community-scripts
A collection of ZAP scripts and tips provided by the community - pull requests very welcome!
파일 탐색기
최종 버전 다운로드 (.zip)- ci.yml
- codeql.yml
- crowdin-upload-files.yml
- prepare-release-add-on.yml
- release-add-on.yml
- dependabot.yml
- bxss.py
- corsair.py
- Cross Site WebSocket Hijacking.js
- cve-2019-5418.js
- gof_lite.js
- JWT None Exploit.js
- OpenModelContextProtocolServer.js
- RCE.py
- README.md
- SSTI.js
- SSTI.py
- TestInsecureHTTPVerbs.py
- User defined attacks.js
- CasAuthentication.js
- DjangoAuthentication.js
- GetsWithRedirectThenPost.js
- KratosApiAuthentication.js
- KratosBrowserAuthentication.js
- MagentoAuthentication.js
- MediaWikiApiAuthentication.js
- MediaWikiAuthentication.js
- OfflineTokenRefresh.js
- README.md
- TwoStepAuthentication.js
- CyberChefExample.js
- double-spacer.js
- JwtDecode.js
- README.md
- arpSyndicateSubdomainDiscovery.js
- HTTP Message Logger.js
- README.md
- ScanMonitor.js
- Simple Reverse Proxy.js
- ZAP onEvent Handler.js
- gradle-wrapper.jar
- gradle-wrapper.properties
- crowdin.yml
- add_msgs_sites_tree.js
- addCacheBusting.js
- FuzzerStopOnStatusCode.js
- http_status_code_filter.py
- random_x_forwarded_for_ip.js
- randomUserAgent.js
- README.md
- showDifferences.js
- unexpected_responses.js
- add-extra-headers.js
- add-more-headers.js
- add_header_request.py
- add_header_response.py
- AddBearerTokenHeader.js
- AlertOnHttpResponseCodeErrors.js
- AlertOnUnexpectedContentTypes.js
- aws-signing-for-zap.py
- Capture and Replace Anti CSRF Token.js
- change_request.py
- change_response.py
- fingerprinter.js
- full-session-n-csrf-nashorn.js
- greenbone-maintain-auth.js
- inject-xss.js
- inject_js_in_html_page.js
- juice-shop-maintain-auth.js
- keep-cookies-going.js
- LogMessages.js
- maintain-jwt.js
- README.md
- RsaEncryptPayloadForZap.py
- RsaSigningForZap.py
- UpgradeHttp1To2.js
- js-auth.bat
- js-auth.sh
- js-test.bat
- js-test.sh
- juiceshop-auth.yaml
- juiceshop-test.yaml
- JuiceShopAuthentication.js
- JuiceShopHttpSender.js
- JuiceShopReset.js
- JuiceShopSelenium.js
- JuiceShopSession.js
- README.md
- ApiScanExample.yaml
- AuthCheckBodgeit.yaml
- BaselineExample.yaml
- BrowserAuthTest.yaml
- FullScanBrokenCrystals.yaml
- FullScanCrApiAuth.yaml
- FullScanDvwaAuth.yaml
- FullScanExample.yaml
- FullScanGinNJuiceAuth.yaml
- FullScanTestfireAuth.yaml
- README.md
- ScriptEnvVarAccess.yaml
- docker-wrapper
- mass-baseline-default.conf
- mass-baseline.sh
- mass-basescore.py
- mass-basewrapper.sh
- README.md
- __init__.py
- scan.py
- zapAddCsp.js
- __init__.py
- zap_session.py
- __init__.py
- config.py
- shared.py
- rules_config_demo.txt
- shutdown-zap.sh
- start-zap.sh
- targets_file_demo.txt
- README.md
- requirements.txt
- run_scan.py
- run_session_setup.py
- DynatraceHooks.py
- export_session.py
- LogMessagesHook.py
- README.md
- template.py
- bypass-waf.png
- emulate-ios.png
- false-true-admin.png
- false-true-email.png
- finding-idor.png
- finding-xss-referer.png
- finding-xss-user.png
- hackerone-header.png
