You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

本地运行ZAP扫描正常,EC2实例部署ZAP扫描失败求助

EC2实例部署OWASP ZAP扫描失败问题排查

本地运行OWASP ZAP可顺利完成完整扫描,但EC2实例上部署的ZAP执行扫描时失败,该EC2实例上的ZAP可通过IP和端口公开访问,报错信息如下:

Proxy error: HTTPConnectionPool(host='10.102.0.156', port=8080): Max retries exceeded with url: http://zap/JSON/ascan/view/status/?scanId=0 (Caused by ProxyError('Unable to connect to proxy', NewConnectionError('<urllib3.connection.HTTPConnection object at 0x0000028E18540940>: Failed to establish a new connection: [WinError 10061] No connection could be made because the target machine actively refused it')))

调用ZAP API的Python代码如下:

from zapv2 import ZAPv2
import time
import requests

# ZAP API configuration
api_key =   # ZAP API Key
zap_ip = 
zap_port = '8080'
# Initialize the ZAP API client
zap = ZAPv2(apikey=api_key, proxies={
    'http': f'http://{zap_ip}:{zap_port}',
    'https': f'http://{zap_ip}:{zap_port}'
})
# JWT token
jwt_token = 'Bearer '  # Replace with your actual JWT token

# Swagger URL for the OpenAPI definition
swagger_url = 'https://inspired-mock-backend.sapidblue.in/v2/api-docs?group=Post Login Resource'
base_url = 'https://inspired-mock-backend.sapidblue.in/'

# Start a new session
zap.core.new_session(name='new_session', overwrite=True)

# Set custom headers for authentication (JWT)
zap.replacer.add_rule(description="Add JWT Authorization Header",
                      enabled=True,
                      matchtype="REQ_HEADER",
                      matchregex=False,
                      matchstring="Authorization",
                      replacement=jwt_token)

try:
    # Import the OpenAPI definition
    zap.openapi.import_url(swagger_url)

    print("Swagger definition imported successfully.")

    # Start an active scan on the base URL
    scan_id = zap.ascan.scan(base_url)
    print(f'Started Active Scan with ID: {scan_id}')

    # Monitor scan progress
    status = 0
    while int(zap.ascan.status(scan_id)) < 100:
        print(f'Scan progress: {zap.ascan.status(scan_id)}%')
        time.sleep(10)

    # Generate and save the HTML report
    html_report = zap.core.htmlreport()
    with open('zap_report.html', 'w') as report_file:
        report_file.write(html_report)

    print('HTML report saved as zap_report.html')

except requests.exceptions.ProxyError as e:
    print(f"Proxy error: {e}")
except requests.exceptions.ConnectionError as e:
    print(f"Connection error: {e}")
except Exception as e:
    print(f"An error occurred: {e}")

排查与解决步骤

  • 调整ZAP启动绑定地址:EC2上的ZAP默认可能仅绑定localhost,导致API无法被外部访问。启动ZAP时需指定绑定所有网卡,Linux下命令为:zap.sh -host 0.0.0.0 -port 8080,Windows下对应命令为zap.exe -host 0.0.0.0 -port 8080。
  • 检查EC2安全组规则:确保安全组入站规则开放8080端口(ZAP服务端口),且允许你的本地IP或指定IP段访问;同时出站规则需允许ZAP访问目标扫描地址的端口(如443)。
  • 验证ZAP API配置:在ZAP界面的「选项」-「API」设置中,勾选「Allow remote access」,确认API密钥正确,且API密钥列表中包含调用端IP的访问权限。
  • 修正ZAP客户端初始化代码:报错中出现http://zap/,说明ZAP内部请求未正确使用外部代理地址。修改初始化代码,添加zap_address参数:
zap = ZAPv2(apikey=api_key, 
            proxies={
                'http': f'http://{zap_ip}:{zap_port}',
                'https': f'http://{zap_ip}:{zap_port}'
            },
            zap_address=f'http://{zap_ip}:{zap_port}')
  • 测试API连通性:用curl直接测试EC2上的ZAP API,命令:curl http://<EC2_IP>:8080/JSON/core/view/version/?apikey=<你的API_KEY>,确认能正常返回版本信息。
  • 检查EC2网络连通性:在EC2实例上执行curl https://inspired-mock-backend.sapidblue.in/,确认能正常访问目标扫描地址,避免因EC2网络限制导致扫描失败。

内容的提问来源于stack exchange,提问作者Deepak dubey

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.17 15:00:05