|
|
(5 intermediate revisions by 2 users not shown) |
Line 1: |
Line 1: |
− | = Main =
| |
| <div style="width:100%;height:90px;border:0,margin:0;overflow: hidden;">[[File: flagship_big.jpg|link=]]</div> | | <div style="width:100%;height:90px;border:0,margin:0;overflow: hidden;">[[File: flagship_big.jpg|link=]]</div> |
| {| style="padding: 0;margin:0;margin-top:10px;text-align:left;" |- | | {| style="padding: 0;margin:0;margin-top:10px;text-align:left;" |- |
− | | style="border-right: 1px dotted gray;padding-right:25px;" valign="top" |<blockquote></blockquote>[[Image:zap128x128.png|right]] | + | | style="border-right: 1px dotted gray;padding-right:25px;" valign="top" | |
− | | + | {{ReviewProject|projectname=zaproxy|language=en}} |
− | == The OWASP Zed Attack Proxy (ZAP) ==
| |
| <div style="font-size:120%;border:none;margin: 0;color:#000"> | | <div style="font-size:120%;border:none;margin: 0;color:#000"> |
− | The OWASP Zed Attack Proxy (ZAP) is one of the world’s most popular free security tools and is actively maintained by hundreds of international volunteers[[#Justification|*]]. It can help you automatically find security vulnerabilities in your web applications while you are developing and testing your applications. It's also a great tool for experienced pentesters to use for manual security testing.
| + | For more details about ZAP see the new ZAP website at [https://www.zaproxy.org zaproxy.org][[Image:Zap-website.png | link=https://www.zaproxy.org/]] |
| | | |
− | <blockquote>'''ZAP 2.8.0 is now available! [[Image:ZAP-Download.png | link=https://github.com/zaproxy/zaproxy/wiki/Downloads]]'''</blockquote>
| + | {{Social Media Links}} |
− | {| | |
− | |-
| |
− | {{#ev:youtube|eH0RBI0nmww}} | |
− | {{#ev:youtube|ztfgip-UhWw}}
| |
| | | |
− | |} | + | | style="padding-left:25px;width:200px;" valign="top" | |
− | | |
− | == Getting Started == | |
− | Get started with ZAP by exploring these guides and tutorial videos.
| |
− | * [https://github.com/zaproxy/zaproxy/releases/download/v2.8.0/ZAPGettingStartedGuide-2.8.pdf Getting Started Guide (pdf)] - an introductory guide
| |
− | * [https://www.youtube.com/playlist?list=PLEBitBW-Hlsv8cEIUntAO8st2UGhmrjUB Tutorial Videos] - a collection of tutorial videos
| |
− | * [https://github.com/zaproxy/zap-core-help/wiki User Guide] - online version of the User Guide included with ZAP
| |
− | | |
− | == Features == | |
− | <gallery>
| |
− | ZAP-ScreenShotAddAlert.png
| |
− | ZAP-ScreenShotHelp.png
| |
− | ZAP-ScreenShotHistoryFilter.png
| |
− | ZAP-ScreenShotSearchTab.png
| |
− | </gallery>'''Some of ZAP's functionality:'''
| |
− | * [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsIntercept Man-in-the-middle Proxy]
| |
− | * [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsSpider Traditional] and AJAX spiders
| |
− | * [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsAscan Automated scanner]
| |
− | * [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsPscan Passive scanner]
| |
− | * [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsBruteforce Forced browsing]
| |
− | * [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsFuzz Fuzzer]
| |
− | * [https://github.com/zaproxy/zap-core-help/wiki/HelpUiDialogsOptionsDynsslcert Dynamic SSL certificates]
| |
− | * [https://github.com/zaproxy/zap-core-help/wiki/SmartCards Smartcard and Client Digital Certificates support]
| |
− | * [https://github.com/zaproxy/zap-core-help/wiki/HelpAddonsWebsocketIntroduction Web sockets] support
| |
− | * [https://github.com/zaproxy/zap-core-help/wiki/HelpAddonsScriptsScripts Support for a wide range of scripting languages]
| |
− | * [https://github.com/zaproxy/zap-core-help/wiki//HelpAddonsPlugnhackPlugnhack Plug-n-Hack support]
| |
− | * Authentication and session support
| |
− | * [https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsApi Powerful REST based API]
| |
− | * Automatic updating option
| |
− | * [https://github.com/zaproxy/zap-extensions/wiki Integrated and growing marketplace of add-ons]
| |
− | | |
− | '''Why use ZAP?'''
