--- title: "Simon Bennetts — OWASP ZAP: past, present, and future" url: https://appsecpodcast.com/simon-bennetts-owasp-zap-past-present-and-future/ date: 2019-04-13 duration_seconds: 1527 guests: ["Simon Bennetts"] topics: ["OWASP Top 10", "OWASP Projects", "Security Testing"] audio: https://www.buzzsprout.com/1730684/episodes/8122650-simon-bennetts-owasp-zap-past-present-and-future.mp3 transcript: true --- # Simon Bennetts — OWASP ZAP: past, present, and future *April 13, 2019 · 25 min* with [Simon Bennetts](https://appsecpodcast.com/guests/simon-bennetts/) on [OWASP Top 10](https://appsecpodcast.com/topics/owasp-top-10/), [OWASP Projects](https://appsecpodcast.com/topics/owasp-projects/), [Security Testing](https://appsecpodcast.com/topics/security-testing/) [Audio](https://www.buzzsprout.com/1730684/episodes/8122650-simon-bennetts-owasp-zap-past-present-and-future.mp3) ## Show notes How do you make a powerful security testing tool approachable to the developers who need it? ZAP project founder Simon Bennetts traces the project from his own experience of a penetration test to a community tool built for learning and automation. Speaking with Robert at CodeMash, he explains the origins of ZAP’s name, the thinking behind its browser-based Heads Up Display, and why usability matters as features multiply. They also discuss ZAP’s API, automated testing, volunteer contributions, and the difficulty of turning a long list of ideas into releases. This conversation captures the project’s direction at the time of recording and gives newcomers a clear picture of how to start using and contributing to ZAP. The Application Security Podcast is brought to you by [Security Journey](https://www.securityjourney.com/). About Security Journey Security Journey provides application security education for developers and everyone in the software development lifecycle. → [Learn more about Security Journey](https://www.securityjourney.com/) Connect with Simon Bennetts: → [Simon Bennetts on LinkedIn](https://www.linkedin.com/in/psiinon/) → [ZAP](https://www.zaproxy.org/) Mentioned in this episode: → [ZAP Heads Up Display](https://www.zaproxy.org/docs/desktop/addons/hud/) → [ZAP API documentation](https://www.zaproxy.org/docs/api/) → [ZAP source code](https://github.com/zaproxy/zaproxy) Chapters: 00:00 ZAP’s past, present, and future with Simon Bennetts 01:51 A developer’s security wake-up call 04:24 How the ZAP project began 07:41 The story behind the name ZAP 09:44 Bringing security tools into the browser with the HUD 14:38 Browser support and the HUD’s implementation 15:32 How to contribute to ZAP 17:20 Too many ideas and too few contributors 17:56 Integrating OWASP guidance and explaining coverage 19:31 Automating testing through the ZAP API 21:47 Downloads and Docker adoption 23:00 Planning releases with a volunteer team 24:24 Where to find ZAP ## Transcript *4,839 words · assemblyai* **0:00 Chris Romeo:** Good afternoon, good morning, good evening, wherever you find yourself on this fine planet. This is Chris Romeo, co-host of the AppSec Podcast and CEO of Security Journey. On this episode, Robert is back at CodeMash and he interviews Simon Bennetts, who is the project lead for the OWASP ZAP project. If you've never heard of ZAP, you really gotta listen in for this one. In this interview, Robert asks Simon about the origins of ZAP, as well as the new heads-up display and using ZAP as an API. We hope you enjoy. This episode of the Application Security Podcast is brought to you by Security Journey. Security Journey has a new weekly publication called High Five, 5 security articles that are worth your time. We scour the internet looking for the best articles on application and product security. We add in just a touch of sarcasm and snark in our descriptions. Just what security people and developers love. To sign up, visit www.securityjourney.com/highfive. That's slash hi the number five. **1:21 Robert Hurlbut:** The Application Security Podcast. Here we Today I am speaking with Simon Bennetts. Simon, welcome. **1:49 Simon Bennetts:** Hi, thank you very much, Robert. **1:51 Robert Hurlbut:** And so, Simon, one of the things that we do as we get started is we ask, you know, what's your origin story? So tell us, how did you get into security? Sure. **2:02 Simon Bennetts:** So I was a developer. I led a small Java development team, and we were developing a service that was critical to the company. It was something— was an online service, a check for update service for company which had a lot of financial desktop software and they had no way of updating their desktops apart from people getting the CDs or downloading them. So we wanted to create a service to solve that and push the software out or be able to— so users could download the software. Obviously, this would be a great way to push malware to all of the customers, which would be a really bad thing. So we considered— you know, we thought we'd consider security about— with this service. But I insisted they had a penetration test