Recently Viewed Topics
Configure Login Form Authentication
These steps describe how to check the authentication values for the Login Form authentication option in the Credentials settings for the Web App Overview and Web App Scan templates.
These steps assume that you already have a login form ready to test your credentials.
To test your authentication values:
For the web application you want to scan, access the login page.
Type your credentials.
Upon successful authentication, in the browser console, locate the call that performs the authentication. In this example, the call is
The Form Data section of the Headers tab displays the key/value pairs. In this example, the pairs are
upass: WAS, and
To run a credentialed scan with login form authentication:
- In Tenable.io Web Application Scanning, either
create a new scan, or access the scan settings for which you want to add credentials.
- In the scan settings, click the Credentials tab.
- Click Web Application Authentication.
- In the Authentication Method drop-down box, select Login Form.
- In the Login Page box, type the URL for your login form page.
In the Credentials boxes, type the key/value pairs that you retrieved in step 3 of To test your authentication values.
In the Regex to verify successul auth box, type the regex to match when the credentials are correct.
Note: In many cases, the regex is text that appears on the login page (e.g.,
- In the Page to verify active session box, type the URL you want to use to verify if the session is still active.
- In the Regex to verify active session box, type the regex to match to confirm the session is still active.
- Click the Save button.