如何在OWASP ZAP中获取导入URL数与总URL数的变量值
提取OWASP ZAP爬虫前URL统计数值到变量的方法
因为这两个统计值仅出现在ZAP的控制台/日志输出中,未包含在标准报告里,你可以通过以下几种方式提取并存入变量:
1. Shell脚本解析日志(适用于Linux/macOS CI/CD场景)
先将ZAP的运行输出重定向到日志文件,再用文本处理工具提取数值:
# 运行ZAP扫描并保存输出到日志 zap-baseline.py -t https://your-microservice-url > zap_run.log 2>&1 # 提取"Number of Imported URLs"的数值 imported_urls=$(grep "Number of Imported URLs:" zap_run.log | awk '{print $NF}') # 提取"Total of X URLs"的数值 total_urls=$(grep "Total of.*URLs" zap_run.log | awk '{print $3}') # 可直接使用变量,比如输出验证 echo "导入URL数量: $imported_urls" echo "总URL数量: $total_urls"
2. Python脚本解析日志(跨平台通用)
用正则匹配从日志中提取数值,适合复杂自动化流程:
import re # 读取ZAP运行日志文件 with open("zap_run.log", "r", encoding="utf-8") as log_file: log_content = log_file.read() # 匹配导入URL数量 imported_match = re.search(r"Number of Imported URLs: (\d+)", log_content) imported_urls = imported_match.group(1) if imported_match else "0" # 匹配总URL数量 total_match = re.search(r"Total of (\d+) URLs", log_content) total_urls = total_match.group(1) if total_match else "0" # 输出或使用变量 print(f"导入URL数量: {imported_urls}") print(f"总URL数量: {total_urls}")
3. ZAP内部自定义脚本(扫描过程中实时提取)
如果使用ZAP的自动化脚本功能,可添加日志监听器实时捕捉数值并存入ZAP上下文变量:
import org.zaproxy.zap.utils.LogListener def logListener = new LogListener() { @Override void messageLogged(String message, int level, String loggerName) { // 提取导入URL数量 if (message.startsWith("Number of Imported URLs:")) { def count = message.split(": ")[1].trim() context.setCustomParameter("imported_urls", count) } // 提取总URL数量 if (message.contains("Total of") && message.endsWith("URLs")) { def count = message.split(" ")[2].trim() context.setCustomParameter("total_urls", count) } } } // 注册日志监听器 org.zaproxy.zap.utils.Log.addListener(logListener)
将上述Groovy脚本添加到ZAP的「脚本」面板(类型选「Listener」),启动扫描后即可在ZAP上下文变量中获取这两个数值。
内容的提问来源于stack exchange,提问作者Harry Palma Santeliz
相关产品推荐
相关产品推荐

