Zest
Zest is an experimental specialized scripting language (also known as a domain-specific language)
originally developed by the Mozilla security team and is intended to be used in web oriented security tools.
Ito ay kasama sa ZAP ng default.
Engine Name
The engine is named Mozilla Zest, which should be used when manually/programmatically configuring ZAP.
Ang paglikha ng Zest na mga script
Mayroong iba't ibang mga paraan upang lumikha ng Zest na mga script:
I-recard ang isang bagong Zest script na button
- Pindutin ang 'Itala ang isang bagong Zest na script' na button sa pangunahing toolbar
- I-type in ang isang angkop na pangalan para sa iyong script sa "Magdagdag ng isang Script" na dialog
- Piliin ang prefix na gusto mong itala sa mga kahilingan para sa, o iwanan na blangko upang matala ang lahat nga mga kahilingan
- Pindutin ang 'Save' na button
- Ang 'Itala ang isang bagong Zest na script' button ay mananatili na naka-pindot, palitan ng "Pagtatala ng isang bagong script' at ipakita ang isang pulang icon.
Ang bagong Zest na script ay makikita sa mga script na tab na may pulang 'nagtatala' na icon.
Ang anumang kahilingan na iyong ginagawa sa ilalim ng naka-specify na prefix ay maidagdag sa script.
Pindutin ang 'Pagtatala ng isang bagong Zest na script' muli na ihinto ang pagtatala ng mga hiling.
Tandaan na maari lamang magtala ng 'Nakatayong mag-isa' Zest na ga script sa paraan na ito. Kung ikaw ay gusto na maglikha ng iabgn mga uri ng Zest na script ay dapat kang gumamit ng ibang mekanismo.
Maari mo din i-right click ang anumang Stand Alone na Zest na script at gamitin ang 'Pag-umpisa ng pagtatala' at 'Pag hinto sa pagtatala' na mga pindutan.
There are two primary methods for script recording: server-side and client-side. For client-side recording, we leverage the ZAP browser extension and a dedicated client add-on.
This combination allows us to efficiently capture and save user interactions in Zest scripts.
Ang bagong script na button
- Ang maglayag sa mga script tree na tab
- Ang pagpindut sa 'Bagong Script....' na button
- I-type in ang isang angkop na pangalan para sa iyong script sa 'Magdagdag ng Script' na dialog
- Pumili ng uri ng script (tingnan sa mga script add-on tulong na pahina para sa karagdagang na mga detalye)
- Pumili ng Zest script engine
- Pumilli ng isa sa mga template (kung kaugnay)
- Pindutin ang 'Save' na button
Anumang uri ng Zest script ay pwedeng mailikha sa ganitong paraan.
Ang pag-right clicking sa isang Zest na template
- Ang maglayag sa mga script na tab
- Palawigin ang 'Mga template' na node at hanapin ang isang template na gusto mong gamitin
- I-right click sa template at pumili ng 'Bagong Script...'
- Pindutin ang 'Save' na button
Any type of Zest script can be created this way.
Ang right clicking na mga hiling
- Maglayag ng anumang tab na nagpapakita ng mga hiling, kagaya ng kasaysayan na tab
- Pumili ng isa o higit pang mga hiling
- I-right click sa kanila
- Piliin ang 'Magdagdag sa Zest na Script' na menu na kung saan ay nagbibigay-daan sa iyo upang pumili ng isang umiiral na Stand Alone na script o lumikha ng bago
Note that you can only add request to 'Stand Alone' Zest scripts.
Ang Plug-n-Hack
If you are using a recent version of Firefox then you can create Zest scripts from within your browser.
- Pindutin ang 'Plug-n-Hack' na button sa ZAP 'Quick Start' na tab
- I-install ang Plug-n-Hack Firefox Add-on at tanggapin ang lahat na mga dialog
- Pindutin ang 'Shift F2' sa Firefox upang ma-access ang Developer Toolbar
- I-type ang 'zap na talaan sa global' upang simulan ang pagtatala sa isang bagong Zest script
- Anumang mga hiling na ginawa sa pamamagitan ng ZAP ay madadagdag sa script
- I-type ang 'zap na talaan off global' upang mahinto ang pagtatala sa script
Note that you can only record 'Stand Alone' Zest scripts in this way. If you want to create other types of Zest script you must use another mechanism.
Ang pag-edit ng Zest na mga script
Zest scripts are edited graphically in the Scripts tree tab.
Each statement is a node in the tree - double click nodes to edit the statement properties.
You can add, move and remove statements via right clicking the Zest nodes.
You can also add requests to 'Stand alone' Zest scripts by right clicking the requests in any of the other tabs.
There are also some right click options available when you select text in the Request or Response tabs.
Zest includes a set of 'built in' variables as well as allowing you to declare your own.
A right click menu is provided (where relevant) in the edit dialogs to allow you to paste in any of the available variable names.
Authentication Scripts
Authentication scripts can use a custom ZAP variable, called TOTP, to send a value to an input field with a TOTP code generated from the user's credentials TOTP data.
Import/Export Integration
When the Import/Export add-on is installed, Zest adds the following functionality:
Import Zest Script
An option to import messages from a Zest script file is available via the 'Import' menu ('Import Zest Script...').
The HTTP requests (and responses, if present) from the script are added to the Sites tree and History panel without replaying them.
Export as Zest Script
The Export menu supports exporting the history as a Zest script file.
This creates a Zest script containing the HTTP requests (and responses).
Automation Framework
When both the Import/Export and Automation add-ons are installed, Zest scripts can be imported and exported via the Automation Framework.
Import Job
Use the Import/Export add-on's import job with type: zest to import HTTP messages from a Zest script file (.zst):
- type: import
parameters:
type: zest
fileName: /path/to/script.zst
The HTTP requests (and responses, if present) from the script are added to the Sites tree and History panel without replaying them.
Export Job
Use the Import/Export add-on's export job with type: zest to export messages to a Zest script file.
The source parameter can be history (manually/proxied messages) or all (all messages including those generated by ZAP):
- type: export
parameters:
type: zest
source: history
fileName: /path/to/output.zst
Mga panlabas na link