You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在OWASP ZAP中获取导入URL数与总URL数的变量值

提取OWASP ZAP爬虫前URL统计数值到变量的方法

因为这两个统计值仅出现在ZAP的控制台/日志输出中,未包含在标准报告里,你可以通过以下几种方式提取并存入变量:

1. Shell脚本解析日志(适用于Linux/macOS CI/CD场景)

先将ZAP的运行输出重定向到日志文件,再用文本处理工具提取数值:

# 运行ZAP扫描并保存输出到日志
zap-baseline.py -t https://your-microservice-url > zap_run.log 2>&1

# 提取"Number of Imported URLs"的数值
imported_urls=$(grep "Number of Imported URLs:" zap_run.log | awk '{print $NF}')

# 提取"Total of X URLs"的数值
total_urls=$(grep "Total of.*URLs" zap_run.log | awk '{print $3}')

# 可直接使用变量,比如输出验证
echo "导入URL数量: $imported_urls"
echo "总URL数量: $total_urls"

2. Python脚本解析日志(跨平台通用)

用正则匹配从日志中提取数值,适合复杂自动化流程:

import re

# 读取ZAP运行日志文件
with open("zap_run.log", "r", encoding="utf-8") as log_file:
    log_content = log_file.read()

# 匹配导入URL数量
imported_match = re.search(r"Number of Imported URLs: (\d+)", log_content)
imported_urls = imported_match.group(1) if imported_match else "0"

# 匹配总URL数量
total_match = re.search(r"Total of (\d+) URLs", log_content)
total_urls = total_match.group(1) if total_match else "0"

# 输出或使用变量
print(f"导入URL数量: {imported_urls}")
print(f"总URL数量: {total_urls}")

3. ZAP内部自定义脚本(扫描过程中实时提取)

如果使用ZAP的自动化脚本功能,可添加日志监听器实时捕捉数值并存入ZAP上下文变量:

import org.zaproxy.zap.utils.LogListener

def logListener = new LogListener() {
    @Override
    void messageLogged(String message, int level, String loggerName) {
        // 提取导入URL数量
        if (message.startsWith("Number of Imported URLs:")) {
            def count = message.split(": ")[1].trim()
            context.setCustomParameter("imported_urls", count)
        }
        // 提取总URL数量
        if (message.contains("Total of") && message.endsWith("URLs")) {
            def count = message.split(" ")[2].trim()
            context.setCustomParameter("total_urls", count)
        }
    }
}

// 注册日志监听器
org.zaproxy.zap.utils.Log.addListener(logListener)

将上述Groovy脚本添加到ZAP的「脚本」面板(类型选「Listener」),启动扫描后即可在ZAP上下文变量中获取这两个数值。

内容的提问来源于stack exchange,提问作者Harry Palma Santeliz

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.25 10:57:33