Gear =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Yes, you can now buy ZAP related gear!&lt;br /&gt;
&lt;br /&gt;
All of the artwork for ZAP swag is released under the Creative Common License and can be downloaded from the [https://github.com/zaproxy/zap-swag zap-swag] repo.&lt;br /&gt;
&lt;br /&gt;
You can of course use the artwork from this repo with any other online store that you like.&lt;br /&gt;
&lt;br /&gt;
A range of products can be purchased from [http://www.redbubble.com/people/zaproxy Redbubble]&lt;br /&gt;
&lt;br /&gt;
Stickers can be purchased from [https://www.stickermule.com/uk/user/1070684077/stickers Stickermule]&lt;br /&gt;
&lt;br /&gt;
T-shirts can be purchased from [http://www.cafepress.com/zaproxy Cafepress]&lt;br /&gt;
&lt;br /&gt;
[[Image:zap-tshirt-cp.PNG | link=http://www.cafepress.com/zaproxy]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Supporters =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
ZAP is developed by a worldwide [https://github.com/zaproxy/zap-core-help/wiki/HelpCredits team] of volunteers.&lt;br /&gt;
&lt;br /&gt;
But we have also been helped by many organizations, either financially or by encouraging their employees to work on ZAP:&lt;br /&gt;
&lt;br /&gt;
* [http://www.mozilla.org Mozilla]&lt;br /&gt;
* [http://www.linuxfoundation.org/ The Linux Foundation]&lt;br /&gt;
* [https://segment.com/ Segment]&lt;br /&gt;
* [http://www.owasp.org OWASP]&lt;br /&gt;
* [http://www.sage.co.uk Sage]&lt;br /&gt;
* [http://www.google.com Google]&lt;br /&gt;
* [http://www.microsoft.com Microsoft]&lt;br /&gt;
* [http://www.hacktics.com/ Hacktics, Ernst &amp;amp; Young]&lt;br /&gt;
* [http://www.dinosec.com/ DinoSec]&lt;br /&gt;
* [http://www.denimgroup.com Denim Group]&lt;br /&gt;
* [http://www.aspectsecurity.com/ Aspect Security]&lt;br /&gt;
* [http://secureideas.net SecureIdeas]&lt;br /&gt;
* [http://utilisec.com UtiliSec]&lt;br /&gt;
* [http://www.encription.co.uk/ encription]&lt;br /&gt;
* [https://www.accenture.com/us-en/digital-index.aspx Accenture Digital]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Functionality =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
'''Some of ZAP's functionality:'''&lt;br /&gt;
&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsIntercept Man-in-the-middle Proxy]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsSpider Traditional] and AJAX spiders&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsAscan Automated scanner]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsPscan Passive scanner]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsBruteforce Forced browsing]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsFuzz Fuzzer]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpUiDialogsOptionsDynsslcert Dynamic SSL certificates]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/SmartCards Smartcard and Client Digital Certificates support]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpAddonsWebsocketIntroduction Web sockets] support&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpAddonsScriptsScripts Support for a wide range of scripting languages]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki//HelpAddonsPlugnhackPlugnhack Plug-n-Hack support]&lt;br /&gt;
* Authentication and session support&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsApi Powerful REST based API]&lt;br /&gt;
* Automatic updating option&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/wiki Integrated and growing marketplace of add-ons]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
= Features =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
'''Some of ZAP's features:'''&lt;br /&gt;
&lt;br /&gt;
* [http://www.apache.org/licenses/LICENSE-2.0 Open source]&lt;br /&gt;
* Cross platform (it even runs on a [https://github.com/zaproxy/zaproxy/wiki/zappi Raspberry Pi!])&lt;br /&gt;
* Easy to install (using a [https://www.ej-technologies.com/products/install4j/overview.html multi-platform installer builder])&lt;br /&gt;
* Completely free (no paid for 'Pro' version)&lt;br /&gt;
* Ease of use a priority&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpIntro Comprehensive help pages]&lt;br /&gt;
* Fully internationalized&lt;br /&gt;
* Translated into over 20 languages&lt;br /&gt;
* Community based, with involvement actively encouraged&lt;br /&gt;
* Under active development by an international team of volunteers&lt;br /&gt;
&lt;br /&gt;
ZAP is a fork of the well regarded [http://www.parosproxy.org/ Paros Proxy].&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Languages =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''ZAP supports the following languages:'''&lt;br /&gt;
&lt;br /&gt;
* English&lt;br /&gt;
* Arabic&lt;br /&gt;
* Bosnian&lt;br /&gt;
* Brazilian Portuguese&lt;br /&gt;
* Chinese&lt;br /&gt;
* Danish&lt;br /&gt;
* Filipino&lt;br /&gt;
* French&lt;br /&gt;
* German&lt;br /&gt;
* Greek&lt;br /&gt;
* Hungarian&lt;br /&gt;
* Indonesian&lt;br /&gt;
* Italian&lt;br /&gt;
* Japanese&lt;br /&gt;
* Korean&lt;br /&gt;
* Persian&lt;br /&gt;
* Polish&lt;br /&gt;
* Russian&lt;br /&gt;
* Sinhala&lt;br /&gt;
* Spanish&lt;br /&gt;
* Urdu &lt;br /&gt;
&lt;br /&gt;
You can use [http://crowdin.net/project/owasp-zap Crowdin] to help improve these translations or add new ones right now!&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Release 2.6.0==&lt;br /&gt;
ZAP 2.6.0 has been released, this is a bug fix and enhancement release&lt;br /&gt;
&lt;br /&gt;
For more details see https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_6_0&lt;br /&gt;
&lt;br /&gt;
==Release 2.7.0==&lt;br /&gt;
ZAP 2.7.0 has been released (Nov 2017), this is a bug fix and enhancement release&lt;br /&gt;
&lt;br /&gt;
For more details see https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_7_0&lt;br /&gt;
&lt;br /&gt;
It requires Java 8 (minimum) and supports Selenium 3.&lt;br /&gt;
&lt;br /&gt;
==Release 2.8.0==&lt;br /&gt;
ZAP 2.8.0 does not yet have a planned release date, but is likely to be in the first half of 2019.&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Get Involved =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Involvement in the development of ZAP is actively encouraged!&lt;br /&gt;
&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
&lt;br /&gt;
Some of the ways you can help:&lt;br /&gt;
&lt;br /&gt;
==Feature Requests==&lt;br /&gt;
&lt;br /&gt;
Please raise new feature requests as enhancement requests here: https://github.com/zaproxy/zaproxy/issues&lt;br /&gt;
&lt;br /&gt;
If there are existing requests you are also interested in then please 'star' them - that way we can see which features people are most interested in and can prioritize them accordingly. &lt;br /&gt;
&lt;br /&gt;
==Feedback==&lt;br /&gt;
&lt;br /&gt;
Please use the [http://groups.google.com/group/zaproxy-users zaproxy-users Google Group] for feedback:&lt;br /&gt;
* What do like?&lt;br /&gt;
* What don't you like?&lt;br /&gt;
* What features could be made easier to use?&lt;br /&gt;
* How could the help pages be improved? &lt;br /&gt;
&lt;br /&gt;
==Log issues==&lt;br /&gt;
&lt;br /&gt;
Have you had a problem using ZAP?&lt;br /&gt;
&lt;br /&gt;
If so and its not already been logged then please [https://github.com/zaproxy/zaproxy/issues report it]&lt;br /&gt;
&lt;br /&gt;
==Localization==&lt;br /&gt;
&lt;br /&gt;
Are you fluent in another language? Can you help translate ZAP into that language?&lt;br /&gt;
&lt;br /&gt;
You can use [http://crowdin.net/project/owasp-zap Crowdin] to do that!&lt;br /&gt;
&lt;br /&gt;
==Development==&lt;br /&gt;
&lt;br /&gt;
If you fancy having a go at adding functionality to ZAP then please get in touch via the [http://groups.google.com/group/zaproxy-develop zaproxy-develop Google Group].&lt;br /&gt;
&lt;br /&gt;
Again, you do not have to be a security expert to contribute code - working on ZAP could be great way to learn more about web application security!&lt;br /&gt;
&lt;br /&gt;
If you actively contribute to ZAP then you will be invited to join the project. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project|Zed Attack Proxy Project]]&lt;br /&gt;
[[Category:OWASP_Tool]]&lt;br /&gt;
[[Category:OWASP Release Quality Tool|OWASP Release Quality Tool]]&lt;br /&gt;
[[Category:OWASP_Download]]&lt;br /&gt;
[[Category:Popular]]&lt;br /&gt;
[[Category:SAMM-ST-2]]&lt;br /&gt;
[[Category:Flagship Projects|Zap]]&lt;br /&gt;
[[Category:OWASP Zed Attack Proxy|Zap]]&lt;/div&gt;</summary>
		<author><name>Psiinon</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Projects/OWASP_Zed_Attack_Proxy_Project/Pages/News&amp;diff=250046</id>
		<title>Projects/OWASP Zed Attack Proxy Project/Pages/News</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Projects/OWASP_Zed_Attack_Proxy_Project/Pages/News&amp;diff=250046"/>
				<updated>2019-04-12T13:17:18Z</updated>
		
		<summary type="html">&lt;p&gt;Psiinon: Added ZAP 1.0.0 and HUD Announcements&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Latest News:'''&lt;br /&gt;
&lt;br /&gt;
* 2018/07/26 The [https://github.com/zaproxy/zap-hud ZAP Heads Up Display (HUD)] revealed at Bay Area OWASP meetup&lt;br /&gt;
* 2017/11/28 Version [https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_7_0 2.7.0] released&lt;br /&gt;
* 2017/03/29 Version [https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_6_0 2.6.0] released&lt;br /&gt;
* 2017/02/11 ZAP came second in the [http://www.toolswatch.org/2017/02/2016-top-security-tools-as-voted-by-toolswatch-org-readers/ Top Security Tools of 2016 as voted by ToolsWatch.org readers]&lt;br /&gt;
* 2016/06/03 Version [https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_5_0 2.5.0] released&lt;br /&gt;
* 2016/05/26 ZAP [https://bugcrowd.com/owaspzap bug bounty program] launched&lt;br /&gt;
* 2016/02/23 ZAP declared the [http://www.toolswatch.org/2016/02/2015-top-security-tools-as-voted-by-toolswatch-org-readers/ Top Security Tool of 2015 as voted by ToolsWatch.org readers]&lt;br /&gt;
* 2016/02/19 ZAP [http://zaproxy.blogspot.com/2016/02/zap-newsletter-2016-february.html February newsletter] published&lt;br /&gt;
* 2016/01/04 ZAP [http://zaproxy.blogspot.com/2016/01/zap-newsletter-2016-january.html January newsletter] published&lt;br /&gt;
* 2015/12/15 ZAP [http://zaproxy.blogspot.co.uk/2015/12/zap-newsletter-2015-december.html December newsletter] published&lt;br /&gt;
* 2015/12/04 Version [https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_4_3 2.4.3] released&lt;br /&gt;
* 2015/11/02 ZAP [http://zaproxy.blogspot.co.uk/2015/11/zap-newsletter-2015-november.html November newsletter] published&lt;br /&gt;
* 2015/09/07 Version [https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_4_2 2.4.2] released&lt;br /&gt;
* 2015/07/31 ZAP [https://www.owasp.org/index.php/2015-08-ZAP-ScriptingCompetition Scripting Competition] launched&lt;br /&gt;
* 2015/07/30 Version [https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_4_1 2.4.1] released&lt;br /&gt;
* 2015/05/05 ZAP featured in the [http://assets.thoughtworks.com/assets/technology-radar-may-2015-en.pdf ThoughtWorks Technology Radar]&lt;br /&gt;
* 2015/04/14 Version [http://owasp.blogspot.co.uk/2015/04/owasp-zap-240.html 2.4.0] released&lt;br /&gt;
* 2015/01/14 ZAP came second in the [http://www.toolswatch.org/2015/01/2014-top-security-tools-as-voted-by-toolswatch-org-readers/ Top Security Tools of 2014 as voted by ToolsWatch.org readers]&lt;br /&gt;
* 2015/01/02 ZAP [https://github.com/zaproxy/community-scripts Community Scripts] repo launched&lt;br /&gt;
* 2014/05/21 Version [https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_3_1 2.3.1] released&lt;br /&gt;
* 2014/04/10 Version [https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_3_0 2.3.0] released&lt;br /&gt;
* 2014/03/10 Hacking ZAP blog post series started: http://zaproxy.blogspot.co.uk/2014/03/hacking-zap-1-why-should-you.html&lt;br /&gt;
* 2014/02/17 ZAP included as one of the [https://sourceforge.net/blog/projects-of-the-week-february-17-2014/ SourceForge projects of the week]&lt;br /&gt;
* 2013/12/20 ZAP declared the [https://www.toolswatch.org/2013/12/2013-top-security-tools-as-voted-by-toolswatch-org-readers/ Top Security Tool of 2013 as voted by ToolsWatch.org readers]&lt;br /&gt;
* 2013/11/04 [https://github.com/zaproxy/zap-core-help/wiki/ZapEvangelists ZAP Evangelists] initiative launched&lt;br /&gt;
* 2013/10/29 Simon won Best Project Leader [https://www.owasp.org/index.php/WASPY_Awards_2013 WASPY Award]&lt;br /&gt;
* 2013/09/27 Version [https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_2_2 2.2.2] released&lt;br /&gt;
* 2013/09/11 Version [https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_2_0 2.2.0] released&lt;br /&gt;
* 2013/07/29 New language file including support for Bosnian&lt;br /&gt;
* 2013/06/17 ZAP user questionnaire launched, now in both [https://docs.google.com/forms/d/1lUPTYHe9CS5tropNStoRK9jVeZ7tWRywhBHDIZjE4cA/viewform English] and [https://docs.google.com/forms/d/1xAKE3TCOaBrmFnyAVUr6NdTd3mKvu7g_uGriOcS2Ka4/viewform Spanish]&lt;br /&gt;
* 2013/06/05 ZAP questions can now be asked on [https://irc.lc/mozilla/websectools/zapuser??? irc]&lt;br /&gt;
* 2013/05/10 5 ZAP related projects accepted for [https://github.com/zaproxy/zap-core-help/wiki/GSoC2013 Google Summer of Code]&lt;br /&gt;
* 2013/04/18 Version [https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_1_0 2.1.0] released&lt;br /&gt;
* 2013/01/30 Version [http://owasp.blogspot.co.uk/2013/01/owasp-zed-attack-proxy-v-200.html 2.0.0] released&lt;br /&gt;
* 2012/11/27 Started a new [http://code.google.com/p/zaproxy-test/ zaproxy-test] project of unit and integrations tests&lt;br /&gt;
* 2012/10/29 Adopted [http://crowdin.net/project/owasp-zap Crowdin] for translations&lt;br /&gt;
* 2012/10/22 Started generating [https://github.com/zaproxy/zap-core-help/wiki/WeeklyReleases weekly releases]&lt;br /&gt;
* 2012/10/12 ZAP Overview tutorial [http://www.youtube.com/watch?v=eH0RBI0nmww video] published&lt;br /&gt;
* 2012/09/18 [http://www.cafepress.com/zaproxy ZAP Gear Store] goes live&lt;br /&gt;
* 2012/08/05 Version [https://github.com/zaproxy/zap-core-help/wiki/HelpReleases1_4_1 1.4.1] released&lt;br /&gt;
* 2012/07/08 Version [https://github.com/zaproxy/zap-core-help/wiki/HelpReleases1_4_0 1.4.0.1] downloaded over 15,000 times&lt;br /&gt;
* 2012/07/05 [https://github.com/zaproxy/zap-core-help/wiki/ApiPython Python API] released&lt;br /&gt;
* 2012/06/15 ZAP accepted for the [[Projects_Reboot_2012|OWASP Project Reboot]]&lt;br /&gt;
* 2012/06/13 Using ZAP for Security Regression tests [http://www.youtube.com/watch?v=ZWSLFHpg1So video] published&lt;br /&gt;
* 2012/06/04 Version [https://github.com/zaproxy/zap-core-help/wiki/HelpReleases1_4_0 1.4.0.1] downloaded over 10,000 times&lt;br /&gt;
* 2012/05/28 Simon's Introduction to ZAP talk at App Sec USA becomes the most watched OWASP video on [http://vimeo.com/owasp/videos/sort:plays vimeo]&lt;br /&gt;
* 2012/04/23 3 ZAP related [https://github.com/zaproxy/zap-core-help/wiki/GSoC2012 Google Summer of Code 2012] projects accepted. To find out how these are progressing please see their [https://github.com/zaproxy/zap-core-help/wiki/GSoC2012 wiki pages].&lt;br /&gt;
* 2012/04/23 OWASP ZAP [https://github.com/zaproxy/zap-core-help/wiki/SmartCards SmartCard Project] officially launched.&lt;br /&gt;
* 2012/04/08 Version [https://github.com/zaproxy/zap-core-help/wiki/HelpReleases1_4_0 1.4.0.1] released&lt;br /&gt;
* 2012/02/10 Version [https://github.com/zaproxy/zap-core-help/wiki/HelpReleases1_3_4 1.3.4] downloaded over 10,000 times&lt;br /&gt;
* 2012/02/01 OWASP ZAP is named the [http://holisticinfosec.blogspot.com/2012/02/2011-toolsmith-tool-of-year-owasp-zap.html Toolsmith Tool of the Year for 2011!]&lt;br /&gt;
* 2010/09/06 The very first ZAP release, 1.0.0 announced via  [https://seclists.org/bugtraq/2010/Sep/38 bugtraq]&lt;/div&gt;</summary>
		<author><name>Psiinon</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Zed_Attack_Proxy_Project&amp;diff=250045</id>
		<title>OWASP Zed Attack Proxy Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Zed_Attack_Proxy_Project&amp;diff=250045"/>
				<updated>2019-04-12T13:09:00Z</updated>
		
		<summary type="html">&lt;p&gt;Psiinon: Tweaked 2.8.0 release date&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Main = &lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:90px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File: flagship_big.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
{{ReviewProject|projectname=zaproxy|language=en}}&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
The OWASP Zed Attack Proxy (ZAP) is one of the world’s most popular free security tools and is actively maintained by hundreds of international volunteers[[#Justification|*]]. It can help you automatically find security vulnerabilities in your web applications while you are developing and testing your applications. Its also a great tool for experienced pentesters to use for manual security testing.&lt;br /&gt;
&lt;br /&gt;
====ZAP 2.7.0 is now available!====&lt;br /&gt;
&lt;br /&gt;
[[Image:ZAP-Download.png | link=https://github.com/zaproxy/zaproxy/wiki/Downloads]]&lt;br /&gt;
&lt;br /&gt;
====Please help us to make ZAP even better for you by answering the [https://docs.google.com/forms/d/1-k-vcj_sSxlil6XLxCFade-m-IQVeE2h9gduA-2ZPPA/viewform ZAP User Questionnaire]!====&lt;br /&gt;
&lt;br /&gt;
For a quick overview of ZAP and an introduction to the [https://wiki.jenkins-ci.org/display/JENKINS/zap+plugin official ZAP Jenkins plugin] see these tutorial videos on YouTube:&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
{{#ev:youtube|eH0RBI0nmww}}&amp;amp;nbsp;&lt;br /&gt;
{{#ev:youtube|mmHZLSffCUg}}&amp;amp;nbsp;&lt;br /&gt;
{{#ev:youtube|ztfgip-UhWw}}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
For more videos see the links on the [https://github.com/zaproxy/zaproxy/wiki/Videos wiki videos page].&lt;br /&gt;
&lt;br /&gt;
Interested in a ZAP talk or training event? See the [https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project#tab=Talks talks] tab. Not one near you? Contact a [https://github.com/zaproxy/zaproxy/wiki/ZapEvangelists Zap Evangelist] to arrange one!&lt;br /&gt;
&lt;br /&gt;
{{#widget:PayPal Donation&lt;br /&gt;
|target=_blank&lt;br /&gt;
|budget=Zed Attack Proxy&lt;br /&gt;
}}  &lt;br /&gt;
&lt;br /&gt;
For general information about ZAP:&lt;br /&gt;
* [https://twitter.com/zaproxy Twitter] - official ZAP announcements (low volume)&lt;br /&gt;
* [https://zaproxy.blogspot.co.uk/ Blog] - official ZAP blog&lt;br /&gt;
&lt;br /&gt;
For help using ZAP:&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/releases/download/2.6.0/ZAPGettingStartedGuide-2.6.pdf Getting Started Guide (pdf)] - an introductory guide you can print&lt;br /&gt;
* [https://www.youtube.com/playlist?list=PLEBitBW-Hlsv8cEIUntAO8st2UGhmrjUB Tutorial Videos]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki User Guide] - online version of the User Guide included with ZAP&lt;br /&gt;
* [https://groups.google.com/group/zaproxy-users User Group] - ask questions about using ZAP&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/wiki Add-ons] - help for the optional add-ons you can install&lt;br /&gt;
* [https://stackoverflow.com/questions/tagged/zap StackOverflow] - because some people use this for all everything ;)&lt;br /&gt;
&lt;br /&gt;
To learn more about ZAP development:&lt;br /&gt;
* [https://github.com/zaproxy Source Code] - for all of the ZAP related projects&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/wiki/Introduction Wiki] - lots of detailed info&lt;br /&gt;
* [https://groups.google.com/group/zaproxy-develop Developer Group] - ask questions about the ZAP internals&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap Crowdin (GUI)] - help translate the ZAP GUI&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap-help Crowdin (User Guide)] - help translate the ZAP User Guide&lt;br /&gt;
* [https://www.openhub.net/p/zaproxy OpenHub]	- FOSS analytics&lt;br /&gt;
* [https://www.bountysource.com/teams/zap/issues BountySource] - Vote on ZAP issues (you can also donate money here, but 10% taken out)&lt;br /&gt;
&lt;br /&gt;
===Justification===&lt;br /&gt;
Justification for the statements made in the tagline at the top;)&lt;br /&gt;
&lt;br /&gt;
Popularity:&lt;br /&gt;
* ToolsWatch Annual Best Free/Open Source Security Tool Survey:&lt;br /&gt;
** 2016 [http://www.toolswatch.org/2017/02/2016-top-security-tools-as-voted-by-toolswatch-org-readers/ 2nd]&lt;br /&gt;
** 2015 [http://www.toolswatch.org/2016/02/2015-top-security-tools-as-voted-by-toolswatch-org-readers/ 1st]&lt;br /&gt;
** 2014 [http://www.toolswatch.org/2015/01/2014-top-security-tools-as-voted-by-toolswatch-org-readers/ 2nd]&lt;br /&gt;
** 2013 [http://www.toolswatch.org/2013/12/2013-top-security-tools-as-voted-by-toolswatch-org-readers/ 1st]&lt;br /&gt;
&lt;br /&gt;
Contributors:&lt;br /&gt;
* [https://www.openhub.net/p/zaproxy Code Contributors]&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap ZAP core i18n Contributors]&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap-help ZAP help i18n Contributors]&lt;br /&gt;
&lt;br /&gt;
{{Social Media Links}}&lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;padding-left:25px;width:200px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
[https://github.com/zaproxy/zaproxy/wiki/Downloads Download OWASP ZAP!]&lt;br /&gt;
&lt;br /&gt;
== Donate to ZAP ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div class=&amp;quot;center&amp;quot; style=&amp;quot;width: auto; margin-left: auto; margin-right: auto;&amp;quot;&amp;gt;{{#widget:PayPal Donation&lt;br /&gt;
|target=_blank&lt;br /&gt;
|budget=Zed Attack Proxy }}&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
Please see the [https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project#News News] and [https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project#Talks Talks] tabs&lt;br /&gt;
&lt;br /&gt;
== Change Log ==&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/commits/develop zaproxy]&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/commits/master zap-extensions]&lt;br /&gt;
&lt;br /&gt;
== Code Repo ==&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/ zaproxy]&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/ zap-extensions]&lt;br /&gt;
&lt;br /&gt;
== Email List ==&lt;br /&gt;
&lt;br /&gt;
Questions? Please ask on the [http://groups.google.com/group/zaproxy-users ZAP User Group]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
Project Leader&amp;lt;br /&amp;gt;[https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @]&lt;br /&gt;
&lt;br /&gt;
Co-Project Leaders&amp;lt;br /&amp;gt;[https://www.owasp.org/index.php/User:Ricardo.Pereira Ricardo Pereira] [mailto:ricardo.pereira@owasp.org @]&lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/index.php/User:Rick.mitchell Rick Mitchell] [mailto:rick.mitchell+wiki@owasp.org @]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_Web_Testing_Environment_Project OWASP WTE]&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_OWTF OWASP OWTF]&lt;br /&gt;
&lt;br /&gt;
== Open Hub Stats ==&lt;br /&gt;
&lt;br /&gt;
*https://www.openhub.net/p/zaproxy&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| cellpadding=&amp;quot;2&amp;quot; width=&amp;quot;200&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; | [[File:Mature projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Flagship_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; width=&amp;quot;50%&amp;quot; valign=&amp;quot;center&amp;quot; | [[File:Owasp-builders-small.png|link=]]&lt;br /&gt;
   |&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; width=&amp;quot;50%&amp;quot; valign=&amp;quot;center&amp;quot; | [[File:Owasp-breakers-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [http://www.apache.org/licenses/LICENSE-2.0 Apache 2 License]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_TOOL.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Screenshots =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotAddAlert.png|||400px|ZAP Add Alert Screen Shot]] &lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotHelp.png||400px|left|ZAP Help Screen Shot]]&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotHistoryFilter.png|thumb|400px|left|ZAP History Filter Screen Shot]]&lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotSearchTab.png|thumb|400px|left|ZAP Search Tab Screen Shot]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Talks =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
{{:Projects/OWASP Zed Attack Proxy Project/Pages/Talks | Talks}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
= News =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
{{:Projects/OWASP Zed Attack Proxy Project/Pages/News | News}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
= ZAP Gear =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Yes, you can now buy ZAP related gear!&lt;br /&gt;
&lt;br /&gt;
All of the artwork for ZAP swag is released under the Creative Common License and can be downloaded from the [https://github.com/zaproxy/zap-swag zap-swag] repo.&lt;br /&gt;
&lt;br /&gt;
You can of course use the artwork from this repo with any other online store that you like.&lt;br /&gt;
&lt;br /&gt;
A range of products can be purchased from [http://www.redbubble.com/people/zaproxy Redbubble]&lt;br /&gt;
&lt;br /&gt;
Stickers can be purchased from [https://www.stickermule.com/uk/user/1070684077/stickers Stickermule]&lt;br /&gt;
&lt;br /&gt;
T-shirts can be purchased from [http://www.cafepress.com/zaproxy Cafepress]&lt;br /&gt;
&lt;br /&gt;
[[Image:zap-tshirt-cp.PNG | link=http://www.cafepress.com/zaproxy]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Supporters =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
ZAP is developed by a worldwide [https://github.com/zaproxy/zap-core-help/wiki/HelpCredits team] of volunteers.&lt;br /&gt;
&lt;br /&gt;
But we have also been helped by many organizations, either financially or by encouraging their employees to work on ZAP:&lt;br /&gt;
&lt;br /&gt;
* [http://www.mozilla.org Mozilla]&lt;br /&gt;
* [http://www.linuxfoundation.org/ The Linux Foundation]&lt;br /&gt;
* [https://segment.com/ Segment]&lt;br /&gt;
* [http://www.owasp.org OWASP]&lt;br /&gt;
* [http://www.sage.co.uk Sage]&lt;br /&gt;
* [http://www.google.com Google]&lt;br /&gt;
* [http://www.microsoft.com Microsoft]&lt;br /&gt;
* [http://www.hacktics.com/ Hacktics, Ernst &amp;amp; Young]&lt;br /&gt;
* [http://www.dinosec.com/ DinoSec]&lt;br /&gt;
* [http://www.denimgroup.com Denim Group]&lt;br /&gt;
* [http://www.aspectsecurity.com/ Aspect Security]&lt;br /&gt;
* [http://secureideas.net SecureIdeas]&lt;br /&gt;
* [http://utilisec.com UtiliSec]&lt;br /&gt;
* [http://www.encription.co.uk/ encription]&lt;br /&gt;
* [https://www.accenture.com/us-en/digital-index.aspx Accenture Digital]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Functionality =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
'''Some of ZAP's functionality:'''&lt;br /&gt;
&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsIntercept Man-in-the-middle Proxy]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsSpider Traditional] and AJAX spiders&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsAscan Automated scanner]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsPscan Passive scanner]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsBruteforce Forced browsing]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsFuzz Fuzzer]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpUiDialogsOptionsDynsslcert Dynamic SSL certificates]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/SmartCards Smartcard and Client Digital Certificates support]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpAddonsWebsocketIntroduction Web sockets] support&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpAddonsScriptsScripts Support for a wide range of scripting languages]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki//HelpAddonsPlugnhackPlugnhack Plug-n-Hack support]&lt;br /&gt;
* Authentication and session support&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsApi Powerful REST based API]&lt;br /&gt;
* Automatic updating option&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/wiki Integrated and growing marketplace of add-ons]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
= Features =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
'''Some of ZAP's features:'''&lt;br /&gt;
&lt;br /&gt;
* [http://www.apache.org/licenses/LICENSE-2.0 Open source]&lt;br /&gt;
* Cross platform (it even runs on a [https://github.com/zaproxy/zaproxy/wiki/zappi Raspberry Pi!])&lt;br /&gt;
* Easy to install (using a [https://www.ej-technologies.com/products/install4j/overview.html multi-platform installer builder])&lt;br /&gt;
* Completely free (no paid for 'Pro' version)&lt;br /&gt;
* Ease of use a priority&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpIntro Comprehensive help pages]&lt;br /&gt;
* Fully internationalized&lt;br /&gt;
* Translated into over 20 languages&lt;br /&gt;
* Community based, with involvement actively encouraged&lt;br /&gt;
* Under active development by an international team of volunteers&lt;br /&gt;
&lt;br /&gt;
ZAP is a fork of the well regarded [http://www.parosproxy.org/ Paros Proxy].&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Languages =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''ZAP supports the following languages:'''&lt;br /&gt;
&lt;br /&gt;
* English&lt;br /&gt;
* Arabic&lt;br /&gt;
* Bosnian&lt;br /&gt;
* Brazilian Portuguese&lt;br /&gt;
* Chinese&lt;br /&gt;
* Danish&lt;br /&gt;
* Filipino&lt;br /&gt;
* French&lt;br /&gt;
* German&lt;br /&gt;
* Greek&lt;br /&gt;
* Hungarian&lt;br /&gt;
* Indonesian&lt;br /&gt;
* Italian&lt;br /&gt;
* Japanese&lt;br /&gt;
* Korean&lt;br /&gt;
* Persian&lt;br /&gt;
* Polish&lt;br /&gt;
* Russian&lt;br /&gt;
* Sinhala&lt;br /&gt;
* Spanish&lt;br /&gt;
* Urdu &lt;br /&gt;
&lt;br /&gt;
You can use [http://crowdin.net/project/owasp-zap Crowdin] to help improve these translations or add new ones right now!&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Release 2.6.0==&lt;br /&gt;
ZAP 2.6.0 has been released, this is a bug fix and enhancement release&lt;br /&gt;
&lt;br /&gt;
For more details see https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_6_0&lt;br /&gt;
&lt;br /&gt;
==Release 2.7.0==&lt;br /&gt;
ZAP 2.7.0 has been released (Nov 2017), this is a bug fix and enhancement release&lt;br /&gt;
&lt;br /&gt;
For more details see https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_7_0&lt;br /&gt;
&lt;br /&gt;
It requires Java 8 (minimum) and supports Selenium 3.&lt;br /&gt;
&lt;br /&gt;
==Release 2.8.0==&lt;br /&gt;
ZAP 2.8.0 does not yet have a planned release date, but is likely to be in the first half of 2019.&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Get Involved =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Involvement in the development of ZAP is actively encouraged!&lt;br /&gt;
&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
&lt;br /&gt;
Some of the ways you can help:&lt;br /&gt;
&lt;br /&gt;
==Feature Requests==&lt;br /&gt;
&lt;br /&gt;
Please raise new feature requests as enhancement requests here: https://github.com/zaproxy/zaproxy/issues&lt;br /&gt;
&lt;br /&gt;
If there are existing requests you are also interested in then please 'star' them - that way we can see which features people are most interested in and can prioritize them accordingly. &lt;br /&gt;
&lt;br /&gt;
==Feedback==&lt;br /&gt;
&lt;br /&gt;
Please use the [http://groups.google.com/group/zaproxy-users zaproxy-users Google Group] for feedback:&lt;br /&gt;
* What do like?&lt;br /&gt;
* What don't you like?&lt;br /&gt;
* What features could be made easier to use?&lt;br /&gt;
* How could the help pages be improved? &lt;br /&gt;
&lt;br /&gt;
==Log issues==&lt;br /&gt;
&lt;br /&gt;
Have you had a problem using ZAP?&lt;br /&gt;
&lt;br /&gt;
If so and its not already been logged then please [https://github.com/zaproxy/zaproxy/issues report it]&lt;br /&gt;
&lt;br /&gt;
==Localization==&lt;br /&gt;
&lt;br /&gt;
Are you fluent in another language? Can you help translate ZAP into that language?&lt;br /&gt;
&lt;br /&gt;
You can use [http://crowdin.net/project/owasp-zap Crowdin] to do that!&lt;br /&gt;
&lt;br /&gt;
==Development==&lt;br /&gt;
&lt;br /&gt;
If you fancy having a go at adding functionality to ZAP then please get in touch via the [http://groups.google.com/group/zaproxy-develop zaproxy-develop Google Group].&lt;br /&gt;
&lt;br /&gt;
Again, you do not have to be a security expert to contribute code - working on ZAP could be great way to learn more about web application security!&lt;br /&gt;
&lt;br /&gt;
If you actively contribute to ZAP then you will be invited to join the project. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project|Zed Attack Proxy Project]]&lt;br /&gt;
[[Category:OWASP_Tool]]&lt;br /&gt;
[[Category:OWASP Release Quality Tool|OWASP Release Quality Tool]]&lt;br /&gt;
[[Category:OWASP_Download]]&lt;br /&gt;
[[Category:Popular]]&lt;br /&gt;
[[Category:SAMM-ST-2]]&lt;br /&gt;
[[Category:Flagship Projects|Zap]]&lt;br /&gt;
[[Category:OWASP Zed Attack Proxy|Zap]]&lt;/div&gt;</summary>
		<author><name>Psiinon</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=GoogleSeasonOfDocs2019&amp;diff=248729</id>
		<title>GoogleSeasonOfDocs2019</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=GoogleSeasonOfDocs2019&amp;diff=248729"/>
				<updated>2019-03-13T09:37:20Z</updated>
		
		<summary type="html">&lt;p&gt;Psiinon: Added ZAP Zest project&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Overview =&lt;br /&gt;
&lt;br /&gt;
OWASP is going to apply to participate in the inaugural [https://developers.google.com/season-of-docs/ Google Season of Docs]&lt;br /&gt;
We will be requesting project ideas to help us complete our organization application which is due April 23rd.&lt;br /&gt;
&lt;br /&gt;
= OWASP Project Documentation Requests =&lt;br /&gt;
&lt;br /&gt;
'''Tips to get you started in no particular order:'''  &lt;br /&gt;
 '''* Read [https://developers.google.com/season-of-docs/docs/project-ideas Google Season of Docs Project Ideas]'''&lt;br /&gt;
 '''* Read [https://developers.google.com/season-of-docs/terms/program-rules Program Rules]'''&lt;br /&gt;
&lt;br /&gt;
==OWASP ZAP==&lt;br /&gt;
[[OWASP Zed Attack Proxy Project]] (ZAP) one of the world’s most popular free security tools and is actively maintained by hundreds of international volunteers. Previous GSoC students have implemented key parts of the ZAP core functionality and have been offered (and accepted) jobs based on their work on ZAP.&lt;br /&gt;
&lt;br /&gt;
=== The API ===&lt;br /&gt;
ZAP has an extremely powerful API that allows you to do nearly everything that possible via the desktop interface. It is considered on of ZAPs strengths and is heavily used for automation.&lt;br /&gt;
Unfortunately is also not particularly well documented and we get many queries about it on the support groups.&lt;br /&gt;
&lt;br /&gt;
Existing documentation includes:&lt;br /&gt;
* https://github.com/zaproxy/zaproxy/wiki/ApiDetails&lt;br /&gt;
* https://github.com/zaproxy/zaproxy/wiki/ApiGen_Index&lt;br /&gt;
&lt;br /&gt;
This project would:&lt;br /&gt;
# Explain the concepts behind the UI&lt;br /&gt;
# Explain how it can be used at a high level&lt;br /&gt;
# Detail all of the API calls&lt;br /&gt;
&lt;br /&gt;
The documentation should be suitable for publishing as web pages and for printing on paper.&lt;br /&gt;
&lt;br /&gt;
=== Zest ===&lt;br /&gt;
Zest is an experimental specialized scripting language developed by the ZAP team and is intended to be used in web oriented security tools.&lt;br /&gt;
While it is tool independent it is heavily used by ZAP.&lt;br /&gt;
&lt;br /&gt;
Existing documentation includes:&lt;br /&gt;
* https://developer.mozilla.org/en-US/docs/Mozilla/Projects/Zest&lt;br /&gt;
* https://github.com/mozilla/zest/wiki&lt;br /&gt;
&lt;br /&gt;
This project would:&lt;br /&gt;
# Explain the concepts behind the Zest&lt;br /&gt;
# Explain how to write Zest scripts&lt;br /&gt;
# Document the ZAP Desktop UI provided relating to Zest&lt;br /&gt;
&lt;br /&gt;
The documentation should be suitable for publishing as web pages and ideally the parts relating to the ZAP Desktop UI should be able to be included within the UI as context sensitive help.&lt;/div&gt;</summary>
		<author><name>Psiinon</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=GoogleSeasonOfDocs2019&amp;diff=248662</id>
		<title>GoogleSeasonOfDocs2019</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=GoogleSeasonOfDocs2019&amp;diff=248662"/>
				<updated>2019-03-12T14:03:21Z</updated>
		
		<summary type="html">&lt;p&gt;Psiinon: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Overview =&lt;br /&gt;
&lt;br /&gt;
OWASP is going to apply to participate in the inaugural [https://developers.google.com/season-of-docs/ Google Season of Docs]&lt;br /&gt;
We will be requesting project ideas to help us complete our organization application which is due April 23rd.&lt;br /&gt;
&lt;br /&gt;
= OWASP Project Documentation Requests =&lt;br /&gt;
&lt;br /&gt;
'''Tips to get you started in no particular order:'''  &lt;br /&gt;
 '''* Read [https://developers.google.com/season-of-docs/docs/project-ideas Google Season of Docs Project Ideas]'''&lt;br /&gt;
 '''* Read [https://developers.google.com/season-of-docs/terms/program-rules Program Rules]'''&lt;br /&gt;
&lt;br /&gt;
==OWASP ZAP==&lt;br /&gt;
[[OWASP Zed Attack Proxy Project]] (ZAP) one of the world’s most popular free security tools and is actively maintained by hundreds of international volunteers. Previous GSoC students have implemented key parts of the ZAP core functionality and have been offered (and accepted) jobs based on their work on ZAP.&lt;br /&gt;
&lt;br /&gt;
=== Documenting the API ===&lt;br /&gt;
ZAP has an extremely powerful API that allows you to do nearly everything that possible via the desktop interface. It is considered on of ZAPs strengths and is heavily used for automation.&lt;br /&gt;
Unfortunately is also not particularly well documented and we get many queries about it on the support groups.&lt;br /&gt;
&lt;br /&gt;
Existing documentation includes:&lt;br /&gt;
* https://github.com/zaproxy/zaproxy/wiki/ApiDetails&lt;br /&gt;
* https://github.com/zaproxy/zaproxy/wiki/ApiGen_Index&lt;br /&gt;
&lt;br /&gt;
This project would:&lt;br /&gt;
# Explain the concepts behind the UI&lt;br /&gt;
# Explain how it can be used at a high level&lt;br /&gt;
# Detail all of the API calls&lt;br /&gt;
&lt;br /&gt;
The documentation should be suitable for publishing as web pages and for printing on paper.&lt;/div&gt;</summary>
		<author><name>Psiinon</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=GoogleSeasonOfDocs2019&amp;diff=248661</id>
		<title>GoogleSeasonOfDocs2019</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=GoogleSeasonOfDocs2019&amp;diff=248661"/>
				<updated>2019-03-12T14:01:23Z</updated>
		
		<summary type="html">&lt;p&gt;Psiinon: Updated ZAP API&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Overview =&lt;br /&gt;
&lt;br /&gt;
OWASP is going to apply to participate in the inaugural [https://developers.google.com/season-of-docs/ Google Season of Docs]&lt;br /&gt;
We will be requesting project ideas to help us complete our organization application which is due April 23rd.&lt;br /&gt;
&lt;br /&gt;
= OWASP Project Documentation Requests =&lt;br /&gt;
&lt;br /&gt;
'''Tips to get you started in no particular order:'''  &lt;br /&gt;
 '''* Read [https://developers.google.com/season-of-docs/docs/project-ideas Google Season of Docs Project Ideas]'''&lt;br /&gt;
 '''* Read [https://developers.google.com/season-of-docs/terms/program-rules Program Rules]'''&lt;br /&gt;
&lt;br /&gt;
==OWASP ZAP==&lt;br /&gt;
[[OWASP Zed Attack Proxy Project]] (ZAP) The OWASP Zed Attack Proxy (ZAP) is one of the world’s most popular free security tools and is actively maintained by hundreds of international volunteers. Previous GSoC students have implemented key parts of the ZAP core functionality and have been offered (and accepted) jobs based on their work on ZAP.&lt;br /&gt;
&lt;br /&gt;
=== Documenting the API ===&lt;br /&gt;
ZAP has an extremely powerful API that allows you to do nearly everything that possible via the desktop interface. It is considered on of ZAPs strengths and is heavily used for automation.&lt;br /&gt;
Unfortunately is also not particularly well documented and we get many queries about it on the support groups.&lt;br /&gt;
&lt;br /&gt;
Existing documentation includes:&lt;br /&gt;
* https://github.com/zaproxy/zaproxy/wiki/ApiDetails&lt;br /&gt;
* https://github.com/zaproxy/zaproxy/wiki/ApiGen_Index&lt;br /&gt;
&lt;br /&gt;
This project would:&lt;br /&gt;
# Explain the concepts behind the UI&lt;br /&gt;
# Explain how it can be used at a high level&lt;br /&gt;
# Detail all of the API calls&lt;br /&gt;
&lt;br /&gt;
The documentation should be suitable for publishing as web pages and for printing on paper.&lt;/div&gt;</summary>
		<author><name>Psiinon</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=GoogleSeasonOfDocs2019&amp;diff=248657</id>
		<title>GoogleSeasonOfDocs2019</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=GoogleSeasonOfDocs2019&amp;diff=248657"/>
				<updated>2019-03-12T13:57:12Z</updated>
		
		<summary type="html">&lt;p&gt;Psiinon: Added ZAP API proposal&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Overview =&lt;br /&gt;
&lt;br /&gt;
OWASP is going to apply to participate in the inaugural [https://developers.google.com/season-of-docs/ Google Season of Docs]&lt;br /&gt;
We will be requesting project ideas to help us complete our organization application which is due April 23rd.&lt;br /&gt;
&lt;br /&gt;
= OWASP Project Documentation Requests =&lt;br /&gt;
&lt;br /&gt;
'''Tips to get you started in no particular order:'''  &lt;br /&gt;
 '''* Read [https://developers.google.com/season-of-docs/docs/project-ideas Google Season of Docs Project Ideas]'''&lt;br /&gt;
 '''* Read [https://developers.google.com/season-of-docs/terms/program-rules Program Rules]'''&lt;br /&gt;
&lt;br /&gt;
==OWASP ZAP==&lt;br /&gt;
[[OWASP Zed Attack Proxy Project]] (ZAP) The OWASP Zed Attack Proxy (ZAP) is one of the world’s most popular free security tools and is actively maintained by hundreds of international volunteers. Previous GSoC students have implemented key parts of the ZAP core functionality and have been offered (and accepted) jobs based on their work on ZAP.&lt;br /&gt;
&lt;br /&gt;
=== Documenting the API ===&lt;br /&gt;
ZAP has an extremely powerful API that allows you to do nearly everything that possible via the desktop interface. It is considered on of ZAPs strengths and is heavily used for automation.&lt;br /&gt;
Unfortunately is also not particularly well documented and we get many queries about it on the support groups.&lt;/div&gt;</summary>
		<author><name>Psiinon</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=GSoC2019_Ideas&amp;diff=248552</id>
		<title>GSoC2019 Ideas</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=GSoC2019_Ideas&amp;diff=248552"/>
				<updated>2019-03-08T08:35:37Z</updated>
		
		<summary type="html">&lt;p&gt;Psiinon: Un highlighted the OWASP-SKF titles so they match the other ones&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=OWASP Project Requests=&lt;br /&gt;
&lt;br /&gt;
'''Tips to get you started in no particular order:'''  &lt;br /&gt;
 '''* Read [https://developers.google.com/open-source/gsoc/ Google Summer of Code Program(GSOC)]`'''&lt;br /&gt;
 '''* Read the [[GSoC SAT]] '''&lt;br /&gt;
 * Read the [https://www.owasp.org/index.php/GSoC GSOC Student Guidelines]&lt;br /&gt;
 * Contact us through the mailing list or irc channel.&lt;br /&gt;
 * Check our [https://github.com/OWASP github organization]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==OWASP-SKF==&lt;br /&gt;
&lt;br /&gt;
=== Idea 1 Improving the Machine Learning chatbot: ===&lt;br /&gt;
We want to extend the functionality of SKF Bot. (Security Knowledge Framework Chatbot):&lt;br /&gt;
&lt;br /&gt;
Some improvements or the suggestions which we can do to improve the functionality are:&lt;br /&gt;
&lt;br /&gt;
1.    Create a desktop version of the chatbot. Where people can install the setup file on their local machine.&lt;br /&gt;
&lt;br /&gt;
2.    Create a Plugin or website bot which we can add in the website for better chat experience for the user.&lt;br /&gt;
&lt;br /&gt;
3.    Extend the bots capability to do the google search (using web scraping) for the things which are not available in the database. So, it will have a wider scope of knowledge.&lt;br /&gt;
&lt;br /&gt;
4.    Add basic conversation flow which makes SKF Bot friendly and provides the better user experience. Example: Replies to the general queries like How are you? What is your Name etc?&lt;br /&gt;
&lt;br /&gt;
5.    Extend the bot capability to reply to what security controls should be followed from the ASVS and MASVS or other custom checklists that are present in SKF.&lt;br /&gt;
# Extend the bot to different platforms like Facebook, telegram, slack, Google Assistant etc.&lt;br /&gt;
Existing chatbot implementation is on Gitter. You can test the bot by typing @skfchatbot on Gitter Community.&lt;br /&gt;
&lt;br /&gt;
'''Getting started:'''&lt;br /&gt;
&lt;br /&gt;
·         Get familiar with the architecture and code base of SKF (Security Knowledge Framework)&lt;br /&gt;
&lt;br /&gt;
·         Get a feeling for the high code &amp;amp; test quality bar by inspecting the existing test suites and static code analysis results&lt;br /&gt;
&lt;br /&gt;
·         Get familiar with the CI/CD process based on Travis-CI and several associated 3rd party services&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
&lt;br /&gt;
·         Python 3+, Flask, Coffee Script&lt;br /&gt;
&lt;br /&gt;
'''Mentors and Leaders'''&lt;br /&gt;
&lt;br /&gt;
Glenn ten Cate (Mentor, Project leader)&lt;br /&gt;
&lt;br /&gt;
Riccardo ten Cate (Mentor, Project leader)&lt;br /&gt;
&lt;br /&gt;
Priyanka Jain (Mentor)&lt;br /&gt;
&lt;br /&gt;
=== Idea 2 Improving and building Lab challenges and write-ups: ===&lt;br /&gt;
Build lab examples and write-ups (how to test) for different vulnerabilities over different technology stacks. These challenges are to be delivered in Docker so they can be &lt;br /&gt;
&lt;br /&gt;
easily deployed.&lt;br /&gt;
&lt;br /&gt;
In the current situation the security knowledge framework ultimately presents a list of security controls with correlating knowledge base items that contain a description and &lt;br /&gt;
&lt;br /&gt;
a solution. The new labs are used to give the software developers or application security specialists a more in depth understanding and approach on how to test the &lt;br /&gt;
&lt;br /&gt;
vulnerabilities in their own code.  &lt;br /&gt;
* For example we have now around 20 lab challenges in Docker container build in Python:&lt;br /&gt;
** A Local File Inclusion Docker app example:&lt;br /&gt;
*** https://github.com/blabla1337/skf-labs/tree/master/LFI&lt;br /&gt;
** A write-up example:&lt;br /&gt;
*** https://owasp-skf.gitbook.io/asvs-write-ups/filename-injection&lt;br /&gt;
The images that are pushed to the Github repository are already automatically build and pushed to a docker registry where the SKF users can easily pull the images from to get their&lt;br /&gt;
&lt;br /&gt;
labs running. Of course they can download it and build it themselves from source by pulling the original repository.  &lt;br /&gt;
&lt;br /&gt;
'''Mentors and Leaders'''  &lt;br /&gt;
&lt;br /&gt;
Glenn ten Cate (Mentor, Project leader)&lt;br /&gt;
&lt;br /&gt;
Riccardo ten Cate (Mentor, Project leader)&lt;br /&gt;
&lt;br /&gt;
== OWASP DefectDojo ==&lt;br /&gt;
OWASP DefectDojo is a popular open source vulnerability management tool, used as the backbone for security programs. It is easy to get started with and work on! We welcome volunteers of all experience levels and are happy to provide mentorship.&lt;br /&gt;
&lt;br /&gt;
Option 1: Unit Tests - Difficulty: Easy&lt;br /&gt;
* If you're new to programming, unit tests are short scripts designed to test a specific function of an application.&lt;br /&gt;
* The project needs additional unit tests to ensure that new code functions properly. &lt;br /&gt;
Option 2: Feature Enhancement - Difficulty: Varies&lt;br /&gt;
* The functionality of DefectDojo is constantly expanding.&lt;br /&gt;
* Feature enhancements offer programming challenges for all levels of experience.&lt;br /&gt;
Option 3: Pull Request Review - Difficulty: Moderate - Hard&lt;br /&gt;
* Test pull requests and provide feedback on code.&lt;br /&gt;
&lt;br /&gt;
== OHP (OWASP Honeypot) ==&lt;br /&gt;
&lt;br /&gt;
[[OWASP_Python_Honeypot|OWASP Honeypot]] is an open source software in Python language which designed for creating honeypot and honeynet in an easy and secure way! This project is compatible with Python 2.x and 3.x and tested on Windows, Mac OS X and Linux.&lt;br /&gt;
&lt;br /&gt;
=== Getting Start ===&lt;br /&gt;
&lt;br /&gt;
It's best to start from [https://github.com/zdresearch/OWASP-Honeypot/wiki GitHub wiki page], we are looking forward to adding more modules and optimize the core.&lt;br /&gt;
&lt;br /&gt;
=== Technologies ===&lt;br /&gt;
&lt;br /&gt;
Currently we are using&lt;br /&gt;
&lt;br /&gt;
* Docker&lt;br /&gt;
* Python&lt;br /&gt;
* MongoDB&lt;br /&gt;
* TShark&lt;br /&gt;
* Flask&lt;br /&gt;
* ChartJS&lt;br /&gt;
* And more linux services&lt;br /&gt;
&lt;br /&gt;
=== Expected Results ===&lt;br /&gt;
&lt;br /&gt;
* Zero Bugs: Currently we may have several bugs in different conditions, and it's best to test the all functions and fix them&lt;br /&gt;
* Monitoring: Right now monitoring limited to the connections (send&amp;amp;recieve) and it's best to store and analysis the contents for farther investigations and recognizing incoming attacks.&lt;br /&gt;
* Duplicated codes: codes are complicated and duplicated in engine, should be fixed/clean up&lt;br /&gt;
* New modules: add some creative ICS/Network/Web modules andvulnerable web applications, services and stuff&lt;br /&gt;
* API: update API sync to all features&lt;br /&gt;
* WebUI: Demonstrate and add API on WebUI and Live version with all features&lt;br /&gt;
* WebUI Special Reports: Track the attacks more creative and provide high risk IPs&lt;br /&gt;
* Database: Better database structure, faster and use queue&lt;br /&gt;
* Data analysis: Analysis stored data and attack signatures&lt;br /&gt;
* OWASP Top 10: Preparing useful processed/raw data for OWASP top 10 project&lt;br /&gt;
&lt;br /&gt;
=== Students Requirements ===&lt;br /&gt;
&lt;br /&gt;
* Python&lt;br /&gt;
* Packet Analysis &amp;amp; Tshark &amp;amp; Libpcap&lt;br /&gt;
* Docker&lt;br /&gt;
* Database&lt;br /&gt;
* Web Development Skills&lt;br /&gt;
* Honeypot and Deception knowledge&lt;br /&gt;
&lt;br /&gt;
=== Mentors and Leaders ===&lt;br /&gt;
&lt;br /&gt;
* [mailto:ali.razmjoo@owasp.org Ali Razmjoo] (Mentor &amp;amp; Project Leader)&lt;br /&gt;
* [mailto:ehsan@nezami.me Ehsan Nezami] (Mentor &amp;amp; Project Leader)&lt;br /&gt;
* [mailto:reza.espargham@owasp.org Reza Espargham](Mentor)&lt;br /&gt;
* [mailto:abiusx@owasp.org Abbas Naderi] (Mentor)&lt;br /&gt;
&lt;br /&gt;
== OWASP Juice Shop ==&lt;br /&gt;
&lt;br /&gt;
[[OWASP Juice Shop Project]] is an intentionally insecure webapp for security trainings written entirely in Javascript which encompasses the entire OWASP Top Ten and other severe security flaws. Juice Shop is written in Node.js, Express and Angular. The application contains more than 30 challenges of varying difficulty where the user is supposed to exploit the underlying vulnerabilities. Apart from the hacker and awareness training use case, pentesting proxies or security scanners can use Juice Shop as a &amp;quot;guinea pig&amp;quot;-application to check how well their tools cope with Javascript-heavy application frontends and REST APIs.&lt;br /&gt;
 The best way to get in touch with us is the '''community chat on https://gitter.im/bkimminich/juice-shop&amp;lt;nowiki/&amp;gt;.''' You can also send PMs to the potential mentors (@bkimminich, @J12934 and @CaptainFreak) there if you like!&lt;br /&gt;
&lt;br /&gt;
 To receive early feedback please '''put your proposal on Google Docs and submit it to the OWASP Organization on Google's GSoC page''' in ''Draft Shared'' mode. Please pick '''''juice shop'' as Proposal Tag''' to make them easier to find for us. '''Thank you!'''&lt;br /&gt;
&lt;br /&gt;
=== Feature Pack 2019 ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
Ideas for potential new functionality and &amp;quot;business&amp;quot; features are collected in [https://github.com/bkimminich/juice-shop/issues?q=is%3Aissue+is%3Aopen+label%3Afeature GitHub issues labeled &amp;quot;feature&amp;quot;]. This project could implement a whole bunch of new features one by one and release them over the course of several small releases. This would allow the student to work in a professional Continuous Delivery kind of way while bringing benefit to the Juice Shop over the duration of the project.&lt;br /&gt;
&lt;br /&gt;
''Coming up with good additional ideas for features and new functionality in the proposal could make the difference between being selected or declined as a student for this project!''&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* 5 or more new features or functional enhancements of significant scope for OWASP Juice Shop (not necessarily including corresponding challenges)&lt;br /&gt;
* Each feature comes with full functional unit and integration tests&lt;br /&gt;
* Extending the functional walk-through chapter of the &amp;quot;Pwning OWASP Juice Shop&amp;quot; ebook&lt;br /&gt;
* Code follows existing styleguides and passes all existing quality gates regarding code smells, test coverage etc.&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
* Get familiar with the architecture and code base of the application's rich Javascript frontend and RESTful backend&lt;br /&gt;
* Get a feeling for the high code &amp;amp; test quality bar by inspecting the existing test suites and static code analysis results&lt;br /&gt;
* Get familiar with the CI/CD process based on Travis-CI and several associated 3rd party services&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* Javascript, Unit/Integration testing, experience with (or willingness to learn) Angular and NodeJS/Express, security knowledge is optional.&lt;br /&gt;
&lt;br /&gt;
'''Potential Mentors:'''&lt;br /&gt;
* [[User:Bjoern_Kimminich|Bjoern Kimminich]] - OWASP Juice Shop Project Leader&lt;br /&gt;
* Jannik Hollenbach - OWASP Juice Shop Project Collaborator&lt;br /&gt;
* Shoeb Patel - OWASP Juice Shop Contributor (and former GSoC 2018 Student)&lt;br /&gt;
&lt;br /&gt;
=== Juice Shop Mobile ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
A complete mobile client for Juice-Shop API which will serve a legit mobile experience for Juice-Shop user as well as a plethora of Mobile app vulnerabilities and challenges around them to solve. Should in the best case translate the idea of Juice Shop's hacking challenges with a score board and success notifications into the mobile world.&lt;br /&gt;
&lt;br /&gt;
''Coming up with a sophisticated proposal (optimally even with a good initial sample implementation) could make the difference between being selected or declined as a student for this project!''&lt;br /&gt;
&lt;br /&gt;
''' Getting started '''&lt;br /&gt;
* Get familiar with the architecture and code base of the application's RESTful backend&lt;br /&gt;
* Get familiar with Native App developement&lt;br /&gt;
* Get familiar with Mobile vulnerabilities&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* A mobile App with consistent UI/UX for Juice-Shop with standard client side vulnerabilities.&lt;br /&gt;
* Sufficient initial release quality (en par with Juice Shop and Juice Shop CTF) to make it an official extension project hosted in its own GitHub repository ''bkimminich/juice-shop-mobile''&lt;br /&gt;
* Code follows existing styleguides and applies similar quality gates regarding code smells, test coverage etc. as the main project.&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* Javascript, Unit/Integration testing, experience with (or willingness to learn) React Native and NodeJS/Express, some Mobile security knowledge would be preferable.&lt;br /&gt;
&lt;br /&gt;
'''Potential Mentors:'''&lt;br /&gt;
* [[User:Bjoern_Kimminich|Bjoern Kimminich]] - OWASP Juice Shop Project Leader&lt;br /&gt;
* Jannik Hollenbach - OWASP Juice Shop Project Collaborator&lt;br /&gt;
* Shoeb Patel - OWASP Juice Shop Contributor (and former GSoC 2018 Student)&lt;br /&gt;
&lt;br /&gt;
=== Challenge Pack 2019 ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
Ideas for potential new hacking challenges are collected in [https://github.com/bkimminich/juice-shop/issues?q=is%3Aissue+is%3Aopen+label%3Achallenge GitHub issues labeled &amp;quot;challenge&amp;quot;]. This project could implement a whole bunch of challenges one by one and release them over the course of several small releases. This would allow the student to work in a professional Continuous Delivery kind of way while bringing benefit to the Juice Shop over the duration of the project.&lt;br /&gt;
&lt;br /&gt;
''Coming up with good additional ideas for challenges in the proposal could make the difference between being selected or declined as a student for this project!''&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* 10 or more new challenges for OWASP Juice Shop (including required functional enhancements to place the challenges)&lt;br /&gt;
* Each challenge comes with full functional unit and integration tests&lt;br /&gt;
* Each challenge is verified to be exploitable by corresponding end-to-end tests&lt;br /&gt;
* Hint and solution sections for each new challenge are added to the &amp;quot;Pwning OWASP Juice Shop&amp;quot; ebook&lt;br /&gt;
* Code follows existing styleguides and passes all existing quality gates regarding code smells, test coverage etc.&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
* Get familiar with the architecture and code base of the application's rich Javascript frontend and RESTful backend&lt;br /&gt;
* Get a feeling for the high code &amp;amp; test quality bar by inspecting the existing test suites and static code analysis results&lt;br /&gt;
* Get familiar with the CI/CD process based on Travis-CI and several associated 3rd party services&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* Javascript, Unit/Integration testing, experience with (or willingness to learn) Angular and NodeJS/Express, some security knowledge would be preferable.&lt;br /&gt;
&lt;br /&gt;
'''Potential Mentors:'''&lt;br /&gt;
* [[User:Bjoern_Kimminich|Bjoern Kimminich]] - OWASP Juice Shop Project Leader&lt;br /&gt;
* Jannik Hollenbach - OWASP Juice Shop Project Collaborator&lt;br /&gt;
* Shoeb Patel - OWASP Juice Shop Contributor (and former GSoC 2018 Student)&lt;br /&gt;
&lt;br /&gt;
=== Hacking Instructor ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
While the Juice Shop is offering a lot of long-lasting motivation and challenges for security experts, it might be a bit daunting for newcomers and less experienced hackers.&lt;br /&gt;
The &amp;quot;Hacking Instructor&amp;quot; as sketched in [https://github.com/bkimminich/juice-shop/issues/440 GitHub issue #440] could guide users from this target audience through at least some of the hacking challenges. As this would be an entirely new and relatively independent feature of the Juice Shop, students should be able to bring in their own creativity and ideas a lot.&lt;br /&gt;
&lt;br /&gt;
''For this project, a good proposal with a design &amp;amp; implementation proposal more sophisticated than the rough ideas in [https://github.com/bkimminich/juice-shop/issues/440 #440] is paramount to be selected as a student!''&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* A working implementation of e.g. an avatar-style &amp;quot;Hacking Instructor&amp;quot; or other solution based on the students own proposal&lt;br /&gt;
* Coverage of at least the trivial (1-star) and some easy (2-star) challenges&lt;br /&gt;
* Documentation how to configure or script the &amp;quot;Hacking Instructor&amp;quot; for challenges in general&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
* Get familiar with the architecture and code base of the application's rich Javascript frontend and RESTful backend&lt;br /&gt;
* Get a feeling for the high code &amp;amp; test quality bar by inspecting the existing test suites and static code analysis results&lt;br /&gt;
* Get familiar with the CI/CD process based on Travis-CI and several associated 3rd party services&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* Javascript, Unit/Integration testing, experience with (or willingness to learn) Angular, some UI/UX experience would be preferable.&lt;br /&gt;
&lt;br /&gt;
'''Potential Mentors:'''&lt;br /&gt;
* [[User:Bjoern_Kimminich|Bjoern Kimminich]] - OWASP Juice Shop Project Leader&lt;br /&gt;
* Jannik Hollenbach - OWASP Juice Shop Project Collaborator&lt;br /&gt;
* Shoeb Patel - OWASP Juice Shop Contributor (and former GSoC 2018 Student)&lt;br /&gt;
&lt;br /&gt;
=== Your idea ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
You have an awesome idea to improve OWASP Juice Shop that is not on this list? Great, please submit it!&lt;br /&gt;
&lt;br /&gt;
''' Getting started '''&lt;br /&gt;
* Get in touch with [https://www.owasp.org/index.php/User:Bjoern_Kimminich Bjoern Kimminich]&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* A new feature that makes OWASP Juice Shop even better&lt;br /&gt;
* Code follows existing styleguides and passes all existing quality gates regarding code smells, test coverage etc.&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* Javascript, Unit/Integration testing, experience with (or willingness to learn) Angular and NodeJS/Express, some security knowledge would be preferable.&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' &lt;br /&gt;
* [[User:Bjoern_Kimminich|Bjoern Kimminich]] - OWASP Juice Shop Project Leader&lt;br /&gt;
&lt;br /&gt;
==OWASP-Securetea Tools Project ==&lt;br /&gt;
The purpose of this application is to warn the user (via various communication mechanisms) whenever their laptop accessed. This small application was developed and tested in python in Linux machine is likely to work well on the Raspberry Pi as well. -&lt;br /&gt;
https://github.com/OWASP/SecureTea-Project/blob/master/README.md&lt;br /&gt;
&lt;br /&gt;
===Brief Explanation===&lt;br /&gt;
We are looking any awesome idea to improve Securetea Project that is not on this list? We are expecting make this project will be useful to everyone to secure their Small IoT. &lt;br /&gt;
&lt;br /&gt;
===Idea===&lt;br /&gt;
Below roadmap and expect  results you can choose to improve Securetea Project . &lt;br /&gt;
if any bugs please help to fix it&lt;br /&gt;
&lt;br /&gt;
===Roadmap=== &lt;br /&gt;
See Our Roadmap&amp;lt;br&amp;gt;&lt;br /&gt;
https://github.com/OWASP/SecureTea-Project#roadmap&amp;lt;br&amp;gt;&lt;br /&gt;
Notify by Twitter (done)&amp;lt;br&amp;gt;&lt;br /&gt;
Securetea Dashboard / Gui (done)&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Expect  Results ===&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
Securetea Protection /firewall&amp;lt;br&amp;gt;&lt;br /&gt;
Securetea Antivirus&amp;lt;br&amp;gt;&lt;br /&gt;
Notify by Whatsapp&amp;lt;br&amp;gt;&lt;br /&gt;
Notify by SMS Alerts&amp;lt;br&amp;gt;&lt;br /&gt;
Notify by Line&amp;lt;br&amp;gt;&lt;br /&gt;
Notify by Telegram&amp;lt;br&amp;gt;&lt;br /&gt;
Intelligent Log Monitoring&amp;lt;br&amp;gt;&lt;br /&gt;
Login History&amp;lt;br&amp;gt;&lt;br /&gt;
=== Students Requirements ===&lt;br /&gt;
&lt;br /&gt;
* Python&lt;br /&gt;
* Javascript &lt;br /&gt;
* Angular and NodeJS/Express&lt;br /&gt;
* Database&lt;br /&gt;
* Linux&lt;br /&gt;
&lt;br /&gt;
=== Mentors === &lt;br /&gt;
&lt;br /&gt;
* [mailto:ade.putra@owasp.org Ade Yoseman Putra] - (OWASP Securetea Project Leader) &amp;lt;br&amp;gt;&lt;br /&gt;
* [mailto:rejah.rehim@owasp.org Rejah Rehim.A.A]]- (OWASP Securetea Project Leader)&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==OWASP OWTF==&lt;br /&gt;
'''[https://github.com/owtf/owtf Offensive Web Testing Framework (OWTF)]''' is a project focused on penetration testing efficiency and alignment of security tests to security standards like the OWASP Testing Guide (v3 and v4), the OWASP Top 10, PTES and NIST. Most of the ideas below focus on rewrite of some major components of OWTF to make it more modular. OWTF is moving to a fresh codebase with a fully Docker testing and deployment environment. If you want to get a jumpstart, check out https://github.com/owtf/owtf/tree/new-arch.&lt;br /&gt;
===OWASP OWTF - MiTM proxy interception and replay capabilities===&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
The OWTF man-in-the-middle proxy is written completely in Python (based on the excellent Tornado framework) and was benchmarked to be the fastest MiTM python proxy. However it lacks the useful and much need interception and replay capabilities of mitmproxy (https://github.com/mitmproxy/mitmproxy).&lt;br /&gt;
&lt;br /&gt;
The current implementation of the MiTM proxy serves its purpose very well. Its fast but its not extensible. There are a number of good use cases for being extensible&lt;br /&gt;
*ability to intercept the transactions&lt;br /&gt;
*modify or replay transaction on the fly&lt;br /&gt;
*add additional capabilities to the proxy (such as session marking/changing) without polluting the main proxy code&lt;br /&gt;
Bonus:&lt;br /&gt;
*Design and implement a proxy plugin (middleware) architecture so that the plugins can be defined separately and the user can choose what plugins to include dynamically (from the web interface).&lt;br /&gt;
*Replace the current Requester (based on urllib, urllib2) with a more robust Requester based on the new urllib3 with support for a real headless browser factory. The typical flow when requested for an authenticated browser instance (using PhantomJS)&lt;br /&gt;
&lt;br /&gt;
*The &amp;quot;Requester&amp;quot; module checks if there is any login parameters provided (i.e form-based or script - look at https://github.com/owtf/login-sessions-plugin)&lt;br /&gt;
*Create a browser instance and do the necessary login procedure&lt;br /&gt;
*Handle the browser for the URI&lt;br /&gt;
*When called to close the browser, do a clean logout and kill the browser instance.&lt;br /&gt;
'''Expected results:'''&lt;br /&gt;
*'''IMPORTANT: [http://legacy.python.org/dev/peps/pep-0008/ PEP-8 compliant code] in all modified code and surrounding areas.'''&lt;br /&gt;
*'''IMPORTANT: [https://github.com/7a/owtf/wiki/Contributor%27s-README OWTF contributor README compliant code]'''&lt;br /&gt;
*'''IMPORTANT: [http://sphinx-doc.org/ Sphinx-friendly python comments] [http://owtf.github.io/ptp/_modules/ptp/tools/w3af/parser.html#W3AFXMLParser example Sphinx-friendly python comments here]'''&lt;br /&gt;
*CRITICAL: Excellent reliability&lt;br /&gt;
*Good performance&lt;br /&gt;
*Unit tests / Functional tests&lt;br /&gt;
*Good documentation&lt;br /&gt;
'''Knowledge Prerequisite:''' Python proficiency, some previous exposure to security concepts and penetration testing is welcome but not strictly necessary as long as there is will to learn.&lt;br /&gt;
&lt;br /&gt;
'''OWASP OWTF Mentors:''' Contact: [mailto:Abraham.Aranguren@owasp.org Abraham Aranguren][mailto:viyat.bhalodia@owasp.org Viyat Bhalodia][mailto:bharadwaj.machiraju@gmail.com Bharadwaj Machiraju] OWASP OWTF Project Leaders&lt;br /&gt;
===OWASP OWTF - Web interface enhancements===&lt;br /&gt;
'''Brief explanation:'''&lt;br /&gt;
&lt;br /&gt;
The current web interface is a mixture of Tornado Jinja templates and ReactJS. A complete UI change to a stable ReactJS-based interface should be the deliverable for this project.  Most of the hard part for the change has already been done and added in a separate branch at https://github.com/owtf/owtf/tree/develop.&lt;br /&gt;
&lt;br /&gt;
For background on OWASP OWTF please see: https://www.owasp.org/index.php/OWASP_OWTF&lt;br /&gt;
&lt;br /&gt;
'''Expected results:'''&lt;br /&gt;
*'''IMPORTANT:Clean, maintainable (ES6 compatible and using recommended design patterns) React (JavaScript) code. ([https://github.com/getsentry/zeus/tree/master/webapp This] is a good example!)'''&lt;br /&gt;
*'''IMPORTANT: Thoroughly documented code along with API examples and example future components.'''&lt;br /&gt;
*'''CRITICAL''': Excellent reliability and performance.&lt;br /&gt;
*Unit tests / Functional tests and easy to setup testing environment (preferably automated).&lt;br /&gt;
'''Knowledge Prerequisite:''' Python (reading API source code and endpoints), React.JS (high proficiency) and general JavaScript proficiency.&lt;br /&gt;
&lt;br /&gt;
'''OWASP OWTF Mentors:''' Contact: [mailto:Abraham.Aranguren@owasp.org Abraham Aranguren][mailto:viyat.bhalodia@owasp.org Viyat Bhalodia][mailto:bharadwaj.machiraju@gmail.com Bharadwaj Machiraju] OWASP OWTF Project Leaders&lt;br /&gt;
===OWASP OWTF - New plugin architecture===&lt;br /&gt;
'''Brief explanation:'''&lt;br /&gt;
&lt;br /&gt;
The current plugin system is not very useful and it is painful to browse many plugins. Most of the plugins do have much code and most of is repeated - much refactoring needed there.&lt;br /&gt;
&lt;br /&gt;
This issue is documented in detail at https://github.com/owtf/owtf/issues/905.&lt;br /&gt;
&lt;br /&gt;
For background on OWASP OWTF please see: https://www.owasp.org/index.php/OWASP_OWTF&lt;br /&gt;
&lt;br /&gt;
'''Expected results:'''&lt;br /&gt;
*'''IMPORTANT: [http://legacy.python.org/dev/peps/pep-0008/ PEP-8 compliant code] in all modified code and surrounding areas.'''&lt;br /&gt;
*'''IMPORTANT: [https://github.com/7a/owtf/wiki/Contributor%27s-README OWTF contributor README compliant code]'''&lt;br /&gt;
*'''IMPORTANT: [http://sphinx-doc.org/ Sphinx-friendly python comments] [http://owtf.github.io/ptp/_modules/ptp/tools/w3af/parser.html#W3AFXMLParser example Sphinx-friendly python comments here]'''&lt;br /&gt;
*CRITICAL: Excellent reliability&lt;br /&gt;
*Good performance&lt;br /&gt;
*Unit tests / Functional tests&lt;br /&gt;
*Good documentation&lt;br /&gt;
&lt;br /&gt;
== OWASP iGoat (draft) ==&lt;br /&gt;
'''Idea 1:''' Completing OWASP iGoat documentation at https://docs.igoatapp.com/ and creating demo videos at for OWASP iGoat YouTube channel for learning purpose.&lt;br /&gt;
&lt;br /&gt;
'''Idea 2:''' Adding new challenge pack / CTF for iGoat. It should be one point solution for learning iOS app security&lt;br /&gt;
&lt;br /&gt;
== OWASP Seraphimdroid ==&lt;br /&gt;
&lt;br /&gt;
=== Idea 1: Anomaly detection of device state ===&lt;br /&gt;
The idea is that certain features of a device would be constantly monitored (battery use, internet usage, opp calls, etc.). Initially, the usual behaviour of the device would be learned. Later, anomalies normal behavior would be reported to the user. This should involve some explanations, such as which applications are causing an anomaly the device behaviors &lt;br /&gt;
&lt;br /&gt;
=== Idea 2: On device machine learning of maliciousness of an app ===&lt;br /&gt;
Tensor-flow for on-device processing and some other libraries have been released that enable machine learning. We have previously applied a system, that based on permissions, is able to distinguish malicious apps from non-malicious. Now, we would like to learn also from other outputs and things one can monitor about application whether it can be malicious. &lt;br /&gt;
&lt;br /&gt;
=== Idea 3:  Enhansing privacy features ===&lt;br /&gt;
The vision of Seraphimdroid is to be aware of privacy threats. This may be achieved throug knowing which applications are using user accounts or other information that user has on phone to send to the server, or just by knowing which applications may be doing it. Knowledge base should be extending with the suggestions on how to improve privacy. Also, automated settings of various apps to use encryption should be proposed.&lt;br /&gt;
==OWASP ZAP==&lt;br /&gt;
[[OWASP Zed Attack Proxy Project]] (ZAP) The OWASP Zed Attack Proxy (ZAP) is one of the world’s most popular free security tools and is actively maintained by hundreds of international volunteers. Previous GSoC students have implemented key parts of the ZAP core functionality and have been offered (and accepted) jobs based on their work on ZAP.&lt;br /&gt;
&lt;br /&gt;
=== Active Scanning WebSockets ===&lt;br /&gt;
: '''Brief Explanation:'''&lt;br /&gt;
: ZAP has good support for websockets, and allows them to be intercepted, changed and fuzzed. Unfortunately it doesn't currently support active scanning (automated attacking) of websocket traffic (messages).&lt;br /&gt;
: We would like to add active scanning support to websockets, ideally in a generic way which would allow us to reuse as many of our existing rules as are relevant. Adding additional websocket specific attacks would also be very useful.&lt;br /&gt;
: This project will be a continuation of the work that was started as part of last year's GSoC.&lt;br /&gt;
: '''Expected Results:'''&lt;br /&gt;
:* An pluggable infrastructure that allows us to active scan websockets&lt;br /&gt;
:* Converting the relevant existing scan rules to work with websockets&lt;br /&gt;
:* Implementing new websocket specific scan rules&lt;br /&gt;
: '''Getting Started:''' &lt;br /&gt;
:* Have a look at the ZAP [https://github.com/zaproxy/zaproxy/blob/develop/CONTRIBUTING.md CONTRIBUTING.md] file, especially the 'Coding' section.&lt;br /&gt;
:* We like to see students who have already contributed to ZAP, so try fixing one of the bugs flagged as [https://github.com/zaproxy/zaproxy/issues?q=is%3Aopen+is%3Aissue+label%3AIdealFirstBug IdealFirstBug].&lt;br /&gt;
: '''Knowledge Prerequisites:'''&lt;br /&gt;
:* ZAP is written in Java, so a good knowledge of this language is recommended. Some knowledge of application security would be useful, but not essential.&lt;br /&gt;
: '''Mentors:''' [https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @] and the rest of the ZAP Core Team&lt;br /&gt;
&lt;br /&gt;
=== Automated Authentication Detection and Configuration ===&lt;br /&gt;
: '''Brief Explanation:'''&lt;br /&gt;
: Currently a user must manually configure ZAP to handle authentication, eg as per &amp;lt;nowiki&amp;gt;https://github.com/zaproxy/zaproxy/wiki/FAQformauth&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
: This is time consuming and error prone.&lt;br /&gt;
: Ideally ZAP would help detect login and registration pages and provide more assistance when configuring authentication, ideally being able to completely automate the task for as many sort of webapps as possible.&lt;br /&gt;
: This project will be a continuation of the work that was started as part of last year's GSoC.&lt;br /&gt;
: '''Expected Results:'''&lt;br /&gt;
:* Detect login and registration pages&lt;br /&gt;
:* Provide a wizard to walk users through the process of setting up authentication, with as much assistance as possible&lt;br /&gt;
:* An option to completely automate the authentication process, for as many authentication mechanisms as possible&lt;br /&gt;
: '''Getting Started:''' &lt;br /&gt;
:* Have a look at the ZAP [https://github.com/zaproxy/zaproxy/blob/develop/CONTRIBUTING.md CONTRIBUTING.md] file, especially the 'Coding' section.&lt;br /&gt;
:* We like to see students who have already contributed to ZAP, so try fixing one of the bugs flagged as [https://github.com/zaproxy/zaproxy/issues?q=is%3Aopen+is%3Aissue+label%3AIdealFirstBug IdealFirstBug].&lt;br /&gt;
: '''Knowledge Prerequisites:'''&lt;br /&gt;
:* ZAP is written in Java, so a good knowledge of this language is recommended. Some knowledge of application security would be useful, but not essential.&lt;br /&gt;
: '''Mentors:''' [https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @] and the rest of the ZAP Core Team&lt;br /&gt;
:&lt;br /&gt;
&lt;br /&gt;
== IoT Goat ==&lt;br /&gt;
IoT Goat will be a deliberately insecure firmware based on OpenWrt. The project’s goal is to teach users about the most common vulnerabilities typically found in IoT devices. The vulnerabilities will be based on the [https://www.owasp.org/images/1/1c/OWASP-IoT-Top-10-2018-final.pdf IoT Top 10 2018]. &lt;br /&gt;
&lt;br /&gt;
===Insecure web services/application===&lt;br /&gt;
''' Getting started '''&lt;br /&gt;
* [https://github.com/scriptingxss/IoTGoat/blob/master/README.md Get familiar with OpenWrt]&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* Web services deployed in OpenWRT containing critical vulnerabilities showcasing the traditional IoT problems. It must contain the following vulnerabilities to be used with the IoT testing guide: SQL injection, local inclusion and XXE injection (I1), Insufficient Authentication (I2), transfer sensitive information using insecure channels (I4).&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* OpenWRT&lt;br /&gt;
* Web security&lt;br /&gt;
* Embedded Security&lt;br /&gt;
&lt;br /&gt;
'''Potential Mentors:'''&lt;br /&gt;
* Aaron Guzman - OWASP IoT Goat Contributor (Project leader of the IoT and Embedded AppSec project)&lt;br /&gt;
* Fotios Chantzis - OWASP IoT Goat Contributor (and former GSoC Student/GSoc Mentor)&lt;br /&gt;
* [[User:Calderpwn|Paulino Calderon]] - OWASP IoT Goat Contributor (and former GSoC 2011 Student/GSoc Mentor in 2015 and 2017)&lt;br /&gt;
&lt;br /&gt;
===Insecure services===&lt;br /&gt;
''' Getting started '''&lt;br /&gt;
* [https://github.com/scriptingxss/IoTGoat/blob/master/README.md Get familiar with OpenWrt]&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* Create/Install/Document network services with security vulnerabilities and insecure configurations that can be abused during the challenges.&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* OpenWRT&lt;br /&gt;
* Network security&lt;br /&gt;
&lt;br /&gt;
'''Potential Mentors:'''&lt;br /&gt;
* Aaron Guzman - OWASP IoT Goat Contributor (Project leader of the IoT and Embedded AppSec project)&lt;br /&gt;
* Fotios Chantzis - OWASP IoT Goat Contributor (and former GSoC Student/GSoc Mentor)&lt;br /&gt;
* [[User:Calderpwn|Paulino Calderon]] - OWASP IoT Goat Contributor (and former GSoC 2011 Student/GSoc Mentor in 2015 and 2017)&lt;br /&gt;
&lt;br /&gt;
===Insecure web services/application===&lt;br /&gt;
''' Getting started '''&lt;br /&gt;
* [https://github.com/scriptingxss/IoTGoat/blob/master/README.md Get familiar with OpenWrt]&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* Web services deployed in OpenWRT containing critical vulnerabilities showcasing the traditional IoT problems. It must contain the following vulnerabilities to be used with the IoT testing guide: SQL injection, local inclusion and XXE injection (I1), Insufficient Authentication (I2), transfer sensitive information using insecure channels (I4).&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* OpenWRT&lt;br /&gt;
* Web security&lt;br /&gt;
&lt;br /&gt;
'''Potential Mentors:'''&lt;br /&gt;
* Aaron Guzman - OWASP IoT Goat Contributor (Project leader of the IoT and Embedded AppSec project)&lt;br /&gt;
* Fotios Chantzis - OWASP IoT Goat Contributor (and former GSoC Student/GSoc Mentor)&lt;br /&gt;
* [[User:Calderpwn|Paulino Calderon]] - OWASP IoT Goat Contributor (and former GSoC 2011 Student/GSoc Mentor in 2015 and 2017)&lt;br /&gt;
&lt;br /&gt;
===Insecure Android/iOS application===&lt;br /&gt;
''' Getting started '''&lt;br /&gt;
* [https://github.com/scriptingxss/IoTGoat/blob/master/README.md Get familiar with OpenWrt]&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* .Android application containing client and server side vulnerabilities covering the OWASP TOP 10 Mobile Risks.&lt;br /&gt;
* iOS application containing client and server side vulnerabilities covering the OWASP TOP 10 Mobile Risks.&lt;br /&gt;
* Web Services deployed as a service in OpenWrt to be used by the Android/iOS clients.&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* OpenWRT&lt;br /&gt;
* Mobile security knowledge.&lt;br /&gt;
* Mobile/Web development knowledge.&lt;br /&gt;
&lt;br /&gt;
'''Potential Mentors:'''&lt;br /&gt;
* Aaron Guzman - OWASP IoT Goat Contributor (Project leader of the IoT and Embedded AppSec project)&lt;br /&gt;
* Fotios Chantzis - OWASP IoT Goat Contributor (and former GSoC Student/GSoc Mentor)&lt;br /&gt;
* [[User:Calderpwn|Paulino Calderon]] - OWASP IoT Goat Contributor (and former GSoC 2011 Student/GSoc Mentor in 2015 and 2017)&lt;/div&gt;</summary>
		<author><name>Psiinon</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=GSoC2019_Ideas&amp;diff=247088</id>
		<title>GSoC2019 Ideas</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=GSoC2019_Ideas&amp;diff=247088"/>
				<updated>2019-02-04T14:07:24Z</updated>
		
		<summary type="html">&lt;p&gt;Psiinon: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=OWASP Project Requests=&lt;br /&gt;
&lt;br /&gt;
'''Tips to get you started in no particular order:'''  &lt;br /&gt;
 '''* Read [https://developers.google.com/open-source/gsoc/ Google Summer of Code Program(GSOC)]`'''&lt;br /&gt;
 '''* Read the [[GSoC SAT]] '''&lt;br /&gt;
 * Read the [https://www.owasp.org/index.php/GSoC GSOC Student Guidelines]&lt;br /&gt;
 * Contact us through the mailing list or irc channel.&lt;br /&gt;
 * Check our [https://github.com/OWASP github organization]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==OWASP-SKF (draft)==&lt;br /&gt;
Idea 1: &lt;br /&gt;
&lt;br /&gt;
Build lab examples and write-ups (how to test) for different vulnerabilities over different technology stacks. These challenges are to be delivered in Docker so they can be &lt;br /&gt;
&lt;br /&gt;
easily deployed.&lt;br /&gt;
&lt;br /&gt;
In the current situation the security knowledge framework ultimately presents a list of security controls with correlating knowledge base items that contain a description and &lt;br /&gt;
&lt;br /&gt;
a solution. The new labs are used to give the software developers or application security specialists a more in depth understanding and approach on how to test the &lt;br /&gt;
&lt;br /&gt;
vulnerabilities in their own code.  &lt;br /&gt;
* For example we have now around 20 lab challenges in Docker container build in Python:&lt;br /&gt;
** A Local File Inclusion Docker app example:&lt;br /&gt;
*** https://github.com/blabla1337/skf-labs/tree/master/LFI&lt;br /&gt;
** A write-up example:&lt;br /&gt;
*** https://owasp-skf.gitbook.io/asvs-write-ups/filename-injection&lt;br /&gt;
The images that are pushed to the Github repository are already automatically build and pushed to a docker registry where the SKF users can easily pull the images from to get their&lt;br /&gt;
&lt;br /&gt;
labs running. Of course they can download it and build it themselves from source by pulling the original repository.  &lt;br /&gt;
&lt;br /&gt;
Idea 2: &lt;br /&gt;
&lt;br /&gt;
We want to extend the Machine learning chatbot functionality in SKF.&lt;br /&gt;
* Create a desktop version of the chatbot. Where people can install the setup file on their local machine.&lt;br /&gt;
* Extend the bots capability to do the google search(using web scraping) for the things which are not available in the database. So, it will have a wider scope of knowledge.&lt;br /&gt;
* Extend the bot capability to reply what security controls should be followed from the ASVS and MASVS or other custom checklists that are present in SKF.&lt;br /&gt;
* Extend the bot to different platforms like Facebook, telegram, slack etc.&lt;br /&gt;
** Now the working chatbot implementation for example is only for Gitter&lt;br /&gt;
&lt;br /&gt;
== OWASP DefectDojo ==&lt;br /&gt;
OWASP DefectDojo is a popular open source vulnerability management tool, used as the backbone for security programs. It is easy to get started with and work on! We welcome volunteers of all experience levels and are happy to provide mentorship.&lt;br /&gt;
&lt;br /&gt;
Option 1: Unit Tests - Difficulty: Easy&lt;br /&gt;
* If you're new to programming, unit tests are short scripts designed to test a specific function of an application.&lt;br /&gt;
* The project needs additional unit tests to ensure that new code functions properly. &lt;br /&gt;
Option 2: Feature Enhancement - Difficulty: Varies&lt;br /&gt;
* The functionality of DefectDojo is constantly expanding.&lt;br /&gt;
* Feature enhancements offer programming challenges for all levels of experience.&lt;br /&gt;
Option 3: Pull Request Review - Difficulty: Moderate - Hard&lt;br /&gt;
* Test pull requests and provide feedback on code.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OHP (OWASP Honeypot) ==&lt;br /&gt;
&lt;br /&gt;
OWASP Honeypot is an open source software in Python language which designed for creating honeypot and honeynet in an easy and secure way! This project is compatible with Python 2.x and 3.x and tested on Windows, Mac OS X and Linux.&lt;br /&gt;
&lt;br /&gt;
=== Getting Start ===&lt;br /&gt;
&lt;br /&gt;
It's best to start from [https://github.com/zdresearch/OWASP-Honeypot/wiki GitHub wiki page], we are looking forward to add more modules and optimize the core.&lt;br /&gt;
&lt;br /&gt;
=== Technologies ===&lt;br /&gt;
&lt;br /&gt;
Currently we are using&lt;br /&gt;
&lt;br /&gt;
* Docker&lt;br /&gt;
* Python&lt;br /&gt;
* MongoDB&lt;br /&gt;
* TShark&lt;br /&gt;
* Flask&lt;br /&gt;
* ChartJS&lt;br /&gt;
* And more linux services&lt;br /&gt;
&lt;br /&gt;
=== Expected Results ===&lt;br /&gt;
...&lt;br /&gt;
&lt;br /&gt;
=== Roadmap ===&lt;br /&gt;
&lt;br /&gt;
...&lt;br /&gt;
&lt;br /&gt;
=== Students Requirements ===&lt;br /&gt;
&lt;br /&gt;
* Python&lt;br /&gt;
* Packet Analysis&lt;br /&gt;
* Docker&lt;br /&gt;
* Database&lt;br /&gt;
&lt;br /&gt;
=== Mentors and Leaders ===&lt;br /&gt;
&lt;br /&gt;
* [mailto:ali.razmjoo@owasp.org Ali Razmjoo] (Mentor &amp;amp; Project Leader)&lt;br /&gt;
* [mailto:ehsan@nezami.me Ehsan Nezami] (Mentor &amp;amp; Project Leader)&lt;br /&gt;
* [mailto:reza.espargham@owasp.org Reza Espargham](Mentor)&lt;br /&gt;
* [mailto:abiusx@owasp.org Abbas Naderi] (Mentor)&lt;br /&gt;
&lt;br /&gt;
== OWASP Juice Shop ==&lt;br /&gt;
&lt;br /&gt;
[[OWASP Juice Shop Project]] is an intentionally insecure webapp for security trainings written entirely in Javascript which encompasses the entire OWASP Top Ten and other severe security flaws. Juice Shop is written in Node.js, Express and Angular. The application contains more than 30 challenges of varying difficulty where the user is supposed to exploit the underlying vulnerabilities. Apart from the hacker and awareness training use case, pentesting proxies or security scanners can use Juice Shop as a &amp;quot;guinea pig&amp;quot;-application to check how well their tools cope with Javascript-heavy application frontends and REST APIs.&lt;br /&gt;
 The best way to get in touch with us is the '''community chat on https://gitter.im/bkimminich/juice-shop&amp;lt;nowiki/&amp;gt;.''' You can also send PMs to the potential mentors (@bkimminich, @wurstbrot and @J12934) there if you like!&lt;br /&gt;
&lt;br /&gt;
 To receive early feedback please '''put your proposal on Google Docs and submit it to the OWASP Organization on Google's GSoC page''' in ''Draft Shared'' mode. Please pick '''''juice shop'' as Proposal Tag''' to make them easier to find for us. '''Thank you!'''&lt;br /&gt;
&lt;br /&gt;
=== Challenge Pack 2019 ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
Ideas for potential new hacking challenges are collected in [https://github.com/bkimminich/juice-shop/issues?q=is%3Aissue+is%3Aopen+label%3Achallenge GitHub issues labeled &amp;quot;challenge&amp;quot;]. This project could implement a whole bunch of challenges one by one and release them over the course of several small releases. This would allow the student to work in a professional Continuous Delivery kind of way while bringing benefit to the Juice Shop over the duration of the project.&lt;br /&gt;
&lt;br /&gt;
Coming up with additional ideas for challenges would be part of the project scope, as the list of pre-existing ideas might not be sufficient for a GSoC project.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* 10 or more new challenges for OWASP Juice Shop (including required functional enhancements to place the challenges)&lt;br /&gt;
* Each challenge comes with full functional unit and integration tests&lt;br /&gt;
* Each challenge is verified to be exploitable by corresponding end-to-end tests&lt;br /&gt;
* Hint and solution sections for each new challenge are added to the &amp;quot;Pwning OWASP Juice Shop&amp;quot; ebook&lt;br /&gt;
* Code follows existing styleguides and passes all existing quality gates regarding code smells, test coverage etc.&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
* Get familiar with the architecture and code base of the application's rich Javascript frontend and RESTful backend&lt;br /&gt;
* Get a feeling for the high code &amp;amp; test quality bar by inspecting the existing test suites and static code analysis results&lt;br /&gt;
* Get familiar with the CI/CD process based on Travis-CI and several associated 3rd party services&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* Javascript, Unit/Integration testing, experience with (or willingness to learn) Angular and NodeJS/Express, some security knowledge would be preferable.&lt;br /&gt;
&lt;br /&gt;
'''Mentors:'''&lt;br /&gt;
* [[User:Bjoern_Kimminich|Bjoern Kimminich]] - OWASP Juice Shop Project Leader&lt;br /&gt;
* [[User:Timo Pagel|Timo Pagel]] - OWASP Juice Shop Project Collaborator&lt;br /&gt;
* Jannik Hollenbach - OWASP Juice Shop Project Collaborator&lt;br /&gt;
&lt;br /&gt;
=== Hacking Instructor ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
TODO&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
&lt;br /&gt;
TODO&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
&lt;br /&gt;
TODO&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
&lt;br /&gt;
TODO&lt;br /&gt;
&lt;br /&gt;
'''Mentors:'''&lt;br /&gt;
* [[User:Bjoern_Kimminich|Bjoern Kimminich]] - OWASP Juice Shop Project Leader&lt;br /&gt;
&lt;br /&gt;
=== Your idea ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
You have an awesome idea to improve OWASP Juice Shop that is not on this list? Great, please submit it!&lt;br /&gt;
&lt;br /&gt;
''' Getting started '''&lt;br /&gt;
* Get in touch with [https://www.owasp.org/index.php/User:Bjoern_Kimminich Bjoern Kimminich]&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* A new feature that makes OWASP Juice Shop even better&lt;br /&gt;
* Code follows existing styleguides and passes all existing quality gates regarding code smells, test coverage etc.&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* Javascript, Unit/Integration testing, experience with (or willingness to learn) Angular and NodeJS/Express, some security knowledge would be preferable.&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' &lt;br /&gt;
* [[User:Bjoern_Kimminich|Bjoern Kimminich]] - OWASP Juice Shop Project Leader&lt;br /&gt;
&lt;br /&gt;
==OWASP-Securetea Tools Project ==&lt;br /&gt;
The purpose of this application is to warn the user (via various communication mechanisms) whenever their laptop accessed. This small application was developed and tested in python in Linux machine is likely to work well on the Raspberry Pi as well. -&lt;br /&gt;
https://github.com/OWASP/SecureTea-Project/blob/master/README.md&lt;br /&gt;
&lt;br /&gt;
===Brief Explanation===&lt;br /&gt;
We are looking any awesome idea to improve Securetea Project that is not on this list? We are expecting make this project will be useful to everyone to secure their Small IoT. &lt;br /&gt;
&lt;br /&gt;
===Idea===&lt;br /&gt;
Below roadmap and expect  results you can choose to improve Securetea Project . &lt;br /&gt;
if any bugs please help to fix it&lt;br /&gt;
&lt;br /&gt;
===Roadmap=== &lt;br /&gt;
See Our Roadmap&amp;lt;br&amp;gt;&lt;br /&gt;
https://github.com/OWASP/SecureTea-Project#roadmap&amp;lt;br&amp;gt;&lt;br /&gt;
Notify by Twitter (done)&amp;lt;br&amp;gt;&lt;br /&gt;
Securetea Dashboard / Gui (done)&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Expect  Results ===&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
Securetea Protection /firewall&amp;lt;br&amp;gt;&lt;br /&gt;
Securetea Antivirus&amp;lt;br&amp;gt;&lt;br /&gt;
Notify by Whatsapp&amp;lt;br&amp;gt;&lt;br /&gt;
Notify by SMS Alerts&amp;lt;br&amp;gt;&lt;br /&gt;
Notify by Line&amp;lt;br&amp;gt;&lt;br /&gt;
Notify by Telegram&amp;lt;br&amp;gt;&lt;br /&gt;
Intelligent Log Monitoring&amp;lt;br&amp;gt;&lt;br /&gt;
Login History&amp;lt;br&amp;gt;&lt;br /&gt;
=== Students Requirements ===&lt;br /&gt;
&lt;br /&gt;
* Python&lt;br /&gt;
* Javascript &lt;br /&gt;
* Angular and NodeJS/Express&lt;br /&gt;
* Database&lt;br /&gt;
* Linux&lt;br /&gt;
&lt;br /&gt;
==='''Mentors '''=== &lt;br /&gt;
&lt;br /&gt;
* [mailto:ade.putra@owasp.org Ade Yoseman Putra] - (OWASP Securetea Project Leader) &amp;lt;br&amp;gt;&lt;br /&gt;
* [mailto:rejah.rehim@owasp.org Rejah Rehim.A.A]]- (OWASP Securetea Project Leader)&lt;br /&gt;
* [https://github.com/sananthu Ananthu S] - (Mentor)&lt;br /&gt;
&lt;br /&gt;
==OWASP OWTF==&lt;br /&gt;
'''[https://github.com/owtf/owtf Offensive Web Testing Framework (OWTF)]''' is a project focused on penetration testing efficiency and alignment of security tests to security standards like the OWASP Testing Guide (v3 and v4), the OWASP Top 10, PTES and NIST. Most of the ideas below focus on rewrite of some major components of OWTF to make it more modular. OWTF is moving to a fresh codebase with a fully Docker testing and deployment environment. If you want to get a jumpstart, check out https://github.com/owtf/owtf/tree/new-arch.&lt;br /&gt;
===OWASP OWTF - MiTM proxy interception and replay capabilities===&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
The OWTF man-in-the-middle proxy is written completely in Python (based on the excellent Tornado framework) and was benchmarked to be the fastest MiTM python proxy. However it lacks the useful and much need interception and replay capabilities of mitmproxy (https://github.com/mitmproxy/mitmproxy).&lt;br /&gt;
&lt;br /&gt;
The current implementation of the MiTM proxy serves its purpose very well. Its fast but its not extensible. There are a number of good use cases for being extensible&lt;br /&gt;
*ability to intercept the transactions&lt;br /&gt;
*modify or replay transaction on the fly&lt;br /&gt;
*add additional capabilities to the proxy (such as session marking/changing) without polluting the main proxy code&lt;br /&gt;
Bonus:&lt;br /&gt;
*Design and implement a proxy plugin (middleware) architecture so that the plugins can be defined separately and the user can choose what plugins to include dynamically (from the web interface).&lt;br /&gt;
*Replace the current Requester (based on urllib, urllib2) with a more robust Requester based on the new urllib3 with support for a real headless browser factory. The typical flow when requested for an authenticated browser instance (using PhantomJS)&lt;br /&gt;
&lt;br /&gt;
*The &amp;quot;Requester&amp;quot; module checks if there is any login parameters provided (i.e form-based or script - look at https://github.com/owtf/login-sessions-plugin)&lt;br /&gt;
*Create a browser instance and do the necessary login procedure&lt;br /&gt;
*Handle the browser for the URI&lt;br /&gt;
*When called to close the browser, do a clean logout and kill the browser instance.&lt;br /&gt;
'''Expected results:'''&lt;br /&gt;
*'''IMPORTANT: [http://legacy.python.org/dev/peps/pep-0008/ PEP-8 compliant code] in all modified code and surrounding areas.'''&lt;br /&gt;
*'''IMPORTANT: [https://github.com/7a/owtf/wiki/Contributor%27s-README OWTF contributor README compliant code]'''&lt;br /&gt;
*'''IMPORTANT: [http://sphinx-doc.org/ Sphinx-friendly python comments] [http://owtf.github.io/ptp/_modules/ptp/tools/w3af/parser.html#W3AFXMLParser example Sphinx-friendly python comments here]'''&lt;br /&gt;
*CRITICAL: Excellent reliability&lt;br /&gt;
*Good performance&lt;br /&gt;
*Unit tests / Functional tests&lt;br /&gt;
*Good documentation&lt;br /&gt;
'''Knowledge Prerequisite:''' Python proficiency, some previous exposure to security concepts and penetration testing is welcome but not strictly necessary as long as there is will to learn.&lt;br /&gt;
&lt;br /&gt;
'''OWASP OWTF Mentors:''' Contact: [mailto:Abraham.Aranguren@owasp.org Abraham Aranguren][mailto:viyat.bhalodia@owasp.org Viyat Bhalodia][mailto:bharadwaj.machiraju@gmail.com Bharadwaj Machiraju] OWASP OWTF Project Leaders&lt;br /&gt;
===OWASP OWTF - Web interface enhancements===&lt;br /&gt;
'''Brief explanation:'''&lt;br /&gt;
&lt;br /&gt;
The current web interface is a mixture of Tornado Jinja templates and ReactJS. A complete UI change to a stable ReactJS-based interface should be the deliverable for this project.  Most of the hard part for the change has already been done and added in a separate branch at https://github.com/owtf/owtf/tree/develop.&lt;br /&gt;
&lt;br /&gt;
For background on OWASP OWTF please see: https://www.owasp.org/index.php/OWASP_OWTF&lt;br /&gt;
&lt;br /&gt;
'''Expected results:'''&lt;br /&gt;
*'''IMPORTANT:Clean, maintainable (ES6 compatible and using recommended design patterns) React (JavaScript) code. ([https://github.com/getsentry/zeus/tree/master/webapp This] is a good example!)'''&lt;br /&gt;
*'''IMPORTANT: Thoroughly documented code along with API examples and example future components.'''&lt;br /&gt;
*'''CRITICAL''': Excellent reliability and performance.&lt;br /&gt;
*Unit tests / Functional tests and easy to setup testing environment (preferably automated).&lt;br /&gt;
'''Knowledge Prerequisite:''' Python (reading API source code and endpoints), React.JS (high proficiency) and general JavaScript proficiency.&lt;br /&gt;
&lt;br /&gt;
'''OWASP OWTF Mentors:''' Contact: [mailto:Abraham.Aranguren@owasp.org Abraham Aranguren][mailto:viyat.bhalodia@owasp.org Viyat Bhalodia][mailto:bharadwaj.machiraju@gmail.com Bharadwaj Machiraju] OWASP OWTF Project Leaders&lt;br /&gt;
===OWASP OWTF - New plugin architecture===&lt;br /&gt;
'''Brief explanation:'''&lt;br /&gt;
&lt;br /&gt;
The current plugin system is not very useful and it is painful to browse many plugins. Most of the plugins do have much code and most of is repeated - much refactoring needed there.&lt;br /&gt;
&lt;br /&gt;
This issue is documented in detail at https://github.com/owtf/owtf/issues/905.&lt;br /&gt;
&lt;br /&gt;
For background on OWASP OWTF please see: https://www.owasp.org/index.php/OWASP_OWTF&lt;br /&gt;
&lt;br /&gt;
'''Expected results:'''&lt;br /&gt;
*'''IMPORTANT: [http://legacy.python.org/dev/peps/pep-0008/ PEP-8 compliant code] in all modified code and surrounding areas.'''&lt;br /&gt;
*'''IMPORTANT: [https://github.com/7a/owtf/wiki/Contributor%27s-README OWTF contributor README compliant code]'''&lt;br /&gt;
*'''IMPORTANT: [http://sphinx-doc.org/ Sphinx-friendly python comments] [http://owtf.github.io/ptp/_modules/ptp/tools/w3af/parser.html#W3AFXMLParser example Sphinx-friendly python comments here]'''&lt;br /&gt;
*CRITICAL: Excellent reliability&lt;br /&gt;
*Good performance&lt;br /&gt;
*Unit tests / Functional tests&lt;br /&gt;
*Good documentation&lt;br /&gt;
&lt;br /&gt;
== OWASP iGoat (draft) ==&lt;br /&gt;
'''Idea 1:''' Completing OWASP iGoat documentation at https://docs.igoatapp.com/ and creating demo videos at for OWASP iGoat YouTube channel for learning purpose.&lt;br /&gt;
&lt;br /&gt;
'''Idea 2:''' Adding new challenge pack / CTF for iGoat. It should be one point solution for learning iOS app security&lt;br /&gt;
&lt;br /&gt;
== OWASP Seraphimdroid ==&lt;br /&gt;
&lt;br /&gt;
=== Idea 1: Anomaly detection of device state ===&lt;br /&gt;
The idea is that certain features of a device would be constantly monitored (battery use, internet usage, opp calls, etc.). Initially, the usual behaviour of the device would be learned. Later, anomalies normal behavior would be reported to the user. This should involve some explanations, such as which applications are causing an anomaly the device behaviors &lt;br /&gt;
&lt;br /&gt;
=== Idea 2: On device machine learning of maliciousness of an app ===&lt;br /&gt;
Tensor-flow for on-device processing and some other libraries have been released that enable machine learning. We have previously applied a system, that based on permissions, is able to distinguish malicious apps from non-malicious. Now, we would like to learn also from other outputs and things one can monitor about application whether it can be malicious. &lt;br /&gt;
&lt;br /&gt;
=== Idea 3:  Enhansing privacy features ===&lt;br /&gt;
The vision of Seraphimdroid is to be aware of privacy threats. This may be achieved throug knowing which applications are using user accounts or other information that user has on phone to send to the server, or just by knowing which applications may be doing it. Knowledge base should be extending with the suggestions on how to improve privacy. Also, automated settings of various apps to use encryption should be proposed.&lt;br /&gt;
==OWASP ZAP==&lt;br /&gt;
[[OWASP Zed Attack Proxy Project]] (ZAP) The OWASP Zed Attack Proxy (ZAP) is one of the world’s most popular free security tools and is actively maintained by hundreds of international volunteers. Previous GSoC students have implemented key parts of the ZAP core functionality and have been offered (and accepted) jobs based on their work on ZAP.&lt;br /&gt;
&lt;br /&gt;
=== Active Scanning WebSockets ===&lt;br /&gt;
: '''Brief Explanation:'''&lt;br /&gt;
: ZAP has good support for websockets, and allows them to be intercepted, changed and fuzzed. Unfortunately it doesnt current support active scanning (automated attacking) of websockets.&lt;br /&gt;
: We would like to add active scanning support to websockets, ideally in a generic way which would allow us to reuse as many of our existing rules as are relevant. Adding additional websocket specific attacks would also be very useful.&lt;br /&gt;
: This project will be a continuation of the work that was started as part of last years GSoC.&lt;br /&gt;
: '''Expected Results:'''&lt;br /&gt;
:* An plugable infrastructure that allows us to active scan websockets&lt;br /&gt;
:* Converting the relevant existing scan rules to work with websockets&lt;br /&gt;
:* Implementing new websocket specific scan rules&lt;br /&gt;
: '''Getting started:''' &lt;br /&gt;
:* Have a look at the ZAP [https://github.com/zaproxy/zaproxy/blob/develop/CONTRIBUTING.md CONTRIBUTING.md] file, especially the 'Coding section.&lt;br /&gt;
:* We like to see students who have already contributed to ZAP, so try fixing one of the bugs flagged as [https://github.com/zaproxy/zaproxy/issues?q=is%3Aopen+is%3Aissue+label%3AIdealFirstBug IdealFirstBug].&lt;br /&gt;
: '''Knowledge Prerequisites:'''&lt;br /&gt;
:* ZAP is written in Java, so a good knowledge of this language is recommended. Some knowledge of application security would be useful, but not essential.&lt;br /&gt;
: '''Mentors:''' [https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @] and the rest of the ZAP Core Team&lt;br /&gt;
&lt;br /&gt;
=== Automated authentication detection and configuration ===&lt;br /&gt;
: '''Brief Explanation:'''&lt;br /&gt;
: Currently a user must manually configure ZAP to handle authentication, eg as per &amp;lt;nowiki&amp;gt;https://github.com/zaproxy/zaproxy/wiki/FAQformauth&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
: This is time consuming and error prone.&lt;br /&gt;
: Ideally ZAP would help detect login and registration pages and provide more assistance when configuring authentication, ideally being able to completely automate the task for as many sort of webapps as possible.&lt;br /&gt;
: This project will be a continuation of the work that was started as part of last years GSoC.&lt;br /&gt;
: '''Expected Results:'''&lt;br /&gt;
:* Detect login and registration pages&lt;br /&gt;
:* Provide a wizard to walk users through the process of setting up authentication, with as much assistance as possible&lt;br /&gt;
:* An option to completely automate the authentication process, for as many authentication mechanisms as possible&lt;br /&gt;
: '''Getting started:''' &lt;br /&gt;
:* Have a look at the ZAP [https://github.com/zaproxy/zaproxy/blob/develop/CONTRIBUTING.md CONTRIBUTING.md] file, especially the 'Coding section.&lt;br /&gt;
:* We like to see students who have already contributed to ZAP, so try fixing one of the bugs flagged as [https://github.com/zaproxy/zaproxy/issues?q=is%3Aopen+is%3Aissue+label%3AIdealFirstBug IdealFirstBug].&lt;br /&gt;
: '''Knowledge Prerequisites:'''&lt;br /&gt;
:* ZAP is written in Java, so a good knowledge of this language is recommended. Some knowledge of application security would be useful, but not essential.&lt;br /&gt;
: '''Mentors:''' [https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @] and the rest of the ZAP Core Team&lt;br /&gt;
:&lt;/div&gt;</summary>
		<author><name>Psiinon</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=GSoC2019_Ideas&amp;diff=247087</id>
		<title>GSoC2019 Ideas</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=GSoC2019_Ideas&amp;diff=247087"/>
				<updated>2019-02-04T14:06:28Z</updated>
		
		<summary type="html">&lt;p&gt;Psiinon: Added ZAP projects&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=OWASP Project Requests=&lt;br /&gt;
&lt;br /&gt;
'''Tips to get you started in no particular order:'''  &lt;br /&gt;
 '''* Read [https://developers.google.com/open-source/gsoc/ Google Summer of Code Program(GSOC)]`'''&lt;br /&gt;
 '''* Read the [[GSoC SAT]] '''&lt;br /&gt;
 * Read the [https://www.owasp.org/index.php/GSoC GSOC Student Guidelines]&lt;br /&gt;
 * Contact us through the mailing list or irc channel.&lt;br /&gt;
 * Check our [https://github.com/OWASP github organization]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==OWASP-SKF (draft)==&lt;br /&gt;
Idea 1: &lt;br /&gt;
&lt;br /&gt;
Build lab examples and write-ups (how to test) for different vulnerabilities over different technology stacks. These challenges are to be delivered in Docker so they can be &lt;br /&gt;
&lt;br /&gt;
easily deployed.&lt;br /&gt;
&lt;br /&gt;
In the current situation the security knowledge framework ultimately presents a list of security controls with correlating knowledge base items that contain a description and &lt;br /&gt;
&lt;br /&gt;
a solution. The new labs are used to give the software developers or application security specialists a more in depth understanding and approach on how to test the &lt;br /&gt;
&lt;br /&gt;
vulnerabilities in their own code.  &lt;br /&gt;
* For example we have now around 20 lab challenges in Docker container build in Python:&lt;br /&gt;
** A Local File Inclusion Docker app example:&lt;br /&gt;
*** https://github.com/blabla1337/skf-labs/tree/master/LFI&lt;br /&gt;
** A write-up example:&lt;br /&gt;
*** https://owasp-skf.gitbook.io/asvs-write-ups/filename-injection&lt;br /&gt;
The images that are pushed to the Github repository are already automatically build and pushed to a docker registry where the SKF users can easily pull the images from to get their&lt;br /&gt;
&lt;br /&gt;
labs running. Of course they can download it and build it themselves from source by pulling the original repository.  &lt;br /&gt;
&lt;br /&gt;
Idea 2: &lt;br /&gt;
&lt;br /&gt;
We want to extend the Machine learning chatbot functionality in SKF.&lt;br /&gt;
* Create a desktop version of the chatbot. Where people can install the setup file on their local machine.&lt;br /&gt;
* Extend the bots capability to do the google search(using web scraping) for the things which are not available in the database. So, it will have a wider scope of knowledge.&lt;br /&gt;
* Extend the bot capability to reply what security controls should be followed from the ASVS and MASVS or other custom checklists that are present in SKF.&lt;br /&gt;
* Extend the bot to different platforms like Facebook, telegram, slack etc.&lt;br /&gt;
** Now the working chatbot implementation for example is only for Gitter&lt;br /&gt;
&lt;br /&gt;
== OWASP DefectDojo ==&lt;br /&gt;
OWASP DefectDojo is a popular open source vulnerability management tool, used as the backbone for security programs. It is easy to get started with and work on! We welcome volunteers of all experience levels and are happy to provide mentorship.&lt;br /&gt;
&lt;br /&gt;
Option 1: Unit Tests - Difficulty: Easy&lt;br /&gt;
* If you're new to programming, unit tests are short scripts designed to test a specific function of an application.&lt;br /&gt;
* The project needs additional unit tests to ensure that new code functions properly. &lt;br /&gt;
Option 2: Feature Enhancement - Difficulty: Varies&lt;br /&gt;
* The functionality of DefectDojo is constantly expanding.&lt;br /&gt;
* Feature enhancements offer programming challenges for all levels of experience.&lt;br /&gt;
Option 3: Pull Request Review - Difficulty: Moderate - Hard&lt;br /&gt;
* Test pull requests and provide feedback on code.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OHP (OWASP Honeypot) ==&lt;br /&gt;
&lt;br /&gt;
OWASP Honeypot is an open source software in Python language which designed for creating honeypot and honeynet in an easy and secure way! This project is compatible with Python 2.x and 3.x and tested on Windows, Mac OS X and Linux.&lt;br /&gt;
&lt;br /&gt;
=== Getting Start ===&lt;br /&gt;
&lt;br /&gt;
It's best to start from [https://github.com/zdresearch/OWASP-Honeypot/wiki GitHub wiki page], we are looking forward to add more modules and optimize the core.&lt;br /&gt;
&lt;br /&gt;
=== Technologies ===&lt;br /&gt;
&lt;br /&gt;
Currently we are using&lt;br /&gt;
&lt;br /&gt;
* Docker&lt;br /&gt;
* Python&lt;br /&gt;
* MongoDB&lt;br /&gt;
* TShark&lt;br /&gt;
* Flask&lt;br /&gt;
* ChartJS&lt;br /&gt;
* And more linux services&lt;br /&gt;
&lt;br /&gt;
=== Expected Results ===&lt;br /&gt;
...&lt;br /&gt;
&lt;br /&gt;
=== Roadmap ===&lt;br /&gt;
&lt;br /&gt;
...&lt;br /&gt;
&lt;br /&gt;
=== Students Requirements ===&lt;br /&gt;
&lt;br /&gt;
* Python&lt;br /&gt;
* Packet Analysis&lt;br /&gt;
* Docker&lt;br /&gt;
* Database&lt;br /&gt;
&lt;br /&gt;
=== Mentors and Leaders ===&lt;br /&gt;
&lt;br /&gt;
* [mailto:ali.razmjoo@owasp.org Ali Razmjoo] (Mentor &amp;amp; Project Leader)&lt;br /&gt;
* [mailto:ehsan@nezami.me Ehsan Nezami] (Mentor &amp;amp; Project Leader)&lt;br /&gt;
* [mailto:reza.espargham@owasp.org Reza Espargham](Mentor)&lt;br /&gt;
* [mailto:abiusx@owasp.org Abbas Naderi] (Mentor)&lt;br /&gt;
&lt;br /&gt;
== OWASP Juice Shop ==&lt;br /&gt;
&lt;br /&gt;
[[OWASP Juice Shop Project]] is an intentionally insecure webapp for security trainings written entirely in Javascript which encompasses the entire OWASP Top Ten and other severe security flaws. Juice Shop is written in Node.js, Express and Angular. The application contains more than 30 challenges of varying difficulty where the user is supposed to exploit the underlying vulnerabilities. Apart from the hacker and awareness training use case, pentesting proxies or security scanners can use Juice Shop as a &amp;quot;guinea pig&amp;quot;-application to check how well their tools cope with Javascript-heavy application frontends and REST APIs.&lt;br /&gt;
 The best way to get in touch with us is the '''community chat on https://gitter.im/bkimminich/juice-shop&amp;lt;nowiki/&amp;gt;.''' You can also send PMs to the potential mentors (@bkimminich, @wurstbrot and @J12934) there if you like!&lt;br /&gt;
&lt;br /&gt;
 To receive early feedback please '''put your proposal on Google Docs and submit it to the OWASP Organization on Google's GSoC page''' in ''Draft Shared'' mode. Please pick '''''juice shop'' as Proposal Tag''' to make them easier to find for us. '''Thank you!'''&lt;br /&gt;
&lt;br /&gt;
=== Challenge Pack 2019 ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
Ideas for potential new hacking challenges are collected in [https://github.com/bkimminich/juice-shop/issues?q=is%3Aissue+is%3Aopen+label%3Achallenge GitHub issues labeled &amp;quot;challenge&amp;quot;]. This project could implement a whole bunch of challenges one by one and release them over the course of several small releases. This would allow the student to work in a professional Continuous Delivery kind of way while bringing benefit to the Juice Shop over the duration of the project.&lt;br /&gt;
&lt;br /&gt;
Coming up with additional ideas for challenges would be part of the project scope, as the list of pre-existing ideas might not be sufficient for a GSoC project.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* 10 or more new challenges for OWASP Juice Shop (including required functional enhancements to place the challenges)&lt;br /&gt;
* Each challenge comes with full functional unit and integration tests&lt;br /&gt;
* Each challenge is verified to be exploitable by corresponding end-to-end tests&lt;br /&gt;
* Hint and solution sections for each new challenge are added to the &amp;quot;Pwning OWASP Juice Shop&amp;quot; ebook&lt;br /&gt;
* Code follows existing styleguides and passes all existing quality gates regarding code smells, test coverage etc.&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
* Get familiar with the architecture and code base of the application's rich Javascript frontend and RESTful backend&lt;br /&gt;
* Get a feeling for the high code &amp;amp; test quality bar by inspecting the existing test suites and static code analysis results&lt;br /&gt;
* Get familiar with the CI/CD process based on Travis-CI and several associated 3rd party services&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* Javascript, Unit/Integration testing, experience with (or willingness to learn) Angular and NodeJS/Express, some security knowledge would be preferable.&lt;br /&gt;
&lt;br /&gt;
'''Mentors:'''&lt;br /&gt;
* [[User:Bjoern_Kimminich|Bjoern Kimminich]] - OWASP Juice Shop Project Leader&lt;br /&gt;
* [[User:Timo Pagel|Timo Pagel]] - OWASP Juice Shop Project Collaborator&lt;br /&gt;
* Jannik Hollenbach - OWASP Juice Shop Project Collaborator&lt;br /&gt;
&lt;br /&gt;
=== Hacking Instructor ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
TODO&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
&lt;br /&gt;
TODO&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
&lt;br /&gt;
TODO&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
&lt;br /&gt;
TODO&lt;br /&gt;
&lt;br /&gt;
'''Mentors:'''&lt;br /&gt;
* [[User:Bjoern_Kimminich|Bjoern Kimminich]] - OWASP Juice Shop Project Leader&lt;br /&gt;
&lt;br /&gt;
=== Your idea ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
You have an awesome idea to improve OWASP Juice Shop that is not on this list? Great, please submit it!&lt;br /&gt;
&lt;br /&gt;
''' Getting started '''&lt;br /&gt;
* Get in touch with [https://www.owasp.org/index.php/User:Bjoern_Kimminich Bjoern Kimminich]&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* A new feature that makes OWASP Juice Shop even better&lt;br /&gt;
* Code follows existing styleguides and passes all existing quality gates regarding code smells, test coverage etc.&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* Javascript, Unit/Integration testing, experience with (or willingness to learn) Angular and NodeJS/Express, some security knowledge would be preferable.&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' &lt;br /&gt;
* [[User:Bjoern_Kimminich|Bjoern Kimminich]] - OWASP Juice Shop Project Leader&lt;br /&gt;
&lt;br /&gt;
==OWASP-Securetea Tools Project ==&lt;br /&gt;
The purpose of this application is to warn the user (via various communication mechanisms) whenever their laptop accessed. This small application was developed and tested in python in Linux machine is likely to work well on the Raspberry Pi as well. -&lt;br /&gt;
https://github.com/OWASP/SecureTea-Project/blob/master/README.md&lt;br /&gt;
&lt;br /&gt;
===Brief Explanation===&lt;br /&gt;
We are looking any awesome idea to improve Securetea Project that is not on this list? We are expecting make this project will be useful to everyone to secure their Small IoT. &lt;br /&gt;
&lt;br /&gt;
===Idea===&lt;br /&gt;
Below roadmap and expect  results you can choose to improve Securetea Project . &lt;br /&gt;
if any bugs please help to fix it&lt;br /&gt;
&lt;br /&gt;
===Roadmap=== &lt;br /&gt;
See Our Roadmap&amp;lt;br&amp;gt;&lt;br /&gt;
https://github.com/OWASP/SecureTea-Project#roadmap&amp;lt;br&amp;gt;&lt;br /&gt;
Notify by Twitter (done)&amp;lt;br&amp;gt;&lt;br /&gt;
Securetea Dashboard / Gui (done)&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Expect  Results ===&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
Securetea Protection /firewall&amp;lt;br&amp;gt;&lt;br /&gt;
Securetea Antivirus&amp;lt;br&amp;gt;&lt;br /&gt;
Notify by Whatsapp&amp;lt;br&amp;gt;&lt;br /&gt;
Notify by SMS Alerts&amp;lt;br&amp;gt;&lt;br /&gt;
Notify by Line&amp;lt;br&amp;gt;&lt;br /&gt;
Notify by Telegram&amp;lt;br&amp;gt;&lt;br /&gt;
Intelligent Log Monitoring&amp;lt;br&amp;gt;&lt;br /&gt;
Login History&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Students Requirements ===&lt;br /&gt;
&lt;br /&gt;
* Python&lt;br /&gt;
* Javascript &lt;br /&gt;
* Angular and NodeJS/Express&lt;br /&gt;
* Database&lt;br /&gt;
* Linux&lt;br /&gt;
&lt;br /&gt;
==='''Mentors '''=== &lt;br /&gt;
&lt;br /&gt;
* [mailto:ade.putra@owasp.org Ade Yoseman Putra] - (OWASP Securetea Project Leader) &amp;lt;br&amp;gt;&lt;br /&gt;
* [mailto:rejah.rehim@owasp.org Rejah Rehim.A.A]]- (OWASP Securetea Project Leader)&lt;br /&gt;
* [https://github.com/sananthu Ananthu S] - (Mentor)&lt;br /&gt;
&lt;br /&gt;
==OWASP OWTF==&lt;br /&gt;
'''[https://github.com/owtf/owtf Offensive Web Testing Framework (OWTF)]''' is a project focused on penetration testing efficiency and alignment of security tests to security standards like the OWASP Testing Guide (v3 and v4), the OWASP Top 10, PTES and NIST. Most of the ideas below focus on rewrite of some major components of OWTF to make it more modular. OWTF is moving to a fresh codebase with a fully Docker testing and deployment environment. If you want to get a jumpstart, check out https://github.com/owtf/owtf/tree/new-arch.&lt;br /&gt;
===OWASP OWTF - MiTM proxy interception and replay capabilities===&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
The OWTF man-in-the-middle proxy is written completely in Python (based on the excellent Tornado framework) and was benchmarked to be the fastest MiTM python proxy. However it lacks the useful and much need interception and replay capabilities of mitmproxy (https://github.com/mitmproxy/mitmproxy).&lt;br /&gt;
&lt;br /&gt;
The current implementation of the MiTM proxy serves its purpose very well. Its fast but its not extensible. There are a number of good use cases for being extensible&lt;br /&gt;
*ability to intercept the transactions&lt;br /&gt;
*modify or replay transaction on the fly&lt;br /&gt;
*add additional capabilities to the proxy (such as session marking/changing) without polluting the main proxy code&lt;br /&gt;
Bonus:&lt;br /&gt;
*Design and implement a proxy plugin (middleware) architecture so that the plugins can be defined separately and the user can choose what plugins to include dynamically (from the web interface).&lt;br /&gt;
*Replace the current Requester (based on urllib, urllib2) with a more robust Requester based on the new urllib3 with support for a real headless browser factory. The typical flow when requested for an authenticated browser instance (using PhantomJS)&lt;br /&gt;
&lt;br /&gt;
*The &amp;quot;Requester&amp;quot; module checks if there is any login parameters provided (i.e form-based or script - look at https://github.com/owtf/login-sessions-plugin)&lt;br /&gt;
*Create a browser instance and do the necessary login procedure&lt;br /&gt;
*Handle the browser for the URI&lt;br /&gt;
*When called to close the browser, do a clean logout and kill the browser instance.&lt;br /&gt;
'''Expected results:'''&lt;br /&gt;
*'''IMPORTANT: [http://legacy.python.org/dev/peps/pep-0008/ PEP-8 compliant code] in all modified code and surrounding areas.'''&lt;br /&gt;
*'''IMPORTANT: [https://github.com/7a/owtf/wiki/Contributor%27s-README OWTF contributor README compliant code]'''&lt;br /&gt;
*'''IMPORTANT: [http://sphinx-doc.org/ Sphinx-friendly python comments] [http://owtf.github.io/ptp/_modules/ptp/tools/w3af/parser.html#W3AFXMLParser example Sphinx-friendly python comments here]'''&lt;br /&gt;
*CRITICAL: Excellent reliability&lt;br /&gt;
*Good performance&lt;br /&gt;
*Unit tests / Functional tests&lt;br /&gt;
*Good documentation&lt;br /&gt;
'''Knowledge Prerequisite:''' Python proficiency, some previous exposure to security concepts and penetration testing is welcome but not strictly necessary as long as there is will to learn.&lt;br /&gt;
&lt;br /&gt;
'''OWASP OWTF Mentors:''' Contact: [mailto:Abraham.Aranguren@owasp.org Abraham Aranguren][mailto:viyat.bhalodia@owasp.org Viyat Bhalodia][mailto:bharadwaj.machiraju@gmail.com Bharadwaj Machiraju] OWASP OWTF Project Leaders&lt;br /&gt;
===OWASP OWTF - Web interface enhancements===&lt;br /&gt;
'''Brief explanation:'''&lt;br /&gt;
&lt;br /&gt;
The current web interface is a mixture of Tornado Jinja templates and ReactJS. A complete UI change to a stable ReactJS-based interface should be the deliverable for this project.  Most of the hard part for the change has already been done and added in a separate branch at https://github.com/owtf/owtf/tree/develop.&lt;br /&gt;
&lt;br /&gt;
For background on OWASP OWTF please see: https://www.owasp.org/index.php/OWASP_OWTF&lt;br /&gt;
&lt;br /&gt;
'''Expected results:'''&lt;br /&gt;
*'''IMPORTANT:Clean, maintainable (ES6 compatible and using recommended design patterns) React (JavaScript) code. ([https://github.com/getsentry/zeus/tree/master/webapp This] is a good example!)'''&lt;br /&gt;
*'''IMPORTANT: Thoroughly documented code along with API examples and example future components.'''&lt;br /&gt;
*'''CRITICAL''': Excellent reliability and performance.&lt;br /&gt;
*Unit tests / Functional tests and easy to setup testing environment (preferably automated).&lt;br /&gt;
'''Knowledge Prerequisite:''' Python (reading API source code and endpoints), React.JS (high proficiency) and general JavaScript proficiency.&lt;br /&gt;
&lt;br /&gt;
'''OWASP OWTF Mentors:''' Contact: [mailto:Abraham.Aranguren@owasp.org Abraham Aranguren][mailto:viyat.bhalodia@owasp.org Viyat Bhalodia][mailto:bharadwaj.machiraju@gmail.com Bharadwaj Machiraju] OWASP OWTF Project Leaders&lt;br /&gt;
===OWASP OWTF - New plugin architecture===&lt;br /&gt;
'''Brief explanation:'''&lt;br /&gt;
&lt;br /&gt;
The current plugin system is not very useful and it is painful to browse many plugins. Most of the plugins do have much code and most of is repeated - much refactoring needed there.&lt;br /&gt;
&lt;br /&gt;
This issue is documented in detail at https://github.com/owtf/owtf/issues/905.&lt;br /&gt;
&lt;br /&gt;
For background on OWASP OWTF please see: https://www.owasp.org/index.php/OWASP_OWTF&lt;br /&gt;
&lt;br /&gt;
'''Expected results:'''&lt;br /&gt;
*'''IMPORTANT: [http://legacy.python.org/dev/peps/pep-0008/ PEP-8 compliant code] in all modified code and surrounding areas.'''&lt;br /&gt;
*'''IMPORTANT: [https://github.com/7a/owtf/wiki/Contributor%27s-README OWTF contributor README compliant code]'''&lt;br /&gt;
*'''IMPORTANT: [http://sphinx-doc.org/ Sphinx-friendly python comments] [http://owtf.github.io/ptp/_modules/ptp/tools/w3af/parser.html#W3AFXMLParser example Sphinx-friendly python comments here]'''&lt;br /&gt;
*CRITICAL: Excellent reliability&lt;br /&gt;
*Good performance&lt;br /&gt;
*Unit tests / Functional tests&lt;br /&gt;
*Good documentation&lt;br /&gt;
&lt;br /&gt;
== OWASP iGoat (draft) ==&lt;br /&gt;
'''Idea 1:''' Completing OWASP iGoat documentation at https://docs.igoatapp.com/ and creating demo videos at for OWASP iGoat YouTube channel for learning purpose.&lt;br /&gt;
&lt;br /&gt;
'''Idea 2:''' Adding new challenge pack / CTF for iGoat. It should be one point solution for learning iOS app security&lt;br /&gt;
&lt;br /&gt;
= OWASP Seraphimdroid =&lt;br /&gt;
&lt;br /&gt;
=== Idea 1: Anomaly detection of device state ===&lt;br /&gt;
The idea is that certain features of a device would be constantly monitored (battery use, internet usage, opp calls, etc.). Initially, the usual behaviour of the device would be learned. Later, anomalies normal behavior would be reported to the user. This should involve some explanations, such as which applications are causing an anomaly the device behaviors &lt;br /&gt;
&lt;br /&gt;
=== Idea 2: On device machine learning of maliciousness of an app ===&lt;br /&gt;
Tensor-flow for on-device processing and some other libraries have been released that enable machine learning. We have previously applied a system, that based on permissions, is able to distinguish malicious apps from non-malicious. Now, we would like to learn also from other outputs and things one can monitor about application whether it can be malicious. &lt;br /&gt;
&lt;br /&gt;
=== Idea 3:  Enhansing privacy features ===&lt;br /&gt;
The vision of Seraphimdroid is to be aware of privacy threats. This may be achieved throug knowing which applications are using user accounts or other information that user has on phone to send to the server, or just by knowing which applications may be doing it. Knowledge base should be extending with the suggestions on how to improve privacy. Also, automated settings of various apps to use encryption should be proposed.&lt;br /&gt;
==OWASP ZAP==&lt;br /&gt;
[[OWASP Zed Attack Proxy Project]] (ZAP) The OWASP Zed Attack Proxy (ZAP) is one of the world’s most popular free security tools and is actively maintained by hundreds of international volunteers. Previous GSoC students have implemented key parts of the ZAP core functionality and have been offered (and accepted) jobs based on their work on ZAP.&lt;br /&gt;
&lt;br /&gt;
=== Active Scanning WebSockets ===&lt;br /&gt;
: '''Brief Explanation:'''&lt;br /&gt;
: ZAP has good support for websockets, and allows them to be intercepted, changed and fuzzed. Unfortunately it doesnt current support active scanning (automated attacking) of websockets.&lt;br /&gt;
: We would like to add active scanning support to websockets, ideally in a generic way which would allow us to reuse as many of our existing rules as are relevant. Adding additional websocket specific attacks would also be very useful.&lt;br /&gt;
: This project will be a continuation of the work that was started as part of last years GSoC.&lt;br /&gt;
: '''Expected Results:'''&lt;br /&gt;
:* An plugable infrastructure that allows us to active scan websockets&lt;br /&gt;
:* Converting the relevant existing scan rules to work with websockets&lt;br /&gt;
:* Implementing new websocket specific scan rules&lt;br /&gt;
: '''Getting started:''' &lt;br /&gt;
:* Have a look at the ZAP [https://github.com/zaproxy/zaproxy/blob/develop/CONTRIBUTING.md CONTRIBUTING.md] file, especially the 'Coding section.&lt;br /&gt;
:* We like to see students who have already contributed to ZAP, so try fixing one of the bugs flagged as [https://github.com/zaproxy/zaproxy/issues?q=is%3Aopen+is%3Aissue+label%3AIdealFirstBug IdealFirstBug].&lt;br /&gt;
: '''Knowledge Prerequisites:'''&lt;br /&gt;
:* ZAP is written in Java, so a good knowledge of this language is recommended. Some knowledge of application security would be useful, but not essential.&lt;br /&gt;
: '''Mentors:''' [https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @] and the rest of the ZAP Core Team&lt;br /&gt;
&lt;br /&gt;
=== Automated authentication detection and configuration ===&lt;br /&gt;
: '''Brief Explanation:'''&lt;br /&gt;
: Currently a user must manually configure ZAP to handle authentication, eg as per &amp;lt;nowiki&amp;gt;https://github.com/zaproxy/zaproxy/wiki/FAQformauth&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
: This is time consuming and error prone.&lt;br /&gt;
: Ideally ZAP would help detect login and registration pages and provide more assistance when configuring authentication, ideally being able to completely automate the task for as many sort of webapps as possible.&lt;br /&gt;
: This project will be a continuation of the work that was started as part of last years GSoC.&lt;br /&gt;
: '''Expected Results:'''&lt;br /&gt;
:* Detect login and registration pages&lt;br /&gt;
:* Provide a wizard to walk users through the process of setting up authentication, with as much assistance as possible&lt;br /&gt;
:* An option to completely automate the authentication process, for as many authentication mechanisms as possible&lt;br /&gt;
: '''Getting started:''' &lt;br /&gt;
:* Have a look at the ZAP [https://github.com/zaproxy/zaproxy/blob/develop/CONTRIBUTING.md CONTRIBUTING.md] file, especially the 'Coding section.&lt;br /&gt;
:* We like to see students who have already contributed to ZAP, so try fixing one of the bugs flagged as [https://github.com/zaproxy/zaproxy/issues?q=is%3Aopen+is%3Aissue+label%3AIdealFirstBug IdealFirstBug].&lt;br /&gt;
: '''Knowledge Prerequisites:'''&lt;br /&gt;
:* ZAP is written in Java, so a good knowledge of this language is recommended. Some knowledge of application security would be useful, but not essential.&lt;br /&gt;
: '''Mentors:''' [https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @] and the rest of the ZAP Core Team&lt;br /&gt;
:&lt;/div&gt;</summary>
		<author><name>Psiinon</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Zed_Attack_Proxy_Project&amp;diff=241304</id>
		<title>OWASP Zed Attack Proxy Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Zed_Attack_Proxy_Project&amp;diff=241304"/>
				<updated>2018-06-14T08:06:37Z</updated>
		
		<summary type="html">&lt;p&gt;Psiinon: Added Segment to list of supporters&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Main = &lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:90px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File: flagship_big.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
{{ReviewProject|projectname=zaproxy|language=en}}&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
The OWASP Zed Attack Proxy (ZAP) is one of the world’s most popular free security tools and is actively maintained by hundreds of international volunteers[[#Justification|*]]. It can help you automatically find security vulnerabilities in your web applications while you are developing and testing your applications. Its also a great tool for experienced pentesters to use for manual security testing.&lt;br /&gt;
&lt;br /&gt;
====ZAP 2.7.0 is now available!====&lt;br /&gt;
&lt;br /&gt;
[[Image:ZAP-Download.png | link=https://github.com/zaproxy/zaproxy/wiki/Downloads]]&lt;br /&gt;
&lt;br /&gt;
====Please help us to make ZAP even better for you by answering the [https://docs.google.com/forms/d/1-k-vcj_sSxlil6XLxCFade-m-IQVeE2h9gduA-2ZPPA/viewform ZAP User Questionnaire]!====&lt;br /&gt;
&lt;br /&gt;
For a quick overview of ZAP and an introduction to the [https://wiki.jenkins-ci.org/display/JENKINS/zap+plugin official ZAP Jenkins plugin] see these tutorial videos on YouTube:&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
{{#ev:youtube|eH0RBI0nmww}}&amp;amp;nbsp;&lt;br /&gt;
{{#ev:youtube|mmHZLSffCUg}}&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
For more videos see the links on the [https://github.com/zaproxy/zaproxy/wiki/Videos wiki videos page].&lt;br /&gt;
&lt;br /&gt;
Interested in a ZAP talk or training event? See the [https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project#tab=Talks talks] tab. Not one near you? Contact a [https://github.com/zaproxy/zaproxy/wiki/ZapEvangelists Zap Evangelist] to arrange one!&lt;br /&gt;
&lt;br /&gt;
{{#widget:PayPal Donation&lt;br /&gt;
|target=_blank&lt;br /&gt;
|budget=Zed Attack Proxy&lt;br /&gt;
}}  &lt;br /&gt;
&lt;br /&gt;
For general information about ZAP:&lt;br /&gt;
* [https://twitter.com/zaproxy Twitter] - official ZAP announcements (low volume)&lt;br /&gt;
* [https://zaproxy.blogspot.co.uk/ Blog] - official ZAP blog&lt;br /&gt;
&lt;br /&gt;
For help using ZAP:&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/releases/download/2.6.0/ZAPGettingStartedGuide-2.6.pdf Getting Started Guide (pdf)] - an introductory guide you can print&lt;br /&gt;
* [https://www.youtube.com/playlist?list=PLEBitBW-Hlsv8cEIUntAO8st2UGhmrjUB Tutorial Videos]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki User Guide] - online version of the User Guide included with ZAP&lt;br /&gt;
* [https://groups.google.com/group/zaproxy-users User Group] - ask questions about using ZAP&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/wiki Add-ons] - help for the optional add-ons you can install&lt;br /&gt;
* [https://stackoverflow.com/questions/tagged/zap StackOverflow] - because some people use this for all everything ;)&lt;br /&gt;
&lt;br /&gt;
To learn more about ZAP development:&lt;br /&gt;
* [https://github.com/zaproxy Source Code] - for all of the ZAP related projects&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/wiki/Introduction Wiki] - lots of detailed info&lt;br /&gt;
* [https://groups.google.com/group/zaproxy-develop Developer Group] - ask questions about the ZAP internals&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap Crowdin (GUI)] - help translate the ZAP GUI&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap-help Crowdin (User Guide)] - help translate the ZAP User Guide&lt;br /&gt;
* [https://www.openhub.net/p/zaproxy OpenHub]	- FOSS analytics&lt;br /&gt;
* [https://www.bountysource.com/teams/zap/issues BountySource] - Vote on ZAP issues (you can also donate money here, but 10% taken out)&lt;br /&gt;
&lt;br /&gt;
===Justification===&lt;br /&gt;
Justification for the statements made in the tagline at the top;)&lt;br /&gt;
&lt;br /&gt;
Popularity:&lt;br /&gt;
* ToolsWatch Annual Best Free/Open Source Security Tool Survey:&lt;br /&gt;
** 2016 [http://www.toolswatch.org/2017/02/2016-top-security-tools-as-voted-by-toolswatch-org-readers/ 2nd]&lt;br /&gt;
** 2015 [http://www.toolswatch.org/2016/02/2015-top-security-tools-as-voted-by-toolswatch-org-readers/ 1st]&lt;br /&gt;
** 2014 [http://www.toolswatch.org/2015/01/2014-top-security-tools-as-voted-by-toolswatch-org-readers/ 2nd]&lt;br /&gt;
** 2013 [http://www.toolswatch.org/2013/12/2013-top-security-tools-as-voted-by-toolswatch-org-readers/ 1st]&lt;br /&gt;
&lt;br /&gt;
Contributors:&lt;br /&gt;
* [https://www.openhub.net/p/zaproxy Code Contributors]&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap ZAP core i18n Contributors]&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap-help ZAP help i18n Contributors]&lt;br /&gt;
&lt;br /&gt;
{{Social Media Links}}&lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;padding-left:25px;width:200px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
[https://github.com/zaproxy/zaproxy/wiki/Downloads Download OWASP ZAP!]&lt;br /&gt;
&lt;br /&gt;
== Donate to OWASP ==&lt;br /&gt;
&amp;lt;div class=&amp;quot;center&amp;quot; style=&amp;quot;width: auto; margin-left: auto; margin-right: auto;&amp;quot;&amp;gt;{{#widget:PayPal Donation&lt;br /&gt;
|target=_blank&lt;br /&gt;
|budget=Other (Website Donation) }}&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
Please see the [https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project#News News] and [https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project#Talks Talks] tabs&lt;br /&gt;
&lt;br /&gt;
== Change Log ==&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/commits/develop zaproxy]&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/commits/master zap-extensions]&lt;br /&gt;
&lt;br /&gt;
== Code Repo ==&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/ zaproxy]&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/ zap-extensions]&lt;br /&gt;
&lt;br /&gt;
== Email List ==&lt;br /&gt;
&lt;br /&gt;
Questions? Please ask on the [http://groups.google.com/group/zaproxy-users ZAP User Group]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
Project Leader&amp;lt;br /&amp;gt;[https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @]&lt;br /&gt;
&lt;br /&gt;
Co-Project Leaders&amp;lt;br /&amp;gt;[https://www.owasp.org/index.php/User:Ricardo.Pereira Ricardo Pereira] [mailto:ricardo.pereira@owasp.org @]&lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/index.php/User:Rick.mitchell Rick Mitchell] [mailto:rick.mitchell+wiki@owasp.org @]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_Web_Testing_Environment_Project OWASP WTE]&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_OWTF OWASP OWTF]&lt;br /&gt;
&lt;br /&gt;
== Ohloh ==&lt;br /&gt;
&lt;br /&gt;
*https://www.openhub.net/p/zaproxy&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| cellpadding=&amp;quot;2&amp;quot; width=&amp;quot;200&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; | [[File:Mature projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Flagship_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; width=&amp;quot;50%&amp;quot; valign=&amp;quot;center&amp;quot; | [[File:Owasp-builders-small.png|link=]]&lt;br /&gt;
   |&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; width=&amp;quot;50%&amp;quot; valign=&amp;quot;center&amp;quot; | [[File:Owasp-breakers-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [http://www.apache.org/licenses/LICENSE-2.0 Apache 2 License]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_TOOL.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Screenshots =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotAddAlert.png|||400px|ZAP Add Alert Screen Shot]] &lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotHelp.png||400px|left|ZAP Help Screen Shot]]&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotHistoryFilter.png|thumb|400px|left|ZAP History Filter Screen Shot]]&lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotSearchTab.png|thumb|400px|left|ZAP Search Tab Screen Shot]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Talks =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
{{:Projects/OWASP Zed Attack Proxy Project/Pages/Talks | Talks}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
= News =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
{{:Projects/OWASP Zed Attack Proxy Project/Pages/News | News}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
= ZAP Gear =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Yes, you can now buy ZAP related gear!&lt;br /&gt;
&lt;br /&gt;
All of the artwork for ZAP swag is released under the Creative Common License and can be downloaded from the [https://github.com/zaproxy/zap-swag zap-swag] repo.&lt;br /&gt;
&lt;br /&gt;
You can of course use the artwork from this repo with any other online store that you like.&lt;br /&gt;
&lt;br /&gt;
A range of products can be purchased from [http://www.redbubble.com/people/zaproxy Redbubble]&lt;br /&gt;
&lt;br /&gt;
Stickers can be purchased from [https://www.stickermule.com/uk/user/1070684077/stickers Stickermule]&lt;br /&gt;
&lt;br /&gt;
T-shirts can be purchased from [http://www.cafepress.com/zaproxy Cafepress]&lt;br /&gt;
&lt;br /&gt;
[[Image:zap-tshirt-cp.PNG | link=http://www.cafepress.com/zaproxy]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Supporters =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
ZAP is developed by a worldwide [https://github.com/zaproxy/zap-core-help/wiki/HelpCredits team] of volunteers.&lt;br /&gt;
&lt;br /&gt;
But we have also been helped by many organizations, either financially or by encouraging their employees to work on ZAP:&lt;br /&gt;
&lt;br /&gt;
* [http://www.mozilla.org Mozilla]&lt;br /&gt;
* [http://www.linuxfoundation.org/ The Linux Foundation]&lt;br /&gt;
* [https://segment.com/ Segment]&lt;br /&gt;
* [http://www.owasp.org OWASP]&lt;br /&gt;
* [http://www.sage.co.uk Sage]&lt;br /&gt;
* [http://www.google.com Google]&lt;br /&gt;
* [http://www.microsoft.com Microsoft]&lt;br /&gt;
* [http://www.hacktics.com/ Hacktics, Ernst &amp;amp; Young]&lt;br /&gt;
* [http://www.dinosec.com/ DinoSec]&lt;br /&gt;
* [http://www.denimgroup.com Denim Group]&lt;br /&gt;
* [http://www.aspectsecurity.com/ Aspect Security]&lt;br /&gt;
* [http://secureideas.net SecureIdeas]&lt;br /&gt;
* [http://utilisec.com UtiliSec]&lt;br /&gt;
* [http://www.encription.co.uk/ encription]&lt;br /&gt;
* [https://www.accenture.com/us-en/digital-index.aspx Accenture Digital]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Functionality =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
'''Some of ZAP's functionality:'''&lt;br /&gt;
&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsIntercept Man-in-the-middle Proxy]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsSpider Traditional] and AJAX spiders&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsAscan Automated scanner]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsPscan Passive scanner]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsBruteforce Forced browsing]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsFuzz Fuzzer]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpUiDialogsOptionsDynsslcert Dynamic SSL certificates]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/SmartCards Smartcard and Client Digital Certificates support]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpAddonsWebsocketIntroduction Web sockets] support&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpAddonsScriptsScripts Support for a wide range of scripting languages]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki//HelpAddonsPlugnhackPlugnhack Plug-n-Hack support]&lt;br /&gt;
* Authentication and session support&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsApi Powerful REST based API]&lt;br /&gt;
* Automatic updating option&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/wiki Integrated and growing marketplace of add-ons]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
= Features =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
'''Some of ZAP's features:'''&lt;br /&gt;
&lt;br /&gt;
* [http://www.apache.org/licenses/LICENSE-2.0 Open source]&lt;br /&gt;
* Cross platform (it even runs on a [https://github.com/zaproxy/zaproxy/wiki/zappi Raspberry Pi!])&lt;br /&gt;
* Easy to install (using a [https://www.ej-technologies.com/products/install4j/overview.html multi-platform installer builder])&lt;br /&gt;
* Completely free (no paid for 'Pro' version)&lt;br /&gt;
* Ease of use a priority&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpIntro Comprehensive help pages]&lt;br /&gt;
* Fully internationalized&lt;br /&gt;
* Translated into over 20 languages&lt;br /&gt;
* Community based, with involvement actively encouraged&lt;br /&gt;
* Under active development by an international team of volunteers&lt;br /&gt;
&lt;br /&gt;
ZAP is a fork of the well regarded [http://www.parosproxy.org/ Paros Proxy].&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Languages =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''ZAP supports the following languages:'''&lt;br /&gt;
&lt;br /&gt;
* English&lt;br /&gt;
* Arabic&lt;br /&gt;
* Bosnian&lt;br /&gt;
* Brazilian Portuguese&lt;br /&gt;
* Chinese&lt;br /&gt;
* Danish&lt;br /&gt;
* Filipino&lt;br /&gt;
* French&lt;br /&gt;
* German&lt;br /&gt;
* Greek&lt;br /&gt;
* Hungarian&lt;br /&gt;
* Indonesian&lt;br /&gt;
* Italian&lt;br /&gt;
* Japanese&lt;br /&gt;
* Korean&lt;br /&gt;
* Persian&lt;br /&gt;
* Polish&lt;br /&gt;
* Russian&lt;br /&gt;
* Sinhala&lt;br /&gt;
* Spanish&lt;br /&gt;
* Urdu &lt;br /&gt;
&lt;br /&gt;
You can use [http://crowdin.net/project/owasp-zap Crowdin] to help improve these translations or add new ones right now!&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Release 2.6.0==&lt;br /&gt;
ZAP 2.6.0 has been released, this is a bug fix and enhancement release&lt;br /&gt;
&lt;br /&gt;
For more details see https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_6_0&lt;br /&gt;
&lt;br /&gt;
==Release 2.7.0==&lt;br /&gt;
ZAP 2.7.0 has been released (Nov 2017), this is a bug fix and enhancement release&lt;br /&gt;
&lt;br /&gt;
For more details see https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_7_0&lt;br /&gt;
&lt;br /&gt;
It requires Java 8 (minimum) and supports Selenium 3.&lt;br /&gt;
&lt;br /&gt;
==Release 2.8.0==&lt;br /&gt;
ZAP 2.8.0 does not yet have a planned release date, but is likely to be around the beginning of 2018 or (more likely) the middle of 2018.&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Get Involved =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Involvement in the development of ZAP is actively encouraged!&lt;br /&gt;
&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
&lt;br /&gt;
Some of the ways you can help:&lt;br /&gt;
&lt;br /&gt;
==Feature Requests==&lt;br /&gt;
&lt;br /&gt;
Please raise new feature requests as enhancement requests here: https://github.com/zaproxy/zaproxy/issues&lt;br /&gt;
&lt;br /&gt;
If there are existing requests you are also interested in then please 'star' them - that way we can see which features people are most interested in and can prioritize them accordingly. &lt;br /&gt;
&lt;br /&gt;
==Feedback==&lt;br /&gt;
&lt;br /&gt;
Please use the [http://groups.google.com/group/zaproxy-users zaproxy-users Google Group] for feedback:&lt;br /&gt;
* What do like?&lt;br /&gt;
* What don't you like?&lt;br /&gt;
* What features could be made easier to use?&lt;br /&gt;
* How could the help pages be improved? &lt;br /&gt;
&lt;br /&gt;
==Log issues==&lt;br /&gt;
&lt;br /&gt;
Have you had a problem using ZAP?&lt;br /&gt;
&lt;br /&gt;
If so and its not already been logged then please [https://github.com/zaproxy/zaproxy/issues report it]&lt;br /&gt;
&lt;br /&gt;
==Localization==&lt;br /&gt;
&lt;br /&gt;
Are you fluent in another language? Can you help translate ZAP into that language?&lt;br /&gt;
&lt;br /&gt;
You can use [http://crowdin.net/project/owasp-zap Crowdin] to do that!&lt;br /&gt;
&lt;br /&gt;
==Development==&lt;br /&gt;
&lt;br /&gt;
If you fancy having a go at adding functionality to ZAP then please get in touch via the [http://groups.google.com/group/zaproxy-develop zaproxy-develop Google Group].&lt;br /&gt;
&lt;br /&gt;
Again, you do not have to be a security expert to contribute code - working on ZAP could be great way to learn more about web application security!&lt;br /&gt;
&lt;br /&gt;
If you actively contribute to ZAP then you will be invited to join the project. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project|Zed Attack Proxy Project]]&lt;br /&gt;
[[Category:OWASP_Tool]]&lt;br /&gt;
[[Category:OWASP Release Quality Tool|OWASP Release Quality Tool]]&lt;br /&gt;
[[Category:OWASP_Download]]&lt;br /&gt;
[[Category:Popular]]&lt;br /&gt;
[[Category:SAMM-ST-2]]&lt;br /&gt;
[[Category:Flagship Projects|Zap]]&lt;br /&gt;
[[Category:OWASP Zed Attack Proxy|Zap]]&lt;/div&gt;</summary>
		<author><name>Psiinon</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Vulnerable_Web_Applications_Directory_Project&amp;diff=240176</id>
		<title>OWASP Vulnerable Web Applications Directory Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Vulnerable_Web_Applications_Directory_Project&amp;diff=240176"/>
				<updated>2018-04-23T14:05:56Z</updated>
		
		<summary type="html">&lt;p&gt;Psiinon: Corrected broken interview link&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Vulnerable Web Applications Directory Project==&lt;br /&gt;
&lt;br /&gt;
The OWASP Vulnerable Web Applications Directory Project (VWAD) is a comprehensive and well maintained registry of all known vulnerable web applications currently available for legal security and vulnerability testing of various kinds.&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
Select from the above tabs to view all of the:&lt;br /&gt;
* On-Line applications&lt;br /&gt;
* Off-Line applications&lt;br /&gt;
* Virtual Machines and ISO images&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
The OWASP Vulnerable Web Applications Directory (VWAD) Project is a comprehensive and well maintained registry of all known vulnerable web applications currently available. These vulnerable web applications can be used by web developers, security auditors and penetration testers to put in practice their knowledge and skills during training sessions (and especially afterwards), as well as to test at any time the multiple hacking tools and offensive techniques available, in preparation for their next real-world engagement.&lt;br /&gt;
&lt;br /&gt;
The main goal of VWAD is to provide a list of vulnerable web applications available to security professionals for hacking and offensive activities, so that they can attack realistic web environments... without going to jail :)&lt;br /&gt;
&lt;br /&gt;
The vulnerable web applications have been classified in three categories: On-Line, Off-Line, and VMs/ISOs. Each list has been ordered alphabetically.&lt;br /&gt;
&lt;br /&gt;
An initial list that inspired this project was maintained till October 2013 at: http://blog.taddong.com/2011/10/hacking-vulnerable-web-applications.html.&lt;br /&gt;
&lt;br /&gt;
A brief description of the OWASP VWAD project is available at: http://blog.dinosec.com/2013/11/owasp-vulnerable-web-applications.html.&lt;br /&gt;
&lt;br /&gt;
The associated GitHub repository is available at: https://github.com/OWASP/OWASP-VWAD.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP Vulnerable Web Applications Directory Projects is free to use. It is licensed under the Apache 2.0 License, so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially.&lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is VWAD? ==&lt;br /&gt;
&lt;br /&gt;
OWASP VWAD provides:&lt;br /&gt;
&lt;br /&gt;
* A list of all known vulnerable web applications.&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
Interview with [https://soundcloud.com/trustedsoftwarealliance/simon-bennetts-web Simon Bennetts – The OWASP Web Applications Vulnerability Project] .&lt;br /&gt;
&lt;br /&gt;
== Project Leaders ==&lt;br /&gt;
&lt;br /&gt;
*[mailto:raul@raulsiles.com Raul Siles]&lt;br /&gt;
*[[User:Simon Bennetts|Simon Bennetts]]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* N/A&lt;br /&gt;
&lt;br /&gt;
== Open Hub ==&lt;br /&gt;
&lt;br /&gt;
*https://www.openhub.net/p/OWASP-VWAD&lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;padding-left:25px;width:200px;&amp;quot; valign=&amp;quot;top&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
* N/A - The project is self contained on the wiki.&lt;br /&gt;
* GitHub repository - https://github.com/OWASP/OWASP-VWAD&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
* [16 Oct 2013] Project created.&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
N/A&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Owasp-incubator-trans-85.png|link=:Category:OWASP_Project#tab=Terminology]]&lt;br /&gt;
   | width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Owasp-breakers-small.png|link=Breakers]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=On-Line apps=&lt;br /&gt;
&lt;br /&gt;
{{:OWASP_Vulnerable_Web_Applications_Directory_Project/Pages/Online | Online}}&lt;br /&gt;
&lt;br /&gt;
Please note that the [https://www.owasp.org/index.php/OWASP_Vulnerable_Web_Applications_Directory_Project/Pages/Online source page] for this tab is automatically generated via the [https://github.com/OWASP/OWASP-VWAD VWAD github project].&lt;br /&gt;
&lt;br /&gt;
You can either edit that page directly or submit a pull request.&lt;br /&gt;
&lt;br /&gt;
= Off-Line apps =&lt;br /&gt;
&lt;br /&gt;
Vulnerable applications that have to be downloaded and used locally:&lt;br /&gt;
&lt;br /&gt;
{{:OWASP_Vulnerable_Web_Applications_Directory_Project/Pages/Offline | Offline}}&lt;br /&gt;
&lt;br /&gt;
Please note that the [https://www.owasp.org/index.php/OWASP_Vulnerable_Web_Applications_Directory_Project/Pages/Offline source page] for this tab is automatically generated via the [https://github.com/OWASP/OWASP-VWAD VWAD github project].&lt;br /&gt;
&lt;br /&gt;
You can either edit that page directly or submit a pull request.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The following apps are quite old and appear not to be maintained - as such they are probably less useful.&lt;br /&gt;
&lt;br /&gt;
{{:OWASP_Vulnerable_Web_Applications_Directory_Project/Pages/OfflineOld | OfflineOld}}&lt;br /&gt;
&lt;br /&gt;
Please note that the [https://www.owasp.org/index.php/OWASP_Vulnerable_Web_Applications_Directory_Project/Pages/OfflineOld source page] for this tab is automatically generated via the [https://github.com/OWASP/OWASP-VWAD VWAD github project].&lt;br /&gt;
&lt;br /&gt;
You can either edit that page directly or submit a pull request.&lt;br /&gt;
&lt;br /&gt;
= Virtual Machines or ISOs =&lt;br /&gt;
&lt;br /&gt;
VMs which contain multiple vulnerable applications:&lt;br /&gt;
&lt;br /&gt;
{{:OWASP_Vulnerable_Web_Applications_Directory_Project/Pages/VMs | VMs}}&lt;br /&gt;
&lt;br /&gt;
Please note that the [https://www.owasp.org/index.php/OWASP_Vulnerable_Web_Applications_Directory_Project/Pages/VMs source page] for this tab is automatically generated via the [https://github.com/OWASP/OWASP-VWAD VWAD github project].&lt;br /&gt;
&lt;br /&gt;
You can either edit that page directly or submit a pull request.&lt;br /&gt;
&lt;br /&gt;
Please add any new apps in alphabetic order, correct mistakes or just comment on this page if you dont have write access to this wiki.&lt;br /&gt;
&lt;br /&gt;
The following apps are quite old and appear not to be maintained - as such they are probably less useful.&lt;br /&gt;
&lt;br /&gt;
{{:OWASP_Vulnerable_Web_Applications_Directory_Project/Pages/VMsOld | VMsOld}}&lt;br /&gt;
&lt;br /&gt;
Please note that the [https://www.owasp.org/index.php/OWASP_Vulnerable_Web_Applications_Directory_Project/Pages/VMsOld source page] for this tab is automatically generated via the [https://github.com/OWASP/OWASP-VWAD VWAD github project].&lt;br /&gt;
&lt;br /&gt;
You can either edit that page directly or submit a pull request.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
VWAD is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
*[mailto:raul@raulsiles.com Raul Siles]&lt;br /&gt;
*[[User:Simon Bennetts|Simon Bennetts]]&lt;br /&gt;
&lt;br /&gt;
==Others==&lt;br /&gt;
* [mailto:achim@owasp.org Achim Hoffmann]&lt;br /&gt;
* [[User:Zakiakhmad|Zaki Akhmad]]&lt;br /&gt;
&lt;br /&gt;
==On-line resources used==&lt;br /&gt;
* [http://blog.taddong.com/2011/10/hacking-vulnerable-web-applications.html Hacking Vulnerable Web Applications Without Going To Jail]&lt;br /&gt;
* [http://securitythoughts.wordpress.com/2010/03/22/vulnerable-web-applications-for-learning/ Vulnerable Web Applications for learning]&lt;br /&gt;
* [http://code.google.com/p/owaspbwa/wiki/UserGuide OWASP BWA User Guide]&lt;br /&gt;
&lt;br /&gt;
==Other vulnerable web-app compilations==&lt;br /&gt;
* [http://www.amanhardikar.com/mindmaps/Practice.html Penetration Testing Practice Labs - Vulnerable Apps/Systems]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
As of March 5, 2014, all known Vulnerable Web Applications have been included.&lt;br /&gt;
&lt;br /&gt;
Going forward the plan is to:&lt;br /&gt;
* Keep publicising&lt;br /&gt;
* Keep up to date with any new apps released or updated&lt;br /&gt;
* Review every 6 months to see if it could be improved in any way&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of the OWASP Vulnerable Web Applications Directory Project is actively encouraged!&lt;br /&gt;
&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
&lt;br /&gt;
Some of the ways you can help:&lt;br /&gt;
* Update the wiki with any missing apps&lt;br /&gt;
* Send pull requests to https://github.com/OWASP/OWASP-VWAD&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP_Vulnerable_Web_Applications_Directory_Project}} &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Breakers]]  &lt;br /&gt;
[[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Psiinon</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Reverse_Tabnapping&amp;diff=237908</id>
		<title>Reverse Tabnapping</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Reverse_Tabnapping&amp;diff=237908"/>
				<updated>2018-02-20T12:19:25Z</updated>
		
		<summary type="html">&lt;p&gt;Psiinon: Blanked the page&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Psiinon</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Reverse_Tabnabbing&amp;diff=237907</id>
		<title>Reverse Tabnabbing</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Reverse_Tabnabbing&amp;diff=237907"/>
				<updated>2018-02-20T12:18:37Z</updated>
		
		<summary type="html">&lt;p&gt;Psiinon: First version&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Template:Attack}}&lt;br /&gt;
&lt;br /&gt;
Last revision (mm/dd/yy): '''{{REVISIONMONTH}}/{{REVISIONDAY}}/{{REVISIONYEAR}}'''&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
Reverse tabnabbing is an attack where a page linked from the target page is able to rewrite that page, for example to replace it with a phishing site. As the user was originally on the correct page they are less likely to notice that it has been changed to a phishing site, especially it the site looks the same as the target. If the user authenticates to this new page then their credentials (or other sensitive data) are sent to the phishing site rather than the legitimate one.&lt;br /&gt;
&lt;br /&gt;
As well as the target site being able to overwrite the target page, any http link can be spoofed to overwrite the target page if the user is on an unsecured network, for example a public wifi hotspot. The attack is possible even if the target site is only available via https as the attacker only needs to spoof the http site that is being linked to.&lt;br /&gt;
&lt;br /&gt;
The attack is typically only possible when the target site uses a &amp;quot;_blank&amp;quot; target attribute in the link and does not include any of the preventative measures detailed below.&lt;br /&gt;
&lt;br /&gt;
==Examples==&lt;br /&gt;
&lt;br /&gt;
Vulnerable page:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&amp;lt;html&amp;gt;&amp;lt;body&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;&amp;lt;a href = &amp;quot;bad.example.com&amp;quot; target=&amp;quot;_blank&amp;quot;&amp;gt;vulnerable target&amp;lt;/a&amp;gt;&lt;br /&gt;
&amp;lt;/body&amp;gt;&amp;lt;/html&amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Malicious site that is linked to:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&amp;lt;html&amp;gt;&amp;lt;body&amp;gt;&lt;br /&gt;
&amp;lt;script&amp;gt;&lt;br /&gt;
if (window.opener) {&lt;br /&gt;
  window.opener.location = &amp;quot;https://phish.example.com&amp;quot;;&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/script&amp;gt;&lt;br /&gt;
&amp;lt;/body&amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
When a user clicks on the ‘vulnerable target’ then the 'malicious' site is opened in a new tab (as expected) but the target site in the original tab is replaced by the phishing site.&lt;br /&gt;
&lt;br /&gt;
==Prevention==&lt;br /&gt;
&lt;br /&gt;
Any of the following options will prevent reverse tabnabbing:&lt;br /&gt;
* Do not use target=&amp;quot;_blank&amp;quot; in a link&lt;br /&gt;
* Add the link attribute rel=&amp;quot;noopener&amp;quot;, rel=&amp;quot;noreferrer&amp;quot; or rel=&amp;quot;noopener noreferrer&amp;quot;&lt;br /&gt;
&lt;br /&gt;
==References==&lt;br /&gt;
&lt;br /&gt;
* https://dev.to/ben/the-targetblank-vulnerability-by-example - The target=&amp;quot;_blank&amp;quot; vulnerability by example &lt;br /&gt;
* https://mathiasbynens.github.io/rel-noopener/ - About rel=noopener&lt;br /&gt;
* https://medium.com/@jitbit/target-blank-the-most-underestimated-vulnerability-ever-96e328301f4c - Target=&amp;quot;_blank&amp;quot; — the most underestimated vulnerability ever&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&lt;br /&gt;
[[Category:Attack]]&lt;/div&gt;</summary>
		<author><name>Psiinon</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Reverse_Tabnapping&amp;diff=237906</id>
		<title>Reverse Tabnapping</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Reverse_Tabnapping&amp;diff=237906"/>
				<updated>2018-02-20T12:09:49Z</updated>
		
		<summary type="html">&lt;p&gt;Psiinon: first version of this page&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Template:Attack}}&lt;br /&gt;
&lt;br /&gt;
Last revision (mm/dd/yy): '''{{REVISIONMONTH}}/{{REVISIONDAY}}/{{REVISIONYEAR}}'''&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
Reverse tabnapping is an attack where a page linked from the target page is able to rewrite that page, for example to replace it with a phishing site. As the user was originally on the correct page they are less likely to notice that it has been changed to a phishing site, especially it the site looks the same as the target. If the user authenticates to this new page then their credentials (or other sensitive data) are sent to the phishing site rather than the legitimate one.&lt;br /&gt;
&lt;br /&gt;
As well as the target site being able to overwrite the target page, any http link can be spoofed to overwrite the target page if the user is on an unsecured network, for example a public wifi hotspot. The attack is possible even if the target site is only available via https as the attacker only needs to spoof the http site that is being linked to.&lt;br /&gt;
&lt;br /&gt;
The attack is typically only possible when the target site uses a &amp;quot;_blank&amp;quot; target attribute in the link and does not include any of the preventative measures detailed below.&lt;br /&gt;
&lt;br /&gt;
==Examples==&lt;br /&gt;
&lt;br /&gt;
Vulnerable page:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&amp;lt;html&amp;gt;&amp;lt;body&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;&amp;lt;a href = &amp;quot;bad.example.com&amp;quot; target=&amp;quot;_blank&amp;quot;&amp;gt;vulnerable target&amp;lt;/a&amp;gt;&lt;br /&gt;
&amp;lt;/body&amp;gt;&amp;lt;/html&amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Malicious site that is linked to:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&amp;lt;html&amp;gt;&amp;lt;body&amp;gt;&lt;br /&gt;
&amp;lt;script&amp;gt;&lt;br /&gt;
if (window.opener) {&lt;br /&gt;
  window.opener.location = &amp;quot;https://phish.example.com&amp;quot;;&lt;br /&gt;
}&lt;br /&gt;
&amp;lt;/script&amp;gt;&lt;br /&gt;
&amp;lt;/body&amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
When a user clicks on the ‘vulnerable target’ then the 'malicious' site is opened in a new tab (as expected) but the target site in the original tab is replaced by the phishing site.&lt;br /&gt;
&lt;br /&gt;
==Prevention==&lt;br /&gt;
&lt;br /&gt;
Any of the following options will prevent reverse tabnabbing:&lt;br /&gt;
* Do not use target=&amp;quot;_blank&amp;quot; in a link&lt;br /&gt;
* Add the link attribute rel=&amp;quot;noopener&amp;quot;, rel=&amp;quot;noreferrer&amp;quot; or rel=&amp;quot;noopener noreferrer&amp;quot;&lt;br /&gt;
&lt;br /&gt;
==References==&lt;br /&gt;
&lt;br /&gt;
* https://dev.to/ben/the-targetblank-vulnerability-by-example - The target=&amp;quot;_blank&amp;quot; vulnerability by example &lt;br /&gt;
* https://mathiasbynens.github.io/rel-noopener/ - About rel=noopener&lt;br /&gt;
* https://medium.com/@jitbit/target-blank-the-most-underestimated-vulnerability-ever-96e328301f4c - Target=&amp;quot;_blank&amp;quot; — the most underestimated vulnerability ever&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&lt;br /&gt;
[[Category:Attack]]&lt;/div&gt;</summary>
		<author><name>Psiinon</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=GSOC2018_Ideas&amp;diff=236869</id>
		<title>GSOC2018 Ideas</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=GSOC2018_Ideas&amp;diff=236869"/>
				<updated>2018-01-17T14:42:47Z</updated>
		
		<summary type="html">&lt;p&gt;Psiinon: Added Active Scanning Websockets&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=OWASP Project Requests=&lt;br /&gt;
&lt;br /&gt;
'''Tips to get you started in no particular order:''' &lt;br /&gt;
 '''* Read [https://developers.google.com/open-source/gsoc/ Google Summer of Code Program(GSOC)]'''&lt;br /&gt;
 '''* Read the [[GSoC SAT]] '''&lt;br /&gt;
 * Read the [https://www.owasp.org/index.php/GSoC GSOC Student Guidelines]&lt;br /&gt;
 * Contact us through the mailing list or irc channel.&lt;br /&gt;
 * Check our [https://github.com/OWASP github organization]&lt;br /&gt;
==OWASP ZAP==&lt;br /&gt;
[[OWASP Zed Attack Proxy Project]] (ZAP) The OWASP Zed Attack Proxy (ZAP) is one of the world’s most popular free security tools and is actively maintained by hundreds of international volunteers. Previous GSoC students have implemented key parts of the ZAP core functionality and have been offered (and accepted) jobs based on their work on ZAP.&lt;br /&gt;
&lt;br /&gt;
We have just included a few of the ideas we have here, for a more complete list see the issues on the ZAP bug tracker with the [https://github.com/zaproxy/zaproxy/issues?q=is%3Aopen+is%3Aissue+label%3Aproject project] label.&lt;br /&gt;
===Active Scanning WebSockets===&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
ZAP has good support for websockets, and allows them to be intercepted, changed and fuzzed. Unfortunately it doesnt current support active scanning (automated attacking) of websockets.&lt;br /&gt;
&lt;br /&gt;
We would like to add active scanning support to websockets, ideally in a generic way which would allow us to reuse as many of our existing rules as are relevant. Adding additional websocket specific attacks would also be very useful.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* An plugable infrastructure that allows us to active scan websockets&lt;br /&gt;
* Converting the relevant existing scan rules to work with websockets&lt;br /&gt;
* Implementing new websocket specific scan rules&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
&lt;br /&gt;
* Have a look at the ZAP [https://github.com/zaproxy/zaproxy/blob/develop/CONTRIBUTING.md CONTRIBUTING.md] file, especially the 'Coding section.&lt;br /&gt;
* We like to see students who have already contributed to ZAP, so try fixing one of the bugs flagged as [https://github.com/zaproxy/zaproxy/issues?q=is%3Aopen+is%3Aissue+label%3AIdealFirstBug IdealFirstBug].&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* ZAP is written in Java, so a good knowledge of this language is recommended. Some knowledge of application security would be useful, but not essential.&lt;br /&gt;
'''Mentors:''' [https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @] and the rest of the ZAP Core Team&lt;br /&gt;
&lt;br /&gt;
=== React Handling  ===&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
ZAP doesnt understand React applications as well as it should be able to.&lt;br /&gt;
&lt;br /&gt;
It would be great if ZAP had a much better understanding of such applications, including how to explore and attack them more effectively.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* ZAP able to explore React applications more effectively&lt;br /&gt;
* ZAP able to attack React applications more effectively&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
&lt;br /&gt;
* Have a look at the ZAP [https://github.com/zaproxy/zaproxy/blob/develop/CONTRIBUTING.md CONTRIBUTING.md] file, especially the 'Coding section.&lt;br /&gt;
* We like to see students who have already contributed to ZAP, so try fixing one of the bugs flagged as [https://github.com/zaproxy/zaproxy/issues?q=is%3Aopen+is%3Aissue+label%3AIdealFirstBug IdealFirstBug].&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* As React is written in JavaScript, good knowledge of this language is recommended. ZAP is written in Java, so some knowledge of this language would be useful. Some knowledge of application security would be useful, but not essential.&lt;br /&gt;
'''Mentors:''' [https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @] and the rest of the ZAP Core Team&lt;br /&gt;
&lt;br /&gt;
=== Automated authentication detection and configuration  ===&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
Currently a user must manually configure ZAP to handle authentication, eg as per &amp;lt;nowiki&amp;gt;https://github.com/zaproxy/zaproxy/wiki/FAQformauth&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This is time consuming and error prone.&lt;br /&gt;
&lt;br /&gt;
Ideally ZAP would help detect login and registration pages and provide more assistance when configuring authentication, ideally being able to completely automate the task for as many sort of webapps as possible.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* Detect login and registration pages&lt;br /&gt;
* Provide a wizard to walk users through the process of setting up authentication, with as much assistance as possible&lt;br /&gt;
* An option to completely automate the authentication process, for as many authentication mechanisms as possible&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
&lt;br /&gt;
* Have a look at the ZAP [https://github.com/zaproxy/zaproxy/blob/develop/CONTRIBUTING.md CONTRIBUTING.md] file, especially the 'Coding section.&lt;br /&gt;
* We like to see students who have already contributed to ZAP, so try fixing one of the bugs flagged as [https://github.com/zaproxy/zaproxy/issues?q=is%3Aopen+is%3Aissue+label%3AIdealFirstBug IdealFirstBug].&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* ZAP is written in Java, so a good knowledge of this language is recommended. Some knowledge of application security would be useful, but not essential.&lt;br /&gt;
'''Mentors:''' [https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @] and the rest of the ZAP Core Team&lt;br /&gt;
&lt;br /&gt;
=== Zest Text Representation and Parser ===&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
Zest is a graphical scripting language from the Mozilla Security team, and is used as the ZAP macro language.&lt;br /&gt;
&lt;br /&gt;
A standardized text representation and parser would be very useful and help its adoption.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* A documented definition of a text representation for Zest&lt;br /&gt;
* A parser that converts the text representation into a working Zest script&lt;br /&gt;
* An option in the Zest java implementation to output Zest scripts text format&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
&lt;br /&gt;
* Have a look at the ZAP [https://github.com/zaproxy/zaproxy/blob/develop/CONTRIBUTING.md CONTRIBUTING.md] file, especially the 'Coding section.&lt;br /&gt;
* We like to see students who have already contributed to ZAP, so try fixing one of the bugs flagged as [https://github.com/zaproxy/zaproxy/issues?q=is%3Aopen+is%3Aissue+label%3AIdealFirstBug IdealFirstBug].&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* The Zest reference implementation is written in Java, so a good knowledge of this language is recommended. Some knowledge of application security would be useful, but not essential.&lt;br /&gt;
'''Mentors:''' [https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @] and the rest of the ZAP Core Team&lt;br /&gt;
&lt;br /&gt;
=== Develop Bamboo Addon ===&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
It would be great to have an official ZAP add-on for [https://www.atlassian.com/software/bamboo Bamboo], equivalent to the one we now have for [https://wiki.jenkins.io/display/JENKINS/zap+plugin Jenkins]&lt;br /&gt;
&lt;br /&gt;
For more information about Bamboo plugins see the [https://developer.atlassian.com/server/bamboo/bamboo-plugin-guide/ Bamboo plugin guide].&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
&lt;br /&gt;
A Bamboo addon that supports:&lt;br /&gt;
* Spidering (using the traditional and Ajax spiders)&lt;br /&gt;
* Active Scanning&lt;br /&gt;
* Authentication&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
&lt;br /&gt;
* Have a look at the ZAP [https://github.com/zaproxy/zaproxy/blob/develop/CONTRIBUTING.md CONTRIBUTING.md] file, especially the 'Coding section.&lt;br /&gt;
* We like to see students who have already contributed to ZAP, so try fixing one of the bugs flagged as [https://github.com/zaproxy/zaproxy/issues?q=is%3Aopen+is%3Aissue+label%3AIdealFirstBug IdealFirstBug].&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* ZAP and Bamboo are written in Java, so a good knowledge of this language is recommended. Some knowledge of application security would be useful, but not essential.&lt;br /&gt;
'''Mentors:''' [https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @] and the rest of the ZAP Core Team&lt;br /&gt;
&lt;br /&gt;
=== Your Idea ===&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
ZAP is a great framework for building new and innovative security testing solutions. If you have an idea that is not on this list then don't worry, you can still submit it, we have accepted original projects in previous years and have even paid a student to work on their idea when we did not get enough GSoC slots to accept all of the projects we wanted.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* A new feature that makes ZAP even better&lt;br /&gt;
* Code that conforms to our Development Rules and Guidelines&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
&lt;br /&gt;
* Have a look at the ZAP [https://github.com/zaproxy/zaproxy/blob/develop/CONTRIBUTING.md CONTRIBUTING.md] file, especially the 'Coding section.&lt;br /&gt;
* We like to see students who have already contributed to ZAP, so try fixing one of the bugs flagged as [https://github.com/zaproxy/zaproxy/issues?q=is%3Aopen+is%3Aissue+label%3AIdealFirstBug IdealFirstBug].&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* ZAP is written in Java, so a good knowledge of this language is recommended. Some knowledge of application security would be useful, but not essential.&lt;br /&gt;
'''Mentors:''' [https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @] and the rest of the ZAP Core Team&lt;br /&gt;
&lt;br /&gt;
== OWASP Juice Shop ==&lt;br /&gt;
&lt;br /&gt;
[[OWASP Juice Shop Project]] is an intentionally insecure webapp for security trainings written entirely in Javascript which encompasses the entire OWASP Top Ten and other severe security flaws. Juice Shop is written in Node.js, Express and AngularJS. The application contains more than 30 challenges of varying difficulty where the user is supposed to exploit the underlying vulnerabilities. Apart from the hacker and awareness training use case, pentesting proxies or security scanners can use Juice Shop as a &amp;quot;guinea pig&amp;quot;-application to check how well their tools cope with Javascript-heavy application frontends and REST APIs.&lt;br /&gt;
&lt;br /&gt;
=== Challenge Pack 2018 ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
Ideas for potential new hacking challenges are collected in [https://github.com/bkimminich/juice-shop/issues?q=is%3Aissue+is%3Aopen+label%3Achallenge GitHub issues labeled &amp;quot;challenge&amp;quot;]. This project could implement a whole bunch of challenges one by one and release them over the course of several small releases. This would allow the student to work in a professional Continuous Delivery kind of way while bringing benefit to the Juice Shop over the duration of the project.&lt;br /&gt;
&lt;br /&gt;
Coming up with additional ideas for challenges would be part of the project scope, as the list of pre-existing ideas might not be sufficient for a GSoC project.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* 10 or more new challenges for OWASP Juice Shop (including required functional enhancements to place the challenges in, e.g. the [https://github.com/bkimminich/juice-shop/issues/244 Order Dashboard] user story])&lt;br /&gt;
* Each challenge comes with full functional unit and integration tests&lt;br /&gt;
* Each challenge is verified to be exploitable by corresponding end-to-end tests&lt;br /&gt;
* Hint and solution sections for each new challenge are added to the &amp;quot;Pwning OWASP Juice Shop&amp;quot; ebook&lt;br /&gt;
* Code follows existing styleguides and passes all existing quality gates regarding code smells, test coverage etc.&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
* Get familiar with the architecture and code base of the application's rich Javascript frontend and RESTful backend&lt;br /&gt;
* Get a feeling for the high code &amp;amp; test quality bar by inspecting the existing test suites and static code analysis results&lt;br /&gt;
* Get familiar with the CI/CD process based on Travis-CI and several associated 3rd party services&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* Javascript, Unit/Integration testing, experience with (or willingness to learn) AngularJS (1.x) and NodeJS/Express, some security knowledge would be preferable.&lt;br /&gt;
&lt;br /&gt;
'''Mentors:'''&lt;br /&gt;
* [[User:Bjoern_Kimminich|Bjoern Kimminich]] - OWASP Juice Shop Project Leader&lt;br /&gt;
* [[User:Timo Pagel|Timo Pagel]] - OWASP Juice Shop Project Collaborator&lt;br /&gt;
* Jannik Hollenbach - OWASP Juice Shop Project Collaborator&lt;br /&gt;
&lt;br /&gt;
=== Frontend Technology Update ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
Development of OWASP Juice Shop started in 2014 and was based on - back then - quite recent Javascript frontend framework AngularJS 1.x along with Bootstrap 3. Several major releases later, there now are [https://github.com/bkimminich/juice-shop/issues/165 Angular 5] and [https://github.com/bkimminich/juice-shop/issues/400 Bootstrap 4] available as well as other mature web frontend frameworks. Migrating the OWASP Juice Shop to the latest version of Angular and Bootstrap is an important step to keep the application relevant as ''the most modern'' intentionally broken web application. Moving to entirely different frameworks might be taken into considerationas well.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* High-level target client-architecture overview including a migration plan with intermediary milestones&lt;br /&gt;
* Execution of migration without breaking functionality or losing tests along the way&lt;br /&gt;
* Code follows existing (or new) styleguides and passes all existing (or new) quality gates regarding code smells, test coverage etc.&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
* Get familiar with the architecture and code base of the application's rich Javascript frontend and RESTful backend&lt;br /&gt;
* Get a feeling for the high code &amp;amp; test quality bar by inspecting the existing test suites and static code analysis results&lt;br /&gt;
* Get familiar with the CI/CD process based on Travis-CI and several associated 3rd party services&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* Javascript, experience with latest Javascript frameworks for frontend, testing and building&lt;br /&gt;
&lt;br /&gt;
'''Mentors:'''&lt;br /&gt;
* [[User:Bjoern_Kimminich|Bjoern Kimminich]] - OWASP Juice Shop Project Leader&lt;br /&gt;
* Jannik Hollenbach - OWASP Juice Shop Project Collaborator&lt;br /&gt;
&lt;br /&gt;
=== UI/Graphics Design Update ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
The UI of OWASP Juice Shop was written following recommendations from Twitter Bootstrap to be responsive, but it never had an actual designer or graphics artist take a look or add some insight. Currently the look &amp;amp; feel comes &amp;quot;out of the box&amp;quot; from a [https://bootswatch.com Bootswatch] theme and [https://fontawesome.com Font Awesome 5] icons. This gives it a quite modern look, but also leaves it very generic. The project could greatly benefit from involvement of someone with actual UI/UX Design expertise. Having a matching theme for [https://ctfd.io CTFd] would be another big achievement for the Juice Shop.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* Design concepts to pick or have the user community vote on (including color schemes, sample screens, icons etc.)&lt;br /&gt;
* Overhauling the overall UI look &amp;amp; feel, e.g. by making an individual Bootswatch theme or designing some individual icons&lt;br /&gt;
* Getting rid of the stock images by providing individually designed product images for the standard inventory of the shop&lt;br /&gt;
* Add more flexibility and options to the existing theming/customization of the UI (see [https://github.com/bkimminich/juice-shop/issues/379 #379])&lt;br /&gt;
* Design a [https://github.com/bkimminich/juice-shop-ctf/issues/9 &amp;quot;Juice Shop&amp;quot; CTFd-theme] playing well with the look &amp;amp; feel of the application&lt;br /&gt;
* Execution of migration without breaking functionality or client-side unit and end-to-end tests along the way&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
* Get familiar with the existing HTML views and CSS of the frontend&lt;br /&gt;
* Get a feeling for the high quality bar by inspecting the existing client-side unit and e2e test suites&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* Strong web and graphic design experience&lt;br /&gt;
* Sophisticated HTML and CSS experience&lt;br /&gt;
&lt;br /&gt;
'''Mentors:'''&lt;br /&gt;
* [[User:Bjoern_Kimminich|Bjoern Kimminich]] - OWASP Juice Shop Project Leader&lt;br /&gt;
* [[User:Timo Pagel|Timo Pagel]] - OWASP Juice Shop Project Collaborator&lt;br /&gt;
* Jannik Hollenbach - OWASP Juice Shop Project Collaborator&lt;br /&gt;
&lt;br /&gt;
=== Your idea ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
You have an awesome idea to improve OWASP Juice Shop that is not on this list? Great, please submit it!&lt;br /&gt;
&lt;br /&gt;
''' Getting started '''&lt;br /&gt;
* Get in touch with [https://www.owasp.org/index.php/User:Bjoern_Kimminich Bjoern Kimminich]&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* A new feature that makes OWASP Juice Shop even better&lt;br /&gt;
* Code follows existing styleguides and passes all existing quality gates regarding code smells, test coverage etc.&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* Javascript, Unit/Integration testing, experience with (or willingness to learn) AngularJS and NodeJS/Express, some security knowledge would be preferable.&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' &lt;br /&gt;
* [[User:Bjoern_Kimminich|Bjoern Kimminich]] - OWASP Juice Shop Project Leader&lt;br /&gt;
&lt;br /&gt;
==OWASP Security Knowledge Framework==&lt;br /&gt;
===Brief Explanation===&lt;br /&gt;
The OWASP Security Knowledge Framework is intended to be a tool that is used as a guide for building and verifying secure software. It can also be used to train developers about application security. Education is the first step in the Secure Software Development Lifecycle. This software can be run on Windows/Linux/OSX using python-flask.&lt;br /&gt;
&lt;br /&gt;
'''In a nutshell'''&lt;br /&gt;
&lt;br /&gt;
- Training developers in writing secure code&lt;br /&gt;
&lt;br /&gt;
- Security support pre-development ( Security by design, early feedback of possible security issues )&lt;br /&gt;
&lt;br /&gt;
- Security support post-development ( Double check your code by means of the OWASP ASVS checklists )&lt;br /&gt;
&lt;br /&gt;
- Code examples for secure coding&lt;br /&gt;
===Your idea / Getting started===&lt;br /&gt;
*Please send an email to riccardo.ten.cate@owasp.org [riccardo.ten.cate@owasp.org] or glenn.ten.cate@owasp.org [glenn.ten.cate@owasp.org] and we would love to tell you all about it! :-)&lt;br /&gt;
===Expected Results===&lt;br /&gt;
*Adding features to SKF project&lt;br /&gt;
**https://github.com/blabla1337/skf-flask/issues/369&lt;br /&gt;
**https://github.com/blabla1337/skf-flask/issues/367&lt;br /&gt;
**https://github.com/blabla1337/skf-flask/issues/68&lt;br /&gt;
**https://github.com/blabla1337/skf-flask/issues/95&lt;br /&gt;
*Adding/updating code examples ( PHP, Java, .NET, Go, Python, NodeJS and more )&lt;br /&gt;
*Adding/updating knowledge base items&lt;br /&gt;
*Adding CWE references to knowledgebase items&lt;br /&gt;
**https://github.com/blabla1337/skf-flask/issues/35&lt;br /&gt;
*Improve unit testing of the Angular quality, currently only 68% of the front-end is unit tested automated &lt;br /&gt;
**https://github.com/blabla1337/skf-flask/issues/352&lt;br /&gt;
===Knowledge Prerequisites===&lt;br /&gt;
*For helping in the development of new features and functions  you need Python flask and for the frond-end we use Angular 4.0&lt;br /&gt;
*For writing knowledgebase items only technical knowledge of application security is required&lt;br /&gt;
*For writing / updating code examples you need to know a programming language along with secure development.&lt;br /&gt;
*For writing the verification guide you need some penetration testing experience.&lt;br /&gt;
'''Mentors:'''&lt;br /&gt;
&lt;br /&gt;
Riccardo ten Cate [mailto:riccardo.ten.cate@owasp.org] Glenn ten Cate [mailto:glenn.ten.cate@owasp.org]&lt;br /&gt;
&lt;br /&gt;
==OWASP Nettacker==&lt;br /&gt;
===Brief Explanation===&lt;br /&gt;
OWASP Nettacker project is created to automate information gathering, vulnerability scanning and eventually generating a report for networks, including services, bugs, vulnerabilities, misconfigurations, and other information. This software will utilize TCP SYN, ACK, ICMP and many other protocols in order to detect and bypass Firewall/IDS/IPS devices. By leveraging a unique method in OWASP Nettacker for discovering protected services and devices such as SCADA. It would make a competitive edge compared to other scanner making it one of the bests.&lt;br /&gt;
&lt;br /&gt;
if you need more details please visit the [https://github.com/viraintel/OWASP-Nettacker GitHub page] or contact a leader([mailto:ali.razmjoo@owasp.org Ali Razmjoo Qalaei], [mailto:reza.espargham@owasp.org Reza Espargham]).&lt;br /&gt;
&lt;br /&gt;
===Getting started===&lt;br /&gt;
&lt;br /&gt;
* You may read the available documents in the [https://github.com/viraintel/OWASP-Nettacker/wiki wiki page]. Developers and users documents are separated.&lt;br /&gt;
&lt;br /&gt;
'''A Better Penetration Testing Automated Framework'''&lt;br /&gt;
&lt;br /&gt;
===Expected Results===&lt;br /&gt;
The expected results are to contribute the OWASP Nettacker framework [https://github.com/viraintel/OWASP-Nettacker/issues issues] (mostly help wanted or enhancement). Please check the GitHub repo to learn more.&lt;br /&gt;
&lt;br /&gt;
===Knowledge Prerequisites===&lt;br /&gt;
&lt;br /&gt;
* The whole framework was written in Python language. You must be familiar with Python 2.x, 3.x.&lt;br /&gt;
* Good knowledge of computer security (and penetration testing)&lt;br /&gt;
* Knowledge of OS (Linux, Windows, Mac...) and Services&lt;br /&gt;
* Familiar with IDS/IPS/Firewalls and ...&lt;br /&gt;
* To develop the API you should be familiar with HTTP, Database...&lt;br /&gt;
&lt;br /&gt;
===Mentors===&lt;br /&gt;
Mentors are: [mailto:ali.razmjoo@owasp.org Ali Razmjoo Qalaei], [mailto:abiusx@owasp.org Abbas Naderi Afooshteh]&lt;br /&gt;
&lt;br /&gt;
==OWASP OWTF==&lt;br /&gt;
'''[https://github.com/owtf/owtf Offensive Web Testing Framework (OWTF)]''' is a project focused on penetration testing efficiency and alignment of security tests to security standards like the OWASP Testing Guide (v3 and v4), the OWASP Top 10, PTES and NIST. Most of the ideas below focus on rewrite of some major components of OWTF to make it more modular. OWTF is moving to a fresh codebase with a fully Docker testing and deployment environment. If you want to get a jumpstart, check out https://github.com/owtf/owtf/tree/new-arch.&lt;br /&gt;
===OWASP OWTF - MiTM proxy interception and replay capabilities===&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
The OWTF man-in-the-middle proxy is written completely in Python (based on the excellent Tornado framework) and was benchmarked to be the fastest MiTM python proxy. However it lacks the useful and much need interception and replay capabilities of mitmproxy (https://github.com/mitmproxy/mitmproxy).&lt;br /&gt;
&lt;br /&gt;
The current implementation of the MiTM proxy serves its purpose very well. Its fast but its not extensible. There are a number of good use cases for being extensible&lt;br /&gt;
*ability to intercept the transactions&lt;br /&gt;
*modify or replay transaction on the fly&lt;br /&gt;
*add additional capabilities to the proxy (such as session marking/changing) without polluting the main proxy code&lt;br /&gt;
Bonus:&lt;br /&gt;
*Design and implement a proxy plugin (middleware) architecture so that the plugins can be defined separately and the user can choose what plugins to include dynamically (from the web interface).&lt;br /&gt;
*Replace the current Requester (based on urllib, urllib2) with a more robust Requester based on the new urllib3 with support for a real headless browser factory. The typical flow when requested for an authenticated browser instance (using PhantomJS)&lt;br /&gt;
&lt;br /&gt;
*The &amp;quot;Requester&amp;quot; module checks if there is any login parameters provided (i.e form-based or script - look at https://github.com/owtf/login-sessions-plugin)&lt;br /&gt;
*Create a browser instance and do the necessary login procedure&lt;br /&gt;
*Handle the browser for the URI&lt;br /&gt;
*When called to close the browser, do a clean logout and kill the browser instance.&lt;br /&gt;
'''Expected results:'''&lt;br /&gt;
*'''IMPORTANT: [http://legacy.python.org/dev/peps/pep-0008/ PEP-8 compliant code] in all modified code and surrounding areas.'''&lt;br /&gt;
*'''IMPORTANT: [https://github.com/7a/owtf/wiki/Contributor%27s-README OWTF contributor README compliant code]'''&lt;br /&gt;
*'''IMPORTANT: [http://sphinx-doc.org/ Sphinx-friendly python comments] [http://owtf.github.io/ptp/_modules/ptp/tools/w3af/parser.html#W3AFXMLParser example Sphinx-friendly python comments here]'''&lt;br /&gt;
*CRITICAL: Excellent reliability&lt;br /&gt;
*Good performance&lt;br /&gt;
*Unit tests / Functional tests&lt;br /&gt;
*Good documentation&lt;br /&gt;
'''Knowledge Prerequisite:''' Python proficiency, some previous exposure to security concepts and penetration testing is welcome but not strictly necessary as long as there is will to learn.&lt;br /&gt;
&lt;br /&gt;
'''OWASP OWTF Mentors:''' Contact: [mailto:Abraham.Aranguren@owasp.org Abraham Aranguren][mailto:viyat.bhalodia@owasp.org Viyat Bhalodia][mailto:bharadwaj.machiraju@gmail.com Bharadwaj Machiraju] OWASP OWTF Project Leaders&lt;br /&gt;
===OWASP OWTF - Web interface enhancements===&lt;br /&gt;
'''Brief explanation:'''&lt;br /&gt;
&lt;br /&gt;
The current web interface is a mixture of Tornado Jinja templates and ReactJS. A complete UI change to a stable ReactJS-based interface should be the deliverable for this project.  Most of the hard part for the change has already been done and added in a separate branch at https://github.com/owtf/owtf/tree/ui-break.&lt;br /&gt;
&lt;br /&gt;
For background on OWASP OWTF please see: https://www.owasp.org/index.php/OWASP_OWTF&lt;br /&gt;
&lt;br /&gt;
'''Expected results:'''&lt;br /&gt;
*'''IMPORTANT:Clean, maintainable (ES6 compatible and using recommended design patterns) React (JavaScript) code. ([https://github.com/getsentry/zeus/tree/master/webapp This] is a good example!)'''&lt;br /&gt;
*'''IMPORTANT: Thoroughly documented code along with API examples and example future components.'''&lt;br /&gt;
*'''CRITICAL''': Excellent reliability and performance.&lt;br /&gt;
*Unit tests / Functional tests and easy to setup testing environment (preferably automated).&lt;br /&gt;
'''Knowledge Prerequisite:''' Python (reading API source code and endpoints), React.JS (high proficiency) and general JavaScript proficiency.&lt;br /&gt;
&lt;br /&gt;
'''OWASP OWTF Mentors:''' Contact: [mailto:Abraham.Aranguren@owasp.org Abraham Aranguren][mailto:viyat.bhalodia@owasp.org Viyat Bhalodia][mailto:bharadwaj.machiraju@gmail.com Bharadwaj Machiraju] OWASP OWTF Project Leaders&lt;br /&gt;
===OWASP OWTF - New plugin architecture===&lt;br /&gt;
'''Brief explanation:'''&lt;br /&gt;
&lt;br /&gt;
The current plugin system is not very useful and it is painful to browse many plugins. Most of the plugins do have much code and most of is repeated - much refactoring needed there.&lt;br /&gt;
&lt;br /&gt;
This issue is documented in detail at https://github.com/owtf/owtf/issues/905.&lt;br /&gt;
&lt;br /&gt;
For background on OWASP OWTF please see: https://www.owasp.org/index.php/OWASP_OWTF&lt;br /&gt;
&lt;br /&gt;
'''Expected results:'''&lt;br /&gt;
*'''IMPORTANT: [http://legacy.python.org/dev/peps/pep-0008/ PEP-8 compliant code] in all modified code and surrounding areas.'''&lt;br /&gt;
*'''IMPORTANT: [https://github.com/7a/owtf/wiki/Contributor%27s-README OWTF contributor README compliant code]'''&lt;br /&gt;
*'''IMPORTANT: [http://sphinx-doc.org/ Sphinx-friendly python comments] [http://owtf.github.io/ptp/_modules/ptp/tools/w3af/parser.html#W3AFXMLParser example Sphinx-friendly python comments here]'''&lt;br /&gt;
*CRITICAL: Excellent reliability&lt;br /&gt;
*Good performance&lt;br /&gt;
*Unit tests / Functional tests&lt;br /&gt;
*Good documentation&lt;br /&gt;
&lt;br /&gt;
== OWASP CSRF Protector ==&lt;br /&gt;
[[CSRFProtector Project|OWASP CSRF Protector Project]] is a project started with the goal to help developer to mitigate CSRF in web applications with ease. It's based on [[Cross-Site Request Forgery (CSRF) Prevention Cheat Sheet|Synchronizer Token Pattern]] and leverages an injected java-script code to provide CSRF mitigation without much developer intervention. So far it has been implemented as a [https://github.com/mebjas/CSRF-Protector-PHP PHP Library] and an [[CSRFProtector Project|Apache 2.2.x module]]. Although different libraries and frameworks provide CSRF mitigation these days - all of them require developer to explicitly inject tokens with every form. &lt;br /&gt;
===OWASP CSRF Protector - Extending the design as a python package to work with Flask and an Express JS (Node.JS) middleware===&lt;br /&gt;
'''Brief explanation:'''&lt;br /&gt;
&lt;br /&gt;
The design of CSRF Protector involves a server side middle-ware that intercepts every incoming request and validates them for CSRF attacks. If the validation is successful the flow of control goes to business logic and the tokens are refreshed. In case of failed validation configured actions are taken. Post that, another middle ware takes care of injecting a JavaScript code (refer [https://github.com/mebjas/CSRF-Protector-PHP/blob/master/js/csrfprotector.js CSRF Protector PHP JS Code]) to HTML output. On the client side this code ensures that, for every request that require validation - the correct token is sent along with the request.&lt;br /&gt;
&lt;br /&gt;
Check [https://github.com/mebjas/CSRF-Protector-PHP/wiki GitHub Wiki] for some reference;&lt;br /&gt;
&lt;br /&gt;
The goal of this project would be to:&lt;br /&gt;
# Port this design to a python module that can be used easily with Flask - [https://github.com/mebjas/CSRF-Protector-py/projects/1?add_cards_query=is%3Aopen Kanban Board]&lt;br /&gt;
# Port this design to a node js module that can work well with express js (a popular Node.JS based framework). - [https://github.com/mebjas/CSRF-Protector-JS Initial Repo Link]&lt;br /&gt;
# Fix some outstanding issues with java-script code used in library: [https://github.com/mebjas/CSRF-Protector-PHP/issues?q=is%3Aopen+is%3Aissue+label%3AJS Issues] &lt;br /&gt;
'''Expected results:'''&lt;br /&gt;
*'''IMPORTANT: Clean, maintainable (ES6 compatible and using recommended design patterns) in case of Node.JS'''&lt;br /&gt;
*'''IMPORTANT: [http://legacy.python.org/dev/peps/pep-0008/ PEP-8 compliant code] in all modified code and surrounding areas.'''&lt;br /&gt;
*'''IMPORTANT: Thoroughly documented code along with API examples and example future components.'''&lt;br /&gt;
*'''CRITICAL''': Excellent reliability and performance.&lt;br /&gt;
*Unit tests / Functional tests and easy to setup testing environment (preferably automated).&lt;br /&gt;
'''Knowledge Prerequisite:''' Javascript (Client Side), Python (having worked with flask preferable), Node.JS (having worked with node.js and middle wares preferable)&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' Contact: [mailto:minhaz@owasp.org;minhazv@microsoft.com Minhaz A V]&lt;/div&gt;</summary>
		<author><name>Psiinon</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=GSOC2018_Ideas&amp;diff=236757</id>
		<title>GSOC2018 Ideas</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=GSOC2018_Ideas&amp;diff=236757"/>
				<updated>2018-01-12T10:56:20Z</updated>
		
