HTTP Server Response Header question

42 views
Skip to first unread message

g

unread,
Apr 7, 2021, 6:04:57 PM4/7/21
to OWASP ZAP User Group

I installed the beta passive scan rules so I could test HTTP Server Response Header.
When I launch a browser from the Quick Start tab and visit the site I'm testing, it returns the following header:
Server: openresty/1.15.8.2

I was expecting to see an Information Disclosure via Response Header alert, but I do not. I also tried setting the threshold for the test to Low, but that didn't make a difference.

What am I misunderstanding?

Using ZAP 2.10.0.

kingthorin+owaspzap

unread,
Apr 7, 2021, 9:25:04 PM4/7/21
to OWASP ZAP User Group
If you proxied the traffic then installed the new scan rules, revisited the page but it was cached then it didn't pass through ZAP again with the new rules.

g

unread,
Apr 8, 2021, 1:28:58 PM4/8/21
to OWASP ZAP User Group
Thanks for your response.

Regarding my original post, I was not seeing a Server Leaks Version Information via "Server" HTTP Response Header Field alert while running ZAP 2.10.0 on ubuntu 20.04 LTS.

I visited the site I'm testing on a different computer, and I see the alert on that machine. It's running MacOS 11.2.3 with ZAP 2.10.0.

In both cases, I'm using ZAP's default context. Any idea why I don't see the alert when I'm using ubuntu?

kingthorin+owaspzap

unread,
Apr 8, 2021, 3:24:17 PM4/8/21
to OWASP ZAP User Group
Not enough info to be sure. Could be cache, could be disabled rule(s), could be a java issue.

When you say you're using the default context do you mean you've configured some details of the default context? Do you have Passive Scan set to scan only in-scope?

g

unread,
Apr 9, 2021, 2:05:05 PM4/9/21
to OWASP ZAP User Group
Hi kingthorin,

The problem was that I set the passive scan to only in-scope, but didn't add in-scope URLs to the context.
After unchecking the passive scanner to only scan in-scope, the Server Leaks Version Information via "Server" HTTP Response Header Field alert is now showing.
Thanks for your help.

kingthorin+owaspzap

unread,
Apr 9, 2021, 5:43:16 PM4/9/21
to OWASP ZAP User Group
Thanks for letting us know.
Reply all
Reply to author
Forward
0 new messages