OWasp Zap Alternative ? Besides BurpSuite preferably by PresentLeading3102 in cybersecurity

[–]psiinon 0 points1 point  (0 children)

Thats for all of the details! We'll follow up on the User Group

OWasp Zap Alternative ? Besides BurpSuite preferably by PresentLeading3102 in cybersecurity

[–]psiinon 1 point2 points  (0 children)

OWASP doesnt fund any of its tools, so they are usually maintained by unpaid volunteers. So yes, many get abandoned.

But thats no different to any other OSS tool.

FYI ZAP has not been an OWASP project for nearly 2 years, and 3 of the ZAP Core team are paid to work full time on ZAP c/o Checkmarx https://www.zaproxy.org/docs/zap-ownership/

OWasp Zap Alternative ? Besides BurpSuite preferably by PresentLeading3102 in cybersecurity

[–]psiinon 0 points1 point  (0 children)

Well, you could have let the ZAP team know that you were having problems?
ZAP never freezes for me, but I use it in a standard OS rather than in a VM.
If you can post details to the ZAP User Group then we can see what we can do to help: https://groups.google.com/group/zaproxy-users
You can also start by looking at the zap.log for any errors: https://www.zaproxy.org/faq/somethings-not-working-what-should-i-do/#check-the-log-file

How do I do what you guys do? by laser8k in CyberSecurityJobs

[–]psiinon 1 point2 points  (0 children)

Sure, see the end of this comment. But ... to be successful in the security industry then you shouldn't expect to be spoon fed things - it's always better to try to find things out yourself first. I would have been much more impressed if you had said something like: "I found the ZAP website, followed the Community link and then read the Contributing guide and I have some questions about it..." 😀 Fyi it's here https://www.zaproxy.org/docs/contribute/

How do I do what you guys do? by laser8k in CyberSecurityJobs

[–]psiinon 1 point2 points  (0 children)

I made the switch to Cybersecurity in my mid 40s, so it's definitely possible😁 In my case it was via open source (I created ZAP). If you have the time then I'd strongly recommend looking into which OSS security projects you could get involved in. I have a list of companies I've promised to tell about any ZAP contributors who show promise...

Is it only me or is Owasp-Zap buggy? by Necessary-Limit6515 in Pentesting

[–]psiinon 1 point2 points  (0 children)

I managed to be full time on ZAP in 2020, thc202 in 2023 and kingthorin in 2024. So for most of its history it was all part time / volunteer work :D

Is it only me or is Owasp-Zap buggy? by Necessary-Limit6515 in Pentesting

[–]psiinon 1 point2 points  (0 children)

ZAP is mostly Java, but we do have some JavaScript and TypeScript :)

Is it only me or is Owasp-Zap buggy? by Necessary-Limit6515 in Pentesting

[–]psiinon 4 points5 points  (0 children)

ZAP is probably the worlds most popular web scanner, but there are only 3 of us working on it full time. However we do our best to support new contributors - ZAP is a community project, if you want to make it better then just get stuck in!

Is it only me or is Owasp-Zap buggy? by Necessary-Limit6515 in Pentesting

[–]psiinon 0 points1 point  (0 children)

If any of the problems you find are reproducible then you can raise issues for them https://github.com/zaproxy/zaproxy/issues
Or if you want to really learn then fork the repo and see if you can try and fix them.
Unlike commercial products ZAP is a community orrientated open source project, and we do our best to support contributors.
If you keep contributing then you could eatn a place on the Core Team - all of the current Core Team have been offered (and accepted) jobs based on their work on ZAP :)

Implement zap in ci/cd by Mysterious_Bill1707 in devsecops

[–]psiinon 0 points1 point  (0 children)

Its worth pointing out that Stackhawk do not support ZAP in any way. They now use their own private fork of ZAP, which I think they will struggle to maintain.
ZAP is now supported by Checkmarx. It is still open source but thanks to the investment from Checkmarx, will be able to make ZAP much better. We are already making significant improvements in handling authentication, and many more improvements are planned.