done on the software. And we got an external company to come in and the company came, the 2 guys came in, we put them in a room. Um, and I, I was very clear that I saw them, they were on our side, so I told them everything I could about the service, you know, just to make sure that, you know, they had everything to go on. And I left them alone for an hour, came back in and found that one of them was logged in as, as me, as superuser. **3:09 Robert Hurlbut:** Uh-huh. **3:09 Simon Bennetts:** And they shouldn't have been able to. In this particular case, that wasn't a bug in— a vulnerability in my code, they just hacked the single sign-on system for the whole company. That kind of was a wake-up call to me and particularly when they found other vulnerabilities. And, you know, I heard of things like cross-site scripting and SQL injection even though I'd never been taught any of these things. But cross-site request forgery, I'd never heard of and I couldn't said, well, it's okay. This, you know, the admin panel you found this problem with is behind the firewall. It's safe. And the guy just looked at me and went, no, no. I can show you how we can attack it from outside the company. It was at that point I realized I needed to learn more about security. And at that point it wasn't about changing my job. It was very much, you know, I developed software that was high performance and resilient and usable, and I saw security as just one of the aspects of the services I wanted to deliver, and I still do. You know, that's just— security isn't all-important. If the software doesn't do what it's supposed to do, it's useless and no one will use it. So, you know, there's so many aspects to software, which is why it's so interesting and challenging to work on. But security was something I realized I didn't know enough about. I needed to learn more. So that's where I got started. **4:24 Robert Hurlbut:** Okay, great, great. And Simon, you're known also as a project lead for OWASP, project lead for the ZAP Project, which is a fantastic tool for testing web applications. So tell us about that. How did that get started? **4:40 Simon Bennetts:** Right. So when I wanted to learn about security, one of the pen testers was— did quite a lot in OWASP, a guy called Yanis. And so he pointed me to OWASP. I had a look at the top 10 and started going through that and learning it. But when it comes down to it, I'm a techie. I'm a developer. I like playing with things. So I wanted some tools to play with. And I thought even then it would be— wouldn't it be a good idea to actually have something which would automatically test my software for the most common security vulnerabilities? So I looked around and there were various tools. There was an old project called WebScarab which I just didn't get on with particularly. But there was a tool called Paros which I liked. It was nice and simple. And I played around with it and it was fun, you know, so I started learning about things. And— but there were some little things about it that annoyed me. I remember there was an option to resend a request. I can't remember which way around it was, but it was on the— either on the history and not on the sites or the other way around. But I'm a Java developer. Paros was written in Java, so I pulled it into Eclipse, compiled it, changed it, got it working. And I still remember that feeling, you know, when I got that first change working. I thought, This is cool. Maybe I could do something more with this. So I started playing around with that and trying to work out how it worked and how I could make it better for me. But I also started talking to— giving talks at the company I was working at to developers and QA people, just talking about the OWASP Top 10, you know, explain these because no one else knew about them either. And in the end, you know, the first question that people would ask is, what tools do we use? So I decided, okay, I'll look at this properly. I started investigating the tools and I wanted something that we could give to all of our developers and there are hundreds of developers and I didn't feel at the time that I'd have been able to go to management and say, we've got to spend, you know, 100 quid or whatever per developer. I didn't— you know, these days it's much easier to justify those things but at the time, I didn't see it as a chance. I wanted it to be open source and cross-platform and ideally, you know, it didn't have to be too complicated, didn't have to do everything, but, you know, being supported would be nice. But I couldn't find anything out there that kind of fit the bill. In fact, the closest thing was Paros. Or actually, when I thought about it, the closest thing was a version of Paros I was hacking around with on my computer. So I decided, okay, I'll release it. I decided to call it ZAP and released it. And then— **7:07 Robert Hurlbut:** so I— **7:07 Simon Bennetts:** What was the first thing you did? asked if OWASP, you know, if OWASP wanted to adopt it. And I assumed the answer