2020 λ§μ§λ§μ΄ μΌλ§ λ¨μ§ μμ μ€λ λλμ΄ ZAP 2.10.0μ΄ λ¦΄λ¦¬μ¦ λμμ΅λλ€. κ·Έλμ dark mode λ±μ μ΄μ λ‘ weekly λ²μ μ μ¬μ©νμλλ°, μ΄μ λ 곡μ λ²μ μΌλ‘ λμ΄κ°λ μ’μ κ² κ°λ€μ.
μ€λμ κ°λ³κ² 2.10.0 μ λ¦΄λ¦¬μ¦ λ ΈνΈλ₯Ό μ΄ν΄λ³΄κ³ , λͺκ°μ§ κΉ¨μκ°μ κΈ°λ₯μ μκ°ν κΉ ν©λλ€.
λλμ΄ Release μμμ΄!
TL;DR
- κΈ°λ₯μ΄ λ§μ΄ μΆκ°λ¬μ΄μ. μμΈν건 λ¦΄λ¦¬μ¦ λ ΈνΈλ₯Ό 보μΈμ
- λ¦΄λ¦¬μ¦ λ ΈνΈμ μλ κΈ°λ₯μ΄ μμ΄μ. μ κΈμ λμΆ© μ νμμΌλ μ°Έκ³ νμΈμ
- μ΄λ² μ λ°μ΄νΈλ νμμ΄λ λΉ λ₯΄κ² μ λ°μ΄νΈ κ°μμ£ .
ZAP 2.10.0 Released Note
Escape Java 8 verison, Go 11!
ZAPμ ꡬν μλ° λ²μ μ μ μ§ν΄μΌνλ μ΄μκ° μμμ΅λλ€. μ΄λ ZAPμͺ½μμλ μ½ 10λ λ§μ μμ λλ μ΄μμ΄κ³ μ΄ λ¬Έμ λ‘ ZAPμ μμ€ν μ μλ°λ₯Ό μ¬μ©νλ κ²μ΄ μλ ZAP λ΄λΆμ Java SDKλ₯Ό κ°μ§κ³ μ€ννλ ννλ‘ λμνμμ΅λλ€. λ¬Όλ‘ μ΄λ‘μΈν΄μ μμ€ν μλ°κ° λ¬Έμ κ° μκΈ΄ κ²½μ°μλ μ§μ₯λ°μ§ μκ³ μ€νν μ μμμ΅λλ€. λ€λ§ μ΄μ λ μλ° 8 λ²μ μ μμ‘΄μ±μ λ²μ΄λ κ²μ΄κΈ° λλ¬Έμ λ κ±°μ μλ°μ λ¬Έμ λ₯Ό νΌν΄κ° μ μλ κΈ°νκ° λμλ€μ :D
Custom pages
Custom Pages can be defined on a per context basis - these allow ZAP to identify various non-standard error handling conditions such as custom error pages and handle them more effectively.
μ΄μ λΆν° Custom pageλ₯Ό Context(Burpμμ Scope) λ³λ‘ μ μνμ¬ μ¬μ©ν μ μμ΅λλ€.
μ΄κ²λ νμ©ν μ μλ λΆλΆμ΄ λ§μ κΈ°λ₯μΈλ°μ, μλΉμ€ λ³λ‘ 200 OK λμ€λ Custom Error νμ΄μ§κ° μ‘΄μ¬ν μ μμ΅λλ€. μ΄λ¬ν νμ΄μ§λ€μ 미리 μ μν΄μ Fuzzingμ΄λ ν μ€ν λ¨κ³μμ κ±Έλ¬λΌ μ μμ΅λλ€.
Authentication Polling
The concept of Authentication Verification Strategies has been introduced which allows ZAP to handle a wider range of authentication mechanisms including the option to poll a specified page for the authentication status of a user.
Authentication Verification Strategies κ°λ μ λμ νλ€κ³ ν©λλ€. μ§μ λ νμ΄μ§λ₯Ό Polling νλ λ°©μμΌλ‘ μΈμ¦ μνλ₯Ό 체ν¬νλ λ°©λ²μ λλ€.
Site Tree Control
Scripts and add-ons now have full access to how nodes are represented in the Sites Tree. Both Input Vector Scripts and add-ons which include implementations of the Variant class can change both the tree structure and names used for new nodes.
