External Redirect vulnerability check failed forpaarmeter due to an I/O error

47 views
Skip to first unread message

Antonio AE

unread,
Sep 22, 2021, 2:52:56 AM9/22/21
to OWASP ZAP User Group
Hello, good morning,

  I am currently doing some active scans on an internal URL with no success: after several hours running the active scan I get this message:

19825663 [ZAP-ActiveScanner-1] WARN  org.zaproxy.zap.extension.ascanrules.ExternalRedirectScanRule - External Redirect vulnerability check failed for parameter [iNumPage]and payload [4100518615406984558.owasp.org] due to an I/O error
java.net.SocketTimeoutException: Read timed out
        at java.net.SocketInputStream.socketRead0(Native Method) ~[?:1.8.0_302]
        at java.net.SocketInputStream.socketRead(SocketInputStream.java:116) ~[?:1.8.0_302]
        at java.net.SocketInputStream.read(SocketInputStream.java:171) ~[?:1.8.0_302]
        at java.net.SocketInputStream.read(SocketInputStream.java:141) ~[?:1.8.0_302]
        at sun.security.ssl.SSLSocketInputRecord.read(SSLSocketInputRecord.java:464) ~[?:1.8.0_302]
.....

  I don't know how to interpret this message, I mean, I don't know what could be the reasons for it, has something similar happened to someone (and how did you solve it)?

  Thank all of you in advance and best regards,


    Antonio


thc...@gmail.com

unread,
Sep 22, 2021, 3:34:46 AM9/22/21
to zaprox...@googlegroups.com
Hi.

Is the target responsive when that happens? Could be that the target is
under heavy load and not able to answer in time.

Best regards.

Antonio AE

unread,
Sep 22, 2021, 7:05:27 AM9/22/21
to OWASP ZAP User Group
Hello,

  Honestly, I think yes, but I don't know because I run the active scan at night and I see the results in the morning. It's true that we have to re-start de app because it is not available/responsive but I have not verifed the system just when the error happens.

  Thank you very mucu for your answer, I will try and notice you up.

  Regards,


     Antonio
Reply all
Reply to author
Forward
0 new messages