OWASP Web Security Testing Guide
@owasp_wstg
Official account of WSTG, the most comprehensive open source guide for testing web apps and services since 2004. That's right, I was around before Twitter.
ID: 1207706785320185856
https://github.com/OWASP/wstg 19-12-2019 16:58:39
217 Tweet
3,3K Takipçi
61 Takip Edilen
Huge news for the Zed Attack Proxy team. Congrats!!!
Bypass URL validation with this new payload from Mateo Hanžek that's 'invalid' to Safari, and valid in Chrome and Firefox! We've just added it to our URL Validation Cheat sheet. portswigger.net/web-security/s…
What public sites that you can self register for have particularly challenging or unusual authentication pages? We've updating Zed Attack Proxy to handle more auth pages automatically (with valid credentials of course). So please send me tricky examples we can test against!
Help the Zed Attack Proxy team!!!
Pro tip - if an article/post mentions "OWASP ZAP" then you know its out of date or badly researched. Zed Attack Proxy has not been an OWASP® Foundation project for nearly 2 years!
ZAP now has full support for Microsoft Edge 😀 zaproxy.org/blog/2025-07-1… #zaproxy #appsec
Great news/update from the Zed Attack Proxy team!
Public Service Announcement from the Zed Attack Proxy team: