Authentication
To get the most out of Fuzzing Hero, we recommend that you configure your collections to use authentication. This ensures that the scan can use the API like normal users of services.
If your service doesn't require authentication, then you can skip this section. If it returns any customer or sensitive data, we highly recommend your application enforces authentication and then return back to Fuzzing Hero to kick off a scan.
Supported Modes
- Basic Authentication (username and password)
- Bearer Tokens (JWT, tokens, etc.)
- Cookies
- Custom HTTP Headers (X-API-Token, etc.)
Authentication Request
Fuzzing Hero allows for a single collection request to be designated as the authentication request. This request will not be fuzzed and will purely be used for testing to see if the authentication criteria is valid.
Occasionally users need to define an endpoint outside of the API to verify authentication. This allows you to safely configure that without needing to send fuzzing traffic to the authentication request target.
Fuzzing Hero will use this request throughout the scan to verify that the credentials are still valid. If the engine notices that the credentials may have been logged out or revoked, it will check the authentication request to determine if it is still valid. In the event that the authentication credentials expired during a scan, the scan will be failed.