Technology Detection
The Technology Detection add-on uses various patterns and finger prints to detect the technologies used by applications.
它的工作方式与Wappalyzer浏览器加载项非常相似,以下情况例外:
- 它不能使用"Global JavaScript变量",因为在没有"完整的"浏览器情况下,很难检测。
- It does not not show the confidence - this is still todo
- It does not match technologies on the basis of DOM properties as some properties are set by JavaScript in the browser after the response has passed through ZAP
- 它允许您参阅用于检测技术的"证据"
技术选项卡
此选项卡显示了所有已选站点上的检测技术。
右键单击技术将会显示一个"显示证据"菜单,在这之下是所有用于检测它的正则表达式。
Selecting a regex will switch to the 'Search' tab and search through the history for that regex. Note: If multiple rows are selected
the menu will not be displayed.
Beside the site selection drop down is a button (with a Globe icon) which controls whether or not the Technology tab's display is linked to the selection in the Sites Tree.
Next is an Export button which can be used to export a CSV (comma separated values) file based on the
table information currently being displayed.
The toolbar also includes:
- An enable/disable toggle button which controls whether the technology detection passive scan rule is functioning or not. This enabled state is persisted between ZAP sessions.
- A button (with a gear icon) which will open the add-on's Options panel when clicked.
Reporting
Technology data is available to reports via the
TechJobResultData class.
External Links
| |
Enthec Webappanalyzer |
This project is a continuation of the iconic Wappalyzer that went private in August 2023. |
| |
https://www.wappalyzer.com/ |
The Wappalyzer Homepage |
| |
https://github.com/wappalyzer/wappalyzer |
As of early August 2023 the Wappalyzer Repository is no longer public. |