You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to OWASP ZAP User Group
We are having the same issue. Could someone point to directions on how to "compare the base request vs the two test responses"?
wade.sc...@gmail.com
unread,
Mar 25, 2016, 10:38:04 AM3/25/16
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to OWASP ZAP User Group
Also, after a scan has run and I load the session there doesn't seem to be a way to recover the original messages. Example, I select one of the SQL injection alerts, right click and pick "Show in History Tab" which brings up an empty dialog. Ideally, what I would like to see is a "diff" of the "good" and the "bad" response (the latter being in response to an attempted injection).
thc...@gmail.com
unread,
Mar 25, 2016, 11:50:08 AM3/25/16
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to zaprox...@googlegroups.com
Hi.
> Example, I select one of the SQL injection alerts, right click and pick "Show in History Tab" which brings up an empty dialog.
Yes, the message is not available in the history tab but it is
automatically shown in the Request/Response tabs when the alert is selected.
(It's also available through the ZAP API.)
> Ideally, what I would like to see is a "diff" of the "good" and the "bad" response (the latter being in response to an attempted injection).
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to zaprox...@googlegroups.com
The alert should indicate which parameter has the problem and the "other
info" the values that were sent during the test and the reason why the
issue was raised.
You would have to manually send the two(?) requests and then compare the
responses.