would be no because it already had WebScarab. I didn't hear back for quite a while, but then it did get accepted. And I try and track everything to do with ZAP, and I saw a leap in downloads. I think 400 downloads in one day, which is quite incredible at the time. And yeah, it took off from there really. **7:31 Robert Hurlbut:** And what time was that? What circa year? **7:34 Simon Bennetts:** So I think I started playing around with security in 2009. And it's 2010 when I released ZAP! **7:41 Robert Hurlbut:** Okay, very good. And so tell me about— you mentioned this in the talk yesterday— the origin of the name ZAP! I'm curious about that. **7:50 Simon Bennetts:** Yeah, so I hate coming up with names. It's really difficult naming things. I knew I wanted something different from Paros because I wanted to be a change. I knew Paros had been taken closed source by the people, and I didn't want to be restricted by that. I wanted it to something different. And I always wanted it to be a community project. That was really important to me. I actually was looking for a community project to get involved in and couldn't find one, so I tried to create one that I wanted to be involved in. But I've always written tools and I've always written scripts to do things as a developer. And if I wrote a script that I knew I was going to reuse, I'd call it something sensible because I always had a big library of scripts. But I often write one-off scripts where you just want to do something and you forget about it, you never use it again. And I always called those scripts either Zap or Pow. I think very much of, you know, the cartoon type thing, Zap, Pow, get it done, do it, that's it. And those 2 names kept on coming up when I was trying to think of something. And I like the idea of zapping a website. It sounded appropriate. And I did a quick search and I was surprised to see there's no other main products called Zap anywhere. **8:58 Chris Romeo:** Okay. **8:59 Simon Bennetts:** And I wanted it to be in capitals. I did avoid putting an exclamation mark on, which is probably just as well. But the best way for it to be capitals is if it stood for something. So it's a backronym. The P for proxy seemed fairly obvious. Didn't take me too long to think of A for attack. The Z was a problem. I couldn't think of anything suitable the Z could stand for. And I thought, well, it doesn't have to stand for anything. It could just be Zed. But then I realized that Americans, I'm afraid, would pronounce it Zee. And to my English ears, Zee Attack Proxy just wasn't right. So I decided it would stand for Zed, Z-E-D. So that's what it stands for. **9:36 Robert Hurlbut:** Perfect, perfect. And I like the backronym. Come up with the ZAP first and then figure out how to fill it in. **9:44 Simon Bennetts:** Absolutely. **9:44 Robert Hurlbut:** Fantastic. So tell me about, you know, what's the latest with the project today? **9:49 Simon Bennetts:** Okay, so the one thing I was giving my talk on CodeMash, and is something called the ZAP Heads Up Display or HUD. And the reason we've— so this is actually a new user interface for ZAP. And there's a couple of reasons we've been working on this. When I started ZAP, I actually said that ZAP was a— I marketed it as the tool, the security tool for developers. And there's various reasons for that. One, I was a developer and it was something I was using to learn about security and I didn't have the cheek to actually say it was for security people. It was only after I started talking at conferences and security people came up to me and said, look, we use it too. So I kind of dropped that tagline for a while. But I still wanted ZAP to be ideal for people new to security. That was very important to me. The fact that we get professional pen testers using it is great and there are lots of features that they use and I use as well, advanced features. So we're trying to appeal to everyone. **10:47 Robert Hurlbut:** Okay. **10:48 Simon Bennetts:** But I still want ZAP to be ideal for people new to web security, whether you want to get into security or whether you've got development background, you want to learn more about security or QA, whatever. But when it comes down to it, the user interface has gotten more and more complicated over the years. We've tried to hide things, so a whole load of tabs will be hidden. So the WebSocket tab will be hidden until a WebSocket message is— **11:13 Robert Hurlbut:** Okay. **11:14 Simon Bennetts:** It gets proxied through ZAP and then it will appear. The Spider tab, the Active Scan tab, they will disappear until they're needed. And we hide lots of things behind right-click options. If you don't— if you're new to the ZAP desktop UI, then right-click everywhere. Everywhere has got context-sensitive help. But it still means the interface is very complicated. So, we wanted to address that. So, But also, I'm— I've got this worry that sometimes security professionals focus on their security tool too much and they don't spend enough time