| |
− | * [http://www.apache.org/licenses/LICENSE-2.0 Open source]
| |
− | * Cross platform (it even runs on a [https://github.com/zaproxy/zaproxy/wiki/zappi Raspberry Pi!])
| |
− | * Easy to install (using a [https://www.ej-technologies.com/products/install4j/overview.html multi-platform installer builder])
| |
− | * Completely free (no paid for 'Pro' version)
| |
− | * Ease of use a priority
| |
− | * [https://github.com/zaproxy/zap-core-help/wiki/HelpIntro Comprehensive help pages]
| |
− | * Fully internationalized
| |
− | * Translated into over 20 languages
| |
− | * Community based, with involvement actively encouraged
| |
− | * Under active development by an international team of volunteers
| |
− | * ZAP is a fork of the well regarded [http://www.parosproxy.org/ Paros Proxy]
| |
− | | |
− | '''Supported Languages'''
| |
− | * English
| |
− | * Arabic
| |
− | * Bosnian
| |
− | * Brazilian Portuguese
| |
− | * Chinese
| |
− | * Danish
| |
− | * Filipino
| |
− | * French
| |
− | * German
| |
− | * Greek
| |
− | * Hungarian
| |
− | * Indonesian
| |
− | * Italian
| |
− | * Japanese
| |
− | * Korean
| |
− | * Persian
| |
− | * Polish
| |
− | * Russian
| |
− | * Sinhala
| |
− | * Spanish
| |
− | * Urdu
| |
− | | |
− | You can use [http://crowdin.net/project/owasp-zap Crowdin] to help improve these translations or add new ones right now!
| |
| | | |
− | == Awards & Acknowledgements == | + | == Quick Download == |
| | | |
− | ToolsWatch Annual Best Free/Open Source Security Tool Survey:
| + | [https://github.com/zaproxy/zaproxy/wiki/Downloads Download OWASP ZAP!] |
− | * 2016 [http://www.toolswatch.org/2017/02/2016-top-security-tools-as-voted-by-toolswatch-org-readers/ 2nd]
| |
− | * 2015 [http://www.toolswatch.org/2016/02/2015-top-security-tools-as-voted-by-toolswatch-org-readers/ 1st]
| |
− | * 2014 [http://www.toolswatch.org/2015/01/2014-top-security-tools-as-voted-by-toolswatch-org-readers/ 2nd]
| |
− | * 2013 [http://www.toolswatch.org/2013/12/2013-top-security-tools-as-voted-by-toolswatch-org-readers/ 1st]<div style="font-size:120%;border:none;margin: 0;color:#000">{{Social Media Links}}
| |
− | | |
− | | style="padding-left:25px;width:200px;" valign="top" |
| |
| | | |
| == Donate to ZAP == | | == Donate to ZAP == |
Line 100: |
Line 21: |
| </div> | | </div> |
| | | |
− | == Download == | + | == News and Events == |
− | [https://github.com/zaproxy/zaproxy/wiki/Downloads Packaged Distributions] | + | Please see the [https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project#News News] and [https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project#Talks Talks] tabs |
− | * [https://github.com/zaproxy/zaproxy/releases/download/v2.8.0/ZAP_2.8.0.dmg MacOS Installer]
| |
− | * [https://github.com/zaproxy/zaproxy/releases/download/v2.8.0/ZAP_2_8_0_windows.exe Windows (64) Installer]
| |
− | * [https://github.com/zaproxy/zaproxy/releases/download/v2.8.0/ZAP_2_8_0_windows-x32.exe Windows (32) Installer]
| |
− | * [https://github.com/zaproxy/zaproxy/releases/download/v2.8.0/ZAP_2.8.0_Linux.tar.gz Linux Package]
| |
− | * [https://github.com/zaproxy/zaproxy/releases/download/v2.8.0/ZAP_2.8.0_Crossplatform.zip Cross Platform]
| |
− | [https://github.com/zaproxy/zaproxy/wiki/Downloads#docker Docker Images]
