Adam,
I'm going to have to disagree with you on that :)
I think its a bit like me saying - "ZAP is easy to download and install, why should distributions like Kali include it?"
According to the stats on
https://api.github.com/repos/zaproxy/zap-extensions/releases FuzzDb is one of the most downloaded ZAP add-ons :)
Why do people download it from there?
I dont really know, but I suspect that convenience and the fact its integrated with ZAP make a big difference.
Do you provide instructions on how to use fuzzdb within ZAP? I couldnt see any, and we dont provide any clear documentation either.
You're also probably looking at this from a pentesters point of view, and assuming everyone will have heard of fuzzdb.
A significant proportion of ZAP users will be developers and QA, as well as people just getting started in security.
They may well not know about fuzzdb.
You might prefer people to use your repo, but I think that if you dont accept that people will want to consume your project in different ways then you'll be doing some of your users a disservice.
Ailton - I'm at fault for not keeping up with the fuzzdb releases, as I originally put together the addon.
I'd be delighted for someone to update it to the latest code, and even more if someone would keep maintaining it :)
So please, go for it - pull requests much appreciated!
BTW, looks like Adam M's official repo is
https://github.com/fuzzdb-project/fuzzdb not sure how
https://github.com/adamdecaf/fuzzdb differs from it.
Cheers,
Simon