Skip to main content

Configure Scan Authentication

Authenticating to the target application allows for you to perform a higher quality scan by enabling the scanner to act as an authenticated user or service.

Getting Started​

  1. Navigate the to the requests view for the collection you wish to configure.
  2. Click on Settings in the top-right corner of the requests view.
  3. Select the Authentication tab.
  4. Select an authentication type from the dropdown menu, such as Bearer, Basic, Cookie, or a Custom Header.
  5. Filling in the required fields based on the authentication type you selected.
  6. Optionally configure an authentication check request by selecting an existing request from the Authentication Check Request dropdown.
  7. Click the Save Changes button to save your changes.

Note that if you select a request as the authentication check request, a key icon will appear next to it in the requests list to indicate to you that this request has been designated to check authentication. Head over to the Authentication to learn more about these requests.

Testing Authentication​

After saving your authentication configuration, you can either test a single endpoint or run a health check against all requests in the collection.

Test Single Endpoint​

  1. From the requests view on a collection, click on the request you wish to check.
  2. Click the Test button on the right-hand side.
  3. Fuzzing Hero will include the authentication credentials in the HTTP request to the target application.
  4. If the service responds with a 200 or otherwise valid status (not 401), then authentication should be successful.
  5. If there are errors, check that the credentials work independently of Fuzzing Hero, and that the correct authentication type and headers are selected.

Run a Health Check​

  1. From the requests view on a collection, click on the Start Scan button in the top-right corner. You don't need to fully start a scan to run a health check, so only running a health check will not use any credits.
  2. Fuzzing Hero will show a loading pop-up while the health check takes place. The authentication credentials will automatically be included when sending the HTTP requests to the target application.
  3. If all endpoints return with valid statuses, the health check will complete and show a success message allowing you to proceed to start a scan. If there were any non-200 statuses, you will have a chance to review the status codes or warnings for each endpoint.
  4. Similarly to testing a single endpoint, if there are 401s, consider checking outside of Fuzzing Hero if the credentials are valid.