| |
− | | |
− | [https://github.com/zaproxy/zaproxy/wiki/Downloads#zap-weekly Weekly Release]
| |
− | | |
− | == Source & Docs ==
| |
| | | |
− | === Source === | + | == Change Log == |
− | [https://github.com/zaproxy/zaproxy/ zaproxy] | + | * [https://github.com/zaproxy/zaproxy/commits/develop zaproxy] |
| + | * [https://github.com/zaproxy/zap-extensions/commits/master zap-extensions] |
| | | |
− | [https://github.com/zaproxy/zap-hud/ zap-hud] | + | == Code Repo == |
| + | * [https://github.com/zaproxy/zaproxy/ zaproxy] |
| + | * [https://github.com/zaproxy/zap-extensions/ zap-extensions] |
| | | |
− | [https://github.com/zaproxy/zap-extensions/ zap-extensions]
| + | == Email List == |
| | | |
− | === Docs ===
| + | Questions? Please ask on the [http://groups.google.com/group/zaproxy-users ZAP User Group] |
− | [https://github.com/zaproxy/zaproxy/wiki zaproxy]
| |
− | | |
− | [https://github.com/zaproxy/zap-hud/wiki zap-hud]
| |
− | | |
− | [https://github.com/zaproxy/zap-extensions/wiki zap-extensions]
| |
− | | |
− | === Change Log ===
| |
− | [https://github.com/zaproxy/zaproxy/commits/develop zaproxy]
| |
− | | |
− | [https://github.com/zaproxy/zap-hud/blob/develop/CHANGELOG.md zap-hud]
| |
− | | |
− | [https://github.com/zaproxy/zap-extensions/commits/master zap-extensions]
| |
− | | |
− | == Support & Collaboration ==
| |
− | [http://groups.google.com/group/zaproxy-users ZAP User Group] | |
− | | |
− | [https://owasp.slack.com/messages/project-zap/ Slack Channel]
| |
− | | |
− | [https://github.com/zaproxy/zaproxy/issues Github Issues]
| |
− | | |
− | Feedback
| |
− | | |
− | [https://docs.google.com/forms/d/e/1FAIpQLSfxnHk35RMXHLdk6cs6B_39-ZoXYXiKDY2kuXnDE6K-mF_7gQ/viewform Questionnaire]
| |
− | | |
− | Mailing List
| |
− | | |
− | [https://stackoverflow.com/questions/tagged/zap Stack Overflow]
| |
− | | |
− | [https://twitter.com/zaproxy Twitter]
| |
− | | |
− | [https://zaproxy.blogspot.com/ Blog]
| |
| | | |
| == Project Leader == | | == Project Leader == |
| | | |
− | ==== Project Leader ====
| + | Project Leader <br />[https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto: [email protected] @] |
− | [https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto: [email protected] @] | |
| | | |
− | ==== Co-Project Leaders ====
| + | Co-Project Leaders <br />[https://www.owasp.org/index.php/User:Ricardo.Pereira Ricardo Pereira] [mailto: [email protected] @] |
− | [https://www.owasp.org/index.php/User:Ricardo.Pereira Ricardo Pereira] [mailto: [email protected] @] | |
| | | |
| [https://www.owasp.org/index.php/User:Rick.mitchell Rick Mitchell] [mailto: [email protected] @] | | [https://www.owasp.org/index.php/User:Rick.mitchell Rick Mitchell] [mailto: [email protected] @] |
| | | |
− | |}
| + | == Related Projects == |
− | | |
− | = Get Involved = | |
− | Involvement in the development of ZAP is actively encouraged! You do not have to be a security expert in order to contribute. Learn about the different ways you can get involved[[Image:zap128x128.png|right]]
| |
− | | |
− | == Contribute ==
| |
− | | |
− | === Develop ===
| |
− | If you fancy having a go at adding functionality to ZAP then please get in touch via the [http://groups.google.com/group/zaproxy-develop zaproxy-develop Google Group].
