Download - Qualys WAS 4.6 New Features...• Introduction of SmartScan • Enhanced Sitemap Reporting • Enhanced Option Profile Scope Selection SmartScan SmartScan allows for enhanced and advanced

Transcript
Page 1: Qualys WAS 4.6 New Features...• Introduction of SmartScan • Enhanced Sitemap Reporting • Enhanced Option Profile Scope Selection SmartScan SmartScan allows for enhanced and advanced

Qualys WAS 4.6 New Features WewelcomesomelongawaitedexcitingnewfeatureswithWAS4.6.TheyareencompassedinwhatwecallSmartScan.SmartScanallowsforenhancedandadvancedscanningofAJAXheavywebapplicationsalongwithenhancedsupportforSinglePageApplications(SPA)andalsoadvancedframeworkssuchasAngularJSandbootstrap.WealsoareintroducingenhancedsupportforGoogleWebToolkit(GWT)andDirectWebRemoting(DWR)aswell.Pleasenotethatthisisourfirstphaseandlimitedreleaseofthesenewfeaturesandcapabilities.WewillbereleasingmanyenhancementstothisSmartScaninupcomingWASversionsincluding,butnotlimitedto;enhancedJSONformatteddatatesting,enhancedURLrewritingsupportalongwithadditionalframeworksupport.*SmartScanwillbeavailableinlimitedreleaseonlyforthefirstphaseofdeploymentandwillonlybeavailableuponrequestfromTechnicalAccountManagers(TAMs).Thisfeaturewillrequireapproval.MinimumdependenciesareWAS4.6,Portal2.12andEngine3.15.Withthisreleasewearealsointroducingadditionalsitemapreportingfunctionalityaswellasvariousbugfixes.FeatureHighlights:

• IntroductionofSmartScan• EnhancedSitemapReporting• EnhancedOptionProfileScopeSelection

SmartScanSmartScanallowsforenhancedandadvancedscanningofAJAXheavywebapplicationsalongwithenhancedsupportforSinglePageApplications(SPA)andalsoadvancedframeworkssuchasAngularJSandbootstrap.WealsoareintroducingenhancedsupportforGoogleWebToolkit(GWT)andDirectWebRemoting(DWR)aswell.Pleasenotethatthisisourfirstphaseandlimitedreleaseofthesenewfeaturesandcapabilities.WewillbereleasingmanyenhancementstothisSmartScaninupcomingWASversionsincluding,butnotlimitedto;enhancedJSONformatteddatatesting,enhancedURLrewritingsupportalongwithadditionalframeworksupport.*SmartScanwillbeavailableinlimitedreleaseonlyforthefirstphaseofdeploymentandwillonlybeavailableuponrequestfromTechnicalAccountManagers(TAMs).

Page 2: Qualys WAS 4.6 New Features...• Introduction of SmartScan • Enhanced Sitemap Reporting • Enhanced Option Profile Scope Selection SmartScan SmartScan allows for enhanced and advanced

Thisfeaturewillrequireapproval.MinimumdependenciesareWAS4.6,Portal2.12andEngine3.15.OptionProfileCreateDialogWhencreatinganewprofile,iftheSmartScanoptionhasbeenenabledforthecustomer,theScanParametersstepwilldisplayanewsectionSmartScanSupport,thatwillexplaintouserwhatthefeatureisaboutandwillproposeacheckboxtoenablethefeature.Iftheusercheckstheoption,anadditionalsettingSmartScanDepthwillbedisplayed,withsomeexplanationoftheroleofthatsetting.Thedefaultvalueforthatsettingwillbesetto5.

Page 3: Qualys WAS 4.6 New Features...• Introduction of SmartScan • Enhanced Sitemap Reporting • Enhanced Option Profile Scope Selection SmartScan SmartScan allows for enhanced and advanced

TheReviewAndConfirmstepwilldisplaytheoptionsselectedbyuser:-Ifuserenabledtheoption:

-Ifuserlefttheoptiondisabled:

Page 4: Qualys WAS 4.6 New Features...• Introduction of SmartScan • Enhanced Sitemap Reporting • Enhanced Option Profile Scope Selection SmartScan SmartScan allows for enhanced and advanced

OptionProfileViewDialogJustlikethereviewstep,theScanParametersstepinoptionprofileViewdialogwilldisplaythevaluesselectedfortheSmartScanoptions.-Ifuserenabledtheoption:

-Ifuserlefttheoptiondisabled:

Page 5: Qualys WAS 4.6 New Features...• Introduction of SmartScan • Enhanced Sitemap Reporting • Enhanced Option Profile Scope Selection SmartScan SmartScan allows for enhanced and advanced

OptionProfileEditDialogThesamestepwillbeavailable,butthistimewiththeEnableSmartScanSupportcheckboxcheckediftheoptionhasbeenpreviouslyenabled.Inthiscase,theSmartScanDepthsettingwillalsobedisplayed,withpropervaluealreadysetfortheprofile.

