Simon Bennetts — OWASP ZAP: past, present, and future episode artwork

EPISODE · Apr 13, 2019 · 25 MIN

Simon Bennetts — OWASP ZAP: past, present, and future

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

How do you make a powerful security testing tool approachable to the developers who need it? ZAP project founder Simon Bennetts traces the project from his own experience of a penetration test to a community tool built for learning and automation. Speaking with Robert at CodeMash, he explains the origins of ZAP’s name, the thinking behind its browser-based Heads Up Display, and why usability matters as features multiply. They also discuss ZAP’s API, automated testing, volunteer contributions, and the difficulty of turning a long list of ideas into releases. This conversation captures the project’s direction at the time of recording and gives newcomers a clear picture of how to start using and contributing to ZAP.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Simon Bennetts:→ Simon Bennetts on LinkedIn→ ZAPMentioned in this episode:→ ZAP Heads Up Display→ ZAP API documentation→ ZAP source codeFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 ZAP’s past, present, and future with Simon Bennetts01:51 A developer’s security wake-up call04:24 How the ZAP project began07:41 The story behind the name ZAP09:44 Bringing security tools into the browser with the HUD14:38 Browser support and the HUD’s implementation15:32 How to contribute to ZAP17:20 Too many ideas and too few contributors17:56 Integrating OWASP guidance and explaining coverage19:31 Automating testing through the ZAP API21:47 Downloads and Docker adoption23:00 Planning releases with a volunteer team24:24 Where to find ZAP

Episode metadata supplied by the publisher feed · Published Apr 13, 2019

Embed this episode

How do you make a powerful security testing tool approachable to the developers who need it? ZAP project founder Simon Bennetts traces the project from his own experience of a penetration test to a community tool built for learning and automation. Speaking with Robert at CodeMash, he explains the origins of ZAP’s name, the thinking behind its browser-based Heads Up Display, and why usability matters as features multiply. They also discuss ZAP’s API, automated testing, volunteer contributions,...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Simon Bennetts — OWASP ZAP: past, present, and future

0:00 25:27

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 25 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on April 13, 2019.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!