		<summary type="html">&lt;p&gt;Psiinon: Added some more ZAP project suggestions&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=OWASP Project Requests=&lt;br /&gt;
&lt;br /&gt;
'''Tips to get you started in no particular order:''' &lt;br /&gt;
 '''* Read [https://developers.google.com/open-source/gsoc/ Google Summer of Code Program(GSOC)]'''&lt;br /&gt;
 '''* Read the [[GSoC SAT]] '''&lt;br /&gt;
 * Read the [https://www.owasp.org/index.php/GSoC GSOC Student Guidelines]&lt;br /&gt;
 * Contact us through the mailing list or irc channel.&lt;br /&gt;
 * Check our [https://github.com/OWASP github organization]&lt;br /&gt;
==OWASP ZAP==&lt;br /&gt;
[[OWASP Zed Attack Proxy Project]] (ZAP) The OWASP Zed Attack Proxy (ZAP) is one of the world’s most popular free security tools and is actively maintained by hundreds of international volunteers. Previous GSoC students have implemented key parts of the ZAP core functionality and have been offered (and accepted) jobs based on their work on ZAP.&lt;br /&gt;
&lt;br /&gt;
We have just included a few of the ideas we have here, for a more complete list see the issues on the ZAP bug tracker with the [https://github.com/zaproxy/zaproxy/issues?q=is%3Aopen+is%3Aissue+label%3Aproject project] label.&lt;br /&gt;
===React Handling===&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
ZAP doesnt understand React applications as well as it should be able to.&lt;br /&gt;
&lt;br /&gt;
It would be great if ZAP had a much better understanding of such applications, including how to explore and attack them more effectively.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* ZAP able to explore React applications more effectively&lt;br /&gt;
* ZAP able to attack React applications more effectively&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
&lt;br /&gt;
* Have a look at the ZAP [https://github.com/zaproxy/zaproxy/blob/develop/CONTRIBUTING.md CONTRIBUTING.md] file, especially the 'Coding section.&lt;br /&gt;
* We like to see students who have already contributed to ZAP, so try fixing one of the bugs flagged as [https://github.com/zaproxy/zaproxy/issues?q=is%3Aopen+is%3Aissue+label%3AIdealFirstBug IdealFirstBug].&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* As React is written in JavaScript, good knowledge of this language is recommended. ZAP is written in Java, so some knowledge of this language would be useful. Some knowledge of application security would be useful, but not essential.&lt;br /&gt;
'''Mentors:''' [https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @] and the rest of the ZAP Core Team&lt;br /&gt;
&lt;br /&gt;
=== Automated authentication detection and configuration  ===&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
Currently a user must manually configure ZAP to handle authentication, eg as per &amp;lt;nowiki&amp;gt;https://github.com/zaproxy/zaproxy/wiki/FAQformauth&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This is time consuming and error prone.&lt;br /&gt;
&lt;br /&gt;
Ideally ZAP would help detect login and registration pages and provide more assistance when configuring authentication, ideally being able to completely automate the task for as many sort of webapps as possible.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* Detect login and registration pages&lt;br /&gt;
* Provide a wizard to walk users through the process of setting up authentication, with as much assistance as possible&lt;br /&gt;
* An option to completely automate the authentication process, for as many authentication mechanisms as possible&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
&lt;br /&gt;
* Have a look at the ZAP [https://github.com/zaproxy/zaproxy/blob/develop/CONTRIBUTING.md CONTRIBUTING.md] file, especially the 'Coding section.&lt;br /&gt;
* We like to see students who have already contributed to ZAP, so try fixing one of the bugs flagged as [https://github.com/zaproxy/zaproxy/issues?q=is%3Aopen+is%3Aissue+label%3AIdealFirstBug IdealFirstBug].&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* ZAP is written in Java, so a good knowledge of this language is recommended. Some knowledge of application security would be useful, but not essential.&lt;br /&gt;
'''Mentors:''' [https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @] and the rest of the ZAP Core Team&lt;br /&gt;
&lt;br /&gt;
=== Zest Text Representation and Parser ===&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
Zest is a graphical scripting language from the Mozilla Security team, and is used as the ZAP macro language.&lt;br /&gt;
&lt;br /&gt;
A standardized text representation and parser would be very useful and help its adoption.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* A documented definition of a text representation for Zest&lt;br /&gt;
* A parser that converts the text representation into a working Zest script&lt;br /&gt;
* An option in the Zest java implementation to output Zest scripts text format&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
&lt;br /&gt;
* Have a look at the ZAP [https://github.com/zaproxy/zaproxy/blob/develop/CONTRIBUTING.md CONTRIBUTING.md] file, especially the 'Coding section.&lt;br /&gt;
* We like to see students who have already contributed to ZAP, so try fixing one of the bugs flagged as [https://github.com/zaproxy/zaproxy/issues?q=is%3Aopen+is%3Aissue+label%3AIdealFirstBug IdealFirstBug].&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* The Zest reference implementation is written in Java, so a good knowledge of this language is recommended. Some knowledge of application security would be useful, but not essential.&lt;br /&gt;
'''Mentors:''' [https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @] and the rest of the ZAP Core Team&lt;br /&gt;
&lt;br /&gt;
=== Develop Bamboo Addon ===&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
It would be great to have an official ZAP add-on for [https://www.atlassian.com/software/bamboo Bamboo], equivalent to the one we now have for [https://wiki.jenkins.io/display/JENKINS/zap+plugin Jenkins]&lt;br /&gt;
&lt;br /&gt;
For more information about Bamboo plugins see the [https://developer.atlassian.com/server/bamboo/bamboo-plugin-guide/ Bamboo plugin guide].&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
&lt;br /&gt;
A Bamboo addon that supports:&lt;br /&gt;
* Spidering (using the traditional and Ajax spiders)&lt;br /&gt;
* Active Scanning&lt;br /&gt;
* Authentication&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
&lt;br /&gt;
* Have a look at the ZAP [https://github.com/zaproxy/zaproxy/blob/develop/CONTRIBUTING.md CONTRIBUTING.md] file, especially the 'Coding section.&lt;br /&gt;
* We like to see students who have already contributed to ZAP, so try fixing one of the bugs flagged as [https://github.com/zaproxy/zaproxy/issues?q=is%3Aopen+is%3Aissue+label%3AIdealFirstBug IdealFirstBug].&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* ZAP and Bamboo are written in Java, so a good knowledge of this language is recommended. Some knowledge of application security would be useful, but not essential.&lt;br /&gt;
'''Mentors:''' [https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @] and the rest of the ZAP Core Team&lt;br /&gt;
&lt;br /&gt;
=== Your Idea ===&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
ZAP is a great framework for building new and innovative security testing solutions. If you have an idea that is not on this list then don't worry, you can still submit it, we have accepted original projects in previous years and have even paid a student to work on their idea when we did not get enough GSoC slots to accept all of the projects we wanted.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* A new feature that makes ZAP even better&lt;br /&gt;
* Code that conforms to our Development Rules and Guidelines&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
&lt;br /&gt;
* Have a look at the ZAP [https://github.com/zaproxy/zaproxy/blob/develop/CONTRIBUTING.md CONTRIBUTING.md] file, especially the 'Coding section.&lt;br /&gt;
* We like to see students who have already contributed to ZAP, so try fixing one of the bugs flagged as [https://github.com/zaproxy/zaproxy/issues?q=is%3Aopen+is%3Aissue+label%3AIdealFirstBug IdealFirstBug].&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* ZAP is written in Java, so a good knowledge of this language is recommended. Some knowledge of application security would be useful, but not essential.&lt;br /&gt;
'''Mentors:''' [https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @] and the rest of the ZAP Core Team&lt;br /&gt;
&lt;br /&gt;
== OWASP Juice Shop ==&lt;br /&gt;
&lt;br /&gt;
[[OWASP Juice Shop Project]] is an intentionally insecure webapp for security trainings written entirely in Javascript which encompasses the entire OWASP Top Ten and other severe security flaws. Juice Shop is written in Node.js, Express and AngularJS. The application contains more than 30 challenges of varying difficulty where the user is supposed to exploit the underlying vulnerabilities. Apart from the hacker and awareness training use case, pentesting proxies or security scanners can use Juice Shop as a &amp;quot;guinea pig&amp;quot;-application to check how well their tools cope with Javascript-heavy application frontends and REST APIs.&lt;br /&gt;
&lt;br /&gt;
=== Challenge Pack 2018 ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
Ideas for potential new hacking challenges are collected in [https://github.com/bkimminich/juice-shop/issues?q=is%3Aissue+is%3Aopen+label%3Achallenge GitHub issues labeled &amp;quot;challenge&amp;quot;]. This project could implement a whole bunch of challenges one by one and release them over the course of several small releases. This would allow the student to work in a professional Continuous Delivery kind of way while bringing benefit to the Juice Shop over the duration of the project.&lt;br /&gt;
&lt;br /&gt;
Coming up with additional ideas for challenges would be part of the project scope, as the list of pre-existing ideas might not be sufficient for a GSoC project.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* 10 or more new challenges for OWASP Juice Shop (including required functional enhancements to place the challenges in, e.g. the [https://github.com/bkimminich/juice-shop/issues/244 Order Dashboard] user story])&lt;br /&gt;
* Each challenge comes with full functional unit and integration tests&lt;br /&gt;
* Each challenge is verified to be exploitable by corresponding end-to-end tests&lt;br /&gt;
* Hint and solution sections for each new challenge are added to the &amp;quot;Pwning OWASP Juice Shop&amp;quot; ebook&lt;br /&gt;
* Code follows existing styleguides and passes all existing quality gates regarding code smells, test coverage etc.&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
* Get familiar with the architecture and code base of the application's rich Javascript frontend and RESTful backend&lt;br /&gt;
* Get a feeling for the high code &amp;amp; test quality bar by inspecting the existing test suites and static code analysis results&lt;br /&gt;
* Get familiar with the CI/CD process based on Travis-CI and several associated 3rd party services&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* Javascript, Unit/Integration testing, experience with (or willingness to learn) AngularJS (1.x) and NodeJS/Express, some security knowledge would be preferable.&lt;br /&gt;
&lt;br /&gt;
'''Mentors:'''&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Bjoern_Kimminich Bjoern Kimminich] - OWASP Juice Shop Project Leader&lt;br /&gt;
&lt;br /&gt;
=== Frontend Technology Update ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
Development of OWASP Juice Shop started in 2014 and was based on - back then - quite recent Javascript frontend framework AngularJS 1.x along with Bootstrap 3. Several major releases later, there now are [https://github.com/bkimminich/juice-shop/issues/165 Angular 5] and [https://github.com/bkimminich/juice-shop/issues/400 Bootstrap 4] available as well as other mature web frontend frameworks. Migrating the OWASP Juice Shop to the latest version of Angular and Bootstrap is an important step to keep the application relevant as ''the most modern'' intentionally broken web application. Moving to entirely different frameworks might be taken into considerationas well.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* High-level target client-architecture overview including a migration plan with intermediary milestones&lt;br /&gt;
* Execution of migration without breaking functionality or losing tests along the way&lt;br /&gt;
* Code follows existing (or new) styleguides and passes all existing (or new) quality gates regarding code smells, test coverage etc.&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
* Get familiar with the architecture and code base of the application's rich Javascript frontend and RESTful backend&lt;br /&gt;
* Get a feeling for the high code &amp;amp; test quality bar by inspecting the existing test suites and static code analysis results&lt;br /&gt;
* Get familiar with the CI/CD process based on Travis-CI and several associated 3rd party services&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* Javascript, experience with latest Javascript frameworks for frontend, testing and building&lt;br /&gt;
&lt;br /&gt;
'''Mentors:'''&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Bjoern_Kimminich Bjoern Kimminich] - OWASP Juice Shop Project Leader&lt;br /&gt;
&lt;br /&gt;
=== UI/Graphics Design Update ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
The UI of OWASP Juice Shop was written following recommendations from Twitter Bootstrap to be responsive, but it never had an actual designer or graphics artist take a look or add some insight. Currently the look &amp;amp; feel comes &amp;quot;out of the box&amp;quot; from a [https://bootswatch.com Bootswatch] theme and [https://fontawesome.com Font Awesome 4] icons. This gives it a quite modern look, but also leaves it very generic. The project could greatly benefit from involvement of someone with actual UI/UX Design expertise. Having a matching theme for [https://ctfd.io CTFd] would be another big achievement for the Juice Shop.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* Design concepts to pick or have the user community vote on (including color schemes, sample screens, icons etc.)&lt;br /&gt;
* Overhauling the overall UI look &amp;amp; feel, e.g. by making an individual Bootswatch theme or designing some individual icons&lt;br /&gt;
* Getting rid of the stock images by providing individually designed product images for the standard inventory of the shop&lt;br /&gt;
* Design a [https://github.com/bkimminich/juice-shop-ctf/issues/9 &amp;quot;Juice Shop&amp;quot; CTFd-theme] playing well with the look &amp;amp; feel of the application&lt;br /&gt;
* Execution of migration without breaking functionality or client-side unit and end-to-end tests along the way&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
* Get familiar with the existing HTML views and CSS of the frontend&lt;br /&gt;
* Get a feeling for the high quality bar by inspecting the existing client-side unit and e2e test suites&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* Strong web and graphic design experience&lt;br /&gt;
* Sophisticated HTML and CSS experience&lt;br /&gt;
&lt;br /&gt;
'''Mentors:'''&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Bjoern_Kimminich Bjoern Kimminich] - OWASP Juice Shop Project Leader&lt;br /&gt;
&lt;br /&gt;
=== Your idea ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
You have an awesome idea to improve OWASP Juice Shop that is not on this list? Great, please submit it!&lt;br /&gt;
&lt;br /&gt;
''' Getting started '''&lt;br /&gt;
* Get in touch with [https://www.owasp.org/index.php/User:Bjoern_Kimminich Bjoern Kimminich]&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* A new feature that makes OWASP Juice Shop even better&lt;br /&gt;
* Code follows existing styleguides and passes all existing quality gates regarding code smells, test coverage etc.&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* Javascript, Unit/Integration testing, experience with (or willingness to learn) AngularJS and NodeJS/Express, some security knowledge would be preferable.&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' &lt;br /&gt;
* [https://www.owasp.org/index.php/User:Bjoern_Kimminich Bjoern Kimminich] - OWASP Juice Shop Project Leader&lt;br /&gt;
&lt;br /&gt;
==OWASP Security Knowledge Framework==&lt;br /&gt;
===Brief Explanation===&lt;br /&gt;
The OWASP Security Knowledge Framework is intended to be a tool that is used as a guide for building and verifying secure software. It can also be used to train developers about application security. Education is the first step in the Secure Software Development Lifecycle. This software can be run on Windows/Linux/OSX using python-flask.&lt;br /&gt;
&lt;br /&gt;
'''In a nutshell'''&lt;br /&gt;
&lt;br /&gt;
- Training developers in writing secure code&lt;br /&gt;
&lt;br /&gt;
- Security support pre-development ( Security by design, early feedback of possible security issues )&lt;br /&gt;
&lt;br /&gt;
- Security support post-development ( Double check your code by means of the OWASP ASVS checklists )&lt;br /&gt;
&lt;br /&gt;
- Code examples for secure coding&lt;br /&gt;
===Your idea / Getting started===&lt;br /&gt;
*Please send an email to riccardo.ten.cate@owasp.org [riccardo.ten.cate@owasp.org] or glenn.ten.cate@owasp.org [glenn.ten.cate@owasp.org] and we would love to tell you all about it! :-)&lt;br /&gt;
===Expected Results===&lt;br /&gt;
*Adding features to SKF project&lt;br /&gt;
**https://github.com/blabla1337/skf-flask/issues/369&lt;br /&gt;
**https://github.com/blabla1337/skf-flask/issues/367&lt;br /&gt;
**https://github.com/blabla1337/skf-flask/issues/68&lt;br /&gt;
**https://github.com/blabla1337/skf-flask/issues/95&lt;br /&gt;
*Adding/updating code examples ( PHP, Java, .NET, Go, Python, NodeJS and more )&lt;br /&gt;
*Adding/updating knowledge base items&lt;br /&gt;
*Adding CWE references to knowledgebase items&lt;br /&gt;
**https://github.com/blabla1337/skf-flask/issues/35&lt;br /&gt;
*Improve unit testing of the Angular quality, currently only 68% of the front-end is unit tested automated &lt;br /&gt;
**https://github.com/blabla1337/skf-flask/issues/352&lt;br /&gt;
===Knowledge Prerequisites===&lt;br /&gt;
*For helping in the development of new features and functions  you need Python flask and for the frond-end we use Angular 4.0&lt;br /&gt;
*For writing knowledgebase items only technical knowledge of application security is required&lt;br /&gt;
*For writing / updating code examples you need to know a programming language along with secure development.&lt;br /&gt;
*For writing the verification guide you need some penetration testing experience.&lt;br /&gt;
'''Mentors:'''&lt;br /&gt;
&lt;br /&gt;
Riccardo ten Cate [mailto:riccardo.ten.cate@owasp.org] Glenn ten Cate [mailto:glenn.ten.cate@owasp.org]&lt;br /&gt;
&lt;br /&gt;
==OWASP Nettacker==&lt;br /&gt;
===Brief Explanation===&lt;br /&gt;
OWASP Nettacker project is created to automate information gathering, vulnerability scanning and eventually generating a report for networks, including services, bugs, vulnerabilities, misconfigurations, and other information. This software will utilize TCP SYN, ACK, ICMP and many other protocols in order to detect and bypass Firewall/IDS/IPS devices. By leveraging a unique method in OWASP Nettacker for discovering protected services and devices such as SCADA. It would make a competitive edge compared to other scanner making it one of the bests.&lt;br /&gt;
&lt;br /&gt;
if you need more details please visit the [https://github.com/viraintel/OWASP-Nettacker GitHub page] or contact a leader([mailto:ali.razmjoo@owasp.org Ali Razmjoo Qalaei], [mailto:reza.espargham@owasp.org Reza Espargham]).&lt;br /&gt;
&lt;br /&gt;
===Getting started===&lt;br /&gt;
&lt;br /&gt;
* You may read the available documents in the [https://github.com/viraintel/OWASP-Nettacker/wiki wiki page]. Developers and users documents are separated.&lt;br /&gt;
&lt;br /&gt;
'''A Better Penetration Testing Automated Framework'''&lt;br /&gt;
&lt;br /&gt;
===Expected Results===&lt;br /&gt;
The expected results are to contribute the OWASP Nettacker framework [https://github.com/viraintel/OWASP-Nettacker/issues issues] (mostly help wanted or enhancement). Please check the GitHub repo to learn more.&lt;br /&gt;
&lt;br /&gt;
===Knowledge Prerequisites===&lt;br /&gt;
&lt;br /&gt;
* The whole framework was written in Python language. You must be familiar with Python 2.x, 3.x.&lt;br /&gt;
* Good knowledge of computer security (and penetration testing)&lt;br /&gt;
* Knowledge of OS (Linux, Windows, Mac...) and Services&lt;br /&gt;
* Familiar with IDS/IPS/Firewalls and ...&lt;br /&gt;
* To develop the API you should be familiar with HTTP, Database...&lt;br /&gt;
&lt;br /&gt;
===Mentors===&lt;br /&gt;
Mentors are: [mailto:ali.razmjoo@owasp.org Ali Razmjoo Qalaei], [mailto:abiusx@owasp.org Abbas Naderi Afooshteh]&lt;br /&gt;
&lt;br /&gt;
==OWASP OWTF==&lt;br /&gt;
'''[https://github.com/owtf/owtf Offensive Web Testing Framework (OWTF)]''' is a project focused on penetration testing efficiency and alignment of security tests to security standards like the OWASP Testing Guide (v3 and v4), the OWASP Top 10, PTES and NIST. Most of the ideas below focus on rewrite of some major components of OWTF to make it more modular. OWTF is moving to a fresh codebase with a fully Docker testing and deployment environment. If you want to get a jumpstart, check out https://github.com/owtf/owtf/tree/new-arch.&lt;br /&gt;
===OWASP OWTF - MiTM proxy interception and replay capabilities===&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
The OWTF man-in-the-middle proxy is written completely in Python (based on the excellent Tornado framework) and was benchmarked to be the fastest MiTM python proxy. However it lacks the useful and much need interception and replay capabilities of mitmproxy (https://github.com/mitmproxy/mitmproxy).&lt;br /&gt;
&lt;br /&gt;
The current implementation of the MiTM proxy serves its purpose very well. Its fast but its not extensible. There are a number of good use cases for being extensible&lt;br /&gt;
*ability to intercept the transactions&lt;br /&gt;
*modify or replay transaction on the fly&lt;br /&gt;
*add additional capabilities to the proxy (such as session marking/changing) without polluting the main proxy code&lt;br /&gt;
Bonus:&lt;br /&gt;
*Design and implement a proxy plugin (middleware) architecture so that the plugins can be defined separately and the user can choose what plugins to include dynamically (from the web interface).&lt;br /&gt;
*Replace the current Requester (based on urllib, urllib2) with a more robust Requester based on the new urllib3 with support for a real headless browser factory. The typical flow when requested for an authenticated browser instance (using PhantomJS)&lt;br /&gt;
&lt;br /&gt;
*The &amp;quot;Requester&amp;quot; module checks if there is any login parameters provided (i.e form-based or script - look at https://github.com/owtf/login-sessions-plugin)&lt;br /&gt;
*Create a browser instance and do the necessary login procedure&lt;br /&gt;
*Handle the browser for the URI&lt;br /&gt;
*When called to close the browser, do a clean logout and kill the browser instance.&lt;br /&gt;
'''Expected results:'''&lt;br /&gt;
*'''IMPORTANT: [http://legacy.python.org/dev/peps/pep-0008/ PEP-8 compliant code] in all modified code and surrounding areas.'''&lt;br /&gt;
*'''IMPORTANT: [https://github.com/7a/owtf/wiki/Contributor%27s-README OWTF contributor README compliant code]'''&lt;br /&gt;
*'''IMPORTANT: [http://sphinx-doc.org/ Sphinx-friendly python comments] [http://owtf.github.io/ptp/_modules/ptp/tools/w3af/parser.html#W3AFXMLParser example Sphinx-friendly python comments here]'''&lt;br /&gt;
*CRITICAL: Excellent reliability&lt;br /&gt;
*Good performance&lt;br /&gt;
*Unit tests / Functional tests&lt;br /&gt;
*Good documentation&lt;br /&gt;
'''Knowledge Prerequisite:''' Python proficiency, some previous exposure to security concepts and penetration testing is welcome but not strictly necessary as long as there is will to learn.&lt;br /&gt;
&lt;br /&gt;
'''OWASP OWTF Mentors:''' Contact: [mailto:Abraham.Aranguren@owasp.org Abraham Aranguren][mailto:viyat.bhalodia@owasp.org Viyat Bhalodia][mailto:bharadwaj.machiraju@gmail.com Bharadwaj Machiraju] OWASP OWTF Project Leaders&lt;br /&gt;
===OWASP OWTF - Web interface enhancements===&lt;br /&gt;
'''Brief explanation:'''&lt;br /&gt;
&lt;br /&gt;
The current web interface is a mixture of Tornado Jinja templates and ReactJS. A complete UI change to a stable ReactJS-based interface should be the deliverable for this project.  Most of the hard part for the change has already been done and added in a separate branch at https://github.com/owtf/owtf/tree/ui-break.&lt;br /&gt;
&lt;br /&gt;
For background on OWASP OWTF please see: https://www.owasp.org/index.php/OWASP_OWTF&lt;br /&gt;
&lt;br /&gt;
'''Expected results:'''&lt;br /&gt;
*'''IMPORTANT:Clean, maintainable (ES6 compatible and using recommended design patterns) React (JavaScript) code. ([https://github.com/getsentry/zeus/tree/master/webapp This] is a good example!)'''&lt;br /&gt;
*'''IMPORTANT: Thoroughly documented code along with API examples and example future components.'''&lt;br /&gt;
*'''CRITICAL''': Excellent reliability and performance.&lt;br /&gt;
*Unit tests / Functional tests and easy to setup testing environment (preferably automated).&lt;br /&gt;
'''Knowledge Prerequisite:''' Python (reading API source code and endpoints), React.JS (high proficiency) and general JavaScript proficiency.&lt;br /&gt;
&lt;br /&gt;
'''OWASP OWTF Mentors:''' Contact: [mailto:Abraham.Aranguren@owasp.org Abraham Aranguren][mailto:viyat.bhalodia@owasp.org Viyat Bhalodia][mailto:bharadwaj.machiraju@gmail.com Bharadwaj Machiraju] OWASP OWTF Project Leaders&lt;br /&gt;
===OWASP OWTF - New plugin architecture===&lt;br /&gt;
'''Brief explanation:'''&lt;br /&gt;
&lt;br /&gt;
The current plugin system is not very useful and it is painful to browse many plugins. Most of the plugins do have much code and most of is repeated - much refactoring needed there.&lt;br /&gt;
&lt;br /&gt;
This issue is documented in detail at https://github.com/owtf/owtf/issues/905.&lt;br /&gt;
&lt;br /&gt;
For background on OWASP OWTF please see: https://www.owasp.org/index.php/OWASP_OWTF&lt;br /&gt;
&lt;br /&gt;
'''Expected results:'''&lt;br /&gt;
*'''IMPORTANT: [http://legacy.python.org/dev/peps/pep-0008/ PEP-8 compliant code] in all modified code and surrounding areas.'''&lt;br /&gt;
*'''IMPORTANT: [https://github.com/7a/owtf/wiki/Contributor%27s-README OWTF contributor README compliant code]'''&lt;br /&gt;
*'''IMPORTANT: [http://sphinx-doc.org/ Sphinx-friendly python comments] [http://owtf.github.io/ptp/_modules/ptp/tools/w3af/parser.html#W3AFXMLParser example Sphinx-friendly python comments here]'''&lt;br /&gt;
*CRITICAL: Excellent reliability&lt;br /&gt;
*Good performance&lt;br /&gt;
*Unit tests / Functional tests&lt;br /&gt;
*Good documentation&lt;br /&gt;
&lt;br /&gt;
== OWASP CSRF Protector ==&lt;br /&gt;
[[CSRFProtector Project|OWASP CSRF Protector Project]] is a project started with the goal to help developer to mitigate CSRF in web applications with ease. It's based on [[Cross-Site Request Forgery (CSRF) Prevention Cheat Sheet|Synchronizer Token Pattern]] and leverages an injected java-script code to provide CSRF mitigation without much developer intervention. So far it has been implemented as a [https://github.com/mebjas/CSRF-Protector-PHP PHP Library] and an [[CSRFProtector Project|Apache 2.2.x module]]. Although different libraries and frameworks provide CSRF mitigation these days - all of them require developer to explicitly inject tokens with every form. &lt;br /&gt;
===OWASP CSRF Protector - Extending the design as a python package to work with Flask and an Express JS (Node.JS) middleware===&lt;br /&gt;
'''Brief explanation:'''&lt;br /&gt;
&lt;br /&gt;
The design of CSRF Protector involves a server side middle-ware that intercepts every incoming request and validates them for CSRF attacks. If the validation is successful the flow of control goes to business logic and the tokens are refreshed. In case of failed validation configured actions are taken. Post that, another middle ware takes care of injecting a JavaScript code (refer [https://github.com/mebjas/CSRF-Protector-PHP/blob/master/js/csrfprotector.js CSRF Protector PHP JS Code]) to HTML output. On the client side this code ensures that, for every request that require validation - the correct token is sent along with the request.&lt;br /&gt;
&lt;br /&gt;
Check [https://github.com/mebjas/CSRF-Protector-PHP/wiki GitHub Wiki] for some reference;&lt;br /&gt;
&lt;br /&gt;
The goal of this project would be to:&lt;br /&gt;
# Port this design to a python module that can be used easily with Flask - [https://github.com/mebjas/CSRF-Protector-py/projects/1?add_cards_query=is%3Aopen Kanban Board]&lt;br /&gt;
# Port this design to a node js module that can work well with express js (a popular Node.JS based framework). - [https://github.com/mebjas/CSRF-Protector-JS Initial Repo Link]&lt;br /&gt;
# Fix some outstanding issues with java-script code used in library: [https://github.com/mebjas/CSRF-Protector-PHP/issues?q=is%3Aopen+is%3Aissue+label%3AJS Issues] &lt;br /&gt;
'''Expected results:'''&lt;br /&gt;
*'''IMPORTANT: Clean, maintainable (ES6 compatible and using recommended design patterns) in case of Node.JS'''&lt;br /&gt;
*'''IMPORTANT: [http://legacy.python.org/dev/peps/pep-0008/ PEP-8 compliant code] in all modified code and surrounding areas.'''&lt;br /&gt;
*'''IMPORTANT: Thoroughly documented code along with API examples and example future components.'''&lt;br /&gt;
*'''CRITICAL''': Excellent reliability and performance.&lt;br /&gt;
*Unit tests / Functional tests and easy to setup testing environment (preferably automated).&lt;br /&gt;
'''Knowledge Prerequisite:''' Javascript (Client Side), Python (having worked with flask preferable), Node.JS (having worked with node.js and middle wares preferable)&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' Contact: [mailto:minhaz@owasp.org;minhazv@microsoft.com Minhaz A V]&lt;/div&gt;</summary>
		<author><name>Psiinon</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=GSOC2018_Ideas&amp;diff=236354</id>
		<title>GSOC2018 Ideas</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=GSOC2018_Ideas&amp;diff=236354"/>
				<updated>2017-12-20T10:56:57Z</updated>
		
		<summary type="html">&lt;p&gt;Psiinon: Added 'Your Idea' ZAP project suggestion&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=OWASP Project Requests=&lt;br /&gt;
&lt;br /&gt;
'''Tips to get you started in no particular order:''' &lt;br /&gt;
 '''* Read [https://developers.google.com/open-source/gsoc/ Google Summer of Code Program(GSOC)]'''&lt;br /&gt;
 '''* Read the [[GSoC SAT]] '''&lt;br /&gt;
 * Read the [https://www.owasp.org/index.php/GSoC GSOC Student Guidelines]&lt;br /&gt;
 * Contact us through the mailing list or irc channel.&lt;br /&gt;
 * Check our [https://github.com/Hackademic/hackademic github repository] and especially the [https://github.com/Hackademic/hackademic/issues open tickets]&lt;br /&gt;
==OWASP ZAP==&lt;br /&gt;
[[OWASP Zed Attack Proxy Project]] (ZAP) The OWASP Zed Attack Proxy (ZAP) is one of the world’s most popular free security tools and is actively maintained by hundreds of international volunteers. Previous GSoC students have implemented key parts of the ZAP core functionality and have been offered (and accepted) jobs based on their work on ZAP.&lt;br /&gt;
&lt;br /&gt;
We have just included a few of the ideas we have here, for a more complete list see the issues on the ZAP bug tracker with the [https://github.com/zaproxy/zaproxy/issues?q=is%3Aopen+is%3Aissue+label%3Aproject project] label.&lt;br /&gt;
===Zest Text Representation and Parser===&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
Zest is a graphical scripting language from the Mozilla Security team, and is used as the ZAP macro language.&lt;br /&gt;
&lt;br /&gt;
A standardized text representation and parser would be very useful and help its adoption.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* A documented definition of a text representation for Zest&lt;br /&gt;
* A parser that converts the text representation into a working Zest script&lt;br /&gt;
* An option in the Zest java implementation to output Zest scripts text format&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
&lt;br /&gt;
* Have a look at the ZAP [https://github.com/zaproxy/zaproxy/blob/develop/CONTRIBUTING.md CONTRIBUTING.md] file, especially the 'Coding section.&lt;br /&gt;
* We like to see students who have already contributed to ZAP, so try fixing one of the bugs flagged as [https://github.com/zaproxy/zaproxy/issues?q=is%3Aopen+is%3Aissue+label%3AIdealFirstBug IdealFirstBug].&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* The Zest reference implementation is written in Java, so a good knowledge of this language is recommended. Some knowledge of application security would be useful, but not essential.&lt;br /&gt;
'''Mentors:''' [https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @] and the rest of the ZAP Core Team&lt;br /&gt;
&lt;br /&gt;
=== Your Idea ===&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
ZAP is a great framework for building new and innovative security testing solutions. If you have an idea that is not on this list then don't worry, you can still submit it, we have accepted original projects in previous years and have even paid a student to work on their idea when we did not get enough GSoC slots to accept all of the projects we wanted.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* A new feature that makes ZAP even better&lt;br /&gt;
* Code that conforms to our Development Rules and Guidelines&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
&lt;br /&gt;
* Have a look at the ZAP [https://github.com/zaproxy/zaproxy/blob/develop/CONTRIBUTING.md CONTRIBUTING.md] file, especially the 'Coding section.&lt;br /&gt;
* We like to see students who have already contributed to ZAP, so try fixing one of the bugs flagged as [https://github.com/zaproxy/zaproxy/issues?q=is%3Aopen+is%3Aissue+label%3AIdealFirstBug IdealFirstBug].&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* ZAP is written in Java, so a good knowledge of this language is recommended. Some knowledge of application security would be useful, but not essential.&lt;br /&gt;
'''Mentors:''' [https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @] and the rest of the ZAP Core Team&lt;br /&gt;
&lt;br /&gt;
== SAMPLE: OWASP Hackademic Challenges ==&lt;br /&gt;
&lt;br /&gt;
[[OWASP Hackademic Challenges Project]]  helps you test your knowledge on web application security. You can use it to actually attack web applications in a realistic but also controllable and safe environment. After a wonderfull 2016 GSoC with 100 new challenges and a couple of new plugins we're mainly looking to get new features in and maybe a couple of challenges. Bellow is a list of proposed features.&lt;br /&gt;
&lt;br /&gt;
=== REST API for the sandbox ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
During the last summer code sprint Hackademic got challenge sandboxing in the form of vagrant and docker wrappers as well as an engine to start and stop the container or vm instances.&lt;br /&gt;
What is needed now is a rest api which supports endpoint authentication and authorization which enables the sandbox engine to be completely independed from the rest of the project.&lt;br /&gt;
&lt;br /&gt;
Ideas on the project:&lt;br /&gt;
Since the sandbox is written in python, you will be using Django to implement the api.&lt;br /&gt;
The endpoint authorization can be done via certificates or plain signature or username/password type authentication. We would like to see what's your idea on the matter.&lt;br /&gt;
However the communication between the two has to be over a secure channel.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* A REST style api which allows an authenticated remote entity control the parts of the  sandbox engine it has access to.&lt;br /&gt;
* PEP8 compliant code&lt;br /&gt;
* Acceptable unit test coverage&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
Since this has been a popular project here's a suggestion on how to get started.&lt;br /&gt;
* Check the excellent work done by mebjas and a0xnirudh in their respective brances in the project's repository&lt;br /&gt;
* Take a brief look at the code and try to get a feeling of the functionality included. (Essentially it's CRUD operations on vms or containers)&lt;br /&gt;
* Read on what Docker and Vagrant are and take a look at their respective py-libraries&lt;br /&gt;
* If you think that contributing helps perhaps it would be a good idea to start with lettuce tests on the current CRUD operations of the existing functionality(which won't change and can eventually be ported to the final project) &lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
Python, test driven development, some idea what REST is, some security knowledge would be preferable.&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' [mailto:konstantinos.papapanaqiotou@owasp.org Konstantinos Papapanagiotou][mailto:spyros.gasteratos@owasp.org Spyros Gasteratos] - Hackademic Challenges Project Leaders&lt;br /&gt;
&lt;br /&gt;
=== New CMS ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
The CMS part of the project is really old and has accumulated a significant amount of technical debt.&lt;br /&gt;
In addition many design decisions are either outdated or could be improved. &lt;br /&gt;
Therefore it may be a good idea to leverage the power of modern web frameworks to create a new CMS.&lt;br /&gt;
The new cms can be written in python using Django.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* New cms with same functionality as the old one (3 types of users -- student, teacher, admin--, 3 types of resources -- article challenge, class--, ACL type permissions, CRUD operations on every resource/user, all functionality can be extended by Plugins.&lt;br /&gt;
* REST endpoints in addition to classic ones&lt;br /&gt;
* tests covering all routes implemented, also complete ACL unit tests, it would be embarassing if a cms by OWASP has rights vulnerabilities.&lt;br /&gt;
* PEP 8 code&lt;br /&gt;
&lt;br /&gt;
''' Note: '''&lt;br /&gt;
This is a huge project, it is ok if the student implements a part of it. However whatever implemented must be up to spec.&lt;br /&gt;
If you decide to take on this project contact us and we can agree on a list of routes.&lt;br /&gt;
If you don't decide to take on this project contact us.&lt;br /&gt;
Generally contact us, we like it when students have insightful questions and the community is active&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''' Getting Started: '''&lt;br /&gt;
* Install and take a brief look around the old cms so you have an idea of the functionality needed&lt;br /&gt;
* It's ok to scream in frustration&lt;br /&gt;
* If you want to contribute to get a feeling of the platform a good idea would be lettuce tests for the current functionality (which won't change and you can port in the new cms eventually)&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
Python, Django, what REST is, the technologies used, some security knowledge would be nice.&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' [mailto:konstantinos.papapanaqiotou@owasp.org Konstantinos Papapanagiotou][mailto:spyros.gasteratos@owasp.org Spyros Gasteratos] - Hackademic Challenges Project Leaders&lt;/div&gt;</summary>
		<author><name>Psiinon</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=GSOC2018_Ideas&amp;diff=236353</id>
		<title>GSOC2018 Ideas</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=GSOC2018_Ideas&amp;diff=236353"/>
				<updated>2017-12-20T10:51:07Z</updated>
		
		<summary type="html">&lt;p&gt;Psiinon: Added first ZAP project suggestion&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=OWASP Project Requests=&lt;br /&gt;
&lt;br /&gt;
'''Tips to get you started in no particular order:''' &lt;br /&gt;
 '''* Read [https://developers.google.com/open-source/gsoc/ Google Summer of Code Program(GSOC)]'''&lt;br /&gt;
 '''* Read the [[GSoC SAT]] '''&lt;br /&gt;
 * Read the [https://www.owasp.org/index.php/GSoC GSOC Student Guidelines]&lt;br /&gt;
 * Contact us through the mailing list or irc channel.&lt;br /&gt;
 * Check our [https://github.com/Hackademic/hackademic github repository] and especially the [https://github.com/Hackademic/hackademic/issues open tickets]&lt;br /&gt;
==OWASP ZAP==&lt;br /&gt;
[[OWASP Zed Attack Proxy Project]] (ZAP) The OWASP Zed Attack Proxy (ZAP) is one of the world’s most popular free security tools and is actively maintained by hundreds of international volunteers. Previous GSoC students have implemented key parts of the ZAP core functionality and have been offered (and accepted) jobs based on their work on ZAP.&lt;br /&gt;
&lt;br /&gt;
We have just included a few of the ideas we have here, for a more complete list see the issues on the ZAP bug tracker with the [https://github.com/zaproxy/zaproxy/issues?q=is%3Aopen+is%3Aissue+label%3Aproject project] label.&lt;br /&gt;
===Zest Text Representation and Parser===&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
Zest is a graphical scripting language from the Mozilla Security team, and is used as the ZAP macro language.&lt;br /&gt;
&lt;br /&gt;
A standardized text representation and parser would be very useful and help its adoption.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* A documented definition of a text representation for Zest&lt;br /&gt;
* A parser that converts the text representation into a working Zest script&lt;br /&gt;
* An option in the Zest java implementation to output Zest scripts text format&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
&lt;br /&gt;
* Have a look at the ZAP [https://github.com/zaproxy/zaproxy/blob/develop/CONTRIBUTING.md CONTRIBUTING.md] file, especially the 'Coding section.&lt;br /&gt;
* We like to see students who have already contributed to ZAP, so try fixing one of the bugs flagged as [https://github.com/zaproxy/zaproxy/issues?q=is%3Aopen+is%3Aissue+label%3AIdealFirstBug IdealFirstBug].&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
The Zest reference implementation is written in Java, so a good knowledge of this language is recommended. Some knowledge of application security would be useful, but not essential.&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' [https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @] and the rest of the ZAP Core Team&lt;br /&gt;
== SAMPLE: OWASP Hackademic Challenges ==&lt;br /&gt;
&lt;br /&gt;
[[OWASP Hackademic Challenges Project]]  helps you test your knowledge on web application security. You can use it to actually attack web applications in a realistic but also controllable and safe environment. After a wonderfull 2016 GSoC with 100 new challenges and a couple of new plugins we're mainly looking to get new features in and maybe a couple of challenges. Bellow is a list of proposed features.&lt;br /&gt;
&lt;br /&gt;
=== REST API for the sandbox ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
During the last summer code sprint Hackademic got challenge sandboxing in the form of vagrant and docker wrappers as well as an engine to start and stop the container or vm instances.&lt;br /&gt;
What is needed now is a rest api which supports endpoint authentication and authorization which enables the sandbox engine to be completely independed from the rest of the project.&lt;br /&gt;
&lt;br /&gt;
Ideas on the project:&lt;br /&gt;
Since the sandbox is written in python, you will be using Django to implement the api.&lt;br /&gt;
The endpoint authorization can be done via certificates or plain signature or username/password type authentication. We would like to see what's your idea on the matter.&lt;br /&gt;
However the communication between the two has to be over a secure channel.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* A REST style api which allows an authenticated remote entity control the parts of the  sandbox engine it has access to.&lt;br /&gt;
* PEP8 compliant code&lt;br /&gt;
* Acceptable unit test coverage&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
Since this has been a popular project here's a suggestion on how to get started.&lt;br /&gt;
* Check the excellent work done by mebjas and a0xnirudh in their respective brances in the project's repository&lt;br /&gt;
* Take a brief look at the code and try to get a feeling of the functionality included. (Essentially it's CRUD operations on vms or containers)&lt;br /&gt;
* Read on what Docker and Vagrant are and take a look at their respective py-libraries&lt;br /&gt;
* If you think that contributing helps perhaps it would be a good idea to start with lettuce tests on the current CRUD operations of the existing functionality(which won't change and can eventually be ported to the final project) &lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
Python, test driven development, some idea what REST is, some security knowledge would be preferable.&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' [mailto:konstantinos.papapanaqiotou@owasp.org Konstantinos Papapanagiotou][mailto:spyros.gasteratos@owasp.org Spyros Gasteratos] - Hackademic Challenges Project Leaders&lt;br /&gt;
&lt;br /&gt;
=== New CMS ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
The CMS part of the project is really old and has accumulated a significant amount of technical debt.&lt;br /&gt;
In addition many design decisions are either outdated or could be improved. &lt;br /&gt;
Therefore it may be a good idea to leverage the power of modern web frameworks to create a new CMS.&lt;br /&gt;
The new cms can be written in python using Django.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* New cms with same functionality as the old one (3 types of users -- student, teacher, admin--, 3 types of resources -- article challenge, class--, ACL type permissions, CRUD operations on every resource/user, all functionality can be extended by Plugins.&lt;br /&gt;
* REST endpoints in addition to classic ones&lt;br /&gt;
* tests covering all routes implemented, also complete ACL unit tests, it would be embarassing if a cms by OWASP has rights vulnerabilities.&lt;br /&gt;
* PEP 8 code&lt;br /&gt;
&lt;br /&gt;
''' Note: '''&lt;br /&gt;
This is a huge project, it is ok if the student implements a part of it. However whatever implemented must be up to spec.&lt;br /&gt;
If you decide to take on this project contact us and we can agree on a list of routes.&lt;br /&gt;
If you don't decide to take on this project contact us.&lt;br /&gt;
Generally contact us, we like it when students have insightful questions and the community is active&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''' Getting Started: '''&lt;br /&gt;
* Install and take a brief look around the old cms so you have an idea of the functionality needed&lt;br /&gt;
* It's ok to scream in frustration&lt;br /&gt;
* If you want to contribute to get a feeling of the platform a good idea would be lettuce tests for the current functionality (which won't change and you can port in the new cms eventually)&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
Python, Django, what REST is, the technologies used, some security knowledge would be nice.&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' [mailto:konstantinos.papapanaqiotou@owasp.org Konstantinos Papapanagiotou][mailto:spyros.gasteratos@owasp.org Spyros Gasteratos] - Hackademic Challenges Project Leaders&lt;/div&gt;</summary>
		<author><name>Psiinon</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:Zap128x128.png&amp;diff=235815</id>
		<title>File:Zap128x128.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:Zap128x128.png&amp;diff=235815"/>
				<updated>2017-11-28T14:15:30Z</updated>
		
		<summary type="html">&lt;p&gt;Psiinon: Psiinon uploaded a new version of File:Zap128x128.png&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Psiinon</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:Zap128x128.png&amp;diff=235814</id>
		<title>File:Zap128x128.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:Zap128x128.png&amp;diff=235814"/>
				<updated>2017-11-28T14:15:20Z</updated>
		
		<summary type="html">&lt;p&gt;Psiinon: Psiinon uploaded a new version of File:Zap128x128.png&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Psiinon</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:Zap128x128.png&amp;diff=235813</id>
		<title>File:Zap128x128.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:Zap128x128.png&amp;diff=235813"/>
				<updated>2017-11-28T14:14:28Z</updated>
		
		<summary type="html">&lt;p&gt;Psiinon: Psiinon uploaded a new version of File:Zap128x128.png&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Psiinon</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Zed_Attack_Proxy_Project&amp;diff=235812</id>
		<title>OWASP Zed Attack Proxy Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Zed_Attack_Proxy_Project&amp;diff=235812"/>
				<updated>2017-11-28T13:59:24Z</updated>
		
		<summary type="html">&lt;p&gt;Psiinon: Updated for 2.7.0&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Main = &lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:90px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File: flagship_big.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
{{ReviewProject|projectname=zaproxy|language=en}}&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
The OWASP Zed Attack Proxy (ZAP) is one of the world’s most popular free security tools and is actively maintained by hundreds of international volunteers[[#Justification|*]]. It can help you automatically find security vulnerabilities in your web applications while you are developing and testing your applications. Its also a great tool for experienced pentesters to use for manual security testing.&lt;br /&gt;
&lt;br /&gt;
====ZAP 2.7.0 is now available!====&lt;br /&gt;
&lt;br /&gt;
[[Image:ZAP-Download.png | link=https://github.com/zaproxy/zaproxy/wiki/Downloads]]&lt;br /&gt;
&lt;br /&gt;
====Please help us to make ZAP even better for you by answering the [https://docs.google.com/forms/d/1-k-vcj_sSxlil6XLxCFade-m-IQVeE2h9gduA-2ZPPA/viewform ZAP User Questionnaire]!====&lt;br /&gt;
&lt;br /&gt;
For a quick overview of ZAP and an introduction to the [https://wiki.jenkins-ci.org/display/JENKINS/zap+plugin official ZAP Jenkins plugin] see these tutorial videos on YouTube:&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
{{#ev:youtube|eH0RBI0nmww}}&amp;amp;nbsp;&lt;br /&gt;
{{#ev:youtube|mmHZLSffCUg}}&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
For more videos see the links on the [https://github.com/zaproxy/zaproxy/wiki/Videos wiki videos page].&lt;br /&gt;
&lt;br /&gt;
Interested in a ZAP talk or training event? See the [https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project#tab=Talks talks] tab. Not one near you? Contact a [https://github.com/zaproxy/zaproxy/wiki/ZapEvangelists Zap Evangelist] to arrange one!&lt;br /&gt;
&lt;br /&gt;
{{#widget:PayPal Donation&lt;br /&gt;
|target=_blank&lt;br /&gt;
|budget=Zed Attack Proxy&lt;br /&gt;
}}  &lt;br /&gt;
&lt;br /&gt;
For general information about ZAP:&lt;br /&gt;
* [https://twitter.com/zaproxy Twitter] - official ZAP announcements (low volume)&lt;br /&gt;
* [https://zaproxy.blogspot.co.uk/ Blog] - official ZAP blog&lt;br /&gt;
&lt;br /&gt;
For help using ZAP:&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/releases/download/2.6.0/ZAPGettingStartedGuide-2.6.pdf Getting Started Guide (pdf)] - an introductory guide you can print&lt;br /&gt;
* [https://www.youtube.com/playlist?list=PLEBitBW-Hlsv8cEIUntAO8st2UGhmrjUB Tutorial Videos]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki User Guide] - online version of the User Guide included with ZAP&lt;br /&gt;
* [https://groups.google.com/group/zaproxy-users User Group] - ask questions about using ZAP&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/wiki Add-ons] - help for the optional add-ons you can install&lt;br /&gt;
* [https://stackoverflow.com/questions/tagged/zap StackOverflow] - because some people use this for all everything ;)&lt;br /&gt;
&lt;br /&gt;
To learn more about ZAP development:&lt;br /&gt;
* [https://github.com/zaproxy Source Code] - for all of the ZAP related projects&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/wiki/Introduction Wiki] - lots of detailed info&lt;br /&gt;
* [https://groups.google.com/group/zaproxy-develop Developer Group] - ask questions about the ZAP internals&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap Crowdin (GUI)] - help translate the ZAP GUI&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap-help Crowdin (User Guide)] - help translate the ZAP User Guide&lt;br /&gt;
* [https://www.openhub.net/p/zaproxy OpenHub]	- FOSS analytics&lt;br /&gt;
* [https://www.bountysource.com/teams/zap/issues BountySource] - Vote on ZAP issues (you can also donate money here, but 10% taken out)&lt;br /&gt;
&lt;br /&gt;
===Justification===&lt;br /&gt;
Justification for the statements made in the tagline at the top;)&lt;br /&gt;
&lt;br /&gt;
Popularity:&lt;br /&gt;
* ToolsWatch Annual Best Free/Open Source Security Tool Survey:&lt;br /&gt;
** 2016 [http://www.toolswatch.org/2017/02/2016-top-security-tools-as-voted-by-toolswatch-org-readers/ 2nd]&lt;br /&gt;
** 2015 [http://www.toolswatch.org/2016/02/2015-top-security-tools-as-voted-by-toolswatch-org-readers/ 1st]&lt;br /&gt;
** 2014 [http://www.toolswatch.org/2015/01/2014-top-security-tools-as-voted-by-toolswatch-org-readers/ 2nd]&lt;br /&gt;
** 2013 [http://www.toolswatch.org/2013/12/2013-top-security-tools-as-voted-by-toolswatch-org-readers/ 1st]&lt;br /&gt;
&lt;br /&gt;
Contributors:&lt;br /&gt;
* [https://www.openhub.net/p/zaproxy Code Contributors]&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap ZAP core i18n Contributors]&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap-help ZAP help i18n Contributors]&lt;br /&gt;
&lt;br /&gt;
{{Social Media Links}}&lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;padding-left:25px;width:200px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
[https://github.com/zaproxy/zaproxy/wiki/Downloads Download OWASP ZAP!]&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
Please see the [https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project#News News] and [https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project#Talks Talks] tabs&lt;br /&gt;
&lt;br /&gt;
== Change Log ==&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/commits/develop zaproxy]&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/commits/master zap-extensions]&lt;br /&gt;
&lt;br /&gt;
== Code Repo ==&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/ zaproxy]&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/ zap-extensions]&lt;br /&gt;
&lt;br /&gt;
== Email List ==&lt;br /&gt;
&lt;br /&gt;
Questions? Please ask on the [http://groups.google.com/group/zaproxy-users ZAP User Group]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
Project Leader&amp;lt;br /&amp;gt;[https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @]&lt;br /&gt;
&lt;br /&gt;
Co-Project Leaders&amp;lt;br /&amp;gt;[https://www.owasp.org/index.php/User:Ricardo.Pereira Ricardo Pereira] [mailto:ricardo.pereira@owasp.org @]&lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/index.php/User:Rick.mitchell Rick Mitchell] [mailto:rick.mitchell@owasp.org @]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_Web_Testing_Environment_Project OWASP WTE]&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_OWTF OWASP OWTF]&lt;br /&gt;
&lt;br /&gt;
== Ohloh ==&lt;br /&gt;
&lt;br /&gt;
*https://www.openhub.net/p/zaproxy&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Mature projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Flagship_Projects]]&lt;br /&gt;
   | width=&amp;quot;50%&amp;quot; valign=&amp;quot;center&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Owasp-builders-small.png|link=]]&lt;br /&gt;
   |&lt;br /&gt;
   |-&lt;br /&gt;
   | width=&amp;quot;50%&amp;quot; valign=&amp;quot;center&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Owasp-breakers-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [http://www.apache.org/licenses/LICENSE-2.0 Apache 2 License]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_TOOL.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Screenshots =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotAddAlert.png|||400px|ZAP Add Alert Screen Shot]] &lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotHelp.png||400px|left|ZAP Help Screen Shot]]&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotHistoryFilter.png|thumb|400px|left|ZAP History Filter Screen Shot]]&lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotSearchTab.png|thumb|400px|left|ZAP Search Tab Screen Shot]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Talks =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
{{:Projects/OWASP Zed Attack Proxy Project/Pages/Talks | Talks}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
= News =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
{{:Projects/OWASP Zed Attack Proxy Project/Pages/News | News}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
= ZAP Gear =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Yes, you can now buy ZAP related gear!&lt;br /&gt;
&lt;br /&gt;
All of the artwork for ZAP swag is released under the Creative Common License and can be downloaded from the [https://github.com/zaproxy/zap-swag zap-swag] repo.&lt;br /&gt;
&lt;br /&gt;
You can of course use the artwork from this repo with any other online store that you like.&lt;br /&gt;
&lt;br /&gt;
A range of products can be purchased from [http://www.redbubble.com/people/zaproxy Redbubble]&lt;br /&gt;
&lt;br /&gt;
Stickers can be purchased from [https://www.stickermule.com/uk/user/1070684077/stickers Stickermule]&lt;br /&gt;
&lt;br /&gt;
T-shirts can be purchased from [http://www.cafepress.com/zaproxy Cafepress]&lt;br /&gt;
&lt;br /&gt;
[[Image:zap-tshirt-cp.PNG | link=http://www.cafepress.com/zaproxy]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Supporters =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
ZAP is developed by a worldwide [https://github.com/zaproxy/zap-core-help/wiki/HelpCredits team] of volunteers.&lt;br /&gt;
&lt;br /&gt;
But we have also been helped by many organizations, either financially or by encouraging their employees to work on ZAP:&lt;br /&gt;
&lt;br /&gt;
* [http://www.mozilla.org Mozilla]&lt;br /&gt;
* [http://www.linuxfoundation.org/ The Linux Foundation]&lt;br /&gt;
* [http://www.owasp.org OWASP]&lt;br /&gt;
* [http://www.sage.co.uk Sage]&lt;br /&gt;
* [http://www.google.com Google]&lt;br /&gt;
* [http://www.microsoft.com Microsoft]&lt;br /&gt;
* [http://www.hacktics.com/ Hacktics, Ernst &amp;amp; Young]&lt;br /&gt;
* [http://www.dinosec.com/ DinoSec]&lt;br /&gt;
* [http://www.denimgroup.com Denim Group]&lt;br /&gt;
* [http://www.aspectsecurity.com/ Aspect Security]&lt;br /&gt;
* [http://secureideas.net SecureIdeas]&lt;br /&gt;
* [http://utilisec.com UtiliSec]&lt;br /&gt;
* [http://www.encription.co.uk/ encription]&lt;br /&gt;
* [https://www.accenture.com/us-en/digital-index.aspx Accenture Digital]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Functionality =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
'''Some of ZAP's functionality:'''&lt;br /&gt;
&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsIntercept Man-in-the-middle Proxy]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsSpider Traditional] and AJAX spiders&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsAscan Automated scanner]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsPscan Passive scanner]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsBruteforce Forced browsing]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsFuzz Fuzzer]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpUiDialogsOptionsDynsslcert Dynamic SSL certificates]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/SmartCards Smartcard and Client Digital Certificates support]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpAddonsWebsocketIntroduction Web sockets] support&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpAddonsScriptsScripts Support for a wide range of scripting languages]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki//HelpAddonsPlugnhackPlugnhack Plug-n-Hack support]&lt;br /&gt;
* Authentication and session support&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsApi Powerful REST based API]&lt;br /&gt;
* Automatic updating option&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/wiki Integrated and growing marketplace of add-ons]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
= Features =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
'''Some of ZAP's features:'''&lt;br /&gt;
&lt;br /&gt;
* [http://www.apache.org/licenses/LICENSE-2.0 Open source]&lt;br /&gt;
* Cross platform (it even runs on a [https://github.com/zaproxy/zaproxy/wiki/zappi Raspberry Pi!])&lt;br /&gt;
* Easy to install (using a [https://www.ej-technologies.com/products/install4j/overview.html multi-platform installer builder])&lt;br /&gt;
* Completely free (no paid for 'Pro' version)&lt;br /&gt;
* Ease of use a priority&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpIntro Comprehensive help pages]&lt;br /&gt;
* Fully internationalized&lt;br /&gt;
* Translated into over 20 languages&lt;br /&gt;
* Community based, with involvement actively encouraged&lt;br /&gt;
* Under active development by an international team of volunteers&lt;br /&gt;
&lt;br /&gt;
ZAP is a fork of the well regarded [http://www.parosproxy.org/ Paros Proxy].&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Languages =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''ZAP supports the following languages:'''&lt;br /&gt;
&lt;br /&gt;
* English&lt;br /&gt;
* Arabic&lt;br /&gt;
* Bosnian&lt;br /&gt;
* Brazilian Portuguese&lt;br /&gt;
* Chinese&lt;br /&gt;
* Danish&lt;br /&gt;
* Filipino&lt;br /&gt;
* French&lt;br /&gt;
* German&lt;br /&gt;
* Greek&lt;br /&gt;
* Hungarian&lt;br /&gt;
* Indonesian&lt;br /&gt;
* Italian&lt;br /&gt;
* Japanese&lt;br /&gt;
* Korean&lt;br /&gt;
* Persian&lt;br /&gt;
* Polish&lt;br /&gt;
* Russian&lt;br /&gt;
* Sinhala&lt;br /&gt;
* Spanish&lt;br /&gt;
* Urdu &lt;br /&gt;
&lt;br /&gt;
You can use [http://crowdin.net/project/owasp-zap Crowdin] to help improve these translations or add new ones right now!&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Release 2.6.0==&lt;br /&gt;
ZAP 2.6.0 has been released, this is a bug fix and enhancement release&lt;br /&gt;
&lt;br /&gt;
For more details see https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_6_0&lt;br /&gt;
&lt;br /&gt;
==Release 2.7.0==&lt;br /&gt;
ZAP 2.7.0 is being actively worked on, and is expected to be released relatively soon.&lt;br /&gt;
&lt;br /&gt;
It will require Java 8 (minimum) and will support Selenium 3. It will also include all of the changes currently available in the [https://github.com/zaproxy/zaproxy/wiki/Downloads#zap-weekly weekly release].&lt;br /&gt;
&lt;br /&gt;
==Release 2.8.0==&lt;br /&gt;
ZAP 2.8.0 does not yet have a planned release date, but is likely to be around the end of 2017 or (more likely) the beginning of 2018.&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Get Involved =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Involvement in the development of ZAP is actively encouraged!&lt;br /&gt;
&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
&lt;br /&gt;
Some of the ways you can help:&lt;br /&gt;
&lt;br /&gt;
==Feature Requests==&lt;br /&gt;
&lt;br /&gt;
Please raise new feature requests as enhancement requests here: https://github.com/zaproxy/zaproxy/issues&lt;br /&gt;
&lt;br /&gt;
If there are existing requests you are also interested in then please 'star' them - that way we can see which features people are most interested in and can prioritize them accordingly. &lt;br /&gt;
&lt;br /&gt;
==Feedback==&lt;br /&gt;
&lt;br /&gt;
Please use the [http://groups.google.com/group/zaproxy-users zaproxy-users Google Group] for feedback:&lt;br /&gt;
* What do like?&lt;br /&gt;
* What don't you like?&lt;br /&gt;
* What features could be made easier to use?&lt;br /&gt;
* How could the help pages be improved? &lt;br /&gt;
&lt;br /&gt;
==Log issues==&lt;br /&gt;
&lt;br /&gt;
Have you had a problem using ZAP?&lt;br /&gt;
&lt;br /&gt;
If so and its not already been logged then please [https://github.com/zaproxy/zaproxy/issues report it]&lt;br /&gt;
&lt;br /&gt;
==Localization==&lt;br /&gt;
&lt;br /&gt;
Are you fluent in another language? Can you help translate ZAP into that language?&lt;br /&gt;
&lt;br /&gt;
You can use [http://crowdin.net/project/owasp-zap Crowdin] to do that!&lt;br /&gt;
&lt;br /&gt;
==Development==&lt;br /&gt;
&lt;br /&gt;
If you fancy having a go at adding functionality to ZAP then please get in touch via the [http://groups.google.com/group/zaproxy-develop zaproxy-develop Google Group].&lt;br /&gt;
&lt;br /&gt;
Again, you do not have to be a security expert to contribute code - working on ZAP could be great way to learn more about web application security!&lt;br /&gt;
&lt;br /&gt;
If you actively contribute to ZAP then you will be invited to join the project. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project|Zed Attack Proxy Project]]&lt;br /&gt;
[[Category:OWASP_Tool]]&lt;br /&gt;
[[Category:OWASP Release Quality Tool|OWASP Release Quality Tool]]&lt;br /&gt;
[[Category:OWASP_Download]]&lt;br /&gt;
[[Category:Popular]]&lt;br /&gt;
[[Category:SAMM-ST-2]]&lt;br /&gt;
[[Category:Flagship Projects|Zap]]&lt;br /&gt;
[[Category:OWASP Zed Attack Proxy|Zap]]&lt;/div&gt;</summary>
		<author><name>Psiinon</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Zed_Attack_Proxy_Project&amp;diff=235347</id>
		<title>OWASP Zed Attack Proxy Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Zed_Attack_Proxy_Project&amp;diff=235347"/>
				<updated>2017-11-13T09:58:13Z</updated>
		
