1N3 / Sn1per

Attack Surface Management Platform
https://sn1persecurity.com
Other
7.9k stars 1.82k forks source link

OWASP ZAP Error: Failed to attack the URL: received handshake warning: unrecognized_name #298

Closed digitizeddude closed 3 years ago

digitizeddude commented 3 years ago

Hello,

I've run in to three different issues with sn1per community and pro when i run a web scan.

First, i'm running in to some weird issue with ZAP. The error i'm getting is: Failed to attack the URL: received handshake warning: unrecognized_name. I'm presuming that this might be specific to ZAP but i've never seen this error before and there is some limited info online on this cause the issues should have been addressed on ZAP 2.4 so i'm not sure if this is sn1per + zap specific or if it is just zap. If it is zap alone then i can ask the team there, i just wanted to check in with sn1per users first to see if they found a fix for this.

In response to zap not functioning the way i need it to for this one engagement

1N3 commented 3 years ago

Just cleaning this up a bit and creating 3 separate issues to track them.

https://github.com/1N3/Sn1per/issues/299

https://github.com/1N3/Sn1per/issues/300

digitizeddude commented 3 years ago

Thanks for cleaning it up.

Out of curiosity, I’ve never used GitHub in any major way so I’m new to it. But I do notice that since I’ve worked on sn1per on several issues with your support team since is started using it in a more meaningful way. Am I able to help reply to support issues or work with you guys on improving the software?

Thanks.

From: xer0dayzmailto:notifications@github.com Sent: Wednesday, November 11, 2020 12:38 PM To: 1N3/Sn1permailto:Sn1per@noreply.github.com Cc: digitizeddudemailto:digitized@live.com; Authormailto:author@noreply.github.com Subject: Re: [1N3/Sn1per] OWASP ZAP Error: Failed to attack the URL: received handshake warning: unrecognized_name (#298)

Just cleaning this up a bit and creating 3 separate issues to track them.

299https://github.com/1N3/Sn1per/issues/299

300https://github.com/1N3/Sn1per/issues/300

— You are receiving this because you authored the thread. Reply to this email directly, view it on GitHubhttps://github.com/1N3/Sn1per/issues/298#issuecomment-725560638, or unsubscribehttps://github.com/notifications/unsubscribe-auth/ARW74DBEN7AXJNKPXTF6R6LSPLDYDANCNFSM4TSIANYQ.

1N3 commented 3 years ago

Absolutely. Anything you can contribute to assist or help is definitely appreciated. 👍

1N3 commented 3 years ago

For starters on this, it would help to know your environment more.

Which version of ZAP are you running? I believe you're running the latest Kali release? Are you able to disclose the target URL? If not, no worries... it would just help to troubleshoot as it might be site specific.

digitizeddude commented 3 years ago

Hi,

Thanks. My mistake.

The environment is as follows: Kali 2020.3 kali-rolling Owasp ZAP 2.9.0 BurpSuite Pro 2020.11 Sn1per 8.8

From: xer0dayzmailto:notifications@github.com Sent: Wednesday, November 11, 2020 12:50 PM To: 1N3/Sn1permailto:Sn1per@noreply.github.com Cc: digitizeddudemailto:digitized@live.com; Authormailto:author@noreply.github.com Subject: Re: [1N3/Sn1per] OWASP ZAP Error: Failed to attack the URL: received handshake warning: unrecognized_name (#298)

For starters on this, it would help to know your environment more.

Which version of ZAP are you running? I believe you're running the latest Kali release? Are you able to disclose the target URL? If not, no worries... it would just help to troubleshoot as it might be site specific.

— You are receiving this because you authored the thread. Reply to this email directly, view it on GitHubhttps://github.com/1N3/Sn1per/issues/298#issuecomment-725567464, or unsubscribehttps://github.com/notifications/unsubscribe-auth/ARW74DHQ3WWHH2FIHDF33GTSPLFGRANCNFSM4TSIANYQ.

1N3 commented 3 years ago

Have you tried running webscan against any other targets?

Can you try running a test scan against testfire.net?

sniper -t testfire.net -m webscan -w testfire.net
digitizeddude commented 3 years ago

Not yet. But i'll run it on testfire and let you know the results.

From: xer0dayzmailto:notifications@github.com Sent: Wednesday, November 11, 2020 12:50 PM To: 1N3/Sn1permailto:Sn1per@noreply.github.com Cc: digitizeddudemailto:digitized@live.com; Authormailto:author@noreply.github.com Subject: Re: [1N3/Sn1per] OWASP ZAP Error: Failed to attack the URL: received handshake warning: unrecognized_name (#298)

For starters on this, it would help to know your environment more.

Which version of ZAP are you running? I believe you're running the latest Kali release? Are you able to disclose the target URL? If not, no worries... it would just help to troubleshoot as it might be site specific.

— You are receiving this because you authored the thread. Reply to this email directly, view it on GitHubhttps://github.com/1N3/Sn1per/issues/298#issuecomment-725567464, or unsubscribehttps://github.com/notifications/unsubscribe-auth/ARW74DHQ3WWHH2FIHDF33GTSPLFGRANCNFSM4TSIANYQ.

digitizeddude commented 3 years ago

It looks like its the site that is causing zap to fail. I'll ask on their project page.