Why not login to Qiita and try out its useful features?

We'll deliver articles that match you.

You can read useful information later.

Delete article

Deleted articles cannot be recovered.

Draft of this article would be also deleted.

Are you sure you want to delete this article?

This article is a Private article. Only a writer and users who know the URL can access it.
Please change open range to public in publish setting if you want to share this article with other users.

More than 3 years have passed since last update.

OWASP ZAP2.9.0で脆弱性診断をする - HTTP Sessions

Posted at

HTTP Sessions

HTTP Sessionsは、すべてのリクエストを特定のセッションに強制できるようにします。サイトのユーザーセッションを簡単に切り替えて、既存のセッションを「破壊」することなく新しいセッションを作成できます。

HTTP Sessionsは、Httpセッションタブで管理します。Httpセッションタブを有効にするとサイト単位で検知したセッションを表示します。

何もactiveにしていない場合、Manual Exploreで当該サイトにアクセスすると、新規セッションが作成されます。
スクリーンショット 2020-05-04 1.48.18.png
スクリーンショット 2020-05-04 1.47.52.png

右クリックし、ActiveにしてからManual Exploreで当該サイトにアクセスすると、そのユーザのセッションになります。
スクリーンショット 2020-05-04 1.51.55.png
スクリーンショット 2020-05-04 1.48.35.png


スクリーンショット 2020-05-04 1.54.35.png

Register as a new user and use Qiita more conveniently

  1. You get articles that match your needs
  2. You can efficiently read back useful information
  3. You can use dark theme
What you can do with signing up


No comments

Let's comment your feelings that are more than good

Qiita Advent Calendar is held!

Qiita Advent Calendar is an article posting event where you post articles by filling a calendar 🎅

Some calendars come with gifts and some gifts are drawn from all calendars 👀

Please tie the article to your calendar and let's enjoy Christmas together!

Delete article

Deleted articles cannot be recovered.

Draft of this article would be also deleted.

Are you sure you want to delete this article?

Login to continue?

Login or Sign up with social account

Login or Sign up with your email address