		<summary type="html">&lt;p&gt;Psiinon: Added Ricardo and corrected the link to Ricks page&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Main = &lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:90px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File: flagship_big.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
{{ReviewProject|projectname=zaproxy|language=en}}&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
The OWASP Zed Attack Proxy (ZAP) is one of the world’s most popular free security tools and is actively maintained by hundreds of international volunteers[[#Justification|*]]. It can help you automatically find security vulnerabilities in your web applications while you are developing and testing your applications. Its also a great tool for experienced pentesters to use for manual security testing.&lt;br /&gt;
&lt;br /&gt;
====ZAP 2.6.0 is now available and includes important security fixes. Please update asap!====&lt;br /&gt;
&lt;br /&gt;
[[Image:ZAP-Download.png | link=https://github.com/zaproxy/zaproxy/wiki/Downloads]]&lt;br /&gt;
&lt;br /&gt;
====Please help us to make ZAP even better for you by answering the [https://docs.google.com/forms/d/1-k-vcj_sSxlil6XLxCFade-m-IQVeE2h9gduA-2ZPPA/viewform ZAP User Questionnaire]!====&lt;br /&gt;
&lt;br /&gt;
For a quick overview of ZAP and an introduction to the [https://wiki.jenkins-ci.org/display/JENKINS/zap+plugin official ZAP Jenkins plugin] see these tutorial videos on YouTube:&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
{{#ev:youtube|eH0RBI0nmww}}&amp;amp;nbsp;&lt;br /&gt;
{{#ev:youtube|mmHZLSffCUg}}&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
For more videos see the links on the [https://github.com/zaproxy/zaproxy/wiki/Videos wiki videos page].&lt;br /&gt;
&lt;br /&gt;
Interested in a ZAP talk or training event? See the [https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project#tab=Talks talks] tab. Not one near you? Contact a [https://github.com/zaproxy/zaproxy/wiki/ZapEvangelists Zap Evangelist] to arrange one!&lt;br /&gt;
&lt;br /&gt;
{{#widget:PayPal Donation&lt;br /&gt;
|target=_blank&lt;br /&gt;
|budget=Zed Attack Proxy&lt;br /&gt;
}}  &lt;br /&gt;
&lt;br /&gt;
For general information about ZAP:&lt;br /&gt;
* [https://twitter.com/zaproxy Twitter] - official ZAP announcements (low volume)&lt;br /&gt;
* [https://zaproxy.blogspot.co.uk/ Blog] - official ZAP blog&lt;br /&gt;
&lt;br /&gt;
For help using ZAP:&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/releases/download/2.6.0/ZAPGettingStartedGuide-2.6.pdf Getting Started Guide (pdf)] - an introductory guide you can print&lt;br /&gt;
* [https://www.youtube.com/playlist?list=PLEBitBW-Hlsv8cEIUntAO8st2UGhmrjUB Tutorial Videos]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki User Guide] - online version of the User Guide included with ZAP&lt;br /&gt;
* [https://groups.google.com/group/zaproxy-users User Group] - ask questions about using ZAP&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/wiki Add-ons] - help for the optional add-ons you can install&lt;br /&gt;
* [https://stackoverflow.com/questions/tagged/zap StackOverflow] - because some people use this for all everything ;)&lt;br /&gt;
&lt;br /&gt;
To learn more about ZAP development:&lt;br /&gt;
* [https://github.com/zaproxy Source Code] - for all of the ZAP related projects&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/wiki/Introduction Wiki] - lots of detailed info&lt;br /&gt;
* [https://groups.google.com/group/zaproxy-develop Developer Group] - ask questions about the ZAP internals&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap Crowdin (GUI)] - help translate the ZAP GUI&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap-help Crowdin (User Guide)] - help translate the ZAP User Guide&lt;br /&gt;
* [https://www.openhub.net/p/zaproxy OpenHub]	- FOSS analytics&lt;br /&gt;
* [https://www.bountysource.com/teams/zap/issues BountySource] - Vote on ZAP issues (you can also donate money here, but 10% taken out)&lt;br /&gt;
&lt;br /&gt;
===Justification===&lt;br /&gt;
Justification for the statements made in the tagline at the top;)&lt;br /&gt;
&lt;br /&gt;
Popularity:&lt;br /&gt;
* ToolsWatch Annual Best Free/Open Source Security Tool Survey:&lt;br /&gt;
** 2016 [http://www.toolswatch.org/2017/02/2016-top-security-tools-as-voted-by-toolswatch-org-readers/ 2nd]&lt;br /&gt;
** 2015 [http://www.toolswatch.org/2016/02/2015-top-security-tools-as-voted-by-toolswatch-org-readers/ 1st]&lt;br /&gt;
** 2014 [http://www.toolswatch.org/2015/01/2014-top-security-tools-as-voted-by-toolswatch-org-readers/ 2nd]&lt;br /&gt;
** 2013 [http://www.toolswatch.org/2013/12/2013-top-security-tools-as-voted-by-toolswatch-org-readers/ 1st]&lt;br /&gt;
&lt;br /&gt;
Contributors:&lt;br /&gt;
* [https://www.openhub.net/p/zaproxy Code Contributors]&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap ZAP core i18n Contributors]&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap-help ZAP help i18n Contributors]&lt;br /&gt;
&lt;br /&gt;
{{Social Media Links}}&lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;padding-left:25px;width:200px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
[https://github.com/zaproxy/zaproxy/wiki/Downloads Download OWASP ZAP!]&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
Please see the [https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project#News News] and [https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project#Talks Talks] tabs&lt;br /&gt;
&lt;br /&gt;
== Change Log ==&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/commits/develop zaproxy]&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/commits/master zap-extensions]&lt;br /&gt;
&lt;br /&gt;
== Code Repo ==&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/ zaproxy]&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/ zap-extensions]&lt;br /&gt;
&lt;br /&gt;
== Email List ==&lt;br /&gt;
&lt;br /&gt;
Questions? Please ask on the [http://groups.google.com/group/zaproxy-users ZAP User Group]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
Project Leader&amp;lt;br /&amp;gt;[https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @]&lt;br /&gt;
&lt;br /&gt;
Co-Project Leaders&amp;lt;br /&amp;gt;&lt;br /&gt;
Ricardo Pereira&amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/index.php/User:Rick.mitchell Rick Mitchell] [mailto:kingthorin@gmail.com @]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_Web_Testing_Environment_Project OWASP WTE]&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_OWTF OWASP OWTF]&lt;br /&gt;
&lt;br /&gt;
== Ohloh ==&lt;br /&gt;
&lt;br /&gt;
*https://www.openhub.net/p/zaproxy&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Mature projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Flagship_Projects]]&lt;br /&gt;
   | width=&amp;quot;50%&amp;quot; valign=&amp;quot;center&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Owasp-builders-small.png|link=]]&lt;br /&gt;
   |&lt;br /&gt;
   |-&lt;br /&gt;
   | width=&amp;quot;50%&amp;quot; valign=&amp;quot;center&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Owasp-breakers-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [http://www.apache.org/licenses/LICENSE-2.0 Apache 2 License]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_TOOL.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Screenshots =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotAddAlert.png|||400px|ZAP Add Alert Screen Shot]] &lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotHelp.png||400px|left|ZAP Help Screen Shot]]&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotHistoryFilter.png|thumb|400px|left|ZAP History Filter Screen Shot]]&lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotSearchTab.png|thumb|400px|left|ZAP Search Tab Screen Shot]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Talks =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
{{:Projects/OWASP Zed Attack Proxy Project/Pages/Talks | Talks}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
= News =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
{{:Projects/OWASP Zed Attack Proxy Project/Pages/News | News}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
= ZAP Gear =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Yes, you can now buy ZAP related gear!&lt;br /&gt;
&lt;br /&gt;
All of the artwork for ZAP swag is released under the Creative Common License and can be downloaded from the [https://github.com/zaproxy/zap-swag zap-swag] repo.&lt;br /&gt;
&lt;br /&gt;
You can of course use the artwork from this repo with any other online store that you like.&lt;br /&gt;
&lt;br /&gt;
A range of products can be purchased from [http://www.redbubble.com/people/zaproxy Redbubble]&lt;br /&gt;
&lt;br /&gt;
Stickers can be purchased from [https://www.stickermule.com/uk/user/1070684077/stickers Stickermule]&lt;br /&gt;
&lt;br /&gt;
T-shirts can be purchased from [http://www.cafepress.com/zaproxy Cafepress]&lt;br /&gt;
&lt;br /&gt;
[[Image:zap-tshirt-cp.PNG | link=http://www.cafepress.com/zaproxy]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Supporters =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
ZAP is developed by a worldwide [https://github.com/zaproxy/zap-core-help/wiki/HelpCredits team] of volunteers.&lt;br /&gt;
&lt;br /&gt;
But we have also been helped by many organizations, either financially or by encouraging their employees to work on ZAP:&lt;br /&gt;
&lt;br /&gt;
* [http://www.mozilla.org Mozilla]&lt;br /&gt;
* [http://www.linuxfoundation.org/ The Linux Foundation]&lt;br /&gt;
* [http://www.owasp.org OWASP]&lt;br /&gt;
* [http://www.sage.co.uk Sage]&lt;br /&gt;
* [http://www.google.com Google]&lt;br /&gt;
* [http://www.microsoft.com Microsoft]&lt;br /&gt;
* [http://www.hacktics.com/ Hacktics, Ernst &amp;amp; Young]&lt;br /&gt;
* [http://www.dinosec.com/ DinoSec]&lt;br /&gt;
* [http://www.denimgroup.com Denim Group]&lt;br /&gt;
* [http://www.aspectsecurity.com/ Aspect Security]&lt;br /&gt;
* [http://secureideas.net SecureIdeas]&lt;br /&gt;
* [http://utilisec.com UtiliSec]&lt;br /&gt;
* [http://www.encription.co.uk/ encription]&lt;br /&gt;
* [https://www.accenture.com/us-en/digital-index.aspx Accenture Digital]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Functionality =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
'''Some of ZAP's functionality:'''&lt;br /&gt;
&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsIntercept Intercepting Proxy]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsSpider Traditional] and AJAX spiders&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsAscan Automated scanner]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsPscan Passive scanner]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsBruteforce Forced browsing]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsFuzz Fuzzer]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpUiDialogsOptionsDynsslcert Dynamic SSL certificates]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/SmartCards Smartcard and Client Digital Certificates support]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpAddonsWebsocketIntroduction Web sockets] support&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpAddonsScriptsScripts Support for a wide range of scripting languages]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki//HelpAddonsPlugnhackPlugnhack Plug-n-Hack support]&lt;br /&gt;
* Authentication and session support&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsApi Powerful REST based API]&lt;br /&gt;
* Automatic updating option&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/wiki Integrated and growing marketplace of add-ons]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
= Features =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
'''Some of ZAP's features:'''&lt;br /&gt;
&lt;br /&gt;
* [http://www.apache.org/licenses/LICENSE-2.0 Open source]&lt;br /&gt;
* Cross platform (it even runs on a [https://github.com/zaproxy/zaproxy/wiki/zappi Raspberry Pi!])&lt;br /&gt;
* Easy to install (using a [https://www.ej-technologies.com/products/install4j/overview.html multi-platform installer builder])&lt;br /&gt;
* Completely free (no paid for 'Pro' version)&lt;br /&gt;
* Ease of use a priority&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpIntro Comprehensive help pages]&lt;br /&gt;
* Fully internationalized&lt;br /&gt;
* Translated into over 20 languages&lt;br /&gt;
* Community based, with involvement actively encouraged&lt;br /&gt;
* Under active development by an international team of volunteers&lt;br /&gt;
&lt;br /&gt;
ZAP is a fork of the well regarded [http://www.parosproxy.org/ Paros Proxy].&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Languages =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''ZAP supports the following languages:'''&lt;br /&gt;
&lt;br /&gt;
* English&lt;br /&gt;
* Arabic&lt;br /&gt;
* Bosnian&lt;br /&gt;
* Brazilian Portuguese&lt;br /&gt;
* Chinese&lt;br /&gt;
* Danish&lt;br /&gt;
* Filipino&lt;br /&gt;
* French&lt;br /&gt;
* German&lt;br /&gt;
* Greek&lt;br /&gt;
* Hungarian&lt;br /&gt;
* Indonesian&lt;br /&gt;
* Italian&lt;br /&gt;
* Japanese&lt;br /&gt;
* Korean&lt;br /&gt;
* Persian&lt;br /&gt;
* Polish&lt;br /&gt;
* Russian&lt;br /&gt;
* Sinhala&lt;br /&gt;
* Spanish&lt;br /&gt;
* Urdu &lt;br /&gt;
&lt;br /&gt;
You can use [http://crowdin.net/project/owasp-zap Crowdin] to help improve these translations or add new ones right now!&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Release 2.6.0==&lt;br /&gt;
ZAP 2.6.0 has been released, this is a bug fix and enhancement release&lt;br /&gt;
&lt;br /&gt;
For more details see https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_6_0&lt;br /&gt;
&lt;br /&gt;
==Release 2.7.0==&lt;br /&gt;
ZAP 2.7.0 is being actively worked on, and is expected to be released relatively soon.&lt;br /&gt;
&lt;br /&gt;
It will require Java 8 (minimum) and will support Selenium 3. It will also include all of the changes currrently available in the [https://github.com/zaproxy/zaproxy/wiki/Downloads#zap-weekly weekly release].&lt;br /&gt;
&lt;br /&gt;
==Release 2.8.0==&lt;br /&gt;
ZAP 2.8.0 does not yet have a planned release date, but is likely to be around the end of 2017 or (more likely) the beginning of 2018.&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Get Involved =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Involvement in the development of ZAP is actively encouraged!&lt;br /&gt;
&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
&lt;br /&gt;
Some of the ways you can help:&lt;br /&gt;
&lt;br /&gt;
==Feature Requests==&lt;br /&gt;
&lt;br /&gt;
Please raise new feature requests as enhancement requests here: https://github.com/zaproxy/zaproxy/issues&lt;br /&gt;
&lt;br /&gt;
If there are existing requests you are also interested in then please 'star' them - that way we can see which features people are most interested in and can prioritize them accordingly. &lt;br /&gt;
&lt;br /&gt;
==Feedback==&lt;br /&gt;
&lt;br /&gt;
Please use the [http://groups.google.com/group/zaproxy-users zaproxy-users Google Group] for feedback:&lt;br /&gt;
* What do like?&lt;br /&gt;
* What don't you like?&lt;br /&gt;
* What features could be made easier to use?&lt;br /&gt;
* How could the help pages be improved? &lt;br /&gt;
&lt;br /&gt;
==Log issues==&lt;br /&gt;
&lt;br /&gt;
Have you had a problem using ZAP?&lt;br /&gt;
&lt;br /&gt;
If so and its not already been logged then please [https://github.com/zaproxy/zaproxy/issues report it]&lt;br /&gt;
&lt;br /&gt;
==Localization==&lt;br /&gt;
&lt;br /&gt;
Are you fluent in another language? Can you help translate ZAP into that language?&lt;br /&gt;
&lt;br /&gt;
You can use [http://crowdin.net/project/owasp-zap Crowdin] to do that!&lt;br /&gt;
&lt;br /&gt;
==Development==&lt;br /&gt;
&lt;br /&gt;
If you fancy having a go at adding functionality to ZAP then please get in touch via the [http://groups.google.com/group/zaproxy-develop zaproxy-develop Google Group].&lt;br /&gt;
&lt;br /&gt;
Again, you do not have to be a security expert to contribute code - working on ZAP could be great way to learn more about web application security!&lt;br /&gt;
&lt;br /&gt;
If you actively contribute to ZAP then you will be invited to join the project. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project|Zed Attack Proxy Project]]&lt;br /&gt;
[[Category:OWASP_Tool]]&lt;br /&gt;
[[Category:OWASP Release Quality Tool|OWASP Release Quality Tool]]&lt;br /&gt;
[[Category:OWASP_Download]]&lt;br /&gt;
[[Category:Popular]]&lt;br /&gt;
[[Category:SAMM-ST-2]]&lt;br /&gt;
[[Category:Flagship Projects|Zap]]&lt;br /&gt;
[[Category:OWASP Zed Attack Proxy|Zap]]&lt;/div&gt;</summary>
		<author><name>Psiinon</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Zed_Attack_Proxy_Project&amp;diff=232114</id>
		<title>OWASP Zed Attack Proxy Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Zed_Attack_Proxy_Project&amp;diff=232114"/>
				<updated>2017-08-09T11:56:28Z</updated>
		
		<summary type="html">&lt;p&gt;Psiinon: Updated 2.7.0&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Main = &lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:90px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File: flagship_big.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
{{ReviewProject|projectname=zaproxy|language=en}}&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
The OWASP Zed Attack Proxy (ZAP) is one of the world’s most popular free security tools and is actively maintained by hundreds of international volunteers[[#Justification|*]]. It can help you automatically find security vulnerabilities in your web applications while you are developing and testing your applications. Its also a great tool for experienced pentesters to use for manual security testing.&lt;br /&gt;
&lt;br /&gt;
====ZAP 2.6.0 is now available and includes important security fixes. Please update asap!====&lt;br /&gt;
&lt;br /&gt;
[[Image:ZAP-Download.png | link=https://github.com/zaproxy/zaproxy/wiki/Downloads]]&lt;br /&gt;
&lt;br /&gt;
====Please help us to make ZAP even better for you by answering the [https://docs.google.com/forms/d/1-k-vcj_sSxlil6XLxCFade-m-IQVeE2h9gduA-2ZPPA/viewform ZAP User Questionnaire]!====&lt;br /&gt;
&lt;br /&gt;
For a quick overview of ZAP and an introduction to the [https://wiki.jenkins-ci.org/display/JENKINS/zap+plugin official ZAP Jenkins plugin] see these tutorial videos on YouTube:&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
{{#ev:youtube|eH0RBI0nmww}}&amp;amp;nbsp;&lt;br /&gt;
{{#ev:youtube|mmHZLSffCUg}}&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
For more videos see the links on the [https://github.com/zaproxy/zaproxy/wiki/Videos wiki videos page].&lt;br /&gt;
&lt;br /&gt;
Interested in a ZAP talk or training event? See the [https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project#tab=Talks talks] tab. Not one near you? Contact a [https://github.com/zaproxy/zaproxy/wiki/ZapEvangelists Zap Evangelist] to arrange one!&lt;br /&gt;
&lt;br /&gt;
{{#widget:PayPal Donation&lt;br /&gt;
|target=_blank&lt;br /&gt;
|budget=Zed Attack Proxy&lt;br /&gt;
}}  &lt;br /&gt;
&lt;br /&gt;
For general information about ZAP:&lt;br /&gt;
* [https://twitter.com/zaproxy Twitter] - official ZAP announcements (low volume)&lt;br /&gt;
* [https://zaproxy.blogspot.co.uk/ Blog] - official ZAP blog&lt;br /&gt;
&lt;br /&gt;
For help using ZAP:&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/releases/download/2.6.0/ZAPGettingStartedGuide-2.6.pdf Getting Started Guide (pdf)] - an introductory guide you can print&lt;br /&gt;
* [https://www.youtube.com/playlist?list=PLEBitBW-Hlsv8cEIUntAO8st2UGhmrjUB Tutorial Videos]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki User Guide] - online version of the User Guide included with ZAP&lt;br /&gt;
* [https://groups.google.com/group/zaproxy-users User Group] - ask questions about using ZAP&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/wiki Add-ons] - help for the optional add-ons you can install&lt;br /&gt;
* [https://stackoverflow.com/questions/tagged/zap StackOverflow] - because some people use this for all everything ;)&lt;br /&gt;
&lt;br /&gt;
To learn more about ZAP development:&lt;br /&gt;
* [https://github.com/zaproxy Source Code] - for all of the ZAP related projects&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/wiki/Introduction Wiki] - lots of detailed info&lt;br /&gt;
* [https://groups.google.com/group/zaproxy-develop Developer Group] - ask questions about the ZAP internals&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap Crowdin (GUI)] - help translate the ZAP GUI&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap-help Crowdin (User Guide)] - help translate the ZAP User Guide&lt;br /&gt;
* [https://www.openhub.net/p/zaproxy OpenHub]	- FOSS analytics&lt;br /&gt;
* [https://www.bountysource.com/teams/zap/issues BountySource] - Vote on ZAP issues (you can also donate money here, but 10% taken out)&lt;br /&gt;
&lt;br /&gt;
===Justification===&lt;br /&gt;
Justification for the statements made in the tagline at the top;)&lt;br /&gt;
&lt;br /&gt;
Popularity:&lt;br /&gt;
* ToolsWatch Annual Best Free/Open Source Security Tool Survey:&lt;br /&gt;
** 2016 [http://www.toolswatch.org/2017/02/2016-top-security-tools-as-voted-by-toolswatch-org-readers/ 2nd]&lt;br /&gt;
** 2015 [http://www.toolswatch.org/2016/02/2015-top-security-tools-as-voted-by-toolswatch-org-readers/ 1st]&lt;br /&gt;
** 2014 [http://www.toolswatch.org/2015/01/2014-top-security-tools-as-voted-by-toolswatch-org-readers/ 2nd]&lt;br /&gt;
** 2013 [http://www.toolswatch.org/2013/12/2013-top-security-tools-as-voted-by-toolswatch-org-readers/ 1st]&lt;br /&gt;
&lt;br /&gt;
Contributors:&lt;br /&gt;
* [https://www.openhub.net/p/zaproxy Code Contributors]&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap ZAP core i18n Contributors]&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap-help ZAP help i18n Contributors]&lt;br /&gt;
&lt;br /&gt;
{{Social Media Links}}&lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;padding-left:25px;width:200px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
[https://github.com/zaproxy/zaproxy/wiki/Downloads Download OWASP ZAP!]&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
Please see the [https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project#News News] and [https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project#Talks Talks] tabs&lt;br /&gt;
&lt;br /&gt;
== Change Log ==&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/commits/develop zaproxy]&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/commits/master zap-extensions]&lt;br /&gt;
&lt;br /&gt;
== Code Repo ==&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/ zaproxy]&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/ zap-extensions]&lt;br /&gt;
&lt;br /&gt;
== Email List ==&lt;br /&gt;
&lt;br /&gt;
Questions? Please ask on the [http://groups.google.com/group/zaproxy-users ZAP User Group]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
Project Leader&amp;lt;br /&amp;gt;[https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_Web_Testing_Environment_Project OWASP WTE]&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_OWTF OWASP OWTF]&lt;br /&gt;
&lt;br /&gt;
== Ohloh ==&lt;br /&gt;
&lt;br /&gt;
*https://www.openhub.net/p/zaproxy&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| cellpadding=&amp;quot;2&amp;quot; width=&amp;quot;200&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Mature projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Flagship_Projects]]&lt;br /&gt;
   | width=&amp;quot;50%&amp;quot; valign=&amp;quot;center&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Owasp-builders-small.png|link=]]&lt;br /&gt;
   |&lt;br /&gt;
   |-&lt;br /&gt;
   | width=&amp;quot;50%&amp;quot; valign=&amp;quot;center&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Owasp-breakers-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [http://www.apache.org/licenses/LICENSE-2.0 Apache 2 License]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_TOOL.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Screenshots =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotAddAlert.png|||400px|ZAP Add Alert Screen Shot]] &lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotHelp.png||400px|left|ZAP Help Screen Shot]]&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotHistoryFilter.png|thumb|400px|left|ZAP History Filter Screen Shot]]&lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotSearchTab.png|thumb|400px|left|ZAP Search Tab Screen Shot]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Talks =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
{{:Projects/OWASP Zed Attack Proxy Project/Pages/Talks | Talks}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
= News =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
{{:Projects/OWASP Zed Attack Proxy Project/Pages/News | News}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
= ZAP Gear =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Yes, you can now buy ZAP related gear!&lt;br /&gt;
&lt;br /&gt;
All of the artwork for ZAP swag is released under the Creative Common License and can be downloaded from the [https://github.com/zaproxy/zap-swag zap-swag] repo.&lt;br /&gt;
&lt;br /&gt;
You can of course use the artwork from this repo with any other online store that you like.&lt;br /&gt;
&lt;br /&gt;
A range of products can be purchased from [http://www.redbubble.com/people/zaproxy Redbubble]&lt;br /&gt;
&lt;br /&gt;
Stickers can be purchased from [https://www.stickermule.com/uk/user/1070684077/stickers Stickermule]&lt;br /&gt;
&lt;br /&gt;
T-shirts can be purchased from [http://www.cafepress.com/zaproxy Cafepress]&lt;br /&gt;
&lt;br /&gt;
[[Image:zap-tshirt-cp.PNG | link=http://www.cafepress.com/zaproxy]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Supporters =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
ZAP is developed by a worldwide [https://github.com/zaproxy/zap-core-help/wiki/HelpCredits team] of volunteers.&lt;br /&gt;
&lt;br /&gt;
But we have also been helped by many organizations, either financially or by encouraging their employees to work on ZAP:&lt;br /&gt;
&lt;br /&gt;
* [http://www.mozilla.org Mozilla]&lt;br /&gt;
* [http://www.linuxfoundation.org/ The Linux Foundation]&lt;br /&gt;
* [http://www.owasp.org OWASP]&lt;br /&gt;
* [http://www.sage.co.uk Sage]&lt;br /&gt;
* [http://www.google.com Google]&lt;br /&gt;
* [http://www.microsoft.com Microsoft]&lt;br /&gt;
* [http://www.hacktics.com/ Hacktics, Ernst &amp;amp; Young]&lt;br /&gt;
* [http://www.dinosec.com/ DinoSec]&lt;br /&gt;
* [http://www.denimgroup.com Denim Group]&lt;br /&gt;
* [http://www.aspectsecurity.com/ Aspect Security]&lt;br /&gt;
* [http://secureideas.net SecureIdeas]&lt;br /&gt;
* [http://utilisec.com UtiliSec]&lt;br /&gt;
* [http://www.encription.co.uk/ encription]&lt;br /&gt;
* [https://www.accenture.com/us-en/digital-index.aspx Accenture Digital]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Functionality =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
'''Some of ZAP's functionality:'''&lt;br /&gt;
&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsIntercept Intercepting Proxy]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsSpider Traditional] and AJAX spiders&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsAscan Automated scanner]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsPscan Passive scanner]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsBruteforce Forced browsing]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsFuzz Fuzzer]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpUiDialogsOptionsDynsslcert Dynamic SSL certificates]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/SmartCards Smartcard and Client Digital Certificates support]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpAddonsWebsocketIntroduction Web sockets] support&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpAddonsScriptsScripts Support for a wide range of scripting languages]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki//HelpAddonsPlugnhackPlugnhack Plug-n-Hack support]&lt;br /&gt;
* Authentication and session support&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsApi Powerful REST based API]&lt;br /&gt;
* Automatic updating option&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/wiki Integrated and growing marketplace of add-ons]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
= Features =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
'''Some of ZAP's features:'''&lt;br /&gt;
&lt;br /&gt;
* [http://www.apache.org/licenses/LICENSE-2.0 Open source]&lt;br /&gt;
* Cross platform (it even runs on a [https://github.com/zaproxy/zaproxy/wiki/zappi Raspberry Pi!])&lt;br /&gt;
* Easy to install (using a [https://www.ej-technologies.com/products/install4j/overview.html multi-platform installer builder])&lt;br /&gt;
* Completely free (no paid for 'Pro' version)&lt;br /&gt;
* Ease of use a priority&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpIntro Comprehensive help pages]&lt;br /&gt;
* Fully internationalized&lt;br /&gt;
* Translated into over 20 languages&lt;br /&gt;
* Community based, with involvement actively encouraged&lt;br /&gt;
* Under active development by an international team of volunteers&lt;br /&gt;
&lt;br /&gt;
ZAP is a fork of the well regarded [http://www.parosproxy.org/ Paros Proxy].&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Languages =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''ZAP supports the following languages:'''&lt;br /&gt;
&lt;br /&gt;
* English&lt;br /&gt;
* Arabic&lt;br /&gt;
* Bosnian&lt;br /&gt;
* Brazilian Portuguese&lt;br /&gt;
* Chinese&lt;br /&gt;
* Danish&lt;br /&gt;
* Filipino&lt;br /&gt;
* French&lt;br /&gt;
* German&lt;br /&gt;
* Greek&lt;br /&gt;
* Hungarian&lt;br /&gt;
* Indonesian&lt;br /&gt;
* Italian&lt;br /&gt;
* Japanese&lt;br /&gt;
* Korean&lt;br /&gt;
* Persian&lt;br /&gt;
* Polish&lt;br /&gt;
* Russian&lt;br /&gt;
* Sinhala&lt;br /&gt;
* Spanish&lt;br /&gt;
* Urdu &lt;br /&gt;
&lt;br /&gt;
You can use [http://crowdin.net/project/owasp-zap Crowdin] to help improve these translations or add new ones right now!&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Release 2.6.0==&lt;br /&gt;
ZAP 2.6.0 has been released, this is a bug fix and enhancement release&lt;br /&gt;
&lt;br /&gt;
For more details see https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_6_0&lt;br /&gt;
&lt;br /&gt;
==Release 2.7.0==&lt;br /&gt;
ZAP 2.7.0 is being actively worked on, and is expected to be released relatively soon.&lt;br /&gt;
&lt;br /&gt;
It will require Java 8 (minimum) and will support Selenium 3. It will also include all of the changes currrently available in the [https://github.com/zaproxy/zaproxy/wiki/Downloads#zap-weekly weekly release].&lt;br /&gt;
&lt;br /&gt;
==Release 2.8.0==&lt;br /&gt;
ZAP 2.8.0 does not yet have a planned release date, but is likely to be around the end of 2017 or (more likely) the beginning of 2018.&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Get Involved =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Involvement in the development of ZAP is actively encouraged!&lt;br /&gt;
&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
&lt;br /&gt;
Some of the ways you can help:&lt;br /&gt;
&lt;br /&gt;
==Feature Requests==&lt;br /&gt;
&lt;br /&gt;
Please raise new feature requests as enhancement requests here: https://github.com/zaproxy/zaproxy/issues&lt;br /&gt;
&lt;br /&gt;
If there are existing requests you are also interested in then please 'star' them - that way we can see which features people are most interested in and can prioritize them accordingly. &lt;br /&gt;
&lt;br /&gt;
==Feedback==&lt;br /&gt;
&lt;br /&gt;
Please use the [http://groups.google.com/group/zaproxy-users zaproxy-users Google Group] for feedback:&lt;br /&gt;
* What do like?&lt;br /&gt;
* What don't you like?&lt;br /&gt;
* What features could be made easier to use?&lt;br /&gt;
* How could the help pages be improved? &lt;br /&gt;
&lt;br /&gt;
==Log issues==&lt;br /&gt;
&lt;br /&gt;
Have you had a problem using ZAP?&lt;br /&gt;
&lt;br /&gt;
If so and its not already been logged then please [https://github.com/zaproxy/zaproxy/issues report it]&lt;br /&gt;
&lt;br /&gt;
==Localization==&lt;br /&gt;
&lt;br /&gt;
Are you fluent in another language? Can you help translate ZAP into that language?&lt;br /&gt;
&lt;br /&gt;
You can use [http://crowdin.net/project/owasp-zap Crowdin] to do that!&lt;br /&gt;
&lt;br /&gt;
==Development==&lt;br /&gt;
&lt;br /&gt;
If you fancy having a go at adding functionality to ZAP then please get in touch via the [http://groups.google.com/group/zaproxy-develop zaproxy-develop Google Group].&lt;br /&gt;
&lt;br /&gt;
Again, you do not have to be a security expert to contribute code - working on ZAP could be great way to learn more about web application security!&lt;br /&gt;
&lt;br /&gt;
If you actively contribute to ZAP then you will be invited to join the project. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project|Zed Attack Proxy Project]]&lt;br /&gt;
[[Category:OWASP_Tool]]&lt;br /&gt;
[[Category:OWASP Release Quality Tool|OWASP Release Quality Tool]]&lt;br /&gt;
[[Category:OWASP_Download]]&lt;br /&gt;
[[Category:Popular]]&lt;br /&gt;
[[Category:SAMM-ST-2]]&lt;br /&gt;
[[Category:Flagship Projects|Zap]]&lt;br /&gt;
[[Category:OWASP Zed Attack Proxy|Zap]]&lt;/div&gt;</summary>
		<author><name>Psiinon</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Zed_Attack_Proxy_Project&amp;diff=232113</id>
		<title>OWASP Zed Attack Proxy Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Zed_Attack_Proxy_Project&amp;diff=232113"/>
				<updated>2017-08-09T11:47:52Z</updated>
		
		<summary type="html">&lt;p&gt;Psiinon: Updated roadmap&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Main = &lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:90px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File: flagship_big.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
{{ReviewProject|projectname=zaproxy|language=en}}&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
The OWASP Zed Attack Proxy (ZAP) is one of the world’s most popular free security tools and is actively maintained by hundreds of international volunteers[[#Justification|*]]. It can help you automatically find security vulnerabilities in your web applications while you are developing and testing your applications. Its also a great tool for experienced pentesters to use for manual security testing.&lt;br /&gt;
&lt;br /&gt;
====ZAP 2.6.0 is now available and includes important security fixes. Please update asap!====&lt;br /&gt;
&lt;br /&gt;
[[Image:ZAP-Download.png | link=https://github.com/zaproxy/zaproxy/wiki/Downloads]]&lt;br /&gt;
&lt;br /&gt;
====Please help us to make ZAP even better for you by answering the [https://docs.google.com/forms/d/1-k-vcj_sSxlil6XLxCFade-m-IQVeE2h9gduA-2ZPPA/viewform ZAP User Questionnaire]!====&lt;br /&gt;
&lt;br /&gt;
For a quick overview of ZAP and an introduction to the [https://wiki.jenkins-ci.org/display/JENKINS/zap+plugin official ZAP Jenkins plugin] see these tutorial videos on YouTube:&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
{{#ev:youtube|eH0RBI0nmww}}&amp;amp;nbsp;&lt;br /&gt;
{{#ev:youtube|mmHZLSffCUg}}&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
For more videos see the links on the [https://github.com/zaproxy/zaproxy/wiki/Videos wiki videos page].&lt;br /&gt;
&lt;br /&gt;
Interested in a ZAP talk or training event? See the [https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project#tab=Talks talks] tab. Not one near you? Contact a [https://github.com/zaproxy/zaproxy/wiki/ZapEvangelists Zap Evangelist] to arrange one!&lt;br /&gt;
&lt;br /&gt;
{{#widget:PayPal Donation&lt;br /&gt;
|target=_blank&lt;br /&gt;
|budget=Zed Attack Proxy&lt;br /&gt;
}}  &lt;br /&gt;
&lt;br /&gt;
For general information about ZAP:&lt;br /&gt;
* [https://twitter.com/zaproxy Twitter] - official ZAP announcements (low volume)&lt;br /&gt;
* [https://zaproxy.blogspot.co.uk/ Blog] - official ZAP blog&lt;br /&gt;
&lt;br /&gt;
For help using ZAP:&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/releases/download/2.6.0/ZAPGettingStartedGuide-2.6.pdf Getting Started Guide (pdf)] - an introductory guide you can print&lt;br /&gt;
* [https://www.youtube.com/playlist?list=PLEBitBW-Hlsv8cEIUntAO8st2UGhmrjUB Tutorial Videos]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki User Guide] - online version of the User Guide included with ZAP&lt;br /&gt;
* [https://groups.google.com/group/zaproxy-users User Group] - ask questions about using ZAP&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/wiki Add-ons] - help for the optional add-ons you can install&lt;br /&gt;
* [https://stackoverflow.com/questions/tagged/zap StackOverflow] - because some people use this for all everything ;)&lt;br /&gt;
&lt;br /&gt;
To learn more about ZAP development:&lt;br /&gt;
* [https://github.com/zaproxy Source Code] - for all of the ZAP related projects&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/wiki/Introduction Wiki] - lots of detailed info&lt;br /&gt;
* [https://groups.google.com/group/zaproxy-develop Developer Group] - ask questions about the ZAP internals&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap Crowdin (GUI)] - help translate the ZAP GUI&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap-help Crowdin (User Guide)] - help translate the ZAP User Guide&lt;br /&gt;
* [https://www.openhub.net/p/zaproxy OpenHub]	- FOSS analytics&lt;br /&gt;
* [https://www.bountysource.com/teams/zap/issues BountySource] - Vote on ZAP issues (you can also donate money here, but 10% taken out)&lt;br /&gt;
&lt;br /&gt;
===Justification===&lt;br /&gt;
Justification for the statements made in the tagline at the top;)&lt;br /&gt;
&lt;br /&gt;
Popularity:&lt;br /&gt;
* ToolsWatch Annual Best Free/Open Source Security Tool Survey:&lt;br /&gt;
** 2016 [http://www.toolswatch.org/2017/02/2016-top-security-tools-as-voted-by-toolswatch-org-readers/ 2nd]&lt;br /&gt;
** 2015 [http://www.toolswatch.org/2016/02/2015-top-security-tools-as-voted-by-toolswatch-org-readers/ 1st]&lt;br /&gt;
** 2014 [http://www.toolswatch.org/2015/01/2014-top-security-tools-as-voted-by-toolswatch-org-readers/ 2nd]&lt;br /&gt;
** 2013 [http://www.toolswatch.org/2013/12/2013-top-security-tools-as-voted-by-toolswatch-org-readers/ 1st]&lt;br /&gt;
&lt;br /&gt;
Contributors:&lt;br /&gt;
* [https://www.openhub.net/p/zaproxy Code Contributors]&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap ZAP core i18n Contributors]&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap-help ZAP help i18n Contributors]&lt;br /&gt;
&lt;br /&gt;
{{Social Media Links}}&lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;padding-left:25px;width:200px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
[https://github.com/zaproxy/zaproxy/wiki/Downloads Download OWASP ZAP!]&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
Please see the [https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project#News News] and [https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project#Talks Talks] tabs&lt;br /&gt;
&lt;br /&gt;
== Change Log ==&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/commits/develop zaproxy]&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/commits/master zap-extensions]&lt;br /&gt;
&lt;br /&gt;
== Code Repo ==&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/ zaproxy]&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/ zap-extensions]&lt;br /&gt;
&lt;br /&gt;
== Email List ==&lt;br /&gt;
&lt;br /&gt;
Questions? Please ask on the [http://groups.google.com/group/zaproxy-users ZAP User Group]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
Project Leader&amp;lt;br /&amp;gt;[https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_Web_Testing_Environment_Project OWASP WTE]&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_OWTF OWASP OWTF]&lt;br /&gt;
&lt;br /&gt;
== Ohloh ==&lt;br /&gt;
&lt;br /&gt;
*https://www.openhub.net/p/zaproxy&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| cellpadding=&amp;quot;2&amp;quot; width=&amp;quot;200&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Mature projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Flagship_Projects]]&lt;br /&gt;
   | width=&amp;quot;50%&amp;quot; valign=&amp;quot;center&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Owasp-builders-small.png|link=]]&lt;br /&gt;
   |&lt;br /&gt;
   |-&lt;br /&gt;
   | width=&amp;quot;50%&amp;quot; valign=&amp;quot;center&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Owasp-breakers-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [http://www.apache.org/licenses/LICENSE-2.0 Apache 2 License]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_TOOL.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Screenshots =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotAddAlert.png|||400px|ZAP Add Alert Screen Shot]] &lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotHelp.png||400px|left|ZAP Help Screen Shot]]&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotHistoryFilter.png|thumb|400px|left|ZAP History Filter Screen Shot]]&lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotSearchTab.png|thumb|400px|left|ZAP Search Tab Screen Shot]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Talks =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
{{:Projects/OWASP Zed Attack Proxy Project/Pages/Talks | Talks}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
= News =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
{{:Projects/OWASP Zed Attack Proxy Project/Pages/News | News}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
= ZAP Gear =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Yes, you can now buy ZAP related gear!&lt;br /&gt;
&lt;br /&gt;
All of the artwork for ZAP swag is released under the Creative Common License and can be downloaded from the [https://github.com/zaproxy/zap-swag zap-swag] repo.&lt;br /&gt;
&lt;br /&gt;
You can of course use the artwork from this repo with any other online store that you like.&lt;br /&gt;
&lt;br /&gt;
A range of products can be purchased from [http://www.redbubble.com/people/zaproxy Redbubble]&lt;br /&gt;
&lt;br /&gt;
Stickers can be purchased from [https://www.stickermule.com/uk/user/1070684077/stickers Stickermule]&lt;br /&gt;
&lt;br /&gt;
T-shirts can be purchased from [http://www.cafepress.com/zaproxy Cafepress]&lt;br /&gt;
&lt;br /&gt;
[[Image:zap-tshirt-cp.PNG | link=http://www.cafepress.com/zaproxy]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Supporters =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
ZAP is developed by a worldwide [https://github.com/zaproxy/zap-core-help/wiki/HelpCredits team] of volunteers.&lt;br /&gt;
&lt;br /&gt;
But we have also been helped by many organizations, either financially or by encouraging their employees to work on ZAP:&lt;br /&gt;
&lt;br /&gt;
* [http://www.mozilla.org Mozilla]&lt;br /&gt;
* [http://www.linuxfoundation.org/ The Linux Foundation]&lt;br /&gt;
* [http://www.owasp.org OWASP]&lt;br /&gt;
* [http://www.sage.co.uk Sage]&lt;br /&gt;
* [http://www.google.com Google]&lt;br /&gt;
* [http://www.microsoft.com Microsoft]&lt;br /&gt;
* [http://www.hacktics.com/ Hacktics, Ernst &amp;amp; Young]&lt;br /&gt;
* [http://www.dinosec.com/ DinoSec]&lt;br /&gt;
* [http://www.denimgroup.com Denim Group]&lt;br /&gt;
* [http://www.aspectsecurity.com/ Aspect Security]&lt;br /&gt;
* [http://secureideas.net SecureIdeas]&lt;br /&gt;
* [http://utilisec.com UtiliSec]&lt;br /&gt;
* [http://www.encription.co.uk/ encription]&lt;br /&gt;
* [https://www.accenture.com/us-en/digital-index.aspx Accenture Digital]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Functionality =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
'''Some of ZAP's functionality:'''&lt;br /&gt;
&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsIntercept Intercepting Proxy]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsSpider Traditional] and AJAX spiders&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsAscan Automated scanner]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsPscan Passive scanner]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsBruteforce Forced browsing]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsFuzz Fuzzer]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpUiDialogsOptionsDynsslcert Dynamic SSL certificates]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/SmartCards Smartcard and Client Digital Certificates support]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpAddonsWebsocketIntroduction Web sockets] support&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpAddonsScriptsScripts Support for a wide range of scripting languages]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki//HelpAddonsPlugnhackPlugnhack Plug-n-Hack support]&lt;br /&gt;
* Authentication and session support&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsApi Powerful REST based API]&lt;br /&gt;
* Automatic updating option&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/wiki Integrated and growing marketplace of add-ons]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
= Features =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
'''Some of ZAP's features:'''&lt;br /&gt;
&lt;br /&gt;
* [http://www.apache.org/licenses/LICENSE-2.0 Open source]&lt;br /&gt;
* Cross platform (it even runs on a [https://github.com/zaproxy/zaproxy/wiki/zappi Raspberry Pi!])&lt;br /&gt;
* Easy to install (using a [https://www.ej-technologies.com/products/install4j/overview.html multi-platform installer builder])&lt;br /&gt;
* Completely free (no paid for 'Pro' version)&lt;br /&gt;
* Ease of use a priority&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpIntro Comprehensive help pages]&lt;br /&gt;
* Fully internationalized&lt;br /&gt;
* Translated into over 20 languages&lt;br /&gt;
* Community based, with involvement actively encouraged&lt;br /&gt;
* Under active development by an international team of volunteers&lt;br /&gt;
&lt;br /&gt;
ZAP is a fork of the well regarded [http://www.parosproxy.org/ Paros Proxy].&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Languages =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''ZAP supports the following languages:'''&lt;br /&gt;
&lt;br /&gt;
* English&lt;br /&gt;
* Arabic&lt;br /&gt;
* Bosnian&lt;br /&gt;
* Brazilian Portuguese&lt;br /&gt;
* Chinese&lt;br /&gt;
* Danish&lt;br /&gt;
* Filipino&lt;br /&gt;
* French&lt;br /&gt;
* German&lt;br /&gt;
* Greek&lt;br /&gt;
* Hungarian&lt;br /&gt;
* Indonesian&lt;br /&gt;
* Italian&lt;br /&gt;
* Japanese&lt;br /&gt;
* Korean&lt;br /&gt;
* Persian&lt;br /&gt;
* Polish&lt;br /&gt;
* Russian&lt;br /&gt;
* Sinhala&lt;br /&gt;
* Spanish&lt;br /&gt;
* Urdu &lt;br /&gt;
&lt;br /&gt;
You can use [http://crowdin.net/project/owasp-zap Crowdin] to help improve these translations or add new ones right now!&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Release 2.6.0==&lt;br /&gt;
ZAP 2.6.0 has been released, this is a bug fix and enhancement release&lt;br /&gt;
&lt;br /&gt;
For more details see https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_6_0&lt;br /&gt;
&lt;br /&gt;
==Release 2.7.0==&lt;br /&gt;
ZAP 2.7.0 is being actively worked on, and is expected to be released relatively soon.&lt;br /&gt;
&lt;br /&gt;
==Release 2.8.0==&lt;br /&gt;
ZAP 2.8.0 does not yet have a planned release date, but is likely to be around the end of 2017 or (more likely) the beginning of 2018.&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Get Involved =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Involvement in the development of ZAP is actively encouraged!&lt;br /&gt;
&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
&lt;br /&gt;
Some of the ways you can help:&lt;br /&gt;
&lt;br /&gt;
==Feature Requests==&lt;br /&gt;
&lt;br /&gt;
Please raise new feature requests as enhancement requests here: https://github.com/zaproxy/zaproxy/issues&lt;br /&gt;
&lt;br /&gt;
If there are existing requests you are also interested in then please 'star' them - that way we can see which features people are most interested in and can prioritize them accordingly. &lt;br /&gt;
&lt;br /&gt;
==Feedback==&lt;br /&gt;
&lt;br /&gt;
Please use the [http://groups.google.com/group/zaproxy-users zaproxy-users Google Group] for feedback:&lt;br /&gt;
* What do like?&lt;br /&gt;
* What don't you like?&lt;br /&gt;
* What features could be made easier to use?&lt;br /&gt;
* How could the help pages be improved? &lt;br /&gt;
&lt;br /&gt;
==Log issues==&lt;br /&gt;
&lt;br /&gt;
Have you had a problem using ZAP?&lt;br /&gt;
&lt;br /&gt;
If so and its not already been logged then please [https://github.com/zaproxy/zaproxy/issues report it]&lt;br /&gt;
&lt;br /&gt;
==Localization==&lt;br /&gt;
&lt;br /&gt;
Are you fluent in another language? Can you help translate ZAP into that language?&lt;br /&gt;
&lt;br /&gt;
You can use [http://crowdin.net/project/owasp-zap Crowdin] to do that!&lt;br /&gt;
&lt;br /&gt;
==Development==&lt;br /&gt;
&lt;br /&gt;
If you fancy having a go at adding functionality to ZAP then please get in touch via the [http://groups.google.com/group/zaproxy-develop zaproxy-develop Google Group].&lt;br /&gt;
&lt;br /&gt;
Again, you do not have to be a security expert to contribute code - working on ZAP could be great way to learn more about web application security!&lt;br /&gt;
&lt;br /&gt;
If you actively contribute to ZAP then you will be invited to join the project. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project|Zed Attack Proxy Project]]&lt;br /&gt;
[[Category:OWASP_Tool]]&lt;br /&gt;
[[Category:OWASP Release Quality Tool|OWASP Release Quality Tool]]&lt;br /&gt;
[[Category:OWASP_Download]]&lt;br /&gt;
[[Category:Popular]]&lt;br /&gt;
[[Category:SAMM-ST-2]]&lt;br /&gt;
[[Category:Flagship Projects|Zap]]&lt;br /&gt;
[[Category:OWASP Zed Attack Proxy|Zap]]&lt;/div&gt;</summary>
		<author><name>Psiinon</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Zed_Attack_Proxy_Project&amp;diff=228311</id>
		<title>OWASP Zed Attack Proxy Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Zed_Attack_Proxy_Project&amp;diff=228311"/>
				<updated>2017-04-04T17:38:46Z</updated>
		
		<summary type="html">&lt;p&gt;Psiinon: Fixed donate button&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Main = &lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:90px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File: flagship_big.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
{{ReviewProject|projectname=zaproxy|language=en}}&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
The OWASP Zed Attack Proxy (ZAP) is one of the world’s most popular free security tools and is actively maintained by hundreds of international volunteers[[#Justification|*]]. It can help you automatically find security vulnerabilities in your web applications while you are developing and testing your applications. Its also a great tool for experienced pentesters to use for manual security testing.&lt;br /&gt;
&lt;br /&gt;
====ZAP 2.6.0 is now available and includes important security fixes. Please update asap!====&lt;br /&gt;
&lt;br /&gt;
[[Image:ZAP-Download.png | link=https://github.com/zaproxy/zaproxy/wiki/Downloads]]&lt;br /&gt;
&lt;br /&gt;
====Please help us to make ZAP even better for you by answering the [https://docs.google.com/forms/d/1-k-vcj_sSxlil6XLxCFade-m-IQVeE2h9gduA-2ZPPA/viewform ZAP User Questionnaire]!====&lt;br /&gt;
&lt;br /&gt;
For a quick overview of ZAP and an introduction to the [https://wiki.jenkins-ci.org/display/JENKINS/zap+plugin official ZAP Jenkins plugin] see these tutorial videos on YouTube:&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
{{#ev:youtube|eH0RBI0nmww}}&amp;amp;nbsp;&lt;br /&gt;
{{#ev:youtube|mmHZLSffCUg}}&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
For more videos see the links on the [https://github.com/zaproxy/zaproxy/wiki/Videos wiki videos page].&lt;br /&gt;
&lt;br /&gt;
Interested in a ZAP talk or training event? See the [https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project#tab=Talks talks] tab. Not one near you? Contact a [https://github.com/zaproxy/zaproxy/wiki/ZapEvangelists Zap Evangelist] to arrange one!&lt;br /&gt;
&lt;br /&gt;
{{#widget:PayPal Donation&lt;br /&gt;
|target=_blank&lt;br /&gt;
|budget=Zed Attack Proxy&lt;br /&gt;
}}  &lt;br /&gt;
&lt;br /&gt;
For general information about ZAP:&lt;br /&gt;
* [https://twitter.com/zaproxy Twitter] - official ZAP announcements (low volume)&lt;br /&gt;
* [https://zaproxy.blogspot.co.uk/ Blog] - official ZAP blog&lt;br /&gt;
&lt;br /&gt;
For help using ZAP:&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/releases/download/2.6.0/ZAPGettingStartedGuide-2.6.pdf Getting Started Guide (pdf)] - an introductory guide you can print&lt;br /&gt;
* [https://www.youtube.com/playlist?list=PLEBitBW-Hlsv8cEIUntAO8st2UGhmrjUB Tutorial Videos]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki User Guide] - online version of the User Guide included with ZAP&lt;br /&gt;
* [https://groups.google.com/group/zaproxy-users User Group] - ask questions about using ZAP&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/wiki Add-ons] - help for the optional add-ons you can install&lt;br /&gt;
* [https://stackoverflow.com/questions/tagged/zap StackOverflow] - because some people use this for all everything ;)&lt;br /&gt;
&lt;br /&gt;
To learn more about ZAP development:&lt;br /&gt;
* [https://github.com/zaproxy Source Code] - for all of the ZAP related projects&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/wiki/Introduction Wiki] - lots of detailed info&lt;br /&gt;
* [https://groups.google.com/group/zaproxy-develop Developer Group] - ask questions about the ZAP internals&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap Crowdin (GUI)] - help translate the ZAP GUI&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap-help Crowdin (User Guide)] - help translate the ZAP User Guide&lt;br /&gt;
* [https://www.openhub.net/p/zaproxy OpenHub]	- FOSS analytics&lt;br /&gt;
* [https://www.bountysource.com/teams/zap/issues BountySource] - Vote on ZAP issues (you can also donate money here, but 10% taken out)&lt;br /&gt;
&lt;br /&gt;
===Justification===&lt;br /&gt;
Justification for the statements made in the tagline at the top;)&lt;br /&gt;
&lt;br /&gt;
Popularity:&lt;br /&gt;
* ToolsWatch Annual Best Free/Open Source Security Tool Survey:&lt;br /&gt;
** 2016 [http://www.toolswatch.org/2017/02/2016-top-security-tools-as-voted-by-toolswatch-org-readers/ 2nd]&lt;br /&gt;
** 2015 [http://www.toolswatch.org/2016/02/2015-top-security-tools-as-voted-by-toolswatch-org-readers/ 1st]&lt;br /&gt;
** 2014 [http://www.toolswatch.org/2015/01/2014-top-security-tools-as-voted-by-toolswatch-org-readers/ 2nd]&lt;br /&gt;
** 2013 [http://www.toolswatch.org/2013/12/2013-top-security-tools-as-voted-by-toolswatch-org-readers/ 1st]&lt;br /&gt;
&lt;br /&gt;
Contributors:&lt;br /&gt;
* [https://www.openhub.net/p/zaproxy Code Contributors]&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap ZAP core i18n Contributors]&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap-help ZAP help i18n Contributors]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{{Social Media Links}}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
[https://github.com/zaproxy/zaproxy/wiki/Downloads Download OWASP ZAP!]&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
Please see the [https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project#News News] and [https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project#Talks Talks] tabs&lt;br /&gt;
&lt;br /&gt;
== Change Log ==&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/commits/develop zaproxy]&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/commits/master zap-extensions]&lt;br /&gt;
&lt;br /&gt;
== Code Repo ==&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/ zaproxy]&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/ zap-extensions]&lt;br /&gt;
&lt;br /&gt;
== Email List ==&lt;br /&gt;
&lt;br /&gt;
Questions? Please ask on the [http://groups.google.com/group/zaproxy-users ZAP User Group]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
Project Leader&amp;lt;br/&amp;gt;[https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_Web_Testing_Environment_Project OWASP WTE]&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_OWTF OWASP OWTF]&lt;br /&gt;
&lt;br /&gt;
== Ohloh ==&lt;br /&gt;
&lt;br /&gt;
*https://www.openhub.net/p/zaproxy&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; rowspan=&amp;quot;2&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Mature projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Flagship_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;center&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]&lt;br /&gt;
   |&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;center&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-breakers-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [http://www.apache.org/licenses/LICENSE-2.0 Apache 2 License]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Screenshots =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotAddAlert.png||400px||ZAP Add Alert Screen Shot]] &lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotHelp.png||400px|left|ZAP Help Screen Shot]]&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotHistoryFilter.png|thumb|400px|left|ZAP History Filter Screen Shot]]&lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotSearchTab.png|thumb|400px|left|ZAP Search Tab Screen Shot]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Talks =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
{{:Projects/OWASP Zed Attack Proxy Project/Pages/Talks | Talks}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
= News =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
{{:Projects/OWASP Zed Attack Proxy Project/Pages/News | News}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
= ZAP Gear =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Yes, you can now buy ZAP related gear!&lt;br /&gt;
&lt;br /&gt;
All of the artwork for ZAP swag is released under the Creative Common License and can be downloaded from the [https://github.com/zaproxy/zap-swag zap-swag] repo.&lt;br /&gt;
&lt;br /&gt;
You can of course use the artwork from this repo with any other online store that you like.&lt;br /&gt;
&lt;br /&gt;
A range of products can be purchased from [http://www.redbubble.com/people/zaproxy Redbubble]&lt;br /&gt;
&lt;br /&gt;
Stickers can be purchased from [https://www.stickermule.com/uk/user/1070684077/stickers Stickermule]&lt;br /&gt;
&lt;br /&gt;
T-shirts can be purchased from [http://www.cafepress.com/zaproxy Cafepress]&lt;br /&gt;
&lt;br /&gt;
[[Image:zap-tshirt-cp.PNG | link=http://www.cafepress.com/zaproxy]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Supporters =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
ZAP is developed by a worldwide [https://github.com/zaproxy/zap-core-help/wiki/HelpCredits team] of volunteers.&lt;br /&gt;
&lt;br /&gt;
But we have also been helped by many organizations, either financially or by encouraging their employees to work on ZAP:&lt;br /&gt;
&lt;br /&gt;
* [http://www.mozilla.org Mozilla]&lt;br /&gt;
* [http://www.linuxfoundation.org/ The Linux Foundation]&lt;br /&gt;
* [http://www.owasp.org OWASP]&lt;br /&gt;
* [http://www.sage.co.uk Sage]&lt;br /&gt;
* [http://www.google.com Google]&lt;br /&gt;
* [http://www.microsoft.com Microsoft]&lt;br /&gt;
* [http://www.hacktics.com/ Hacktics, Ernst &amp;amp; Young]&lt;br /&gt;
* [http://www.dinosec.com/ DinoSec]&lt;br /&gt;
* [http://www.denimgroup.com Denim Group]&lt;br /&gt;
* [http://www.aspectsecurity.com/ Aspect Security]&lt;br /&gt;
* [http://secureideas.net SecureIdeas]&lt;br /&gt;
* [http://utilisec.com UtiliSec]&lt;br /&gt;
* [http://www.encription.co.uk/ encription]&lt;br /&gt;
* [https://www.accenture.com/us-en/digital-index.aspx Accenture Digital]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Functionality =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
'''Some of ZAP's functionality:'''&lt;br /&gt;
&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsIntercept Intercepting Proxy]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsSpider Traditional] and AJAX spiders&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsAscan Automated scanner]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsPscan Passive scanner]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsBruteforce Forced browsing]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsFuzz Fuzzer]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpUiDialogsOptionsDynsslcert Dynamic SSL certificates]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/SmartCards Smartcard and Client Digital Certificates support]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpAddonsWebsocketIntroduction Web sockets] support&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpAddonsScriptsScripts Support for a wide range of scripting languages]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki//HelpAddonsPlugnhackPlugnhack Plug-n-Hack support]&lt;br /&gt;
* Authentication and session support&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsApi Powerful REST based API]&lt;br /&gt;
* Automatic updating option&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/wiki Integrated and growing marketplace of add-ons]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
= Features =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
'''Some of ZAP's features:'''&lt;br /&gt;
&lt;br /&gt;
* [http://www.apache.org/licenses/LICENSE-2.0 Open source]&lt;br /&gt;
* Cross platform (it even runs on a [https://github.com/zaproxy/zaproxy/wiki/zappi Raspberry Pi!])&lt;br /&gt;
* Easy to install (using a [https://www.ej-technologies.com/products/install4j/overview.html multi-platform installer builder])&lt;br /&gt;
* Completely free (no paid for 'Pro' version)&lt;br /&gt;
* Ease of use a priority&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpIntro Comprehensive help pages]&lt;br /&gt;
* Fully internationalized&lt;br /&gt;
* Translated into over 20 languages&lt;br /&gt;
* Community based, with involvement actively encouraged&lt;br /&gt;
* Under active development by an international team of volunteers&lt;br /&gt;
&lt;br /&gt;
ZAP is a fork of the well regarded [http://www.parosproxy.org/ Paros Proxy].&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Languages =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''ZAP supports the following languages:'''&lt;br /&gt;
&lt;br /&gt;
* English&lt;br /&gt;
* Arabic&lt;br /&gt;
* Bosnian&lt;br /&gt;
* Brazilian Portuguese&lt;br /&gt;
* Chinese&lt;br /&gt;
* Danish&lt;br /&gt;
* Filipino&lt;br /&gt;
* French&lt;br /&gt;
* German&lt;br /&gt;
* Greek&lt;br /&gt;
* Hungarian&lt;br /&gt;
* Indonesian&lt;br /&gt;
* Italian&lt;br /&gt;
* Japanese&lt;br /&gt;
* Korean&lt;br /&gt;
* Persian&lt;br /&gt;
* Polish&lt;br /&gt;
* Russian&lt;br /&gt;
* Sinhala&lt;br /&gt;
* Spanish&lt;br /&gt;
* Urdu &lt;br /&gt;
&lt;br /&gt;
You can use [http://crowdin.net/project/owasp-zap Crowdin] to help improve these translations or add new ones right now!&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Release 2.6.0==&lt;br /&gt;
ZAP 2.6.0 has been released, this is a bug fix and enhancement release&lt;br /&gt;
&lt;br /&gt;
For more details see https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_6_0&lt;br /&gt;
&lt;br /&gt;
==Release 2.7.0==&lt;br /&gt;
ZAP 2.7.0 is planned for around the end of June 2017.&lt;br /&gt;
&lt;br /&gt;
==Release 2.8.0==&lt;br /&gt;
ZAP 2.8.0 is planned for around the end of September 2017.&lt;br /&gt;
&lt;br /&gt;
==Release 2.9.0==&lt;br /&gt;
ZAP 2.9.0 is planned for around the end of December 2017.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Get Involved =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Involvement in the development of ZAP is actively encouraged!&lt;br /&gt;
&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
&lt;br /&gt;
Some of the ways you can help:&lt;br /&gt;
&lt;br /&gt;
==Feature Requests==&lt;br /&gt;
&lt;br /&gt;
Please raise new feature requests as enhancement requests here: https://github.com/zaproxy/zaproxy/issues&lt;br /&gt;
&lt;br /&gt;
If there are existing requests you are also interested in then please 'star' them - that way we can see which features people are most interested in and can prioritize them accordingly. &lt;br /&gt;
&lt;br /&gt;
==Feedback==&lt;br /&gt;
&lt;br /&gt;
Please use the [http://groups.google.com/group/zaproxy-users zaproxy-users Google Group] for feedback:&lt;br /&gt;
* What do like?&lt;br /&gt;
* What don't you like?&lt;br /&gt;
* What features could be made easier to use?&lt;br /&gt;
* How could the help pages be improved? &lt;br /&gt;
&lt;br /&gt;
==Log issues==&lt;br /&gt;
&lt;br /&gt;
Have you had a problem using ZAP?&lt;br /&gt;
&lt;br /&gt;
If so and its not already been logged then please [https://github.com/zaproxy/zaproxy/issues report it]&lt;br /&gt;
&lt;br /&gt;
==Localization==&lt;br /&gt;
&lt;br /&gt;
Are you fluent in another language? Can you help translate ZAP into that language?&lt;br /&gt;
&lt;br /&gt;
You can use [http://crowdin.net/project/owasp-zap Crowdin] to do that!&lt;br /&gt;
&lt;br /&gt;
==Development==&lt;br /&gt;
&lt;br /&gt;
If you fancy having a go at adding functionality to ZAP then please get in touch via the [http://groups.google.com/group/zaproxy-develop zaproxy-develop Google Group].&lt;br /&gt;
&lt;br /&gt;
Again, you do not have to be a security expert to contribute code - working on ZAP could be great way to learn more about web application security!&lt;br /&gt;
&lt;br /&gt;
If you actively contribute to ZAP then you will be invited to join the project. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Zed Attack Proxy Project]]&lt;br /&gt;
[[Category:OWASP_Tool]]&lt;br /&gt;
[[Category:OWASP_Release_Quality_Tool|OWASP Release Quality Tool]]&lt;br /&gt;
[[Category:OWASP_Download]]&lt;br /&gt;
[[Category:Popular]]&lt;br /&gt;
[[Category:SAMM-ST-2]]&lt;/div&gt;</summary>
		<author><name>Psiinon</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Zed_Attack_Proxy_Project&amp;diff=228094</id>
		<title>OWASP Zed Attack Proxy Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Zed_Attack_Proxy_Project&amp;diff=228094"/>
				<updated>2017-03-29T15:41:41Z</updated>
		
