如何在ZAP 2.7.0中对指定子目录执行强制浏览枚举?
Got it, let's break down exactly how to run forced browsing only on abc.com/subdir1/ in ZAP 2.7.0—no need to scan the entire site:
First, get the subdirectory into ZAP's Site Tree
Ifabc.com/subdir1/isn't already listed in ZAP's left-hand Site Tree, manually navigate to the URL in ZAP's built-in browser (or your regular browser proxied through ZAP). ZAP will automatically add the subdirectory to the Site Tree once it detects traffic to it.Launch Forced Browsing for the subdirectory
In the Site Tree, right-click on theabc.com/subdir1/node. From the dropdown menu, select Forced Browse—this will open the configuration window.Verify the target URL
In the Forced Browse window, check the Target section. It should automatically populate withhttps://abc.com/subdir1/(orhttp://depending on your site's protocol). If it doesn't, manually edit the URL to point directly to your target subdirectory.Load your dictionary file
Click the Load button in the window, then select the dictionary file you want to use (just like you did with DirBuster). ZAP supports common dictionary formats, so your existing DirBuster dictionaries should work fine.Tweak optional settings (if needed)
Adjust things like thread count, timeout values, or redirect handling based on your needs. For example, if the site is slow, lower the thread count to avoid getting blocked.Start the scan
Hit the Start button, and ZAP will begin enumerating files and directories only underabc.com/subdir1/. You can monitor progress in the Forced Browse tab that opens up.
A quick reminder: Always ensure you have explicit permission to scan the target site—stick to ethical testing guidelines for any site you don't own or manage.
内容的提问来源于stack exchange,提问作者user1192748

