Form based + HTTP Sender script in command line

19 views
Skip to first unread message

Pritish Thapa

unread,
Mar 30, 2023, 8:29:12 AM3/30/23
to OWASP ZAP User Group
Hello everyone!

Is it possible to do the form based authentication ( scanning) along with the HTTP Sender script(which i have written) , through command prompt in windows?


Thanks


Pritish

Simon Bennetts

unread,
Mar 30, 2023, 8:43:28 AM3/30/23
to OWASP ZAP User Group
Yes, using the Automation Framework.
I'm begining to sound like a broken rocord arent I :)

Create and test your context and script in the Desktop.
Create an Automation plan in the desktop using that context.
Run and test it in the desktop.
Assuming it all works export the plan as a yaml file.

You can now run that yaml AF plan from the command line.

Cheers,

Simon

Pritish Thapa

unread,
Mar 30, 2023, 1:37:32 PM3/30/23
to OWASP ZAP User Group
That's amazing Simon, I wonder what else ZAP can do.

By the way, I had a query...
I did an ajax spider scan of my website in ZAP GUI, it was working well as it was opening the website through the browser and scanning each page, but suddenly after scanning 65,000 URLs, the pages became irresponsive and saying some proxy issue in the firefox browser itself! What could be the reason behind that?


Will appreciate your reply upon it :)


Pritish 
Reply all
Reply to author
Forward
0 new messages