actually in the application. And I think that's important because some of the most interesting application vulnerabilities are when you abuse the application functionality, when you get under the skin of the application, really understand it and work out how to do bad things with it. And some of those things tools will never help you with. You need that human brain to work these things out. So I was worried that people were spending too much time either in ZAP or in other security tools and not enough time in the application itself and seeing what they can do with it. So what we did, we talked about this in the team and we decided to come up with this thing which is the heads-up display. And, you know, for something like a fighter pilot, the heads-up display is taking all the essential controls and projecting them on the the screen of the fighter plane so they can just see— so they can focus on their environment but see this information and react to it as needed. And when you're dealing with a web application, the— your field of view is the browser. So, but take— basically taking information from ZAP and then making it available in the browser. So what the HUD is, basically we inject the HUD into the browser. And so you don't need any browser add-ons and the idea will be on by default within ZAP, but you will be able to turn it off if you don't want it. And we basically add information around the left-hand side, the right-hand side, and the bottom. And that gives you information about types of vulnerabilities ZAP has found, when it's making requests, you'll see counts go up, you can see where there are hidden fields. And you can also interact with the application via the HUD as well, interact with the application and ZAP itself. So you can actually make hidden fields visible and make fields that you can't change, make them changeable. You can see details of the vulnerabilities, you can kick off the spider, the active scan, you can see the history, you can see the sites, you can see the requests and responses. So loads of things. Not everything that ZAP can do, but it's a good But it just— you can do— hopefully you'll be able to do the essential stuff. And the idea is if you're new to security, a developer or QA person, you can start— you can have the HUD enabled, just do your normal testing on the application and see information. You can see what's going on. If you're a security professional, you can also then focus on the application, you get information about what the application is doing. And if you want to do things like intercept things, you can do that in HUD without switching between your tools. Um, so I think it's a— it's not something that security professionals use all the time, but I think it can be very effective. And we're hoping it will— could become the main interface that a lot of people use for ZAP. But it is early days. Um, so, you know, we're still working on it, but it is actually available in the weekly releases. **14:38 Robert Hurlbut:** Okay, very good. And so, um, if I remember correctly, you're using JavaScript to inject something into the session. And what browsers would you use to support? **14:51 Simon Bennetts:** So we support all modern browsers, but in reality, that is Firefox and Chrome. We haven't— I don't know. We haven't deliberately gone out of our way to use HTML5 technologies, but then we have. We've tried to use what's appropriate and we haven't been— you know, we're not supporting IE6 or anything like that. So we want to use the most appropriate modern technologies, and it turns out loads of HTML5 things are. So we're using loads of HTML— you know, the latest technology we're using. So yeah, any modern browser that is called Firefox or Chrome at this stage. **15:24 Robert Hurlbut:** Okay. And you said it's in weekly releases? **15:26 Simon Bennetts:** Yeah. **15:26 Robert Hurlbut:** And again, free? So it's available to download and take a look at and start playing with it? **15:31 Chris Romeo:** Yeah. **15:32 Robert Hurlbut:** Okay, great. And in terms of— I mean, you run the project. You obviously have other people that are helping as well. And so if somebody wanted to, any of our listeners, if anyone would like to give feedback or even just maybe help with the project, what would they do? **15:46 Simon Bennetts:** Well, yeah, that's a great question. So when I set up ZAP, I deliberately said it was a community project. And that's been a big focus for all of us. We want people to get involved. We want ZAP to be the project you can get involved in if you want to. And there's loads of things to do. Not just coding, but there's documentation, testing, testing, evangelizing, translating. ZAP is one of the few security tools that's translated— completely internationalized and translated into like 30-odd languages. **16:15 Robert Hurlbut:** Wow. **16:16 Simon Bennetts:** So there's loads of things you can do. And I think actually in the ZAP desktop UI, under the online option, there's links to both the user and developer