How to Make OWASP ZAP Scan Results More Specific for Certain Folders or Endpoints?

52 views
Skip to first unread message

Jonathan Wilbert Gunawan

unread,
Nov 19, 2024, 11:04:48 AM11/19/24
to ZAP Developer Group

Hi everyone, I’m using OWASP ZAP to perform vulnerability scans on my website, but I’m facing an issue where the scan results are too generic. For example, when scanning the domain evil.com, ZAP only reports findings like "X-Content-Type-Options Header Missing" on a few main URLs, such as:

However, within the folder /v1, there are many subfolders and API endpoints. I’d like to know which specific folder or endpoint has issues so I can address them more effectively.


My Questions:
  1. How can I configure OWASP ZAP to make the scan results more specific, focusing on a particular folder like evil.com/v1 and its subfolders?
  2. Are there any recommended configurations or scan policies for scanning folders with multiple endpoints?

psiinon

unread,
Nov 19, 2024, 11:06:18 AM11/19/24
to zaproxy...@googlegroups.com
Hi,

Please ask questions like this on the ZAP User Group: https://groups.google.com/group/zaproxy-users

This group is for questions relating to ZAP development.
Oh, and ZAP has not been an OWASP project for over a year now...

Cheers,

Simon

--
ZAP by Checkmarx: https://www.zaproxy.org/
---
You received this message because you are subscribed to the Google Groups "ZAP Developer Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to zaproxy-devel...@googlegroups.com.
To view this discussion, visit https://groups.google.com/d/msgid/zaproxy-develop/c3bf5057-70d8-4b7d-9989-057e26f88a0bn%40googlegroups.com.


--
ZAP Project leader
Message has been deleted

Jonathan Wilbert Gunawan

unread,
Nov 19, 2024, 11:12:34 AM11/19/24
to ZAP Developer Group

Hi,

Thank you for your response! Just to clarify, I am indeed using ZAP as part of a development project. Specifically, I’m working on building a custom vulnerability scanning tool that integrates ZAP as the scanning engine.

My goal is to optimize the way ZAP identifies and reports vulnerabilities in specific folders or endpoints during development. I’m looking for advice on how to configure it effectively for such use cases.

If this question is still more suitable for the ZAP User Group, I’ll be happy to ask there instead. Thank you for the clarification about the project’s status as well!

Best regards,
Jonathan

psiinon

unread,
Nov 19, 2024, 11:20:11 AM11/19/24
to ZAP Developer Group
Hi Jonathan,

This group is for developing ZAP :)
It does not sound like you are helping us to develop ZAP, rather you are trying to use it.

So yes, please post this to our User Group.

Cheers,

Simon
Reply all
Reply to author
Forward
0 new messages