Skip to content

Troubleshooting

No findings are appearing

  • Check that the pentest is Started, not Paused.
  • Verify scope includes the target URLs.
  • Ensure credentials are valid for authenticated areas.
  • Allow time for discovery on large or complex targets.

Access blocked by firewall

  • Allowlist egress IPs: 104.155.20.182, 34.76.33.170, 34.22.192.89.
  • Out-of-band callbacks are separate and travel the other way — see Security for defenders.

Blind findings (SSRF, XXE, command injection) are missing

  • These are confirmed only by a callback from your own infrastructure, not by the application's response.
  • Allow outbound DNS/HTTP from the target environment to prod.oob.squr.ai (130.211.69.252).
  • If that egress is blocked, these classes cannot be confirmed and will be reported as not found — a false negative rather than a clean result.

Pentest won't start

  • Confirm you have enough credits for the selected scope.
  • Make sure you accepted the consent terms.
  • Refresh the page and try again.

Pentest seems slow or stuck

  • Large scopes take longer; start with a smaller, high-value area.
  • Avoid pausing repeatedly, which can disrupt the agent's discovery flow.
  • Check whether the target is rate limiting or blocking requests.

Pentest is stuck on "Human needed"

  • Open the pentest to see what input is required (e.g., consent or credentials).
  • Provide the missing information and resume.

Authentication isn't working

  • Ensure the login URL is correct and accessible.
  • Verify the post-login verification URL is only available after login.
  • Use a dedicated test account whose login is not gated by CAPTCHA. Email-based one-time codes / two-factor (2FA) are supported — just give SQUR a mailbox it can read. Authenticator-app or hardware-key MFA (TOTP / FIDO) is not supported yet, so use a test account without those.
  • Re-check credentials for typos or expired passwords.

Informational findings are missing

  • Use the eye toggle on Remediation to include informational, merged, or AI-rejected items.

Findings look like duplicates

  • Open the finding details and check the linked findings section.
  • Update the status and add a short reason to keep the audit trail clear.

Retest log is empty

  • Confirm the retest started and wait a moment for the first events.
  • If the retest fails, try again after confirming the fix is deployed.

Report download fails

  • Try switching report level, then retry the export.
  • Wait until the pentest finishes if the report is still generating.
  • If the problem persists, contact support with the pentest ID.

Retest does not start

  • Make sure the finding status is updated to reflect your fix.
  • Confirm the target URL and credentials still work.
  • Try again after a short wait if the system is still processing updates.

Finding export to Markdown fails

  • Refresh the page and try the export again.
  • If the download does not start, try a different browser.