Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

OWASP ZAP Error: Failed to attack the URL: received handshake warning: unrecognized_name #298

Closed
digitizeddude opened this issue Nov 11, 2020 · 8 comments

Comments

@digitizeddude
Copy link

digitizeddude commented Nov 11, 2020

Hello,

I've run in to three different issues with sn1per community and pro when i run a web scan.

First, i'm running in to some weird issue with ZAP. The error i'm getting is: Failed to attack the URL: received handshake warning: unrecognized_name. I'm presuming that this might be specific to ZAP but i've never seen this error before and there is some limited info online on this cause the issues should have been addressed on ZAP 2.4 so i'm not sure if this is sn1per + zap specific or if it is just zap. If it is zap alone then i can ask the team there, i just wanted to check in with sn1per users first to see if they found a fix for this.

In response to zap not functioning the way i need it to for this one engagement

@1N3 1N3 changed the title Sniper pro and some weird issues OWASP ZAP Error: Failed to attack the URL: received handshake warning: unrecognized_name Nov 11, 2020
@1N3
Copy link
Owner

1N3 commented Nov 11, 2020

Just cleaning this up a bit and creating 3 separate issues to track them.

#299

#300

@digitizeddude
Copy link
Author

digitizeddude commented Nov 11, 2020 via email

@1N3
Copy link
Owner

1N3 commented Nov 11, 2020

Absolutely. Anything you can contribute to assist or help is definitely appreciated. 👍

@1N3
Copy link
Owner

1N3 commented Nov 11, 2020

For starters on this, it would help to know your environment more.

Which version of ZAP are you running?
I believe you're running the latest Kali release?
Are you able to disclose the target URL? If not, no worries... it would just help to troubleshoot as it might be site specific.

@digitizeddude
Copy link
Author

digitizeddude commented Nov 11, 2020 via email

@1N3
Copy link
Owner

1N3 commented Nov 11, 2020

Have you tried running webscan against any other targets?

Can you try running a test scan against testfire.net?

sniper -t testfire.net -m webscan -w testfire.net

@digitizeddude
Copy link
Author

digitizeddude commented Nov 11, 2020 via email

@digitizeddude
Copy link
Author

It looks like its the site that is causing zap to fail. I'll ask on their project page.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants