EPISODE · Apr 13, 2019 · 25 MIN
Simon Bennetts — OWASP ZAP: past, present, and future
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
How do you make a powerful security testing tool approachable to the developers who need it? ZAP project founder Simon Bennetts traces the project from his own experience of a penetration test to a community tool built for learning and automation. Speaking with Robert at CodeMash, he explains the origins of ZAP’s name, the thinking behind its browser-based Heads Up Display, and why usability matters as features multiply. They also discuss ZAP’s API, automated testing, volunteer contributions, and the difficulty of turning a long list of ideas into releases. This conversation captures the project’s direction at the time of recording and gives newcomers a clear picture of how to start using and contributing to ZAP.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Simon Bennetts:→ Simon Bennetts on LinkedIn→ ZAPMentioned in this episode:→ ZAP Heads Up Display→ ZAP API documentation→ ZAP source codeFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 ZAP’s past, present, and future with Simon Bennetts01:51 A developer’s security wake-up call04:24 How the ZAP project began07:41 The story behind the name ZAP09:44 Bringing security tools into the browser with the HUD14:38 Browser support and the HUD’s implementation15:32 How to contribute to ZAP17:20 Too many ideas and too few contributors17:56 Integrating OWASP guidance and explaining coverage19:31 Automating testing through the ZAP API21:47 Downloads and Docker adoption23:00 Planning releases with a volunteer team24:24 Where to find ZAP
Embed this episode
What this episode covers
How do you make a powerful security testing tool approachable to the developers who need it? ZAP project founder Simon Bennetts traces the project from his own experience of a penetration test to a community tool built for learning and automation. Speaking with Robert at CodeMash, he explains the origins of ZAP’s name, the thinking behind its browser-based Heads Up Display, and why usability matters as features multiply. They also discuss ZAP’s API, automated testing, volunteer contributions,...
Ready to play
Simon Bennetts — OWASP ZAP: past, present, and future
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.