Zest
Zest is an experimental specialized scripting language (also known as a domain-specific language)
originally developed by the Mozilla security team and is intended to be used in web oriented security tools.
默认情况下,它包含ZAP.
Engine Name
The engine is named Mozilla Zest, which should be used when manually/programmatically configuring ZAP.
创建Zest脚本
创建Zest脚本有多种方法:
Record a new Zest script Button
- Press the 'Record a new Zest script' button on the main toolbar
- 在"添加Zest脚本"对话框中键入适合您的脚本名称
- 选择您想要记录请求的前缀,或者留空白以记录所有请求
- 按"保存"按钮
- The 'Record a new Zest script' button will stay pressed, change to 'Recording a new Zest script' and show a red icon.
新的带有红色"录制"图标的Zest脚本将显示在脚本选项卡中。
您在指定前缀下所做的任何请求都将添加到脚本中。
Press the 'Recording a new Zest script' again to stop recording the requests.
注意,您只能用此方式记录"独立"的Zest脚本。如果您想创建其他类型的Zest脚本,您必须使用另一个机制。
您也可以右键单击任何独立Zest脚本,并使用"开始录制"和"停止录制"按钮。
There are two primary methods for script recording: server-side and client-side. For client-side recording, we leverage the ZAP browser extension and a dedicated client add-on.
This combination allows us to efficiently capture and save user interactions in Zest scripts.
新建脚本按钮
- 导航到脚本树选项卡
- 按"新建脚本..."按钮
- 在"新建脚本"对话框中键入适合您的脚本名称
- 选择脚本类型(有关详情,请参阅脚本附件的帮助页面)
- 选择Zest脚本引擎
- 选择其中一个模版(如果相关)
- 按"保存"按钮
Any type of Zest script can be created this way.
Right clicking a Zest template
- Navigate to the Scripts tree tab
- 展开"模版"节点并查找您想使用的模版
- 右键单击该模版并且选择"新建脚本..."
- 按"保存"按钮
Any type of Zest script can be created this way.
右键单击请求
- 导航到显示请求的任何选项卡,例如历史记录选项卡
- 选择一个或多个请求
- 右键点击它们
- 选择"添加到Zest脚本"菜单,它允许您选择一个现存的独立脚本或者创建一个新脚本
Note that you can only add request to 'Stand Alone' Zest scripts.
Plug-n-Hack
If you are using a recent version of Firefox then you can create Zest scripts from within your browser.
- Press the 'Plug-n-Hack' button on the ZAP 'Quick Start' tab
- Install the Plug-n-Hack Firefox Add-on and accept all of the dialogs
- 在Firefox中按"Shift F2"访问Developer Toolbar(开发工具栏)
- Type 'zap record on global' to start recording a new Zest script
- 您通过ZAP发出的任何请求都将添加到脚本中
- Type 'zap record off global' to stop recording the script
Note that you can only record 'Stand Alone' Zest scripts in this way. If you want to create other types of Zest script you must use another mechanism.
编辑Zest脚本
Zest scripts are edited graphically in the Scripts tree tab.
Each statement is a node in the tree - double click nodes to edit the statement properties.
You can add, move and remove statements via right clicking the Zest nodes.
You can also add requests to 'Stand alone' Zest scripts by right clicking the requests in any of the other tabs.
There are also some right click options available when you select text in the Request or Response tabs.
Zest includes a set of 'built in' variables as well as allowing you to declare your own.
A right click menu is provided (where relevant) in the edit dialogs to allow you to paste in any of the available variable names.
Authentication Scripts
Authentication scripts can use a custom ZAP variable, called TOTP, to send a value to an input field with a TOTP code generated from the user's credentials TOTP data.
Import/Export Integration
When the Import/Export add-on is installed, Zest adds the following functionality:
Import Zest Script
An option to import messages from a Zest script file is available via the 'Import' menu ('Import Zest Script...').
The HTTP requests (and responses, if present) from the script are added to the Sites tree and History panel without replaying them.
Export as Zest Script
The Export menu supports exporting the history as a Zest script file.
This creates a Zest script containing the HTTP requests (and responses).
Automation Framework
When both the Import/Export and Automation add-ons are installed, Zest scripts can be imported and exported via the Automation Framework.
Import Job
Use the Import/Export add-on's import job with type: zest to import HTTP messages from a Zest script file (.zst):
- type: import
parameters:
type: zest
fileName: /path/to/script.zst
The HTTP requests (and responses, if present) from the script are added to the Sites tree and History panel without replaying them.
Export Job
Use the Import/Export add-on's export job with type: zest to export messages to a Zest script file.
The source parameter can be history (manually/proxied messages) or all (all messages including those generated by ZAP):
- type: export
parameters:
type: zest
source: history
fileName: /path/to/output.zst
外部链接