Zap docker scan hangs with "Starting new HTTP connection" message

235 views
Skip to first unread message

Dan Shiebler

unread,
Feb 7, 2024, 10:20:39 PM2/7/24
to ZAP User Group
Hi, I'm having some difficulty using a ZAP docker scan. Here is the command I am using:
```
docker run -p 8090:8090 --rm  -v ./zap_conf:/zap/wrk/:rw   softwaresecurityproject/zap-stable zap-full-scan.py -t http://host.docker.internal:3000/#/ -P 8090 -a -d -j  -r  zap-report.html;
```

I'm running this on an M2 mac with colima. This prints out the following message endlessly
```

2024-02-08 03:13:42,160 Starting new HTTP connection (1): localhost:8090

2024-02-08 03:13:43,163 Starting new HTTP connection (1): localhost:8090

2024-02-08 03:13:44,165 Starting new HTTP connection (1): localhost:8090

2024-02-08 03:13:45,167 Starting new HTTP connection (1): localhost:8090

2024-02-08 03:13:46,174 Starting new HTTP connection (1): localhost:8090

2024-02-08 03:13:47,180 Starting new HTTP connection (1): localhost:8090

2024-02-08 03:13:48,187 Starting new HTTP connection (1): localhost:8090

2024-02-08 03:13:49,193 Starting new HTTP connection (1): localhost:8090

2024-02-08 03:13:50,199 Starting new HTTP connection (1): localhost:8090

```

I'm not sure exactly how to debug this. I've tried restarting colima, restarting my computer, deleting the re-pulling the docker image, changing with the port, and using ps aux and lsof to find other processes that could be using the port. This issue seems to persist through all of these. This doesn't seem to be specific to the choice of target either. The following command produces the same result (with a different port)

```
docker run --rm  -v ./zap_conf:/zap/wrk/:rw   softwaresecurityproject/zap-stable zap-full-scan.py -t https://danshiebler.com  -a -d -j  -r  zap-report.html;
```

Can anyone suggest next steps for debugging this?

thc...@gmail.com

unread,
Feb 8, 2024, 3:45:24 AM2/8/24
to zaprox...@googlegroups.com
Hi,

The zap.log file should have more details:
https://www.zaproxy.org/faq/what-is-the-default-directory-that-zap-uses/


Best regards.
Reply all
Reply to author
Forward
0 new messages