Some websites are designed to use custom 404 error pages instead of a web browser’s standard error page because they can be branded and made to contain useful links to other important pages. If your website uses custom 404 error pages — which generate different error codes — Invicti WVSÂ (during a security scan) can misinterpret them as being real site pages if it has not been configured to recognize them automatically.
WVS will automatically detect custom 404 error page by sending rogue URL requests. If Invicti WVS is unable to find a matching pattern to distinguish the custom 404 error page, you will be alerted and have to configure the Invicti WVS custom 404 error page rule.
The following instructions illustrate how to configure Invicti WVS if it does not automatically detect the custom error page:
- Specify the URL of the website for which you would like to create a custom 404 error page rule in the âURL to match onâ input field.
- In the Pattern input field, you should specify a text pattern or regular expression which matches some unique text on the custom 404 error page.
- Specify where the pattern can be found in the custom 404 error page response from the âMatch onâ drop down menu.
Alternatively you can also generate such pattern automatically by following the below procedure:
- Enter the websiteâs URL in the âBrowse URLâ input field and click âGOâ. The browser will request non existing URLâs to trigger the Custom 404 error page.
- Highlight the unique text from the custom error page.
- Click on âGenerate pattern from selectionâ.
View all the Invicti FAQs here.
Get the latest content on web security
in your inbox each week.