| |
− | | |
− | Again, you do not have to be a security expert to contribute code - working on ZAP could be great way to learn more about web application security!
| |
− | | |
− | If you actively contribute to ZAP then you will be invited to join the project.
| |
− | | |
− | * [https://groups.google.com/group/zaproxy-develop Developer Group] - ask questions about the ZAP internals
| |
− | * [https://www.openhub.net/p/zaproxy OpenHub] - FOSS analytics
| |
− | | |
− | === Localization ===
| |
− | Are you fluent in another language? Can you help translate ZAP into that language?
| |
− | | |
− | You can use [http://crowdin.net/project/owasp-zap Crowdin] to do that!
| |
− | * [https://crowdin.com/project/owasp-zap Crowdin (GUI)] - help translate the ZAP GUI
| |
− | * [https://crowdin.com/project/owasp-zap-help Crowdin (User Guide)] - help translate the ZAP User Guide
| |
− | | |
− | === Bounty Source ===
| |
− | [https://www.bountysource.com/teams/zap/issues BountySource] - Vote on ZAP issues (you can also donate money here, but 10% taken out
| |
− | | |
− | === Bug Bounty ===
| |
− | Find us on [https://bugcrowd.com/owaspzap Bugcrowd] to starting hacking!
| |
− | | |
− | == Feedback ==
| |
| | | |
− | === Issues / Bugs ===
| + | * [https://www.owasp.org/index.php/OWASP_Web_Testing_Environment_Project OWASP WTE] |
− | Have you had a problem using ZAP?
| + | * [https://www.owasp.org/index.php/OWASP_OWTF OWASP OWTF] |
| | | |
− | If so and its not already been logged then please [https://github.com/zaproxy/zaproxy/issues report it]
| + | == Open Hub Stats == |
| | | |
− | === Feedback Forms ===
| + | *https://www.openhub.net/p/zaproxy |
− | Please use the [http://groups.google.com/group/zaproxy-users zaproxy-users Google Group] for feedback:
| |
− | * What do like?
| |
− | * What don't you like?
| |
− | * What features could be made easier to use?
| |
− | * How could the help pages be improved?
| |
| | | |
− | === Feature Requests === | + | ==Classifications== |
− | Please raise new feature requests as enhancement requests here: https://github.com/zaproxy/zaproxy/issues
| |
| | | |
− | If there are existing requests you are also interested in then please 'star' them - that way we can see which features people are most interested in and can prioritize them accordingly.
| + | {| width="200" cellpadding="2" |
| + | |- |
| + | | rowspan="2" width="50%" valign="top" align="center" | [[File:Mature projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Flagship_Projects]] |
| + | | width="50%" valign="center" align="center" | [[File:Owasp-builders-small.png|link=]] |
| + | | |
| + | |- |
| + | | width="50%" valign="center" align="center" | [[File:Owasp-breakers-small.png|link=]] |
| + | |- |
| + | | colspan="2" align="center" | [http://www.apache.org/licenses/LICENSE-2.0 Apache 2 License] |
| + | |- |
| + | | colspan="2" align="center" | [[File:Project_Type_Files_TOOL.jpg|link=]] |
| + | |} |
| | | |
− | == Roadmap == | + | |}<div style="font-size:120%;border:none;margin: 0;color:#000"> |
| | | |
− | ===(Current) Release 2.8.0===
| |
− | ZAP 2.8.0 has been released (June 2019), this is a bug fix and enhancement release
| |
− |
| |
− | For more details see https://github.com/zaproxy/zap-core-help/wiki/HelpReleases2_8_0
| |
− |
| |
− | === (Hopeful) Future Features ===
| |
− |
| |
− | === (Exciting) Possible Ideas ===
| |
− | <div style="font-size:120%;border:none;margin: 0;color:#000"></div>
| |
− | = Media, News, & Social =
| |
− | [[Image:zap128x128.png|right]]
| |
− |
| |
− | == Talks ==
| |
− |
| |
− | == Social ==
| |
− |
| |
− | == Swag ==
| |
− | All of the artwork for ZAP swag is released under the Creative Common License and can be downloaded from the [https://github.com/zaproxy/zap-swag zap-swag] repo. You can of course use the artwork from this repo with any other online store that you like.
