ZAP does not proxy on localhost running application

4,409 views
Skip to first unread message

Albert

unread,
Dec 9, 2015, 10:56:05 AM12/9/15
to OWASP ZAP User Group
I am trying to proxy my browser request to ZAP, it works fine but when I try to access WebGoat which runs on my localhost: 

localhost:8080/WebGoat/login.mvc 

it does not list the request, seems is not proxying. If i try any other URL (www.google.com) in another browser tab it does. 

So the browser is proxying properly on port 8081 as I set it like that in both the ZAP and browser network properties. 

Why it does not proxy the request the browser sent to access my localhost but does proxy any other url?

Any idea?


Albert

unread,
Dec 9, 2015, 11:03:58 AM12/9/15
to OWASP ZAP User Group
Just to mention as well that Firefox, ZAP and the WebGoat are all running on a VM

thc...@gmail.com

unread,
Dec 9, 2015, 11:09:13 AM12/9/15
to zaprox...@googlegroups.com
Hi.

Did you remove "localhost, 127.0.0.1" from the option "No Proxy for" in
the "Connection Settings" dialogue?

Browsers usually require extra steps/configurations to proxy "localhost"
traffic.

Best regards.

On 09/12/15 16:03, Albert wrote:
> Just to mention as well that Firefox, ZAP and the WebGoat are all
> running on a VM
>
> On Wednesday, December 9, 2015 at 4:56:05 PM UTC+1, Albert wrote:
>
> I am trying to proxy my browser request to ZAP, it works fine but
> when I try to access WebGoat which runs on my localhost:
>
> localhost:8080/WebGoat/login.mvc
>
> it does not list the request, seems is not proxying. If i try any
> other URL (www.google.com <http://www.google.com>) in another
> browser tab it does.
>
> So the browser is proxying properly on port 8081 as I set it like
> that in both the ZAP and browser network properties.
>
> Why it does not proxy the request the browser sent to access my
> localhost but does proxy any other url?
>
> Any idea?
>
>
> --
> You received this message because you are subscribed to the Google
> Groups "OWASP ZAP User Group" group.
> To unsubscribe from this group and stop receiving emails from it, send
> an email to zaproxy-user...@googlegroups.com
> <mailto:zaproxy-user...@googlegroups.com>.
> For more options, visit https://groups.google.com/d/optout.

Albert

unread,
Dec 9, 2015, 11:28:12 AM12/9/15
to OWASP ZAP User Group
Yes that was it. Thanks!!!


On Wednesday, December 9, 2015 at 4:56:05 PM UTC+1, Albert wrote:

zeus

unread,
Mar 31, 2017, 3:45:10 AM3/31/17
to OWASP ZAP User Group
Spent my entire day on this problem.

Thanks a lot!

Samir Rakshit

unread,
Jun 18, 2019, 5:35:00 AM6/18/19
to OWASP ZAP User Group
I did a simple thing: added this into  /etc/hosts
127.0.0.1       samir.com

and ran(in mac terminal): sudo killall -HUP mDNSResponder

Sahil Doshi

unread,
Jun 19, 2019, 3:19:44 AM6/19/19
to OWASP ZAP User Group
localhost requests are not captured by ZAP although I had remove localhost from "No Proxy for".
Screenshot (145).png

Sahil Doshi

unread,
Jun 19, 2019, 3:20:26 AM6/19/19
to OWASP ZAP User Group
Are there any other settings which need to make for it?

Peter Hauschulz

unread,
Jun 19, 2019, 3:31:16 AM6/19/19
to OWASP ZAP User Group
as long as ZAP is listening on localhost:7777

what are your settings in ZAP?

thc...@gmail.com

unread,
Jun 19, 2019, 4:51:35 AM6/19/19
to zaprox...@googlegroups.com
Not sure which version you are using, Firefox 67+ no longer proxies
"localhost" by default, you need to set the preference
"network.proxy.allow_hijacking_localhost" to "true".

If you launch Firefox from ZAP it will have all required settings to
proxy correctly through ZAP.

Best regards.
>>> an email to zaprox...@googlegroups.com <javascript:>
>>> <mailto:zaproxy-user...@googlegroups.com <javascript:>>.

thc...@gmail.com

unread,
Jun 19, 2019, 4:56:20 AM6/19/19
to zaprox...@googlegroups.com
Note that you're answering to a 5 years old thread, things changed in
the meantime (one has to configure other setting to proxy localhost, as
mentioned in a previous post).

Best regards.

Sahil Doshi

unread,
Jun 19, 2019, 6:56:24 AM6/19/19
to OWASP ZAP User Group
This works for me
>>> <mailto:zaproxy-users+unsub...@googlegroups.com <javascript:>>.
Reply all
Reply to author
Forward
0 new messages