NOTES
ZAP is my dependable no-subscription web proxy. I use it to build an application map, preserve request history, manually resend requests, compare responses, and fuzz one confirmed input at a time.
The useful mental model is browser traffic first, manual confirmation second, targeted automation third. Scanner alerts are leads; a finding requires a reproducible request, response, impact, and evidence.
WORKFLOW
- Create a context and explicitly include only authorized hosts.
- Browse the application normally and label authentication boundaries, roles, endpoints, parameters, and content types.
- Open important messages in Requester, change one variable at a time, and save the exact confirming request.
- Use the Fuzzer only after identifying the insertion point and defining what response difference matters.
- Export session or request artifacts that support reproduction; remove credentials and unrelated data before sharing.
GOTCHAS
- Confirm ZAP is not silently following a redirect that hides the meaningful response.
- Compare status, length, headers, body structure, and timing instead of searching for one success string.
- Keep separate authenticated contexts for separate users when testing authorization.
- Do not run active scanning against endpoints that change state unless the rules of engagement allow it.
- Capture the browser-visible impact and the proxy evidence while the state is still reproducible.
CHECKS
- History contains only in-scope hosts.
- Requester reproduces the baseline before mutation.
- Anti-CSRF tokens, cookies, and authorization headers are intentionally included or removed.
- Fuzz results use narrow matchers and filters.
- The saved evidence explains impact without requiring the reader to infer it.