{"repo":"gdgd009xcd/RequestRecorder","free":true,"listed":false,"github":"https://github.com/gdgd009xcd/RequestRecorder","clone":"git clone https://github.com/gdgd009xcd/RequestRecorder.git","description":"A ZAPROXY Add-on that allows testing of web application vulnerabilities by recording complex multi-step sequences. You can test applications that need to access pages in a specific order, such as shopping carts or registration of member information.","language":"Java","stars":23,"topics":["security","zaproxy","zap-extension","addon","security-tools","security-testing","vulnerability-scanners","webcrawler","activescan","csrf"],"license":"Apache-2.0","category":"security-tools","readme_excerpt":"RequestRecorder for ZAP. RequestRecorder is an extension of Zed Attack Proxy(ZAP). You can test applications that need to access pages in a specific order, such as shopping carts or registration of member information. This Extension records the http request sequence of the web application, tracks the anti-CSRF token and session cookies, and can tests it by ZAPROXY tools(ActiveScan). To summarize the above, this addon can build multistep request sequence without scripting, and can use them with tool such as scanners or manual request on ZAP. Prerequisite ZAP ver 2.13.0 or later java ver 11 or later how to use Click here below: English manuals Japanese manuals a member registration sample web test results. I tested member registration my sample page which has CSRF token. below is result: Test Environment: WEBSAMPSQLINJ Docker image(docker-compose) Scantarget: [Modify User] 3.2.moduser.php (See Sitemap ) ZAPROXY Version: 2.10.0-SNAPSHOT Addon: RequestRecorder ver0.9.6, ActiveScan rule addons(See below). ZAPROXY Mode: Standard mode url parameter Advanced SQLInjection Scanner Ver13 beta CustomActiveScan ver0.0.1 alpha http://localhost:8110/moduser.php password DETECTED (time based pg sleep(5)) DETECTED(boolean based) http://localhost:8110/moduser.php age DETECTED (time based pg sleep(5)) DETECTED(boolean based) Download & Building in Ubuntu The add-on is built with [Gradle]: https://gradle.org/ build with command line tools(Ubuntu) To download & build this addon, simply run: $ git","default_branch":null,"files":null,"tree":[],"storefront":"/r/gdgd009xcd","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/gdgd009xcd/RequestRecorder/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}