Security Testing of single page application with ZAP
134 views
Skip to first unread message
shashank shekhar
unread,
Oct 9, 2023, 12:13:12 PM10/9/23
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to ZAP User Group
Hey , spider is stuck on a single page and cannot iterate to other urls in a website based on angular. Anyone have experience doing this please reply
Simon Bennetts
unread,
Oct 9, 2023, 12:14:34 PM10/9/23
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to ZAP User Group
Which spider?
Is it finding any of the URLs?
Cheers,
Simon
shashank shekhar
unread,
Oct 9, 2023, 12:29:47 PM10/9/23
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to ZAP User Group
I initially used the traditional spider, which successfully handled authentication. However, it only scanned the page for which I provided the URL. When attempting to use the Ajax spider, it encountered difficulties with the authentication process, preventing it from progressing further in the scanning process.
Cheers,
Shashank
Simon Bennetts
unread,
Oct 9, 2023, 12:33:04 PM10/9/23
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to ZAP User Group
Hi Shashank,
You will need to use the AJAX Spider to explore your app - the traditional spider cannot handle javascript, although it may still find some useful links.
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to ZAP User Group
Thankyou
In my application, both the frontend and backend are hosted on different ports, and the login process is routed through a gateway on yet another port. Is this setup a potential concern?
Cheers,
Shashank
Simon Bennetts
unread,
Oct 9, 2023, 3:15:41 PM10/9/23
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to ZAP User Group
That should not matter.
Cheers,
Simon
shashank shekhar
unread,
Oct 14, 2023, 8:37:44 PM10/14/23
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to ZAP User Group
Hello, I've updated my ZAP version, and I'm wondering if there's a way to set up authentication in the quick start process?
Cheers,
Shashank
Message has been deleted
shashank shekhar
unread,
Oct 14, 2023, 8:55:48 PM10/14/23
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to ZAP User Group
Also when i scan my url using quick start method login request is not showing in site node so how can i setup authentication?
Simon Bennetts
unread,
Oct 16, 2023, 4:37:31 AM10/16/23
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message