Groups
Groups
Sign in
Groups
Groups
ZAP Developer Group
Conversations
About
Send feedback
Help
ZAP False Positive for 40018 SQL Injection
50 views
Skip to first unread message
MPR GTR
unread,
May 26, 2025, 5:10:44 AM
May 26
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to ZAP Developer Group
Hey,
I have a SQL Injection High Risk but it is false positive so i wanted to know if this works
-z "-alertfilter.addFilter=true -alertfilter.ruleId=40018 -alertfilter.newLevel=FalsePositive -alertfilter.url=.*"
if this right
psiinon
unread,
May 27, 2025, 6:16:17 AM
May 27
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to ZAP Developer Group
No its not.
Did you get that from an LLM? If so you should be aware that LLMs are bad at technical detail :D
See
https://www.zaproxy.org/faq/how-do-you-find-out-what-key-to-use-to-set-a-config-value-on-the-command-line/
But also be aware that for non trivial automation we recommend using the Automation Framework:
https://www.zaproxy.org/docs/automate/automation-framework/
This has an alertFilter job:
https://www.zaproxy.org/docs/desktop/addons/alert-filters/automation/
Oh, and this group is really for discussions relating to developing ZAP.
For questions about using ZAP please use the User Group next time:
https://groups.google.com/group/zaproxy-users
Cheers,
Simon
Reply all
Reply to author
Forward
0 new messages