添加认证脚本后OWASP ZAP-Advanced容器启动失败,无法执行DAST扫描
问题解决:secureCodeBox ZAP Advanced添加认证脚本后容器启动失败
问题分析
容器卡在ContainerCreating状态,结合你的配置,核心问题集中在YAML格式错误、认证脚本不符合ZAP规范、参数格式错误这几点:
- 扫描配置的YAML中,认证脚本的
scripts块缩进异常,导致配置解析失败 - 你的认证脚本用了Node.js风格的
node-fetch,但ZAP的Graal.js环境不支持Node.js模块,且未实现ZAP认证脚本要求的标准接口 - Scan资源中
-t参数后的URL带多余空格,可能引发参数解析异常
修复步骤
1. 修正YAML配置缩进
调整zap-advanced-scan-config ConfigMap里的scripts块缩进,使其与apis、contexts同级(原配置缩进多了一个空格,导致YAML结构错误):
--- apiVersion: v1 kind: ConfigMap metadata: name: zap-advanced-scan-config data: 2-zap-advanced-scan.yaml: |- global: sessionName: mybizservice-zap-api-scan scripts: - name: "Alert_on_HTTP_Response_Code_Errors.js" enabled: true filePath: "/home/zap/.ZAP_D/scripts/scripts/httpsender/Alert_on_HTTP_Response_Code_Errors.js" engine: "Oracle Nashorn" type: "httpsender" description: "A HTTP Sender Script which will raise alerts based on HTTP Response codes." - name: "Alert_on_Unexpected_Content_Types.js" enabled: true filePath: "/home/zap/.ZAP_D/scripts/scripts/httpsender/Alert_on_Unexpected_Content_Types.js" engine: "Oracle Nashorn" type: "httpsender" description: "A HTTP Sender Script which will raise alerts based on unexpected Content-Types." contexts: - name: mybizservice-context url: https://abc-dev.org.cloud/ includePaths: - "https://abc-dev.org.cloud/backend/payment.*" excludePaths: - ".*\\.css" - ".*\\.png" - ".*\\.jpeg" apis: - name: scb-mybizservice-api context: mybizservice-context format: openapi url: https://abc-dev.org.cloud/backend/payment/v3/api-docs hostOverride: https://abc-dev.org.cloud scripts: - name: "zap-api-authentication-script" enabled: true filePath: "/home/zap/.ZAP_D/scripts/scripts/authentication/zap-api-authentication.js" engine: "Graal.js" type: "authentication" description: "ZAP API AuthN script for K8s" spiders: - name: mybizservice-spider context: mybizservice-context url: https://abc-dev.org.cloud/backend/payment/ failIfFoundUrlsLessThan: 0 warnIfFoundUrlsLessThan: 0 maxDuration: 1 maxDepth: 5 maxChildren: 10 acceptCookies: true parseComments: true parseGit: false parseRobotsTxt: false parseSitemapXml: false parseSVNEntries: false postForm: true processForm: true requestWaitTime: 200 sendRefererHeader: true threadCount: 2 userAgent: "secureCodeBox / ZAP Spider" scanners: - name: scb-mybizservice-scan context: mybizservice-context url: https://abc-dev.org.cloud/backend/payment/ policy: "API-Minimal" default: 0 unlimited maxRuleDurationInMins: 1 maxScanDurationInMins: 5 threadPerHost: 5 delayInMs: 0 addQueryParam: false handleAntiCSRFTokens: false injectPluginIdInHeader: false scanHeadersAllRequests: false
2. 重写符合ZAP规范的认证脚本
ZAP的Graal.js认证脚本必须实现authenticate()等标准方法,且需用Java原生HTTP工具(不能用Node.js模块)。以下是适配Client Credentials模式的正确脚本:
function getRequiredParams() { return []; } function getOptionalParams() { return []; } function authenticate(helper, params, credentials) { // 认证配置 const clientId = "clientid1212"; const clientSecret = "abcd1234-200f-4427-9c8c-48ef6789wxyz"; const tokenUrl = "https://abc-dev.org.cloud/uaa/oauth/token"; // 构建Basic Auth头 const basicAuth = java.util.Base64.getEncoder().encodeToString((clientId + ":" + clientSecret).getBytes()); // 构建请求体 const formData = "grant_type=client_credentials"; // 发送POST请求获取Token const url = new java.net.URL(tokenUrl); const conn = url.openConnection(); conn.setRequestMethod("POST"); conn.setRequestProperty("Content-Type", "application/x-www-form-urlencoded"); conn.setRequestProperty("Authorization", "Basic " + basicAuth); conn.setDoOutput(true); const os = conn.getOutputStream(); os.write(formData.getBytes()); os.flush(); os.close(); // 读取并解析响应 const is = conn.getInputStream(); const reader = new java.io.BufferedReader(new java.io.InputStreamReader(is)); let line; const response = []; while ((line = reader.readLine()) != null) { response.push(line); } reader.close(); is.close(); const json = JSON.parse(response.join("")); const accessToken = json.access_token; // 将Token添加到ZAP的认证头中 helper.addAuthHeader("Authorization: Bearer " + accessToken); return true; } function getAuthParamNames() { return []; } function getCredentialsParamsNames() { return []; }
把这个脚本替换到zap-api-authentication-script ConfigMap中。
3. 修正Scan资源的参数错误
去掉-t参数后URL前的多余空格:
apiVersion: "execution.securecodebox.io/v1" kind: Scan metadata: name: "zap-advanced-api-scan-mybizservice" labels: organization: "OWASP" spec: scanType: "zap-advanced-scan" parameters: - "-t" - "https://abc-dev.org.cloud/backend/payment/" - "-o" - "/home/securecodebox/" volumeMounts: - name: zap-advanced-scan-config mountPath: /home/securecodebox/configs/2-zap-advanced-scan.yaml subPath: 2-zap-advanced-scan.yaml readOnly: true - name: zap-api-authentication-script mountPath: /home/zap/.ZAP_D/scripts/scripts/authentication/zap-api-authentication.js subPath: zap-api-authentication.js volumes: - name: zap-advanced-scan-config configMap: name: zap-advanced-scan-config - name: zap-api-authentication-script configMap: name: zap-api-authentication-script
4. 验证修复效果
重新应用所有配置:
kubectl apply -f zap-advanced-scan-config.yaml kubectl apply -f zap-api-authentication-script.yaml kubectl apply -f scan.yaml
查看Pod状态:
kubectl get pods
如果仍有问题,查看Pod事件排查细节:
kubectl describe pod <你的Pod名称>
额外提示
- 确保集群网络策略允许ZAP容器访问认证服务器(
https://abc-dev.org.cloud/uaa/oauth/token) - 扫描完成后,通过
kubectl logs <你的Pod名称>查看ZAP日志,确认认证是否成功执行
内容的提问来源于stack exchange,提问作者Dhaval Simaria
相关产品推荐
相关产品推荐

