This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Difference between revisions of "Projects/OWASP Zed Attack Proxy Project/Pages/Talks"

From OWASP
Jump to: navigation, search
Line 2: Line 2:
  
  
'''2014 October 9: Columbus, OH: [http://www.meetup.com/Columbus-OWASP/events/194244112/ OWASP Code Jam]'''
+
'''2014 October 16: Skills Matter eXchange, London: [https://skillsmatter.com/conferences/1912-london-tester-gathering-workshops-2014#program Bill Matthews: Security Testing with OWASP ZAP: from zero to hero]'''
  
The central Ohio OWASP chapter is going to be squashing some ZAP bugs :)
+
More and more Security Testing is becoming part of the tester’s role and so we need to equip ourselves with the knowledge and tools to take on this challenge.
 +
 
 +
A good tool for beginners and experienced security testers is the OWASP ZAP tool (voted best security tool 2013 by toolswatch.org) so in this session we will be using the OWASP ZAP tool to conduct a security test against a deliberately vulnerable web application through a series of guided exercises that will take you from knowing little or nothing about ZAP or security testing and give you a grounding in using ZAP for Security Testing that is beyond the majority of other ZAP users.
  
  

Revision as of 09:12, 10 October 2014

Upcoming Talks/Training:


2014 October 16: Skills Matter eXchange, London: Bill Matthews: Security Testing with OWASP ZAP: from zero to hero

More and more Security Testing is becoming part of the tester’s role and so we need to equip ourselves with the knowledge and tools to take on this challenge.

A good tool for beginners and experienced security testers is the OWASP ZAP tool (voted best security tool 2013 by toolswatch.org) so in this session we will be using the OWASP ZAP tool to conduct a security test against a deliberately vulnerable web application through a series of guided exercises that will take you from knowing little or nothing about ZAP or security testing and give you a grounding in using ZAP for Security Testing that is beyond the majority of other ZAP users.


2014 October 16-17: Black Hat Arsenal, Amsterdam: Zakaria Rachid: OWASP ZAP

The Zed Attack Proxy (ZAP) is currently the most active open source web application security tool and competes effectively with commercial tools.

While it is an ideal tool for people new to appsec, it also has many features specifically intended for advanced penetration testing.

Zack will give a quick introduction to ZAP and then dive into the more advanced features, presenting some useful scripts as well as giving an overview of where its heading.