--
You received this message because you are subscribed to the Google Groups "OWASP ZAP Developer Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to zaproxy-devel...@googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
--
[Off list]
Simon,
I think that's a great idea. The main reason we've been told we can't download & use ZAP at Wells Fargo is that it pretty much always does active scans by default. I think ideally the powers that be would prefer a deployment of ZAP with NO active scans at all, but IMHO that would pretty much cripple it. However, I think we maybe could argue this as a happy middle ground.
-kevin
Sent from my Droid; please excuse typos.
--
https://github.com/zaproxy/zaproxy/wiki/Downloads#zap-241-core
Both spiders also have their own set of options, so where does this end?
Having said that, if people want it then theres a use-case for it :)
One option would be a 'Advance quick scan' dialog (ok, ok, it would need another name :P )
This could include tabs for anything and everything.
I'd be wary of putting it on the Quick Start tab, but we could definitely have a toolbar button / menu item / hot key for it.
It would, of course, be implemented as an add-on, and whether it gets included by default can be decided later.
Another option is an add-on that adds a Spider tab to the existing Active Scan dialog - other add-ons already do this.
We might need to make some changes to ensure it can kick off the spider(s) before the active scan, but that shouldnt be too hard.
This would definitely _not_ be included by default, but could easily be installed by anyone who wants to use ZAP in this way.
Thoughts?
Simon
A reply from Dave, who still hasnt joined the list ;)
---------- Forwarded message ----------
From: Dave Wichers <dave.wichers@aspectsecurity.com>
Date: Tue, Sep 1, 2015 at 6:31 PM
Subject: RE: [zaproxy-develop] Spider option on Active Scan dialog
To: Mark Rader <msr...@gmail.com>, "zaproxy-develop@googlegroups.com" <zaproxy-develop@googlegroups.com>
Cc: "psi...@gmail.com" <psi...@gmail.com>
Simon, Can you forward my reply to this list?
That's kind of what I asked for at first, but Simon was hesitant to clutter the Quick Start tab with more features.
And, I want to be able to do this on the Active scan where I can also select a custom policy I want to use, unless you want to add select policy to the Quick Start tab too. (but that's even more features on Quick Start).
That's why I think adding this to Active Scan is best as it leaves Quick Start alone, but makes the Active scan work like Quick Start (or can easily be configured to do so, depending on the default settings).
-Dave
Cc: Dave Wichers
Subject: Re: [zaproxy-develop] Spider option on Active Scan dialog
Simon
From my perspective, I can see how that might be useful, but I would see it of being of more benefit under the Quick Start tab. Probably a check box of "Spider Only" with two check boxes of Spider and Ajax Spider to let you select one or both of the spiders. This would then feed active scan, and all of the other scanners.
Then one could active scan particular areas or just do the scan one wants at the time.
Mark
On Tue, Sep 1, 2015 at 10:50 AM, psiinon <psi...@gmail.com> wrote:
I've had a suggestion from Dave Wichers about adding a 'spider' option (checkbox) to the Active Scan dialog.
So this would allow you to kick off the (traditional) spider before launching the active scan, ie similar behaviour to the Quick Start tab.
We could also add a 'Ajax Spider' checkbox as well.
What do you all think?
Could it be useful?
Cheers,
Simon
--
You received this message because you are subscribed to the Google Groups "OWASP ZAP Developer Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to zaproxy-develop+unsubscribe@googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
--