β οΈ Important: If using admin credentials, it is recommended to exercise caution
π‘Tip: Record in an incognito tab, using Developer Tools on the latest version of Google Chrome.
π‘Tip: Start the recording on a blank tab before you visit the webpage
βΉοΈ Note: If your login button is accessible via hover, you'll need to start the recording from the login page itself.
Benefits of using recorded login
Can be used for form-based, session-based, and header-based authentication
Supports web apps with SSO (excluding Google SSO βΒ due to MFA being enforced)
Supports apps where authentication is handled by a different domain
β
How to generate the file
Open an incognito window in Google Chrome
Go to your target domain (in this case, we're using intruder.io)
If you don't have
Recorderin the top navigation, click the ellipses (...) >More tools>Recorder
Click
Create a new recording:
How to upload the file
Verifying the authentication
Complete
Given how nuanced apps are, we don't presume the accuracy of authentication β instead, we show you what the scanner encountered and allow you to decide whether it has worked or not (the screenshot in particular is helpful, as you can use that to gauge if the scanner can access pages behind the login).
You could get any combination of results, here are just a few:
β
Managing authentication(s)
Once you've completed this information, you will see the authentication appear under the Authentications tab.
β
To disable an authentication
Click ... > Disable:
And the modal will update to this:
To re-enable, just click the ellipsis again > Enable:
β






















