Skip to content

Installation

Chris Horn edited this page Jul 11, 2018 · 9 revisions

Attack Surface Detector Plugin Installation

The Attack Surface Detector can be installed in one of two ways: manually or from the OWASP ZAP marketplace.

Install Attack Surface Detector Plugin From OWASP ZAP Marketplace

  1. Download and install the latest build of OWASP ZAP from https://github.com/zaproxy/zaproxy/wiki/Downloads
  2. Launch OWASP ZAP
  3. Select the "Manage Add-ons" from the tool bar
  4. Locate and select "Attack Surface Detector"
  5. Select "Install Selected"

Install Attack Surface Detector Plugin Manually

  1. Download and install the latest build of OWASP ZAP from https://github.com/zaproxy/zaproxy/wiki/Downloads
  2. Download latest Attack Surface Detector ZAP add-on file from https://github.com/secdec/attack-surface-detector-zap/releases
  3. Launch OWASP ZAP
  4. Navigate to "Load Add-on File" (File->Load Add-on File)
  5. In the popup, browse to the downloaded attacksurfacedetector-release-#.zap file
  6. Click Open (Note: The plugin file must be named attacksuracedetector-release-#.zap, where "#" is some number. This should be the default name when you download/grab the plugin.)
  7. Notice that selecting the green plus sign on the status bar now has an option for the Attack Surface Detector panel.