> --
> You received this message because you are subscribed to the Google Groups "zaproxy-develop" group.
> To post to this group, send email to zaproxy...@googlegroups.com.
> To unsubscribe from this group, send email to zaproxy-devel...@googlegroups.com.
> For more options, visit this group at http://groups.google.com/group/zaproxy-develop?hl=en.
>
>
In the xml/config.xml file there's an option (line 47) in the spider
section:
<spider>
<thread>2</thread>
<maxDepth>5</maxDepth>
<scope></scope>
<postform>0</postform>
<skipurl></skipurl>
</spider>
Usually its <postform>1</postform>, but set it to 0 to disable the crawling.
There used to be an option for it in Paros and earlier versions of ZAP I
believe, but it seems to have disappeared lol.
Anyway, you're obviously not going to find as many things without
posting stuff, but I do that sort of analysis manually, because GETing
stuff automatically takes down the bulk of the work to find stuff usually.
Hope it helps!
Ryan
GET isn't always safer than post, because even thought the HTTP RFC
defines how idempotency is supposed to work, in practice, many apps
use GET requests to change data server-side. Posts get (improperly)
used where nothing changes at all on the server side state.
> --
> You received this message because you are subscribed to the Google Groups
> "zaproxy-develop" group.
> To view this discussion on the web visit
> https://groups.google.com/d/msg/zaproxy-develop/-/vmMtZzoB-6MJ.