Configuring and Verifying Form Authentication
When using Acunetix 360 to scan a web application that has a form-based login, you need to configure the credentials and verify the session. Session verification is important to confirm that the configuration is correct and to ensure that the scanner can differentiate between a logged-in and a logged-out session. This enables the scanner to identify a terminated session so that if it happens during a web vulnerability scan, the scanner can automatically log back in again, ensuring all password-protected pages are scanned.
This document explains how to:
- Set up a scan with a form-based login component
- Verify that your form authentication configuration is correct
TIP: You can integrate Acunetix 360 with a Privileged Access Management solution so that you do not have to enter sensitive credentials to scan the web application. For more information, refer to Integrating Acunetix 360 with HashiCorp Vault and Integrating Acunetix 360 with CyberArk Vault. |
How to configure form authentication
- Select Scans > New Scan from the left-side menu.
- Confirm the Target URL and Scan Profile.
- In the Scan Settings options, select Form (under Authentication).
- Click the checkbox to enable Form Authentication.
- Enter the Login Form URL. This is the URL (including the protocol HTTP or HTTPS) of the login form that the scanner will access .
- If required, select the Override Target URL With Authenticated Page checkbox. This setting enables the system to use the last page from the authentication process as the start URL, instead of the Target URL.
- If required, select the Detect Bearer Authorization Token checkbox. If there is an AJAX request after the login is performed, Bearer Authentication Tokens will be intercepted and used during the scan.
- If required, click Token Matching Rules. This enables you to enter a token regular expression if Acunetix 360 is required to get the token from a website other than the Target URL. Configure this option only if you want Acunetix 360 to capture the token from a website and then use the same token for different websites.
- If required, select the Enable enhanced authentication event logging checkbox. This setting allows Acunetix 360 to collect enhanced logs for diagnostic purposes that will help troubleshoot authentication issues if they occur.
- In the Personas section, click + New Persona. Then, enter the Username and Password for the login form that the scanner will use.
TIP: You can specify multiple sets of credentials, and select the Active option next to the credentials Acunetix 360 should use during the upcoming scan. |
- If required, select the ellipsis (...) in the OTP field to configure One-Time-Password settings. For further instructions, refer to Configuring Form Authentication with OTP.
How to verify form authentication configuration
- Select Verify Login & Logout so the scanner can test the login and determine a pattern to use to automatically detect logged-in and logged-out sessions.
NOTE: If automatic authentication does not work for your website, you can click Custom Script and enter a JavaScript script that will be used to authenticate against the web application. For more information, refer to Custom Scripts for Form Authentication. |
- The Verify Form Authentication window is displayed, showing the progress of the test.
- During verification, the following occurs:
- On the left, the scanner logs in to the web application using the supplied credentials and displays a logged-in session.
- On the right, the scanner displays how the web application looks when not logged in. It also displays the Logout Detection pattern.
- Once the test is ready, it is important that you:
- Confirm that both logged-in and logged-out sessions look as expected.
- Confirm that the logout detection pattern is correct since this will be used by the scanner to identify a terminated session and log back in to continue the scan.
For more information, refer to Logout Detection.