		<summary type="html">&lt;p&gt;Psiinon: Updated for installer&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Main = &lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:90px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File: flagship_big.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
{{ReviewProject|projectname=zaproxy|language=en}}&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
The OWASP Zed Attack Proxy (ZAP) is one of the world’s most popular free security tools and is actively maintained by hundreds of international volunteers[[#Justification|*]]. It can help you automatically find security vulnerabilities in your web applications while you are developing and testing your applications. Its also a great tool for experienced pentesters to use for manual security testing.&lt;br /&gt;
&lt;br /&gt;
====ZAP 2.6.0 is now available and includes important security fixes. Please update asap!====&lt;br /&gt;
&lt;br /&gt;
[[Image:ZAP-Download.png | link=https://github.com/zaproxy/zaproxy/wiki/Downloads]]&lt;br /&gt;
&lt;br /&gt;
====Please help us to make ZAP even better for you by answering the [https://docs.google.com/forms/d/1-k-vcj_sSxlil6XLxCFade-m-IQVeE2h9gduA-2ZPPA/viewform ZAP User Questionnaire]!====&lt;br /&gt;
&lt;br /&gt;
For a quick overview of ZAP and an introduction to the [https://wiki.jenkins-ci.org/display/JENKINS/zap+plugin official ZAP Jenkins plugin] see these tutorial videos on YouTube:&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
{{#ev:youtube|eH0RBI0nmww}}&amp;amp;nbsp;&lt;br /&gt;
{{#ev:youtube|mmHZLSffCUg}}&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
For more videos see the links on the [https://github.com/zaproxy/zaproxy/wiki/Videos wiki videos page].&lt;br /&gt;
&lt;br /&gt;
Interested in a ZAP talk or training event? See the [https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project#tab=Talks talks] tab. Not one near you? Contact a [https://github.com/zaproxy/zaproxy/wiki/ZapEvangelists Zap Evangelist] to arrange one!&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Zed Attack Proxy&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
For general information about ZAP:&lt;br /&gt;
* [https://twitter.com/zaproxy Twitter] - official ZAP announcements (low volume)&lt;br /&gt;
* [https://zaproxy.blogspot.co.uk/ Blog] - official ZAP blog&lt;br /&gt;
&lt;br /&gt;
For help using ZAP:&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/releases/download/2.6.0/ZAPGettingStartedGuide-2.6.pdf Getting Started Guide (pdf)] - an introductory guide you can print&lt;br /&gt;
* [https://www.youtube.com/playlist?list=PLEBitBW-Hlsv8cEIUntAO8st2UGhmrjUB Tutorial Videos]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki User Guide] - online version of the User Guide included with ZAP&lt;br /&gt;
* [https://groups.google.com/group/zaproxy-users User Group] - ask questions about using ZAP&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/wiki Add-ons] - help for the optional add-ons you can install&lt;br /&gt;
* [https://stackoverflow.com/questions/tagged/zap StackOverflow] - because some people use this for all everything ;)&lt;br /&gt;
&lt;br /&gt;
To learn more about ZAP development:&lt;br /&gt;
* [https://github.com/zaproxy Source Code] - for all of the ZAP related projects&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/wiki/Introduction Wiki] - lots of detailed info&lt;br /&gt;
* [https://groups.google.com/group/zaproxy-develop Developer Group] - ask questions about the ZAP internals&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap Crowdin (GUI)] - help translate the ZAP GUI&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap-help Crowdin (User Guide)] - help translate the ZAP User Guide&lt;br /&gt;
* [https://www.openhub.net/p/zaproxy OpenHub]	- FOSS analytics&lt;br /&gt;
* [https://www.bountysource.com/teams/zap/issues BountySource] - Vote on ZAP issues (you can also donate money here, but 10% taken out)&lt;br /&gt;
&lt;br /&gt;
===Justification===&lt;br /&gt;
Justification for the statements made in the tagline at the top;)&lt;br /&gt;
&lt;br /&gt;
Popularity:&lt;br /&gt;
* ToolsWatch Annual Best Free/Open Source Security Tool Survey:&lt;br /&gt;
** 2016 [http://www.toolswatch.org/2017/02/2016-top-security-tools-as-voted-by-toolswatch-org-readers/ 2nd]&lt;br /&gt;
** 2015 [http://www.toolswatch.org/2016/02/2015-top-security-tools-as-voted-by-toolswatch-org-readers/ 1st]&lt;br /&gt;
** 2014 [http://www.toolswatch.org/2015/01/2014-top-security-tools-as-voted-by-toolswatch-org-readers/ 2nd]&lt;br /&gt;
** 2013 [http://www.toolswatch.org/2013/12/2013-top-security-tools-as-voted-by-toolswatch-org-readers/ 1st]&lt;br /&gt;
&lt;br /&gt;
Contributors:&lt;br /&gt;
* [https://www.openhub.net/p/zaproxy Code Contributors]&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap ZAP core i18n Contributors]&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap-help ZAP help i18n Contributors]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{{Social Media Links}}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
[https://github.com/zaproxy/zaproxy/wiki/Downloads Download OWASP ZAP!]&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
Please see the [https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project#News News] and [https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project#Talks Talks] tabs&lt;br /&gt;
&lt;br /&gt;
== Change Log ==&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/commits/develop zaproxy]&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/commits/master zap-extensions]&lt;br /&gt;
&lt;br /&gt;
== Code Repo ==&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/ zaproxy]&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/ zap-extensions]&lt;br /&gt;
&lt;br /&gt;
== Email List ==&lt;br /&gt;
&lt;br /&gt;
Questions? Please ask on the [http://groups.google.com/group/zaproxy-users ZAP User Group]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
Project Leader&amp;lt;br/&amp;gt;[https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_Web_Testing_Environment_Project OWASP WTE]&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_OWTF OWASP OWTF]&lt;br /&gt;
&lt;br /&gt;
== Ohloh ==&lt;br /&gt;
&lt;br /&gt;
*https://www.openhub.net/p/zaproxy&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; rowspan=&amp;quot;2&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Mature projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Flagship_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;center&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]&lt;br /&gt;
   |&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;center&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-breakers-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [http://www.apache.org/licenses/LICENSE-2.0 Apache 2 License]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Screenshots =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotAddAlert.png||400px||ZAP Add Alert Screen Shot]] &lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotHelp.png||400px|left|ZAP Help Screen Shot]]&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotHistoryFilter.png|thumb|400px|left|ZAP History Filter Screen Shot]]&lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotSearchTab.png|thumb|400px|left|ZAP Search Tab Screen Shot]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Talks =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
{{:Projects/OWASP Zed Attack Proxy Project/Pages/Talks | Talks}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
= News =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
{{:Projects/OWASP Zed Attack Proxy Project/Pages/News | News}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
= ZAP Gear =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Yes, you can now buy ZAP related gear!&lt;br /&gt;
&lt;br /&gt;
All of the artwork for ZAP swag is released under the Creative Common License and can be downloaded from the [https://github.com/zaproxy/zap-swag zap-swag] repo.&lt;br /&gt;
&lt;br /&gt;
You can of course use the artwork from this repo with any other online store that you like.&lt;br /&gt;
&lt;br /&gt;
A range of products can be purchased from [http://www.redbubble.com/people/zaproxy Redbubble]&lt;br /&gt;
&lt;br /&gt;
Stickers can be purchased from [https://www.stickermule.com/uk/user/1070684077/stickers Stickermule]&lt;br /&gt;
&lt;br /&gt;
T-shirts can be purchased from [http://www.cafepress.com/zaproxy Cafepress]&lt;br /&gt;
&lt;br /&gt;
[[Image:zap-tshirt-cp.PNG | link=http://www.cafepress.com/zaproxy]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Supporters =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
ZAP is developed by a worldwide [https://github.com/zaproxy/zap-core-help/wiki/HelpCredits team] of volunteers.&lt;br /&gt;
&lt;br /&gt;
But we have also been helped by many organizations, either financially or by encouraging their employees to work on ZAP:&lt;br /&gt;
&lt;br /&gt;
* [http://www.mozilla.org Mozilla]&lt;br /&gt;
* [http://www.linuxfoundation.org/ The Linux Foundation]&lt;br /&gt;
* [http://www.owasp.org OWASP]&lt;br /&gt;
* [http://www.sage.co.uk Sage]&lt;br /&gt;
* [http://www.google.com Google]&lt;br /&gt;
* [http://www.microsoft.com Microsoft]&lt;br /&gt;
* [http://www.hacktics.com/ Hacktics, Ernst &amp;amp; Young]&lt;br /&gt;
* [http://www.dinosec.com/ DinoSec]&lt;br /&gt;
* [http://www.denimgroup.com Denim Group]&lt;br /&gt;
* [http://www.aspectsecurity.com/ Aspect Security]&lt;br /&gt;
* [http://secureideas.net SecureIdeas]&lt;br /&gt;
* [http://utilisec.com UtiliSec]&lt;br /&gt;
* [http://www.encription.co.uk/ encription]&lt;br /&gt;
* [https://www.accenture.com/us-en/digital-index.aspx Accenture Digital]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Functionality =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
'''Some of ZAP's functionality:'''&lt;br /&gt;
&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsIntercept Intercepting Proxy]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsSpider Traditional] and AJAX spiders&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsAscan Automated scanner]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsPscan Passive scanner]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsBruteforce Forced browsing]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsFuzz Fuzzer]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpUiDialogsOptionsDynsslcert Dynamic SSL certificates]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/SmartCards Smartcard and Client Digital Certificates support]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpAddonsWebsocketIntroduction Web sockets] support&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpAddonsScriptsScripts Support for a wide range of scripting languages]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki//HelpAddonsPlugnhackPlugnhack Plug-n-Hack support]&lt;br /&gt;
* Authentication and session support&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsApi Powerful REST based API]&lt;br /&gt;
* Automatic updating option&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/wiki Integrated and growing marketplace of add-ons]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
= Features =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
'''Some of ZAP's features:'''&lt;br /&gt;
&lt;br /&gt;
* [http://www.apache.org/licenses/LICENSE-2.0 Open source]&lt;br /&gt;
* Cross platform (it even runs on a [https://github.com/zaproxy/zaproxy/wiki/zappi Raspberry Pi!])&lt;br /&gt;
* Easy to install (using a [https://www.ej-technologies.com/products/install4j/overview.html multi-platform installer builder])&lt;br /&gt;
* Completely free (no paid for 'Pro' version)&lt;br /&gt;
* Ease of use a priority&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpIntro Comprehensive help pages]&lt;br /&gt;
* Fully internationalized&lt;br /&gt;
* Translated into over 20 languages&lt;br /&gt;
* Community based, with involvement actively encouraged&lt;br /&gt;
* Under active development by an international team of volunteers&lt;br /&gt;
&lt;br /&gt;
ZAP is a fork of the well regarded [http://www.parosproxy.org/ Paros Proxy].&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Languages =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''ZAP supports the following languages:'''&lt;br /&gt;
&lt;br /&gt;
* English&lt;br /&gt;
* Arabic&lt;br /&gt;
* Bosnian&lt;br /&gt;
* Brazilian Portuguese&lt;br /&gt;
* Chinese&lt;br /&gt;
* Danish&lt;br /&gt;
* Filipino&lt;br /&gt;
* French&lt;br /&gt;
* German&lt;br /&gt;
* Greek&lt;br /&gt;
* Hungarian&lt;br /&gt;
* Indonesian&lt;br /&gt;
* Italian&lt;br /&gt;
* Japanese&lt;br /&gt;
* Korean&lt;br /&gt;
* Persian&lt;br /&gt;
* Polish&lt;br /&gt;
* Russian&lt;br /&gt;
* Sinhala&lt;br /&gt;
* Spanish&lt;br /&gt;
* Urdu &lt;br /&gt;
&lt;br /&gt;
You can use [http://crowdin.net/project/owasp-zap Crowdin] to help improve these translations or add new ones right now!&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Release 2.6.0==&lt;br /&gt;
ZAP 2.6.0 has been released, this is a bug fix and enhancement release&lt;br /&gt;
&lt;br /&gt;
For more details see https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_6_0&lt;br /&gt;
&lt;br /&gt;
==Release 2.7.0==&lt;br /&gt;
ZAP 2.7.0 is planned for around the end of June 2017.&lt;br /&gt;
&lt;br /&gt;
==Release 2.8.0==&lt;br /&gt;
ZAP 2.8.0 is planned for around the end of September 2017.&lt;br /&gt;
&lt;br /&gt;
==Release 2.9.0==&lt;br /&gt;
ZAP 2.9.0 is planned for around the end of December 2017.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Get Involved =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Involvement in the development of ZAP is actively encouraged!&lt;br /&gt;
&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
&lt;br /&gt;
Some of the ways you can help:&lt;br /&gt;
&lt;br /&gt;
==Feature Requests==&lt;br /&gt;
&lt;br /&gt;
Please raise new feature requests as enhancement requests here: https://github.com/zaproxy/zaproxy/issues&lt;br /&gt;
&lt;br /&gt;
If there are existing requests you are also interested in then please 'star' them - that way we can see which features people are most interested in and can prioritize them accordingly. &lt;br /&gt;
&lt;br /&gt;
==Feedback==&lt;br /&gt;
&lt;br /&gt;
Please use the [http://groups.google.com/group/zaproxy-users zaproxy-users Google Group] for feedback:&lt;br /&gt;
* What do like?&lt;br /&gt;
* What don't you like?&lt;br /&gt;
* What features could be made easier to use?&lt;br /&gt;
* How could the help pages be improved? &lt;br /&gt;
&lt;br /&gt;
==Log issues==&lt;br /&gt;
&lt;br /&gt;
Have you had a problem using ZAP?&lt;br /&gt;
&lt;br /&gt;
If so and its not already been logged then please [https://github.com/zaproxy/zaproxy/issues report it]&lt;br /&gt;
&lt;br /&gt;
==Localization==&lt;br /&gt;
&lt;br /&gt;
Are you fluent in another language? Can you help translate ZAP into that language?&lt;br /&gt;
&lt;br /&gt;
You can use [http://crowdin.net/project/owasp-zap Crowdin] to do that!&lt;br /&gt;
&lt;br /&gt;
==Development==&lt;br /&gt;
&lt;br /&gt;
If you fancy having a go at adding functionality to ZAP then please get in touch via the [http://groups.google.com/group/zaproxy-develop zaproxy-develop Google Group].&lt;br /&gt;
&lt;br /&gt;
Again, you do not have to be a security expert to contribute code - working on ZAP could be great way to learn more about web application security!&lt;br /&gt;
&lt;br /&gt;
If you actively contribute to ZAP then you will be invited to join the project. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Zed Attack Proxy Project]]&lt;br /&gt;
[[Category:OWASP_Tool]]&lt;br /&gt;
[[Category:OWASP_Release_Quality_Tool|OWASP Release Quality Tool]]&lt;br /&gt;
[[Category:OWASP_Download]]&lt;br /&gt;
[[Category:Popular]]&lt;br /&gt;
[[Category:SAMM-ST-2]]&lt;/div&gt;</summary>
		<author><name>Psiinon</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Zed_Attack_Proxy_Project&amp;diff=228083</id>
		<title>OWASP Zed Attack Proxy Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Zed_Attack_Proxy_Project&amp;diff=228083"/>
				<updated>2017-03-29T11:26:02Z</updated>
		
		<summary type="html">&lt;p&gt;Psiinon: Added 2.6.0 line and updated Getting Started Guide link&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Main = &lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:90px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File: flagship_big.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
{{ReviewProject|projectname=zaproxy|language=en}}&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
The OWASP Zed Attack Proxy (ZAP) is one of the world’s most popular free security tools and is actively maintained by hundreds of international volunteers[[#Justification|*]]. It can help you automatically find security vulnerabilities in your web applications while you are developing and testing your applications. Its also a great tool for experienced pentesters to use for manual security testing.&lt;br /&gt;
&lt;br /&gt;
====ZAP 2.6.0 is now available and includes important security fixes. Please update asap!====&lt;br /&gt;
&lt;br /&gt;
[[Image:ZAP-Download.png | link=https://github.com/zaproxy/zaproxy/wiki/Downloads]]&lt;br /&gt;
&lt;br /&gt;
====Please help us to make ZAP even better for you by answering the [https://docs.google.com/forms/d/1-k-vcj_sSxlil6XLxCFade-m-IQVeE2h9gduA-2ZPPA/viewform ZAP User Questionnaire]!====&lt;br /&gt;
&lt;br /&gt;
For a quick overview of ZAP and an introduction to the [https://wiki.jenkins-ci.org/display/JENKINS/zap+plugin official ZAP Jenkins plugin] see these tutorial videos on YouTube:&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
{{#ev:youtube|eH0RBI0nmww}}&amp;amp;nbsp;&lt;br /&gt;
{{#ev:youtube|mmHZLSffCUg}}&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
For more videos see the links on the [https://github.com/zaproxy/zaproxy/wiki/Videos wiki videos page].&lt;br /&gt;
&lt;br /&gt;
Interested in a ZAP talk or training event? See the [https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project#tab=Talks talks] tab. Not one near you? Contact a [https://github.com/zaproxy/zaproxy/wiki/ZapEvangelists Zap Evangelist] to arrange one!&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Zed Attack Proxy&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
For general information about ZAP:&lt;br /&gt;
* [https://twitter.com/zaproxy Twitter] - official ZAP announcements (low volume)&lt;br /&gt;
* [https://zaproxy.blogspot.co.uk/ Blog] - official ZAP blog&lt;br /&gt;
&lt;br /&gt;
For help using ZAP:&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/releases/download/2.6.0/ZAPGettingStartedGuide-2.6.pdf Getting Started Guide (pdf)] - an introductory guide you can print&lt;br /&gt;
* [https://www.youtube.com/playlist?list=PLEBitBW-Hlsv8cEIUntAO8st2UGhmrjUB Tutorial Videos]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki User Guide] - online version of the User Guide included with ZAP&lt;br /&gt;
* [https://groups.google.com/group/zaproxy-users User Group] - ask questions about using ZAP&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/wiki Add-ons] - help for the optional add-ons you can install&lt;br /&gt;
* [https://stackoverflow.com/questions/tagged/zap StackOverflow] - because some people use this for all everything ;)&lt;br /&gt;
&lt;br /&gt;
To learn more about ZAP development:&lt;br /&gt;
* [https://github.com/zaproxy Source Code] - for all of the ZAP related projects&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/wiki/Introduction Wiki] - lots of detailed info&lt;br /&gt;
* [https://groups.google.com/group/zaproxy-develop Developer Group] - ask questions about the ZAP internals&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap Crowdin (GUI)] - help translate the ZAP GUI&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap-help Crowdin (User Guide)] - help translate the ZAP User Guide&lt;br /&gt;
* [https://www.openhub.net/p/zaproxy OpenHub]	- FOSS analytics&lt;br /&gt;
* [https://www.bountysource.com/teams/zap/issues BountySource] - Vote on ZAP issues (you can also donate money here, but 10% taken out)&lt;br /&gt;
&lt;br /&gt;
===Justification===&lt;br /&gt;
Justification for the statements made in the tagline at the top;)&lt;br /&gt;
&lt;br /&gt;
Popularity:&lt;br /&gt;
* ToolsWatch Annual Best Free/Open Source Security Tool Survey:&lt;br /&gt;
** 2016 [http://www.toolswatch.org/2017/02/2016-top-security-tools-as-voted-by-toolswatch-org-readers/ 2nd]&lt;br /&gt;
** 2015 [http://www.toolswatch.org/2016/02/2015-top-security-tools-as-voted-by-toolswatch-org-readers/ 1st]&lt;br /&gt;
** 2014 [http://www.toolswatch.org/2015/01/2014-top-security-tools-as-voted-by-toolswatch-org-readers/ 2nd]&lt;br /&gt;
** 2013 [http://www.toolswatch.org/2013/12/2013-top-security-tools-as-voted-by-toolswatch-org-readers/ 1st]&lt;br /&gt;
&lt;br /&gt;
Contributors:&lt;br /&gt;
* [https://www.openhub.net/p/zaproxy Code Contributors]&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap ZAP core i18n Contributors]&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap-help ZAP help i18n Contributors]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{{Social Media Links}}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
[https://github.com/zaproxy/zaproxy/wiki/Downloads Download OWASP ZAP!]&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
Please see the [https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project#News News] and [https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project#Talks Talks] tabs&lt;br /&gt;
&lt;br /&gt;
== Change Log ==&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/commits/develop zaproxy]&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/commits/master zap-extensions]&lt;br /&gt;
&lt;br /&gt;
== Code Repo ==&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/ zaproxy]&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/ zap-extensions]&lt;br /&gt;
&lt;br /&gt;
== Email List ==&lt;br /&gt;
&lt;br /&gt;
Questions? Please ask on the [http://groups.google.com/group/zaproxy-users ZAP User Group]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
Project Leader&amp;lt;br/&amp;gt;[https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_Web_Testing_Environment_Project OWASP WTE]&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_OWTF OWASP OWTF]&lt;br /&gt;
&lt;br /&gt;
== Ohloh ==&lt;br /&gt;
&lt;br /&gt;
*https://www.openhub.net/p/zaproxy&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; rowspan=&amp;quot;2&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Mature projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Flagship_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;center&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]&lt;br /&gt;
   |&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;center&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-breakers-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [http://www.apache.org/licenses/LICENSE-2.0 Apache 2 License]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Screenshots =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotAddAlert.png||400px||ZAP Add Alert Screen Shot]] &lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotHelp.png||400px|left|ZAP Help Screen Shot]]&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotHistoryFilter.png|thumb|400px|left|ZAP History Filter Screen Shot]]&lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotSearchTab.png|thumb|400px|left|ZAP Search Tab Screen Shot]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Talks =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
{{:Projects/OWASP Zed Attack Proxy Project/Pages/Talks | Talks}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
= News =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
{{:Projects/OWASP Zed Attack Proxy Project/Pages/News | News}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
= ZAP Gear =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Yes, you can now buy ZAP related gear!&lt;br /&gt;
&lt;br /&gt;
All of the artwork for ZAP swag is released under the Creative Common License and can be downloaded from the [https://github.com/zaproxy/zap-swag zap-swag] repo.&lt;br /&gt;
&lt;br /&gt;
You can of course use the artwork from this repo with any other online store that you like.&lt;br /&gt;
&lt;br /&gt;
A range of products can be purchased from [http://www.redbubble.com/people/zaproxy Redbubble]&lt;br /&gt;
&lt;br /&gt;
Stickers can be purchased from [https://www.stickermule.com/uk/user/1070684077/stickers Stickermule]&lt;br /&gt;
&lt;br /&gt;
T-shirts can be purchased from [http://www.cafepress.com/zaproxy Cafepress]&lt;br /&gt;
&lt;br /&gt;
[[Image:zap-tshirt-cp.PNG | link=http://www.cafepress.com/zaproxy]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Supporters =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
ZAP is developed by a worldwide [https://github.com/zaproxy/zap-core-help/wiki/HelpCredits team] of volunteers.&lt;br /&gt;
&lt;br /&gt;
But we have also been helped by many organizations, either financially or by encouraging their employees to work on ZAP:&lt;br /&gt;
&lt;br /&gt;
* [http://www.mozilla.org Mozilla]&lt;br /&gt;
* [http://www.linuxfoundation.org/ The Linux Foundation]&lt;br /&gt;
* [http://www.owasp.org OWASP]&lt;br /&gt;
* [http://www.sage.co.uk Sage]&lt;br /&gt;
* [http://www.google.com Google]&lt;br /&gt;
* [http://www.microsoft.com Microsoft]&lt;br /&gt;
* [http://www.hacktics.com/ Hacktics, Ernst &amp;amp; Young]&lt;br /&gt;
* [http://www.dinosec.com/ DinoSec]&lt;br /&gt;
* [http://www.denimgroup.com Denim Group]&lt;br /&gt;
* [http://www.aspectsecurity.com/ Aspect Security]&lt;br /&gt;
* [http://secureideas.net SecureIdeas]&lt;br /&gt;
* [http://utilisec.com UtiliSec]&lt;br /&gt;
* [http://www.encription.co.uk/ encription]&lt;br /&gt;
* [https://www.accenture.com/us-en/digital-index.aspx Accenture Digital]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Functionality =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
'''Some of ZAP's functionality:'''&lt;br /&gt;
&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsIntercept Intercepting Proxy]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsSpider Traditional] and AJAX spiders&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsAscan Automated scanner]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsPscan Passive scanner]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsBruteforce Forced browsing]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsFuzz Fuzzer]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpUiDialogsOptionsDynsslcert Dynamic SSL certificates]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/SmartCards Smartcard and Client Digital Certificates support]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpAddonsWebsocketIntroduction Web sockets] support&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpAddonsScriptsScripts Support for a wide range of scripting languages]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki//HelpAddonsPlugnhackPlugnhack Plug-n-Hack support]&lt;br /&gt;
* Authentication and session support&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsApi Powerful REST based API]&lt;br /&gt;
* Automatic updating option&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/wiki Integrated and growing marketplace of add-ons]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
= Features =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
'''Some of ZAP's features:'''&lt;br /&gt;
&lt;br /&gt;
* [http://www.apache.org/licenses/LICENSE-2.0 Open source]&lt;br /&gt;
* Cross platform (it even runs on a [https://github.com/zaproxy/zaproxy/wiki/zappi Raspberry Pi!])&lt;br /&gt;
* Easy to install (just requires java 1.7)&lt;br /&gt;
* Completely free (no paid for 'Pro' version)&lt;br /&gt;
* Ease of use a priority&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpIntro Comprehensive help pages]&lt;br /&gt;
* Fully internationalized&lt;br /&gt;
* Translated into over 20 languages&lt;br /&gt;
* Community based, with involvement actively encouraged&lt;br /&gt;
* Under active development by an international team of volunteers&lt;br /&gt;
&lt;br /&gt;
ZAP is a fork of the well regarded [http://www.parosproxy.org/ Paros Proxy].&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Languages =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''ZAP supports the following languages:'''&lt;br /&gt;
&lt;br /&gt;
* English&lt;br /&gt;
* Arabic&lt;br /&gt;
* Bosnian&lt;br /&gt;
* Brazilian Portuguese&lt;br /&gt;
* Chinese&lt;br /&gt;
* Danish&lt;br /&gt;
* Filipino&lt;br /&gt;
* French&lt;br /&gt;
* German&lt;br /&gt;
* Greek&lt;br /&gt;
* Hungarian&lt;br /&gt;
* Indonesian&lt;br /&gt;
* Italian&lt;br /&gt;
* Japanese&lt;br /&gt;
* Korean&lt;br /&gt;
* Persian&lt;br /&gt;
* Polish&lt;br /&gt;
* Russian&lt;br /&gt;
* Sinhala&lt;br /&gt;
* Spanish&lt;br /&gt;
* Urdu &lt;br /&gt;
&lt;br /&gt;
You can use [http://crowdin.net/project/owasp-zap Crowdin] to help improve these translations or add new ones right now!&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Release 2.6.0==&lt;br /&gt;
ZAP 2.6.0 has been released, this is a bug fix and enhancement release&lt;br /&gt;
&lt;br /&gt;
For more details see https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_6_0&lt;br /&gt;
&lt;br /&gt;
==Release 2.7.0==&lt;br /&gt;
ZAP 2.7.0 is planned for around the end of June 2017.&lt;br /&gt;
&lt;br /&gt;
==Release 2.8.0==&lt;br /&gt;
ZAP 2.8.0 is planned for around the end of September 2017.&lt;br /&gt;
&lt;br /&gt;
==Release 2.9.0==&lt;br /&gt;
ZAP 2.9.0 is planned for around the end of December 2017.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Get Involved =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Involvement in the development of ZAP is actively encouraged!&lt;br /&gt;
&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
&lt;br /&gt;
Some of the ways you can help:&lt;br /&gt;
&lt;br /&gt;
==Feature Requests==&lt;br /&gt;
&lt;br /&gt;
Please raise new feature requests as enhancement requests here: https://github.com/zaproxy/zaproxy/issues&lt;br /&gt;
&lt;br /&gt;
If there are existing requests you are also interested in then please 'star' them - that way we can see which features people are most interested in and can prioritize them accordingly. &lt;br /&gt;
&lt;br /&gt;
==Feedback==&lt;br /&gt;
&lt;br /&gt;
Please use the [http://groups.google.com/group/zaproxy-users zaproxy-users Google Group] for feedback:&lt;br /&gt;
* What do like?&lt;br /&gt;
* What don't you like?&lt;br /&gt;
* What features could be made easier to use?&lt;br /&gt;
* How could the help pages be improved? &lt;br /&gt;
&lt;br /&gt;
==Log issues==&lt;br /&gt;
&lt;br /&gt;
Have you had a problem using ZAP?&lt;br /&gt;
&lt;br /&gt;
If so and its not already been logged then please [https://github.com/zaproxy/zaproxy/issues report it]&lt;br /&gt;
&lt;br /&gt;
==Localization==&lt;br /&gt;
&lt;br /&gt;
Are you fluent in another language? Can you help translate ZAP into that language?&lt;br /&gt;
&lt;br /&gt;
You can use [http://crowdin.net/project/owasp-zap Crowdin] to do that!&lt;br /&gt;
&lt;br /&gt;
==Development==&lt;br /&gt;
&lt;br /&gt;
If you fancy having a go at adding functionality to ZAP then please get in touch via the [http://groups.google.com/group/zaproxy-develop zaproxy-develop Google Group].&lt;br /&gt;
&lt;br /&gt;
Again, you do not have to be a security expert to contribute code - working on ZAP could be great way to learn more about web application security!&lt;br /&gt;
&lt;br /&gt;
If you actively contribute to ZAP then you will be invited to join the project. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Zed Attack Proxy Project]]&lt;br /&gt;
[[Category:OWASP_Tool]]&lt;br /&gt;
[[Category:OWASP_Release_Quality_Tool|OWASP Release Quality Tool]]&lt;br /&gt;
[[Category:OWASP_Download]]&lt;br /&gt;
[[Category:Popular]]&lt;br /&gt;
[[Category:SAMM-ST-2]]&lt;/div&gt;</summary>
		<author><name>Psiinon</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Projects/OWASP_Zed_Attack_Proxy_Project/Pages/News&amp;diff=228072</id>
		<title>Projects/OWASP Zed Attack Proxy Project/Pages/News</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Projects/OWASP_Zed_Attack_Proxy_Project/Pages/News&amp;diff=228072"/>
				<updated>2017-03-29T09:50:46Z</updated>
		
		<summary type="html">&lt;p&gt;Psiinon: Updated for ZAP 2.6.0&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Latest News:'''&lt;br /&gt;
&lt;br /&gt;
* 2017/03/29 Version [https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_6_0 2.6.0] released&lt;br /&gt;
* 2016/06/03 Version [https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_5_0 2.5.0] released&lt;br /&gt;
* 2016/05/26 ZAP [https://bugcrowd.com/owaspzap bug bounty program] launched&lt;br /&gt;
* 2016/02/23 ZAP declared the [http://www.toolswatch.org/2016/02/2015-top-security-tools-as-voted-by-toolswatch-org-readers/ Top Security Tool of 2015 as voted by ToolsWatch.org readers]&lt;br /&gt;
* 2016/02/19 ZAP [http://zaproxy.blogspot.com/2016/02/zap-newsletter-2016-february.html February newsletter] published&lt;br /&gt;
* 2016/01/04 ZAP [http://zaproxy.blogspot.com/2016/01/zap-newsletter-2016-january.html January newsletter] published&lt;br /&gt;
* 2015/12/15 ZAP [http://zaproxy.blogspot.co.uk/2015/12/zap-newsletter-2015-december.html December newsletter] published&lt;br /&gt;
* 2015/12/04 Version [https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_4_3 2.4.3] released&lt;br /&gt;
* 2015/11/02 ZAP [http://zaproxy.blogspot.co.uk/2015/11/zap-newsletter-2015-november.html November newsletter] published&lt;br /&gt;
* 2015/09/07 Version [https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_4_2 2.4.2] released&lt;br /&gt;
* 2015/07/31 ZAP [https://www.owasp.org/index.php/2015-08-ZAP-ScriptingCompetition Scripting Competition] launched&lt;br /&gt;
* 2015/07/30 Version [https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_4_1 2.4.1] released&lt;br /&gt;
* 2015/05/05 ZAP featured in the [http://assets.thoughtworks.com/assets/technology-radar-may-2015-en.pdf ThoughtWorks Technology Radar]&lt;br /&gt;
* 2015/04/14 Version [http://owasp.blogspot.co.uk/2015/04/owasp-zap-240.html 2.4.0] released&lt;br /&gt;
* 2015/01/14 ZAP came second in the [http://www.toolswatch.org/2015/01/2014-top-security-tools-as-voted-by-toolswatch-org-readers/ Top Security Tools of 2014 as voted by ToolsWatch.org readers]&lt;br /&gt;
* 2015/01/02 ZAP [https://github.com/zaproxy/community-scripts Community Scripts] repo launched&lt;br /&gt;
* 2014/05/21 Version [https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_3_1 2.3.1] released&lt;br /&gt;
* 2014/04/10 Version [https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_3_0 2.3.0] released&lt;br /&gt;
* 2014/03/10 Hacking ZAP blog post series started: http://zaproxy.blogspot.co.uk/2014/03/hacking-zap-1-why-should-you.html&lt;br /&gt;
* 2014/02/17 ZAP included as one of the [https://sourceforge.net/blog/projects-of-the-week-february-17-2014/ SourceForge projects of the week]&lt;br /&gt;
* 2013/12/20 ZAP declared the [https://www.toolswatch.org/2013/12/2013-top-security-tools-as-voted-by-toolswatch-org-readers/ Top Security Tool of 2013 as voted by ToolsWatch.org readers]&lt;br /&gt;
* 2013/11/04 [https://github.com/zaproxy/zap-core-help/wiki/ZapEvangelists ZAP Evangelists] initiative launched&lt;br /&gt;
* 2013/10/29 Simon won Best Project Leader [https://www.owasp.org/index.php/WASPY_Awards_2013 WASPY Award]&lt;br /&gt;
* 2013/09/27 Version [https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_2_2 2.2.2] released&lt;br /&gt;
* 2013/09/11 Version [https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_2_0 2.2.0] released&lt;br /&gt;
* 2013/07/29 New language file including support for Bosnian&lt;br /&gt;
* 2013/06/17 ZAP user questionnaire launched, now in both [https://docs.google.com/forms/d/1lUPTYHe9CS5tropNStoRK9jVeZ7tWRywhBHDIZjE4cA/viewform English] and [https://docs.google.com/forms/d/1xAKE3TCOaBrmFnyAVUr6NdTd3mKvu7g_uGriOcS2Ka4/viewform Spanish]&lt;br /&gt;
* 2013/06/05 ZAP questions can now be asked on [https://irc.lc/mozilla/websectools/zapuser??? irc]&lt;br /&gt;
* 2013/05/10 5 ZAP related projects accepted for [https://github.com/zaproxy/zap-core-help/wiki/GSoC2013 Google Summer of Code]&lt;br /&gt;
* 2013/04/18 Version [https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_1_0 2.1.0] released&lt;br /&gt;
* 2013/01/30 Version [http://owasp.blogspot.co.uk/2013/01/owasp-zed-attack-proxy-v-200.html 2.0.0] released&lt;br /&gt;
* 2012/11/27 Started a new [http://code.google.com/p/zaproxy-test/ zaproxy-test] project of unit and integrations tests&lt;br /&gt;
* 2012/10/29 Adopted [http://crowdin.net/project/owasp-zap Crowdin] for translations&lt;br /&gt;
* 2012/10/22 Started generating [https://github.com/zaproxy/zap-core-help/wiki/WeeklyReleases weekly releases]&lt;br /&gt;
* 2012/10/12 ZAP Overview tutorial [http://www.youtube.com/watch?v=eH0RBI0nmww video] published&lt;br /&gt;
* 2012/09/18 [http://www.cafepress.com/zaproxy ZAP Gear Store] goes live&lt;br /&gt;
* 2012/08/05 Version [https://github.com/zaproxy/zap-core-help/wiki/HelpReleases1_4_1 1.4.1] released&lt;br /&gt;
* 2012/07/08 Version [https://github.com/zaproxy/zap-core-help/wiki/HelpReleases1_4_0 1.4.0.1] downloaded over 15,000 times&lt;br /&gt;
* 2012/07/05 [https://github.com/zaproxy/zap-core-help/wiki/ApiPython Python API] released&lt;br /&gt;
* 2012/06/15 ZAP accepted for the [[Projects_Reboot_2012|OWASP Project Reboot]]&lt;br /&gt;
* 2012/06/13 Using ZAP for Security Regression tests [http://www.youtube.com/watch?v=ZWSLFHpg1So video] published&lt;br /&gt;
* 2012/06/04 Version [https://github.com/zaproxy/zap-core-help/wiki/HelpReleases1_4_0 1.4.0.1] downloaded over 10,000 times&lt;br /&gt;
* 2012/05/28 Simon's Introduction to ZAP talk at App Sec USA becomes the most watched OWASP video on [http://vimeo.com/owasp/videos/sort:plays vimeo]&lt;br /&gt;
* 2012/04/23 3 ZAP related [https://github.com/zaproxy/zap-core-help/wiki/GSoC2012 Google Summer of Code 2012] projects accepted. To find out how these are progressing please see their [https://github.com/zaproxy/zap-core-help/wiki/GSoC2012 wiki pages].&lt;br /&gt;
* 2012/04/23 OWASP ZAP [https://github.com/zaproxy/zap-core-help/wiki/SmartCards SmartCard Project] officially launched.&lt;br /&gt;
* 2012/04/08 Version [https://github.com/zaproxy/zap-core-help/wiki/HelpReleases1_4_0 1.4.0.1] released&lt;br /&gt;
* 2012/02/10 Version [https://github.com/zaproxy/zap-core-help/wiki/HelpReleases1_3_4 1.3.4] downloaded over 10,000 times&lt;br /&gt;
* 2012/02/01 OWASP ZAP is named the [http://holisticinfosec.blogspot.com/2012/02/2011-toolsmith-tool-of-year-owasp-zap.html Toolsmith Tool of the Year for 2011!]&lt;/div&gt;</summary>
		<author><name>Psiinon</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Zed_Attack_Proxy_Project&amp;diff=228070</id>
		<title>OWASP Zed Attack Proxy Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Zed_Attack_Proxy_Project&amp;diff=228070"/>
				<updated>2017-03-29T09:47:52Z</updated>
		
		<summary type="html">&lt;p&gt;Psiinon: /* Roadmap */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Main = &lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:90px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File: flagship_big.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
{{ReviewProject|projectname=zaproxy|language=en}}&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
The OWASP Zed Attack Proxy (ZAP) is one of the world’s most popular free security tools and is actively maintained by hundreds of international volunteers[[#Justification|*]]. It can help you automatically find security vulnerabilities in your web applications while you are developing and testing your applications. Its also a great tool for experienced pentesters to use for manual security testing.&lt;br /&gt;
&lt;br /&gt;
[[Image:ZAP-Download.png | link=https://github.com/zaproxy/zaproxy/wiki/Downloads]]&lt;br /&gt;
&lt;br /&gt;
====Please help us to make ZAP even better for you by answering the [https://docs.google.com/forms/d/1-k-vcj_sSxlil6XLxCFade-m-IQVeE2h9gduA-2ZPPA/viewform ZAP User Questionnaire]!====&lt;br /&gt;
&lt;br /&gt;
For a quick overview of ZAP and an introduction to the [https://wiki.jenkins-ci.org/display/JENKINS/zap+plugin official ZAP Jenkins plugin] see these tutorial videos on YouTube:&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
{{#ev:youtube|eH0RBI0nmww}}&amp;amp;nbsp;&lt;br /&gt;
{{#ev:youtube|mmHZLSffCUg}}&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
For more videos see the links on the [https://github.com/zaproxy/zaproxy/wiki/Videos wiki videos page].&lt;br /&gt;
&lt;br /&gt;
Interested in a ZAP talk or training event? See the [https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project#tab=Talks talks] tab. Not one near you? Contact a [https://github.com/zaproxy/zaproxy/wiki/ZapEvangelists Zap Evangelist] to arrange one!&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Zed Attack Proxy&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
For general information about ZAP:&lt;br /&gt;
* [https://twitter.com/zaproxy Twitter] - official ZAP announcements (low volume)&lt;br /&gt;
* [https://zaproxy.blogspot.co.uk/ Blog] - official ZAP blog&lt;br /&gt;
&lt;br /&gt;
For help using ZAP:&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/releases/download/2.4.0/ZAPGettingStartedGuide-2.4.pdf Getting Started Guide (pdf)] - an introductory guide you can print&lt;br /&gt;
* [https://www.youtube.com/playlist?list=PLEBitBW-Hlsv8cEIUntAO8st2UGhmrjUB Tutorial Videos]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki User Guide] - online version of the User Guide included with ZAP&lt;br /&gt;
* [https://groups.google.com/group/zaproxy-users User Group] - ask questions about using ZAP&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/wiki Add-ons] - help for the optional add-ons you can install&lt;br /&gt;
* [https://stackoverflow.com/questions/tagged/zap StackOverflow] - because some people use this for all everything ;)&lt;br /&gt;
&lt;br /&gt;
To learn more about ZAP development:&lt;br /&gt;
* [https://github.com/zaproxy Source Code] - for all of the ZAP related projects&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/wiki/Introduction Wiki] - lots of detailed info&lt;br /&gt;
* [https://groups.google.com/group/zaproxy-develop Developer Group] - ask questions about the ZAP internals&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap Crowdin (GUI)] - help translate the ZAP GUI&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap-help Crowdin (User Guide)] - help translate the ZAP User Guide&lt;br /&gt;
* [https://www.openhub.net/p/zaproxy OpenHub]	- FOSS analytics&lt;br /&gt;
* [https://www.bountysource.com/teams/zap/issues BountySource] - Vote on ZAP issues (you can also donate money here, but 10% taken out)&lt;br /&gt;
&lt;br /&gt;
===Justification===&lt;br /&gt;
Justification for the statements made in the tagline at the top;)&lt;br /&gt;
&lt;br /&gt;
Popularity:&lt;br /&gt;
* ToolsWatch Annual Best Free/Open Source Security Tool Survey:&lt;br /&gt;
** 2016 [http://www.toolswatch.org/2017/02/2016-top-security-tools-as-voted-by-toolswatch-org-readers/ 2nd]&lt;br /&gt;
** 2015 [http://www.toolswatch.org/2016/02/2015-top-security-tools-as-voted-by-toolswatch-org-readers/ 1st]&lt;br /&gt;
** 2014 [http://www.toolswatch.org/2015/01/2014-top-security-tools-as-voted-by-toolswatch-org-readers/ 2nd]&lt;br /&gt;
** 2013 [http://www.toolswatch.org/2013/12/2013-top-security-tools-as-voted-by-toolswatch-org-readers/ 1st]&lt;br /&gt;
&lt;br /&gt;
Contributors:&lt;br /&gt;
* [https://www.openhub.net/p/zaproxy Code Contributors]&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap ZAP core i18n Contributors]&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap-help ZAP help i18n Contributors]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{{Social Media Links}}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
[https://github.com/zaproxy/zaproxy/wiki/Downloads Download OWASP ZAP!]&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
Please see the [https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project#News News] and [https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project#Talks Talks] tabs&lt;br /&gt;
&lt;br /&gt;
== Change Log ==&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/commits/develop zaproxy]&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/commits/master zap-extensions]&lt;br /&gt;
&lt;br /&gt;
== Code Repo ==&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/ zaproxy]&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/ zap-extensions]&lt;br /&gt;
&lt;br /&gt;
== Email List ==&lt;br /&gt;
&lt;br /&gt;
Questions? Please ask on the [http://groups.google.com/group/zaproxy-users ZAP User Group]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
Project Leader&amp;lt;br/&amp;gt;[https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_Web_Testing_Environment_Project OWASP WTE]&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_OWTF OWASP OWTF]&lt;br /&gt;
&lt;br /&gt;
== Ohloh ==&lt;br /&gt;
&lt;br /&gt;
*https://www.openhub.net/p/zaproxy&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; rowspan=&amp;quot;2&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Mature projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Flagship_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;center&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]&lt;br /&gt;
   |&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;center&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-breakers-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [http://www.apache.org/licenses/LICENSE-2.0 Apache 2 License]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Screenshots =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotAddAlert.png||400px||ZAP Add Alert Screen Shot]] &lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotHelp.png||400px|left|ZAP Help Screen Shot]]&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotHistoryFilter.png|thumb|400px|left|ZAP History Filter Screen Shot]]&lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotSearchTab.png|thumb|400px|left|ZAP Search Tab Screen Shot]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Talks =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
{{:Projects/OWASP Zed Attack Proxy Project/Pages/Talks | Talks}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
= News =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
{{:Projects/OWASP Zed Attack Proxy Project/Pages/News | News}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
= ZAP Gear =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Yes, you can now buy ZAP related gear!&lt;br /&gt;
&lt;br /&gt;
All of the artwork for ZAP swag is released under the Creative Common License and can be downloaded from the [https://github.com/zaproxy/zap-swag zap-swag] repo.&lt;br /&gt;
&lt;br /&gt;
You can of course use the artwork from this repo with any other online store that you like.&lt;br /&gt;
&lt;br /&gt;
A range of products can be purchased from [http://www.redbubble.com/people/zaproxy Redbubble]&lt;br /&gt;
&lt;br /&gt;
Stickers can be purchased from [https://www.stickermule.com/uk/user/1070684077/stickers Stickermule]&lt;br /&gt;
&lt;br /&gt;
T-shirts can be purchased from [http://www.cafepress.com/zaproxy Cafepress]&lt;br /&gt;
&lt;br /&gt;
[[Image:zap-tshirt-cp.PNG | link=http://www.cafepress.com/zaproxy]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Supporters =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
ZAP is developed by a worldwide [https://github.com/zaproxy/zap-core-help/wiki/HelpCredits team] of volunteers.&lt;br /&gt;
&lt;br /&gt;
But we have also been helped by many organizations, either financially or by encouraging their employees to work on ZAP:&lt;br /&gt;
&lt;br /&gt;
* [http://www.mozilla.org Mozilla]&lt;br /&gt;
* [http://www.linuxfoundation.org/ The Linux Foundation]&lt;br /&gt;
* [http://www.owasp.org OWASP]&lt;br /&gt;
* [http://www.sage.co.uk Sage]&lt;br /&gt;
* [http://www.google.com Google]&lt;br /&gt;
* [http://www.microsoft.com Microsoft]&lt;br /&gt;
* [http://www.hacktics.com/ Hacktics, Ernst &amp;amp; Young]&lt;br /&gt;
* [http://www.dinosec.com/ DinoSec]&lt;br /&gt;
* [http://www.denimgroup.com Denim Group]&lt;br /&gt;
* [http://www.aspectsecurity.com/ Aspect Security]&lt;br /&gt;
* [http://secureideas.net SecureIdeas]&lt;br /&gt;
* [http://utilisec.com UtiliSec]&lt;br /&gt;
* [http://www.encription.co.uk/ encription]&lt;br /&gt;
* [https://www.accenture.com/us-en/digital-index.aspx Accenture Digital]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Functionality =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
'''Some of ZAP's functionality:'''&lt;br /&gt;
&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsIntercept Intercepting Proxy]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsSpider Traditional] and AJAX spiders&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsAscan Automated scanner]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsPscan Passive scanner]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsBruteforce Forced browsing]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsFuzz Fuzzer]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpUiDialogsOptionsDynsslcert Dynamic SSL certificates]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/SmartCards Smartcard and Client Digital Certificates support]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpAddonsWebsocketIntroduction Web sockets] support&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpAddonsScriptsScripts Support for a wide range of scripting languages]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki//HelpAddonsPlugnhackPlugnhack Plug-n-Hack support]&lt;br /&gt;
* Authentication and session support&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsApi Powerful REST based API]&lt;br /&gt;
* Automatic updating option&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/wiki Integrated and growing marketplace of add-ons]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
= Features =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
'''Some of ZAP's features:'''&lt;br /&gt;
&lt;br /&gt;
* [http://www.apache.org/licenses/LICENSE-2.0 Open source]&lt;br /&gt;
* Cross platform (it even runs on a [https://github.com/zaproxy/zaproxy/wiki/zappi Raspberry Pi!])&lt;br /&gt;
* Easy to install (just requires java 1.7)&lt;br /&gt;
* Completely free (no paid for 'Pro' version)&lt;br /&gt;
* Ease of use a priority&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpIntro Comprehensive help pages]&lt;br /&gt;
* Fully internationalized&lt;br /&gt;
* Translated into over 20 languages&lt;br /&gt;
* Community based, with involvement actively encouraged&lt;br /&gt;
* Under active development by an international team of volunteers&lt;br /&gt;
&lt;br /&gt;
ZAP is a fork of the well regarded [http://www.parosproxy.org/ Paros Proxy].&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Languages =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''ZAP supports the following languages:'''&lt;br /&gt;
&lt;br /&gt;
* English&lt;br /&gt;
* Arabic&lt;br /&gt;
* Bosnian&lt;br /&gt;
* Brazilian Portuguese&lt;br /&gt;
* Chinese&lt;br /&gt;
* Danish&lt;br /&gt;
* Filipino&lt;br /&gt;
* French&lt;br /&gt;
* German&lt;br /&gt;
* Greek&lt;br /&gt;
* Hungarian&lt;br /&gt;
* Indonesian&lt;br /&gt;
* Italian&lt;br /&gt;
* Japanese&lt;br /&gt;
* Korean&lt;br /&gt;
* Persian&lt;br /&gt;
* Polish&lt;br /&gt;
* Russian&lt;br /&gt;
* Sinhala&lt;br /&gt;
* Spanish&lt;br /&gt;
* Urdu &lt;br /&gt;
&lt;br /&gt;
You can use [http://crowdin.net/project/owasp-zap Crowdin] to help improve these translations or add new ones right now!&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Release 2.6.0==&lt;br /&gt;
ZAP 2.6.0 has been released, this is a bug fix and enhancement release&lt;br /&gt;
&lt;br /&gt;
For more details see https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_6_0&lt;br /&gt;
&lt;br /&gt;
==Release 2.7.0==&lt;br /&gt;
ZAP 2.7.0 is planned for around the end of June 2017.&lt;br /&gt;
&lt;br /&gt;
==Release 2.8.0==&lt;br /&gt;
ZAP 2.8.0 is planned for around the end of September 2017.&lt;br /&gt;
&lt;br /&gt;
==Release 2.9.0==&lt;br /&gt;
ZAP 2.9.0 is planned for around the end of December 2017.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Get Involved =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Involvement in the development of ZAP is actively encouraged!&lt;br /&gt;
&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
&lt;br /&gt;
Some of the ways you can help:&lt;br /&gt;
&lt;br /&gt;
==Feature Requests==&lt;br /&gt;
&lt;br /&gt;
Please raise new feature requests as enhancement requests here: https://github.com/zaproxy/zaproxy/issues&lt;br /&gt;
&lt;br /&gt;
If there are existing requests you are also interested in then please 'star' them - that way we can see which features people are most interested in and can prioritize them accordingly. &lt;br /&gt;
&lt;br /&gt;
==Feedback==&lt;br /&gt;
&lt;br /&gt;
Please use the [http://groups.google.com/group/zaproxy-users zaproxy-users Google Group] for feedback:&lt;br /&gt;
* What do like?&lt;br /&gt;
* What don't you like?&lt;br /&gt;
* What features could be made easier to use?&lt;br /&gt;
* How could the help pages be improved? &lt;br /&gt;
&lt;br /&gt;
==Log issues==&lt;br /&gt;
&lt;br /&gt;
Have you had a problem using ZAP?&lt;br /&gt;
&lt;br /&gt;
If so and its not already been logged then please [https://github.com/zaproxy/zaproxy/issues report it]&lt;br /&gt;
&lt;br /&gt;
==Localization==&lt;br /&gt;
&lt;br /&gt;
Are you fluent in another language? Can you help translate ZAP into that language?&lt;br /&gt;
&lt;br /&gt;
You can use [http://crowdin.net/project/owasp-zap Crowdin] to do that!&lt;br /&gt;
&lt;br /&gt;
==Development==&lt;br /&gt;
&lt;br /&gt;
If you fancy having a go at adding functionality to ZAP then please get in touch via the [http://groups.google.com/group/zaproxy-develop zaproxy-develop Google Group].&lt;br /&gt;
&lt;br /&gt;
Again, you do not have to be a security expert to contribute code - working on ZAP could be great way to learn more about web application security!&lt;br /&gt;
&lt;br /&gt;
If you actively contribute to ZAP then you will be invited to join the project. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Zed Attack Proxy Project]]&lt;br /&gt;
[[Category:OWASP_Tool]]&lt;br /&gt;
[[Category:OWASP_Release_Quality_Tool|OWASP Release Quality Tool]]&lt;br /&gt;
[[Category:OWASP_Download]]&lt;br /&gt;
[[Category:Popular]]&lt;br /&gt;
[[Category:SAMM-ST-2]]&lt;/div&gt;</summary>
		<author><name>Psiinon</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=GSOC2017_Ideas&amp;diff=225474</id>
		<title>GSOC2017 Ideas</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=GSOC2017_Ideas&amp;diff=225474"/>
				<updated>2017-01-23T15:44:02Z</updated>
		
		<summary type="html">&lt;p&gt;Psiinon: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=OWASP Project Requests=&lt;br /&gt;
&lt;br /&gt;
'''Tips to get you started in no particular order:''' &lt;br /&gt;
 * Read the [[GSoC SAT]]&lt;br /&gt;
 * Check out the suggested projects below&lt;br /&gt;
 * Contact the mentors and teams of the projects that you are interested in&lt;br /&gt;
&lt;br /&gt;
== OWASP Juice Shop ==&lt;br /&gt;
&lt;br /&gt;
[[OWASP Juice Shop Project]] is an intentionally insecure webapp for security trainings written entirely in Javascript which encompasses the entire OWASP Top Ten and other severe security flaws. Juice Shop is written in Node.js, Express and AngularJS. The application contains more than 30 challenges of varying difficulty where the user is supposed to exploit the underlying vulnerabilities. Apart from the hacker and awareness training use case, pentesting proxies or security scanners can use Juice Shop as a &amp;quot;guinea pig&amp;quot;-application to check how well their tools cope with Javascript-heavy application frontends and REST APIs.&lt;br /&gt;
&lt;br /&gt;
=== Challenge Pack 2017 ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
Ideas for potential new hacking challenges are collected in [https://github.com/bkimminich/juice-shop/issues?q=is%3Aissue+is%3Aopen+label%3Achallenge GitHub issues labeled &amp;quot;challenge&amp;quot;]. This project could implement a whole bunch of challenges one by one and release them over the course of several small releases. This would allow the student to work in a professional Continuous Delivery kind of way while bringing benefit to the Juice Shop over the duration of the project.&lt;br /&gt;
&lt;br /&gt;
Coming up with additional ideas for challenges would be part of the project scope, as the list of pre-existing ideas might not be sufficient for a GSoC project.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* 10 or more new challenges for OWASP Juice Shop (including required functional enhancements to place the challenges in, e.g. the [https://github.com/bkimminich/juice-shop/issues/244 Order Dashboard] and [https://github.com/bkimminich/juice-shop/issues/243 Pomace Recycling user stories])&lt;br /&gt;
* Each challenge comes with full functional unit and integration tests&lt;br /&gt;
* Each challenge is verified to be exploitable by corresponding end-to-end tests&lt;br /&gt;
* Hint and solution sections for each new challenge are added to the &amp;quot;Pwning OWASP Juice Shop&amp;quot; ebook&lt;br /&gt;
* Code follows existing styleguides and passes all existing quality gates regarding code smells, test coverage etc.&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
* Get familiar with the architecture and code base of the application's rich Javascript frontend and RESTful backend&lt;br /&gt;
* Get a feeling for the high code &amp;amp; test quality bar by inspecting the existing test suites and static code analysis results&lt;br /&gt;
* Get familiar with the CI/CD process based on Travis-CI and several associated 3rd party services&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* Javascript, Unit/Integration testing, experience with (or willingness to learn) AngularJS (1.x) and NodeJS/Express, some security knowledge would be preferable.&lt;br /&gt;
&lt;br /&gt;
'''Mentors:'''&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Bjoern_Kimminich Bjoern Kimminich] - OWASP Juice Shop Project Leader&lt;br /&gt;
&lt;br /&gt;
=== Tech Stack Update ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
Development of OWASP Juice Shop started in 2014 and was based on - back then - quite recent Javascript frameworks and modules:&lt;br /&gt;
&lt;br /&gt;
* AngularJS 1.x with Bootstrap in the client&lt;br /&gt;
* Express on top of NodeJS on the server with&lt;br /&gt;
** SQLite as a database&lt;br /&gt;
** Sequelize as an OR-Mapper&lt;br /&gt;
*** sequelize-restful as an automatic API-generator on top of the DB entities&lt;br /&gt;
* Jasmine 1.x to specify behavioral tests&lt;br /&gt;
** Karma as a test runner for the client-side unit tests&lt;br /&gt;
** Frisby.js for API tests on a dynamically launched server&lt;br /&gt;
** Protractor for end-to-end testing of the challenge exploits&lt;br /&gt;
* NPM for running/testing the application&lt;br /&gt;
* Grunt for some of the custom build scripts&lt;br /&gt;
&lt;br /&gt;
Several of the above frameworks or modules have moved on to new (runtime incompatible) major releases, namely [https://github.com/bkimminich/juice-shop/issues/165 Angular 2], [https://github.com/bkimminich/juice-shop/issues/167 Sequelize], [https://github.com/bkimminich/juice-shop/issues/164 Frisby and Jasmine]. Other modules are out of maintenance entirely, e.g. [https://github.com/bkimminich/juice-shop/issues/167 sequelize-restful].&lt;br /&gt;
&lt;br /&gt;
Migrating the OWASP Juice Shop to the latest versions of the mentioned frameworks &amp;amp; modules is an important step to keep the application relevant as ''the most modern'' intentionally broken web application. Moving to entirely different frameworks might be taken into considerationas well.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* High-level target architecture overview including a migration plan with intermediary milestones&lt;br /&gt;
* Execution of migration without breaking functionality or losing tests along the way&lt;br /&gt;
* Code follows existing (or new) styleguides and passes all existing (or new) quality gates regarding code smells, test coverage etc.&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
* Get familiar with the architecture and code base of the application's rich Javascript frontend and RESTful backend&lt;br /&gt;
* Get a feeling for the high code &amp;amp; test quality bar by inspecting the existing test suites and static code analysis results&lt;br /&gt;
* Get familiar with the CI/CD process based on Travis-CI and several associated 3rd party services&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* Javascript, experience with latest Javascript frameworks for frontend, backend, testing and building (e.g. AngularJS 2.x, Jasmine 2.x, ...)&lt;br /&gt;
&lt;br /&gt;
'''Mentors:'''&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Bjoern_Kimminich Bjoern Kimminich] - OWASP Juice Shop Project Leader&lt;br /&gt;
&lt;br /&gt;
=== Your idea ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
You have an awesome idea to improve OWASP Juice Shop that is not on this list? Great, please submit it!&lt;br /&gt;
&lt;br /&gt;
''' Getting started '''&lt;br /&gt;
* Get in touch with [https://www.owasp.org/index.php/User:Bjoern_Kimminich Bjoern Kimminich]&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* A new feature that makes OWASP Juice Shop even better&lt;br /&gt;
* Code follows existing styleguides and passes all existing quality gates regarding code smells, test coverage etc.&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* Javascript, Unit/Integration testing, experience with (or willingness to learn) AngularJS (1.x) and NodeJS/Express, some security knowledge would be preferable.&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' &lt;br /&gt;
* [https://www.owasp.org/index.php/User:Bjoern_Kimminich Bjoern Kimminich] - OWASP Juice Shop Project Leader&lt;br /&gt;
&lt;br /&gt;
== OWASP Mobile Hacking Playground ==&lt;br /&gt;
&lt;br /&gt;
The OWASP Mobile Hacking Playground (https://github.com/OWASP/OMTG-Hacking-Playground) is part of the OWASP Mobile universe, which consists at the moment of the following projects: &lt;br /&gt;
&lt;br /&gt;
* Mobile Application Security Verification (MASVS). The MASVS is a list of security requirements for mobile applications that can be used by architects, developers, testers, security professionals, and consumers to define what a secure mobile application is. (https://github.com/OWASP/owasp-masvs)&lt;br /&gt;
* Mobile Security Testing Guide (MSTG). The OWASP MSTG is a comprehensive manual for testing the security of mobile apps. It describes technical processes for verifying the controls listed in the OWASP Mobile Application Verification Standard (MASVS). The MSTG is meant to provide a baseline set of test cases for dynamic and static security tests, and to help ensure completeness and consistency of the tests. (https://github.com/OWASP/owasp-mstg)&lt;br /&gt;
&lt;br /&gt;
In order to give also practical guidance to developers, security researches and penetration testers of mobile Apps, a hacking playground was created with the goal to create different mobile App’s that contain different vulnerabilities that map to the MSTG test cases. Every test case described in the MSTG will therefore be implemented in an Android and iOS App. This has two advantages:&lt;br /&gt;
&lt;br /&gt;
* A developer can identify vulnerable code in the provided App’s and can see the implications and risks if such patterns are used and can look for the best practices in the MSTG to mitigate the vulnerabilities.&lt;br /&gt;
* Penetration testers / security researchers can identify bad practices, dangerous methods and classes they should look for when assessing a Mobile App and can gain more knowledge through the information provided in the OMTG.&lt;br /&gt;
&lt;br /&gt;
It is also encouraged to use the App(s) for education purpose during trainings and workshops.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Creation of Android Code Samples ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
An Android App that maps to the MSTG test cases is already created. This App contains mostly test cases that are related to data storage on an Android device. In order to close the gap to the MSTG more test cases need to be added that show &amp;quot;bad practices&amp;quot; that lead to vulnerabilites, but also the latest security best practices to demonstrate how vulnerabilites can be mitigated. &lt;br /&gt;
&lt;br /&gt;
For examples of implemented test cases, see the Wiki of the Mobile Hacking Playground: https://github.com/OWASP/OMTG-Hacking-Playground/wiki/Android-App&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
&lt;br /&gt;
The following categories and their test cases are not fully added to the  Android App:&lt;br /&gt;
&lt;br /&gt;
* Cryptography (https://github.com/OWASP/owasp-masvs/blob/master/Document/0x08-V3-Cryptography_Verification_Requirements.md)&lt;br /&gt;
* Authentication and Session Management (https://github.com/OWASP/owasp-masvs/blob/master/Document/0x09-V4-Authentication_and_Session_Management%20Requirements.md)&lt;br /&gt;
* Network Communication (https://github.com/OWASP/owasp-masvs/blob/master/Document/0x10-V5-Network_communication_requirements.md)&lt;br /&gt;
* Environmental Interaction (https://github.com/OWASP/owasp-masvs/blob/master/Document/0x11-V6-Interaction_with_the_environment.md)&lt;br /&gt;
* Code Quality (https://github.com/OWASP/owasp-masvs/blob/master/Document/0x12-V7-Code_quality_and_build_setting_requirements.md)&lt;br /&gt;
&lt;br /&gt;
For some of the testcases this also includes creating an endpoint on server side in order to fully understand the test case and possible security concerns.&lt;br /&gt;
&lt;br /&gt;
As not all missing test cases can be implemented during the GSOC a subset of them will be defined with the student together. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
Here are a few suggestion on how to get started.&lt;br /&gt;
* Check the Mobile Hacking Playground Android App, browse through the code and Wiki to get an understanding of what a test case look likes. &lt;br /&gt;
* Browse through the MASVS and check the different areas and their defined requirements.&lt;br /&gt;
* Read about Security vulnerabilites and best practices for Android in areas you are interested in (e.g. Cryptography).&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
General interest in Mobile and Security. Basic knowledge of Android and Java.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' [mailto:sven.schleier@owasp.org Sven Schleier] - OWASP Mobile Security Testing Guide and Mobile Hacking Playground Project Leader&lt;br /&gt;
&lt;br /&gt;
== OWASP ZAP ==&lt;br /&gt;
&lt;br /&gt;
[[OWASP Zed Attack Proxy Project]] (ZAP) The OWASP Zed Attack Proxy (ZAP) is one of the world’s most popular free security tools and is actively maintained by hundreds of international volunteers. Previous GSoC students have implemented key parts of the ZAP core functionality and have been offered (and accepted) jobs based on their work on ZAP.&lt;br /&gt;
&lt;br /&gt;
We have just included a few of the ideas we have here, for a more complete list see the issues on the ZAP bug tracker with the [https://github.com/zaproxy/zaproxy/issues?q=is%3Aopen+is%3Aissue+label%3Aproject project] label.&lt;br /&gt;
&lt;br /&gt;
=== Field enumeration ===&lt;br /&gt;
&lt;br /&gt;
This would allow a user to iterate though a set of (user defined) characters in order to identify the ones that are filtered out and/or escaped.&lt;br /&gt;
&lt;br /&gt;
The user should be able to define the character sets to test and will probably need to configure the success and failure conditions, as well as valid values for other fields in the form.&lt;br /&gt;
&lt;br /&gt;
''' Expected Results '''&lt;br /&gt;
&lt;br /&gt;
* User able to specify a specific field to enumerate via the ZAP UI&lt;br /&gt;
* A list of all valid characters to be returned from the sets of characters the user specifies&lt;br /&gt;
* Ability to configure a wide range of success and failure conditions to cope with as many possible situations as possible&lt;br /&gt;
* Code that conforms to our [https://github.com/zaproxy/zaproxy/wiki/DevGuidelines Development Rules and Guidelines]&lt;br /&gt;
&lt;br /&gt;
''' Knowledge Prerequisite: '''&lt;br /&gt;
ZAP is written in Java, so a good knowledge of this language is recommended, as is knowledge of HTML. Some knowledge of application security would be useful, but not essential.&lt;br /&gt;
&lt;br /&gt;
''' Mentors '''&lt;br /&gt;
[https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @] and the rest of the ZAP Core Team&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Scripting Code Completion ===&lt;br /&gt;
&lt;br /&gt;
ZAP provides a very powerful scripting interface. Unfortunately to use it effectively is only really possible with a good knowledge of the ZAP internals. Adding code completion (eg using a project like https://github.com/bobbylight/AutoComplete) would significantly help users.&lt;br /&gt;
&lt;br /&gt;
''' Expected Results '''&lt;br /&gt;
&lt;br /&gt;
* Code completion for all of the parameters for all available functions in the standard scripts&lt;br /&gt;
* Implementations for JavaScript, JRuby and Jython&lt;br /&gt;
* Helper classes with code completion for commonly required functionality&lt;br /&gt;
* Code that conforms to our [https://github.com/zaproxy/zaproxy/wiki/DevGuidelines Development Rules and Guidelines]&lt;br /&gt;
&lt;br /&gt;
''' Knowledge Prerequisite: '''&lt;br /&gt;
ZAP is written in Java, so a good knowledge of this language is recommended. Some knowledge of application security would be useful, but not essential.&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' &lt;br /&gt;
[https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @] and the rest of the ZAP Core Team&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Your idea ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
ZAP is a great framework for building new and innovative security testing solutions. If you have an idea that is not on this list then don't worry, you can still submit it, we have accepted original projects in previous years and have even paid a student to work on their idea when we did not get enough GSoC slots to accept all of the projects we wanted.&lt;br /&gt;
&lt;br /&gt;
''' Getting started '''&lt;br /&gt;
* Get in touch with us :)&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* A new feature that makes ZAP even better&lt;br /&gt;
* Code that conforms to our [https://github.com/zaproxy/zaproxy/wiki/DevGuidelines Development Rules and Guidelines]&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
ZAP is written in Java, so a good knowledge of this language is recommended, as is knowledge of HTML. Some knowledge of application security would be useful, but not essential.&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' &lt;br /&gt;
[https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @] and the rest of the ZAP Core Team&lt;br /&gt;
&lt;br /&gt;
== BLT / Bugheist ==&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
Bugheist lets anyone report issues they find on the internet. Found something out of place on Amazon.com ?  Let them know.  Companies are held accountable and shows their response time and history.  Get points for reporting bugs and help keep the internet bug free.&lt;br /&gt;
&lt;br /&gt;
''' Getting started '''&lt;br /&gt;
* Get in touch with us :)&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* A new feature that makes Bugheist even better&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
BLT is written in Python / Django, so a good knowledge of this language and framework is recommended, as is knowledge of HTML. Some knowledge of application security would be useful, but not essential.&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' &lt;br /&gt;
[https://www.owasp.org/index.php/User:Sauriti Sean Auriti] [mailto:sean.auriti@owasp.org @] and the rest of the BLT Core Team&lt;/div&gt;</summary>
		<author><name>Psiinon</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=GSOC2017_Ideas&amp;diff=225413</id>
		<title>GSOC2017 Ideas</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=GSOC2017_Ideas&amp;diff=225413"/>
				<updated>2017-01-20T12:09:17Z</updated>
		
