In the last chapter, we covered another important part of penetration testing, which was about exploiting cross-site scripting vulnerabilities.
Now, in this chapter, we are going to be studying a tool called ZAP, which will help us detect the risks and vulnerabilities of web applications. We will then explore various scans that we can perform and also learn to read the scan results. We will see this through a few examples.
This chapter will cover the following web penetration testing topics:
- OWASP ZAP start
- OWASP ZAP result