Disable passive scan for docker image of zap

164 views
Skip to first unread message

Andrew Andrew

unread,
Jan 28, 2022, 1:34:01 PM1/28/22
to OWASP ZAP User Group
Hello all.

 I`am using owasp/zap2docker-stable for spidering of my web application. I need to disable passive scan for docker image of zap because passive scan consume many resources and have many false postive alerts

Any help / ideas on this would be appreciated.

Simon Bennetts

unread,
Jan 31, 2022, 4:44:53 AM1/31/22
to OWASP ZAP User Group
It depends on how you are using ZAP.
If you are _not_ using the scope then the easiest option is to set the passive scanner to only scan things in scope:
If you are using the scope then you another option would be to just uninstall all of the passive scan rule add-ons.
If thats not an option then you'll need to turn off each individual rule.

I was thinking about adding a "default passive scan rule level" option - if you raise an issue for that then it might be more likely to happen? :)

Cheers,

Simon
Reply all
Reply to author
Forward
0 new messages