Access to websites containing cognito with owasp zap
401 views
Skip to first unread message
vel
unread,
Jun 30, 2022, 10:41:09 AM6/30/22
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to OWASP ZAP User Group
Hello.
I have found another issue that I would like to post. Currently we want to connect from owasp zap to a website where aws cognito is configured. I have set the login screen URL to "Login from Target URL" and "URL to GET Login Page" in configure Authentication Method. However, we could not confirm the log of the successful connection.
We apologize for the lack of information, but we would appreciate it if you could provide us with some guidance.
Simon Bennetts
unread,
Jun 30, 2022, 10:45:25 AM6/30/22
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
It should be possible to configure ZAP to handle it but it wont be easy.
Its not something I've tried or am planing to try anytime soon I'm afraid.
Has anyone else looked into this?
Cheers,
Simon
vel
unread,
Jul 1, 2022, 10:01:18 AM7/1/22
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to OWASP ZAP User Group
Hello.
Thank you for your answer. I shared the answer with the members and we have decided not to implement it at this time. Thanks for the very useful information.