Monday, 10 April 2023

How to using tool OWASP ZAP to test security

  1. Install and open OWASP (you have to install java before OWASP)
  2. Click Manual Explore | Manual Explore
  3. Setup Protected Mode | Protected Mode
  4. Put URL to explore
  5. Select browser Chrome
  6. Click Launch Browser
    Note: (if there are errors in launch browser then change config brower version in OWASP equal version your Chrom browser)
  7. Input account and login
  8. Select screen need to run
  9. Let OWASP scan your app
  10. Right click domain run
  11. Click Include in Context 
  12. Click on New Context
  13. Click link *
  14. Click OK

    → After include context
  15. Click menu File > Session Properties
  16. Select Authentication
  17. Select [Form-based Authentication]
  18. Click Select
  19. Click domain
  20. Select「POST.login」
  21. Click button Select

    → will show data like below
  22. Update: email={%username%}&password={%password%}
    Username Parameter * is username và Password Parameter * is password
  23. Click Users
  24. Click button Add
  25. Input account cần run
  26. Click Add

    → will show data like below
  27. Click Forced User
  28. Select User created
  29. Click Ok

    → here use is disable
  30. Click to Enable user
  31. Select Active Scan
  32. Select context
  33. Select user

    Select Threshold of SQL Injection to default to scan

click Start Scan

  1. Start Scan
  2. Click Active Scan to see scan process
  3. Click Alert too see erros  
    Red: High
    Dark yellow: Medium
    Light yellow: Low

  1. Click on error to see

    Note: you can off error you dont want

    Click icon to off

No comments:

Post a Comment

Golang Advanced Interview Q&A