Missing exclude path in FullScanDvwaAuth.yaml

Open Beginner friendly
#522 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
1/5
Estimated time
Under an hour
Newbie friendliness
90/100
Issue type
Bug
Clarity
Clearly specified
Activity status
Active
Tech stack
yaml
Domain
security

Research direction

Open other/af-plans/FullScanDvwaAuth.yaml and inspect its existing excludepath settings. Add the requested exclusion for the cryptography endpoint, then run the automation plan and verify the spider no longer discovers thousands of matching URLs.

Written by the indexing model from the issue text.

Description

I was testing with the FullScanDvwaAuth.yaml in other/af-plans/
The automation works well but in the yml the should be an additional excludepath: "http://localhost:4280/vulnerabilities/cryptography.*"
Not having this excludepath makes the spider find thousands of urls on the /vulnerabilities/cryptography?token= endpoint.
Can this be fixed?
Thanks!
Regards,
Rob

Dominant language
JavaScript
Stars
895
Forks
260
Avg merge
53m
Merged PRs (30d)
1

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from zaproxy/community-scripts

All issues in zaproxy/community-scripts

Similar issues

More JavaScript issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.