Monday 17 August 2015

Securing Web @ZAP Day-2

On the second day of workshop we had installed the ZAP software and taught them  about the User Interface of ZAP software. After Installing ZAP  we have taken a session about generating a Dynamic SSL certificate and installing on Firefox browser. This SSL certificate is installed on browser for testing the websites using the browser plugin tool as a manual testing of vulnerabilities.

Later I explained them about the modes of ZAP tool which are used for finding out the vulnerabilities i.e Safe mode, Protected Mode, Standard Mode and Attack Mode.

                                   IMG_20150620_102422

I explained them with a demo on using the ZAP in standard mode and attacking on a test site and showed them the vulnerabilities like XSS Cross Site scripting and other vulnerabilities.
I have also explained about many features of  ZAP tool like Intercepting, Fizzing, Spiders and scanners.

                                 image-78d178c7f4db44c5bbd2a6ab7e734a2e1c1ba08ca6186f20d512f9f9c9b6fc97-V

 In day two we covered many important concepts like :

  • UI
  • Intercepting
  • Fuzzing concepts
  • Proxy concepts
  • Testing web application
Finally the workshop was ended with a Worksheet which add many questions related to network security and vulnerabilities.

No comments:

Post a Comment