ZAPit

クイックスタートアドオンは、指定されたURLのクイックな「偵察 (reconnaissance)」スキャンを実行するために、以下のコマンドラインオプションをサポートしています。

オプションを複数回指定することで、複数のURLを指定できます:

-cmd オプションを指定する必要があります。指定されていない場合、-zapit オプションは無視されます。

http:// または https:// のいずれかで始まるURLを指定しない場合、ZAPは両方のスキームをスキャンします。

ZAPitスキャンは、スキャンを実行する前に新しいZAPセッションを開始します。そのため、保持したいセッションでZAPを起動しないでください。

ZAPitスキャンが現在実行する内容は以下の通りです:

  1. ターゲットURLへのリクエストを1回実行する
  2. 行われたすべてのリクエストとレスポンス (リダイレクトによるものなど) に関する主要な詳細を報告する
  3. 技術検出アドオン (インストールされている場合) によって検出されたすべてのテクノロジーを報告する
  4. 検出されたアラートの概要を報告する
  5. ルートURLからのいくつかの統計情報を報告する

出力例:

ZAPit scan of https://www.example.com
Requests:
	https://www.example.com
		Request took 325 msec
		Response code 200 (OK)
		Response body size 1,256 bytes
		No request cookies
		No response cookies
Technology:
	Amazon ECS
	Amazon Web Services
	Azure
	Azure CDN
	Docker
Number of alerts: 9
	Medium: Content Security Policy (CSP) Header Not Set : ""
	Medium: Missing Anti-clickjacking Header : "x-frame-options"
	Low: Permissions Policy Header Not Set : ""
	Low: Server Leaks Version Information via "Server" HTTP Response Header Field : "ECS (dcb/7EC9)"
	Low: Strict-Transport-Security Header Not Set : ""
	Low: X-Content-Type-Options Header Missing : "x-content-type-options"
	Informational: Re-examine Cache-control Directives : "max-age=604800"
	Informational: Retrieved from Cache : "HIT"
	Informational: Storable and Cacheable Content : "max-age=604800"
Root page stats:
	Content type: text/html; charset=UTF-8
	Number of HTML tags: 24
	Number of HTML links: 1
	Number of HTML forms: 0
	Number of HTML input fields: 0
	
この機能はまだ初期段階にあり、さらなる拡張が計画されています。

関連情報

     クイックスタート クイックスタートの概要