--- title: "Simon Bennetts -- Using OWASP Zap across an Enterprise" url: https://appsecpodcast.com/simon-bennetts-using-owasp-zap-across-an-enterprise/ date: 2021-11-10 duration_seconds: 2400 guests: ["Simon Bennetts"] topics: ["OWASP Top 10", "OWASP Projects", "Security Testing", "DevSecOps and CI/CD"] audio: https://www.buzzsprout.com/1730684/episodes/9525963-simon-bennetts-using-owasp-zap-across-an-enterprise.mp3 video: https://www.youtube.com/watch?v=mCMlLog5Rbs transcript: true --- # Simon Bennetts -- Using OWASP Zap across an Enterprise *November 10, 2021 · 40 min* with [Simon Bennetts](https://appsecpodcast.com/guests/simon-bennetts/) on [OWASP Top 10](https://appsecpodcast.com/topics/owasp-top-10/), [OWASP Projects](https://appsecpodcast.com/topics/owasp-projects/), [Security Testing](https://appsecpodcast.com/topics/security-testing/), [DevSecOps and CI/CD](https://appsecpodcast.com/topics/devsecops/) [Audio](https://www.buzzsprout.com/1730684/episodes/9525963-simon-bennetts-using-owasp-zap-across-an-enterprise.mp3) · [Video](https://www.youtube.com/watch?v=mCMlLog5Rbs) ## Show notes Simon Bennetts is the OWASP Zed Attack Proxy (ZAP) Project Leader and a Distinguished Engineer at StackHawk, a company that uses ZAP to help users fix application security bugs before they hit production. He has talked about and demonstrated ZAP at conferences all over the world. Prior to making a move into security, he was a developer for 25 years and strongly believes that you cannot build secure web applications without knowing how to attack them. He's talked about and demonstrated ZAP at conferences all over the world. Prior to making the move into security, he was a developer for 25 years and strongly believes that you cannot build secure web applications without knowing how to attack them. The Application Security Podcast is brought to you by [Security Journey](https://www.securityjourney.com/). About Security Journey Simon Bennetts is the OWASP Zed Attack Proxy, or ZAP, project leader and a distinguished engineer at StackHawk, a company that uses ZAP to help users fix application security bugs before they hit production. → [Learn more about Security Journey](https://www.securityjourney.com/) Connect with Simon Bennetts: → [OWASP ZAP](https://www.zaproxy.org/) → [StackHawk](https://www.stackhawk.com/) Mentioned in this episode: → [OWASP ZAP](https://www.zaproxy.org/) → [StackHawk](https://www.stackhawk.com/) → [ZAP Heads Up Display (HUD)](https://www.zaproxy.org/docs/desktop/addons/hud/) → [Burp Suite](https://portswigger.net/burp) → [OWASP Juice Shop](https://owasp.org/www-project-juice-shop/) → [OWASP Juice Shop](https://owasp-juice.shop/) → [OWASP Web Security Testing Guide (WSTG)](https://owasp.org/www-project-web-security-testing-guide/) → [OWASP Triangle Chapter](https://owasp.org/www-chapter-triangle-nc/) → [Docker](https://www.docker.com/) Chapters: 00:00 Meet Simon Bennetts: Using OWASP Zap across an Enterprise 04:20 We think about the things that ZAP is looking for, is 10:10 One of the things that is a new feature since the 14:59 Were not OWASP people, were not security people, and we've set 20:43 One of the other, you know, when I think about the 24:14 I've always been so impressed with what OWASP projects such as 29:10 I use this, when I integrate Zap into my pipeline, then 31:41 This, this was one of those questions where, like, this is 36:54 People are using this in the enterprise would be really powerful ## Transcript *7,303 words · assemblyai* **0:00 Chris Romeo:** Simon Bennetts is the OWASP Zed Attack Proxy, or ZAP, project leader and a distinguished engineer at StackHawk, a company that uses ZAP to help users fix application security bugs before they hit production. He's talked about and demonstrated ZAP at conferences all over the world. Prior to making the move into security, he was a developer for 25 years and strongly believes that you cannot build secure web applications without knowing how to attack them. Simon joins us for the second time to refresh our knowledge of ZAP explain how to use ZAP as an automation tool in your pipeline, and what he knows about rolling ZAP out across an enterprise. We hope you enjoy this conversation with Simon Bennetts. **0:39** You're about to listen to AppSec Podcast. When you're done with this, be sure to check out our other show, High Five. **0:48 Chris Romeo:** Hey folks, welcome to another episode of the Application Security Podcast. This is Chris Romeo, CEO of Security Journey and co-host of the podcast. I am also joined by Robert. Hey, Robert, how are you today? **1:03** Hey, Chris, doing well. This is Robert Hurlbut, threat modeling architect. Really happy to be here with Simon today. We're going to be talking about ZAP. **1:13 Chris Romeo:** Yeah, having some fun talking about kind of an update to things that have changed in the ZAP space. I just wanted to mention that, you know, we were talking right when we were about to start the interview. I had a chance to go to LASCON last week in Austin, Texas. We had a conference that was back together with people. So thank you, OWASP, for— and the LASKCON organizers for bringing an in-person event back together. Yeah, the audience was, was a little smaller than we thought, but it was so cool to have a room full of smiling people who chuckled a tiny bit at my corny jokes, just like our audience on the podcast does. I know you're in your cars. I know you're chuckling. But even having people in the room, It was just a really powerful experience. So hopefully that's a trend