I am having issues using the zap hud in parrot-sec os, anyone got any clues why??

258 views
Skip to first unread message

Andrew Simon

unread,
Aug 1, 2019, 4:35:26 PM8/1/19
to OWASP ZAP User Group

Yo' Citizens, of the www,
How you doing today! I hope that you are having a great and cyber-secure day!

Check it out, I am having issues using the zap v2.8.0 hud in parrot-sec os, anyone got any clues why??

I am using:
Parrot-Sec OS
Release 4.7 64-bit
Kernel Linux 5.1.0-parrot1-3t-amd64 x86_64
MATE 1.20.4
memory: 7.0 GiB
AMD A8-5545M APU with Radeon(tm) HD Graphics × 4
avail. disk space: 422.3 GiB

Everything is, or seems to be loaded correctly?? However, zap will not launch any browsers, i.e. Firefox 60.8.0esr (64-bit) or,
Chromium, Version 73.0.3683.75 (Developer Build) built on Debian buster/sid, running on Debian parrot (64-bit)
through the quick launch window. At All.
And when I click on the firefox tab /button in the top, right hand corner, of the application, next to the HUD button /tab,
It will only "partially" display part if the jxbrowser hud display. Meaning; the firefox browser does not launch, at all, but,
part of the browser that lays on top of the (firefox)browser, (You know the part that shows the pilot's helmet the HUD part)
only part of it shows up as the browser,.. but shows up completely grayed out, looks like this:

Screenshot at 2019-08-01 13-14-40.png




2 things,

#1 - If anyone has any clues on how I can fix this??  I would greatly appreciate to here any 411 you's guy'z !

#2 - I have been working really hard on updating my website; Citizens first cyber security professionals, cfcspro.com. And I was literally about too,
go back "LIVE" today! After doing some changes to the format of the site. After adding back some of the new forums!

IS GOING BACK LIVE TODAY, WITH THIS FLAW IN THE OWASP HUD, WILL IT LEAVE OUR WEBSITE SERVER VULNERABLE TO AN ATTACK???

Curiosity is most definitely going to be the death of this cat! Lol.
Seriously, any 411 you citizens have will help.

Thank you for your time, Citizens
I hope that you have a wonderful and cyber-secure day!

Thank you,

Andrew Simon
A.K.A - Brooklyn, Kind_AJ
Citizens First Cyber Security Professionals

Peter Hauschulz

unread,
Aug 2, 2019, 2:18:56 AM8/2/19
to OWASP ZAP User Group
Hello!

Personally I don't have any experience with that release flavor, so hopefully someone else over here will chime in with some relevant info in a few hours.

But, one thing we can start with, is what does zap.log show when you get these weird behaviors? If it doesn't have any relevant WARN or other  nasty messages, you can also set it to DEBUG mode in the log4j.properties for ZAP (then restart it and try again). 

As for #2, no I don't see how a ZAP browser integration error (webdriver issue?) would leave your server vulnerable to attack. As long as the HUD/browser launching is the only issue, you can perform all of the needed scans and manual testing to verify that your server is in good condition to go live, it just might not be as fun without the HUD interface. :)


Did you have any similar issues with ZAP 2.7?

And thanks for all of the positivity and good initiative! 

Simon Bennetts

unread,
Aug 2, 2019, 3:38:06 AM8/2/19
to OWASP ZAP User Group
Yeah, definitely check the zap.log file, after having checked for updates: https://github.com/zaproxy/zaproxy/wiki/FAQhelp

You should still be able to configure any of the browsers you have installed to proxy through ZAP, just remember to import the ZAP Root CA cert as a trusted CA cert.

Its worth noting that the HUD wont work with JxBrowser. We've also discontinued support for it due to licensing changes: https://groups.google.com/d/msg/zaproxy-users/eFDbamVt1cE/Vef0rrvfBgAJ

Cheers,

Simon

Andrew Simon

unread,
Aug 2, 2019, 4:35:31 PM8/2/19
to OWASP ZAP User Group
Yo' Peter thanks i will try again and review those logs.
I was just glancing through the terminal at the directory, I must be missing something, because atm I don't see the log.
so I will restart zap and try to locate that log-file and see what is say's.
And get back with you guy's.

Plus, get my site back up online. better safe than sorry, on that note, I needed a second opinion there.

Thanks for your time,
I hope that you have a great and cyber-secure day!

Andrew Simon

unread,
Aug 2, 2019, 4:37:15 PM8/2/19
to OWASP ZAP User Group
Yo' Simon,
Thanks i will try again and review those logs.
I will restart zap and try to locate that log-file and see what is say's.
And get back with you guy's.

Thanks for your time,
I hope that you have a great and cyber-secure day!

thc...@gmail.com

unread,
Aug 2, 2019, 4:40:27 PM8/2/19
to zaprox...@googlegroups.com
Hi.

The log will be in ZAP's home dir:
https://github.com/zaproxy/zaproxy/wiki/FAQconfig

Best regards.

Andrew Simon

unread,
Aug 3, 2019, 3:20:44 AM8/3/19
to OWASP ZAP User Group
Hi Citizens,
Okay, took me a few to track down, the start to finish points,
But Here was my most recent log file, from start to finish.
Looks like it just wants to hang...

  //OWASP ZAP LOG - 08/02/2019

//-Begin-

2019-08-02 23:35:34,540 [main ] INFO  GuiBootstrap - OWASP ZAP 2.8.0 started 02/08/2019, 23:35:34 with home /root/.ZAP/
2019-08-02 23:35:35,013 [AWT-EventQueue-0] INFO  SSLConnector - Reading supported SSL/TLS protocols...
2019-08-02 23:35:35,019 [AWT-EventQueue-0] INFO  SSLConnector - Using a SSLEngine...
2019-08-02 23:35:35,283 [AWT-EventQueue-0] INFO  SSLConnector - Done reading supported SSL/TLS protocols: [SSLv2Hello, SSLv3, TLSv1, TLSv1.1, TLSv1.2, TLSv1.3]
2019-08-02 23:35:35,298 [AWT-EventQueue-0] INFO  OptionsParamCertificate - Unsafe SSL renegotiation disabled.
2019-08-02 23:35:36,411 [AWT-EventQueue-0] INFO  ENGINE - dataFileCache open start
2019-08-02 23:35:36,493 [AWT-EventQueue-0] INFO  ENGINE - dataFileCache open end
2019-08-02 23:35:37,222 [AWT-EventQueue-0] INFO  View - Initialising View
2019-08-02 23:35:39,810 [ZAP-BootstrapGUI] INFO  ExtensionFactory - Loading extensions
2019-08-02 23:35:42,727 [ZAP-BootstrapGUI] INFO  ExtensionFactory - Installed add-ons: [[id=alertFilters, version=8.0.0], [id=ascanrules, version=33.0.0], [id=bruteforce, version=8.0.0], [id=coreLang, version=13.0.0], [id=diff, version=9.0.0], [id=directorylistv1, version=3.0.0], [id=directorylistv2_3, version=3.0.0], [id=directorylistv2_3_lc, version=3.0.0], [id=fuzz, version=11.0.0], [id=fuzzdb, version=5.0.0], [id=fuzzdbwebbackdoors, version=1.0.0], [id=gettingStarted, version=10.0.0], [id=help, version=9.0.0], [id=hud, version=0.5.0], [id=importurls, version=6.0.0], [id=invoke, version=9.0.0], [id=jxbrowser, version=14.0.0], [id=jxbrowserlinux64, version=12.0.0], [id=onlineMenu, version=6.0.0], [id=pscanrules, version=24.0.0], [id=quickstart, version=26.0.0], [id=replacer, version=7.0.0], [id=reveal, version=2.0.0], [id=saverawmessage, version=4.0.0], [id=savexmlmessage, version=0.0.1], [id=scripts, version=25.0.0], [id=selenium, version=15.0.0], [id=spiderAjax, version=23.0.0], [id=tips, version=6.0.0], [id=webdriverlinux, version=11.0.0], [id=websocket, version=20.0.0], [id=zest, version=29.0.0]]
2019-08-02 23:35:43,198 [ZAP-BootstrapGUI] INFO  ExtensionFactory - Extensions loaded
2019-08-02 23:35:43,998 [ZAP-BootstrapGUI] INFO  ExtensionJxBrowser - Using version 6.23.1 of JxBrowser.
2019-08-02 23:35:44,722 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing Allows ZAP to check for updates
2019-08-02 23:35:44,955 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing Options Extension
2019-08-02 23:35:45,951 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing Edit Menu Extension
2019-08-02 23:35:45,999 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing Provides a rest based API for controlling and accessing ZAP
2019-08-02 23:35:46,098 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing Session State Extension
2019-08-02 23:35:46,101 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing Report Extension
2019-08-02 23:35:46,138 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing History Extension
2019-08-02 23:35:46,510 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing Show hidden fields and enable disabled fields
2019-08-02 23:35:46,557 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing Search messages for strings and regular expressions
2019-08-02 23:35:46,807 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing Encode/Decode/Hash...
2019-08-02 23:35:46,849 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing Allows you to intercept and modify requests and responses
2019-08-02 23:35:47,022 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing Passive scanner
2019-08-02 23:35:47,201 [ZAP-BootstrapGUI] INFO  ExtensionPassiveScan - loaded passive scan rule: Script Passive Scan Rules
2019-08-02 23:35:47,202 [ZAP-BootstrapGUI] INFO  ExtensionPassiveScan - loaded passive scan rule: Stats Passive Scan Rule
2019-08-02 23:35:47,205 [ZAP-BootstrapGUI] INFO  ExtensionPassiveScan - loaded passive scan rule: Application Error Disclosure
2019-08-02 23:35:47,208 [ZAP-BootstrapGUI] INFO  ExtensionPassiveScan - loaded passive scan rule: Absence of Anti-CSRF Tokens
2019-08-02 23:35:47,211 [ZAP-BootstrapGUI] INFO  ExtensionPassiveScan - loaded passive scan rule: Incomplete or No Cache-control and Pragma HTTP Header Set
2019-08-02 23:35:47,215 [ZAP-BootstrapGUI] INFO  ExtensionPassiveScan - loaded passive scan rule: Charset Mismatch
2019-08-02 23:35:47,220 [ZAP-BootstrapGUI] INFO  ExtensionPassiveScan - loaded passive scan rule: CSP Scanner
2019-08-02 23:35:47,224 [ZAP-BootstrapGUI] INFO  ExtensionPassiveScan - loaded passive scan rule: Content-Type Header Missing
2019-08-02 23:35:47,230 [ZAP-BootstrapGUI] INFO  ExtensionPassiveScan - loaded passive scan rule: Cookie No HttpOnly Flag
2019-08-02 23:35:47,235 [ZAP-BootstrapGUI] INFO  ExtensionPassiveScan - loaded passive scan rule: Loosely Scoped Cookie
2019-08-02 23:35:47,251 [ZAP-BootstrapGUI] INFO  ExtensionPassiveScan - loaded passive scan rule: Cookie Without Secure Flag
2019-08-02 23:35:47,257 [ZAP-BootstrapGUI] INFO  ExtensionPassiveScan - loaded passive scan rule: Cross-Domain JavaScript Source File Inclusion
2019-08-02 23:35:47,273 [ZAP-BootstrapGUI] INFO  ExtensionPassiveScan - loaded passive scan rule: Web Browser XSS Protection Not Enabled
2019-08-02 23:35:47,279 [ZAP-BootstrapGUI] INFO  ExtensionPassiveScan - loaded passive scan rule: Information Disclosure - Debug Error Messages
2019-08-02 23:35:47,286 [ZAP-BootstrapGUI] INFO  ExtensionPassiveScan - loaded passive scan rule: Weak Authentication Method
2019-08-02 23:35:47,299 [ZAP-BootstrapGUI] INFO  ExtensionPassiveScan - loaded passive scan rule: Insecure JSF ViewState
2019-08-02 23:35:47,306 [ZAP-BootstrapGUI] INFO  ExtensionPassiveScan - loaded passive scan rule: Secure Pages Include Mixed Content
2019-08-02 23:35:47,317 [ZAP-BootstrapGUI] INFO  ExtensionPassiveScan - loaded passive scan rule: Private IP Disclosure
2019-08-02 23:35:47,322 [ZAP-BootstrapGUI] INFO  ExtensionPassiveScan - loaded passive scan rule: Session ID in URL Rewrite
2019-08-02 23:35:47,329 [ZAP-BootstrapGUI] INFO  ExtensionPassiveScan - loaded passive scan rule: Viewstate Scanner
2019-08-02 23:35:47,333 [ZAP-BootstrapGUI] INFO  ExtensionPassiveScan - loaded passive scan rule: X-Content-Type-Options Header Missing
2019-08-02 23:35:47,337 [ZAP-BootstrapGUI] INFO  ExtensionPassiveScan - loaded passive scan rule: X-Frame-Options Header Scanner
2019-08-02 23:35:47,440 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing Allows you to view and manage alerts
2019-08-02 23:35:47,611 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing Active scanner, heavily based on the original Paros active scanner, but with additional tests added
2019-08-02 23:35:47,861 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing Spider used for automatically finding URIs on a site
2019-08-02 23:35:48,125 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing A set of common popup menus for miscellaneous tasks
2019-08-02 23:35:48,169 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing Forced browsing of files and directories using code from the OWASP DirBuster tool
2019-08-02 23:35:48,310 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing Manual Request Editor Extension
2019-08-02 23:35:48,322 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing Compares 2 sessions and generates an HTML file showing the differences
2019-08-02 23:35:48,330 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing Invoke external applications passing context related information such as URLs and parameters
2019-08-02 23:35:48,436 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing Handles anti cross site request forgery (CSRF) tokens
2019-08-02 23:35:48,509 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing Authentication Extension
2019-08-02 23:35:48,559 [ZAP-BootstrapGUI] INFO  ExtensionAuthentication - Loaded authentication method types: [Form-based Authentication, HTTP/NTLM Authentication, Manual Authentication, Script-based Authentication, JSON-based Authentication]
2019-08-02 23:35:48,588 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing Creates a dynamic SSL certificate to allow SSL communications to be intercepted without warnings being generated by the browser
2019-08-02 23:35:49,117 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing Logs errors to the Output tab in development mode only
2019-08-02 23:35:49,140 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing Users Extension
2019-08-02 23:35:49,150 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing Summarise and analyse FORM and URL parameters as well as cookies
2019-08-02 23:35:49,224 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing Script integration
2019-08-02 23:35:49,308 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing Scripting console, supports all JSR 223 scripting languages
2019-08-02 23:35:50,118 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing Forced User Extension
2019-08-02 23:35:50,141 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing Extension handling HTTP sessions
2019-08-02 23:35:50,237 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing Zest is a specialized scripting language from Mozilla specifically designed to be used in security tools
2019-08-02 23:35:50,701 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing ExtensionDiff
2019-08-02 23:35:50,717 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing HTTP Panel Post Table View Extension
2019-08-02 23:35:50,752 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing Session Management Extension
2019-08-02 23:35:50,768 [ZAP-BootstrapGUI] INFO  ExtensionSessionManagement - Loaded session management method types: [Cookie-based Session Management, HTTP Authentication Session Management]
2019-08-02 23:35:50,784 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing HTTP Panel Form Table View Extension
2019-08-02 23:35:50,862 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing Capture messages from WebSockets with the ability to set breakpoints.
2019-08-02 23:35:51,348 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing Allows you to import a file containing URLs which ZAP will access, adding them to the Sites tree
2019-08-02 23:35:51,369 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing Core UI related functionality.
2019-08-02 23:35:51,373 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing Authorization Extension
2019-08-02 23:35:51,383 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing AJAX Spider, uses Crawljax
2019-08-02 23:35:51,585 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing Provides WebDrivers to control several browsers using Selenium and includes HtmlUnit browser.
2019-08-02 23:35:51,629 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing Manages the local proxy configurations
2019-08-02 23:35:51,720 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing Handles adding Global Excluded URLs
2019-08-02 23:35:51,762 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing Adds menu item to refresh the Sites tree
2019-08-02 23:35:51,773 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing OWASP ZAP User Guide
2019-08-02 23:35:52,181 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing Provides a URL suitable for calling from target sites
2019-08-02 23:35:52,272 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing Allows you to configure which extensions are loaded when ZAP starts
2019-08-02 23:35:52,337 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing Combined HTTP Panels Extension
2019-08-02 23:35:52,416 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing HTTP Panel Hex View Extension
2019-08-02 23:35:52,535 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing HTTP Panel Image View Extension
2019-08-02 23:35:52,554 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing HTTP Panel Large Request View Extension
2019-08-02 23:35:52,587 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing HTTP Panel Large Response View Extension
2019-08-02 23:35:52,620 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing HTTP Panel Query Table View Extension
2019-08-02 23:35:52,699 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing HTTP Panel Syntax Highlighter View Extension
2019-08-02 23:35:52,959 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing Adds support for configurable keyboard shortcuts for all of the ZAP menus.
2019-08-02 23:35:52,991 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing Active and passive rule configuration
2019-08-02 23:35:53,026 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing Statistics
2019-08-02 23:35:53,051 [ZAP-BootstrapGUI] INFO  ExtensionStats - Start recording in memory stats
2019-08-02 23:35:53,060 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing ExtensionJxBrowserLinux64
2019-08-02 23:35:53,075 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing ExtSelJxBrowserLinux64
2019-08-02 23:35:53,101 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing The Online menu links
2019-08-02 23:35:53,113 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing ExtensionJxBrowser
2019-08-02 23:35:53,118 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing Active Scan Rules
2019-08-02 23:35:53,129 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing ExtensionSaveRawHttpMessage
2019-08-02 23:35:53,143 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing ExtensionSaveXMLHttpMessage
2019-08-02 23:35:53,180 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing Context alert rules filter
2019-08-02 23:35:53,185 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing Adds the Quick Start panel for scanning and exploring applications
2019-08-02 23:35:53,276 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing Add the option to use the Ajax Spider in the Quick Start scan
2019-08-02 23:35:53,318 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing Launch browsers proxying through ZAP
2019-08-02 23:35:53,327 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing Launch browsers proxying through ZAP
2019-08-02 23:35:53,412 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing Tips and Tricks
2019-08-02 23:35:53,434 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing Passive Scan Rules
