how to test HTTP strict transport security (hsts) in OWASP ZAP tool.

1,307 views
Skip to first unread message

Vemana

unread,
May 23, 2016, 3:23:40 PM5/23/16
to OWASP ZAP Developer Group

Hi Friends,


Could you please let me know how to test the HTTP strict transport security (hsts) through  OWASP ZAP tool ?

I did not see this Test under the passive scan rules.

Thanks in advance.
Vemana



thc...@gmail.com

unread,
May 23, 2016, 4:00:06 PM5/23/16
to zaproxy...@googlegroups.com
Hi.

The scanner "Strict-Transport-Security Header Scanner" is (currently)
included in the add-on "Passive scanner rules (alpha)" [1], available in
the marketplace. [2]

(In the current version, 8, it's shown under a different name,
"Strict-Transport-Security Header Not Set".)


[1]
https://github.com/zaproxy/zap-extensions/wiki/HelpAddonsPscanrulesAlphaPscanalpha
[2]
https://github.com/zaproxy/zap-core-help/wiki/HelpUiDialogsManageaddons#marketplace

Best regards.
> --
> You received this message because you are subscribed to the Google
> Groups "OWASP ZAP Developer Group" group.
> To unsubscribe from this group and stop receiving emails from it, send
> an email to zaproxy-devel...@googlegroups.com
> <mailto:zaproxy-devel...@googlegroups.com>.
> For more options, visit https://groups.google.com/d/optout.

Chinthamreddy Bhaskar Reddy

unread,
Jul 18, 2023, 7:44:14 AM7/18/23
to OWASP ZAP Developer Group
Hi Team ,

Can you somebody help to test HSTS using OWASP ZAP tool ? I'm using 2.12.0 version ZAP 

Thanks
Bhaskar

kingthorin+owaspzap

unread,
Jul 18, 2023, 9:21:56 PM7/18/23
to OWASP ZAP Developer Group
See previous reply
Reply all
Reply to author
Forward
0 new messages