diff --git a/src/main/java/org/zaproxy/zap/extension/jwt/JWTActiveScanRule.java b/src/main/java/org/zaproxy/zap/extension/jwt/JWTActiveScanRule.java index d1857c8..e8b7d2e 100644 --- a/src/main/java/org/zaproxy/zap/extension/jwt/JWTActiveScanRule.java +++ b/src/main/java/org/zaproxy/zap/extension/jwt/JWTActiveScanRule.java @@ -68,7 +68,7 @@ public void init() { maxRequestCount = 8; break; case HIGH: - maxRequestCount = 12; + maxRequestCount = 18; break; case INSANE: maxRequestCount = 28; @@ -105,9 +105,7 @@ public void scan(HttpMessage msg, String param, String value) { } if (JWTConfiguration.getInstance().isEnableClientConfigurationScan()) { - if (performAttackClientSideConfigurations(msg, param)) { - return; - } + performAttackClientSideConfigurations(msg, param); this.decreaseRequestCount(); } performAttackServerSideConfigurations(msg, param, jwtHolder, value);