		<summary type="html">&lt;p&gt;Psiinon: /* OWASP Project Requests */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=OWASP Project Requests=&lt;br /&gt;
&lt;br /&gt;
'''Tips to get you started in no particular order:''' &lt;br /&gt;
 * Read the [[GSoC SAT]]&lt;br /&gt;
 * Check out the suggested projects below&lt;br /&gt;
 * Contact the mentors and teams of the projects that you are interested in&lt;br /&gt;
&lt;br /&gt;
== OWASP Juice Shop ==&lt;br /&gt;
&lt;br /&gt;
[[OWASP Juice Shop Project]] is an intentionally insecure webapp for security trainings written entirely in Javascript which encompasses the entire OWASP Top Ten and other severe security flaws. Juice Shop is written in Node.js, Express and AngularJS. The application contains more than 30 challenges of varying difficulty where the user is supposed to exploit the underlying vulnerabilities. Apart from the hacker and awareness training use case, pentesting proxies or security scanners can use Juice Shop as a &amp;quot;guinea pig&amp;quot;-application to check how well their tools cope with Javascript-heavy application frontends and REST APIs.&lt;br /&gt;
&lt;br /&gt;
=== Challenge Pack 2017 ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
Ideas for potential new hacking challenges are collected in [https://github.com/bkimminich/juice-shop/issues?q=is%3Aissue+is%3Aopen+label%3Achallenge GitHub issues labeled &amp;quot;challenge&amp;quot;]. This project could implement a whole bunch of challenges one by one and release them over the course of several small releases. This would allow the student to work in a professional Continuous Delivery kind of way while bringing benefit to the Juice Shop over the duration of the project.&lt;br /&gt;
&lt;br /&gt;
Coming up with additional ideas for challenges would be part of the project scope, as the list of pre-existing ideas might not be sufficient for a GSoC project.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* 10 or more new challenges for OWASP Juice Shop (including required functional enhancements to place the challenges in, e.g. the [https://github.com/bkimminich/juice-shop/issues/244 Order Dashboard] and [https://github.com/bkimminich/juice-shop/issues/243 Pomace Recycling user stories])&lt;br /&gt;
* Each challenge comes with full functional unit and integration tests&lt;br /&gt;
* Each challenge is verified to be exploitable by corresponding end-to-end tests&lt;br /&gt;
* Hint and solution sections for each new challenge are added to the &amp;quot;Pwning OWASP Juice Shop&amp;quot; ebook&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
* Get familiar with the architecture and code base of the application's rich Javascript frontend and RESTful backend&lt;br /&gt;
* Get a feeling for the high code &amp;amp; test quality bar by inspecting the existing test suites and static code analysis results&lt;br /&gt;
* Get familiar with the CI/CD process based on Travis-CI and several associated 3rd party services&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
Javascript, Test Driven Development, experience with (or willingness to learn) AngularJS (1.x) and NodeJS/Express, some security knowledge would be preferable.&lt;br /&gt;
&lt;br /&gt;
'''Mentors:'''&lt;br /&gt;
* [mailto:bjoern.kimminich@owasp.org Bjoern Kimminich] - OWASP Juice Shop Project Leader&lt;br /&gt;
&lt;br /&gt;
=== Tech Stack Update ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
t.b.d.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
t.b.d.&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
t.b.d.&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
t.b.d.&lt;br /&gt;
&lt;br /&gt;
'''Mentors:'''&lt;br /&gt;
t.b.d.&lt;br /&gt;
&lt;br /&gt;
== OWASP Mobile Hacking Playground ==&lt;br /&gt;
&lt;br /&gt;
The OWASP Mobile Hacking Playground (https://github.com/OWASP/OMTG-Hacking-Playground) is part of the OWASP Mobile universe, which consists at the moment of the following projects: &lt;br /&gt;
&lt;br /&gt;
* Mobile Application Security Verification (MASVS). The MASVS is a list of security requirements for mobile applications that can be used by architects, developers, testers, security professionals, and consumers to define what a secure mobile application is. (https://github.com/OWASP/owasp-masvs)&lt;br /&gt;
* Mobile Security Testing Guide (MSTG). The OWASP MSTG is a comprehensive manual for testing the security of mobile apps. It describes technical processes for verifying the controls listed in the OWASP Mobile Application Verification Standard (MASVS). The MSTG is meant to provide a baseline set of test cases for dynamic and static security tests, and to help ensure completeness and consistency of the tests. (https://github.com/OWASP/owasp-mstg)&lt;br /&gt;
&lt;br /&gt;
In order to give also practical guidance to developers, security researches and penetration testers of mobile Apps, a hacking playground was created with the goal to create different mobile App’s that contain different vulnerabilities that map to the MSTG test cases. Every test case described in the MSTG will therefore be implemented in an Android and iOS App. This has two advantages:&lt;br /&gt;
&lt;br /&gt;
* A developer can identify vulnerable code in the provided App’s and can see the implications and risks if such patterns are used and can look for the best practices in the MSTG to mitigate the vulnerabilities.&lt;br /&gt;
* Penetration testers / security researchers can identify bad practices, dangerous methods and classes they should look for when assessing a Mobile App and can gain more knowledge through the information provided in the OMTG.&lt;br /&gt;
&lt;br /&gt;
It is also encouraged to use the App(s) for education purpose during trainings and workshops.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Creation of Android Code Samples ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
An Android App that maps to the MSTG test cases is already created. This App contains mostly test cases that are related to data storage on an Android device. In order to close the gap to the MSTG more test cases need to be added that show &amp;quot;bad practices&amp;quot; that lead to vulnerabilites, but also the latest security best practices to demonstrate how vulnerabilites can be mitigated. &lt;br /&gt;
&lt;br /&gt;
For examples of implemented test cases, see the Wiki of the Mobile Hacking Playground: https://github.com/OWASP/OMTG-Hacking-Playground/wiki/Android-App&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
&lt;br /&gt;
The following categories and their test cases are not fully added to the  Android App:&lt;br /&gt;
&lt;br /&gt;
* Cryptography (https://github.com/OWASP/owasp-masvs/blob/master/Document/0x08-V3-Cryptography_Verification_Requirements.md)&lt;br /&gt;
* Authentication and Session Management (https://github.com/OWASP/owasp-masvs/blob/master/Document/0x09-V4-Authentication_and_Session_Management%20Requirements.md)&lt;br /&gt;
* Network Communication (https://github.com/OWASP/owasp-masvs/blob/master/Document/0x10-V5-Network_communication_requirements.md)&lt;br /&gt;
* Environmental Interaction (https://github.com/OWASP/owasp-masvs/blob/master/Document/0x11-V6-Interaction_with_the_environment.md)&lt;br /&gt;
* Code Quality (https://github.com/OWASP/owasp-masvs/blob/master/Document/0x12-V7-Code_quality_and_build_setting_requirements.md)&lt;br /&gt;
&lt;br /&gt;
For some of the testcases this also includes creating an endpoint on server side in order to fully understand the test case and possible security concerns.&lt;br /&gt;
&lt;br /&gt;
As not all missing test cases can be implemented during the GSOC a subset of them will be defined with the student together. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
Here are a few suggestion on how to get started.&lt;br /&gt;
* Check the Mobile Hacking Playground Android App, browse through the code and Wiki to get an understanding of what a test case look likes. &lt;br /&gt;
* Browse through the MASVS and check the different areas and their defined requirements.&lt;br /&gt;
* Read about Security vulnerabilites and best practices for Android in areas you are interested in (e.g. Cryptography).&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
General interest in Mobile and Security. Basic knowledge of Android and Java.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' [mailto:sven.schleier@owasp.org Sven Schleier] - OWASP Mobile Security Testing Guide and Mobile Hacking Playground Project Leader&lt;br /&gt;
&lt;br /&gt;
== OWASP ZAP ==&lt;br /&gt;
&lt;br /&gt;
[[OWASP Zed Attack Proxy Project]] (ZAP) The OWASP Zed Attack Proxy (ZAP) is one of the world’s most popular free security tools and is actively maintained by hundreds of international volunteers. Previous GSoC students have implemented key parts of the ZAP core functionality and have been offered (and accepted) jobs based on their work on ZAP.&lt;br /&gt;
&lt;br /&gt;
We have just included a few of the ideas we have here, for a more complete list see the issues on the ZAP bug tracker with the [https://github.com/zaproxy/zaproxy/issues?q=is%3Aopen+is%3Aissue+label%3Aproject project] label.&lt;br /&gt;
&lt;br /&gt;
=== Field enumeration ===&lt;br /&gt;
&lt;br /&gt;
This would allow a user to iterate though a set of (user defined) characters in order to identify the ones that are filtered out and/or escaped.&lt;br /&gt;
&lt;br /&gt;
The user should be able to define the character sets to test and will probably need to configure the success and failure conditions, as well as valid values for other fields in the form.&lt;br /&gt;
&lt;br /&gt;
''' Expected Results '''&lt;br /&gt;
&lt;br /&gt;
* User able to specify a specific field to enumerate via the ZAP UI&lt;br /&gt;
* A list of all valid characters to be returned from the sets of characters the user specifies&lt;br /&gt;
* Ability to configure a wide range of success and failure conditions to cope with as many possible situations as possible&lt;br /&gt;
* Code that conforms to our [https://github.com/zaproxy/zaproxy/wiki/DevGuidelines Development Rules and Guidelines]&lt;br /&gt;
&lt;br /&gt;
''' Knowledge Prerequisite: '''&lt;br /&gt;
ZAP is written in Java, so a good knowledge of this language is recommended, as is knowledge of HTML. Some knowledge of application security would be useful, but not essential.&lt;br /&gt;
&lt;br /&gt;
''' Mentors '''&lt;br /&gt;
[https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @] and the rest of the ZAP Core Team&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Scripting Code Completion ===&lt;br /&gt;
&lt;br /&gt;
ZAP provides a very powerful scripting interface. Unfortunately to use it effectively is only really possible with a good knowledge of the ZAP internals. Adding code completion (eg using a project like https://github.com/bobbylight/AutoComplete) would significantly help users.&lt;br /&gt;
&lt;br /&gt;
''' Expected Results '''&lt;br /&gt;
&lt;br /&gt;
* Code completion for all of the parameters for all available functions in the standard scripts&lt;br /&gt;
* Implementations for JavaScript, JRuby and Jython&lt;br /&gt;
* Helper classes with code completion for commonly required functionality&lt;br /&gt;
* Code that conforms to our [https://github.com/zaproxy/zaproxy/wiki/DevGuidelines Development Rules and Guidelines]&lt;br /&gt;
&lt;br /&gt;
''' Knowledge Prerequisite: '''&lt;br /&gt;
ZAP is written in Java, so a good knowledge of this language is recommended. Some knowledge of application security would be useful, but not essential.&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' &lt;br /&gt;
[https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @] and the rest of the ZAP Core Team&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Your idea ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
ZAP is a great framework for building new and innovative security testing solutions. If you have an idea that is not on this list then don't worry, you can still submit it, we have accepted original projects in previous years and have even paid a student to work on their idea when we did not get enough GSoC slots to accept all of the projects we wanted.&lt;br /&gt;
&lt;br /&gt;
''' Getting started '''&lt;br /&gt;
* Get in touch with us :)&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* A new feature that makes ZAP even better&lt;br /&gt;
* Code that conforms to our [https://github.com/zaproxy/zaproxy/wiki/DevGuidelines Development Rules and Guidelines]&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
ZAP is written in Java, so a good knowledge of this language is recommended, as is knowledge of HTML. Some knowledge of application security would be useful, but not essential.&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' &lt;br /&gt;
[https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @] and the rest of the ZAP Core Team&lt;/div&gt;</summary>
		<author><name>Psiinon</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=GSOC2017_Ideas&amp;diff=225409</id>
		<title>GSOC2017 Ideas</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=GSOC2017_Ideas&amp;diff=225409"/>
				<updated>2017-01-20T09:52:22Z</updated>
		
		<summary type="html">&lt;p&gt;Psiinon: /* OWASP ZAP */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=OWASP Project Requests=&lt;br /&gt;
&lt;br /&gt;
'''Tips to get you started in no particular order:''' &lt;br /&gt;
 * Read the [[GSoC SAT]]&lt;br /&gt;
 * Check the Hackademic wiki page linked above&lt;br /&gt;
 * Contact us through the mailing list or irc channel.&lt;br /&gt;
 * Check our [https://github.com/Hackademic/hackademic github repository] and especially the [https://github.com/Hackademic/hackademic/issues open tickets]&lt;br /&gt;
&lt;br /&gt;
== OWASP Juice Shop ==&lt;br /&gt;
&lt;br /&gt;
[[OWASP Juice Shop Project]] is an intentionally insecure webapp for security trainings written entirely in Javascript which encompasses the entire OWASP Top Ten and other severe security flaws. Juice Shop is written in Node.js, Express and AngularJS. The application contains more than 30 challenges of varying difficulty where the user is supposed to exploit the underlying vulnerabilities. Apart from the hacker and awareness training use case, pentesting proxies or security scanners can use Juice Shop as a &amp;quot;guinea pig&amp;quot;-application to check how well their tools cope with Javascript-heavy application frontends and REST APIs.&lt;br /&gt;
&lt;br /&gt;
=== Challenge Pack 2017 ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
Ideas for potential new hacking challenges are collected in [https://github.com/bkimminich/juice-shop/issues?q=is%3Aissue+is%3Aopen+label%3Achallenge GitHub issues labeled &amp;quot;challenge&amp;quot;]. This project could implement a whole bunch of challenges one by one and release them over the course of several small releases. This would allow the student to work in a professional Continuous Delivery kind of way while bringing benefit to the Juice Shop over the duration of the project.&lt;br /&gt;
&lt;br /&gt;
Coming up with additional ideas for challenges would be part of the project scope, as the list of pre-existing ideas might not be sufficient for a GSoC project.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* 10 or more new challenges for OWASP Juice Shop (including required functional enhancements to place the challenges in, e.g. the [https://github.com/bkimminich/juice-shop/issues/244 Order Dashboard] and [https://github.com/bkimminich/juice-shop/issues/243 Pomace Recycling user stories])&lt;br /&gt;
* Each challenge comes with full functional unit and integration tests&lt;br /&gt;
* Each challenge is verified to be exploitable by corresponding end-to-end tests&lt;br /&gt;
* Hint and solution sections for each new challenge are added to the &amp;quot;Pwning OWASP Juice Shop&amp;quot; ebook&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
* Get familiar with the architecture and code base of the application's rich Javascript frontend and RESTful backend&lt;br /&gt;
* Get a feeling for the high code &amp;amp; test quality bar by inspecting the existing test suites and static code analysis results&lt;br /&gt;
* Get familiar with the CI/CD process based on Travis-CI and several associated 3rd party services&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
Javascript, Test Driven Development, experience with (or willingness to learn) AngularJS (1.x) and NodeJS/Express, some security knowledge would be preferable.&lt;br /&gt;
&lt;br /&gt;
'''Mentors:'''&lt;br /&gt;
* [mailto:bjoern.kimminich@owasp.org Bjoern Kimminich] - OWASP Juice Shop Project Leader&lt;br /&gt;
&lt;br /&gt;
=== Tech Stack Update ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
t.b.d.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
t.b.d.&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
t.b.d.&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
t.b.d.&lt;br /&gt;
&lt;br /&gt;
'''Mentors:'''&lt;br /&gt;
t.b.d.&lt;br /&gt;
&lt;br /&gt;
== OWASP Mobile Hacking Playground ==&lt;br /&gt;
&lt;br /&gt;
The OWASP Mobile Hacking Playground (https://github.com/OWASP/OMTG-Hacking-Playground) is part of the OWASP Mobile universe, which consists at the moment of the following projects: &lt;br /&gt;
&lt;br /&gt;
* Mobile Application Security Verification (MASVS). The MASVS is a list of security requirements for mobile applications that can be used by architects, developers, testers, security professionals, and consumers to define what a secure mobile application is. (https://github.com/OWASP/owasp-masvs)&lt;br /&gt;
* Mobile Security Testing Guide (MSTG). The OWASP MSTG is a comprehensive manual for testing the security of mobile apps. It describes technical processes for verifying the controls listed in the OWASP Mobile Application Verification Standard (MASVS). The MSTG is meant to provide a baseline set of test cases for dynamic and static security tests, and to help ensure completeness and consistency of the tests. (https://github.com/OWASP/owasp-mstg)&lt;br /&gt;
&lt;br /&gt;
In order to give also practical guidance to developers, security researches and penetration testers of mobile Apps, a hacking playground was created with the goal to create different mobile App’s that contain different vulnerabilities that map to the MSTG test cases. Every test case described in the MSTG will therefore be implemented in an Android and iOS App. This has two advantages:&lt;br /&gt;
&lt;br /&gt;
* A developer can identify vulnerable code in the provided App’s and can see the implications and risks if such patterns are used and can look for the best practices in the MSTG to mitigate the vulnerabilities.&lt;br /&gt;
* Penetration testers / security researchers can identify bad practices, dangerous methods and classes they should look for when assessing a Mobile App and can gain more knowledge through the information provided in the OMTG.&lt;br /&gt;
&lt;br /&gt;
It is also encouraged to use the App(s) for education purpose during trainings and workshops.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Creation of Android Code Samples ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
An Android App that maps to the MSTG test cases is already created. This App contains mostly test cases that are related to data storage on an Android device. In order to close the gap to the MSTG more test cases need to be added that show &amp;quot;bad practices&amp;quot; that lead to vulnerabilites, but also the latest security best practices to demonstrate how vulnerabilites can be mitigated. &lt;br /&gt;
&lt;br /&gt;
For examples of implemented test cases, see the Wiki of the Mobile Hacking Playground: https://github.com/OWASP/OMTG-Hacking-Playground/wiki/Android-App&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
&lt;br /&gt;
The following categories and their test cases are not fully added to the  Android App:&lt;br /&gt;
&lt;br /&gt;
* Cryptography (https://github.com/OWASP/owasp-masvs/blob/master/Document/0x08-V3-Cryptography_Verification_Requirements.md)&lt;br /&gt;
* Authentication and Session Management (https://github.com/OWASP/owasp-masvs/blob/master/Document/0x09-V4-Authentication_and_Session_Management%20Requirements.md)&lt;br /&gt;
* Network Communication (https://github.com/OWASP/owasp-masvs/blob/master/Document/0x10-V5-Network_communication_requirements.md)&lt;br /&gt;
* Environmental Interaction (https://github.com/OWASP/owasp-masvs/blob/master/Document/0x11-V6-Interaction_with_the_environment.md)&lt;br /&gt;
* Code Quality (https://github.com/OWASP/owasp-masvs/blob/master/Document/0x12-V7-Code_quality_and_build_setting_requirements.md)&lt;br /&gt;
&lt;br /&gt;
For some of the testcases this also includes creating an endpoint on server side in order to fully understand the test case and possible security concerns.&lt;br /&gt;
&lt;br /&gt;
As not all missing test cases can be implemented during the GSOC a subset of them will be defined with the student together. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
Here are a few suggestion on how to get started.&lt;br /&gt;
* Check the Mobile Hacking Playground Android App, browse through the code and Wiki to get an understanding of what a test case look likes. &lt;br /&gt;
* Browse through the MASVS and check the different areas and their defined requirements.&lt;br /&gt;
* Read about Security vulnerabilites and best practices for Android in areas you are interested in (e.g. Cryptography).&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
General interest in Mobile and Security. Basic knowledge of Android and Java.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' [mailto:sven.schleier@owasp.org Sven Schleier] - OWASP Mobile Security Testing Guide and Mobile Hacking Playground Project Leader&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP Hackademic Challenges SAMPLE ENTRY==&lt;br /&gt;
&lt;br /&gt;
[[OWASP Hackademic Challenges Project]]  helps you test your knowledge on web application security. You can use it to actually attack web applications in a realistic but also controllable and safe environment. After a wonderfull 2014 GSoC with 100 new challenges and a couple of new plugins we're mainly looking to get new features in and maybe a couple of challenges. Bellow is a list of proposed features.&lt;br /&gt;
&lt;br /&gt;
=== REST API for the sandbox ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
During the last summer code sprint Hackademic got challenge sandboxing in the form of vagrant and docker wrappers as well as an engine to start and stop the container or vm instances.&lt;br /&gt;
What is needed now is a rest api which supports endpoint authentication and authorization which enables the sandbox engine to be completely independed from the rest of the project.&lt;br /&gt;
&lt;br /&gt;
Ideas on the project:&lt;br /&gt;
Since the sandbox is written in python, you will be using Django to implement the api.&lt;br /&gt;
The endpoint authorization can be done via certificates or plain signature or username/password type authentication. We would like to see what's your idea on the matter.&lt;br /&gt;
However the communication between the two has to be over a secure channel.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* A REST style api which allows an authenticated remote entity control the parts of the  sandbox engine it has access to.&lt;br /&gt;
* PEP8 compliant code&lt;br /&gt;
* Acceptable unit test coverage&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
Since this has been a popular project here's a suggestion on how to get started.&lt;br /&gt;
* Check the excellent work done by mebjas and a0xnirudh in their respective brances in the project's repository&lt;br /&gt;
* Take a brief look at the code and try to get a feeling of the functionality included. (Essentially it's CRUD operations on vms or containers)&lt;br /&gt;
* Read on what Docker and Vagrant are and take a look at their respective py-libraries&lt;br /&gt;
* If you think that contributing helps perhaps it would be a good idea to start with lettuce tests on the current CRUD operations of the existing functionality(which won't change and can eventually be ported to the final project) &lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
Python, test driven development, some idea what REST is, some security knowledge would be preferable.&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' [mailto:konstantinos.papapanaqiotou@owasp.org Konstantinos Papapanagiotou][mailto:spyros.gasteratos@owasp.org Spyros Gasteratos] - Hackademic Challenges Project Leaders&lt;br /&gt;
&lt;br /&gt;
=== New CMS ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
The CMS part of the project is really old and has accumulated a significant amount of technical debt.&lt;br /&gt;
In addition many design decisions are either outdated or could be improved. &lt;br /&gt;
Therefore it may be a good idea to leverage the power of modern web frameworks to create a new CMS.&lt;br /&gt;
The new cms can be written in python using Django.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* New cms with same functionality as the old one (3 types of users -- student, teacher, admin--, 3 types of resources -- article challenge, class--, ACL type permissions, CRUD operations on every resource/user, all functionality can be extended by Plugins.&lt;br /&gt;
* REST endpoints in addition to classic ones&lt;br /&gt;
* tests covering all routes implemented, also complete ACL unit tests, it would be embarassing if a cms by OWASP has rights vulnerabilities.&lt;br /&gt;
* PEP 8 code&lt;br /&gt;
&lt;br /&gt;
''' Note: '''&lt;br /&gt;
This is a huge project, it is ok if the student implements a part of it. However whatever implemented must be up to spec.&lt;br /&gt;
If you decide to take on this project contact us and we can agree on a list of routes.&lt;br /&gt;
If you don't decide to take on this project contact us.&lt;br /&gt;
Generally contact us, we like it when students have insightful questions and the community is active&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''' Getting Started: '''&lt;br /&gt;
* Install and take a brief look around the old cms so you have an idea of the functionality needed&lt;br /&gt;
* It's ok to scream in frustration&lt;br /&gt;
* If you want to contribute to get a feeling of the platform a good idea would be lettuce tests for the current functionality (which won't change and you can port in the new cms eventually)&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
Python, Django, what REST is, the technologies used, some security knowledge would be nice.&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' [mailto:konstantinos.papapanaqiotou@owasp.org Konstantinos Papapanagiotou][mailto:spyros.gasteratos@owasp.org Spyros Gasteratos] - Hackademic Challenges Project Leaders&lt;br /&gt;
&lt;br /&gt;
=== First Course Type Challenge ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
We have a wonderful sandbox engine which allows for complex guided challenges to be implemented.&lt;br /&gt;
We'd like to build a challenge that guides the user through a series of steps to an end goal and teaches more information on the subject matter on the way.&lt;br /&gt;
This is a very open-ended project on purpose to allow creative student to come up with nice ideas.&lt;br /&gt;
Bellow you will find some examples that we thought might be interesting.&lt;br /&gt;
&lt;br /&gt;
Ideas on the project:&lt;br /&gt;
* Purposefully vulnerable web page that guides the user via javascript tooltips and hints to exploiting it using ZAP. ( Bonus: using ZAP via the ZAP api). The challenge is solved when the the student submits the contents of a text file located on the disk (obtained by exploited an RCE)&lt;br /&gt;
&lt;br /&gt;
* Reversing a provided binary to extract information by providing step by step instructions to reversing using any popular reversing tool (well, you can't use IDA so gdb should have to do). Challenge is solved when the keys are extracted from the binary and submitted. Bonus points if each binary donwloaded has different keys.&lt;br /&gt;
&lt;br /&gt;
* Guide to exploiting the TOP10. (Using ZAP?)&lt;br /&gt;
&lt;br /&gt;
* Defensive Type challenges -- Here's how to create a patch for this kind of vulnerability -- Challenge is solved when the unit tests are run and the vulnerability isn't there.&lt;br /&gt;
&lt;br /&gt;
''' Getting started '''&lt;br /&gt;
* Check popular javascript guide tools such as: (http://introjs.com/ and http://github.hubspot.com/shepherd/docs/welcome/ )&lt;br /&gt;
* If you're more interested in system or non-web challenges check serverspec and definitely check quest (https://github.com/puppetlabs/quest)&lt;br /&gt;
* If you think contributing is a good idea to make yourself familiar with the project you can either port one of the existing simpler 1-page challenges to a docker container and submit a pull request or write a guide on how to create such a challenge&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
&lt;br /&gt;
* One or more Course - style challenges provided either as a docker container or as a vagrant box.&lt;br /&gt;
* Concrete documentation on how to build a challenge like this.&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
The technologies used.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' [mailto:konstantinos.papapanaqiotou@owasp.org Konstantinos Papapanagiotou][mailto:spyros.gasteratos@owasp.org Spyros Gasteratos] - Hackademic Challenges Project Leaders&lt;br /&gt;
&lt;br /&gt;
=== Advanced Sandboxed Challenges ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
In the spirit of the challenges above, we're looking for true ctf type challenges.&lt;br /&gt;
This is an open ended task. We're expecting awesome fresh ideas.&lt;br /&gt;
&lt;br /&gt;
Ideas on the project:&lt;br /&gt;
* An application vulnerable to one or more TOP 10 elements.&lt;br /&gt;
* A logic flaws based ctf&lt;br /&gt;
* Your idea here&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
* Check what Vagrant/Docker is&lt;br /&gt;
* Port one simple 1-page challenge (you can use one we already have ) to docker or vagrant&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
Docker containers or Vagrant boxes that contain complete new challenges.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
Knowledge of the technologies used&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' [mailto:konstantinos.papapanaqiotou@owasp.org Konstantinos Papapanagiotou][mailto:spyros.gasteratos@owasp.org Spyros Gasteratos] - Hackademic Challenges Project Leaders&lt;br /&gt;
&lt;br /&gt;
=== Your idea ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
Amazing students, in our experience, the best, most creative and unique ideas show up when we let students suggest their own feature in relation to the project.&lt;br /&gt;
The above should give you a general idea where we're going but don't let them constrain you.&lt;br /&gt;
Do you wanna do something that would fit into Hackademic? Send us an email!&lt;br /&gt;
&lt;br /&gt;
Ideas on the project:&lt;br /&gt;
No idea, that's your turn to shine!&lt;br /&gt;
&lt;br /&gt;
''' Getting started '''&lt;br /&gt;
* Be awesome&lt;br /&gt;
* Have an idea&lt;br /&gt;
* Be a student&lt;br /&gt;
* Explain definite proof of the p vs np solution(jk, an algorithm that breaks RSA in polynomial time would be totally acceptable)&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
If it's code, code according to our coding standards.&lt;br /&gt;
If it's challenges, something new and interesting.&lt;br /&gt;
If it's something else, then written like the person who's going to maintain your code is a raging psychopath with an axe who knows where you live.&lt;br /&gt;
&lt;br /&gt;
In short we'd like some quality. ;-)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' [mailto:konstantinos.papapanaqiotou@owasp.org Konstantinos Papapanagiotou][mailto:spyros.gasteratos@owasp.org Spyros Gasteratos] - Hackademic Challenges Project Leaders&lt;br /&gt;
&lt;br /&gt;
== OWASP ZAP ==&lt;br /&gt;
&lt;br /&gt;
[[OWASP Zed Attack Proxy Project]] (ZAP) The OWASP Zed Attack Proxy (ZAP) is one of the world’s most popular free security tools and is actively maintained by hundreds of international volunteers. Previous GSoC students have implemented key parts of the ZAP core functionality and have been offered (and accepted) jobs based on their work on ZAP.&lt;br /&gt;
&lt;br /&gt;
We have just included a few of the ideas we have here, for a more complete list see the issues on the ZAP bug tracker with the [https://github.com/zaproxy/zaproxy/issues?q=is%3Aopen+is%3Aissue+label%3Aproject project] label.&lt;br /&gt;
&lt;br /&gt;
=== Field enumeration ===&lt;br /&gt;
&lt;br /&gt;
This would allow a user to iterate though a set of (user defined) characters in order to identify the ones that are filtered out and/or escaped.&lt;br /&gt;
&lt;br /&gt;
The user should be able to define the character sets to test and will probably need to configure the success and failure conditions, as well as valid values for other fields in the form.&lt;br /&gt;
&lt;br /&gt;
''' Expected Results '''&lt;br /&gt;
&lt;br /&gt;
* User able to specify a specific field to enumerate via the ZAP UI&lt;br /&gt;
* A list of all valid characters to be returned from the sets of characters the user specifies&lt;br /&gt;
* Ability to configure a wide range of success and failure conditions to cope with as many possible situations as possible&lt;br /&gt;
* Code that conforms to our [https://github.com/zaproxy/zaproxy/wiki/DevGuidelines Development Rules and Guidelines]&lt;br /&gt;
&lt;br /&gt;
''' Knowledge Prerequisite: '''&lt;br /&gt;
ZAP is written in Java, so a good knowledge of this language is recommended, as is knowledge of HTML. Some knowledge of application security would be useful, but not essential.&lt;br /&gt;
&lt;br /&gt;
''' Mentors '''&lt;br /&gt;
[https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @] and the rest of the ZAP Core Team&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Scripting Code Completion ===&lt;br /&gt;
&lt;br /&gt;
ZAP provides a very powerful scripting interface. Unfortunately to use it effectively is only really possible with a good knowledge of the ZAP internals. Adding code completion (eg using a project like https://github.com/bobbylight/AutoComplete) would significantly help users.&lt;br /&gt;
&lt;br /&gt;
''' Expected Results '''&lt;br /&gt;
&lt;br /&gt;
* Code completion for all of the parameters for all available functions in the standard scripts&lt;br /&gt;
* Implementations for JavaScript, JRuby and Jython&lt;br /&gt;
* Helper classes with code completion for commonly required functionality&lt;br /&gt;
* Code that conforms to our [https://github.com/zaproxy/zaproxy/wiki/DevGuidelines Development Rules and Guidelines]&lt;br /&gt;
&lt;br /&gt;
''' Knowledge Prerequisite: '''&lt;br /&gt;
ZAP is written in Java, so a good knowledge of this language is recommended. Some knowledge of application security would be useful, but not essential.&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' &lt;br /&gt;
[https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @] and the rest of the ZAP Core Team&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Your idea ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
ZAP is a great framework for building new and innovative security testing solutions. If you have an idea that is not on this list then don't worry, you can still submit it, we have accepted original projects in previous years and have even paid a student to work on their idea when we did not get enough GSoC slots to accept all of the projects we wanted.&lt;br /&gt;
&lt;br /&gt;
''' Getting started '''&lt;br /&gt;
* Get in touch with us :)&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* A new feature that makes ZAP even better&lt;br /&gt;
* Code that conforms to our [https://github.com/zaproxy/zaproxy/wiki/DevGuidelines Development Rules and Guidelines]&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
ZAP is written in Java, so a good knowledge of this language is recommended, as is knowledge of HTML. Some knowledge of application security would be useful, but not essential.&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' &lt;br /&gt;
[https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @] and the rest of the ZAP Core Team&lt;/div&gt;</summary>
		<author><name>Psiinon</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=GSOC2017_Ideas&amp;diff=225408</id>
		<title>GSOC2017 Ideas</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=GSOC2017_Ideas&amp;diff=225408"/>
				<updated>2017-01-20T09:37:31Z</updated>
		
		<summary type="html">&lt;p&gt;Psiinon: /* Scripting Code Completion */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=OWASP Project Requests=&lt;br /&gt;
&lt;br /&gt;
'''Tips to get you started in no particular order:''' &lt;br /&gt;
 * Read the [[GSoC SAT]]&lt;br /&gt;
 * Check the Hackademic wiki page linked above&lt;br /&gt;
 * Contact us through the mailing list or irc channel.&lt;br /&gt;
 * Check our [https://github.com/Hackademic/hackademic github repository] and especially the [https://github.com/Hackademic/hackademic/issues open tickets]&lt;br /&gt;
&lt;br /&gt;
== OWASP Juice Shop ==&lt;br /&gt;
&lt;br /&gt;
[[OWASP Juice Shop Project]] is an intentionally insecure webapp for security trainings written entirely in Javascript which encompasses the entire OWASP Top Ten and other severe security flaws. Juice Shop is written in Node.js, Express and AngularJS. The application contains more than 30 challenges of varying difficulty where the user is supposed to exploit the underlying vulnerabilities. Apart from the hacker and awareness training use case, pentesting proxies or security scanners can use Juice Shop as a &amp;quot;guinea pig&amp;quot;-application to check how well their tools cope with Javascript-heavy application frontends and REST APIs.&lt;br /&gt;
&lt;br /&gt;
=== Challenge Pack 2017 ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
Ideas for potential new hacking challenges are collected in [https://github.com/bkimminich/juice-shop/issues?q=is%3Aissue+is%3Aopen+label%3Achallenge GitHub issues labeled &amp;quot;challenge&amp;quot;]. This project could implement a whole bunch of challenges one by one and release them over the course of several small releases. This would allow the student to work in a professional Continuous Delivery kind of way while bringing benefit to the Juice Shop over the duration of the project.&lt;br /&gt;
&lt;br /&gt;
Coming up with additional ideas for challenges would be part of the project scope, as the list of pre-existing ideas might not be sufficient for a GSoC project.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* 10 or more new challenges for OWASP Juice Shop (including required functional enhancements to place the challenges in, e.g. the [https://github.com/bkimminich/juice-shop/issues/244 Order Dashboard] and [https://github.com/bkimminich/juice-shop/issues/243 Pomace Recycling user stories])&lt;br /&gt;
* Each challenge comes with full functional unit and integration tests&lt;br /&gt;
* Each challenge is verified to be exploitable by corresponding end-to-end tests&lt;br /&gt;
* Hint and solution sections for each new challenge are added to the &amp;quot;Pwning OWASP Juice Shop&amp;quot; ebook&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
* Get familiar with the architecture and code base of the application's rich Javascript frontend and RESTful backend&lt;br /&gt;
* Get a feeling for the high code &amp;amp; test quality bar by inspecting the existing test suites and static code analysis results&lt;br /&gt;
* Get familiar with the CI/CD process based on Travis-CI and several associated 3rd party services&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
Javascript, Test Driven Development, experience with (or willingness to learn) AngularJS (1.x) and NodeJS/Express, some security knowledge would be preferable.&lt;br /&gt;
&lt;br /&gt;
'''Mentors:'''&lt;br /&gt;
* [mailto:bjoern.kimminich@owasp.org Bjoern Kimminich] - OWASP Juice Shop Project Leader&lt;br /&gt;
&lt;br /&gt;
=== Tech Stack Update ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
t.b.d.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
t.b.d.&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
t.b.d.&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
t.b.d.&lt;br /&gt;
&lt;br /&gt;
'''Mentors:'''&lt;br /&gt;
t.b.d.&lt;br /&gt;
&lt;br /&gt;
== OWASP Mobile Hacking Playground ==&lt;br /&gt;
&lt;br /&gt;
The OWASP Mobile Hacking Playground (https://github.com/OWASP/OMTG-Hacking-Playground) is part of the OWASP Mobile universe, which consists at the moment of the following projects: &lt;br /&gt;
&lt;br /&gt;
* Mobile Application Security Verification (MASVS). The MASVS is a list of security requirements for mobile applications that can be used by architects, developers, testers, security professionals, and consumers to define what a secure mobile application is. (https://github.com/OWASP/owasp-masvs)&lt;br /&gt;
* Mobile Security Testing Guide (MSTG). The OWASP MSTG is a comprehensive manual for testing the security of mobile apps. It describes technical processes for verifying the controls listed in the OWASP Mobile Application Verification Standard (MASVS). The MSTG is meant to provide a baseline set of test cases for dynamic and static security tests, and to help ensure completeness and consistency of the tests. (https://github.com/OWASP/owasp-mstg)&lt;br /&gt;
&lt;br /&gt;
In order to give also practical guidance to developers, security researches and penetration testers of mobile Apps, a hacking playground was created with the goal to create different mobile App’s that contain different vulnerabilities that map to the MSTG test cases. Every test case described in the MSTG will therefore be implemented in an Android and iOS App. This has two advantages:&lt;br /&gt;
&lt;br /&gt;
* A developer can identify vulnerable code in the provided App’s and can see the implications and risks if such patterns are used and can look for the best practices in the MSTG to mitigate the vulnerabilities.&lt;br /&gt;
* Penetration testers / security researchers can identify bad practices, dangerous methods and classes they should look for when assessing a Mobile App and can gain more knowledge through the information provided in the OMTG.&lt;br /&gt;
&lt;br /&gt;
It is also encouraged to use the App(s) for education purpose during trainings and workshops.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Creation of Android Code Samples ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
An Android App that maps to the MSTG test cases is already created. This App contains mostly test cases that are related to data storage on an Android device. In order to close the gap to the MSTG more test cases need to be added that show &amp;quot;bad practices&amp;quot; that lead to vulnerabilites, but also the latest security best practices to demonstrate how vulnerabilites can be mitigated. &lt;br /&gt;
&lt;br /&gt;
For examples of implemented test cases, see the Wiki of the Mobile Hacking Playground: https://github.com/OWASP/OMTG-Hacking-Playground/wiki/Android-App&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
&lt;br /&gt;
The following categories and their test cases are not fully added to the  Android App:&lt;br /&gt;
&lt;br /&gt;
* Cryptography (https://github.com/OWASP/owasp-masvs/blob/master/Document/0x08-V3-Cryptography_Verification_Requirements.md)&lt;br /&gt;
* Authentication and Session Management (https://github.com/OWASP/owasp-masvs/blob/master/Document/0x09-V4-Authentication_and_Session_Management%20Requirements.md)&lt;br /&gt;
* Network Communication (https://github.com/OWASP/owasp-masvs/blob/master/Document/0x10-V5-Network_communication_requirements.md)&lt;br /&gt;
* Environmental Interaction (https://github.com/OWASP/owasp-masvs/blob/master/Document/0x11-V6-Interaction_with_the_environment.md)&lt;br /&gt;
* Code Quality (https://github.com/OWASP/owasp-masvs/blob/master/Document/0x12-V7-Code_quality_and_build_setting_requirements.md)&lt;br /&gt;
&lt;br /&gt;
For some of the testcases this also includes creating an endpoint on server side in order to fully understand the test case and possible security concerns.&lt;br /&gt;
&lt;br /&gt;
As not all missing test cases can be implemented during the GSOC a subset of them will be defined with the student together. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
Here are a few suggestion on how to get started.&lt;br /&gt;
* Check the Mobile Hacking Playground Android App, browse through the code and Wiki to get an understanding of what a test case look likes. &lt;br /&gt;
* Browse through the MASVS and check the different areas and their defined requirements.&lt;br /&gt;
* Read about Security vulnerabilites and best practices for Android in areas you are interested in (e.g. Cryptography).&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
General interest in Mobile and Security. Basic knowledge of Android and Java.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' [mailto:sven.schleier@owasp.org Sven Schleier] - OWASP Mobile Security Testing Guide and Mobile Hacking Playground Project Leader&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP Hackademic Challenges SAMPLE ENTRY==&lt;br /&gt;
&lt;br /&gt;
[[OWASP Hackademic Challenges Project]]  helps you test your knowledge on web application security. You can use it to actually attack web applications in a realistic but also controllable and safe environment. After a wonderfull 2014 GSoC with 100 new challenges and a couple of new plugins we're mainly looking to get new features in and maybe a couple of challenges. Bellow is a list of proposed features.&lt;br /&gt;
&lt;br /&gt;
=== REST API for the sandbox ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
During the last summer code sprint Hackademic got challenge sandboxing in the form of vagrant and docker wrappers as well as an engine to start and stop the container or vm instances.&lt;br /&gt;
What is needed now is a rest api which supports endpoint authentication and authorization which enables the sandbox engine to be completely independed from the rest of the project.&lt;br /&gt;
&lt;br /&gt;
Ideas on the project:&lt;br /&gt;
Since the sandbox is written in python, you will be using Django to implement the api.&lt;br /&gt;
The endpoint authorization can be done via certificates or plain signature or username/password type authentication. We would like to see what's your idea on the matter.&lt;br /&gt;
However the communication between the two has to be over a secure channel.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* A REST style api which allows an authenticated remote entity control the parts of the  sandbox engine it has access to.&lt;br /&gt;
* PEP8 compliant code&lt;br /&gt;
* Acceptable unit test coverage&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
Since this has been a popular project here's a suggestion on how to get started.&lt;br /&gt;
* Check the excellent work done by mebjas and a0xnirudh in their respective brances in the project's repository&lt;br /&gt;
* Take a brief look at the code and try to get a feeling of the functionality included. (Essentially it's CRUD operations on vms or containers)&lt;br /&gt;
* Read on what Docker and Vagrant are and take a look at their respective py-libraries&lt;br /&gt;
* If you think that contributing helps perhaps it would be a good idea to start with lettuce tests on the current CRUD operations of the existing functionality(which won't change and can eventually be ported to the final project) &lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
Python, test driven development, some idea what REST is, some security knowledge would be preferable.&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' [mailto:konstantinos.papapanaqiotou@owasp.org Konstantinos Papapanagiotou][mailto:spyros.gasteratos@owasp.org Spyros Gasteratos] - Hackademic Challenges Project Leaders&lt;br /&gt;
&lt;br /&gt;
=== New CMS ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
The CMS part of the project is really old and has accumulated a significant amount of technical debt.&lt;br /&gt;
In addition many design decisions are either outdated or could be improved. &lt;br /&gt;
Therefore it may be a good idea to leverage the power of modern web frameworks to create a new CMS.&lt;br /&gt;
The new cms can be written in python using Django.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* New cms with same functionality as the old one (3 types of users -- student, teacher, admin--, 3 types of resources -- article challenge, class--, ACL type permissions, CRUD operations on every resource/user, all functionality can be extended by Plugins.&lt;br /&gt;
* REST endpoints in addition to classic ones&lt;br /&gt;
* tests covering all routes implemented, also complete ACL unit tests, it would be embarassing if a cms by OWASP has rights vulnerabilities.&lt;br /&gt;
* PEP 8 code&lt;br /&gt;
&lt;br /&gt;
''' Note: '''&lt;br /&gt;
This is a huge project, it is ok if the student implements a part of it. However whatever implemented must be up to spec.&lt;br /&gt;
If you decide to take on this project contact us and we can agree on a list of routes.&lt;br /&gt;
If you don't decide to take on this project contact us.&lt;br /&gt;
Generally contact us, we like it when students have insightful questions and the community is active&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''' Getting Started: '''&lt;br /&gt;
* Install and take a brief look around the old cms so you have an idea of the functionality needed&lt;br /&gt;
* It's ok to scream in frustration&lt;br /&gt;
* If you want to contribute to get a feeling of the platform a good idea would be lettuce tests for the current functionality (which won't change and you can port in the new cms eventually)&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
Python, Django, what REST is, the technologies used, some security knowledge would be nice.&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' [mailto:konstantinos.papapanaqiotou@owasp.org Konstantinos Papapanagiotou][mailto:spyros.gasteratos@owasp.org Spyros Gasteratos] - Hackademic Challenges Project Leaders&lt;br /&gt;
&lt;br /&gt;
=== First Course Type Challenge ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
We have a wonderful sandbox engine which allows for complex guided challenges to be implemented.&lt;br /&gt;
We'd like to build a challenge that guides the user through a series of steps to an end goal and teaches more information on the subject matter on the way.&lt;br /&gt;
This is a very open-ended project on purpose to allow creative student to come up with nice ideas.&lt;br /&gt;
Bellow you will find some examples that we thought might be interesting.&lt;br /&gt;
&lt;br /&gt;
Ideas on the project:&lt;br /&gt;
* Purposefully vulnerable web page that guides the user via javascript tooltips and hints to exploiting it using ZAP. ( Bonus: using ZAP via the ZAP api). The challenge is solved when the the student submits the contents of a text file located on the disk (obtained by exploited an RCE)&lt;br /&gt;
&lt;br /&gt;
* Reversing a provided binary to extract information by providing step by step instructions to reversing using any popular reversing tool (well, you can't use IDA so gdb should have to do). Challenge is solved when the keys are extracted from the binary and submitted. Bonus points if each binary donwloaded has different keys.&lt;br /&gt;
&lt;br /&gt;
* Guide to exploiting the TOP10. (Using ZAP?)&lt;br /&gt;
&lt;br /&gt;
* Defensive Type challenges -- Here's how to create a patch for this kind of vulnerability -- Challenge is solved when the unit tests are run and the vulnerability isn't there.&lt;br /&gt;
&lt;br /&gt;
''' Getting started '''&lt;br /&gt;
* Check popular javascript guide tools such as: (http://introjs.com/ and http://github.hubspot.com/shepherd/docs/welcome/ )&lt;br /&gt;
* If you're more interested in system or non-web challenges check serverspec and definitely check quest (https://github.com/puppetlabs/quest)&lt;br /&gt;
* If you think contributing is a good idea to make yourself familiar with the project you can either port one of the existing simpler 1-page challenges to a docker container and submit a pull request or write a guide on how to create such a challenge&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
&lt;br /&gt;
* One or more Course - style challenges provided either as a docker container or as a vagrant box.&lt;br /&gt;
* Concrete documentation on how to build a challenge like this.&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
The technologies used.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' [mailto:konstantinos.papapanaqiotou@owasp.org Konstantinos Papapanagiotou][mailto:spyros.gasteratos@owasp.org Spyros Gasteratos] - Hackademic Challenges Project Leaders&lt;br /&gt;
&lt;br /&gt;
=== Advanced Sandboxed Challenges ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
In the spirit of the challenges above, we're looking for true ctf type challenges.&lt;br /&gt;
This is an open ended task. We're expecting awesome fresh ideas.&lt;br /&gt;
&lt;br /&gt;
Ideas on the project:&lt;br /&gt;
* An application vulnerable to one or more TOP 10 elements.&lt;br /&gt;
* A logic flaws based ctf&lt;br /&gt;
* Your idea here&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
* Check what Vagrant/Docker is&lt;br /&gt;
* Port one simple 1-page challenge (you can use one we already have ) to docker or vagrant&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
Docker containers or Vagrant boxes that contain complete new challenges.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
Knowledge of the technologies used&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' [mailto:konstantinos.papapanaqiotou@owasp.org Konstantinos Papapanagiotou][mailto:spyros.gasteratos@owasp.org Spyros Gasteratos] - Hackademic Challenges Project Leaders&lt;br /&gt;
&lt;br /&gt;
=== Your idea ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
Amazing students, in our experience, the best, most creative and unique ideas show up when we let students suggest their own feature in relation to the project.&lt;br /&gt;
The above should give you a general idea where we're going but don't let them constrain you.&lt;br /&gt;
Do you wanna do something that would fit into Hackademic? Send us an email!&lt;br /&gt;
&lt;br /&gt;
Ideas on the project:&lt;br /&gt;
No idea, that's your turn to shine!&lt;br /&gt;
&lt;br /&gt;
''' Getting started '''&lt;br /&gt;
* Be awesome&lt;br /&gt;
* Have an idea&lt;br /&gt;
* Be a student&lt;br /&gt;
* Explain definite proof of the p vs np solution(jk, an algorithm that breaks RSA in polynomial time would be totally acceptable)&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
If it's code, code according to our coding standards.&lt;br /&gt;
If it's challenges, something new and interesting.&lt;br /&gt;
If it's something else, then written like the person who's going to maintain your code is a raging psychopath with an axe who knows where you live.&lt;br /&gt;
&lt;br /&gt;
In short we'd like some quality. ;-)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' [mailto:konstantinos.papapanaqiotou@owasp.org Konstantinos Papapanagiotou][mailto:spyros.gasteratos@owasp.org Spyros Gasteratos] - Hackademic Challenges Project Leaders&lt;br /&gt;
&lt;br /&gt;
== OWASP ZAP ==&lt;br /&gt;
&lt;br /&gt;
[[OWASP Zed Attack Proxy Project]] (ZAP) The OWASP Zed Attack Proxy (ZAP) is one of the world’s most popular free security tools and is actively maintained by hundreds of international volunteers. Previous GSoC students have implemented key parts of the ZAP core functionality and have been offered (and accepted) jobs based on their work on ZAP.&lt;br /&gt;
&lt;br /&gt;
We have just included a few of the ideas we have here, for a more complete list see the issues on the ZAP bug tracker with the [https://github.com/zaproxy/zaproxy/issues?q=is%3Aopen+is%3Aissue+label%3Aproject project] label.&lt;br /&gt;
&lt;br /&gt;
=== Field enumeration ===&lt;br /&gt;
&lt;br /&gt;
This would allow a user to iterate though a set of (user defined) characters in order to identify the ones that are filtered out and/or escaped.&lt;br /&gt;
&lt;br /&gt;
The user should be able to define the character sets to test and will probably need to configure the success and failure conditions, as well as valid values for other fields in the form.&lt;br /&gt;
&lt;br /&gt;
''' Expected Results '''&lt;br /&gt;
&lt;br /&gt;
* User able to specify a specific field to enumerate via the ZAP UI&lt;br /&gt;
* A list of all valid characters to be returned from the sets of characters the user specifies&lt;br /&gt;
* Ability to configure a wide range of success and failure conditions to cope with as many possible situations as possible&lt;br /&gt;
* Code that conforms to our [https://github.com/zaproxy/zaproxy/wiki/DevGuidelines Development Rules and Guidelines]&lt;br /&gt;
&lt;br /&gt;
''' Knowledge Prerequisite: '''&lt;br /&gt;
ZAP is written in Java, so a good knowledge of this language is recommended, as is knowledge of HTML. Some knowledge of application security would be useful, but not essential.&lt;br /&gt;
&lt;br /&gt;
''' Mentors '''&lt;br /&gt;
[mailto:psiinon@gmail.com Simon Bennetts] and other members of the ZAP core team&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Scripting Code Completion ===&lt;br /&gt;
&lt;br /&gt;
ZAP provides a very powerful scripting interface. Unfortunately to use it effectively is only really possible with a good knowledge of the ZAP internals. Adding code completion (eg using a project like https://github.com/bobbylight/AutoComplete) would significantly help users.&lt;br /&gt;
&lt;br /&gt;
''' Expected Results '''&lt;br /&gt;
&lt;br /&gt;
* Code completion for all of the parameters for all available functions in the standard scripts&lt;br /&gt;
* Implementations for JavaScript, JRuby and Jython&lt;br /&gt;
* Helper classes with code completion for commonly required functionality&lt;br /&gt;
* Code that conforms to our [https://github.com/zaproxy/zaproxy/wiki/DevGuidelines Development Rules and Guidelines]&lt;br /&gt;
&lt;br /&gt;
''' Knowledge Prerequisite: '''&lt;br /&gt;
ZAP is written in Java, so a good knowledge of this language is recommended. Some knowledge of application security would be useful, but not essential.&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' &lt;br /&gt;
[https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @] and the rest of the ZAP Core Team&lt;br /&gt;
&lt;br /&gt;
=== Your idea ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
ZAP is a great framework for building new and innovative security testing solutions. If you have an idea that is not on this list then don't worry, you can still submit it, we have accepted original projects in previous years and have even paid a student to work on their idea when we did not get enough GSoC slots to accept all of the projects we wanted.&lt;br /&gt;
&lt;br /&gt;
''' Getting started '''&lt;br /&gt;
* Get in touch with us :)&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* A new feature that makes ZAP even better&lt;br /&gt;
* Code that conforms to our [https://github.com/zaproxy/zaproxy/wiki/DevGuidelines Development Rules and Guidelines]&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* Experience with Java will definitely help&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' &lt;br /&gt;
[https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @] and the rest of the ZAP Core Team&lt;/div&gt;</summary>
		<author><name>Psiinon</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=GSOC2017_Ideas&amp;diff=225407</id>
		<title>GSOC2017 Ideas</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=GSOC2017_Ideas&amp;diff=225407"/>
				<updated>2017-01-20T09:33:33Z</updated>
		
