Jump to content

WebScarab

From Wikipedia, the free encyclopedia
The printable version is no longer supported and may have rendering errors. Please update your browser bookmarks and please use the default browser print function instead.
WebScarab
Developer(s)The Open Web Application Security Project
Repositorygithub.com/OWASP/OWASP-WebScarab
Written inJava
Successor Zed Attack Proxy
Type Web security testing tool
LicenseGPLv2
WebsiteWebScarab

WebScarab is a web security application testing tool. It serves as a proxy that intercepts and allows people to alter web browser web requests (both HTTP and HTTPS) and web server replies. WebScarab also may record traffic for further review.[1]

In 2013 official development of WebScarab slowed. The project repository was archived on 4 April 2024.[2] The website of the project was also archived and recommends using OWASP's Zed Attack Proxy instead.[3]

Overview

WebScarab is an open source tool developed by The Open Web Application Security Project (OWASP), and was implemented in Java so it could run across multiple operating systems.[4]

WebScarab is meant to act as a framework, being extensible and with most features being implemented as plugins.[3]

Features

Some of the features provided by plugins include: [3]

References

  1. ^ Hope, Brian; Walther, Ben (2009). Web security testing cookbook : systematic techniques to find problems fast. Internet Archive. Sebastopol, Ca. : O'Reilly. ISBN 978-0-596-51483-9.
  2. ^ "OWASP-WebScarab GitHub repository". GitHub. Retrieved 23 May 2025.
  3. ^ a b c "OWASP-WebScarab website". OWASP. Archived from the original on 12 May 2025. Retrieved 23 May 2025.
  4. ^ "Website Design for Crafting a Captivating Online Presence". Retrieved 2023-10-20.