OWASP ZAP

OWASP ZAP

OWASP
+
+

Related Products

  • Aikido Security
    72 Ratings
    Visit Website
  • Astra Pentest
    169 Ratings
    Visit Website
  • Carbide
    88 Ratings
    Visit Website
  • Sahi Pro
    60 Ratings
    Visit Website
  • Testeum
    8 Ratings
    Visit Website
  • Cisco Umbrella
    1,177 Ratings
    Visit Website
  • Global App Testing
    48 Ratings
    Visit Website
  • KrakenD
    66 Ratings
    Visit Website
  • YouTestMe
    35 Ratings
    Visit Website
  • Parasoft
    126 Ratings
    Visit Website

About

OWASP ZAP (Zed Attack Proxy) is a free, open-source penetration testing tool being maintained under the umbrella of the Open Web Application Security Project (OWASP). ZAP is designed specifically for testing web applications and is both flexible and extensible. At its core, ZAP is what is known as a “man-in-the-middle proxy.” It stands between the tester’s browser and the web application so that it can intercept and inspect messages sent between browser and web application, modify the contents if needed, and then forward those packets on to the destination. It can be used as a stand-alone application, and as a daemon process. ZAP provides functionality for a range of skill levels – from developers, to testers new to security testing, to security testing specialists. ZAP has versions for each major OS and Docker, so you are not tied to a single OS. Additional functionality is freely available from a variety of add-ons in the ZAP Marketplace, accessible from within the ZAP client.

About

sqlmap is an open source penetration testing tool that automates the process of detecting and exploiting SQL injection flaws and taking over of database servers. It comes with a powerful detection engine, many niche features for the ultimate penetration tester and a broad range of switches lasting from database fingerprinting, over data fetching from the database, to accessing the underlying file system and executing commands on the operating system via out-of-band connections. Support to directly connect to the database without passing via a SQL injection, by providing DBMS credentials, IP address, port and database name. Automatic recognition of password hash formats and support for cracking them using a dictionary-based attack. Support to dump database tables entirely, a range of entries or specific columns as per user's choice. The user can also choose to dump only a range of characters from each column's entry.

Platforms Supported

Windows
Mac
Linux
Cloud
On-Premises
iPhone
iPad
Android
Chromebook

Platforms Supported

Windows
Mac
Linux
Cloud
On-Premises
iPhone
iPad
Android
Chromebook

Audience

A Security Testing application for DevOps teams or companies

Audience

Penetration Testing platform for IT teams

Support

Phone Support
24/7 Live Support
Online

Support

Phone Support
24/7 Live Support
Online

API

Offers API

API

Offers API

Screenshots and Videos

Screenshots and Videos

Pricing

No information available.
Free Version
Free Trial

Pricing

No information available.
Free Version
Free Trial

Reviews/Ratings

Overall 0.0 / 5
ease 0.0 / 5
features 0.0 / 5
design 0.0 / 5
support 0.0 / 5

This software hasn't been reviewed yet. Be the first to provide a review:

Review this Software

Reviews/Ratings

Overall 0.0 / 5
ease 0.0 / 5
features 0.0 / 5
design 0.0 / 5
support 0.0 / 5

This software hasn't been reviewed yet. Be the first to provide a review:

Review this Software

Training

Documentation
Webinars
Live Online
In Person

Training

Documentation
Webinars
Live Online
In Person

Company Information

OWASP
Founded: 2001
United States
www.zaproxy.org

Company Information

sqlmap
sqlmap.org

Alternatives

Caido

Caido

Caido Labs Inc.

Alternatives

Acunetix

Acunetix

Invicti Security
Core Impact

Core Impact

Fortra
Burp Suite

Burp Suite

PortSwigger

Categories

Categories

Integrations

Seeker
CUBRID
Docker
FrontBase
Greenplum
HyperSQL DataBase
IBM Db2
InterSystems Caché
Microsoft Access
MonetDB
MySQL
Nucleus
Parasoft
PostgreSQL
SQL Server
SQLite
Seconize DeRisk Center
Subject7
ThreadFix
Virtuoso

Integrations

Seeker
CUBRID
Docker
FrontBase
Greenplum
HyperSQL DataBase
IBM Db2
InterSystems Caché
Microsoft Access
MonetDB
MySQL
Nucleus
Parasoft
PostgreSQL
SQL Server
SQLite
Seconize DeRisk Center
Subject7
ThreadFix
Virtuoso
Claim OWASP ZAP and update features and information
Claim OWASP ZAP and update features and information
Claim sqlmap and update features and information
Claim sqlmap and update features and information