Manual Authentication
Manual Authentication in Invicti Standard is an authentication configuration that allows you to import requests from various file formats, such as Postman and Fiddler. Invictireplays these requests at the beginning of a scan to implement authentication. You can also configure the logout detection so that Invicti replays these requests while the scan is in progress if logout occurs.
Manual Authentication Fields
This table lists and explains the fields in the Manual Authentication section.
Field |
Description |
Enabled |
Select to enable Manual Authentication. Once enabled, the Authentication Settings and Logout Detection fields are clickable. |
Test Credentials |
Click to test the configured settings. |
Authentication Settings |
These are authentication settings you can add, edit, delete, clear, search import or enter. |
Add |
Click to add a new link. |
Edit |
Click to edit a selected link. |
Delete |
Click to delete a selected link. |
Clear |
Click to clear imported links. |
Search |
Click to toggle the find panel. |
Import From File |
Click to select file type from dropdown list. |
Enter Links |
Click to enter links manually. |
Method |
This is the method of imported HTTP requests. |
URL |
This is the URL from the imported requests. |
Logout Detection |
This section contains the logout detection options. |
None |
This is if you want no logout detection. |
Redirect Based |
This enables redirect based detection by entering a Redirect URL. |
Keyword Based |
This enables keyword based detection by entering a Keyword Pattern and checking Is Regex, if the pattern is a RegEx pattern. |
For further information, see How Does Logout Detection Work?, How to Configure Redirect-Based Logout Detection in Invicti Standard, and How to Configure Keyword-Based Logout Detection in Invicti Standard.
How to Configure Manual Authentication with Authentication Settings in Invicti Standard
- Open Invicti Standard.
- The Start a New Website or Web Service Scan dialog is displayed.
- Click the Manual tab. The Manual Authentication section is displayed.
- Check Enabled.
The Authentication Settings tab is displayed.
- To add your requests, click:
- Add to display the Add New Link dialog
- Import From File to display the Import from File dropdown
- Enter Links to display the Enter Links/HTTP Requests dialog
(See Configuring Additional Websites for information on how to import links for additional websites in Invicti Standard.)
- Click Start Scan.
How to Configure Manual Authentication with Logout Detection in Invicti Standard
- Open Invicti Standard.
- From the Home tab, click New. The Start a New Website or Web Service Scan dialog is displayed.
- Click the Manual tab.
- Check Enabled.
- Click the Logout Detection tab.
- To add your requests, click:
- None for no logout detection
- Redirect Based for display the Redirect URL field
- Keyword Based to display the Keyword Pattern and Is Regex check
See Logout Detection.
- Click Start Scan.