for where we're going into the future here. So we've got Simon with us today. Simon is the project lead for the OWASP ZAP project. And so before we dive in, I just want to mention the fact that we've talked to Simon before, so we're not going to ask him his origin story, but you can go back and find Simon's initial visit to the AppSec Podcast. The episode was entitled OWASP ZAP: Past, Present, and Future. It came out in about April 2019. So I'm really excited to hear some updates about what's been happening with ZAP and then also talk about, you know, kind of where ZAP's going. But we want to break this interview into 2 different pieces. We're going to talk tactical and then we're going to talk strategic. And so, Simon, from a refresher perspective, I think almost everybody on earth knows what OWASP ZAP is, but there's got to be a few people out there we can still reach. What is ZAP and why does it exist? **2:50 Simon Bennetts:** Okay, well, first of all, thank you for inviting me again. It's great to see you and talk to you. So ZAP is a tool for finding vulnerabilities in web applications. Like all those projects, it's completely free and completely open source. And we kind of— it's difficult to be sure, but we're pretty sure, we're fairly certain that ZAP is the most frequently used web application scanner in the world, and that includes all the commercial tools as well. So it's all about finding vulnerabilities in web applications, and we're not really talking about known problems with known applications. So if you've got a WordPress installation and a lot of WordPress plugins, we're not looking for known vulnerabilities and known WordPress plugins or the like. We're looking for unknown vulnerabilities, vulnerabilities that potentially no one has seen before, possibly because you're developing the application and no one's had a chance to look at it. You know, it's a really good idea because ZAP is free It means you can actually use ZAP as you're developing your application, and you can use ZAP to find vulnerabilities before you get the pen testers involved. You know, it's not a replacement for a manual pen test conducted by experts. You know, they're always going to find much more interesting things, but if you use ZAP early on, you'll find the simple stuff, the boring stuff, and you'll actually get much more value out of your pen testers because they'll be forced to actually find the more interesting stuff and find the stuff that's harder to automate. **4:20 Chris Romeo:** So when we think about the things that ZAP is looking for, is it primarily OWASP Top 10 type stuff that the tool's looking for, or is there a larger universe of things that the tool is good at finding? **4:36 Simon Bennetts:** So the OWASP Top 10 is a great resource. It's a great project, but it's— it's not really a good way of evaluating web application scanners. The OWASP Top 10, some of the vulnerabilities are kind of straightforward and you can kind of map them to real vulnerabilities, and others are kind of quite fuzzy and they're not always easy to, you know, some of them are very difficult to find an automated way, and some of them are just, they're kind of grab bags. They're that they cover so many things. So whenever you see a tool saying, we find all of the OWASP Top 10, you can be sure they're being a little bit stretching the truth a little bit. So the OWASP Top 10 is not a good way to evaluate security tools. So we do find quite a few of the vulnerabilities that are covered in the OWASP Top 10, but we're certainly not limited to that. We're looking for all web vulnerabilities. So, you know, if you're at the start of your journey, the OWASP Top 10 security journey, the OWASP Top 10 is a great place to start, but you have to be aware there are a lot of vulnerabilities outside of it, some of which are very, very important. And you don't necessarily, you know, an automated tool is not gonna find everything in the OWASP Top 10. It just doesn't work that way. **5:59 Chris Romeo:** What do you think is the source for, you mentioned kind of all these things that are above, that are outside the OWASP Top 10 that are important things that we should be looking at. If we have a listener out there and they're thinking, awesome, I want to understand, where's the knowledge base of what those things are? Or is it just because the ZAP team has lots of folks who are really deep into AppSec and you were able to build that list yourself? Is there a source or is it really just from the knowledge that y'all had? **6:28 Simon Bennetts:** So, I mean, there is, we've got, there's the OWASP Testing Guide, Web Testing Guide, which is a great resource. There's a lot of stuff in there. So, I mean, OWASP's got some really great documentation projects that you should definitely check out if if you haven't already. But ZAP is a community project, so anyone can get involved. So, you know, whenever somebody gets in touch with us and says they want to contribute, we try and, you know, help them get involved. We want people to get involved. So if you are a pen tester and think, you know, you can make ZAP better, then we'd love to hear from you. But there's quite a difference between finding vulnerabilities manually and then trying to automate those. And, you know, trying to find a particular vulnerability you know about is one thing, but trying to find the same vulnerability across a whole set of different web applications is a little bit harder. But we've had a lot of contributions from a lot of people. So it's community knowledge really. **7:23** So curious, how many people are using ZAP now? And also, do you have a breakdown of like developers, security testers, other folks who may be using ZAP? **7:33 Simon Bennetts:** I would love to have that information. We do have a little bit. So we— I've been trying to collect statistics on ZAP since the day it was released. I kind of remember when ZAP became an OWASP project and I had 400 downloads in one day, and that was like, whoa, that's huge. Things have changed since then. So we have a website called zapproxy.org, and on there, there's a statistics page. So that shows a whole load of statistics that we've got available. So we have a check for updates. So ZAP will typically do a check for updates request when it starts up. You can disable it if you want, but We're always pushing out updates to the ZAP add-ons. So we recommend you actually keep up to date. And the previous month or the month before last, we actually had— we just peaked at over a million check for update requests, which is huge. Last month was a little bit down, but only a bit. I mean, we find these things go up and down, but yeah, I mean, that jumped the month before last in a big way. Then we're counting the direct downloads last month. over 60,000. Docker pulls we're getting last month was over 10 million. So, you know, this kind of gives you the idea of, you know, the scale of ZAP being used. We don't really know, you know, who's using it and what they're using it for. We're actually looking at putting some telemetry in ZAP because that will give us more information. We're not interested in the actual sites people are using it or the exact vulnerabilities, but we want to know things like, are people using the spider, the AJAX spider, which rules they're using, which rules are finding vulnerabilities, and which rules are finding false positives? Because we never get enough feedback. And it's kind of difficult because we're not really using ZAP at scale. It's the people who use ZAP who use ZAP at scale. So we really need more feedback and more information. We do have a user questionnaire linked from the front page of zaproxy.org. So we get some information. And, you know, we think a lot of developers are using ZAP. A lot of security people are using it. Based on the— we know that ZAP is run more in daemon mode than it is in desktop mode. So we think ZAP is being used for automation more than manual testing. There's still a lot of people using ZAP for manual testing. So yeah, we get those kind of— that kind of information, but we don't know the details. **10:09 Chris Romeo:** So one of the things that is a new feature since the last time we spoke in 2019— yes, I was perusing through the release notes a little bit thinking, hey, what's new in ZAP that we can talk about? And so you've got this feature called the Heads-Up Display. which has always had a really cool— I've always thought that's a really cool name. Like, no matter what, you know, when Cadillac first came out with the heads-up display in the car where you could see your speed on the windshield in front of you, you know, or I guess the fighter pilots with their heads-up displays are the ones that we think of. But how does— what is the heads-up display in a ZAP context, and how does that help me as a tester? **10:49 Simon Bennetts:** Okay. So one of the things I've always been a bit concerned about with manual testing is I think sometimes it's too easy to focus on the tool rather than the target application. And that sounds a bit strange coming from someone who writes a security tool, but, you know, the most of the fun vulnerabilities that you find are always the kind of logical ones, the one where you're abusing the application functionality rather than just kind of cross-site scripting or SQL injection and things like that. So the whole idea of the HUD was that we wanted people to be able to focus more on the target application than on the security tools app. So what happens is your field of view, the space you're working in is the browser. That is how you interact with the target application. So now when you launch a browser from ZAP, I mean, you can configure your own browser to proxy through ZAP. You've got to import the root CA cert and mess around with that. So we actually launch browsers from ZAP. We can launch any modern browser, which comes down to Firefox and Chrome really. By default, we enable the HUD. You can turn this off, but what will happen is you'll get a big splash screen until you turn that off because we want people to be aware of what's going on. But then ZAP will actually decorate the browser. So this is not a browser add-on. It's not a plugin. We're actually manipulating the HTML as it goes through ZAP because we can do that. And we actually inject extra content. So we have its own ZAP domain and we put information to the left of the screen, to the right of the screen, at the bottom. So it's information about kind of potential vulnerabilities that have been found on this specific page, on the application, information like whether there are any hidden fields. You can pull up from the bottom, you can see the history, so you can actually see all the requests and responses. You can have a look at the sites tree. We've tried to make sure that you can actually see everything all the essential features that you get in ZAP actually in the browser. And you can focus on the application, but you can still see the essential information. And you might see, okay, there's a potential cross-site scripting vulnerability here. Let's delve into that. And you can do things like you can intercept things in the browser. And this is one of the— I think it's a killer feature because if you think about if you're using ZAP or another commercial security tool and you want to intercept a request, You're in the browser. You have to switch to your security tool. You have to turn intercept on. You go back to your browser. You make the request, then go back to your security tool. And then you can manipulate it, send it on, and then you go back to your browser. With the HUD enabled, there's just one button which you basically click on the break button similar to the ZAP desktop, but you're doing this in the browser. You make a request, and then the request actually pops up in the browser. You can then change it, you can step, you can drop, you can continue, and then you see the effect straight away. So you're not switching between tools. And the first time we got that working, it was just like, oh, this is great. It's just so much easier. So we know that the HUD hasn't got all the power of the full ZAP desktop. There's loads of things it hasn't got, but it has got the essentials. So, you know, if you're actually starting to do a manual test on a new application, the HUD is a really great option because what you can do is you can have it, you know, have the HUD there, you can see this security information kind of in your peripheral vision, you can focus on the actual target application and try and get under the skin and see how can abuse that with the essential ZAP features right to hand. **14:29 Chris Romeo:** Have you, have you heard any feedback from users about the HUD being something that's more beneficial for a developer who's new to using ZAP? Because when I think about how developers test their own web applications, and the only reason I'm even— I mean, I should have known about this, but at our OWASP chapter here in Raleigh, the OWASP Triangle chapter, we had an event where we just put up a bunch of Juice Shop instances, and we had a bunch of developers who came in. **14:58 Simon Bennetts:** Yeah. **14:59 Chris Romeo:** who were not OWASP people, were not security people, and we've set them into groups and had a security person at each table. And just watching them tear apart Juice Shop with their own console, you know, dev consoles and stuff, the way that they just were thinking was fascinating to me. And so I'm wondering, like, have you seen an instance where developers that are not security people are using the HUD and going, oh, I get this, like, this makes sense? It seems like it would open a door for them that they may not see in the regular desktop app. **15:26 Simon Bennetts:** I'm hoping so, but I don't get to see people use that very much. So it's— so yeah, we've had a little bit of feedback. Some people absolutely love the HUD. I think quite a lot of developers are using, are really looking to use ZAP in automation where the HUD isn't so relevant or not relevant at all really. But yeah, we just don't get enough feedback about how people are using ZAP, what they like and what they don't like. So I'd love to hear more. So if any of your listeners want to tell me more about how they're using ZAP and any problems they have, then please get in touch. Yeah, definitely. **15:59 Chris Romeo:** So one other question on the HUD. What about single-page applications? Does the HUD speak React and Angular and all those types of things to integrate there, or where— how does that fit in? **16:12 Simon Bennetts:** It should work fine. So, I mean, there will be certain— we're aware of certain applications which cause problems, but they're few and far between. I mean, ZAP is doing some really nasty things under the hood, but it seems to work pretty well. We haven't had too many reports of problems. ZAP, I mean, security tools generally, single-page applications can be a little bit tricky. But the HUD is kind of a high level. It's in the browser. And it does mean we have access to more of the browser things. So it should work fine. We have a differentiation between page alerts and site alerts. That's kind of irrelevant when it comes to single-page apps because it, you know, there's just one site really, or one page. But in general, it should, should still work fine. I mean, there's still, there's still more work. **17:02** Yeah. **17:03 Simon Bennetts:** I definitely want to improve how ZAP handles single-page applications because there's always more to do there and they're always tricky. **17:09** Yeah, definitely. What does the marketplace allow me to do with ZAP? **17:14 Simon Bennetts:** So the marketplace is something we've had for a very long time. What we've done is we kind of have ZAP, the core ZAP, which is the essential functionality. But it's always had a kind of plugin architecture. And what we've done is we've tried to move as much of the ZAP functionality into add-ons. So when you actually download ZAP, you'll be getting the core and you'll be getting a set of add-ons which we think are really useful. So something like even something like the AJAX Spider, that's an add-on. There's just loads of separate add-ons. You won't really notice that they're add-ons as opposed to the core. Except the fact that we can update add-ons anytime via the marketplace. So you can— we can actually view the marketplace from zaproxy.org. The easiest way is to actually view it from within ZAP. So ZAP is integrated with the marketplace. It'll tell you when there are any updates, or it's got that option to tell you of any updates. You can download them and install them automatically, and you can install new things as well. So there's a marketplace Manage Add-ons button in the ZAP toolbar. You click on there and you'll be able to go to the marketplace and see. You can, you can search things. You can— so you can update any add-ons which, um, existing add-ons which we've got improvements for or new features, or you can install new add-ons because there's a whole set of add-ons which we think are really good but aren't necessarily useful for everyone. Um, and we can also have some quite experimental things in there, um, things which, you know, so we have this concept of alpha, beta, and release quality. So there'll be, we'll be able to push out alpha quality add-ons for people to try out and just be aware that they might be in early stage, they might cause problems. And then when we're a bit more comfortable, they get promoted to beta and then to release. But even though they're release quality add-ons, that doesn't necessarily mean we'll put them into a ZAP release, which you download because they might not be as relevant to as many people. **19:11 Chris Romeo:** Who, who are the primary authors of the things that go into the marketplace? Are these community members who are already contributing to ZAP or are these other folks from the community? What's the source of this stuff? **19:22 Simon Bennetts:** It's more community members who are already contributing to ZAP. So I think the core ZAP core team has implemented most of the add-ons. One exception to that, well, they kind of— one thing we found is that Google Summer of Code, which takes place every year, we've taken part in that for many years and it's been absolutely great. So we've had some loads of great students work on that and they typically work on new add-ons. which go into the marketplace. Some of those, some like the AJAX Spider was implemented as an add-on by a Google Summer of Code project. The HUD wasn't, that was actually a collaboration with another student, but we decided not to do that through Google Summer of Code because we knew it would take so long. But there's a whole set of GraphQL support, OpenAPI, a lot of API support has come in through Google Summer of Code. And some of the students have then gone on to become ZAP core team members as well. We would love to see more add-ons on there. I think we tend to find that it's more— I suspect it's more security people who feel like they want to create add-ons. And unfortunately, they tend to create them for commercial tools rather than ZAP because that's what they often use in. But yeah, we would love to see more. We'd love to see more in the ZAP marketplace. **20:42 Chris Romeo:** So one of the other, you know, when I think about the 2 tools that people use so often in pen testing and even application security people, you know, it's, it's ZAP and Burp as the 2 things that kind of go, that are always in the conversation. And so what are your thoughts on kind of the differences and stuff between ZAP and Burp? I mean, are there, are there major differences? I mean, obviously ZAP's open source, you can go look at everything that's there, but what's your take on ZAP versus Burp? **21:13 Simon Bennetts:** Well, first of all, I'm not going to say anything bad about Burp. It is a great tool. It is relatively cheap, an amazing team behind them. So, you know, there's 30-odd people in the company working full-time. With ZAP, we've got— well, I'm kind of working full-time on ZAP. We've got, you know, everyone else is volunteers working their own time most of the time. **21:37** Yeah. **21:37 Simon Bennetts:** So, you know, the fact that people compare us, I think, is actually a testament to how well we're doing within the ZAP team. My view is though, if you're a developer or a functional tester, then ZAP is probably the only web security tool you need, and it's really great for automation. I think ZAP is the best web security tool for automation, including all the commercial tools. We've really focused on that, and we've got an amazing API. The functionality is exceeds these commercial tools, to be honest. If you're a security professional, you should know the strengths and weaknesses of all the top tools, and you should know how to use them, when to use them, when to use one, when to use the other, and when you used to use them together. So, you know, I'd absolutely expect a pen tester to have a Burp Pro license, but I'd also expect them to know ZAP and to know what its strengths and weaknesses are. I think apart from automation, one of ZAP's strengths is scripting. So ZAP has insane scripting support. Basically, you can— we have a whole load of integration points where you can run ZAP scripts, and they can be run manually, or they can be automatically injected and run at specific points. So you can essentially rewrite ZAP on the fly. We've got a script console. You can change the scripts. You can— we've got a community scripts repo with loads of different example scripts you can play around with. So I think the ZAP scripting support is, yeah, better than anything in the commercial world that I'm aware of. And something like the HUD, the HUD is unique. I've not seen any other tool, security or otherwise, with anything quite like the HUD. I know Burp has got some really great features and, you know, it's, it's probably a lot slicker. The UI is a lot slicker than ZAP's. You know, they've got more people they can focus on these things. The Burp