Skip to content

Conversation

@e1l1ya
Copy link

@e1l1ya e1l1ya commented Oct 26, 2025

These files add to this changes:

  1. Add Web Cache Deception script for targeted scripts

@psiinon
Copy link
Member

psiinon commented Oct 26, 2025

Logo
Checkmarx One – Scan Summary & Details7e28f3cf-da43-4461-af17-b7781a82f630

Great job! No new security vulnerabilities introduced in this pull request


Use @Checkmarx to reach out to us for assistance.

Just send a PR comment with @Checkmarx followed by a natural language request.

Examples: @Checkmarx how are you able to help me? @Checkmarx rescan this PR

@kingthorin
Copy link
Member

@e1l1ya e1l1ya force-pushed the main branch 2 times, most recently from 072e849 to f9ac05a Compare October 27, 2025 06:39
@e1l1ya
Copy link
Author

e1l1ya commented Oct 27, 2025

Hi again i add the sign-off the commit.

Copy link
Member

@kingthorin kingthorin left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I haven't been able to test it. I don't see anything obviously wrong. Have you tested that the host header is set as you expect?

@kingthorin
Copy link
Member

You should also add an entry in the changelog as part of the unreleased/added section
https://github.com/zaproxy/community-scripts/blob/main/CHANGELOG.md

@thc202
Copy link
Member

thc202 commented Oct 30, 2025

The filename should also follow the guidelines: https://github.com/zaproxy/community-scripts/blob/main/CONTRIBUTING.md#naming-scripts

Signed-off-by: eiliya keshtkar <[email protected]>
Signed-off-by: eiliya keshtkar <[email protected]>
Signed-off-by: eiliya keshtkar <[email protected]>
Signed-off-by: eiliya keshtkar <[email protected]>
Signed-off-by: eiliya keshtkar <[email protected]>
Copy link
Member

@kingthorin kingthorin Nov 10, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Any time it sends I'd suggest a try/catch. In the catch it should probably just bail with a message that an error occurred and quote the exception.getMessage(). Instead of just barfing over and over and over:

Ex:

------------------------------------------------------------
Target: https://scanme.nmap.org/
------------------------------------------------------------
[+] Starting Web Cache Deception tests...
[i] Base: https://scanme.nmap.org/

[!] Error sending to: https://scanme.nmap.org/;cachetest => java.net.NoRouteToHostException: No route to host
[!] Error sending to: https://scanme.nmap.org/%00cachetest => java.net.NoRouteToHostException: No route to host
[!] Error sending to: https://scanme.nmap.org/%0Acachetest => java.net.NoRouteToHostException: No route to host
[!] Error sending to: https://scanme.nmap.org/%09cachetest => java.net.NoRouteToHostException: No route to host
[!] Error sending to: https://scanme.nmap.org/.cachetest => java.net.NoRouteToHostException: No route to host
[!] Error sending to: https://scanme.nmap.org//cachetest => java.net.NoRouteToHostException: No route to host
[!] Error sending to: https://scanme.nmap.org/~cachetest => java.net.NoRouteToHostException: No route to host

Actually I guess it's when your sending method returns null, it may as well bail from whatever loop it's in.

Comment on lines +36 to +39
// Set Host header properly
var host = uri.getHost();
var port = uri.getPort();
msg.getRequestHeader().setHeader("Host", port > 0 && port !== 80 && port !== 443 ? host + ":" + port : host);
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

When are you finding that it isn't set "properly"??

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

4 participants