
R M ⚡🇺🇦
@kingthorin_rm
IT Sec guy, @zaproxy co-lead, @owasp_wstg co-lead, VWAD co-lead, @owasp_ottawa volunteer, Hac≺3r, supporter of oxford commas, #INTJ. (Opinions == mine) 🍁
ID: 4657211780
https://www.zaproxy.org/authors/thorin/ 26-12-2015 20:22:52
16,16K Tweet
1,1K Followers
435 Following



13.7K ⭐️ Thank you! 🙏 star-history.com/#zaproxy/zapro… github.com/zaproxy/zaproxy #starhistory #GitHub #OpenSource via Star History

We have started to document how to configure ZAP against well known vulnerable apps: zaproxy.org/docs/testapps/ Let Simon Bennetts ⚡🇺🇦 know if you have any feedback or specific requests

A dev once told me: We dont have security bugs. Ran a ZAP scan on staging. 😅 ZAP didn’t just highlight issues - it showed patterns: missing headers, poor input handling, and outdated libraries. 💡 It’s not paranoia, it’s about visibility. Had a “Zed Attack Proxy wake-up call” moment?









We released v18.0.0! It removes Node.js 18.x support; mitigates local build issues w/ libxmljs; adds a new ⭐⭐⭐⭐⭐-challenge; adds a DEF CON 33 theme for the OWASP® Foundation collab w/ Blue Team Village; fixes some bugs w/ telemetry, cats, and coupons! github.com/juice-shop/jui…

Pro tip - if an article/post mentions "OWASP ZAP" then you know its out of date or badly researched. Zed Attack Proxy has not been an OWASP® Foundation project for nearly 2 years!