Collaborator, where you're looking for out-of-band vulnerabilities, we didn't have anything like that until recently. But this year we had a Google Summer of Code student work on integration with some of the open source out-of-band servers that are out there. So we're definitely not at Burp levels with that, but we're getting there. So it's, you know, it depends. Burp is a great tool. You should, you know, security professional, we should definitely use it, but you should also use ZAP as well. And yeah, WebSocket support. I think we've had better WebSocket support since the year dot. So you really should know more about both tools. **24:14** Yeah. **24:14 Chris Romeo:** And I've always been so impressed with what OWASP projects such as ZAP and many of the other ones out there, like what you're able to achieve with a volunteer group of people coming together. And I know that it's nights, it's weekends, it's hours in the middle of the night. And so, So, you know, I just want to recognize that here and say, I don't know, not enough people know kind of what goes into this from a project perspective. And so you and the rest of the core team, you're doing an awesome job with ZAP, and we appreciate it as a community. I'm going to speak for the whole AppSec community now. I don't normally get to do this, but I'm going to speak for our whole community and say, because we know how many people are using it. I mean, your stats are showing everybody's got this. Everybody's using it as a way to, you know, connect with developers. If you're going to show them how to use a security tool, what are you going to start with? You know, I mean, ZAP is the one that they can put their— they can see, they can use the interception feature, they can watch, they can test one of their own apps quite easily. So, but I want to come back to something you said about automation. And I really want to understand better about how ZAP is such a great tool from an automation perspective. And so maybe I think a way we could approach this would be maybe walk us through, say we have a build pipeline we're using, you know, We're using continuous integration, continuous delivery, deployment, all those things. We've got other tools. We've got static tools in our existing build pipeline. We've got software composition analysis tools like dependency check that are looking for third-party vulnerabilities. What are the things— what are the steps? What are the things I have to do if I want to add ZAP into my build pipeline to kind of fill out, you know, the other existing tools that I have? **25:57 Simon Bennetts:** Sure. So, My previous job was at Mozilla, and we're kind of responsible for the websites, web applications behind Firefox. So what I did was there are about 200-odd web apps, and what we did, we actually implemented something called the baseline scan. And if you've got a large number of websites and you just want to get started, this is a really great place to start. So the baseline scan is included in the ZAP Docker images. It is tied to Docker. It didn't have to be. That's kind of historic really. But what you can do is the baseline scan will by default do a 1-minute spider of your target application and then we'll just do passive scanning. So it takes a minute, 2 minutes, maybe something like that by default. You can, you can run the AJAX spider and various other options if you've got a more modern web application. But what this will do is it will find a whole set of potential vulnerabilities which can be things like missing security headers, missing secure cookie flags, and a whole load of interesting things which, you know, there are many things you actually want to fix and there's quite fine-grained controls so you can actually turn things on and off. There's particular things you're not interested in or you can tune things up and down. So there's a lot of flexibility, but it's a great way to actually get ZAP into CI/CD. And because it's so quick, it's something you can turn around very quickly. So, you know, a couple of minutes is usually acceptable within the CI/CD pipeline. But that is very much passive scanning. It's not doing the interesting attacking stuff. So we have 2 more package scans. And actually, when I talk about package scans, we have GitHub Actions as well. So we have 3 package scans and we have 3 associated GitHub Actions. So we have the baseline scan, which is just doing a short spider and passive scanning. Then we have an API scan, and that can import an API definition. So that can be SOAP, it can be OpenAPI, it can be GraphQL, and then it will do an attack on that. So we'll actually be doing active scanning on it And we've tuned the scanner so that it won't do things that are more associated with UIs. So I don't think we do cross-site scripting attacks because we're talking about APIs here, but we do some extra scans. I think we, we warn if we get errors reported by the API, which we wouldn't normally do on a website, and if the content type is unexpected. So we do some extra scans and we tune things very much to APIs. Then we have the full scan, and that is, I think, is unlimited spider and unlimited active scan. But again, you can tune that. So if you just want to run cross-site scripting testing or SQL injection, you can just do that. So you have quite a fine-grained control of those 3 things. I said they're available as package scans in the Docker images and available as GitHub Actions as well. **29:10 Chris Romeo:** So when I use this, when I integrate Zap into my pipeline, then is