SOAP WSDL IMPORT DOES NOT PRODUCE ANY RESULT

55 views
Skip to first unread message

Gabriele Bertolini

unread,
Apr 20, 2023, 4:46:31 AM4/20/23
to OWASP ZAP User Group
Hi team,

I'd like to ask for your help...
I'm tring to start an API dast on a SOAP endpoint.
But trying to import the wsdl configuration nothing appens... the request are not mapped and no errors are displayed.

Details of the wsdl header:


wsdl_header.jpg

Version of zap: 2.12.0
Soap support plugin: 17.0.0

Thank you in advance!!!

Simon Bennetts

unread,
Apr 20, 2023, 5:32:14 AM4/20/23
to OWASP ZAP User Group
Are there any errors in the zap.log file?

Can you share an obfuscated version of the whole file, or just a small subset which you have checked also doesnt work?

Cheers,

Simon

Gabriele Bertolini

unread,
Apr 20, 2023, 6:32:10 AM4/20/23
to OWASP ZAP User Group
Here the exception:

2023-04-20 11:33:37,677 [ZAP-Import-WSDL-1] ERROR WSDLCustomParser - There was an error while parsing WSDL content.

I've resolved it importing locally the wsdl and the xsd schema.

But doing the scan with the automation plugin, active scan doesn't start:

2023-04-20 12:30:58,384 [ZAP-Automation] INFO  CommandLine - Job activeScan started
2023-04-20 12:30:58,403 [ZAP-Automation] INFO  Scanner - scanner started
2023-04-20 12:30:58,418 [ZAP-Scanner-0] INFO  HostProcess - No nodes to scan from https://*******, skipping all plugins.

 and reports doesn't show any alert.

Gabriele Bertolini

unread,
Apr 20, 2023, 6:32:29 AM4/20/23
to OWASP ZAP User Group
Thank you in advance!

Simon Bennetts

unread,
Apr 20, 2023, 6:44:59 AM4/20/23
to OWASP ZAP User Group
Are any endpoints imported?
You should see any that are in the Sites tree.
Message has been deleted

Gabriele Bertolini

unread,
Apr 20, 2023, 8:27:03 AM4/20/23
to OWASP ZAP User Group
Endpoint are imported correctly.

WSDL_IMPORT.jpg

Passive scan have findings:

passive_scan_results.jpg
Active scan don't do anything.

active_scan.JPG

Report don't have any finding.

I have to launch manually the active scan selecting the site in order to active scan it.

Gabriele Bertolini

unread,
Apr 20, 2023, 9:08:20 AM4/20/23
to OWASP ZAP User Group
Putting into the context not the start point of the rest api (eg: http://example.com/API/REST) but the fqdn (eg: http://example.com) the active scan is doing his job!
In general, configuring APIs scans do you recommend to insert into the context the entire site?

Thank you!

Reply all
Reply to author
Forward
0 new messages