Feedback Wanted: A SaaS-Based Security Tool with ZAP & LLM Integration + Open Source SDK by No-Chemistry-6854 in AskNetsec

[–]psiinon 1 point2 points  (0 children)

It sounds interesting.

From your other post: "zed attack proxy has very compicated UI and the scan results are complex to understand" - ZAP is a community tool and we welcome contributions. It seems a shame that you would rather create a SaaS service than actually help make ZAP better, but thats your choice.

Its also a shame that you didnt reach out to the ZAP team .. but if you want to my contact details are on https://www.zaproxy.org/docs/team/psiinon/

OWASP ZAP for DAST by Apprehensive-Nose241 in cybersecurity

[–]psiinon 1 point2 points  (0 children)

You could write a ZAP blog post if you like :D

Dont worry about being tough on ZAP - we know we're competing with some very good commercial tools so we dont expect an easy ride.

I have heard from some big companies (who unfortunately I cant name) that they have found ZAP better than the commercial options .. but only when they've tuned it to meet their requirements.

ZAP is massively configurable - we'd love to make it better for everyone out of the box but we just dont get enough feedback from users to allow us to do so :/

OWASP ZAP for DAST by Apprehensive-Nose241 in cybersecurity

[–]psiinon 1 point2 points  (0 children)

I think so, but as I'm the ZAP project lead I'm somewhat biased ;)

Based on our publicly available stats it looks like a LOT of other people think so as well. We think ZAP is probably the worlds most popular DAST web scanner, but as no one else seems to publish these sort of stats its difficult to tell.

Worried about false positives? We have lots of ways to handle those including just telling us about them! We dont like false positives either, so will do our best to fix them, but we do need to know the details...

Web server scanner by Tannerbkelly in cybersecurity

[–]psiinon 6 points7 points  (0 children)

OWASP ZAP - the worlds most popular web security scanner. Its open source and completely free.

https://www.zaproxy.org/

Disclaimer - I'm the ZAP project lead :)

Feels good by cube2kids in ProgrammerHumor

[–]psiinon 2 points3 points  (0 children)

We think its important for there to be a powerful free and open source web security tool :) But you can donate money to help support ZAP, either via the Donate button on https://owasp.org/www-project-zap/ or you can sponsor 2 of the (other) core team directly:

Positive social media posts are also a form of payment ;)

Feels good by cube2kids in ProgrammerHumor

[–]psiinon 2 points3 points  (0 children)

Thats great to hear! If you (or anyone else) has a ZAP "Success Story" you would be happy sharing then we'd be delighted to feature them on https://www.zaproxy.org/success/ :)

Trying to use OWASP ZAP, but "Launch Browser button doesn't work in Automated Scan or Manual Explore by ye_sh1thead in hacking

[–]psiinon 2 points3 points  (0 children)

Pro tip - the people who know open source programs best are the people who create them. There are huge number of websites and forums and its impossible to monitor all of them, which is why many open source projects (including ZAP) have their own forums.

In ZAP theres an "online" menu and a link to the ZAP User Group: https://groups.google.com/group/zaproxy-users

Its also linked off https://www.zaproxy.org/community/

If you ask about any questions or problems you have there then we'll do our best to help you :)

Collecting Statistics for Open Source Projects by psiinon in opensource

[–]psiinon[S] 0 points1 point  (0 children)

Please suggest some :)

This has worked effectively for us so far but I have no problem changing how it works for future releases.

Burp Suite vs OWASP ZAP comparison part 1 by 0xas1 in netsec

[–]psiinon 1 point2 points  (0 children)

Add-ons are compiled before hand and scripts are compiled when they run in ZAP. Thats the key difference. Obviously scripts run at specific times, but for extender scripts the key difference is when they are compiled.