How to login and scan with ZAP, integrated into Jenkins pipeline - using zap docker?

57 views
Skip to first unread message

truclb

unread,
Jul 21, 2024, 11:51:57 PM7/21/24
to ZAP User Group
I have a web application, and I want to integrate OWASP ZAP (Zed Attack Proxy) into the CI/CD Jenkins pipeline for automated security testing after deploying it to production. However, I find it challenging to handle authentication if I want to scan all URL links. I wonder if it is possible to do this. Has anyone tried doing it before?

truclb

unread,
Jul 22, 2024, 4:08:11 AM7/22/24
to ZAP User Group
 Actually, it's possible—I used ZAP for DAST in DevSecOps. It mimics human behavior to try to exploit vulnerabilities and then generates a report. ZAP is an amazing tool. I followed this video to solve my problem. 
Vào lúc 10:51:57 UTC+7 ngày Thứ Hai, 22 tháng 7, 2024, truclb đã viết:

Simon Bennetts

unread,
Jul 25, 2024, 7:44:19 AM7/25/24
to ZAP User Group
FYI there are now more options available for authentication.

Oh, and ZAP is no longer part of OWASP :)

Cheers,

Simon
Reply all
Reply to author
Forward
0 new messages