OWASP's ZAP and the Fuzz ability

Viewed 11679

My scenario:

I navigate to a login page. I put in a known username with a bad password. ZAP picks this up no issue.

I select the POST to the login page. I find the lines that contain the Username and password. The password: ctl00%24ContentPlaceHolder1%24cpLoginAspx%24ctl00%24LoginControl1%24LTLogin%24Password=12345&

I highlight the 12345 and right click to select Fuzz. I had put in a custom list with the correct password for the test account and I select that.

When I do, it works its way through the list as I expected. Changing the 12345 to the various options in the list.

But, when it gets to the word I KNOW is the correct password. It does nothing different to alert me that it was correct. The password in this case was Password5. I expected that it would reflect or something showing it was directed to a new page. But, that happens for 'password' which is not correct for the test user.

I see this in the Fuzzer tab: enter image description here

1 Answers
Related