Customer questions around DAST Browser Based
-
Hey all! Question around DAST browser-based. Working with a partner helping a customer configure it, and there are certain links it just refuses to "notice" and crawl. Logs currently show successes, but doesn't show any failures. Is there something we can do configuration-wise to see why it's skipping something? Currently seems to be no rhyme or reason to it. -
is reaching pages that do not require authentication possible after the DAST tool logins in, or is it possible to define this as an action before the tool logs in? Should be instead be running a separate DAST job to check these? -
Is the tool capable to of interfacing with user submitted forms other than the login fields, i.e entering a phone number or clicking a submit button? -
We're having issue with the tool not crawling to specific pages that are reached by things like drop down menus and our front-end engineers are assuring us that there doesn't seem to be anything different for the tool to get stuck on. I've attached an images of such an example.
- Could you let us know if this is an issue for the tool or not or how we can remedy this? Can it not crawl "hidden" elements that are later exposed via drop-down, etc?
- Is there a way to visually view what the browser is doing? Like a recording or such. Something like the dast_debug_auth_report so we can see what the tool is exactly doing? We're aware that some logging shows this but it can be difficult to read and it's hard to understand exactly where the tool is having issues.
