DAST Scanning
Receiving a 403 Forbidden For All Requests
1min
Some firewalls have a default configuration which will block DAST scans. The ZAP scanner sends a identification header on each request, X-Scanner: ZAP which may be an indicator to your WAF to block the request. A false-positive issue may then be created in SOOS.
This can be verified by running the curl command associated with the SOOS issue, first as written, and then a second time without the X-Scanner header to see if it makes a difference in the response.
data:image/s3,"s3://crabby-images/14f88/14f88f4a6013832952a0194ad219a57f507d3b31" alt="Document image Document image"
It may be necessary to create a specific exception in your firewall to allow the DAST scan to run.
Updated 25 Feb 2025
Did this page help you?