QualysGuard Web Application Scanning
by HNS - Wednesday, 7 December 2011.
Yesterday, Qualys released version 2.1 of QualysGuard Web Application Scanning (WAS), that integrates with Selenium to help companies further automate scanning of web applications with complex authentication.

Mike Shema, Director of Engineering at Qualys, offers insight into the latest release of QualysGuard WAS.

How will WAS 2.1 will enable users to successfully authenticate dynamic security testing during scans?

Since its beginning WAS has focused on automating the login process as much as possible in order to ease the burden of complex configurations or deep knowledge of a target on the part of the user.

Automation can't hit 100% percent of the login forms WAS encounters. Sometimes the login page uses weird HTML layout, like separate forms for the username, password, and submit button. Sometimes the login form doesn't match an expected heuristic, like merely asking for a single ID number in a text field to "authenticate" to the site. Other situations require the user to complete multiple steps before successfully logging in to the site.

Whatever the case may be, supporting Selenium means that if the authentication process can be recorded in the browser, then it can be replayed by the scanner. Selenium is an easy-to-use tool that already has wide adoption for QA testing. So, it's possible WAS could re-use Selenium login scripts already created for QA. Also, the choice of Selenium means that users can take a script created for WAS and re-use it in their own Selenium environments -- they're not beholden to a "WAS format" for training the scanner.

How will WAS 2.1 simplify complex authentication processes?

As mentioned earlier, the process should already be simple -- the user provides a username and password and WAS figures out how to login to the site. When this doesn't work automatically, the user can record a login sequence with a browser plugin: Hit record, login as normal, hit stop, and upload the script to WAS. There's no need to write JavaScript functions or read through HTML to figure out a form's structure.

How will WAS 2.1 stand apart in the market?

WAS already automates a majority of login forms, and will further stand apart by integrating with a solution, Selenium, that is already in use by large enterprises for functional web app testing. This integration will enable users to address the problem of scalability when dealing with dozens, hundreds, or possibly thousands of web apps across an organization. By standardizing on Selenium, future versions of WAS will support the use of Selenium scripts for workflow testing, which will reduce overall testing efforts in an unparalleled way.

Spotlight

eBook: Cybersecurity for Dummies

Posted on 16 December 2014.  |  APTs have changed the world of enterprise security and how networks and organizations are attacked. These threats, and the cybercriminals behind them, are experts at remaining hidden from traditional security while exhibiting an intelligence, resiliency, and patience that has never been seen before.


Weekly newsletter

Reading our newsletter every Monday will keep you up-to-date with security news.
  



Daily digest

Receive a daily digest of the latest security news.
  
DON'T
MISS

Thu, Dec 18th
    COPYRIGHT 1998-2014 BY HELP NET SECURITY.   // READ OUR PRIVACY POLICY // ABOUT US // ADVERTISE //