μ€μν μ λ°μ΄νΈ λΆλΆ μ€ νλ μΈλ°μ, 2.10 λΆν° Add-On κ³Ό Scriptsμμ Site treeλ₯Ό μ μ΄ν μ μμ΄μ§λλ€. μ΄λ νμ₯ κΈ°λ₯λ€μ΄ μ‘°κΈ λ μ μ°νκ² κ°λ°λ μ μλλ‘ μ λλ κ² κ°λ€μ. μ΄μ©λ Sites treeλ₯Ό μ μ΄νλ©΄ μ΄λ―Έ μμ§λ Endpoint URLμ μ»κ±°λ μΆκ°/μμ νλ λ°©μμΌλ‘λ μ¬μ©ν μ μμ΄μ κ°μΈμ μΌλ‘ λ§μλλ λΆλΆμ λλ€.
Dynamic Look and Feel (Dark mode)
The Desktop UI includes a new set of open source Look and Feelβs c/o FlatLaf including 2 Dark Mode options. You can also dynamically switch the Look and Feel via a button on the Top Level Toolbar.
μ κ° ZAPμ κ°μ λ‘ Weekly λ²μ μ μ¬μ©νκ² λ§λ κΈ°λ₯μ λλ€. μ΄κΈ°μλ λ€ν¬λͺ¨λ μ§μλ§ μμμ§λ§ μ΄νμ λμ μΌλ‘ LaFλ₯Ό λ³κ²½ν μ μλλ‘ μΆκ°λμμ΅λλ€.
Authentication headers via env vars
A new set of environmental variables are available which allow you to easily add an authentication header to all of the requests that are proxied through ZAP or initiated by the ZAP tools, including the spiders and active scanner. These are documented on the Authentication page.
κΈ°μ‘΄μλ Custom ν€λ λ±μ μΆκ°νκΈ° μν΄μ replacerμ κ°μ νμ₯μ μ΄μ©ν΄μ λ³κ²½νμ΄μΌ ν©λλ€. μ΄λ¬ν κ³Όμ μ΄ Env VarsλΌλ νλΌλ―Έν°μ μ μνμ¬ λͺ¨λ μμ²μ μλν ν€λλ₯Ό λΆμ¬μ£Όλ λ±μ μ‘μ μ΄ κ°λ₯ν΄μ§λλ€.
SOCKS Proxy Config
It is now possible to dynamically configure the outgoing SOCKS proxy in the Optionsβ Connection screen. By default the SOCKS proxy configuration applies to all connections made by ZAP.
SOCKS Proxyλ₯Ό ZAPμμ μ μ΄ν μ μκ² λ©λλ€.
Cached scripts
The following script types are now cached between invocations reducing the time it takes to reuse them:
λͺλͺ μ νμ μ€ν¬λ¦½νΈλ€μ΄ νΈμΆκ°μ μΊμλμ΄μ μ¬μ¬μ©μ 걸리λ μκ°μ λ¨μΆνλ€κ³ ν©λλ€. μ°λ¦¬κ° λκ° λ μλ λΆλΆμ μκ³ μ²΄κ°μ μΌλ‘ μλκ° μ‘°κΈ λ λΉ¨λΌμ§κ² λ€μ.
and New/Updated Add-Ons, APIs
μΌλΆ alpha/betaμ μλ Add-Onλ€μ΄ Releaseλ‘ λμ΄μμ΅λλ€. APIλ μΆκ°λκ² μλ κ² κ°κ΅¬μ. μμΈν건 Release λ ΈνΈλ₯Ό μ°Έκ³ ν΄μ£ΌμΈμ.
μλ €μ§μ§ μμ μ λ°μ΄νΈ λ΄μ©
Content-Length κ°μ μμ κ°λ₯(for HTTP Request Smuggling)
μ΄μ Manual requestμμ Content-Lengthλ₯Ό μ μ΄ν μ μμ΅λλ€. κΈ°μ‘΄μλ ZAPμ΄ μ΄ κΈ°λ₯μ μ§μνμ§ μμμ HTTP Request Smugglingμ ν μ€ν ν λ μ‘°κΈ λΆνΈν λΆλΆμ΄ μμμ§μ. (TL:CEμ κ²½μ°λ 무쑰건 Burpμμλ§ ν μ€ν ν μ λ°μ μμμ΅λλ€)
λ€λ§ Requester κ°μ νμ₯ κΈ°λ₯μͺ½μμλ ν΄λΉ λ²νΌμ΄ λ ΈμΆλμ§ μλ κ²μΌλ‘ 보μ ν΄λΉ νμ₯ κΈ°λ₯μμ μ λ°μ΄νΈλ₯Ό ν΄μ€μΌ ν κ² κ°λ€μ.
Macμμ μ 체νλ©΄μ μ§μν¨
μ΄μ λ©λλ€. (2.9λλ μλμ κ³ μ..)