HostedScan

use case

Authenticated Web Application Vulnerability Scan

Scan behind the login of websites and web apps

Security team reviewing scan results on their monitors

what it is

What is an Authenticated Vulnerability Scan?

An authenticated vulnerability scan logs in to the target web application. This allows the scan to cover sections of the application that are accessible only to logged in users. For many web applications, a significant amount of the content is behind a log in and an authenticated scan is required for a thorough security test.

You can authenticate using two methods:

By creating a selenium script to walk through your login form. Read below for details.

By configuring customized request headers for alternative authentication strategies like Basic Authentication, Bearer Token and API keys. Read more on Customize Request Headers (OWASP Zap).

how it works

How to set up and run an authenticated scan

With HostedScan Security you can easily run authenticated OWASP ZAP scans using a recorded login for your web application. HostedScan uses the recorded login to authenticate into your application and scan behind the login.

Follow the steps below to configure your authentication and run scans.

  1. 01

    Record the Authentication

    HostedScan uses Selenium recordings to capture and replay the login steps for a website. Selenium is a widely used open-source tool for recording and automating actions on a web page.

    • Install the Selenium IDE browser extension for Firefox or run the Selenium IDE desktop application. The desktop application can be easily launched using a node package manager such as npm: npx selenium-ide. Note that the Selenium IDE browser extension is currently not supported in Chrome due to recent changes in Chrome extension requirements.
    • Open the extension and select Record a new test in a new project, enter a name for the project, enter your website's URL, and then click Start recording.
    • Your website will open in a new window where you will make the recording. Authenticate to your website and Selenium will record the actions.
      Always use a test user account. Some scans will click buttons and submit forms as part of testing, which could cause changes to the account.
    • After logging in to your website, stop the recording and save it as a .side file.
    Selenium IDE welcome dialog with the option to record a new test in a new project
  2. 02

    Upload the Recorded Authentication to HostedScan

    HostedScan uses Selenium recordings to capture and replay the login steps for a website. Selenium is a widely used open-source tool for recording and automating actions on a web page.

    • In your HostedScan account, edit the Target you are configuring for authenticated scanning.
    • Click Upload New File and upload the .side file that you previously recorded with Selenium.
    • Under Logout Routes to Exclude, list the logout URLs for your application. e.g. https://mysite.com/logout.
      It is important to configure these URLs so that the scanner does not visit them and unauthenticate during the scan.
    • Test your configuration by clicking >> Test Now. This will test if we can play back your Selenium recording. When the test is finished, verify that the captured screenshot shows your website authenticated as you expect.
    HostedScan Edit Target dialog with the uploaded Selenium recording, the logout routes to exclude, and a successful test result
  3. 03

    Run Scan!

    On the Targets menu click the New Scan button.

    The scan may take a couple minutes to start as it goes through the authentication process.

    HostedScan navigation bar with the New Scan button highlighted
  4. 04

    Select an OWASP ZAP Active Web Application Scan.

    New Scan dialog with the OWASP ZAP Active Web Application Scan option selected
  5. 05

    Select your Target.

    New Scan target list with the authenticated website target selected
  6. 06

    Select the option to enable authentication (where you select schedule and email settings) and click "Submit"

    New Scan configure step showing the schedule, email notification, and Use authentication settings

Benefits of using HostedScan

Strengthen your
cybersecurity
resilience

Mitigate security vulnerabilities

Discover CVEs, OWASP Top 10 vulnerabilities, and exploitable weaknesses across your entire infrastructure. Get prioritized remediation guidance with CVSS scoring and actionable risk classifications—fix what matters first.

Learn more

Manage your risk exposure

With regulations such as GDPR and CCPA, failure to maintain reasonable security procedures is grounds for lawsuits and fines.

Get started

Meet compliance requirements

Vulnerability scanning is essential for your compliance with SOC 2, ISO 27001, cyber insurance, and more.

Learn more

Detect misconfigurations

90% of cyber attacks exploit simple misconfigurations, not zero-days. Detect exposed ports, weak credentials, outdated software, and common security gaps before attackers do—automatically, every day.

Get started

Map your attack surface

Your infrastructure changes constantly. Automatically discover and monitor all websites, servers, networks, and APIs—maintaining complete visibility of your attack surface without manual tracking.

Get started

Our Customers

5,000+ MSPs and IT teams who move faster

BbAmericas
Porsche
ExpediaGroup
WeMakeApps
SibylSoft
Luminary
CoinMe
Appetize
WonderProxy
Median
TaxiCaller
Yamaha
UniversityOfOxford

Speed and power,
without the complexity

The world's leading vulnerability scanners, all in one platform.

Loading call to action