Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer peopleโ€™s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer peopleโ€™s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 7059353
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 28, 20262026-05-28T04:13:19+00:00 2026-05-28T04:13:19+00:00

I am trying to test a webpage using Nessus. I have tested all the

  • 0

I am trying to test a webpage using Nessus. I have tested all the stuff about the Server. But now I want to proceed by login to the webpage and test all possible pages behind the login form. But I couldn’t achieve it. I gave all(text, password and hidden fields) the form fields’ values including the ticket generated by Central Authentication System. But nothing happens. Either there isn’t any security issue behind the login page ( ๐Ÿ˜› ), or I couldn’t login to the page (100% possibility ๐Ÿ˜€ ). For extra info:

These are login fields. ๐Ÿ˜‰

username=
&password=
&lt=_c0C1F5872-F217-B20F-6D86-AA3AA1C1262E_kC7BEB4F7-5216-53EB-2F9A-7FDDFE01D145
&_eventId=submit
&submit=Login

Is there anyone who used Nessus and know how to solve this problem? And is there anyone who knows how to import Cookies to Nessus?

Thanks in advance. ๐Ÿ˜‰

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-28T04:13:20+00:00Added an answer on May 28, 2026 at 4:13 am

    I had similar problems; can’t speak for you, but sounds like you have about as much website knowledge as I do (which ain’t much!) – no offense intended. In my case I’m not sure I’m understanding the most most basic structural elements of the website, such as what URL to point the scan at, and then concatenating that correctly with the login pages in the policy. I’m far better at the network and infrastructure penetration testing ๐Ÿ˜€

    I did a search in a search engine for “Nessus HTTP cookie import”, and found that Tenable discussed this on their podcast, episode 14:

    http://blog.tenablesecurity.com/2009/11/tenable-network-security-podcast—episode-14.html

    If you look at the “Stories” note on the above web page, there’s a hint to use the “Export Cookies” Firefox add-on. The add-on has some guidance, but essentially:

    • Install the add-on to your browser (I’m using the OWASP Mantra browser; I urge you to look at it)
    • Restart your browser
    • Login into the subject website and authenticate
    • From the Tools menu, go for “Export Cookies”
    • Save to file, and point your Nessus scan policy at that file

    NOTE: I’m still trying this now, but thought I’d post the possibility anyway in case I forget – I will update this thread with a confirm or deny shortly.

    Best of luck!

    UPDATE: Well, it didn’t work for me on first attempt. I’m confirming I don’t have any conflicting or superseding settings in the policy, but if that doesn’t work it’s on to Tenable Support, I fear…

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

hi all I'm trying to extract the META description from a webpage using libxml
I've trying to get some vertical text on a little test webpage after reading
just trying to test for equality in this piece of code, but getting a
I trying to test an AccountController that uses DotNetOpenAuth but I am running into
Im trying to test my successfully creates a new user after login (using authlogic).
I am trying out CGI-scripts for the first time but without success. I have
I'm trying to implement in app-billing in my application, but I have a little
I have this website http://smithachallathomas.net63.net/ . Now I am trying to add a share,
I have a webpage form with a checkbox on it. I am trying to
I have application that displays webpage with url something like https://www.test.com/checkout/reserve/DHrhrzPEC6MepeMoZinxoQD4QvAaevgx7xYDZJtX8azf0_ii_Zv2b2rpiYgToXHP from this url

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.