		<summary type="html">&lt;p&gt;Psiinon: /* OWASP ZAP */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=OWASP Project Requests=&lt;br /&gt;
&lt;br /&gt;
'''Tips to get you started in no particular order:''' &lt;br /&gt;
 * Read the [[GSoC SAT]]&lt;br /&gt;
 * Check the Hackademic wiki page linked above&lt;br /&gt;
 * Contact us through the mailing list or irc channel.&lt;br /&gt;
 * Check our [https://github.com/Hackademic/hackademic github repository] and especially the [https://github.com/Hackademic/hackademic/issues open tickets]&lt;br /&gt;
&lt;br /&gt;
== OWASP Juice Shop ==&lt;br /&gt;
&lt;br /&gt;
[[OWASP Juice Shop Project]] is an intentionally insecure webapp for security trainings written entirely in Javascript which encompasses the entire OWASP Top Ten and other severe security flaws. Juice Shop is written in Node.js, Express and AngularJS. The application contains more than 30 challenges of varying difficulty where the user is supposed to exploit the underlying vulnerabilities. Apart from the hacker and awareness training use case, pentesting proxies or security scanners can use Juice Shop as a &amp;quot;guinea pig&amp;quot;-application to check how well their tools cope with Javascript-heavy application frontends and REST APIs.&lt;br /&gt;
&lt;br /&gt;
=== Challenge Pack 2017 ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
Ideas for potential new hacking challenges are collected in [https://github.com/bkimminich/juice-shop/issues?q=is%3Aissue+is%3Aopen+label%3Achallenge GitHub issues labeled &amp;quot;challenge&amp;quot;]. This project could implement a whole bunch of challenges one by one and release them over the course of several small releases. This would allow the student to work in a professional Continuous Delivery kind of way while bringing benefit to the Juice Shop over the duration of the project.&lt;br /&gt;
&lt;br /&gt;
Coming up with additional ideas for challenges would be part of the project scope, as the list of pre-existing ideas might not be sufficient for a GSoC project.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* 10 or more new challenges for OWASP Juice Shop (including required functional enhancements to place the challenges in, e.g. the [https://github.com/bkimminich/juice-shop/issues/244 Order Dashboard] and [https://github.com/bkimminich/juice-shop/issues/243 Pomace Recycling user stories])&lt;br /&gt;
* Each challenge comes with full functional unit and integration tests&lt;br /&gt;
* Each challenge is verified to be exploitable by corresponding end-to-end tests&lt;br /&gt;
* Hint and solution sections for each new challenge are added to the &amp;quot;Pwning OWASP Juice Shop&amp;quot; ebook&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
* Get familiar with the architecture and code base of the application's rich Javascript frontend and RESTful backend&lt;br /&gt;
* Get a feeling for the high code &amp;amp; test quality bar by inspecting the existing test suites and static code analysis results&lt;br /&gt;
* Get familiar with the CI/CD process based on Travis-CI and several associated 3rd party services&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
Javascript, Test Driven Development, experience with (or willingness to learn) AngularJS (1.x) and NodeJS/Express, some security knowledge would be preferable.&lt;br /&gt;
&lt;br /&gt;
'''Mentors:'''&lt;br /&gt;
* [mailto:bjoern.kimminich@owasp.org Bjoern Kimminich] - OWASP Juice Shop Project Leader&lt;br /&gt;
&lt;br /&gt;
=== Tech Stack Update ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
t.b.d.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
t.b.d.&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
t.b.d.&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
t.b.d.&lt;br /&gt;
&lt;br /&gt;
'''Mentors:'''&lt;br /&gt;
t.b.d.&lt;br /&gt;
&lt;br /&gt;
== OWASP Mobile Hacking Playground ==&lt;br /&gt;
&lt;br /&gt;
The OWASP Mobile Hacking Playground (https://github.com/OWASP/OMTG-Hacking-Playground) is part of the OWASP Mobile universe, which consists at the moment of the following projects: &lt;br /&gt;
&lt;br /&gt;
* Mobile Application Security Verification (MASVS). The MASVS is a list of security requirements for mobile applications that can be used by architects, developers, testers, security professionals, and consumers to define what a secure mobile application is. (https://github.com/OWASP/owasp-masvs)&lt;br /&gt;
* Mobile Security Testing Guide (MSTG). The OWASP MSTG is a comprehensive manual for testing the security of mobile apps. It describes technical processes for verifying the controls listed in the OWASP Mobile Application Verification Standard (MASVS). The MSTG is meant to provide a baseline set of test cases for dynamic and static security tests, and to help ensure completeness and consistency of the tests. (https://github.com/OWASP/owasp-mstg)&lt;br /&gt;
&lt;br /&gt;
In order to give also practical guidance to developers, security researches and penetration testers of mobile Apps, a hacking playground was created with the goal to create different mobile App’s that contain different vulnerabilities that map to the MSTG test cases. Every test case described in the MSTG will therefore be implemented in an Android and iOS App. This has two advantages:&lt;br /&gt;
&lt;br /&gt;
* A developer can identify vulnerable code in the provided App’s and can see the implications and risks if such patterns are used and can look for the best practices in the MSTG to mitigate the vulnerabilities.&lt;br /&gt;
* Penetration testers / security researchers can identify bad practices, dangerous methods and classes they should look for when assessing a Mobile App and can gain more knowledge through the information provided in the OMTG.&lt;br /&gt;
&lt;br /&gt;
It is also encouraged to use the App(s) for education purpose during trainings and workshops.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Creation of Android Code Samples ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
An Android App that maps to the MSTG test cases is already created. This App contains mostly test cases that are related to data storage on an Android device. In order to close the gap to the MSTG more test cases need to be added that show &amp;quot;bad practices&amp;quot; that lead to vulnerabilites, but also the latest security best practices to demonstrate how vulnerabilites can be mitigated. &lt;br /&gt;
&lt;br /&gt;
For examples of implemented test cases, see the Wiki of the Mobile Hacking Playground: https://github.com/OWASP/OMTG-Hacking-Playground/wiki/Android-App&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
&lt;br /&gt;
The following categories and their test cases are not fully added to the  Android App:&lt;br /&gt;
&lt;br /&gt;
* Cryptography (https://github.com/OWASP/owasp-masvs/blob/master/Document/0x08-V3-Cryptography_Verification_Requirements.md)&lt;br /&gt;
* Authentication and Session Management (https://github.com/OWASP/owasp-masvs/blob/master/Document/0x09-V4-Authentication_and_Session_Management%20Requirements.md)&lt;br /&gt;
* Network Communication (https://github.com/OWASP/owasp-masvs/blob/master/Document/0x10-V5-Network_communication_requirements.md)&lt;br /&gt;
* Environmental Interaction (https://github.com/OWASP/owasp-masvs/blob/master/Document/0x11-V6-Interaction_with_the_environment.md)&lt;br /&gt;
* Code Quality (https://github.com/OWASP/owasp-masvs/blob/master/Document/0x12-V7-Code_quality_and_build_setting_requirements.md)&lt;br /&gt;
&lt;br /&gt;
For some of the testcases this also includes creating an endpoint on server side in order to fully understand the test case and possible security concerns.&lt;br /&gt;
&lt;br /&gt;
As not all missing test cases can be implemented during the GSOC a subset of them will be defined with the student together. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
Here are a few suggestion on how to get started.&lt;br /&gt;
* Check the Mobile Hacking Playground Android App, browse through the code and Wiki to get an understanding of what a test case look likes. &lt;br /&gt;
* Browse through the MASVS and check the different areas and their defined requirements.&lt;br /&gt;
* Read about Security vulnerabilites and best practices for Android in areas you are interested in (e.g. Cryptography).&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
General interest in Mobile and Security. Basic knowledge of Android and Java.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' [mailto:sven.schleier@owasp.org Sven Schleier] - OWASP Mobile Security Testing Guide and Mobile Hacking Playground Project Leader&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP Hackademic Challenges SAMPLE ENTRY==&lt;br /&gt;
&lt;br /&gt;
[[OWASP Hackademic Challenges Project]]  helps you test your knowledge on web application security. You can use it to actually attack web applications in a realistic but also controllable and safe environment. After a wonderfull 2014 GSoC with 100 new challenges and a couple of new plugins we're mainly looking to get new features in and maybe a couple of challenges. Bellow is a list of proposed features.&lt;br /&gt;
&lt;br /&gt;
=== REST API for the sandbox ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
During the last summer code sprint Hackademic got challenge sandboxing in the form of vagrant and docker wrappers as well as an engine to start and stop the container or vm instances.&lt;br /&gt;
What is needed now is a rest api which supports endpoint authentication and authorization which enables the sandbox engine to be completely independed from the rest of the project.&lt;br /&gt;
&lt;br /&gt;
Ideas on the project:&lt;br /&gt;
Since the sandbox is written in python, you will be using Django to implement the api.&lt;br /&gt;
The endpoint authorization can be done via certificates or plain signature or username/password type authentication. We would like to see what's your idea on the matter.&lt;br /&gt;
However the communication between the two has to be over a secure channel.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* A REST style api which allows an authenticated remote entity control the parts of the  sandbox engine it has access to.&lt;br /&gt;
* PEP8 compliant code&lt;br /&gt;
* Acceptable unit test coverage&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
Since this has been a popular project here's a suggestion on how to get started.&lt;br /&gt;
* Check the excellent work done by mebjas and a0xnirudh in their respective brances in the project's repository&lt;br /&gt;
* Take a brief look at the code and try to get a feeling of the functionality included. (Essentially it's CRUD operations on vms or containers)&lt;br /&gt;
* Read on what Docker and Vagrant are and take a look at their respective py-libraries&lt;br /&gt;
* If you think that contributing helps perhaps it would be a good idea to start with lettuce tests on the current CRUD operations of the existing functionality(which won't change and can eventually be ported to the final project) &lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
Python, test driven development, some idea what REST is, some security knowledge would be preferable.&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' [mailto:konstantinos.papapanaqiotou@owasp.org Konstantinos Papapanagiotou][mailto:spyros.gasteratos@owasp.org Spyros Gasteratos] - Hackademic Challenges Project Leaders&lt;br /&gt;
&lt;br /&gt;
=== New CMS ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
The CMS part of the project is really old and has accumulated a significant amount of technical debt.&lt;br /&gt;
In addition many design decisions are either outdated or could be improved. &lt;br /&gt;
Therefore it may be a good idea to leverage the power of modern web frameworks to create a new CMS.&lt;br /&gt;
The new cms can be written in python using Django.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* New cms with same functionality as the old one (3 types of users -- student, teacher, admin--, 3 types of resources -- article challenge, class--, ACL type permissions, CRUD operations on every resource/user, all functionality can be extended by Plugins.&lt;br /&gt;
* REST endpoints in addition to classic ones&lt;br /&gt;
* tests covering all routes implemented, also complete ACL unit tests, it would be embarassing if a cms by OWASP has rights vulnerabilities.&lt;br /&gt;
* PEP 8 code&lt;br /&gt;
&lt;br /&gt;
''' Note: '''&lt;br /&gt;
This is a huge project, it is ok if the student implements a part of it. However whatever implemented must be up to spec.&lt;br /&gt;
If you decide to take on this project contact us and we can agree on a list of routes.&lt;br /&gt;
If you don't decide to take on this project contact us.&lt;br /&gt;
Generally contact us, we like it when students have insightful questions and the community is active&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''' Getting Started: '''&lt;br /&gt;
* Install and take a brief look around the old cms so you have an idea of the functionality needed&lt;br /&gt;
* It's ok to scream in frustration&lt;br /&gt;
* If you want to contribute to get a feeling of the platform a good idea would be lettuce tests for the current functionality (which won't change and you can port in the new cms eventually)&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
Python, Django, what REST is, the technologies used, some security knowledge would be nice.&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' [mailto:konstantinos.papapanaqiotou@owasp.org Konstantinos Papapanagiotou][mailto:spyros.gasteratos@owasp.org Spyros Gasteratos] - Hackademic Challenges Project Leaders&lt;br /&gt;
&lt;br /&gt;
=== First Course Type Challenge ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
We have a wonderful sandbox engine which allows for complex guided challenges to be implemented.&lt;br /&gt;
We'd like to build a challenge that guides the user through a series of steps to an end goal and teaches more information on the subject matter on the way.&lt;br /&gt;
This is a very open-ended project on purpose to allow creative student to come up with nice ideas.&lt;br /&gt;
Bellow you will find some examples that we thought might be interesting.&lt;br /&gt;
&lt;br /&gt;
Ideas on the project:&lt;br /&gt;
* Purposefully vulnerable web page that guides the user via javascript tooltips and hints to exploiting it using ZAP. ( Bonus: using ZAP via the ZAP api). The challenge is solved when the the student submits the contents of a text file located on the disk (obtained by exploited an RCE)&lt;br /&gt;
&lt;br /&gt;
* Reversing a provided binary to extract information by providing step by step instructions to reversing using any popular reversing tool (well, you can't use IDA so gdb should have to do). Challenge is solved when the keys are extracted from the binary and submitted. Bonus points if each binary donwloaded has different keys.&lt;br /&gt;
&lt;br /&gt;
* Guide to exploiting the TOP10. (Using ZAP?)&lt;br /&gt;
&lt;br /&gt;
* Defensive Type challenges -- Here's how to create a patch for this kind of vulnerability -- Challenge is solved when the unit tests are run and the vulnerability isn't there.&lt;br /&gt;
&lt;br /&gt;
''' Getting started '''&lt;br /&gt;
* Check popular javascript guide tools such as: (http://introjs.com/ and http://github.hubspot.com/shepherd/docs/welcome/ )&lt;br /&gt;
* If you're more interested in system or non-web challenges check serverspec and definitely check quest (https://github.com/puppetlabs/quest)&lt;br /&gt;
* If you think contributing is a good idea to make yourself familiar with the project you can either port one of the existing simpler 1-page challenges to a docker container and submit a pull request or write a guide on how to create such a challenge&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
&lt;br /&gt;
* One or more Course - style challenges provided either as a docker container or as a vagrant box.&lt;br /&gt;
* Concrete documentation on how to build a challenge like this.&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
The technologies used.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' [mailto:konstantinos.papapanaqiotou@owasp.org Konstantinos Papapanagiotou][mailto:spyros.gasteratos@owasp.org Spyros Gasteratos] - Hackademic Challenges Project Leaders&lt;br /&gt;
&lt;br /&gt;
=== Advanced Sandboxed Challenges ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
In the spirit of the challenges above, we're looking for true ctf type challenges.&lt;br /&gt;
This is an open ended task. We're expecting awesome fresh ideas.&lt;br /&gt;
&lt;br /&gt;
Ideas on the project:&lt;br /&gt;
* An application vulnerable to one or more TOP 10 elements.&lt;br /&gt;
* A logic flaws based ctf&lt;br /&gt;
* Your idea here&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
* Check what Vagrant/Docker is&lt;br /&gt;
* Port one simple 1-page challenge (you can use one we already have ) to docker or vagrant&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
Docker containers or Vagrant boxes that contain complete new challenges.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
Knowledge of the technologies used&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' [mailto:konstantinos.papapanaqiotou@owasp.org Konstantinos Papapanagiotou][mailto:spyros.gasteratos@owasp.org Spyros Gasteratos] - Hackademic Challenges Project Leaders&lt;br /&gt;
&lt;br /&gt;
=== Your idea ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
Amazing students, in our experience, the best, most creative and unique ideas show up when we let students suggest their own feature in relation to the project.&lt;br /&gt;
The above should give you a general idea where we're going but don't let them constrain you.&lt;br /&gt;
Do you wanna do something that would fit into Hackademic? Send us an email!&lt;br /&gt;
&lt;br /&gt;
Ideas on the project:&lt;br /&gt;
No idea, that's your turn to shine!&lt;br /&gt;
&lt;br /&gt;
''' Getting started '''&lt;br /&gt;
* Be awesome&lt;br /&gt;
* Have an idea&lt;br /&gt;
* Be a student&lt;br /&gt;
* Explain definite proof of the p vs np solution(jk, an algorithm that breaks RSA in polynomial time would be totally acceptable)&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
If it's code, code according to our coding standards.&lt;br /&gt;
If it's challenges, something new and interesting.&lt;br /&gt;
If it's something else, then written like the person who's going to maintain your code is a raging psychopath with an axe who knows where you live.&lt;br /&gt;
&lt;br /&gt;
In short we'd like some quality. ;-)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' [mailto:konstantinos.papapanaqiotou@owasp.org Konstantinos Papapanagiotou][mailto:spyros.gasteratos@owasp.org Spyros Gasteratos] - Hackademic Challenges Project Leaders&lt;br /&gt;
&lt;br /&gt;
== OWASP ZAP ==&lt;br /&gt;
&lt;br /&gt;
[[OWASP Zed Attack Proxy Project]] (ZAP) The OWASP Zed Attack Proxy (ZAP) is one of the world’s most popular free security tools and is actively maintained by hundreds of international volunteers. Previous GSoC students have implemented key parts of the ZAP core functionality and have been offered (and accepted) jobs based on their work on ZAP.&lt;br /&gt;
&lt;br /&gt;
We have just included a few of the ideas we have here, for a more complete list see the issues on the ZAP bug tracker with the [https://github.com/zaproxy/zaproxy/issues?q=is%3Aopen+is%3Aissue+label%3Aproject project] label.&lt;br /&gt;
&lt;br /&gt;
=== Field enumeration ===&lt;br /&gt;
&lt;br /&gt;
This would allow a user to iterate though a set of (user defined) characters in order to identify the ones that are filtered out and/or escaped.&lt;br /&gt;
&lt;br /&gt;
The user should be able to define the character sets to test and will probably need to configure the success and failure conditions, as well as valid values for other fields in the form.&lt;br /&gt;
&lt;br /&gt;
''' Expected Results '''&lt;br /&gt;
&lt;br /&gt;
* User able to specify a specific field to enumerate via the ZAP UI&lt;br /&gt;
* A list of all valid characters to be returned from the sets of characters the user specifies&lt;br /&gt;
* Ability to configure a wide range of success and failure conditions to cope with as many possible situations as possible&lt;br /&gt;
* Code that conforms to our [https://github.com/zaproxy/zaproxy/wiki/DevGuidelines Development Rules and Guidelines]&lt;br /&gt;
&lt;br /&gt;
''' Knowledge Prerequisite: '''&lt;br /&gt;
ZAP is written in Java, so a good knowledge of this language is recommended, as is knowledge of HTML. Some knowledge of application security would be useful, but not essential.&lt;br /&gt;
&lt;br /&gt;
''' Mentors '''&lt;br /&gt;
[mailto:psiinon@gmail.com Simon Bennetts] and other members of the ZAP core team&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Scripting Code Completion ===&lt;br /&gt;
&lt;br /&gt;
ZAP provides a very powerful scripting interface. Unfortunately to use it effectively is only really possible with a good knowledge of the ZAP internals. Adding code completion (eg using a project like https://github.com/bobbylight/AutoComplete) would significantly help users.&lt;br /&gt;
&lt;br /&gt;
==== Expected Results ====&lt;br /&gt;
&lt;br /&gt;
* Code completion for all of the parameters for all available functions in the standard scripts&lt;br /&gt;
* Implementations for JavaScript, JRuby and Jython&lt;br /&gt;
* Helper classes with code completion for commonly required functionality&lt;br /&gt;
* Code that conforms to our [https://github.com/zaproxy/zaproxy/wiki/DevGuidelines Development Rules and Guidelines]&lt;br /&gt;
&lt;br /&gt;
==== Knowledge Prerequisite: ====&lt;br /&gt;
ZAP is written in Java, so a good knowledge of this language is recommended. Some knowledge of application security would be useful, but not essential.&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' &lt;br /&gt;
[https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @] and the rest of the ZAP Core Team&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Your idea ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
ZAP is a great framework for building new and innovative security testing solutions. If you have an idea that is not on this list then don't worry, you can still submit it, we have accepted original projects in previous years and have even paid a student to work on their idea when we did not get enough GSoC slots to accept all of the projects we wanted.&lt;br /&gt;
&lt;br /&gt;
''' Getting started '''&lt;br /&gt;
* Get in touch with us :)&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* A new feature that makes ZAP even better&lt;br /&gt;
* Code that conforms to our [https://github.com/zaproxy/zaproxy/wiki/DevGuidelines Development Rules and Guidelines]&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* Experience with Java will definitely help&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' &lt;br /&gt;
[https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @] and the rest of the ZAP Core Team&lt;/div&gt;</summary>
		<author><name>Psiinon</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=GSOC2017_Ideas&amp;diff=225404</id>
		<title>GSOC2017 Ideas</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=GSOC2017_Ideas&amp;diff=225404"/>
				<updated>2017-01-20T09:26:27Z</updated>
		
		<summary type="html">&lt;p&gt;Psiinon: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=OWASP Project Requests=&lt;br /&gt;
&lt;br /&gt;
'''Tips to get you started in no particular order:''' &lt;br /&gt;
 * Read the [[GSoC SAT]]&lt;br /&gt;
 * Check the Hackademic wiki page linked above&lt;br /&gt;
 * Contact us through the mailing list or irc channel.&lt;br /&gt;
 * Check our [https://github.com/Hackademic/hackademic github repository] and especially the [https://github.com/Hackademic/hackademic/issues open tickets]&lt;br /&gt;
&lt;br /&gt;
== OWASP Juice Shop ==&lt;br /&gt;
&lt;br /&gt;
[[OWASP Juice Shop Project]] is an intentionally insecure webapp for security trainings written entirely in Javascript which encompasses the entire OWASP Top Ten and other severe security flaws. Juice Shop is written in Node.js, Express and AngularJS. The application contains more than 30 challenges of varying difficulty where the user is supposed to exploit the underlying vulnerabilities. Apart from the hacker and awareness training use case, pentesting proxies or security scanners can use Juice Shop as a &amp;quot;guinea pig&amp;quot;-application to check how well their tools cope with Javascript-heavy application frontends and REST APIs.&lt;br /&gt;
&lt;br /&gt;
=== Challenge Pack 2017 ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
Ideas for potential new hacking challenges are collected in [https://github.com/bkimminich/juice-shop/issues?q=is%3Aissue+is%3Aopen+label%3Achallenge GitHub issues labeled &amp;quot;challenge&amp;quot;]. This project could implement a whole bunch of challenges one by one and release them over the course of several small releases. This would allow the student to work in a professional Continuous Delivery kind of way while bringing benefit to the Juice Shop over the duration of the project.&lt;br /&gt;
&lt;br /&gt;
Coming up with additional ideas for challenges would be part of the project scope, as the list of pre-existing ideas might not be sufficient for a GSoC project.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* 10 or more new challenges for OWASP Juice Shop (including required functional enhancements to place the challenges in, e.g. the [https://github.com/bkimminich/juice-shop/issues/244 Order Dashboard] and [https://github.com/bkimminich/juice-shop/issues/243 Pomace Recycling user stories])&lt;br /&gt;
* Each challenge comes with full functional unit and integration tests&lt;br /&gt;
* Each challenge is verified to be exploitable by corresponding end-to-end tests&lt;br /&gt;
* Hint and solution sections for each new challenge are added to the &amp;quot;Pwning OWASP Juice Shop&amp;quot; ebook&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
* Get familiar with the architecture and code base of the application's rich Javascript frontend and RESTful backend&lt;br /&gt;
* Get a feeling for the high code &amp;amp; test quality bar by inspecting the existing test suites and static code analysis results&lt;br /&gt;
* Get familiar with the CI/CD process based on Travis-CI and several associated 3rd party services&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
Javascript, Test Driven Development, experience with (or willingness to learn) AngularJS (1.x) and NodeJS/Express, some security knowledge would be preferable.&lt;br /&gt;
&lt;br /&gt;
'''Mentors:'''&lt;br /&gt;
* [mailto:bjoern.kimminich@owasp.org Bjoern Kimminich] - OWASP Juice Shop Project Leader&lt;br /&gt;
&lt;br /&gt;
=== Tech Stack Update ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
t.b.d.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
t.b.d.&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
t.b.d.&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
t.b.d.&lt;br /&gt;
&lt;br /&gt;
'''Mentors:'''&lt;br /&gt;
t.b.d.&lt;br /&gt;
&lt;br /&gt;
== OWASP Mobile Hacking Playground ==&lt;br /&gt;
&lt;br /&gt;
The OWASP Mobile Hacking Playground (https://github.com/OWASP/OMTG-Hacking-Playground) is part of the OWASP Mobile universe, which consists at the moment of the following projects: &lt;br /&gt;
&lt;br /&gt;
* Mobile Application Security Verification (MASVS). The MASVS is a list of security requirements for mobile applications that can be used by architects, developers, testers, security professionals, and consumers to define what a secure mobile application is. (https://github.com/OWASP/owasp-masvs)&lt;br /&gt;
* Mobile Security Testing Guide (MSTG). The OWASP MSTG is a comprehensive manual for testing the security of mobile apps. It describes technical processes for verifying the controls listed in the OWASP Mobile Application Verification Standard (MASVS). The MSTG is meant to provide a baseline set of test cases for dynamic and static security tests, and to help ensure completeness and consistency of the tests. (https://github.com/OWASP/owasp-mstg)&lt;br /&gt;
&lt;br /&gt;
In order to give also practical guidance to developers, security researches and penetration testers of mobile Apps, a hacking playground was created with the goal to create different mobile App’s that contain different vulnerabilities that map to the MSTG test cases. Every test case described in the MSTG will therefore be implemented in an Android and iOS App. This has two advantages:&lt;br /&gt;
&lt;br /&gt;
* A developer can identify vulnerable code in the provided App’s and can see the implications and risks if such patterns are used and can look for the best practices in the MSTG to mitigate the vulnerabilities.&lt;br /&gt;
* Penetration testers / security researchers can identify bad practices, dangerous methods and classes they should look for when assessing a Mobile App and can gain more knowledge through the information provided in the OMTG.&lt;br /&gt;
&lt;br /&gt;
It is also encouraged to use the App(s) for education purpose during trainings and workshops.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Creation of Android Code Samples ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
An Android App that maps to the MSTG test cases is already created. This App contains mostly test cases that are related to data storage on an Android device. In order to close the gap to the MSTG more test cases need to be added that show &amp;quot;bad practices&amp;quot; that lead to vulnerabilites, but also the latest security best practices to demonstrate how vulnerabilites can be mitigated. &lt;br /&gt;
&lt;br /&gt;
For examples of implemented test cases, see the Wiki of the Mobile Hacking Playground: https://github.com/OWASP/OMTG-Hacking-Playground/wiki/Android-App&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
&lt;br /&gt;
The following categories and their test cases are not fully added to the  Android App:&lt;br /&gt;
&lt;br /&gt;
* Cryptography (https://github.com/OWASP/owasp-masvs/blob/master/Document/0x08-V3-Cryptography_Verification_Requirements.md)&lt;br /&gt;
* Authentication and Session Management (https://github.com/OWASP/owasp-masvs/blob/master/Document/0x09-V4-Authentication_and_Session_Management%20Requirements.md)&lt;br /&gt;
* Network Communication (https://github.com/OWASP/owasp-masvs/blob/master/Document/0x10-V5-Network_communication_requirements.md)&lt;br /&gt;
* Environmental Interaction (https://github.com/OWASP/owasp-masvs/blob/master/Document/0x11-V6-Interaction_with_the_environment.md)&lt;br /&gt;
* Code Quality (https://github.com/OWASP/owasp-masvs/blob/master/Document/0x12-V7-Code_quality_and_build_setting_requirements.md)&lt;br /&gt;
&lt;br /&gt;
For some of the testcases this also includes creating an endpoint on server side in order to fully understand the test case and possible security concerns.&lt;br /&gt;
&lt;br /&gt;
As not all missing test cases can be implemented during the GSOC a subset of them will be defined with the student together. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
Here are a few suggestion on how to get started.&lt;br /&gt;
* Check the Mobile Hacking Playground Android App, browse through the code and Wiki to get an understanding of what a test case look likes. &lt;br /&gt;
* Browse through the MASVS and check the different areas and their defined requirements.&lt;br /&gt;
* Read about Security vulnerabilites and best practices for Android in areas you are interested in (e.g. Cryptography).&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
General interest in Mobile and Security. Basic knowledge of Android and Java.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' [mailto:sven.schleier@owasp.org Sven Schleier] - OWASP Mobile Security Testing Guide and Mobile Hacking Playground Project Leader&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP Hackademic Challenges SAMPLE ENTRY==&lt;br /&gt;
&lt;br /&gt;
[[OWASP Hackademic Challenges Project]]  helps you test your knowledge on web application security. You can use it to actually attack web applications in a realistic but also controllable and safe environment. After a wonderfull 2014 GSoC with 100 new challenges and a couple of new plugins we're mainly looking to get new features in and maybe a couple of challenges. Bellow is a list of proposed features.&lt;br /&gt;
&lt;br /&gt;
=== REST API for the sandbox ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
During the last summer code sprint Hackademic got challenge sandboxing in the form of vagrant and docker wrappers as well as an engine to start and stop the container or vm instances.&lt;br /&gt;
What is needed now is a rest api which supports endpoint authentication and authorization which enables the sandbox engine to be completely independed from the rest of the project.&lt;br /&gt;
&lt;br /&gt;
Ideas on the project:&lt;br /&gt;
Since the sandbox is written in python, you will be using Django to implement the api.&lt;br /&gt;
The endpoint authorization can be done via certificates or plain signature or username/password type authentication. We would like to see what's your idea on the matter.&lt;br /&gt;
However the communication between the two has to be over a secure channel.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* A REST style api which allows an authenticated remote entity control the parts of the  sandbox engine it has access to.&lt;br /&gt;
* PEP8 compliant code&lt;br /&gt;
* Acceptable unit test coverage&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
Since this has been a popular project here's a suggestion on how to get started.&lt;br /&gt;
* Check the excellent work done by mebjas and a0xnirudh in their respective brances in the project's repository&lt;br /&gt;
* Take a brief look at the code and try to get a feeling of the functionality included. (Essentially it's CRUD operations on vms or containers)&lt;br /&gt;
* Read on what Docker and Vagrant are and take a look at their respective py-libraries&lt;br /&gt;
* If you think that contributing helps perhaps it would be a good idea to start with lettuce tests on the current CRUD operations of the existing functionality(which won't change and can eventually be ported to the final project) &lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
Python, test driven development, some idea what REST is, some security knowledge would be preferable.&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' [mailto:konstantinos.papapanaqiotou@owasp.org Konstantinos Papapanagiotou][mailto:spyros.gasteratos@owasp.org Spyros Gasteratos] - Hackademic Challenges Project Leaders&lt;br /&gt;
&lt;br /&gt;
=== New CMS ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
The CMS part of the project is really old and has accumulated a significant amount of technical debt.&lt;br /&gt;
In addition many design decisions are either outdated or could be improved. &lt;br /&gt;
Therefore it may be a good idea to leverage the power of modern web frameworks to create a new CMS.&lt;br /&gt;
The new cms can be written in python using Django.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* New cms with same functionality as the old one (3 types of users -- student, teacher, admin--, 3 types of resources -- article challenge, class--, ACL type permissions, CRUD operations on every resource/user, all functionality can be extended by Plugins.&lt;br /&gt;
* REST endpoints in addition to classic ones&lt;br /&gt;
* tests covering all routes implemented, also complete ACL unit tests, it would be embarassing if a cms by OWASP has rights vulnerabilities.&lt;br /&gt;
* PEP 8 code&lt;br /&gt;
&lt;br /&gt;
''' Note: '''&lt;br /&gt;
This is a huge project, it is ok if the student implements a part of it. However whatever implemented must be up to spec.&lt;br /&gt;
If you decide to take on this project contact us and we can agree on a list of routes.&lt;br /&gt;
If you don't decide to take on this project contact us.&lt;br /&gt;
Generally contact us, we like it when students have insightful questions and the community is active&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''' Getting Started: '''&lt;br /&gt;
* Install and take a brief look around the old cms so you have an idea of the functionality needed&lt;br /&gt;
* It's ok to scream in frustration&lt;br /&gt;
* If you want to contribute to get a feeling of the platform a good idea would be lettuce tests for the current functionality (which won't change and you can port in the new cms eventually)&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
Python, Django, what REST is, the technologies used, some security knowledge would be nice.&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' [mailto:konstantinos.papapanaqiotou@owasp.org Konstantinos Papapanagiotou][mailto:spyros.gasteratos@owasp.org Spyros Gasteratos] - Hackademic Challenges Project Leaders&lt;br /&gt;
&lt;br /&gt;
=== First Course Type Challenge ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
We have a wonderful sandbox engine which allows for complex guided challenges to be implemented.&lt;br /&gt;
We'd like to build a challenge that guides the user through a series of steps to an end goal and teaches more information on the subject matter on the way.&lt;br /&gt;
This is a very open-ended project on purpose to allow creative student to come up with nice ideas.&lt;br /&gt;
Bellow you will find some examples that we thought might be interesting.&lt;br /&gt;
&lt;br /&gt;
Ideas on the project:&lt;br /&gt;
* Purposefully vulnerable web page that guides the user via javascript tooltips and hints to exploiting it using ZAP. ( Bonus: using ZAP via the ZAP api). The challenge is solved when the the student submits the contents of a text file located on the disk (obtained by exploited an RCE)&lt;br /&gt;
&lt;br /&gt;
* Reversing a provided binary to extract information by providing step by step instructions to reversing using any popular reversing tool (well, you can't use IDA so gdb should have to do). Challenge is solved when the keys are extracted from the binary and submitted. Bonus points if each binary donwloaded has different keys.&lt;br /&gt;
&lt;br /&gt;
* Guide to exploiting the TOP10. (Using ZAP?)&lt;br /&gt;
&lt;br /&gt;
* Defensive Type challenges -- Here's how to create a patch for this kind of vulnerability -- Challenge is solved when the unit tests are run and the vulnerability isn't there.&lt;br /&gt;
&lt;br /&gt;
''' Getting started '''&lt;br /&gt;
* Check popular javascript guide tools such as: (http://introjs.com/ and http://github.hubspot.com/shepherd/docs/welcome/ )&lt;br /&gt;
* If you're more interested in system or non-web challenges check serverspec and definitely check quest (https://github.com/puppetlabs/quest)&lt;br /&gt;
* If you think contributing is a good idea to make yourself familiar with the project you can either port one of the existing simpler 1-page challenges to a docker container and submit a pull request or write a guide on how to create such a challenge&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
&lt;br /&gt;
* One or more Course - style challenges provided either as a docker container or as a vagrant box.&lt;br /&gt;
* Concrete documentation on how to build a challenge like this.&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
The technologies used.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' [mailto:konstantinos.papapanaqiotou@owasp.org Konstantinos Papapanagiotou][mailto:spyros.gasteratos@owasp.org Spyros Gasteratos] - Hackademic Challenges Project Leaders&lt;br /&gt;
&lt;br /&gt;
=== Advanced Sandboxed Challenges ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
In the spirit of the challenges above, we're looking for true ctf type challenges.&lt;br /&gt;
This is an open ended task. We're expecting awesome fresh ideas.&lt;br /&gt;
&lt;br /&gt;
Ideas on the project:&lt;br /&gt;
* An application vulnerable to one or more TOP 10 elements.&lt;br /&gt;
* A logic flaws based ctf&lt;br /&gt;
* Your idea here&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
* Check what Vagrant/Docker is&lt;br /&gt;
* Port one simple 1-page challenge (you can use one we already have ) to docker or vagrant&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
Docker containers or Vagrant boxes that contain complete new challenges.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
Knowledge of the technologies used&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' [mailto:konstantinos.papapanaqiotou@owasp.org Konstantinos Papapanagiotou][mailto:spyros.gasteratos@owasp.org Spyros Gasteratos] - Hackademic Challenges Project Leaders&lt;br /&gt;
&lt;br /&gt;
=== Your idea ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
Amazing students, in our experience, the best, most creative and unique ideas show up when we let students suggest their own feature in relation to the project.&lt;br /&gt;
The above should give you a general idea where we're going but don't let them constrain you.&lt;br /&gt;
Do you wanna do something that would fit into Hackademic? Send us an email!&lt;br /&gt;
&lt;br /&gt;
Ideas on the project:&lt;br /&gt;
No idea, that's your turn to shine!&lt;br /&gt;
&lt;br /&gt;
''' Getting started '''&lt;br /&gt;
* Be awesome&lt;br /&gt;
* Have an idea&lt;br /&gt;
* Be a student&lt;br /&gt;
* Explain definite proof of the p vs np solution(jk, an algorithm that breaks RSA in polynomial time would be totally acceptable)&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
If it's code, code according to our coding standards.&lt;br /&gt;
If it's challenges, something new and interesting.&lt;br /&gt;
If it's something else, then written like the person who's going to maintain your code is a raging psychopath with an axe who knows where you live.&lt;br /&gt;
&lt;br /&gt;
In short we'd like some quality. ;-)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' [mailto:konstantinos.papapanaqiotou@owasp.org Konstantinos Papapanagiotou][mailto:spyros.gasteratos@owasp.org Spyros Gasteratos] - Hackademic Challenges Project Leaders&lt;br /&gt;
&lt;br /&gt;
== OWASP ZAP ==&lt;br /&gt;
&lt;br /&gt;
[[OWASP Zed Attack Proxy Project]] (ZAP) The OWASP Zed Attack Proxy (ZAP) is one of the world’s most popular free security tools and is actively maintained by hundreds of international volunteers. Previous GSoC students have implemented key parts of the ZAP core functionality and have been offered (and accepted) jobs based on their work on ZAP.&lt;br /&gt;
&lt;br /&gt;
We have just included a few of the ideas we have here, for a more complete list see the issues on the ZAP bug tracker with the [https://github.com/zaproxy/zaproxy/issues?q=is%3Aopen+is%3Aissue+label%3Aproject project] label.&lt;br /&gt;
&lt;br /&gt;
=== Field enumeration ===&lt;br /&gt;
&lt;br /&gt;
This would allow a user to iterate though a set of (user defined) characters in order to identify the ones that are filtered out and/or escaped.&lt;br /&gt;
&lt;br /&gt;
The user should be able to define the character sets to test and will probably need to configure the success and failure conditions, as well as valid values for other fields in the form.&lt;br /&gt;
&lt;br /&gt;
''' Expected Results '''&lt;br /&gt;
&lt;br /&gt;
* User able to specify a specific field to enumerate via the ZAP UI&lt;br /&gt;
* A list of all valid characters to be returned from the sets of characters the user specifies&lt;br /&gt;
* Ability to configure a wide range of success and failure conditions to cope with as many possible situations as possible&lt;br /&gt;
&lt;br /&gt;
''' Knowledge Prerequisite: '''&lt;br /&gt;
ZAP is written in Java, so a good knowledge of this language is recommended, as is knowledge of HTML. Some knowledge of application security would be useful, but not essential.&lt;br /&gt;
&lt;br /&gt;
''' Mentors '''&lt;br /&gt;
[mailto:psiinon@gmail.com Simon Bennetts] and other members of the ZAP core team&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Your idea ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
ZAP is a great framework for building new and innovative security testing solutions. If you have an idea that is not on this list then don't worry, you can still submit it, we have accepted original projects in previous years and have even paid a student to work on their idea when we did not get enough GSoC slots to accept all of the projects we wanted.&lt;br /&gt;
&lt;br /&gt;
''' Getting started '''&lt;br /&gt;
* Get in touch with us :)&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* Code that conforms to our [https://github.com/zaproxy/zaproxy/wiki/DevGuidelines Development Rules and Guidelines]&lt;br /&gt;
* A new feature that makes ZAP even better&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* Experience with Java will definitely help&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' [https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @] and the rest of the ZAP core team&lt;/div&gt;</summary>
		<author><name>Psiinon</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Zed_Attack_Proxy_Project&amp;diff=224248</id>
		<title>OWASP Zed Attack Proxy Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Zed_Attack_Proxy_Project&amp;diff=224248"/>
				<updated>2016-12-20T16:29:39Z</updated>
		
		<summary type="html">&lt;p&gt;Psiinon: added link to jenkins plugin homepage&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Main = &lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:90px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File: flagship_big.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
{{ReviewProject|projectname=zaproxy|language=en}}&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
The OWASP Zed Attack Proxy (ZAP) is one of the world’s most popular free security tools and is actively maintained by hundreds of international volunteers[[#Justification|*]]. It can help you automatically find security vulnerabilities in your web applications while you are developing and testing your applications. Its also a great tool for experienced pentesters to use for manual security testing.&lt;br /&gt;
&lt;br /&gt;
[[Image:ZAP-Download.png | link=https://github.com/zaproxy/zaproxy/wiki/Downloads]]&lt;br /&gt;
&lt;br /&gt;
====Please help us to make ZAP even better for you by answering the [https://docs.google.com/forms/d/1-k-vcj_sSxlil6XLxCFade-m-IQVeE2h9gduA-2ZPPA/viewform ZAP User Questionnaire]!====&lt;br /&gt;
&lt;br /&gt;
For a quick overview of ZAP and an introduction to the [https://wiki.jenkins-ci.org/display/JENKINS/zap+plugin official ZAP Jenkins plugin] see these tutorial videos on YouTube:&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
{{#ev:youtube|eH0RBI0nmww}}&amp;amp;nbsp;&lt;br /&gt;
{{#ev:youtube|mmHZLSffCUg}}&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
For more videos see the links on the [https://github.com/zaproxy/zaproxy/wiki/Videos wiki videos page].&lt;br /&gt;
&lt;br /&gt;
Interested in a ZAP talk or training event? See the [https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project#tab=Talks talks] tab. Not one near you? Contact a [https://github.com/zaproxy/zaproxy/wiki/ZapEvangelists Zap Evangelist] to arrange one!&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Zed Attack Proxy&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
For general information about ZAP:&lt;br /&gt;
* [https://twitter.com/zaproxy Twitter] - official ZAP announcements (low volume)&lt;br /&gt;
* [https://zaproxy.blogspot.co.uk/ Blog] - official ZAP blog&lt;br /&gt;
&lt;br /&gt;
For help using ZAP:&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/releases/download/2.4.0/ZAPGettingStartedGuide-2.4.pdf Getting Started Guide (pdf)] - an introductory guide you can print&lt;br /&gt;
* [https://www.youtube.com/playlist?list=PLEBitBW-Hlsv8cEIUntAO8st2UGhmrjUB Tutorial Videos]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki User Guide] - online version of the User Guide included with ZAP&lt;br /&gt;
* [https://groups.google.com/group/zaproxy-users User Group] - ask questions about using ZAP&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/wiki Add-ons] - help for the optional add-ons you can install&lt;br /&gt;
* [https://stackoverflow.com/questions/tagged/zap StackOverflow] - because some people use this for all everything ;)&lt;br /&gt;
&lt;br /&gt;
To learn more about ZAP development:&lt;br /&gt;
* [https://github.com/zaproxy Source Code] - for all of the ZAP related projects&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/wiki/Introduction Wiki] - lots of detailed info&lt;br /&gt;
* [https://groups.google.com/group/zaproxy-develop Developer Group] - ask questions about the ZAP internals&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap Crowdin (GUI)] - help translate the ZAP GUI&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap-help Crowdin (User Guide)] - help translate the ZAP User Guide&lt;br /&gt;
* [https://www.openhub.net/p/zaproxy OpenHub]	- FOSS analytics&lt;br /&gt;
* [https://www.bountysource.com/teams/zap/issues BountySource] - Vote on ZAP issues (you can also donate money here, but 10% taken out)&lt;br /&gt;
&lt;br /&gt;
===Justification===&lt;br /&gt;
Justification for the statements made in the tagline at the top;)&lt;br /&gt;
&lt;br /&gt;
Popularity:&lt;br /&gt;
* ToolsWatch Annual Best Free/Open Source Security Tool Survey:&lt;br /&gt;
** 2015 [http://www.toolswatch.org/2016/02/2015-top-security-tools-as-voted-by-toolswatch-org-readers/ 1st]&lt;br /&gt;
** 2014 [http://www.toolswatch.org/2015/01/2014-top-security-tools-as-voted-by-toolswatch-org-readers/ 2nd]&lt;br /&gt;
** 2013 [http://www.toolswatch.org/2013/12/2013-top-security-tools-as-voted-by-toolswatch-org-readers/ 1st]&lt;br /&gt;
&lt;br /&gt;
Contributors:&lt;br /&gt;
* [https://www.openhub.net/p/zaproxy Code Contributors]&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap ZAP core i18n Contributors]&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap-help ZAP help i18n Contributors]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{{Social Media Links}}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
[https://github.com/zaproxy/zaproxy/wiki/Downloads Download OWASP ZAP!]&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
Please see the [https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project#News News] and [https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project#Talks Talks] tabs&lt;br /&gt;
&lt;br /&gt;
== Change Log ==&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/commits/develop zaproxy]&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/commits/master zap-extensions]&lt;br /&gt;
&lt;br /&gt;
== Code Repo ==&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/ zaproxy]&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/ zap-extensions]&lt;br /&gt;
&lt;br /&gt;
== Email List ==&lt;br /&gt;
&lt;br /&gt;
Questions? Please ask on the [http://groups.google.com/group/zaproxy-users ZAP User Group]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
Project Leader&amp;lt;br/&amp;gt;[https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_Web_Testing_Environment_Project OWASP WTE]&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_OWTF OWASP OWTF]&lt;br /&gt;
&lt;br /&gt;
== Ohloh ==&lt;br /&gt;
&lt;br /&gt;
*https://www.openhub.net/p/zaproxy&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; rowspan=&amp;quot;2&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Mature projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Flagship_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;center&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]&lt;br /&gt;
   |&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;center&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-breakers-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [http://www.apache.org/licenses/LICENSE-2.0 Apache 2 License]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Screenshots =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotAddAlert.png||400px||ZAP Add Alert Screen Shot]] &lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotHelp.png||400px|left|ZAP Help Screen Shot]]&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotHistoryFilter.png|thumb|400px|left|ZAP History Filter Screen Shot]]&lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotSearchTab.png|thumb|400px|left|ZAP Search Tab Screen Shot]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Talks =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
{{:Projects/OWASP Zed Attack Proxy Project/Pages/Talks | Talks}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
= News =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
{{:Projects/OWASP Zed Attack Proxy Project/Pages/News | News}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
= ZAP Gear =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Yes, you can now buy ZAP related gear!&lt;br /&gt;
&lt;br /&gt;
All of the artwork for ZAP swag is released under the Creative Common License and can be downloaded from the [https://github.com/zaproxy/zap-swag zap-swag] repo.&lt;br /&gt;
&lt;br /&gt;
You can of course use the artwork from this repo with any other online store that you like.&lt;br /&gt;
&lt;br /&gt;
A range of products can be purchased from [http://www.redbubble.com/people/zaproxy Redbubble]&lt;br /&gt;
&lt;br /&gt;
Stickers can be purchased from [https://www.stickermule.com/uk/user/1070684077/stickers Stickermule]&lt;br /&gt;
&lt;br /&gt;
T-shirts can be purchased from [http://www.cafepress.com/zaproxy Cafepress]&lt;br /&gt;
&lt;br /&gt;
[[Image:zap-tshirt-cp.PNG | link=http://www.cafepress.com/zaproxy]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Supporters =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
ZAP is developed by a worldwide [https://github.com/zaproxy/zap-core-help/wiki/HelpCredits team] of volunteers.&lt;br /&gt;
&lt;br /&gt;
But we have also been helped by many organizations, either financially or by encouraging their employees to work on ZAP:&lt;br /&gt;
&lt;br /&gt;
* [http://www.mozilla.org Mozilla]&lt;br /&gt;
* [http://www.linuxfoundation.org/ The Linux Foundation]&lt;br /&gt;
* [http://www.owasp.org OWASP]&lt;br /&gt;
* [http://www.sage.co.uk Sage]&lt;br /&gt;
* [http://www.google.com Google]&lt;br /&gt;
* [http://www.microsoft.com Microsoft]&lt;br /&gt;
* [http://www.hacktics.com/ Hacktics, Ernst &amp;amp; Young]&lt;br /&gt;
* [http://www.dinosec.com/ DinoSec]&lt;br /&gt;
* [http://www.denimgroup.com Denim Group]&lt;br /&gt;
* [http://www.aspectsecurity.com/ Aspect Security]&lt;br /&gt;
* [http://secureideas.net SecureIdeas]&lt;br /&gt;
* [http://utilisec.com UtiliSec]&lt;br /&gt;
* [http://www.encription.co.uk/ encription]&lt;br /&gt;
* [https://www.accenture.com/us-en/digital-index.aspx Accenture Digital]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Functionality =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
'''Some of ZAP's functionality:'''&lt;br /&gt;
&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsIntercept Intercepting Proxy]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsSpider Traditional] and AJAX spiders&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsAscan Automated scanner]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsPscan Passive scanner]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsBruteforce Forced browsing]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsFuzz Fuzzer]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpUiDialogsOptionsDynsslcert Dynamic SSL certificates]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/SmartCards Smartcard and Client Digital Certificates support]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpAddonsWebsocketIntroduction Web sockets] support&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpAddonsScriptsScripts Support for a wide range of scripting languages]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki//HelpAddonsPlugnhackPlugnhack Plug-n-Hack support]&lt;br /&gt;
* Authentication and session support&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsApi Powerful REST based API]&lt;br /&gt;
* Automatic updating option&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/wiki Integrated and growing marketplace of add-ons]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
= Features =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
'''Some of ZAP's features:'''&lt;br /&gt;
&lt;br /&gt;
* [http://www.apache.org/licenses/LICENSE-2.0 Open source]&lt;br /&gt;
* Cross platform (it even runs on a [https://github.com/zaproxy/zaproxy/wiki/zappi Raspberry Pi!])&lt;br /&gt;
* Easy to install (just requires java 1.7)&lt;br /&gt;
* Completely free (no paid for 'Pro' version)&lt;br /&gt;
* Ease of use a priority&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpIntro Comprehensive help pages]&lt;br /&gt;
* Fully internationalized&lt;br /&gt;
* Translated into over 20 languages&lt;br /&gt;
* Community based, with involvement actively encouraged&lt;br /&gt;
* Under active development by an international team of volunteers&lt;br /&gt;
&lt;br /&gt;
ZAP is a fork of the well regarded [http://www.parosproxy.org/ Paros Proxy].&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Languages =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''ZAP supports the following languages:'''&lt;br /&gt;
&lt;br /&gt;
* English&lt;br /&gt;
* Arabic&lt;br /&gt;
* Bosnian&lt;br /&gt;
* Brazilian Portuguese&lt;br /&gt;
* Chinese&lt;br /&gt;
* Danish&lt;br /&gt;
* Filipino&lt;br /&gt;
* French&lt;br /&gt;
* German&lt;br /&gt;
* Greek&lt;br /&gt;
* Hungarian&lt;br /&gt;
* Indonesian&lt;br /&gt;
* Italian&lt;br /&gt;
* Japanese&lt;br /&gt;
* Korean&lt;br /&gt;
* Persian&lt;br /&gt;
* Polish&lt;br /&gt;
* Russian&lt;br /&gt;
* Sinhala&lt;br /&gt;
* Spanish&lt;br /&gt;
* Urdu &lt;br /&gt;
&lt;br /&gt;
You can use [http://crowdin.net/project/owasp-zap Crowdin] to help improve these translations or add new ones right now!&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Release 2.4.3==&lt;br /&gt;
ZAP 2.4.3 has been released, this is a bug fix and enhancement release&lt;br /&gt;
&lt;br /&gt;
For more details see https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_4_3&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Get Involved =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Involvement in the development of ZAP is actively encouraged!&lt;br /&gt;
&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
&lt;br /&gt;
Some of the ways you can help:&lt;br /&gt;
&lt;br /&gt;
==Feature Requests==&lt;br /&gt;
&lt;br /&gt;
Please raise new feature requests as enhancement requests here: https://github.com/zaproxy/zaproxy/issues&lt;br /&gt;
&lt;br /&gt;
If there are existing requests you are also interested in then please 'star' them - that way we can see which features people are most interested in and can prioritize them accordingly. &lt;br /&gt;
&lt;br /&gt;
==Feedback==&lt;br /&gt;
&lt;br /&gt;
Please use the [http://groups.google.com/group/zaproxy-users zaproxy-users Google Group] for feedback:&lt;br /&gt;
* What do like?&lt;br /&gt;
* What don't you like?&lt;br /&gt;
* What features could be made easier to use?&lt;br /&gt;
* How could the help pages be improved? &lt;br /&gt;
&lt;br /&gt;
==Log issues==&lt;br /&gt;
&lt;br /&gt;
Have you had a problem using ZAP?&lt;br /&gt;
&lt;br /&gt;
If so and its not already been logged then please [https://github.com/zaproxy/zaproxy/issues report it]&lt;br /&gt;
&lt;br /&gt;
==Localization==&lt;br /&gt;
&lt;br /&gt;
Are you fluent in another language? Can you help translate ZAP into that language?&lt;br /&gt;
&lt;br /&gt;
You can use [http://crowdin.net/project/owasp-zap Crowdin] to do that!&lt;br /&gt;
&lt;br /&gt;
==Development==&lt;br /&gt;
&lt;br /&gt;
If you fancy having a go at adding functionality to ZAP then please get in touch via the [http://groups.google.com/group/zaproxy-develop zaproxy-develop Google Group].&lt;br /&gt;
&lt;br /&gt;
Again, you do not have to be a security expert to contribute code - working on ZAP could be great way to learn more about web application security!&lt;br /&gt;
&lt;br /&gt;
If you actively contribute to ZAP then you will be invited to join the project. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Zed Attack Proxy Project]]&lt;br /&gt;
[[Category:OWASP_Tool]]&lt;br /&gt;
[[Category:OWASP_Release_Quality_Tool|OWASP Release Quality Tool]]&lt;br /&gt;
[[Category:OWASP_Download]]&lt;br /&gt;
[[Category:Popular]]&lt;br /&gt;
[[Category:SAMM-ST-2]]&lt;/div&gt;</summary>
		<author><name>Psiinon</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Zed_Attack_Proxy_Project&amp;diff=224191</id>
		<title>OWASP Zed Attack Proxy Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Zed_Attack_Proxy_Project&amp;diff=224191"/>
				<updated>2016-12-16T11:58:16Z</updated>
		
		<summary type="html">&lt;p&gt;Psiinon: Replaced 2.4.0 vid with Jenkins one&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Main = &lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:90px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File: flagship_big.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
{{ReviewProject|projectname=zaproxy|language=en}}&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
The OWASP Zed Attack Proxy (ZAP) is one of the world’s most popular free security tools and is actively maintained by hundreds of international volunteers[[#Justification|*]]. It can help you automatically find security vulnerabilities in your web applications while you are developing and testing your applications. Its also a great tool for experienced pentesters to use for manual security testing.&lt;br /&gt;
&lt;br /&gt;
[[Image:ZAP-Download.png | link=https://github.com/zaproxy/zaproxy/wiki/Downloads]]&lt;br /&gt;
&lt;br /&gt;
====Please help us to make ZAP even better for you by answering the [https://docs.google.com/forms/d/1-k-vcj_sSxlil6XLxCFade-m-IQVeE2h9gduA-2ZPPA/viewform ZAP User Questionnaire]!====&lt;br /&gt;
&lt;br /&gt;
For a quick overview of ZAP and an introduction to the official ZAP Jenkins plugin see these tutorial videos on YouTube:&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
{{#ev:youtube|eH0RBI0nmww}}&amp;amp;nbsp;&lt;br /&gt;
{{#ev:youtube|mmHZLSffCUg}}&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
For more videos see the links on the [https://github.com/zaproxy/zaproxy/wiki/Videos wiki videos page].&lt;br /&gt;
&lt;br /&gt;
Interested in a ZAP talk or training event? See the [https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project#tab=Talks talks] tab. Not one near you? Contact a [https://github.com/zaproxy/zaproxy/wiki/ZapEvangelists Zap Evangelist] to arrange one!&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Zed Attack Proxy&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
For general information about ZAP:&lt;br /&gt;
* [https://twitter.com/zaproxy Twitter] - official ZAP announcements (low volume)&lt;br /&gt;
* [https://zaproxy.blogspot.co.uk/ Blog] - official ZAP blog&lt;br /&gt;
&lt;br /&gt;
For help using ZAP:&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/releases/download/2.4.0/ZAPGettingStartedGuide-2.4.pdf Getting Started Guide (pdf)] - an introductory guide you can print&lt;br /&gt;
* [https://www.youtube.com/playlist?list=PLEBitBW-Hlsv8cEIUntAO8st2UGhmrjUB Tutorial Videos]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki User Guide] - online version of the User Guide included with ZAP&lt;br /&gt;
* [https://groups.google.com/group/zaproxy-users User Group] - ask questions about using ZAP&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/wiki Add-ons] - help for the optional add-ons you can install&lt;br /&gt;
* [https://stackoverflow.com/questions/tagged/zap StackOverflow] - because some people use this for all everything ;)&lt;br /&gt;
&lt;br /&gt;
To learn more about ZAP development:&lt;br /&gt;
* [https://github.com/zaproxy Source Code] - for all of the ZAP related projects&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/wiki/Introduction Wiki] - lots of detailed info&lt;br /&gt;
* [https://groups.google.com/group/zaproxy-develop Developer Group] - ask questions about the ZAP internals&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap Crowdin (GUI)] - help translate the ZAP GUI&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap-help Crowdin (User Guide)] - help translate the ZAP User Guide&lt;br /&gt;
* [https://www.openhub.net/p/zaproxy OpenHub]	- FOSS analytics&lt;br /&gt;
* [https://www.bountysource.com/teams/zap/issues BountySource] - Vote on ZAP issues (you can also donate money here, but 10% taken out)&lt;br /&gt;
&lt;br /&gt;
===Justification===&lt;br /&gt;
Justification for the statements made in the tagline at the top;)&lt;br /&gt;
&lt;br /&gt;
Popularity:&lt;br /&gt;
* ToolsWatch Annual Best Free/Open Source Security Tool Survey:&lt;br /&gt;
** 2015 [http://www.toolswatch.org/2016/02/2015-top-security-tools-as-voted-by-toolswatch-org-readers/ 1st]&lt;br /&gt;
** 2014 [http://www.toolswatch.org/2015/01/2014-top-security-tools-as-voted-by-toolswatch-org-readers/ 2nd]&lt;br /&gt;
** 2013 [http://www.toolswatch.org/2013/12/2013-top-security-tools-as-voted-by-toolswatch-org-readers/ 1st]&lt;br /&gt;
&lt;br /&gt;
Contributors:&lt;br /&gt;
* [https://www.openhub.net/p/zaproxy Code Contributors]&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap ZAP core i18n Contributors]&lt;br /&gt;
* [https://crowdin.com/project/owasp-zap-help ZAP help i18n Contributors]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{{Social Media Links}}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
[https://github.com/zaproxy/zaproxy/wiki/Downloads Download OWASP ZAP!]&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
Please see the [https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project#News News] and [https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project#Talks Talks] tabs&lt;br /&gt;
&lt;br /&gt;
== Change Log ==&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/commits/develop zaproxy]&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/commits/master zap-extensions]&lt;br /&gt;
&lt;br /&gt;
== Code Repo ==&lt;br /&gt;
* [https://github.com/zaproxy/zaproxy/ zaproxy]&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/ zap-extensions]&lt;br /&gt;
&lt;br /&gt;
== Email List ==&lt;br /&gt;
&lt;br /&gt;
Questions? Please ask on the [http://groups.google.com/group/zaproxy-users ZAP User Group]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
Project Leader&amp;lt;br/&amp;gt;[https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_Web_Testing_Environment_Project OWASP WTE]&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_OWTF OWASP OWTF]&lt;br /&gt;
&lt;br /&gt;
== Ohloh ==&lt;br /&gt;
&lt;br /&gt;
*https://www.openhub.net/p/zaproxy&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; rowspan=&amp;quot;2&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Mature projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Flagship_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;center&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]&lt;br /&gt;
   |&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;center&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-breakers-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [http://www.apache.org/licenses/LICENSE-2.0 Apache 2 License]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Screenshots =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotAddAlert.png||400px||ZAP Add Alert Screen Shot]] &lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotHelp.png||400px|left|ZAP Help Screen Shot]]&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotHistoryFilter.png|thumb|400px|left|ZAP History Filter Screen Shot]]&lt;br /&gt;
|&lt;br /&gt;
[[Image:ZAP-ScreenShotSearchTab.png|thumb|400px|left|ZAP Search Tab Screen Shot]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Talks =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
{{:Projects/OWASP Zed Attack Proxy Project/Pages/Talks | Talks}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
= News =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
{{:Projects/OWASP Zed Attack Proxy Project/Pages/News | News}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
= ZAP Gear =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Yes, you can now buy ZAP related gear!&lt;br /&gt;
&lt;br /&gt;
All of the artwork for ZAP swag is released under the Creative Common License and can be downloaded from the [https://github.com/zaproxy/zap-swag zap-swag] repo.&lt;br /&gt;
&lt;br /&gt;
You can of course use the artwork from this repo with any other online store that you like.&lt;br /&gt;
&lt;br /&gt;
A range of products can be purchased from [http://www.redbubble.com/people/zaproxy Redbubble]&lt;br /&gt;
&lt;br /&gt;
Stickers can be purchased from [https://www.stickermule.com/uk/user/1070684077/stickers Stickermule]&lt;br /&gt;
&lt;br /&gt;
T-shirts can be purchased from [http://www.cafepress.com/zaproxy Cafepress]&lt;br /&gt;
&lt;br /&gt;
[[Image:zap-tshirt-cp.PNG | link=http://www.cafepress.com/zaproxy]]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Supporters =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
ZAP is developed by a worldwide [https://github.com/zaproxy/zap-core-help/wiki/HelpCredits team] of volunteers.&lt;br /&gt;
&lt;br /&gt;
But we have also been helped by many organizations, either financially or by encouraging their employees to work on ZAP:&lt;br /&gt;
&lt;br /&gt;
* [http://www.mozilla.org Mozilla]&lt;br /&gt;
* [http://www.linuxfoundation.org/ The Linux Foundation]&lt;br /&gt;
* [http://www.owasp.org OWASP]&lt;br /&gt;
* [http://www.sage.co.uk Sage]&lt;br /&gt;
* [http://www.google.com Google]&lt;br /&gt;
* [http://www.microsoft.com Microsoft]&lt;br /&gt;
* [http://www.hacktics.com/ Hacktics, Ernst &amp;amp; Young]&lt;br /&gt;
* [http://www.dinosec.com/ DinoSec]&lt;br /&gt;
* [http://www.denimgroup.com Denim Group]&lt;br /&gt;
* [http://www.aspectsecurity.com/ Aspect Security]&lt;br /&gt;
* [http://secureideas.net SecureIdeas]&lt;br /&gt;
* [http://utilisec.com UtiliSec]&lt;br /&gt;
* [http://www.encription.co.uk/ encription]&lt;br /&gt;
* [https://www.accenture.com/us-en/digital-index.aspx Accenture Digital]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Functionality =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
'''Some of ZAP's functionality:'''&lt;br /&gt;
&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsIntercept Intercepting Proxy]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsSpider Traditional] and AJAX spiders&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsAscan Automated scanner]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsPscan Passive scanner]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsBruteforce Forced browsing]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsFuzz Fuzzer]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpUiDialogsOptionsDynsslcert Dynamic SSL certificates]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/SmartCards Smartcard and Client Digital Certificates support]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpAddonsWebsocketIntroduction Web sockets] support&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpAddonsScriptsScripts Support for a wide range of scripting languages]&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki//HelpAddonsPlugnhackPlugnhack Plug-n-Hack support]&lt;br /&gt;
* Authentication and session support&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsApi Powerful REST based API]&lt;br /&gt;
* Automatic updating option&lt;br /&gt;
* [https://github.com/zaproxy/zap-extensions/wiki Integrated and growing marketplace of add-ons]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
= Features =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
'''Some of ZAP's features:'''&lt;br /&gt;
&lt;br /&gt;
* [http://www.apache.org/licenses/LICENSE-2.0 Open source]&lt;br /&gt;
* Cross platform (it even runs on a [https://github.com/zaproxy/zaproxy/wiki/zappi Raspberry Pi!])&lt;br /&gt;
* Easy to install (just requires java 1.7)&lt;br /&gt;
* Completely free (no paid for 'Pro' version)&lt;br /&gt;
* Ease of use a priority&lt;br /&gt;
* [https://github.com/zaproxy/zap-core-help/wiki/HelpIntro Comprehensive help pages]&lt;br /&gt;
* Fully internationalized&lt;br /&gt;
* Translated into over 20 languages&lt;br /&gt;
* Community based, with involvement actively encouraged&lt;br /&gt;
* Under active development by an international team of volunteers&lt;br /&gt;
&lt;br /&gt;
ZAP is a fork of the well regarded [http://www.parosproxy.org/ Paros Proxy].&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Languages =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''ZAP supports the following languages:'''&lt;br /&gt;
&lt;br /&gt;
* English&lt;br /&gt;
* Arabic&lt;br /&gt;
* Bosnian&lt;br /&gt;
* Brazilian Portuguese&lt;br /&gt;
* Chinese&lt;br /&gt;
* Danish&lt;br /&gt;
* Filipino&lt;br /&gt;
* French&lt;br /&gt;
* German&lt;br /&gt;
* Greek&lt;br /&gt;
* Hungarian&lt;br /&gt;
* Indonesian&lt;br /&gt;
* Italian&lt;br /&gt;
* Japanese&lt;br /&gt;
* Korean&lt;br /&gt;
* Persian&lt;br /&gt;
* Polish&lt;br /&gt;
* Russian&lt;br /&gt;
* Sinhala&lt;br /&gt;
* Spanish&lt;br /&gt;
* Urdu &lt;br /&gt;
&lt;br /&gt;
You can use [http://crowdin.net/project/owasp-zap Crowdin] to help improve these translations or add new ones right now!&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Roadmap =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Release 2.4.3==&lt;br /&gt;
ZAP 2.4.3 has been released, this is a bug fix and enhancement release&lt;br /&gt;
&lt;br /&gt;
For more details see https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_4_3&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Get Involved =&lt;br /&gt;
[[Image:zap128x128.png|right]]&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:120%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Involvement in the development of ZAP is actively encouraged!&lt;br /&gt;
&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
&lt;br /&gt;
Some of the ways you can help:&lt;br /&gt;
&lt;br /&gt;
==Feature Requests==&lt;br /&gt;
&lt;br /&gt;
Please raise new feature requests as enhancement requests here: https://github.com/zaproxy/zaproxy/issues&lt;br /&gt;
&lt;br /&gt;
If there are existing requests you are also interested in then please 'star' them - that way we can see which features people are most interested in and can prioritize them accordingly. &lt;br /&gt;
&lt;br /&gt;
==Feedback==&lt;br /&gt;
&lt;br /&gt;
Please use the [http://groups.google.com/group/zaproxy-users zaproxy-users Google Group] for feedback:&lt;br /&gt;
* What do like?&lt;br /&gt;
* What don't you like?&lt;br /&gt;
* What features could be made easier to use?&lt;br /&gt;
* How could the help pages be improved? &lt;br /&gt;
&lt;br /&gt;
==Log issues==&lt;br /&gt;
&lt;br /&gt;
Have you had a problem using ZAP?&lt;br /&gt;
&lt;br /&gt;
If so and its not already been logged then please [https://github.com/zaproxy/zaproxy/issues report it]&lt;br /&gt;
&lt;br /&gt;
==Localization==&lt;br /&gt;
&lt;br /&gt;
Are you fluent in another language? Can you help translate ZAP into that language?&lt;br /&gt;
&lt;br /&gt;
You can use [http://crowdin.net/project/owasp-zap Crowdin] to do that!&lt;br /&gt;
&lt;br /&gt;
==Development==&lt;br /&gt;
&lt;br /&gt;
If you fancy having a go at adding functionality to ZAP then please get in touch via the [http://groups.google.com/group/zaproxy-develop zaproxy-develop Google Group].&lt;br /&gt;
&lt;br /&gt;
Again, you do not have to be a security expert to contribute code - working on ZAP could be great way to learn more about web application security!&lt;br /&gt;
&lt;br /&gt;
If you actively contribute to ZAP then you will be invited to join the project. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Zed Attack Proxy Project]]&lt;br /&gt;
[[Category:OWASP_Tool]]&lt;br /&gt;
[[Category:OWASP_Release_Quality_Tool|OWASP Release Quality Tool]]&lt;br /&gt;
[[Category:OWASP_Download]]&lt;br /&gt;
[[Category:Popular]]&lt;br /&gt;
[[Category:SAMM-ST-2]]&lt;/div&gt;</summary>
		<author><name>Psiinon</name></author>	</entry>

	</feed>