Projects / OWASP Zed Attack Proxy

OWASP Zed Attack Proxy

OWASP Zed Attack Proxy (ZAP) is an easy-to-use integrated penetration testing tool for finding vulnerabilities in Web applications. It is designed to be used by people with a wide range of security experience and as such is ideal for developers and functional testers who are new to penetration testing as well as being a useful addition to an experienced pen tester's toolbox. ZAP provides automated scanners as well as a set of tools that allow you to find security vulnerabilities manually.

Tags
Licenses
Operating Systems
Implementation
Translations

RSS Last announcement

Persian support now added 03 Feb 2012

Download the latest language pack from https://code.google.com/p/zaproxy/downloads/list

Thanks to Mohsen Mostafa Jokar

RSS Recent releases

  •  18 Apr 2013 14:40

    Release Notes: Minor enhancements and lots of bugfixes.

    •  30 Jan 2013 23:55

      Release Notes: An online marketplace, new traditional and AJAX spiders, Web sockets support, and many other changes.

      •  05 Aug 2012 18:45

        Release Notes: This is a bugfix release.

        •  08 Apr 2012 19:00

          Release Notes: This release adds the following main features: syntax highlighting; fuzzdb integration; parameter analysis; an enhanced XSS scanner; a port of some of the Watcher checks; and pluggable extensions. There are many bugfixes.

          •  06 Nov 2011 21:20

            Release Notes: This is a bugfix and usability release.

            RSS Recent comments

            13 Jan 2011 20:54 xambroz Thumbs up

            Cool. With this approach it will be matching burpsuite soon :)

            Screenshot

            Project Spotlight

            GFeedLine

            A social networking client.

            Screenshot

            Project Spotlight

            STX B+ Tree

            C++ template classes implementing a B+ tree key/data container in main memory.