- log4shell.png
- shellshock.png
- show-hidden-1.png
- show-hidden-2.png
- show-hidden-3.png
- xbb-header.png
- README.md
- README.md
- edge_file_location.png
- edge_properties.png
- edge_shortcut_properties.png
- launch.png
- selenium_options.png
- README.md
- README.md
- README.md
- CHANGELOG.md
- README.md
- clacks.js
- CookieHTTPOnly.js
- detect_csp_notif_and_reportonly.js
- detect_samesite_protection.js
- f5_bigip_cookie_internal_ip.js
- find base64 strings.js
- Find Credit Cards.js
- Find Emails.js
- Find Hashes.js
- Find HTML Comments.js
- Find IBANs.js
- Find Internal IPs.js
- find_reflected_params.py
- google_api_keys_finder.js
- HUNT.py
- JavaDisclosure.js
- Mutliple Security Header Check.js
- README.md
- Report non static sites.js
- RPO.js
- s3.js
- Server Header Disclosure.js
- SQL injection detection.js
- Telerik Using Poor Crypto.js
- Upload form discovery.js
- X-Powered-By_header_checker.js
- associated_fields.py
- bruteforce.py
- README.md
- securerandom.js
- deflate_gzip_encoding.py
- README.md
- sqlmap - apostrophemask.py
- sqlmap - apostrophenullencode.py
- sqlmap - chardoubleencode.py
- sqlmap - charencode.py
- sqlmap - charunicodeencode.py
- sqlmap - equaltolike.py
- sqlmap - lowercase.py
- sqlmap - percentage.py
- sqlmap - randomcase.py
- sqlmap - space2comments.py
- to-hex.js
- Add spoofed CORS origin.zst
- Change all POSTs to GETs.zst
- Convert HTTPS links to HTTP.zst
- Disable browser XSS protection.zst
- Drop requests by response code.js
- Drop requests not in scope.js
- Drop requests via URL regexes.zst
- dropCookiesSelectively.js
- Emulate Android.js
- Emulate Chrome.js
- Emulate Firefox.js
- Emulate IE.js
- Emulate iOS.js
- Emulate Safari.js
- Hide Referer header.zst
- Ignore cookies.zst
- README.md
- Remove all JavaScript form validation.zst
- Remove CSP.zst
- Remove data validation tags in response body.zst
- Remove HSTS headers.zst
- Remove object tags in response body.zst
- Remove script tags in response body.zst
- Remove secure flag from cookies.zst
- Replace in request body.zst
- Replace in request header.zst
- Replace in request or response body.js
- Replace in response body.zst
- Replace in response header.zst
- Require non-cached response.zst
- Require non-compressed responses.zst
- Return fake response.js
- Show commented out in response body.zst
- Useragent Replace.js
- WAF_Bypass.js
- FillOTPInMFA.js
- README.md
- Selenium Juice Shop.js
- README.md
- Juice Shop Session Management.js
- README.md
- ExtensionCommunityScripts.java
- script-share.png
- communityScripts.html
- helpset.hs
- index.xml
- map.jhm
- toc.xml
- script-share.png
- communityScripts.html
- helpset_ar_SA.hs
- index.xml
- map.jhm
- toc.xml
- script-share.png
- communityScripts.html
- helpset_az_AZ.hs
- index.xml
- map.jhm
- toc.xml
- script-share.png
- communityScripts.html
- helpset_bs_BA.hs
- index.xml
- map.jhm
- toc.xml
- script-share.png
- communityScripts.html
- helpset_da_DK.hs
- index.xml
- map.jhm
- toc.xml
- script-share.png
- communityScripts.html
- helpset_de_DE.hs
- index.xml
- map.jhm
- toc.xml
- script-share.png
- communityScripts.html
- helpset_el_GR.hs
- index.xml
- map.jhm
- toc.xml
- script-share.png
- communityScripts.html
- helpset_es_ES.hs
- index.xml
- map.jhm
- toc.xml
- script-share.png
- communityScripts.html
- helpset_fa_IR.hs
- index.xml
- map.jhm
- toc.xml
- script-share.png
- communityScripts.html
- helpset_fil_PH.hs
- index.xml
- map.jhm
- toc.xml
- script-share.png
- communityScripts.html
- helpset_fr_FR.hs
- index.xml
- map.jhm
- toc.xml
- script-share.png
- communityScripts.html
- helpset_hi_IN.hs
- index.xml
- map.jhm
- toc.xml
- script-share.png
- communityScripts.html
- helpset_hr_HR.hs
- index.xml
- map.jhm
- toc.xml
- script-share.png
- communityScripts.html
- helpset_hu_HU.hs
- index.xml
- map.jhm
- toc.xml
- script-share.png
- communityScripts.html
- helpset_id_ID.hs
- index.xml
- map.jhm
- toc.xml
- script-share.png
- communityScripts.html
- helpset_it_IT.hs
- index.xml
- map.jhm
- toc.xml
- script-share.png
- communityScripts.html
- helpset_ja_JP.hs
- index.xml
- map.jhm
- toc.xml
- script-share.png
- communityScripts.html
- helpset_ko_KR.hs
- index.xml
- map.jhm
- toc.xml
- script-share.png
- communityScripts.html
- helpset_ms_MY.hs
- index.xml
- map.jhm
- toc.xml
- script-share.png
- communityScripts.html
- helpset_pl_PL.hs
- index.xml
- map.jhm
- toc.xml
- script-share.png
- communityScripts.html
- helpset_pt_BR.hs
- index.xml
- map.jhm
- toc.xml
- script-share.png
- communityScripts.html
- helpset_ro_RO.hs
- index.xml
- map.jhm
- toc.xml
- script-share.png
- communityScripts.html
- helpset_ru_RU.hs
- index.xml
- map.jhm
- toc.xml
- script-share.png
- communityScripts.html
- helpset_si_LK.hs
- index.xml
- map.jhm
- toc.xml
- script-share.png
- communityScripts.html
- helpset_sk_SK.hs
- index.xml
- map.jhm
- toc.xml
- script-share.png
- communityScripts.html
- helpset_sl_SI.hs
- index.xml
- map.jhm
- toc.xml
- script-share.png
- communityScripts.html
- helpset_sq_AL.hs
- index.xml
- map.jhm
- toc.xml
- script-share.png
- communityScripts.html
- helpset_sr_CS.hs
- index.xml
- map.jhm
- toc.xml
- script-share.png
- communityScripts.html
- helpset_sr_SP.hs
- index.xml
- map.jhm
- toc.xml
- script-share.png
- communityScripts.html
- helpset_tr_TR.hs
- index.xml
- map.jhm
- toc.xml
- script-share.png
- communityScripts.html
- helpset_ur_PK.hs
- index.xml
- map.jhm
- toc.xml
- script-share.png
- communityScripts.html
- helpset_zh_CN.hs
- index.xml
- map.jhm
- toc.xml
- cve-2021-22214.yml
- Messages.properties
- Messages_ar_SA.properties
- Messages_az_AZ.properties
- Messages_bn_BD.properties
- Messages_bs_BA.properties
- Messages_ceb_PH.properties
- Messages_da_DK.properties
- Messages_de_DE.properties
- Messages_el_GR.properties
- Messages_es_ES.properties
- Messages_fa_IR.properties
- Messages_fil_PH.properties
- Messages_fr_FR.properties
- Messages_ha_HG.properties
- Messages_he_IL.properties
- Messages_hi_IN.properties
- Messages_hr_HR.properties
- Messages_hu_HU.properties
- Messages_id_ID.properties
- Messages_it_IT.properties
- Messages_ja_JP.properties
- Messages_ko_KR.properties
- Messages_mk_MK.properties
- Messages_ms_MY.properties
- Messages_nb_NO.properties
- Messages_nl_NL.properties
- Messages_pcm_NG.properties
- Messages_pl_PL.properties
- Messages_pt_BR.properties
- Messages_pt_PT.properties
- Messages_ro_RO.properties
- Messages_ru_RU.properties
- Messages_si_LK.properties
- Messages_sk_SK.properties
- Messages_sl_SI.properties
- Messages_sq_AL.properties
- Messages_sr_CS.properties
- Messages_sr_SP.properties
- Messages_tr_TR.properties
- Messages_uk_UA.properties
- Messages_ur_PK.properties
- Messages_vi_VN.properties
- Messages_yo_NG.properties
- Messages_zh_CN.properties
- Messages_zh_TW.properties
- VerifyScripts.java
- Active scan rule list.js
- alertAndPluginDetails.js
- devTools.js
- domainFinder.js
- enableDebugLogging.js
- example_library.js
- extHistoryEnumerator.py
- historySourceTagger.js
- Juice shop authentication by form.js
- Juice shop authentication by google.js
- load_context_from_burp.py
- load_function_example.js
- Loop through alerts.js
- Loop through history table.js
- Open Fortune 500 websites in a browser.zst
- past_cookies_jar.py
- Persona Create Account.zst
- PrivateMethodAccess.js
- README.md
- scan_rule_list.js
- SecurityCrawlMazeScore.js
- Split download extract.rb
- Traverse sites tree.js
- WebSocketExportToOrg.py
- window_creation_template.js
- window_creation_template.py
- curl_command_generator.js
- cve-2021-22214.js
- cve-2021-41773-apache-path-trav.js
- dns-email-spoofing.js
- ElasticSearchExploit.js
- Find HTML comments.js
- Find largest subtree.js
- json_csrf_poc_generator.js
- README.md
- Remove 302s.js
- request_to_xml.js
- Resend as a GET request.zst
- search cvedetails using target server header.js
- Search www.xssposed.org for known XSS.js
- SQLMapCommandGenerator.js
- WordPress User Enumeration.js
- AddUrlParams.js
- CompoundCookies.js
- JsonStrings.js
- param_name_variant.js
- README.md
- README.md
- README.md
- .gitattributes
- .gitignore
- build.gradle.kts
- CHANGELOG.md
- CONTRIBUTING.md
- gradle.properties
- gradlew
- gradlew.bat
- LICENSE
- README.md
- RELEASING.md
- settings.gradle.kts
🚀 설치 가이드
1. 코드 내려받기
git clone https://github.com/zaproxy/community-scripts
깃허브에서 프로젝트 코드 전체를 내 컴퓨터로 내려받습니다.
cd community-scripts
방금 내려받은 프로젝트 폴더 안으로 이동합니다.
2. Gradle (Java/Kotlin)
보통 추천사전 준비물
- Git GitHub에서 프로젝트 코드를 내려받으려면 필요합니다.
- JDK (Java) Java/Kotlin 프로젝트를 빌드/실행하려면 필요합니다.
- Gradle 레포에 포함된 gradlew(Gradle Wrapper)를 쓰면 Gradle을 따로 설치할 필요가 없습니다.
./gradlew build
Gradle로 빌드를 진행합니다.
BUILD SUCCESSFUL 메시지가 뜨면 성공입니다. build/ 폴더에 결과물이 생성됩니다.
이 레포의 README에 적힌 실제 명령어를 그대로 가져왔습니다.
3. Python
쉬움사전 준비물
pip install -r other/api/sdlc-integration/requirements.txt
requirements.txt 등에 명시된 파이썬 라이브러리를 설치합니다.
python <실행할 파일명>.py # README에서 정확한 실행 파일명을 확인하세요
파이썬 스크립트(또는 모듈)를 실행합니다.
에러 메시지 없이 실행되고 터미널에 안내 문구가 출력되면 정상입니다.
// repository documentation
Was this content helpful?
(0 ratings)
