-
-
Notifications
You must be signed in to change notification settings - Fork 138
HelpUiTabsParams
psiinon edited this page Jun 3, 2015
·
5 revisions
This shows a summary of the parameters a site uses.
Sites can be selected via the toolbar or the Sites tab. For each parameter you can see:
| The type - Cookie, FORM or URL | |
| The name of the parameter | |
| The number of times it has been used | |
| The number of unique values | |
| The percentage change, where 0 means only one value has been used and 100 means all values are unique | |
| The flags - including cookie flags and anticsrf and session | |
| Some of the values - the full set of values may not all be visible |
Right clicking on a node will bring up a menu which will allow you to:
This will show all examples of the parameter selected in the Search tab.
This will flag the parameter as an Anti CSRF token.
This will remove the Anti CSRF token flag from the parameter.
This will mark the parameter as a Session token for the current Site and will notify the Http Sessions tool accordingly.
This will unmark the parameter as a Session token for the current site and will notify the Http Sessions tool accordingly.
| UI Overview | for an overview of the user interface |
-
ZAP User Guide
- Introduction
-
Getting Started
- Configuring proxies
-
Features
- Active Scan
- Add-ons
- Alerts
- Anti CSRF Tokens
- API
- Authentication
- Break Points
- Callbacks
- Contexts
- Data Driven Content
- Filters
- Globally Excluded URLs
- HTTP Sessions
- Man-in-the-middle Proxy
- Modes
- Notes
- Passive Scan
- Scan Policies
- Scope
- Session Management
- Spider
- Statistics
- Structural Modifiers
- Structural Parameters
- Tags
- Users
- Scanner Rules
- A Simple Penetration Test
-
The User Interface
- Overview
- The Top Level Menu
- The Top Level Toolbar
- The Tabs
-
The Dialogs
- Active Scan
- Add Alert
- Add Break Point
- Add Note
- Encode/Decode/Hash
- Filter
- Find
- History Filter
- Manual Request Editor
- Manage Add-ons
- Manage Tags
-
Options
- Active Scan
- Active Scan Input Vectors
- Alerts
- Anti CSRF Tokens
- API
- Breakpoints
- Callback Address
- Certificate
- Check for Updates
- Connection
- Database
- Display
- Dynamic SSL Certificates
- Extensions
- Global Exclude URL
- HTTP Sessions
- JVM
- Keyboard
- Language
- Local Proxies
- Passive Scan Rules
- Passive Scan Tags
- Passive Scanner
- Rule Configuration
- Scripts
- Search
- Spider
- Statistics
- Persist Session
- Resend
- Scan Policy Manager
- Scan Progress
- Session
- Spider
- The Footer
- Command Line
- Add Ons
- Releases
- Paros Proxy
- Credits