| |
− |
| |
− | === Shirts ===
| |
− | T-shirts can be purchased from [http://www.cafepress.com/zaproxy Cafepress]
| |
− |
| |
− | [[Image:zap-tshirt-cp.PNG | link=http://www.cafepress.com/zaproxy]]
| |
− |
| |
− | === Stickers & More ===
| |
− | A range of products can be purchased from [http://www.redbubble.com/people/zaproxy Redbubble]
| |
− |
| |
− | == News ==
| |
− | <div style="font-size:120%;border:none;margin: 0;color:#000">{{:Projects/OWASP Zed Attack Proxy Project/Pages/News | News}}
| |
− |
| |
− | </div>
| |
− | = Acknowledgements =
| |
− | <div style="font-size:120%;border:none;margin: 0;color:#000">
| |
− |
| |
− | ZAP is developed by a worldwide [https://github.com/zaproxy/zap-core-help/wiki/HelpCredits team] of volunteers.
| |
− | </div>
| |
− |
| |
− | == Core Team ==
| |
− | * Simon Bennetts (@psiinon)
| |
− | * thc202
| |
− | * Rick Mitchell (Kingthorin)
| |
− | * David Scrobonia (@david_scrobonia)
| |
− | * Sherif Mansour
| |
− |
| |
− | == Contributors ==
| |
− | * [https://github.com/zaproxy/zap-core-help/wiki/HelpCredits#zap-extended-team Extended Contributors]
| |
− | * [https://github.com/zaproxy/zap-core-help/wiki/HelpCredits#zap-extended-team Translation Contributors]
| |
− | * [https://github.com/zaproxy/zap-core-help/wiki/HelpCredits#3rd-party-libraries-and-files Third Party Libraries]
| |
− |
| |
− | == Supporters ==
| |
− | <div style="font-size:120%;border:none;margin: 0;color:#000">
| |
− |
| |
− | We have been helped by many organizations, either financially or by encouraging their employees to work on ZAP. Thank you to all of these organizations for their support.
| |
− |
| |
− | * [http://www.mozilla.org Mozilla]
| |
− | * [http://www.linuxfoundation.org/ The Linux Foundation]
| |
− | * [https://segment.com/ Segment]
| |
− | * [http://www.owasp.org OWASP]
| |
− | * [http://www.sage.co.uk Sage]
| |
− | * [http://www.google.com Google]
| |
− | * [http://www.microsoft.com Microsoft]
| |
− | * [http://www.hacktics.com/ Hacktics, Ernst & Young]
| |
− | * [http://www.dinosec.com/ DinoSec]
| |
− | * [http://www.denimgroup.com Denim Group]
| |
− | * [http://www.aspectsecurity.com/ Aspect Security]
| |
− | * [http://secureideas.net SecureIdeas]
| |
− | * [http://utilisec.com UtiliSec]
| |
− | * [http://www.encription.co.uk/ encription]
| |
− | * [https://www.accenture.com/us-en/digital-index.aspx Accenture Digital]
| |
| </div> | | </div> |
| | | |
− | __NOTOC__ <headertabs></headertabs> | + | __NOTOC__ |
− | | |
| [[Category:OWASP Project|Zed Attack Proxy Project]] | | [[Category:OWASP Project|Zed Attack Proxy Project]] |
| [[Category:OWASP_Tool]] | | [[Category:OWASP_Tool]] |