2019-08-02 23:35:53,435 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing Provides the foundation for concrete message types (for example, HTTP, WebSockets) expose fuzzer implementations.
2019-08-02 23:35:53,470 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing Allows to fuzz HTTP messages.
2019-08-02 23:35:53,618 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing The ZAP Getting Started Guide
2019-08-02 23:35:53,623 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing Easy way to replace strings in requests and responses
2019-08-02 23:35:53,677 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing Heads Up Display
2019-08-02 23:35:53,804 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing ExtensionHUDlaunch
2019-08-02 23:35:53,813 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing Translations of the core language files
2019-08-02 23:35:53,814 [ZAP-BootstrapGUI] INFO  ExtensionLoader - Initializing Allows to fuzz WebSocket messages.
2019-08-02 23:35:55,355 [ZAP-BootstrapGUI] INFO  ExtensionCallback - Started callback server on 0.0.0.0:44893
2019-08-02 23:35:55,356 [ZAP-BootstrapGUI] INFO  ExtensionKeyboard - Initializing keyboard shortcuts
2019-08-02 23:36:03,032 [AWT-EventQueue-0] INFO  Control - New Session
2019-08-02 23:36:03,074 [AWT-EventQueue-0] INFO  Control - Create and Open Untitled Db
2019-08-02 23:36:03,178 [AWT-EventQueue-0] INFO  ENGINE - dataFileCache commit start
2019-08-02 23:36:03,234 [AWT-EventQueue-0] INFO  ENGINE - dataFileCache commit end
2019-08-02 23:36:03,326 [AWT-EventQueue-0] INFO  ENGINE - Database closed
2019-08-02 23:36:03,719 [AWT-EventQueue-0] INFO  ENGINE - dataFileCache open start
2019-08-02 23:36:03,771 [AWT-EventQueue-0] INFO  ENGINE - dataFileCache open end
2019-08-02 23:37:04,223 [ZAP-BrowserLauncher] ERROR ExtensionQuickStartLaunch - Unable to find a matching set of capabilities
Build info: version: 'unknown', revision: 'unknown', time: 'unknown'
System info: host: 'parrot', ip: '127.0.1.1', os.name: 'Linux', os.arch: 'amd64', os.version: '5.1.0-parrot1-3t-amd64', java.version: '11.0.4'
Driver info: driver.version: FirefoxDriver
remote stacktrace:
org.openqa.selenium.SessionNotCreatedException: Unable to find a matching set of capabilities
Build info: version: 'unknown', revision: 'unknown', time: 'unknown'
System info: host: 'parrot', ip: '127.0.1.1', os.name: 'Linux', os.arch: 'amd64', os.version: '5.1.0-parrot1-3t-amd64', java.version: '11.0.4'
Driver info: driver.version: FirefoxDriver
remote stacktrace:
    at java.base/jdk.internal.reflect.NativeConstructorAccessorImpl.newInstance0(Native Method)
    at java.base/jdk.internal.reflect.NativeConstructorAccessorImpl.newInstance(NativeConstructorAccessorImpl.java:62)
    at java.base/jdk.internal.reflect.DelegatingConstructorAccessorImpl.newInstance(DelegatingConstructorAccessorImpl.java:45)
    at java.base/java.lang.reflect.Constructor.newInstance(Constructor.java:490)
    at org.openqa.selenium.remote.W3CHandshakeResponse.lambda$new$0(W3CHandshakeResponse.java:57)
    at org.openqa.selenium.remote.W3CHandshakeResponse.lambda$getResponseFunction$2(W3CHandshakeResponse.java:104)
    at org.openqa.selenium.remote.ProtocolHandshake.lambda$createSession$0(ProtocolHandshake.java:123)
    at java.base/java.util.stream.ReferencePipeline$3$1.accept(ReferencePipeline.java:195)
    at java.base/java.util.Spliterators$ArraySpliterator.tryAdvance(Spliterators.java:958)
    at java.base/java.util.stream.ReferencePipeline.forEachWithCancel(ReferencePipeline.java:127)
    at java.base/java.util.stream.AbstractPipeline.copyIntoWithCancel(AbstractPipeline.java:502)
    at java.base/java.util.stream.AbstractPipeline.copyInto(AbstractPipeline.java:488)
    at java.base/java.util.stream.AbstractPipeline.wrapAndCopyInto(AbstractPipeline.java:474)
    at java.base/java.util.stream.FindOps$FindOp.evaluateSequential(FindOps.java:150)
    at java.base/java.util.stream.AbstractPipeline.evaluate(AbstractPipeline.java:234)
    at java.base/java.util.stream.ReferencePipeline.findFirst(ReferencePipeline.java:543)
    at org.openqa.selenium.remote.ProtocolHandshake.createSession(ProtocolHandshake.java:126)
    at org.openqa.selenium.remote.ProtocolHandshake.createSession(ProtocolHandshake.java:73)
    at org.openqa.selenium.remote.HttpCommandExecutor.execute(HttpCommandExecutor.java:142)
    at org.openqa.selenium.remote.service.DriverCommandExecutor.execute(DriverCommandExecutor.java:83)
    at org.openqa.selenium.remote.RemoteWebDriver.execute(RemoteWebDriver.java:600)
    at org.openqa.selenium.remote.RemoteWebDriver.startSession(RemoteWebDriver.java:219)
    at org.openqa.selenium.remote.RemoteWebDriver.<init>(RemoteWebDriver.java:142)
    at org.openqa.selenium.firefox.FirefoxDriver.<init>(FirefoxDriver.java:120)
    at org.zaproxy.zap.extension.selenium.ExtensionSelenium.getWebDriverImpl(ExtensionSelenium.java:777)
    at org.zaproxy.zap.extension.selenium.ExtensionSelenium.getWebDriver(ExtensionSelenium.java:700)