group. So just ping us on the developer group is an ideal place. You can search for it as well. That's linked off the GitHub repo. I'm on Twitter as well, psinon, P-S-I-N-O-N. You should be able to get in touch. You know, if you can't get in touch, then you're really not trying hard enough. We're always very keen to hear about— from people. And actually, one set of people we're very keen on hearing from is students. We've had lots of students work on ZAP as part of projects at university. Some of them work through Google Summer of Code. Mozilla Winter of Security, um, OWASP had some similar events. But also students have just contacted me directly and say, you know, I'm working on a security project, can I contribute to ZAP, or can we contribute to ZAP? I'm always delighted to hear from people. We've always got a huge amount of things we want to do and can't, can't do, so there's always loads to do. **17:20 Robert Hurlbut:** Is that— I was just thinking about for a moment the challenges probably in a project like Yeah. With the scale and so forth. I mean, that's one of them. I'm assuming it's just all the things you want to do, but trying to find the people to help you get it done. Are there some other challenges that you've found over the years? **17:35 Simon Bennetts:** I, I think the biggest problem is I've got too many ideas and not enough people. So, you know, I used to say, used to say that I could keep a team of 6 people busy full-time. One of our biggest competitors, Burp, has got 30 people full-time now. you know, we can't compete with that. So, but, you know, there's always way too much to do. **17:56 Robert Hurlbut:** Sure, sure. And then let's see if anybody— oh, one other question I had was OWASP, other things in OWASP like the Top 10 and so forth. How do you— whenever those kinds of things come out, new things come out like that, how do you build those in in terms of testing and so on? **18:12 Simon Bennetts:** Yeah, that's tricky. I mean, I think generally within OWASP, we're quite quite good at focusing on our own projects and not so good at talking between the projects. **18:22 Robert Hurlbut:** Um-hum. **18:23 Simon Bennetts:** So we have chatted with various other projects, but we don't have as good integration as we'd like. I think something like the testing guide, we'd love to have better integration with the testing guide. We've had a couple of— we've had that down as a Google Summer of Code project for the last couple of years, but I don't think anyone's taken it on. So, yeah. trying to work out what to focus on is very difficult. And something like the OWASP Top 10, I think I wrote a— there's a page on the OWASP wiki explaining why ZAP doesn't find everything in the OWASP Top 10 and why actually no security tools do. **18:59 Robert Hurlbut:** Right. **19:00 Simon Bennetts:** So if you see a commercial— **19:01 Robert Hurlbut:** Especially not the last one. **19:01 Simon Bennetts:** Yeah. If you see a security tool saying we find everything in the OWASP Top 10, they're lying. **19:06 Chris Romeo:** Right. **19:07 Simon Bennetts:** You know, so Um, we want to be completely honest about things and explain what we can do and what we can't do. And, you know, ZAP is not the silver bullet. There are no silver bullets here. So we want to make sure people understand how you can use ZAP effectively, what it will do for you, and what it won't do for you. You know, if you're a developer, it'll help you find security vulnerabilities. It is not a replacement for a professional penetration test. **19:31 Robert Hurlbut:** Right. Okay, good. And, you know, I've used it over the years, uh, from the UI. I really enjoy it. But one of the other features that I know it has is an API. I've seen it used by Gauntlet, Robot Framework, and a few others that are using the API. Tell us about the API usage and how easy it is to get started. **19:51 Simon Bennetts:** Yeah. So, I mean, I think I mentioned before, one of the reasons I started ZAP was to actually make— do automated testing on my own applications. So that was always a big thing. And quite a few years ago, we we added the API. And that was a big focus for us. And we've got to the stage now where virtually everything you can do from the desktop UI, you can do with the API. And what we have is we have a very simple user interface on top of the API, an HTML one, so you can actually explore the API and you can invoke it. And you can actually see what happens. You can see the results. And it's a generated API, so you can get back results in XML or JSON or HTML. And we have various— you can just use straightforward HTTP, HTTPS requests or we've got some client libraries as well. So we've got the Java one. I actually think the Python one is probably the best supported and I use that at work quite a lot. But you don't have to use any client libraries if you don't want to. So the ZAP API is very comprehensive and one of the— So, One of the reasons that we've been pushing it so hard in the last few years is because