ZAP Zed Attack Proxy and the OWASP Juice Shop Group 7: Lucas Breno de Souza Noronha Braga (0853061) Aarti Devi (0848815) Honey Honey (0851642) Haris Ahmed Rajput (0837455) CYB204: Computer Forensics and investigation Professor Andreas Maniatis
ZAP - Zed Attack Proxy ZAP (Zed Attack Proxy) is a powerful web application security testing tool. It allows for the interception and modification of HTTP requests, making it ideal for security demonstrations. Its ability to modify requests enables researchers to inject payloads crafted for exploiting NoSQL vulnerabilities. Being open source, ZAP benefits from a community of contributors.
OWASP What is OWASP? OWASP stands for Open Web Application Security Project. A worldwide nonprofit organization focused on improving software security. Produces freely available tools, documentation, and guides for web application security. Mission OWASP's mission is to make software security visible so that individuals and organizations can make informed decisions about true software security risks.
OWASP – TOP 10 What is the OWASP Top 10? The OWASP Top 10 is a regularly updated list of the top 10 most critical web application security risks. Designed to raise awareness about common security vulnerabilities in web applications. Why is it Important? Helps organizations prioritize their efforts in securing their web applications. Provides developers with guidance on what to focus on when building and testing applications.
OWASP Juice Shop Addresses the TOP 10 Vulnerabilities A modern web application developed by the OWASP Foundation. Designed with multiple vulnerabilities for security training and awareness. Allows for the simulation and exploration of different vulnerabilities. Users can post product reviews after authentication. Reviews can only be altered by the user who submitted them.
Conclusion Web Security Matters: Securing web applications is crucial, to deal with common risks. Know the Risks: Understanding the OWASP Top 10 gives us insight into the main threats. Learn by Doing: Through OWASP Juice Shop, we practiced finding and fixing vulnerabilities. Tools for Safety: ZAP is a strong ally, helping us scan and fix security flaws effectively.