Illegal or Unrecognized Value in Parameter

308 views
Skip to first unread message

troy....@coveros.com

unread,
Jul 8, 2016, 5:05:25 PM7/8/16
to OWASP ZAP User Group, Nick Kirschke, Nathan Chen, Matthew Grasberger
Hello!

I'm trying to automatically authenticate a user on a web application, login, and then spider and scan the site. However, when running the script, an error is produced with the text "Provided parameter has illegal or unrecognized value (illegal_parameter) : scriptName". Several different attempts at modifying the "scriptName" value to resolve this error have been attempted, but none, as of yet, have succeeded. Has anyone here encountered this seemingly syntax-based issue, or one similar to it, before? If so, what value format or other solution did you use to resolve said issue?

Thank you for your time!



The offending lines seem to be 30 and 31.


Auto Generated Inline Image 1

thc...@gmail.com

unread,
Jul 8, 2016, 5:49:50 PM7/8/16
to zaprox...@googlegroups.com
Hi.

That error happens because the authentication scripts can not be enabled
(nor disabled).
Setting the script to a context it's enough for it to be used.

Best regards.
> The offending lines seem to be 30 and 31.
>
>
> --
> You received this message because you are subscribed to the Google
> Groups "OWASP ZAP User Group" group.
> To unsubscribe from this group and stop receiving emails from it, send
> an email to zaproxy-user...@googlegroups.com
> <mailto:zaproxy-user...@googlegroups.com>.
> To view this discussion on the web visit
> https://groups.google.com/d/msgid/zaproxy-users/88b53a6a-723e-4dc8-884f-01e0ef588b34%40googlegroups.com
> <https://groups.google.com/d/msgid/zaproxy-users/88b53a6a-723e-4dc8-884f-01e0ef588b34%40googlegroups.com?utm_medium=email&utm_source=footer>.
> For more options, visit https://groups.google.com/d/optout.

Troy Dinga

unread,
Jul 12, 2016, 9:36:29 AM7/12/16
to zaprox...@googlegroups.com, Nathan Chen, Nick Kirschke
Hello, and thank you for the response!

I must be honest, I'm not sure what you mean by "setting the script to a context". What exactly would this entail, or what criteria needs to be fulfilled for a script to be "set to a context"?

--
You received this message because you are subscribed to a topic in the Google Groups "OWASP ZAP User Group" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/zaproxy-users/EY4feJcoT9E/unsubscribe.
To unsubscribe from this group and all its topics, send an email to zaproxy-user...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/zaproxy-users/57801FFB.4040304%40gmail.com.

thc...@gmail.com

unread,
Jul 12, 2016, 9:47:47 AM7/12/16
to zaprox...@googlegroups.com
Hi.

With that I mean, set/use it as a Script-Based Authentication method in
a context. [1]


[1]
https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsAuthentication#script-based-authentication

Best regards.

On 12/07/16 14:36, Troy Dinga wrote:
> Hello, and thank you for the response!
>
> I must be honest, I'm not sure what you mean by "setting the script to a
> context". What exactly would this entail, or what criteria needs to be
> fulfilled for a script to be "set to a context"?
>
> On Fri, Jul 8, 2016 at 5:49 PM, <thc...@gmail.com
> <mailto:thc...@gmail.com>> wrote:
>
> Hi.
>
> That error happens because the authentication scripts can not be enabled
> (nor disabled).
> Setting the script to a context it's enough for it to be used.
>
> Best regards.
>
> On 08/07/16 22:05, troy....@coveros.com
> <mailto:troy....@coveros.com> wrote:
> > Hello!
> >
> > I'm trying to automatically authenticate a user on a web application,
> > login, and then spider and scan the site. However, when running the
> > script, an error is produced with the text "Provided parameter has
> > illegal or unrecognized value (illegal_parameter) : scriptName". Several
> > different attempts at modifying the "scriptName" value to resolve this
> > error have been attempted, but none, as of yet, have succeeded. Has
> > anyone here encountered this seemingly syntax-based issue, or one
> > similar to it, before? If so, what value format or other solution did
> > you use to resolve said issue?
> >
> > Thank you for your time!
> >
> >
> >
> > The offending lines seem to be 30 and 31.
> >
> >
> > --
> > You received this message because you are subscribed to the Google
> > Groups "OWASP ZAP User Group" group.
> > To unsubscribe from this group and stop receiving emails from it, send
> > an email to zaproxy-user...@googlegroups.com
> <mailto:zaproxy-users%2Bunsu...@googlegroups.com>
> > <mailto:zaproxy-user...@googlegroups.com
> <mailto:zaproxy-users%2Bunsu...@googlegroups.com>>.
> > To view this discussion on the web visit
> > https://groups.google.com/d/msgid/zaproxy-users/88b53a6a-723e-4dc8-884f-01e0ef588b34%40googlegroups.com
> >
> <https://groups.google.com/d/msgid/zaproxy-users/88b53a6a-723e-4dc8-884f-01e0ef588b34%40googlegroups.com?utm_medium=email&utm_source=footer>.
> > For more options, visit https://groups.google.com/d/optout.
>
> --
> You received this message because you are subscribed to a topic in
> the Google Groups "OWASP ZAP User Group" group.
> To unsubscribe from this topic, visit
> https://groups.google.com/d/topic/zaproxy-users/EY4feJcoT9E/unsubscribe.
> To unsubscribe from this group and all its topics, send an email to
> zaproxy-user...@googlegroups.com
> <mailto:zaproxy-users%2Bunsu...@googlegroups.com>.
> To view this discussion on the web visit
> --
> You received this message because you are subscribed to the Google
> Groups "OWASP ZAP User Group" group.
> To unsubscribe from this group and stop receiving emails from it, send
> an email to zaproxy-user...@googlegroups.com
> <mailto:zaproxy-user...@googlegroups.com>.
> To view this discussion on the web visit
> https://groups.google.com/d/msgid/zaproxy-users/CADHYBpZrUjDRpyKzHqKBG4fWUSBhFNDmeuMEBALi8OUGc-nzhw%40mail.gmail.com
> <https://groups.google.com/d/msgid/zaproxy-users/CADHYBpZrUjDRpyKzHqKBG4fWUSBhFNDmeuMEBALi8OUGc-nzhw%40mail.gmail.com?utm_medium=email&utm_source=footer>.
Reply all
Reply to author
Forward
0 new messages