Instead of forcing QA individuals to learn about security testing, they can simply select the record button while perform their typical functional testing (no security testing/experience required). By selecting the record button on the toolbar, all application activities including button clicks, GETs/POSTs, links, and user actions are recorded on behalf of the user. Once functional testing is complete, the SecurityQA Toolbar can then run any selected module on the recorded session. For advanced users, the recorded session can be opened with OWASP’s Webscarab tool for analysis and/or modification.
