本地运行ZAP扫描正常,EC2实例部署ZAP扫描失败求助
EC2实例部署OWASP ZAP扫描失败问题排查
本地运行OWASP ZAP可顺利完成完整扫描,但EC2实例上部署的ZAP执行扫描时失败,该EC2实例上的ZAP可通过IP和端口公开访问,报错信息如下:
Proxy error: HTTPConnectionPool(host='10.102.0.156', port=8080): Max retries exceeded with url: http://zap/JSON/ascan/view/status/?scanId=0 (Caused by ProxyError('Unable to connect to proxy', NewConnectionError('<urllib3.connection.HTTPConnection object at 0x0000028E18540940>: Failed to establish a new connection: [WinError 10061] No connection could be made because the target machine actively refused it')))
调用ZAP API的Python代码如下:
from zapv2 import ZAPv2 import time import requests # ZAP API configuration api_key = # ZAP API Key zap_ip = zap_port = '8080' # Initialize the ZAP API client zap = ZAPv2(apikey=api_key, proxies={ 'http': f'http://{zap_ip}:{zap_port}', 'https': f'http://{zap_ip}:{zap_port}' }) # JWT token jwt_token = 'Bearer ' # Replace with your actual JWT token # Swagger URL for the OpenAPI definition swagger_url = 'https://inspired-mock-backend.sapidblue.in/v2/api-docs?group=Post Login Resource' base_url = 'https://inspired-mock-backend.sapidblue.in/' # Start a new session zap.core.new_session(name='new_session', overwrite=True) # Set custom headers for authentication (JWT) zap.replacer.add_rule(description="Add JWT Authorization Header", enabled=True, matchtype="REQ_HEADER", matchregex=False, matchstring="Authorization", replacement=jwt_token) try: # Import the OpenAPI definition zap.openapi.import_url(swagger_url) print("Swagger definition imported successfully.") # Start an active scan on the base URL scan_id = zap.ascan.scan(base_url) print(f'Started Active Scan with ID: {scan_id}') # Monitor scan progress status = 0 while int(zap.ascan.status(scan_id)) < 100: print(f'Scan progress: {zap.ascan.status(scan_id)}%') time.sleep(10) # Generate and save the HTML report html_report = zap.core.htmlreport() with open('zap_report.html', 'w') as report_file: report_file.write(html_report) print('HTML report saved as zap_report.html') except requests.exceptions.ProxyError as e: print(f"Proxy error: {e}") except requests.exceptions.ConnectionError as e: print(f"Connection error: {e}") except Exception as e: print(f"An error occurred: {e}")
排查与解决步骤
- 调整ZAP启动绑定地址:EC2上的ZAP默认可能仅绑定
localhost,导致API无法被外部访问。启动ZAP时需指定绑定所有网卡,Linux下命令为:zap.sh -host 0.0.0.0 -port 8080,Windows下对应命令为zap.exe -host 0.0.0.0 -port 8080。 - 检查EC2安全组规则:确保安全组入站规则开放8080端口(ZAP服务端口),且允许你的本地IP或指定IP段访问;同时出站规则需允许ZAP访问目标扫描地址的端口(如443)。
- 验证ZAP API配置:在ZAP界面的「选项」-「API」设置中,勾选「Allow remote access」,确认API密钥正确,且API密钥列表中包含调用端IP的访问权限。
- 修正ZAP客户端初始化代码:报错中出现
http://zap/,说明ZAP内部请求未正确使用外部代理地址。修改初始化代码,添加zap_address参数:
zap = ZAPv2(apikey=api_key, proxies={ 'http': f'http://{zap_ip}:{zap_port}', 'https': f'http://{zap_ip}:{zap_port}' }, zap_address=f'http://{zap_ip}:{zap_port}')
- 测试API连通性:用curl直接测试EC2上的ZAP API,命令:
curl http://<EC2_IP>:8080/JSON/core/view/version/?apikey=<你的API_KEY>,确认能正常返回版本信息。 - 检查EC2网络连通性:在EC2实例上执行
curl https://inspired-mock-backend.sapidblue.in/,确认能正常访问目标扫描地址,避免因EC2网络限制导致扫描失败。
内容的提问来源于stack exchange,提问作者Deepak dubey
相关产品推荐
相关产品推荐

