O'Reilly logo

Kali Linux Web Penetration Testing Cookbook by Gilberto Nájera-Gutiérrez

Stay ahead with the world's most comprehensive technology and business learning platform.

With Safari, you learn the way you learn best. Get unlimited access to videos, live online training, learning paths, books, tutorials, and more.

Start Free Trial

No credit card required

Using OWASP ZAP to scan for vulnerabilities

OWASP ZAP is a tool that we have already used in this book for various tasks, and among its many features, it includes an automated vulnerability scanner. Its use and report generation will be covered in this recipe.

Getting ready

Before we perform a successful vulnerability scan in OWASP ZAP, we need to crawl the site:

  1. Open OWASP ZAP and configure the Web browser to use it as proxy.
  2. Navigate to 192.168.56.102/peruggia/.
  3. Follow the instructions from Using ZAP's spider from Chapter 3, Crawlers and Spiders.

How to do it...

  1. Go to OWASP ZAP's Sites panel and right-click on the peruggia folder.
  2. From the menu, navigate to Attack | Active Scan.
  3. A new window will pop up. At this point, we know what technology our application ...

With Safari, you learn the way you learn best. Get unlimited access to videos, live online training, learning paths, books, interactive tutorials, and more.

Start Free Trial

No credit card required