Web Application Security Testing with OWASP ZAP

Coursera MOOC / Non-credit USD 9.99
Enroll now →
Web Application Security Testing with OWASP ZAP

About this course

By the end of this project, you will learn the fundamentals of how to use OWASP Zed Attack Proxy (ZAP). This tool greatly aids security professionals and penetration testers to discover vulnerabilities within web applications. You will learn how to perform a basic web app vulnerability scan, analyze the results, and generate a report of those results. This course includes steps on how to configure the browser proxy to passively scan web requests and responses by simply exploring websites. This course will also include how to use dictionary lists to find files and folders on a web server, and how to spider crawl websites to find all the links and URLs. Finally, the end of the course gives a brief overview of how to intercept, view, modify, and forward web requests that occur between the browser and web application. Note: This course works best for learners who are based in the North America region. We’re currently working on providing the same experience in other regions.

What you'll learn

  • perform a basic web application vulnerability scan
  • analyze scan results and generate reports
  • configure a browser proxy for passive scanning
  • use dictionary lists for file and folder discovery
  • spider crawl websites to identify links and URLs
  • intercept and modify web requests

Skills you'll gain

Related courses

Course details are provided by the platform and may change — always confirm on the provider's site. Links may be affiliate links.