We will be using the vulnerable website Hackazon to demonstrate automation security testing techniques: http://hackazon.webscantest.com/. We will be using three cases to explore the testing scenario and automation techniques, which are listed in the following table:
Case scenario | Security testing objective | Security automation techniques |
Case 1—web security testing using the ZAP REST API | General web security assessments |
|
Case 2—full automation with CURL and the ZAP daemon |
|
— |
Case 3—automated security testing for the user registration flow | Security assessments for the user registration flow |
|