Wednesday, 3 February 2016

OWASP ZAP Fuzzing -1 [Multiple Parameters/Payloads + Message Processors]

 Fuzzing Multiple Parameters and tagging Custom Response String (using Message Processors) to associate a successful event --This can be useful to Brute Force username and password at the login page and use a text from successful login to tag (Message Processors) the success of right combination of username and password. This way fuzzing can be stopped at an earlier stage.

No comments:

Post a Comment