zap攻击实例_在ZAP工具中添加身份验证以攻击URL

本文介绍如何将浏览器代理设置为ZAP工具,以便在扫描网站时通过ZAP传递认证信息。首先在Firefox中配置手动代理,设置ZAP主机地址和端口。登录应用程序后,在ZAP的站点选项卡中将其包含到默认上下文,并激活HTTP会话。这使得可以使用已登录的会话执行ZAP爬虫和主动扫描。若应用使用其他认证方式,请提供更多信息。
摘要由CSDN通过智能技术生成

How to pass authentication details to the ZAP tool to scan the website. Please help me to solve the problem.

解决方案

Quite old question but here it goes.

The most simple way to do this is setting your browser to Proxy through ZAP.

On Firefox you can go to:

Options -> Advanced -> Network -> Settings.

Select Manual Proxy Configuration and fill the HTTP Host with the address of the machine running ZAP (most probably localhost) and the configured ZAP port.

You can check and configure ZAP port opening ZAP and accessing:

Tools -> Options -> Local Proxy.

Then open your web browser and login to your application.

Now go to ZAP, in the Sites tab (left side of ZAP), select your site, right click on it and select:

Include in Context -> Default Context

Now open the HTTP Sessions tab right click on the session and "Set as Active".

(HTTP Sessions Tab: View -> Show Tab -> HTTP Sessions)

Now you can perform ZAP Spider, Active Scan and so with an logged in session.

If this is not your scenario, please provide more info about which authentication method your application is using.

Hope it still helps you or someone searching for similar questions.

Thanks,

  • 0
    点赞
  • 1
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值