Skip to content

Commit 13bb8db

Browse files
authored
Merge pull request #3287 from psiinon/main
ZAP vs GnJ - AF plan
2 parents 53d452d + ded1dc5 commit 13bb8db

File tree

1 file changed

+7
-1
lines changed

1 file changed

+7
-1
lines changed

site/content/docs/testapps/ginnjuiceshop.md

Lines changed: 7 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -13,6 +13,11 @@ Despite claiming to be a modern app is is actually relatively traditional (it is
1313

1414
* Online: https://ginandjuice.shop/
1515

16+
> [!WARNING]
17+
> We are aware that a 3rd Party has published a blog post claiming that ZAP is not effective when scanning Gin & Juice Shop.
18+
> We have pointed out the mistakes that they have made but to date they have not corrected their misinformation.
19+
> Luckily as ZAP is Open Source you should be able to easily test this for yourself given the information below.
20+
1621
### Potential Pitfalls
1722

1823
This is an online app which may be unavailable or broken at any point.
@@ -103,7 +108,8 @@ For the AJAX Spider you need to exclude the logout link:
103108
104109
Gin & Juice Shop has a well documented set of [vulnerabilities](https://ginandjuice.shop/vulnerabilities).
105110
106-
Not too surprisingly you will need to configure the [activeScan](/docs/desktop/addons/automation-framework/job-ascan/) job, and you will probably want to generate a [report](/docs/desktop/addons/report-generation/automation/).
111+
We have a simple example Automation Framework Plan for performing an authenticated scan:
112+
[FullScanGinNJuiceAuth.yaml](https://github.com/zaproxy/community-scripts/blob/main/other/af-plans/FullScanGinNJuiceAuth.yaml)
107113
108114
Some of the Gin N Juice shop vulnerabilities can only be found using [OAST](/blog/2021-08-23-oast-with-owasp-zap/). You will need to configure ZAP to use OAST as it is disabled by default,
109115
due to the fact that it will send data to 3rd party services.

0 commit comments

Comments
 (0)