ZAP Scans not work for URL which have special chars (Because of URL Encoding)
149 views
Skip to first unread message
Rohit Kumar
unread,
Jul 26, 2022, 3:26:18 AM7/26/22
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to OWASP ZAP User Group
We'd a use case where swagger.json url contains a special character "[" and "]" and because of this zap is trying to url encoding since it's passing it to ZAP API.
And ZAP sends request to that encoded url and ZAP gets 404 in that case. Have a look at below example
Because of this issue, scans aren't proper, in above scenario. Character "[" is getting converted to %5B and that kind of URL returns 404
Can we do something here, apart from asking client to changes on their end?
thc...@gmail.com
unread,
Jul 26, 2022, 3:36:18 AM7/26/22
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to zaprox...@googlegroups.com
Hi.
That shows the URL encoded while being sent, ZAP will decode the query
parameters before use.
I'd suggest checking the zap.log for errors.
Best regards.
thc...@gmail.com
unread,
Jul 26, 2022, 3:58:15 AM7/26/22
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to zaprox...@googlegroups.com
Said that, ZAP will encode those characters when sending the request
which probably shouldn't.
Best regards.
Rohit Kumar
unread,
Jul 28, 2022, 3:48:21 AM7/28/22
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to OWASP ZAP User Group
Hi All,
It seems there is something wrong within ZAP, can someone please help me here. I'm attaching all logs / screenshots of whatever kind of testing i did. I Initiated scan for https://gateway.alumni-services-002.com/v2/api-docs?group=[Public]%20API%20Gateway using ZAP docker api scan and then from ZAP UI, in both cases it's not working for me.