Zest
Zest is an experimental specialized scripting language (also known as a domain-specific language)
originally developed by the Mozilla security team and is intended to be used in web oriented security tools.
Ini termasuk secara default dengan ZAP.
Engine Name
The engine is named Mozilla Zest, which should be used when manually/programmatically configuring ZAP.
Membuat skrip Zest
Ada berbagai cara untuk membuat skrip Zest:
Tombol Rekam sebuah skrip Zest baru
- Tekan tombol 'Rekam sebuah skrip Zest baru' pada toolbar utama
- Ketik nama yang cocok untuk skrip Anda di dialog 'Tambah sebuah skrip Zest'
- Pilih awalan yang anda inginkan untuk mencatat permintaan, atau biarkan kosong untuk mencatat semua permintaan
- Tekan tombol 'Simpan'
- Tombol 'Rekam sebuah skrip Zest baru' akan tetap ditekan, berubah menjadi 'Sedang merekam sebuah skrip Zest baru' dan menampilkan ikon merah.
Skrip Zest baru akan ditampilkan di tab Skrip dengan ikon merah 'merekam'.
Setiap permintaan yang Anda buat di bawah prefiks yang dinyatakan akan ditambahkan ke skrip.
Tekan tombol 'Sedang merekam sebuah skrip Zest baru' lagi untuk berhenti merekam permintaan.
Perhatikan bahwa anda hanya dapat merekam 'Stand Alone' Semangat script dengan cara ini. Jika anda ingin membuat jenis lain dari Semangat script anda harus menggunakan mekanisme lain.
Anda juga dapat klik kanan setiap Stand Alone Semangat script dan menggunakan 'Start recording' dan 'Stop recording' tombol.
There are two primary methods for script recording: server-side and client-side. For client-side recording, we leverage the ZAP browser extension and a dedicated client add-on.
This combination allows us to efficiently capture and save user interactions in Zest scripts.
Tombol Skrip Baru
- Navigasi ke tab pohon Skrip
- Tekan tombol 'Skrip Baru...'
- Ketik suatu nama yang cocok untuk skrip Anda di dialog 'Skrip Baru'
- Pilih jenis script (lihat Script add-on halaman bantuan untuk informasi lebih lanjut)
- Pilih mesin skrip Zest
- Pilih salah satu template (jika relevan)
- Tekan tombol 'Simpan'
Setiap jenis dari skrip Zest bisa dibuat melalui cara ini.
Klik kanan template Zest
- Arahkan ke tab pohon Skrip
- Perluas node 'Templates' dan cari sebuah template yang anda ingin gunakan
- Klik kanan pada template dan pilih 'New Script...'
- Tekan tombol 'Save'
Any type of Zest script can be created this way.
Klik kanan permintaan
- Arahkan ke tab mana saja yang menampilkan permintaan, seperti tab riwayat
- Pilih satu permintaan atau lebih
- Klik kanan pada mereka
- Pilih menu 'Tambah ke Zest Script' yang akan memungkinkan anda untuk memilih Stand Alone Script yang ada atau buat yang baru
Note that you can only add request to 'Stand Alone' Zest scripts.
Plug-n-Hack
If you are using a recent version of Firefox then you can create Zest scripts from within your browser.
- Tekan tombol 'Plug-n-Hack' pada tab 'Quick Start' ZAP
- Memasang Add-on Plug-n-Hack Firefox dan terima semua dialog
- Tekan 'Shift F2' dalam Firefox untuk mengakses Toolbal pengembang
- Tuliskan 'zap record on global' untuk mulai merekam Zest script baru
- Setiap permintaan yang anda buat melalui Zap akan ditambahkan ke script
- Ketik 'zap record off global' untuk menghentikan rekaman script
Note that you can only record 'Stand Alone' Zest scripts in this way. If you want to create other types of Zest script you must use another mechanism.
Menyunting skrip Zest
Zest scripts are edited graphically in the Scripts tree tab.
Each statement is a node in the tree - double click nodes to edit the statement properties.
You can add, move and remove statements via right clicking the Zest nodes.
You can also add requests to 'Stand alone' Zest scripts by right clicking the requests in any of the other tabs.
There are also some right click options available when you select text in the Request or Response tabs.
Zest includes a set of 'built in' variables as well as allowing you to declare your own.
A right click menu is provided (where relevant) in the edit dialogs to allow you to paste in any of the available variable names.
Authentication Scripts
Authentication scripts can use a custom ZAP variable, called TOTP, to send a value to an input field with a TOTP code generated from the user's credentials TOTP data.
Import/Export Integration
When the Import/Export add-on is installed, Zest adds the following functionality:
Import Zest Script
An option to import messages from a Zest script file is available via the 'Import' menu ('Import Zest Script...').
The HTTP requests (and responses, if present) from the script are added to the Sites tree and History panel without replaying them.
Export as Zest Script
The Export menu supports exporting the history as a Zest script file.
This creates a Zest script containing the HTTP requests (and responses).
Automation Framework
When both the Import/Export and Automation add-ons are installed, Zest scripts can be imported and exported via the Automation Framework.
Import Job
Use the Import/Export add-on's import job with type: zest to import HTTP messages from a Zest script file (.zst):
- type: import
parameters:
type: zest
fileName: /path/to/script.zst
The HTTP requests (and responses, if present) from the script are added to the Sites tree and History panel without replaying them.
Export Job
Use the Import/Export add-on's export job with type: zest to export messages to a Zest script file.
The source parameter can be history (manually/proxied messages) or all (all messages including those generated by ZAP):
- type: export
parameters:
type: zest
source: history
fileName: /path/to/output.zst
Tautan eksternal