-
-
Notifications
You must be signed in to change notification settings - Fork 135
HelpAddonsWebsocketTab
The WebSockets tab displays all messages from WebSocket connections. While ZAP is active, visit e.g.: Mozilla's BrowserQuest to see WebSockets in action.
You can restrict the display of messages to one specific WebSocket channel or all. If you select a specific channel, then the Show handshake button () becomes enabled. When you click on it, the corresponding HTTP handshake is shown in the Request/Response tab.
In the filter dialog () you can further control which messages are displayed.
You can set custom breakpoints using the Add Custom Breakpoints button (). Alternatively you can use the Right click menu.
Right clicking on a WebSocket message will bring up a menu which will allow you to:
WebSocket connections can be excluded from the WebSockets tab by adding an excluded URL to the Session Properties. Clicking on this item, brings up the session properties with the URL pre-filled. Excluding a WebSocket connection will not result in closing the connection, but in forwarding them without further processing.
This will bring up the Add Break Point dialog which allows you to set up a custom break point.
-
ZAP User Guide
- Introduction
-
Getting Started
- Configuring proxies
-
Features
- Active Scan
- Add-ons
- Alerts
- Anti CSRF Tokens
- API
- Authentication
- Break Points
- Callbacks
- Contexts
- Data Driven Content
- Filters
- Globally Excluded URLs
- HTTP Sessions
- Man-in-the-middle Proxy
- Modes
- Notes
- Passive Scan
- Scan Policies
- Scope
- Session Management
- Spider
- Statistics
- Structural Modifiers
- Structural Parameters
- Tags
- Users
- Scanner Rules
- A Simple Penetration Test
-
The User Interface
- Overview
- The Top Level Menu
- The Top Level Toolbar
- The Tabs
-
The Dialogs
- Active Scan
- Add Alert
- Add Break Point
- Add Note
- Encode/Decode/Hash
- Filter
- Find
- History Filter
- Manual Request Editor
- Manage Add-ons
- Manage Tags
-
Options
- Active Scan
- Active Scan Input Vectors
- Alerts
- Anti CSRF Tokens
- API
- Breakpoints
- Callback Address
- Certificate
- Check for Updates
- Connection
- Database
- Display
- Dynamic SSL Certificates
- Extensions
- Global Exclude URL
- HTTP Sessions
- JVM
- Keyboard
- Language
- Local Proxies
- Passive Scan Rules
- Passive Scan Tags
- Passive Scanner
- Rule Configuration
- Scripts
- Search
- Spider
- Statistics
- Persist Session
- Resend
- Scan Policy Manager
- Scan Progress
- Session
- Spider
- The Footer
- Command Line
- Add Ons
- Releases
- Paros Proxy
- Credits