I have a problem... the ZAP failed to authenticate when I use the fuzzer even if when I enable the "forced user mode" by selecting the lock button.
I'm sure that the credentials are right as I am testing my own app. (Also the spider is working fine even without selecting the "forced user mode" button!).
Also it is worth to mention that the authentication worked before without selecting the "forced user mode" (I didn't know about this option until I had this problem!).. I also documented the steps which describe how the ZAP authenticated successfully (with screenshots) before I had this problem.. so I wonder where the problem came from!
More info about how the problem occurs specifically.. check step 9 under the title Identifying the vulnerability using OWASP Zed Attack Proxy (ZAP) in section Vulnerability: A3-Cross-Site Scripting (XSS).. here is the link:
https://github.com/ahm3dhany/Broken-Web-Application#identifying-the-vulnerability-using-owasp-zed-attack-proxy-zap
@thc202 sorry to bring that issue up again..
I tried to use the "User Message Processor" along with the fuzzer.. but
it doesn't work. I tested it on both ZAP v2.7 & v2.5.
you can reproduce this issue if you tried these steps under the title "Identifying the vulnerability using OWASP Zed Attack Proxy (ZAP)" even when you combine it with the "User Message Processor" as I said before.
--
You received this message because you are subscribed to a topic in the Google Groups "OWASP ZAP User Group" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/zaproxy-users/XIQBantcAXM/unsubscribe.
To unsubscribe from this group and all its topics, send an email to zaproxy-user...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/zaproxy-users/1bdefec8-f49a-67e6-388e-6d021ff80d6e%40gmail.com.
For more options, visit https://groups.google.com/d/optout.