TOC & Recently Viewed

Recently Viewed Topics

Configure Login Form Authentication

These steps describe how to check the authentication values for the Login Form authentication method in the Credentials settings for the Web App Overview and Web App Scan templates.

These steps assume that you already have a login form ready to test your credentials.

Steps

  1. For the web application you want to scan, access the login page.

  2. Type your credentials as necessary.

  3. Upon successful authentication, in the browser console, locate the call that performs the authentication. In this example, the call is login.

    The Form Data section displays the key/value pairs. In this example, they are uname: Nessus, upass: WAS, and udomain: Tenable.io.

  4. In Tenable.io Web Application Scanning, either create a new scan, or access the scan settings for which you want to add credentials.
  5. In the scan settings, click the Credentials tab.
  6. Click General.
    1. In the Authentication Method drop-down box, select Login Form.
    2. In the Login Page box, type the URL for your login form page.
    3. In the Regex to verify successul auth box, type the regex to match when the credentials are correct.

      Note: In many cases, this is text that appears on the login page (e.g., Login Successful!)

    4. In the Credentials boxes, type the key/value pairs that you retrieved in step 3.

  7. Click the Save button.

Copyright 2017. Tenable Network Security, Inc. All rights reserved. Tenable Network Security, Nessus, SecurityCenter Continuous View, Passive Vulnerability Scanner, and Log Correlation Engine are registered trademarks of Tenable Network Security, Inc. All other products or services are trademarks of their respective owners.