    at org.zaproxy.zap.extension.selenium.internal.BuiltInSingleWebDriverProvider.getWebDriver(BuiltInSingleWebDriverProvider.java:62)
    at org.zaproxy.zap.extension.selenium.ExtensionSelenium.getWebDriverImpl(ExtensionSelenium.java:639)
    at org.zaproxy.zap.extension.selenium.ExtensionSelenium.getWebDriver(ExtensionSelenium.java:509)
    at org.zaproxy.zap.extension.selenium.ExtensionSelenium.getProxiedBrowser(ExtensionSelenium.java:602)
    at org.zaproxy.zap.extension.selenium.ExtensionSelenium.getProxiedBrowserByName(ExtensionSelenium.java:566)
    at org.zaproxy.zap.extension.selenium.ExtensionSelenium.getProxiedBrowserByName(ExtensionSelenium.java:552)
    at org.zaproxy.zap.extension.selenium.ExtensionSelenium.getProxiedBrowserByName(ExtensionSelenium.java:542)
    at org.zaproxy.zap.extension.quickstart.launch.ExtensionQuickStartLaunch$2.run(ExtensionQuickStartLaunch.java:227)
    at java.base/java.lang.Thread.run(Thread.java:834)
2019-08-02 23:39:36,113 [ZAP-BrowserLauncher] ERROR ExtensionQuickStartLaunch - Unable to find a matching set of capabilities
Build info: version: 'unknown', revision: 'unknown', time: 'unknown'
System info: host: 'parrot', ip: '127.0.1.1', os.name: 'Linux', os.arch: 'amd64', os.version: '5.1.0-parrot1-3t-amd64', java.version: '11.0.4'
Driver info: driver.version: FirefoxDriver
remote stacktrace:
org.openqa.selenium.SessionNotCreatedException: Unable to find a matching set of capabilities
Build info: version: 'unknown', revision: 'unknown', time: 'unknown'
System info: host: 'parrot', ip: '127.0.1.1', os.name: 'Linux', os.arch: 'amd64', os.version: '5.1.0-parrot1-3t-amd64', java.version: '11.0.4'
Driver info: driver.version: FirefoxDriver
remote stacktrace:
    at java.base/jdk.internal.reflect.NativeConstructorAccessorImpl.newInstance0(Native Method)
    at java.base/jdk.internal.reflect.NativeConstructorAccessorImpl.newInstance(NativeConstructorAccessorImpl.java:62)
    at java.base/jdk.internal.reflect.DelegatingConstructorAccessorImpl.newInstance(DelegatingConstructorAccessorImpl.java:45)
    at java.base/java.lang.reflect.Constructor.newInstance(Constructor.java:490)
    at org.openqa.selenium.remote.W3CHandshakeResponse.lambda$new$0(W3CHandshakeResponse.java:57)
    at org.openqa.selenium.remote.W3CHandshakeResponse.lambda$getResponseFunction$2(W3CHandshakeResponse.java:104)
    at org.openqa.selenium.remote.ProtocolHandshake.lambda$createSession$0(ProtocolHandshake.java:123)
    at java.base/java.util.stream.ReferencePipeline$3$1.accept(ReferencePipeline.java:195)
    at java.base/java.util.Spliterators$ArraySpliterator.tryAdvance(Spliterators.java:958)
    at java.base/java.util.stream.ReferencePipeline.forEachWithCancel(ReferencePipeline.java:127)
    at java.base/java.util.stream.AbstractPipeline.copyIntoWithCancel(AbstractPipeline.java:502)
    at java.base/java.util.stream.AbstractPipeline.copyInto(AbstractPipeline.java:488)
    at java.base/java.util.stream.AbstractPipeline.wrapAndCopyInto(AbstractPipeline.java:474)
    at java.base/java.util.stream.FindOps$FindOp.evaluateSequential(FindOps.java:150)
    at java.base/java.util.stream.AbstractPipeline.evaluate(AbstractPipeline.java:234)
    at java.base/java.util.stream.ReferencePipeline.findFirst(ReferencePipeline.java:543)
    at org.openqa.selenium.remote.ProtocolHandshake.createSession(ProtocolHandshake.java:126)
    at org.openqa.selenium.remote.ProtocolHandshake.createSession(ProtocolHandshake.java:73)
    at org.openqa.selenium.remote.HttpCommandExecutor.execute(HttpCommandExecutor.java:142)
    at org.openqa.selenium.remote.service.DriverCommandExecutor.execute(DriverCommandExecutor.java:83)
    at org.openqa.selenium.remote.RemoteWebDriver.execute(RemoteWebDriver.java:600)
    at org.openqa.selenium.remote.RemoteWebDriver.startSession(RemoteWebDriver.java:219)
    at org.openqa.selenium.remote.RemoteWebDriver.<init>(RemoteWebDriver.java:142)
    at org.openqa.selenium.firefox.FirefoxDriver.<init>(FirefoxDriver.java:120)
    at org.zaproxy.zap.extension.selenium.ExtensionSelenium.getWebDriverImpl(ExtensionSelenium.java:777)
    at org.zaproxy.zap.extension.selenium.ExtensionSelenium.getWebDriver(ExtensionSelenium.java:700)
    at org.zaproxy.zap.extension.selenium.internal.BuiltInSingleWebDriverProvider.getWebDriver(BuiltInSingleWebDriverProvider.java:62)
    at org.zaproxy.zap.extension.selenium.ExtensionSelenium.getWebDriverImpl(ExtensionSelenium.java:639)
    at org.zaproxy.zap.extension.selenium.ExtensionSelenium.getWebDriver(ExtensionSelenium.java:509)
    at org.zaproxy.zap.extension.selenium.ExtensionSelenium.getProxiedBrowser(ExtensionSelenium.java:602)
    at org.zaproxy.zap.extension.selenium.ExtensionSelenium.getProxiedBrowserByName(ExtensionSelenium.java:566)
    at org.zaproxy.zap.extension.selenium.ExtensionSelenium.getProxiedBrowserByName(ExtensionSelenium.java:552)
