Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Integrate into Zaproxy? #6

Closed
omerlh opened this issue Dec 4, 2017 · 2 comments
Closed

Integrate into Zaproxy? #6

omerlh opened this issue Dec 4, 2017 · 2 comments

Comments

@omerlh
Copy link

omerlh commented Dec 4, 2017

This tool could be really awesome if it will be integrated into Zap - using it to attack/tests web app will be a lot easier. I've opened an issue (zaproxy/zaproxy#4112) - so feel free to join the discussion...

@pwntester
Copy link
Owner

Ive written a passive scanner for burp that I will publish soon. Once I publish it, it should be easy to port to ZAP. As for active scanning, ysoserial can produce payloads that would cause a delay in the response so they can be detected by ZAP/Burp, but I have no plans right now to implement that.

@irsdl
Copy link
Collaborator

irsdl commented Mar 14, 2019

We have this plugin for Burp (active and passive): https://github.com/nccgroup/freddy/ - Perhaps you can also port it into ZAP but I don't know whether ZAP has similar capability of Burp Collaborator for the active scans.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants