Technology Detection
The Technology Detection add-on uses various patterns and finger prints to detect the technologies used by applications.
Ele funciona de maneira muito semelhante aos complementos do navegador Wappalyzer com as seguintes exceções:
- Ele não usa as 'variáveis JavaScript Globais' porque são difíceis de testar sem um navegador 'completo'
- It does not not show the confidence - this is still todo
- It does not match technologies on the basis of DOM properties as some properties are set by JavaScript in the browser after the response has passed through ZAP
- Ele permite que você veja as 'provas' usadas para detectar as tecnologias
Aba de tecnologia
Esta aba mostra todas as tecnologias detectadas no site selecionado.
Clicando com o botão direito em uma tecnologia irá exibir o menu 'Mostrar provas' com todos os regexes usados para detectá-la.
Selecting a regex will switch to the 'Search' tab and search through the history for that regex. Note: If multiple rows are selected
the menu will not be displayed.
Beside the site selection drop down is a button (with a Globe icon) which controls whether or not the Technology tab's display is linked to the selection in the Sites Tree.
Next is an Export button which can be used to export a CSV (comma separated values) file based on the
table information currently being displayed.
The toolbar also includes:
- An enable/disable toggle button which controls whether the technology detection passive scan rule is functioning or not. This enabled state is persisted between ZAP sessions.
- A button (with a gear icon) which will open the add-on's Options panel when clicked.
Reporting
Technology data is available to reports via the
TechJobResultData class.
External Links
| |
Enthec Webappanalyzer |
This project is a continuation of the iconic Wappalyzer that went private in August 2023. |
| |
https://www.wappalyzer.com/ |
The Wappalyzer Homepage |
| |
https://github.com/wappalyzer/wappalyzer |
As of early August 2023 the Wappalyzer Repository is no longer public. |