ZAP XSS DOM Based Skipped

144 views
Skip to first unread message

Alessio Cassio

unread,
Feb 20, 2024, 1:17:06 PM2/20/24
to ZAP User Group
Hi everyone,
Im kinda new to this stuffs and i have a problem that i cannot understand...
So i have installed ZAP 2.14.0 on my VM Kali and i was doing some scanning for my university project, everything working fine but its a bit slow, so i downloaded ZAP 2.14.0 on my main desktop with Window 10. 
I lunched the same attack i did in my VM, with the same settings, but somehow when the Active Scan starts, the XSS DOM Based is not performing... It says "Skipped, failed to start or connected to the browser", so i tried to reinstall Chrome, btw im using Chrome Headless for the AJAX Spider, but i still got the same error
Can u guys help me? What am i missing?
Thanks!! 
ps: sorry for my bad English
Annotazione 2024-02-20 191350.jpg

Simon Bennetts

unread,
Feb 22, 2024, 4:01:32 AM2/22/24
to ZAP User Group
The DOM XSS scan rule depends on ZAP being able to launch the chosen browser.
If it cannot do that then we have no alternative but to skip the rule.


Cheers,

Simon
Reply all
Reply to author
Forward
0 new messages