QualysGuard Web Application Scanning
by HNS - Wednesday, 7 December 2011.
Yesterday, Qualys released version 2.1 of QualysGuard Web Application Scanning (WAS), that integrates with Selenium to help companies further automate scanning of web applications with complex authentication.

Mike Shema, Director of Engineering at Qualys, offers insight into the latest release of QualysGuard WAS.

How will WAS 2.1 will enable users to successfully authenticate dynamic security testing during scans?

Since its beginning WAS has focused on automating the login process as much as possible in order to ease the burden of complex configurations or deep knowledge of a target on the part of the user.

Automation can't hit 100% percent of the login forms WAS encounters. Sometimes the login page uses weird HTML layout, like separate forms for the username, password, and submit button. Sometimes the login form doesn't match an expected heuristic, like merely asking for a single ID number in a text field to "authenticate" to the site. Other situations require the user to complete multiple steps before successfully logging in to the site.

Whatever the case may be, supporting Selenium means that if the authentication process can be recorded in the browser, then it can be replayed by the scanner. Selenium is an easy-to-use tool that already has wide adoption for QA testing. So, it's possible WAS could re-use Selenium login scripts already created for QA. Also, the choice of Selenium means that users can take a script created for WAS and re-use it in their own Selenium environments -- they're not beholden to a "WAS format" for training the scanner.

How will WAS 2.1 simplify complex authentication processes?

As mentioned earlier, the process should already be simple -- the user provides a username and password and WAS figures out how to login to the site. When this doesn't work automatically, the user can record a login sequence with a browser plugin: Hit record, login as normal, hit stop, and upload the script to WAS. There's no need to write JavaScript functions or read through HTML to figure out a form's structure.

How will WAS 2.1 stand apart in the market?

WAS already automates a majority of login forms, and will further stand apart by integrating with a solution, Selenium, that is already in use by large enterprises for functional web app testing. This integration will enable users to address the problem of scalability when dealing with dozens, hundreds, or possibly thousands of web apps across an organization. By standardizing on Selenium, future versions of WAS will support the use of Selenium scripts for workflow testing, which will reduce overall testing efforts in an unparalleled way.

Spotlight

The role of the cloud in the modern security architecture

Posted on 31 July 2014.  |  Stephen Pao, General Manager, Security Business at Barracuda Networks, offers advice to CISOs concerned about moving the secure storage of their documents into the cloud and discusses how the cloud shaping the modern security architecture.


Weekly newsletter

Reading our newsletter every Monday will keep you up-to-date with security news.
  



Daily digest

Receive a daily digest of the latest security news.
  

DON'T
MISS

Fri, Aug 1st
    COPYRIGHT 1998-2014 BY HELP NET SECURITY.   // READ OUR PRIVACY POLICY // ABOUT US // ADVERTISE //