it running in the Docker container, for example? Is it running in the daemon mode? And then from, say, I'm not even using GitHub Actions because I think that does a lot of the work for me. Say I've got my own pipeline on CircleCI or something. Do I need to then call Zap via the command line to connect to the daemon and then kind of make my settings? Or give me a little more context about how that fits together. **29:40 Simon Bennetts:** So it's actually in the process of transition at the moment, but the package scans are actually Python scripts. So they have— you don't have to worry about the details. Up until recently, they were starting ZAP in daemon mode and using the API. So ZAP daemon mode and the API is incredibly powerful, but we found that the package scans, they're they're very flexible, but they have limits. And when we're actually then getting people to jump from the package scans to daemon API, that caused people a lot of problems. So we're actually working on something new called the Automation Framework. And the Automation Framework is a step in between. We're not going to get rid of the package scans, and we're not going to get rid of the daemon API mode. So there's a new option. And in fact, we're migrating the package scans to use the Automation Framework. The automation framework doesn't use the daemon mode. It actually uses command line mode. So you can run ZAP with a -cmd and it will just do what it tells you to do inline and then exits. And what you do is the automation framework is you give it a YAML file and that YAML file will tell ZAP what to do. It defines a set of jobs and they will correspond to things like the spider, the Ajax spider, the active scan, importing API definitions. But you can define, you know, a wide range of jobs, and they have more options than we can make available from a Python script. So we think the automation framework is going to be the way to go for most people using ZAP in automation. But I said the package scans aren't going anywhere, and neither is the API. And the fact that a lot of people are using the package scans are already using the automation framework Hopefully without realizing. But at the moment, they can only use the most common options. Some of the more obscure options we haven't implemented in the automation framework yet, but we will do over time. Very cool. **31:41 Chris Romeo:** And this, this was one of those questions where, like, this is for personal reasons. Like, I don't have ZAP in our build pipeline right now, and I'm like, I'm going to ask Simon how to do that. I think other people might want to know that too. And that was really helpful. So to kind of Come towards the conclusion of our conversation. We've been very tactical so far, very much in the details. And so, what I'd love to do is just kind of step back, look out the window of the airplane at the 10,000-foot view now, down on all those people using Zap all over the world, and ask you a question about what have you heard. I know it's been limited feedback, but— or what would you recommend if I'm somebody who's like, okay, I've got 1,000 developers, and I want to use ZAP to help them get better at security. Like, what have you heard from other people, maybe anecdotally, or what would be your advice as someone who probably is the person who knows ZAP the best on planet Earth? What would be your advice for— what would you tell me to do? Like, how do I get ZAP to 1,000 developers and use it as a tool that they can learn from? **32:45 Simon Bennetts:** Yeah, that is a good question and challenging. I mean, I think You know, ZAP is very much a tool and it's not the solution to everything. So you have to think wider. You have to think about how you're going to educate your developers about security. And you've already mentioned Juice Shop. Juice Shop is a great application, a great fun way. So I actually ran a capture the flag event using Juice Shop at Mozilla. And we had pen testers, we had developers, we had QA all getting involved. So run sessions like that where you're teaching developers about security using vulnerable applications like Juice Shop, using ZAP to see what's possible. Because I do think actually using ZAP, that using the ZAP desktop in development and QA is really powerful and really helps. And actually having the desktop makes it— the automation easier, because when you're trying to automate things you can't see what's going on if you're using daemon mode. If everything's running in the background, you can't see what's happening. So it's actually really good to be able to run— use the desktop even if you don't want to use the desktop full-time, you know, all the time. You want to get things automated, start the desktop. And coincidentally, with the automation framework, we made it much easier to go from the desktop to generate the configuration you were using the desktop for the automation framework, so you can go straight into automation. So definitely, you know, play around with the ZAP Desktop with deliberately vulnerable applications when testing your own applications, but get the baseline scan in there, particularly if you have, if you have your pipeline. It's really good to get the baseline in there and then start looking at how you're going to get the full scan or the API scan. One thing is with authentication That's always painful. We're working on that, but it's never going to be easy because authentication is really painful. We're going to put more documentation in place, but if you can always run your