Skip to content

1dson/zap-api-scanner

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

16 Commits
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Description

This project is an example of how you can security scan an API

Prerequisite

The following technologies should be installed on your system.

  • Java JDK 11
  • Maven 3
  • ZAP docker

Technologies

  • Java
  • Maven

NOTE

ZAP needs to be instantiated before executing the test

Scan Policies

List of policies that can be used in scan.

ldap-injection
remote-file-inclusion
parameter-pollution
insecure-http-methods
server-side-code-injection
SOAP XML Injection
el-injection
script-active-scan-rules
server-side-include
source-code-disclosure
shell-shock
crlf-injection
padding-oracle
external-redirect
xpath-injection
cross-site-scripting
remote-code-execution
sql-injection
remote-os-command-injection
path-traversal
parameter-tampering
directory-browsing
xml-external-entity

About

Scanning APIs with ZAP

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

 
 
 

Languages