JavaScript / Standalone / Search for HTML Comments

453 views
Skip to first unread message

kingt...@gmail.com

unread,
Mar 26, 2014, 8:32:19 AM3/26/14
to zaproxy...@googlegroups.com
I've put together what you might call an 'Advanced Comment Finding' script, based on the Targeted Comment Finding template and standard passive template. You can find it attached, and I'd be glad to get/address any feedback people might have.

It's based on this RegEx: http://regex101.com/r/dC9kW6

I'd like to get people's thoughts on it. As you can see it picks up the first 12 variations but not the 13th, which I think I'm actually perfectly fine with. If a HTML comment exists purely to house JavaScript then I don't think that's a major security concern. Developers have been doing so for a long time and they're not "real" comments.

The RegEx I'm proposing was grown from: http://ostermiller.org/findhtmlcomment.html


PassiveHTMLCommentFinder.js
Message has been deleted

kingthorin+owaspzap

unread,
May 28, 2014, 3:01:27 PM5/28/14
to zaproxy...@googlegroups.com
Updated version now allows you to return results per comment (using a fakeParameter to differentiate) or "RollUp" all comments per URL.
The RegEx has also been tweaked slightly based on feedback from thc202.

Braces in the right positions this time.....
PassiveHTMLCommentFinder.js

kingthorin+owaspzap

unread,
Sep 23, 2014, 5:11:25 PM9/23/14
to zaproxy...@googlegroups.com
Note: This is actually a Passive script not a standalone.

kingthorin+owaspzap

unread,
Apr 28, 2015, 12:29:38 PM4/28/15
to zaproxy...@googlegroups.com
An up-to-date version of this script can be found in the official community scripts repo:
https://github.com/zaproxy/community-scripts/blob/master/passive/Find%20HTML%20Comments.js


mar adrian belen

unread,
Apr 18, 2017, 7:55:18 AM4/18/17
to OWASP ZAP Scripts
How can I highlight found string?? for example, I created a script that searches email in the HTTP response and found emails should be highlighted.

kingthorin+owaspzap

unread,
Apr 18, 2017, 8:21:58 AM4/18/17
to OWASP ZAP Scripts
Reply all
Reply to author
Forward
0 new messages