OWASP ZAP: Problems to run OWASP ZAP against an Application which uses VAADIN

57 views
Skip to first unread message

Jens Kuzminski

unread,
Sep 5, 2018, 8:29:57 AM9/5/18
to OWASP ZAP User Group

Hello,
 
for a couple of weeks I tried witout success to configure ZAP 2.7 to run against an web application which uses the VAADIN framework.
 
Now – since two weeks - I try it with the OWASP weekly build and the newly feature “Authentification Status”.
My problem is: after a valid application login the following pages are moved. It seems to be that ZAP do not get the application context.
--> I cannot idenify the needed/rights configuration.
 
I hope you can help me or give a hint.

Many thanks and best regards
Jens

Simon Bennetts

unread,
Sep 5, 2018, 8:32:17 AM9/5/18
to OWASP ZAP User Group
I'm afraid I know very little about the VAADIN framework, and suspect other people here will be in the same position.
Can you explain in a lot more detail what you have done and why it appears not to be working for you?

Cheers,

Simon

Jens Kuzminski

unread,
Sep 5, 2018, 2:10:32 PM9/5/18
to OWASP ZAP User Group
I'm using the current OWASP ZAP weekly build.
And in the tab "Authentification Status" the funcionality "Check status".

The configuration looks fine

!cid_image005_png@01D4454D.png


When I then start the "Scan" I receive the following result:

!cid_image001_png@01D4454E.png




When I only change the "Starting Point":

!cid_image006_png@01D4454E.png

and start the "Scan" I receive the following result:

!cid_image002_png@01D4454E.png


This results looks much better. But I'm not sure if these a base for a valid scan.


How can I identify that my configuration is well and complete?
It will be great to get information about indicators for a valid scan base.

Regards
Jens


kingthorin+owaspzap

unread,
Sep 5, 2018, 4:38:45 PM9/5/18
to OWASP ZAP User Group

Jens Kuzminski

unread,
Sep 13, 2018, 12:21:01 PM9/13/18
to OWASP ZAP User Group
Many thanks for this useful hint!
Reply all
Reply to author
Forward
0 new messages