You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Windows系统下如何通过命令行运行ZAP并配置表单式身份验证登录凭证?

Windows命令行运行ZAP及表单式身份验证配置

一、基础命令行启动ZAP

先确认ZAP安装路径(默认:C:\Program Files\OWASP\Zed Attack Proxy),可将路径加入系统环境变量,或直接进入该目录执行命令。

基础后台启动命令:

zap.bat -daemon

指定端口启动(避免端口冲突):

zap.bat -daemon -port 8080

二、表单式身份验证配置步骤

1. 收集登录表单关键信息

用浏览器开发者工具(F12)获取以下内容:

  • 登录页面URL(如https://your-app.com/login)
  • 表单提交目标URL(查看表单action属性,可能与登录页面不同)
  • 用户名输入框的name属性(如username)
  • 密码输入框的name属性(如password)
  • 登录成功标识:比如登录后跳转的专属URL,或页面中固定出现的文本(如“欢迎登录”)

2. 生成ZAP上下文文件(推荐方式)

通过GUI配置后导出上下文文件更直观:

  • 打开ZAP GUI,点击「File」→「New Context」,命名后添加目标应用的URL规则(如https://your-app.com/*)
  • 切换到「Authentication」标签,选择Form-Based Authentication
  • 填入之前收集的登录页面、提交URL、用户名/密码字段名,设置登录成功指示器(比如勾选“URL matches”并填入登录后的跳转URL)
  • 若表单含CSRF Token,勾选「Enable CSRF Token Support」,指定Token字段的name属性(如csrf_token)
  • 点击「OK」后,导出上下文文件:「File」→「Export Context」,保存为app_context.context

3. 命令行加载上下文并配置登录凭证

启动ZAP时加载上下文文件,同时指定登录凭证:

zap.bat -daemon -port 8080 -context "C:\path\to\app_context.context" -user "your-username" -password "your-password"

如需强制指定验证类型,添加-authtype "formBased"参数:

zap.bat -daemon -port 8080 -context "C:\path\to\app_context.context" -user "your-username" -password "your-password" -authtype "formBased"

4. 验证登录有效性

可通过ZAP API或扫描命令验证:

  • 访问http://localhost:8080/JSON/core/view/urls/,检查是否抓取到需登录才能访问的页面
  • 执行主动扫描测试:
zap.bat -daemon -port 8080 -context "C:\path\to\app_context.context" -user "your-username" -password "your-password" -spider "https://your-app.com" -activeScan "https://your-app.com"

三、无上下文文件的直接配置(参数较多,不推荐)

不想用上下文文件时,可通过-config参数直接指定所有验证配置:

zap.bat -daemon -port 8080 ^
-config context.myApp.name="MyAppContext" ^
-config context.myApp.urls.0="https://your-app.com/*" ^
-config context.myApp.auth.type="formBased" ^
-config context.myApp.auth.formBased.loginUrl="https://your-app.com/login" ^
-config context.myApp.auth.formBased.loginRequestUrl="https://your-app.com/login/submit" ^
-config context.myApp.auth.formBased.usernameField="username" ^
-config context.myApp.auth.formBased.passwordField="password" ^
-config context.myApp.users.0.name="test-user" ^
-config context.myApp.users.0.username="test-user" ^
-config context.myApp.users.0.password="test-pass" ^
-config context.myApp.auth.managementLoginUrl="https://your-app.com/login" ^
-config context.myApp.auth.managementUsernameField="username" ^
-config context.myApp.auth.managementPasswordField="password"

(Windows命令行用^换行,提升可读性)

内容的提问来源于stack exchange,提问作者Wilfred richard

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.17 10:01:17