• Icon: Bug Bug
    • Resolution: Not A Defect
    • Icon: Minor Minor
    • zaproxy-plugin

      Hello Ludovic,

      I'm trying to set up ZAP under Jenkins using Selenium, but I cannot get the same results as ZAP GUI on my desktop.

      General information :

      • My webapp for testing is DVWA
      • Capture a user sequence using Selenium plugin for Firefox
      • Launch a ZAP scan (Default Profile using HIGH and INSANE) via GUI (firefox is wired to the ZAP proxy) using the same sequence, export results
      • Doing the same thing using Jenkins, start ZAP proxy, configure Firefox to go through ZAP proxy, launch selenium tests, launch scans using the Zap plugin.

      But it won't show me any High alerts (at least, it should show me an SQLI alert)
      (cf: jenkins build logs attached)

      Am I doing something wrong ?

      EDIT : reports CI and Desktop added + job configuration

      Cheers,
      Farid.

        1. SeleniumConfigLudovic.PNG
          SeleniumConfigLudovic.PNG
          17 kB
        2. sel_test.html
          2 kB
        3. set_suite.html
          0.5 kB
        4. report_zap.html
          88 kB
        5. jenkins_2.png
          jenkins_2.png
          35 kB
        6. jenkins_1.png
          jenkins_1.png
          36 kB
        7. report_zap_jenkins.html
          1.18 MB
        8. testresult.html
          5 kB
        9. rapport_desktop.html
          91 kB
        10. stdout.txt
          33 kB

          [JENKINS-29265] Active scan not working with selenium

          Farid Boukerche created issue -
          Farid Boukerche made changes -
          Attachment New: report_zap_jenkins.html [ 30144 ]
          Attachment New: testresult.html [ 30145 ]
          Attachment New: rapport_desktop.html [ 30146 ]
          Description Original: Hello Ludovic,

          I'm trying to set up ZAP under Jenkins using Selenium, but I cannot get the same results as ZAP GUI on my desktop.

          General information :
           - My webapp for testing is DVWA
           - Capture a user sequence using Selenium plugin for Firefox
           - Launch a ZAP scan (Default Profile using HIGH and INSANE) via GUI (firefox is wired to the ZAP proxy) using the same sequence, export results
           - Doing the same thing using Jenkins, start ZAP proxy, configure Firefox to go through ZAP proxy, launch selenium tests, launch scans using the Zap plugin.

          But it won't show me any High alerts :( (at least, it should show me an SQLI alert)
          (cf: jenkins build logs attached)

          Am I doing something wrong ?

          Cheers,
          Farid.
          New: Hello Ludovic,

          I'm trying to set up ZAP under Jenkins using Selenium, but I cannot get the same results as ZAP GUI on my desktop.

          General information :
           - My webapp for testing is DVWA
           - Capture a user sequence using Selenium plugin for Firefox
           - Launch a ZAP scan (Default Profile using HIGH and INSANE) via GUI (firefox is wired to the ZAP proxy) using the same sequence, export results
           - Doing the same thing using Jenkins, start ZAP proxy, configure Firefox to go through ZAP proxy, launch selenium tests, launch scans using the Zap plugin.

          But it won't show me any High alerts :( (at least, it should show me an SQLI alert)
          (cf: jenkins build logs attached)

          Am I doing something wrong ?

          EDIT : reports CI and Desktop added

          Cheers,
          Farid.
          Farid Boukerche made changes -
          Attachment New: jenkins_1.png [ 30147 ]
          Attachment New: jenkins_2.png [ 30148 ]
          Description Original: Hello Ludovic,

          I'm trying to set up ZAP under Jenkins using Selenium, but I cannot get the same results as ZAP GUI on my desktop.

          General information :
           - My webapp for testing is DVWA
           - Capture a user sequence using Selenium plugin for Firefox
           - Launch a ZAP scan (Default Profile using HIGH and INSANE) via GUI (firefox is wired to the ZAP proxy) using the same sequence, export results
           - Doing the same thing using Jenkins, start ZAP proxy, configure Firefox to go through ZAP proxy, launch selenium tests, launch scans using the Zap plugin.

          But it won't show me any High alerts :( (at least, it should show me an SQLI alert)
          (cf: jenkins build logs attached)

          Am I doing something wrong ?

          EDIT : reports CI and Desktop added

          Cheers,
          Farid.
          New: Hello Ludovic,

          I'm trying to set up ZAP under Jenkins using Selenium, but I cannot get the same results as ZAP GUI on my desktop.

          General information :
           - My webapp for testing is DVWA
           - Capture a user sequence using Selenium plugin for Firefox
           - Launch a ZAP scan (Default Profile using HIGH and INSANE) via GUI (firefox is wired to the ZAP proxy) using the same sequence, export results
           - Doing the same thing using Jenkins, start ZAP proxy, configure Firefox to go through ZAP proxy, launch selenium tests, launch scans using the Zap plugin.

          But it won't show me any High alerts :( (at least, it should show me an SQLI alert)
          (cf: jenkins build logs attached)

          Am I doing something wrong ?

          EDIT : reports CI and Desktop added + job configuration

          Cheers,
          Farid.
          Farid Boukerche made changes -
          Attachment New: report_zap.html [ 30150 ]
          Farid Boukerche made changes -
          Attachment New: sel_test.html [ 30156 ]
          Attachment New: set_suite.html [ 30157 ]
          Ludovic Roucoux made changes -
          Attachment New: SeleniumConfigLudovic.PNG [ 30189 ]
          Ludovic Roucoux made changes -
          Resolution New: Not A Defect [ 7 ]
          Status Original: Open [ 1 ] New: Closed [ 6 ]
          R. Tyler Croy made changes -
          Workflow Original: JNJira [ 164134 ] New: JNJira + In-Review [ 208962 ]

            ludovicroucoux Ludovic Roucoux
            pythondz Farid Boukerche
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved: