Keluaran 1.3.0

Perubahan berikut telah dilakukan dalam keluaran ini:

Perubahan signifikan:

Ujian Kabur

Rentetan dalam suatu maklum balas sekarang boleh dikaburkan untuk cuba mencarikan kelemahan.
Token anti CRSF boleh dikesan dan dijanakan semula secara automatik semasa ujian kabur.
Fungsi ini adalah berasaskan kod daripada projek OWASP JBroFuzz.

Sijil SSL Dinamik

Sokongan bagi sambungan SSL telah ditambah baikkan dan diringkaskan.
Pengguna sekarang boleh mencipta sijil root mereka sendiri dan mengedarkan ini ke dalam klien HTTP mereka.

Mod Daemon dan API

Starting ZAP with the "-daemon" command line option will cause it to run in the background in 'headless' mode, meaning that no UI is displayed.
An initial API has been implemented in XML, JSON and HTML.
If ZAP is running as a daemon then the API is automatically enabled, otherwise the API must be enabled via the Options API screen.
The API can be navigated by opening http://zap/ in your browser when proxying via ZAP.

Integrasi Beanshell

The BeanShell is an interactive Java shell that can be used to execute BeanShell scripts.
These scripts are a simplified form of Java that use many elements from Java syntax, but in a simpler scripting format.
All Java code is also valid BeanShell code.
BeanShell integration in OWASP ZAP enables you to write scripts using the ZAP functions and data set.
This can be a very powerful feature for analyzing web applications.

Pengantarabangsaan Penuh

All display string are now fully internationalised.

Persetempatan

Out of the box support for the following languages:
    Bahasa Inggeris
    Bahasa Portugis Brazil
    Bahasa Cina
    Bahasa Perancis
    Bahasa Jerman
    Bahasa Greek
    Bahasa Indonesia
    Bahasa Jepun
    Bahasa Poland
    Bahasa Sepanyol

Perubahan kecil:

Paparan Heks

The Request, Response tabs now provide a 'Hex View' option which will display the request and response bodies in hex format.

Hasil Carian

The Search tab now displays all instances of a string found rather than just the first instance in each request or response.

URL Dikecualikan

URLs can be explicitly excluded from the active scanner, spider and from the proxy.

Sokongan menyalin

Most of the panels now provide a 'right click' 'Copy' menu option, including the Port Scan and Brute Force panels.

Sokongan Buat Asal/Buat Semula

All of the input fields now support Undo/Redo actions using the operating systems default Undo/Redo accelerators:

Sokongan proksi pengimbas port dan pilihan masa tamat

The Port Scanner can now use the outgoing proxy (if configured) and the timeout in milliseconds can also now be set.

Bebutang putus permintaan dan maklum balas

There are now 2 'Set Break' buttons to allow breaks to be set on all requests and all responses independently.

Bebutang memperluaskan tab Laman dan Maklumat

There are now 2 buttons which allow you to switch between having the Sites and Information tabs expanded.

Break tab icon changes colour when breakpoint hit

While the Break tab is not in use its icon is a grey cross:    .
When a breakpoint is hit the tab icon is changed to a red cross:    .

Masa tamat yang boleh dilaras

The Option: Connection screen allows you to set the timeout in seconds to make it easier to test slow applications.

Kemas kini perpustakaan

Most of the libraries used by ZAP have been updated to the latest versions.

Suatu Ikon yang baru :)

Thanks to Simon Egli and all others for submitting cool icon suggestions.

Isu-isu yang diketahui:

Mac OS C: SSL Dinamik dan Google Chrome

Currently Dynamic SSL is not working when using Google Chrome. This is because of an unresolved known issue with Google Chrome and Mac OS X Keychain. When importing OWASP ZAP's Root CA into the keychain and requesting a SSL website, an "Invalid certificate" error message is shown.

Lihat juga

     Pengenalanpengenalan kepada ZAP
     Keluaranset penuh keluaran
     Kreditorang ramai dan kumpulan yang telah membantu menghasilkan keluaran ini