we've been working on the HUD and the HUD uses the ZAP API. So the whole idea was you can build a completely new interface to ZAP, whether it's an automated one or a visual one, and that's what we're using for the HUD. And so the few things that you can't do via the API, I think fuzzing is one of the main ones. **21:15 Robert Hurlbut:** Okay. **21:15 Simon Bennetts:** You know, we're going to add the API to that because we want to use it from the HUD. But I You know, I've been told— you know, I don't keep a very careful track on commercial projects, but I've been told that our API is more effective than nearly all the commercial projects out there, security tools. So, and if there's something that people want to do via the API and can't yet, then let us know and we'll try and prioritize it. **21:38 Robert Hurlbut:** Okay, great. And I know you said early on about 400 downloads. Where are you now? **21:42 Simon Bennetts:** So I think direct downloads, we're averaging about 2,000 a day. **21:47 Robert Hurlbut:** Wow. **21:47 Simon Bennetts:** The latest version, which is about a year old, 2.7.0, has had 600,000 direct downloads. We know a lot of people use it via other things like Kali. We also have Docker images, and the— so we've got lots of different Docker images, but the stable one, which is still on 2.7.0, has had over a million downloads. We have weekly downloads We also have live downloads. So if somebody makes a change, then the build will kick off and an hour later we'll have a new version. We've had cases of people coming onto IRC and chatting to us. So we use IRC quite a lot. And, you know, it's used in Mozilla but we use it for ZAP as well. And details on the repo if you want to get in touch with us. But people get in touch and saying, we've had this particular problem. We've looked at it, we found out we can fix it quite quickly. We've done the fix, and within 2 hours they've had the fix available and been able to use the Docker image. We don't promise that for all bugs, but, you know, where possible we can, we'll try and fix things quickly and you'll have the fix available within, you know, an hour after that. **22:56 Robert Hurlbut:** Great. And then 2.8, you said, I believe, is coming out soon. **23:00 Simon Bennetts:** Yeah. So it's really difficult to plan plan exactly when things will come out when you're dealing with volunteers. And, you know, we're all doing it in— you know, we're all volunteers, a lot of people doing it in their spare time. I would have loved to get 2.8.0 out before Christmas. Didn't happen. We're aiming for end of January, but I've been promised— you know, I promise releases and then we, we never hit them. **23:24 Robert Hurlbut:** No. **23:24 Simon Bennetts:** So we're trying to get it done as soon as possible. One of the big things we're doing with ZAP is for historic reasons we've got a couple of different repos. One of them is the ZAP extensions repo and we have different branches. We have the master branch, we've got the beta branch and the alpha branch. We've got different code on all 3 which is confusing. So trying to merge that and then we'll actually be able to promote a whole load of add-ons and rules because we have alpha, beta and release quality add-ons and rules, scan rules. Both passive and active scan rules. So we want to get that work done and promote some of those. We want to make the HUD a bit more stable and a few more little features. So there's quite a lot we want to do, but there's still, you know, it shouldn't be too long. **24:13 Robert Hurlbut:** Okay. **24:13 Simon Bennetts:** But if people want to jump in, I mean, something like the HUD is something you can jump in and get, you know, still quite a small code base. And if you know JavaScript, then you're probably more one up on someone like me. **24:24 Robert Hurlbut:** OK. Well, I definitely want to recommend everyone take a look at it if you haven't already. Any of our listeners, if they're interested, it's available for free. It's on GitHub as well as— is there a project site as well? **24:36 Simon Bennetts:** Yeah. So there's a page on the OWASP Wiki, but most of the links are on the GitHub site now. We are planning a proper website, but not enough time. There's so much to do. **24:48 Robert Hurlbut:** I understand. I understand. Well, Simon, thank you very much for joining us and telling us about ZAP. It's really interesting to hear the history and everything that's going on and certainly look forward to looking at the latest things and continue with it. **25:02 Simon Bennetts:** Thank you very much, Robert. Thanks for listening to the Application Security Podcast. If you enjoy the podcast, please do us a favor and visit the iTunes Store and give us a 5-star rating. Our intro music is 8-Bit Kung Fu by Born and TJ, and the outro is Southern Delight by Stefan Cartenberg. You can find us on Twitter @AppSecPodcast or on the web at www.appsecpodcast.org. --- Source: https://appsecpodcast.com/simon-bennetts-owasp-zap-past-present-and-future/