File tree Expand file tree Collapse file tree 2 files changed +68
-0
lines changed Expand file tree Collapse file tree 2 files changed +68
-0
lines changed Original file line number Diff line number Diff line change @@ -3,6 +3,9 @@ All notable changes to the 'other' section of this repository will be documented
33
44The format is based on [ Keep a Changelog] ( https://keepachangelog.com/en/1.0.0/ ) .
55
6+ ### 2025-09-30  
7+ -  Added af-plans/FullScanGinNJuiceAuth.yaml
8+ 
69### 2025-02-21  
710-  Added af-plans/BrowserAuthTest.yaml
811
Original file line number Diff line number Diff line change 1+ ---
2+ #  A simple plan for performing an authenticated scan against Gin n Juice Shop.
3+ #  It does not currently support OAST which is required for some of the known vulnerabilities.
4+ env :
5+   contexts :
6+   - name : Gin N Juice Shop 
7+     urls :
8+     - https://ginandjuice.shop 
9+     includePaths :
10+     - https://ginandjuice.shop.* 
11+     excludePaths :
12+     - https://ginandjuice.shop/logout 
13+     authentication :
14+       method : browser 
15+       parameters :
16+         loginPageUrl : https://ginandjuice.shop/login 
17+         browserId : firefox-headless 
18+         loginPageWait : 1 
19+         steps : [] 
20+       verification :
21+         method : poll 
22+         loggedInRegex : \Q 200 OK\E 
23+         loggedOutRegex : \Q 302 Found\E 
24+         pollFrequency : 60 
25+         pollUnits : requests 
26+         pollUrl : https://ginandjuice.shop/my-account 
27+         pollPostData : " " 
28+     sessionManagement :
29+       method : headers 
30+     users :
31+     - name : carlos 
32+       credentials :
33+         password : hunter2 
34+         username : carlos 
35+   parameters : {} 
36+ jobs :
37+ - type : spider 
38+   parameters :
39+     context : Gin N Juice Shop 
40+     user : carlos 
41+ - type : spiderAjax 
42+   parameters :
43+     context : Gin N Juice Shop 
44+     user : carlos 
45+     browserId : firefox-headless 
46+     excludedElements :
47+     - description : Logout 
48+       element : a 
49+       text : Log out 
50+ - type : passiveScan-wait 
51+   parameters : {} 
52+ - type : activeScan 
53+   parameters :
54+     context : Gin N Juice Shop 
55+     user : carlos 
56+   policyDefinition :
57+     defaultStrength : medium 
58+     defaultThreshold : medium 
59+ - parameters :
60+     template : " modern" 
61+     reportTitle : " ZAP Scanning Report" 
62+     reportDescription : " " 
63+   name : " report" 
64+   type : " report" 
65+ 
    
 
   
 
     
   
   
          
     
  
    
     
 
    
      
     
 
     
    You can’t perform that action at this time.
  
 
    
  
     
    
      
        
     
 
       
      
     
   
 
    
    
  
 
  
 
     
    
0 commit comments