Tela de opções do AJAX Spider

Esta tela permite que você configure opções do AJAX Spider . O Spider AJAX é um complemento para um rastreador chamado Crawljax. O complemento configura um proxy local no ZAP falar com o Crawljax. O spider AJAX permite a você percorrer aplicações web escritas em AJAX em muito mais profundidade do que o spider nativo. Use o spider AJAX se você estiver testando aplicativos web escritos em AJAX. Você também deve usar o spider nativo para uma cobertura completa de um aplicativo da web (por exemplo, para abranger comentários do HTML).

Configuration Options


Field Details Default
Browser AJAX Spider relies on an external browser to crawl the targeted site. You can specify which one you want to use. For more details on supported browsers refer to "Selenium" add-on help pages. Firefox Headless
Number of Browser Windows to Open You can configure the number of windows to be used by AJAX Spider. The more windows, the faster the process will be. Num cores
Maximum Crawl Depth The maximum depth that the crawler can reach. Zero means unlimited depth. 10
Maximum Crawl States The maximum number of states that the crawler should crawl. Zero means unlimited crawl states. 0 (unlimited)
Maximum Duration The maximum time that the crawler is allowed to run. Zero means unlimited running time. 60 minutes
Event Wait Time The time to wait after a client side event is fired. 1000 ms
Reload Wait Time The time to wait after URL is loaded. 1000 ms
Enable Browser Extensions When enabled, any browser extensions added by other add-ons will be enabled in the browsers used for crawling. False
Click Elements Once When enabled, the crawler attempts to interact with each element (e.g., by clicking) only once. If this is not set, the crawler will attempt to click multiple times. Unsetting this option is more rigorous but may take considerably more time. Verdadeiro
Use Random Values in Form Fields When enabled, inserts random values into form fields. Otherwise, it uses empty values. True
Click Default Elements Only When enabled, only elements "a", "button" and "input" will be clicked during crawl. Otherwise, it uses the table below to determine which elements will be clicked. For more in depth analysis, disable this and configure the clickable elements in the table. Verdadeiro
Select elements to click during crawl (table) The list of elements to crawl. This table only applies when "click default elements only" is not enabled. Use "enable all" for a more in depth analysis, though it may take somewhat longer. All enabled
Scope Check How the scope is checked:
  • Strict - enforces that all requests need to be in scope to be accessed, with the exception of the Allowed Resources.
  • Flexible - allows all requests to be accessed. This scope check does not use nor require configuring the Allowed Resources for targets that need domains out of scope to work. This scope check has the side effect of allowing out of scope domains to be accessed, but not crawled.
Strict
Logout Avoidance When enabled, the spider will avoid clicking common logout elements, which does not require manually excluding them. False
Allowed Resources (table) The list of allowed resources. The allowed resources are always fetched even if out of scope, allowing to include necessary resources (e.g. scripts) from 3rd-parties.

Veja também

     AJAX Spider para uma visão geral do AJAX Spider
     Aba do Spider Ajax para uma visão geral do AJAX Spider
     Diálogo do Spider Ajax para uma visão geral do Diálogo do Spider AJAX