OptionProfileSaveAsTheSmartScansettingswillbealsocopiedoverwhenauserperformsaSaveAsactionfromthedatalistorfromtheoptionprofileview/editdialogs.ExistingProfilesAllexistingprofileswillhavetheEnableSmartScanSupportoptiondisabledbydefault.TheSmartScanDepthvaluewillbesetto5.

Page 6: Qualys WAS 4.6 New Features...• Introduction of SmartScan • Enhanced Sitemap Reporting • Enhanced Option Profile Scope Selection SmartScan SmartScan allows for enhanced and advanced

EnhancedSitemapReportingWAS4.6nowallowsthecustomertheabilitytodownloadallURLsforasiteviatheSitemapfeatureandnothavetonavigatetoeachbranchofthesitemapindividually.WebApplication/ScanSitemapDialogThedialogusedtodisplaythesitemapforscansandwebapplicationswillhaveanewExportSitemapbuttonnowalwaysenabled.

Uponclicking,anExportSitemapLinksdialogwillbedisplayed,proposingtotheusertheformattobeusedtodownloadthesitemaplinks.Theformatandtimezonefieldsselectedbydefaultwilldependonuserpreferencesassetintheirprofile.

Page 7: Qualys WAS 4.6 New Features...• Introduction of SmartScan • Enhanced Sitemap Reporting • Enhanced Option Profile Scope Selection SmartScan SmartScan allows for enhanced and advanced

Formatofthedownloadedcontentsisthesamewhendownloadingcurrentpage,theonlydifferenceisthatthistimeallthelinkswillbedownloadedwiththeirabsolutepath.Columnswillthereforebe:

Page 8: Qualys WAS 4.6 New Features...• Introduction of SmartScan • Enhanced Sitemap Reporting • Enhanced Option Profile Scope Selection SmartScan SmartScan allows for enhanced and advanced

EnhancedOptionProfileScopeSelectionWhencreatingoreditinganOptionProfile,underSearchCriteria->DetectionScope;ifwechoose"Custom"previouslyanerrormessageimpliedthatausermustenteran"include"searchlist.Youcouldhavestillenteredan"exclude"searchlisttoexcludeonly,butthelocationofthiserrormessagewasconfusing.Wehavecorrectedandenhancedthisfunctionality.OptionProfileDialogTheSearchCriteria>DetectionScopesectionhasbeenupdatedasfollows:

• Texthasbeenaddedtointroducetousertheoption.

• ADetectioncomponenthasreplacedthe“focusthescantospecificvulnerabilities”,andproposestheoptionsCompletevs.Customasadropdownelementinsteadofradiobuttons.

InCreationmode,theoptionselectedbydefaultisComplete.

Inbothcreationandeditmode,whentheuserselectsCustom,thefollowingelementsaredisplayedbelowtheDetectioncomponent:

• Thesearchliststoinclude• Thesearchliststoexclude• Anadditionaltextmessageabovethesearchliststoexclude,thatexplains

howtheexcludedsearchlistswillbeused

Page 9: Qualys WAS 4.6 New Features...• Introduction of SmartScan • Enhanced Sitemap Reporting • Enhanced Option Profile Scope Selection SmartScan SmartScan allows for enhanced and advanced

IftheuserclickstheNextbutton,thevalidationisperformed,andifnosearchlistshavebeenselected:

• The2searchlistscomponentsarehighlightedinred• Anerrormessageisdisplayedontopofsearchliststoincludecomponentto

requestusertospecifyatleastonesearchlist

Page 10: Qualys WAS 4.6 New Features...• Introduction of SmartScan • Enhanced Sitemap Reporting • Enhanced Option Profile Scope Selection SmartScan SmartScan allows for enhanced and advanced

By selecting at least one search list, the error message is removed and the two search lists are be marked as valid.