Zest

Zestは、実験的な特殊スクリプト言語 (ドメイン固有言語またはDSLとも呼ばれます) です。元々はMozillaのセキュリティチームによって開発され、Webに特化したセキュリティツールで使用されることを目的としています。

これはZAPにデフォルトで含まれています。

エンジン名

エンジン名は Mozilla Zestです。ZAPを手動またはプログラムで設定する際には、この名称を使用してください。

Zestスクリプトの作り方

Zestスクリプトを作成するには、様々な方法があります:

「新規Zestスクリプトを記録」ボタン

新しいZestスクリプトは、「スクリプト」タブに赤い「記録中」アイコン付きで表示されます。
指定したプレフィックス配下で行われたリクエストは、すべてこのスクリプトに追加されます。
記録を停止するには、「新規Zestスクリプトを記録中」ボタンを再度クリックします。
この方法では「スタンドアロン」タイプのZestスクリプトしか記録できない点に注意してください。他のタイプのZestスクリプトを作成したい場合は、別の方法を用いる必要があります。

また、任意のスタンドアロンZestスクリプトを右クリックし、「記録を開始」および「記録を停止」ボタンを使用することもできます。

スクリプトの記録には、主にサーバーサイドとクライアントサイドの2つの方法があります。クライアントサイドでの記録には、ZAPブラウザ拡張機能と専用のクライアントアドオンを活用します。
この組み合わせにより、ユーザーの操作を効率的にZestスクリプトとしてキャプチャし、保存することができます。

「新しいスクリプト」ボタン

この方法では、あらゆるタイプのZestスクリプトを作成できます。

Zestテンプレートを右クリック

この方法では、あらゆるタイプのZestスクリプトを作成できます。

リクエストを右クリック

リクエストを追加できるのは「スタンドアロン」タイプのZestスクリプトのみである点に注意してください。

Plug-n-Hack

最近のバージョンのFirefoxを使用している場合、ブラウザ内からZestスクリプトを作成できます。
この方法では「スタンドアロン」タイプのZestスクリプトしか記録できない点に注意してください。他のタイプのZestスクリプトを作成したい場合は、別の方法を用いる必要があります。

Zestスクリプトの編集

Zestスクリプトは、「スクリプト」ツリータブでグラフィカルに編集します。
各ステートメントはツリー内のノードとして表現されます。ノードをダブルクリックすると、そのステートメントのプロパティを編集できます。
Zestのノードを右クリックすることで、ステートメントの追加、移動、削除が可能です。
また、他のタブに表示されているリクエストを右クリックして、「スタンドアロン」タイプのZestスクリプトに追加することもできます。
さらに、「リクエスト」タブや「レスポンス」タブでテキストを選択した際に利用できる、いくつかの右クリックオプションもあります。

Zestには一連の「組み込み」変数が含まれているほか、独自の変数を宣言することも可能です。
編集ダイアログでは(必要に応じて)右クリックメニューが提供され、利用可能な変数名を貼り付けることができます。

認証スクリプト

認証スクリプトでは、 TOTPというZAPのカスタム変数を使用できます。この変数は、ユーザーの認証情報にあるTOTPデータから生成されたTOTPコードを、入力フィールドに送信するために利用します。

Import/Export Integration

When the Import/Export add-on is installed, Zest adds the following functionality:

Import Zest Script

An option to import messages from a Zest script file is available via the 'Import' menu ('Import Zest Script...'). The HTTP requests (and responses, if present) from the script are added to the Sites tree and History panel without replaying them.

Export as Zest Script

The Export menu supports exporting the history as a Zest script file. This creates a Zest script containing the HTTP requests (and responses).

Automation Framework

When both the Import/Export and Automation add-ons are installed, Zest scripts can be imported and exported via the Automation Framework.

Import Job

Use the Import/Export add-on's import job with type: zest to import HTTP messages from a Zest script file (.zst):
  - type: import
    parameters:
      type: zest
      fileName: /path/to/script.zst
The HTTP requests (and responses, if present) from the script are added to the Sites tree and History panel without replaying them.

Export Job

Use the Import/Export add-on's export job with type: zest to export messages to a Zest script file. The source parameter can be history (manually/proxied messages) or all (all messages including those generated by ZAP):
  - type: export
    parameters:
      type: zest
      source: history
      fileName: /path/to/output.zst

外部リンク

     https://github.com/zaproxy/zest/ Zest GitHubリポジトリ、言語の詳細を含む