Latest news
Yesterday, Qualys released version 2.1 of QualysGuard Web Application Scanning (WAS), that integrates with Selenium to help companies further automate scanning of web applications with complex authentication.Mike Shema, Director of Engineering at Qualys, offers insight into the latest release of QualysGuard WAS.
How will WAS 2.1 will enable users to successfully authenticate dynamic security testing during scans?
Since its beginning WAS has focused on automating the login process as much as possible in order to ease the burden of complex configurations or deep knowledge of a target on the part of the user.
Automation can't hit 100% percent of the login forms WAS encounters. Sometimes the login page uses weird HTML layout, like separate forms for the username, password, and submit button. Sometimes the login form doesn't match an expected heuristic, like merely asking for a single ID number in a text field to "authenticate" to the site. Other situations require the user to complete multiple steps before successfully logging in to the site.
Whatever the case may be, supporting Selenium means that if the authentication process can be recorded in the browser, then it can be replayed by the scanner. Selenium is an easy-to-use tool that already has wide adoption for QA testing. So, it's possible WAS could re-use Selenium login scripts already created for QA. Also, the choice of Selenium means that users can take a script created for WAS and re-use it in their own Selenium environments -- they're not beholden to a "WAS format" for training the scanner.
How will WAS 2.1 simplify complex authentication processes?
As mentioned earlier, the process should already be simple -- the user provides a username and password and WAS figures out how to login to the site. When this doesn't work automatically, the user can record a login sequence with a browser plugin: Hit record, login as normal, hit stop, and upload the script to WAS. There's no need to write JavaScript functions or read through HTML to figure out a form's structure.
How will WAS 2.1 stand apart in the market?
WAS already automates a majority of login forms, and will further stand apart by integrating with a solution, Selenium, that is already in use by large enterprises for functional web app testing. This integration will enable users to address the problem of scalability when dealing with dozens, hundreds, or possibly thousands of web apps across an organization. By standardizing on Selenium, future versions of WAS will support the use of Selenium scripts for workflow testing, which will reduce overall testing efforts in an unparalleled way.
Spotlight

The CSO perspective on healthcare security and compliance
Posted on 20 May 2013. | Randall Gamby is the CSO of the Medicaid Information Service Center of New York. In this interview he discusses healthcare security and compliance challenges and offers a variety of tips.

Cyber espionage campaign uses professionally-made malware
Posted on 20 May 2013. | A massive cyber espionage campaign has been hitting government ministries, IT companies, academic research institutions, and more.

Ransomware adds password stealing to its arsenal
Posted on 17 May 2013. | Microsoft researchers are warning about a new variant of the well-known Reveton ransomware doing rounds.

IT security jobs: What's in demand and how to meet it
Posted on 15 May 2013. | Let's say you want a career in information security, where do you start? What credentials do you need? What are employers looking for? Read on to find some answers.

Hacking charge stations for electric cars
Posted on 15 May 2013. | Ofer Shezaf talks about what charge stations really are, why they have to be ‘smart’ and the potential risks created to the grid, to the car and most importantly to its owner’s privacy and safety.
By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.





