@MASTERSTHESIS\{IMM2014-06823, author = "L. Kristensen and S. {\O}. Pedersen", title = "Multi-step scanning in {ZAP} - Handling sequences in {OWASP} {ZAP}", year = "2014", school = "Technical University of Denmark, Department of Applied Mathematics and Computer Science", address = "Richard Petersens Plads, Building 324, {DK-}2800 Kgs. Lyngby, Denmark, compute@compute.dtu.dk", type = "", note = "Supervised by Associate Professor Christian W. Probst, cwpr@dtu.dk, {DTU} Compute", url = "http://www.compute.dtu.dk/English.aspx", abstract = "This report presents a solution for scanning sequences of {HTTP} requests in the open source penetration testing tool, Zed Attack Proxy or {ZAP}. The report documents the analysis, design and implementation phases of the project, as well as explain how the different test scenarios were set up and used for verification of the functionality developed in this project. The proposed solution will serve as a proof-of-concept, before being integrated with the publically available version of the application." }