Issue: Failed to attack URL: received a 403 response code
4,941 views
Skip to first unread message
asif.r...@gmail.com
unread,
Oct 25, 2016, 2:02:13 AM10/25/16
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to OWASP ZAP User Group
There is a wordpress site which I want to attack on, but this is getting fail due to "All in one wp-security" plugin on that site.
Failure displays error: Issue: Failed to attack URL: received a 403 response code
Is there a way to make it work?
Simon Bennetts
unread,
Oct 25, 2016, 4:11:52 AM10/25/16
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to OWASP ZAP User Group
I'm guessing you are using the "Quick Start" Attack option? This is a quick way to get started but will not handle things like authentication. ZAP can scan sites that require authentication but it will take a bit more effort on your part.
Can you proxy your browser through ZAP and explore your application? Can you identify the HTTP session? If so you can then try using an "active session" to force the active scanner to use the one you have started with your browser.
There are other options for handling this situation but this is a good place to start.
Cheers,
Simon
asif.r...@gmail.com
unread,
Oct 25, 2016, 4:27:04 AM10/25/16
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to OWASP ZAP User Group
Yes sure I can. Let me try configuring proxy settings, I hope that work for me.
If you can share any details that will help me in proxy setting then it would be really appreciable.
Thank you for help Mr. Simon
Simon Bennetts
unread,
Oct 25, 2016, 4:29:26 AM10/25/16
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message