gpt4 book ai didi

Authenticated Web App Scanning in Nessus using HTTP login form and HTTP cookies import issues(在Nessus中使用HTTP登录表单和HTTP Cookie导入问题进行身份验证的Web应用程序扫描)

转载 作者:bug小助手 更新时间:2023-10-24 17:11:01 41 4
gpt4 key购买 nike



Context: Run Nessus web application scan using Authentication credentials HTTP login form (Login Form Authentication);

上下文:使用身份验证凭据运行Nessus Web应用程序扫描HTTP登录表单(登录表单身份验证);


Official guide does not help me with figuring out how to determine the login parameters of a web page;

官方指南并没有帮助我弄清楚如何确定网页的登录参数;


I have already attempted the using JSON key value pairs (for example, {"username": "%USER%","password": "%PASS%"}) and

我已经尝试使用JSON密钥值对(例如,{“UserName”:“%User%”,“Password”:“%Pass%”})和


also followed steps to resolve the issue, using information from below listed pages:

还使用下面列出的页面中的信息执行了解决问题的步骤:



  1. Web Application Vulnerability Testing with Nessus
    presentation
    ; page number: 96

  2. https://stackoverflow.com/a/50199945/10053482

  3. https://www.tenable.com/blog/scanning-web-applications-that-require-authentication

  4. https://community.tenable.com/s/article/How-to-Configure-Web-Application-Authentication-in-Tenable-io-WAS

  5. https://community.tenable.com/s/article/Credentialed-Web-App-Scanning-in-Nessus-6


But nothing helped for a web page which does not supports http URI query-string parameters based login.

但对于不支持基于http URI查询字符串参数的登录的网页来说,这无济于事。




Another issue that I am encountering is I am not able to debug why Authentication / Credential Info (Hosts) using HTTP cookies import (Cookie Authentication) is Failing

我遇到的另一个问题是,我无法调试为什么使用HTTP Cookie导入(Cookie身份验证)的身份验证/凭据信息(主机)失败


For this I tried changing the logs settings as listed below

为此,我尝试更改日志设置,如下所示


log_details: yes
log_whole_attack: yes
backend_log_level: debug

But I dont see any useful information in logs to understand why the authenticated scan is failing with using Cookie Authentication

但我在日志中看不到任何有用的信息,无法理解使用Cookie身份验证进行身份验证扫描失败的原因


Kindly advice

善意的忠告


更多回答
优秀答案推荐
更多回答

41 4 0
Copyright 2021 - 2024 cfsdn All Rights Reserved 蜀ICP备2022000587号
广告合作:1813099741@qq.com 6ren.com