    at org.zaproxy.zap.extension.selenium.ExtensionSelenium.getProxiedBrowserByName(ExtensionSelenium.java:542)
    at org.zaproxy.zap.extension.quickstart.launch.ExtensionQuickStartLaunch$2.run(ExtensionQuickStartLaunch.java:227)
    at java.base/java.lang.Thread.run(Thread.java:834)
2019-08-02 23:41:07,526 [AWT-EventQueue-0] INFO  SSLConnector - ClientCert disabled
2019-08-02 23:41:14,665 [ZAP-BrowserLauncher] ERROR ExtensionQuickStartLaunch - Unable to find a matching set of capabilities
Build info: version: 'unknown', revision: 'unknown', time: 'unknown'
System info: host: 'parrot', ip: '127.0.1.1', os.name: 'Linux', os.arch: 'amd64', os.version: '5.1.0-parrot1-3t-amd64', java.version: '11.0.4'
Driver info: driver.version: FirefoxDriver
remote stacktrace:
org.openqa.selenium.SessionNotCreatedException: Unable to find a matching set of capabilities
Build info: version: 'unknown', revision: 'unknown', time: 'unknown'
System info: host: 'parrot', ip: '127.0.1.1', os.name: 'Linux', os.arch: 'amd64', os.version: '5.1.0-parrot1-3t-amd64', java.version: '11.0.4'
Driver info: driver.version: FirefoxDriver
remote stacktrace:
    at java.base/jdk.internal.reflect.NativeConstructorAccessorImpl.newInstance0(Native Method)
    at java.base/jdk.internal.reflect.NativeConstructorAccessorImpl.newInstance(NativeConstructorAccessorImpl.java:62)
    at java.base/jdk.internal.reflect.DelegatingConstructorAccessorImpl.newInstance(DelegatingConstructorAccessorImpl.java:45)
    at java.base/java.lang.reflect.Constructor.newInstance(Constructor.java:490)
    at org.openqa.selenium.remote.W3CHandshakeResponse.lambda$new$0(W3CHandshakeResponse.java:57)
    at org.openqa.selenium.remote.W3CHandshakeResponse.lambda$getResponseFunction$2(W3CHandshakeResponse.java:104)
    at org.openqa.selenium.remote.ProtocolHandshake.lambda$createSession$0(ProtocolHandshake.java:123)
    at java.base/java.util.stream.ReferencePipeline$3$1.accept(ReferencePipeline.java:195)
    at java.base/java.util.Spliterators$ArraySpliterator.tryAdvance(Spliterators.java:958)
    at java.base/java.util.stream.ReferencePipeline.forEachWithCancel(ReferencePipeline.java:127)
    at java.base/java.util.stream.AbstractPipeline.copyIntoWithCancel(AbstractPipeline.java:502)
    at java.base/java.util.stream.AbstractPipeline.copyInto(AbstractPipeline.java:488)
    at java.base/java.util.stream.AbstractPipeline.wrapAndCopyInto(AbstractPipeline.java:474)
    at java.base/java.util.stream.FindOps$FindOp.evaluateSequential(FindOps.java:150)
    at java.base/java.util.stream.AbstractPipeline.evaluate(AbstractPipeline.java:234)
    at java.base/java.util.stream.ReferencePipeline.findFirst(ReferencePipeline.java:543)
    at org.openqa.selenium.remote.ProtocolHandshake.createSession(ProtocolHandshake.java:126)
    at org.openqa.selenium.remote.ProtocolHandshake.createSession(ProtocolHandshake.java:73)
    at org.openqa.selenium.remote.HttpCommandExecutor.execute(HttpCommandExecutor.java:142)
    at org.openqa.selenium.remote.service.DriverCommandExecutor.execute(DriverCommandExecutor.java:83)
    at org.openqa.selenium.remote.RemoteWebDriver.execute(RemoteWebDriver.java:600)
    at org.openqa.selenium.remote.RemoteWebDriver.startSession(RemoteWebDriver.java:219)
    at org.openqa.selenium.remote.RemoteWebDriver.<init>(RemoteWebDriver.java:142)
    at org.openqa.selenium.firefox.FirefoxDriver.<init>(FirefoxDriver.java:120)
    at org.zaproxy.zap.extension.selenium.ExtensionSelenium.getWebDriverImpl(ExtensionSelenium.java:777)
    at org.zaproxy.zap.extension.selenium.ExtensionSelenium.getWebDriver(ExtensionSelenium.java:700)
    at org.zaproxy.zap.extension.selenium.internal.BuiltInSingleWebDriverProvider.getWebDriver(BuiltInSingleWebDriverProvider.java:62)
    at org.zaproxy.zap.extension.selenium.ExtensionSelenium.getWebDriverImpl(ExtensionSelenium.java:639)
    at org.zaproxy.zap.extension.selenium.ExtensionSelenium.getWebDriver(ExtensionSelenium.java:509)
    at org.zaproxy.zap.extension.selenium.ExtensionSelenium.getProxiedBrowser(ExtensionSelenium.java:602)
    at org.zaproxy.zap.extension.selenium.ExtensionSelenium.getProxiedBrowserByName(ExtensionSelenium.java:566)
    at org.zaproxy.zap.extension.selenium.ExtensionSelenium.getProxiedBrowserByName(ExtensionSelenium.java:552)
    at org.zaproxy.zap.extension.selenium.ExtensionSelenium.getProxiedBrowserByName(ExtensionSelenium.java:542)
    at org.zaproxy.zap.extension.quickstart.launch.ExtensionQuickStartLaunch$2.run(ExtensionQuickStartLaunch.java:227)
    at java.base/java.lang.Thread.run(Thread.java:834)
2019-08-02 23:41:24,466 [ZAP-Shutdown] INFO  ENGINE - dataFileCache commit start
2019-08-02 23:41:24,533 [ZAP-Shutdown] INFO  ENGINE - dataFileCache commit end
2019-08-02 23:41:24,623 [ZAP-Shutdown] INFO  ENGINE - Database closed
2019-08-02 23:41:24,757 [ZAP-Shutdown] INFO  Control - OWASP ZAP 2.8.0 terminated.


//-END-

I hope that this helps, with an analysis.

Thank you, again citizens, for your time and input!

Andrew Simon

unread,
Aug 3, 2019, 3:25:00 AM8/3/19
to OWASP ZAP User Group
Thanks for your input brother. Here is what my log says;
I hope this helps, Thank you

On Thursday, August 1, 2019 at 11:18:56 PM UTC-7, Peter Hauschulz wrote:

Andrew Simon

unread,
Aug 3, 2019, 3:32:09 AM8/3/19
to OWASP ZAP User Group
I found it and posted it up here my friend,
Thank you for your time and consideration, with your help and input.
Have a great and cyber-secure night.

Andrew Simon

unread,
Aug 3, 2019, 4:37:41 PM8/3/19
to OWASP ZAP User Group
Yo' Citizens,
I believe this is the main part where the error shows up in the zap.log??

2019-08-02 23:37:04,223 [ZAP-BrowserLauncher] ERROR ExtensionQuickStartLaunch - Unable to find a matching set of capabilities
Build info: version: 'unknown', revision: 'unknown', time: 'unknown'
System info: host: 'parrot', ip: '127.0.1.1', os.name: 'Linux', os.arch: 'amd64', os.version: '5.1.0-parrot1-3t-amd64', java.version: '11.0.4'
Driver info: driver.version: FirefoxDriver
remote stacktrace:
org.openqa.selenium.
SessionNotCreatedException: Unable to find a matching set of capabilities

Build info: version: 'unknown', revision: 'unknown', time: 'unknown'
System info: host: 'parrot', ip: '127.0.1.1', os.name: 'Linux', os.arch: 'amd64', os.version: '5.1.0-parrot1-3t-amd64', java.version: '11.0.4'
Driver info: driver.version: FirefoxDriver
remote stacktrace: .....

But I am not sure what needs to be done here?

Suggestions? Please!?

Thank you for your time citizens,
I hope that you have a great and cyber-secure day!!

Thank you,
Andrew Simon

On Thursday, August 1, 2019 at 1:35:26 PM UTC-7, Andrew Simon wrote:

Peter Hauschulz

unread,
Aug 5, 2019, 2:22:17 AM8/5/19
to OWASP ZAP User Group
Based on what that looks like, it does seem to be a webdriver related issue. That's unfortunately not really my area of expertise, so I'm unable to suggest genuine solutions beyond the tried and trust uninstall/reinstall, turn it off and on again type stuff. 

Maybe I can help narrow it down a little though.....if you manually open a firefox browser and point it to ZAP, does everything look like it works ok? 

If yes, can you record or create a Zest script with client control elements and see if that works?

Also, it might be worth going into the ZAP Marketplace and just finding the Selenium add-on and see if you can update it manually. Not sure if that's exactly the right one, but that's what I'd try!
Reply all
Reply to author
Forward
0 new messages