Zest is a specialized scripting language developed by the Mozilla security team and is intended to be used in web oriented security tools.
It is completely free, open source and can be included in any tool whether open or closed, free or commercial.
Version 1 of Zest:
- Is aimed at creating scripts for reproducing basic security vulnerabilities
- Includes a Java reference implementation
- Has been included in a proof-of-concept OWASP ZAP add-on
The first version of Zest is intentionally very basic. Future versions of Zest are planned which will significantly increase the scope of the language.
All constructive feedback is very welcome.
Anyone can contribute to the onward development of Zest, and teams or individuals who develop security tools are especially welcome to join and help shape Zest's future.
The Java reference implementation for the first phase is complete .. but right now there's no documentation. That's coming soon ;)
There is, however, an OWASP ZAP add-on which provides a UI for creating and running Zest scripts. For more details see: http://code.google.com/p/zap-extensions/wiki/AddOn_Zest
For more information (when it's available) see: