Zest
Zest is an experimental specialized scripting language (also known as a domain-specific language)
originally developed by the Mozilla security team and is intended to be used in web oriented security tools.
ZAP ile birlikte varsayılan olarak dahildir.
Engine Name
The engine is named Mozilla Zest, which should be used when manually/programmatically configuring ZAP.
Zest Komut Dosyaları Oluşturma
Zest komut dosyaları oluşturmanın çeşitli yolları vardır:
Yeni bir Zest komut dosyası kaydet Butonu
- Ana araç çubuğunda 'Yeni bir Zest komut dosyası kaydet' butonuna basın
- 'Bir Zest Komut Dosyası Ekle' iletişim kutusunda komut dosyanız için uygun bir isim girin
- İstekleri kaydetmek istediğiniz bir önek seçin, veya tüm istekleri kaydetmek için boş bırakın
- 'Kaydet' butonuna basın
- 'Yeni bir Zest komut dosyası kaydet' butonu basılı kalacak, 'Yeni bir Zest komut dosyası kaydediliyor' olarak değişecek ve kırmızı bir simge gösterecek.
Yeni Zest komut dosyası, Komut Dosyaları sekmesinde kırmızı bir 'kaydetme' simgesi ile gösterilecektir.
Belirtilen önekin altında yaptığınız tüm istekler komut dosyasına eklenecektir.
Kaydetme isteklerini durdurmak için 'Yeni bir Zest komut dosyası kaydediliyor' butonuna tekrar basın.
Bu yöntemle yalnızca 'Bağımsız' Zest komut dosyalarını kaydedebileceğinizi unutmayın. Zest komut dosyalarının diğer türlerini oluşturmak isterseniz diğer yöntemleri kullanmalısınız.
Ayrıca herhangi bir Bağımsız Zest komut dosyasına sağ tıklayabilir ve 'Kaydı başlat' ve 'Kaydı durdur' butonlarını kullanabilirsiniz.
There are two primary methods for script recording: server-side and client-side. For client-side recording, we leverage the ZAP browser extension and a dedicated client add-on.
This combination allows us to efficiently capture and save user interactions in Zest scripts.
Yeni Komut Dosyası Butonu
- Komut Dosyaları ağacı sekmesine gelin
- 'Yeni Komut Dosyası...' butonuna basın
- 'Yeni Komut Dosyası' iletişim kutusunda komut dosyanız için uygun bir isim girin
- Komut dosyası türünü seçin (Daha fazla bilgi için Komut dosyaları eklentisi yardım sayfasına bakınız)
- Zest komut dosyası aracını seçin
- Şablonların birini seçin (uygun ise)
- 'Kaydet' butonuna basın
Bu yöntemle herhangi türde Zest komut dosyası oluşturulabilir.
Bir Zest şablonuna sağ tıklama
- Komut Dosyaları ağacı sekmesine gelin
- 'Şablonlar' düğümünü genişletin ve kullanmak istediğiniz bir şablon bulun
- Şablona sağ tıklayın ve 'Yeni Komut Dosyası...' seçin
- 'Kaydet' butonuna basın
Any type of Zest script can be created this way.
Sağ tıklama istekleri
- Geçmiş sekmesi gibi, istekleri gösteren herhangi bir sekmeye gelin
- Bir veya daha fazla istek seçin
- Sağ tıklayın
- Mevcut bir Bağımsız komut dosyası seçmenizi veya yeni bir tane oluşturmanızı sağlayan 'Zest Komut Dosyasına Ekle' menüsünü seçin
Note that you can only add request to 'Stand Alone' Zest scripts.
Plug-n-Hack
If you are using a recent version of Firefox then you can create Zest scripts from within your browser.
- ZAP 'Hızlı Başlangıç' sekmesindeki 'Plug-n-Hack' butonuna basın
- Plug-n-Hack Firefox eklentisini yükleyin ve tüm iletileri kabul edin
- Geliştirici Araç Çubuğuna erişmek için Firefox'ta 'Shift F2' tuşuna basın
- Yeni bir Zest komut dosyasını kaydetmeye başlamak için 'zap record on global' yazın
- ZAP vasıtasıyla yaptığınız tüm istekler komut dosyasına eklenecek
- Komut dosyası kaydını durdurmak için 'zap record off global' yazın
Note that you can only record 'Stand Alone' Zest scripts in this way. If you want to create other types of Zest script you must use another mechanism.
Zest komut dosyalarını düzenleme
Zest scripts are edited graphically in the Scripts tree tab.
Each statement is a node in the tree - double click nodes to edit the statement properties.
You can add, move and remove statements via right clicking the Zest nodes.
You can also add requests to 'Stand alone' Zest scripts by right clicking the requests in any of the other tabs.
There are also some right click options available when you select text in the Request or Response tabs.
Zest includes a set of 'built in' variables as well as allowing you to declare your own.
A right click menu is provided (where relevant) in the edit dialogs to allow you to paste in any of the available variable names.
Authentication Scripts
Authentication scripts can use a custom ZAP variable, called TOTP, to send a value to an input field with a TOTP code generated from the user's credentials TOTP data.
Import/Export Integration
When the Import/Export add-on is installed, Zest adds the following functionality:
Import Zest Script
An option to import messages from a Zest script file is available via the 'Import' menu ('Import Zest Script...').
The HTTP requests (and responses, if present) from the script are added to the Sites tree and History panel without replaying them.
Export as Zest Script
The Export menu supports exporting the history as a Zest script file.
This creates a Zest script containing the HTTP requests (and responses).
Automation Framework
When both the Import/Export and Automation add-ons are installed, Zest scripts can be imported and exported via the Automation Framework.
Import Job
Use the Import/Export add-on's import job with type: zest to import HTTP messages from a Zest script file (.zst):
- type: import
parameters:
type: zest
fileName: /path/to/script.zst
The HTTP requests (and responses, if present) from the script are added to the Sites tree and History panel without replaying them.
Export Job
Use the Import/Export add-on's export job with type: zest to export messages to a Zest script file.
The source parameter can be history (manually/proxied messages) or all (all messages including those generated by ZAP):
- type: export
parameters:
type: zest
source: history
fileName: /path/to/output.zst
Dış bağlantılar