how to solve this Information Disclosure - Suspicious Comments?

554 views
Skip to first unread message

chirag suthar

unread,
Apr 28, 2021, 10:31:02 AM4/28/21
to OWASP ZAP User Group
Hello 

How to solve this error? Information Disclosure - Suspicious Comments

Thanks,



ZAP-Scanning-Report.png
ZAP-Scanning-Report (1).png

kingthorin+owaspzap

unread,
Apr 28, 2021, 11:08:09 AM4/28/21
to OWASP ZAP User Group
First note that it's an informational finding.

If you want/need to fix it then you'd have to contact the third party, or make local copies and edit them.

If you look at the comments and are find with them then you could add an Alert Filter https://www.zaproxy.org/docs/desktop/addons/alert-filters/

Chirag Suthar

unread,
Apr 29, 2021, 10:09:05 AM4/29/21
to zaprox...@googlegroups.com
how to fix it any idea?

--
You received this message because you are subscribed to the Google Groups "OWASP ZAP User Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to zaproxy-user...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/zaproxy-users/5c5f5009-c0a0-42d3-a290-4b8ccee0bc3fn%40googlegroups.com.

kingthorin+owaspzap

unread,
Apr 29, 2021, 3:01:23 PM4/29/21
to OWASP ZAP User Group
Yup as I stated in the previous message.

ZHEN XIAN LIM

unread,
May 16, 2023, 4:27:55 AM5/16/23
to OWASP ZAP User Group
how you determine the word is suspicious or not? Do you have a list? Because I realised mine also got it. Some in comment, some even in variable. 

kingthorin+owaspzap

unread,
May 16, 2023, 8:47:23 AM5/16/23
to OWASP ZAP User Group
Here's the documentation on this finding:

Note it currently looks at full JavaScript files/blocks as we don't currently have a way to extract JS comments. (That's coming.)

Reply all
Reply to author
Forward
0 new messages