applications in a safe environment where you can turn authentication off or use something simple like HTTP authentication— if you've got single sign-on, you're just going to make life difficult for yourself. So, you know, run in a safe environment where you can, you know, you don't want a firewall in there. You're not testing the firewall. You're not testing SSO. You're testing your application. Run your application in an environment where you can turn these safety features off. The ones you want in production, but you don't want them when you're actually testing with a security tool. But having said that, you know, we know that there are limitations to what ZAP can do. We're a small team, but we also know there's a load of commercial companies who are actually building on top of ZAP. And so if you go to the ZAP website, there's a— under the community link, there's third-party services. So a whole set of commercial companies who are building on top of ZAP and will provide the kind of extra features and support that we can't do as a small open-source team. **35:49 Chris Romeo:** And I guess the last thing I wanted to make sure we make our listeners aware about is you've got another instance of ZAPcon coming up here in 2022. Tell us a little bit about that. **35:59 Simon Bennetts:** Yes. So early last year, we had the very first ZAPcon. Which was online-only event but worked out really well, way more popular than we expected. So this is being organized by StackHawk. So I work for StackHawk. StackHawk are one of the companies building a commercial solution on top of ZAP, but they pay me to focus on the open-source ZAP project. But StackHawk are running ZAPcon in conjunction with the ZAP Core team. And yeah, we had one last year which was really great success. All the talks are available on YouTube. And we're having another one, yep, 8th of March next year. And the call for papers should be going out fairly soon. **36:40 Chris Romeo:** Very, very cool. So we'll encourage our listeners to go attend that. And if you're someone who's doing something unique and fun with ZAP, put a CFP entry in there. We'd love to hear about it. **36:53 Simon Bennetts:** Definitely. **36:53 Chris Romeo:** How people are using this in the enterprise would be really powerful. So Simon, what, I guess, what's a key takeaway a call to action, you know, other than go to ZAPcon or submit a CFP entry? What other call to action would you give to our listeners here? What do you want them to do as homework coming out of this conversation? **37:13 Simon Bennetts:** It depends where they are. If they are not using a tool like ZAP to test their applications, that's where you got to start. There are, you know, lots of different types of security tools. You've got your SAST, your software your source code analysis, you've got software composition analysis, but the DAST, the dynamic scanning that ZAP does, that's the attacker's view. If you're not doing it, then the attackers have got a one-up on you because they will be attacking your applications. So if you're getting started, you need to start with ZAP straight away. That's not to say you shouldn't be going doing source code analysis, that's very important, but with an existing project, it will probably, you know, report loads of issues, many of which you might not be interested in. Software composition analysis, keeping your dependencies up to date, that's critical, particularly from a development point of view, not just as well as the security. You should be doing that as well, but just get started with ZAP and see what it tells you. If you're actually using ZAP manually, then start looking at the automation. If you're a pen tester and you're just using Burp, you should really try ZAP. It works in a different way. It, we are not trying to be a Burp clone. So there will be a, a period of adjustment, but we've heard people, people say the same thing when they're going from ZAP to Burp. You know, they work in different ways, but they're doing similar things and you should really under, you know, understand what ZAP can do for you in addition, in addition to Burp. **38:43 Chris Romeo:** Simon, thank you so much for answering more of our questions about ZAP. And I know we got into even a few things that, that weren't on our original list. We dove pretty deep into automation, but I love the fact that we've got that perspective now. And so my homework is to go make sure we have ZAP in our build pipeline. So that's the homework I'm taking away. Simon, thank you for sharing with our audience, and I look forward to talking to you again in the future about where ZAP's going and all the cool things that they're doing. Once again, give our thanks to the core team and all the volunteers that are out there that are putting in these countless hours in the middle of the night. We really appreciate it, and you're helping to make a difference in the application security community, and we appreciate Thank you very much, and thank you, Chris and Robert, for inviting me to talk again. **39:27 Simon Bennetts:** It's a pleasure to speak with you as always. **39:29 Chris Romeo:** Thanks for listening to the Application Security Podcast. You'll find the show on Twitter @AppSecPodcast and on the web at www.securityjourney.com/resources/podcast. You can also find Chris on Twitter @edgeroute and Robert @RobertHurlbut. Remember, with application security, there are many paths, but only one destination. --- Source: https://appsecpodcast.com/simon-bennetts-using-owasp-zap-across-an-enterprise/