Zest
Zest is an experimental specialized scripting language (also known as a domain-specific language)
originally developed by the Mozilla security team and is intended to be used in web oriented security tools.
Se incluye con ZAP por defecto.
Engine Name
The engine is named Mozilla Zest, which should be used when manually/programmatically configuring ZAP.
Crear scripts Zest
Hay una variedad de maneras de crear scripts de Zest:
Registrar un nuevo botón de script Zest
- Presione el botón "Registrar un nuevo script Zest" en la barra de tareas principal
- Escriba un nombre apropiado para el script en el cuadro de diálogo "Agregar un script Zest"
- Seleccione el prefijo que desee para registrar solicitudes, o dejar en blanco para registrar todas las solicitudes
- Presione el botón "Guardar"
- El botón "Registrar un nuevo script Zest" siempre estará presionado, cambia a "Registrando un nuevo script Zest" y muestra un icono rojo.
El nuevo script Zest aparecerá en la pestaña Scripts con un icono rojo de "registrando".
Cualquier solicitud que se haga bajo el prefijo especificado será agregado al script.
Presione de nuevo "Registrando un nuevo script Zest" para detener el registro de solicitudes.
Tenga en cuenta que solo se puede registrar de esta manera scripts Zest "Independientes". Si desea crear otros tipos de script Zest se debe utilizar otro mecanismo.
También se puede hacer clic derecho en cualquier script Zest Idependiente y utilizar los botones "Iniciar registro" y "Detener registro".
There are two primary methods for script recording: server-side and client-side. For client-side recording, we leverage the ZAP browser extension and a dedicated client add-on.
This combination allows us to efficiently capture and save user interactions in Zest scripts.
Nuevo Botón Script
- Navegue hasta el árbol de pestañas de Scripts
- Presione el botón "Nuevo Script..."
- Escriba un nombre apropiado para el script en el cuadro de diálogo "Nuevo Script"
- Seleccione el tipo de script (consulte la página de ayuda de complemento Scripts para más detalles)
- Seleccione el motor de script Zest
- Seleccione una de las plantillas (si procede)
- Presione el botón "Guardar"
Cualquier tipo de script Zest puede crearse de esta manera.
Hacer clic derecho en una plantilla Zest
- Navegue hasta el árbol de pestañas Scripts
- Expanda el nodo de "Plantillas" y encuentre la plantilla que desea utilizar
- Haga clic derecho en la plantilla y seleccione "Nuevo Script..."
- Presione el botón "Guardar"
Any type of Zest script can be created this way.
Hacer clic derecho en las solicitudes
- Navegue hasta cualquier pestaña que muestre solicitudes, como la pestaña de Historial
- Seleccione una o mas solicitudes
- Haga clic derecho sobre ellos
- Seleccione el menú "Agregar a Script Zest" el cual permite seleccionar un script "Stand Alone" existente o crear uno nuevo
Note that you can only add request to 'Stand Alone' Zest scripts.
Plug-n-Hack
If you are using a recent version of Firefox then you can create Zest scripts from within your browser.
- Presione el botón "Plug-n-Hack" sobre la pestaña "Inicio rápido" de ZAP
- Instale el complemento de Firefox Plug-n-Hack y acepte todos los cuadros de diálogo
- Presione "Shift F2" en Firefox para acceder a la barra de herramientas de desarrollador
- Escriba "zap record on global" para empezar a registrar un nuevo script Zest
- Cualquier solicitud que se haga a través de ZAP se añadirá al script
- Escriba "zap record off global" para detener el registro un script
Note that you can only record 'Stand Alone' Zest scripts in this way. If you want to create other types of Zest script you must use another mechanism.
Editar script Zest
Zest scripts are edited graphically in the Scripts tree tab.
Each statement is a node in the tree - double click nodes to edit the statement properties.
You can add, move and remove statements via right clicking the Zest nodes.
You can also add requests to 'Stand alone' Zest scripts by right clicking the requests in any of the other tabs.
There are also some right click options available when you select text in the Request or Response tabs.
Zest includes a set of 'built in' variables as well as allowing you to declare your own.
A right click menu is provided (where relevant) in the edit dialogs to allow you to paste in any of the available variable names.
Authentication Scripts
Authentication scripts can use a custom ZAP variable, called TOTP, to send a value to an input field with a TOTP code generated from the user's credentials TOTP data.
Import/Export Integration
When the Import/Export add-on is installed, Zest adds the following functionality:
Import Zest Script
An option to import messages from a Zest script file is available via the 'Import' menu ('Import Zest Script...').
The HTTP requests (and responses, if present) from the script are added to the Sites tree and History panel without replaying them.
Export as Zest Script
The Export menu supports exporting the history as a Zest script file.
This creates a Zest script containing the HTTP requests (and responses).
Automation Framework
When both the Import/Export and Automation add-ons are installed, Zest scripts can be imported and exported via the Automation Framework.
Import Job
Use the Import/Export add-on's import job with type: zest to import HTTP messages from a Zest script file (.zst):
- type: import
parameters:
type: zest
fileName: /path/to/script.zst
The HTTP requests (and responses, if present) from the script are added to the Sites tree and History panel without replaying them.
Export Job
Use the Import/Export add-on's export job with type: zest to export messages to a Zest script file.
The source parameter can be history (manually/proxied messages) or all (all messages including those generated by ZAP):
- type: export
parameters:
type: zest
source: history
fileName: /path/to/output.zst
Enlaces externos