Skip to content

Commit 298c91a

Browse files
authored
Merge pull request #3294 from psiinon/vs/gnj-summary
Gin n Juice Quick Start section
2 parents 5049ffb + 222ab07 commit 298c91a

File tree

1 file changed

+30
-0
lines changed

1 file changed

+30
-0
lines changed

site/content/docs/testapps/ginnjuiceshop.md

Lines changed: 30 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -18,6 +18,36 @@ Despite claiming to be a modern app is is actually relatively traditional (it is
1818
> We have pointed out the mistakes that they have made but to date they have not corrected their misinformation.
1919
> Luckily as ZAP is Open Source you should be able to easily test this for yourself given the information below.
2020
21+
### Quick Start
22+
23+
New to ZAP and just want to quickly run ZAP against Gin & Juice Shop?
24+
25+
Just run these commands:
26+
27+
```bash
28+
# Download the recommended plan using curl, or use any other suitable tool
29+
curl -O https://raw.githubusercontent.com/zaproxy/community-scripts/refs/heads/main/other/af-plans/FullScanGinNJuiceAuth.yaml
30+
31+
# Run ZAP using the stable Docker image, mapping the CWD so that Docker can access the file and export the report
32+
docker run -v $(pwd):/zap/wrk/:rw -t zaproxy/zap-stable zap.sh -cmd -autorun wrk/FullScanGinNJuiceAuth.yaml
33+
```
34+
35+
To run this command on Windows see the [relevant documentation](/docs/docker/about/#mounting-the-current-directory).
36+
37+
You will need to have Docker installed. If you do not want to use Docker then you can of course install ZAP locally.
38+
39+
This command should take around 25 minutes (once the Docker image has been downloaded) on a MacBook M2 and should find the following High and Medium risk alerts:
40+
41+
* 🔴 [Cross Site Scripting (DOM Based)](/docs/alerts/40026/)
42+
* 🔴 [Cross Site Scripting (Reflected](/docs/alerts/40012/)
43+
* 🔴 [SQL Injection](/docs/alerts/40018/)
44+
* 🔴 [Vulnerable JS Library](/docs/alerts/10003/)
45+
* 🟠 [Absence of Anti-CSRF Tokens](/docs/alerts/10202/)
46+
* 🟠 [CRLF Injection](/docs/alerts/40003/)
47+
* 🟠 [Content Security Policy (CSP) Header Not Set](/docs/alerts/10038/)
48+
49+
It will create an HTML file in your CWD containing full details of all of the issues found.
50+
2151
### Potential Pitfalls
2252

2353
This is an online app which may be unavailable or broken at any point.

0 commit comments

Comments
 (0)