qualys was 4.6 new features...• introduction of smartscan • enhanced sitemap reporting •...

10
Qualys WAS 4.6 New Features We welcome some long awaited exciting new features with WAS 4.6. They are encompassed in what we call SmartScan. SmartScan allows for enhanced and advanced scanning of AJAX heavy web applications along with enhanced support for Single Page Applications (SPA) and also advanced frameworks such as AngularJS and bootstrap. We also are introducing enhanced support for Google Web Toolkit (GWT) and Direct Web Remoting (DWR) as well. Please note that this is our first phase and limited release of these new features and capabilities. We will be releasing many enhancements to this SmartScan in upcoming WAS versions including, but not limited to; enhanced JSON formatted data testing, enhanced URL rewriting support along with additional framework support. *SmartScan will be available in limited release only for the first phase of deployment and will only be available upon request from Technical Account Managers (TAMs). This feature will require approval. Minimum dependencies are WAS 4.6, Portal 2.12 and Engine 3.15. With this release we are also introducing additional sitemap reporting functionality as well as various bug fixes. Feature Highlights: Introduction of SmartScan Enhanced Sitemap Reporting Enhanced Option Profile Scope Selection SmartScan SmartScan allows for enhanced and advanced scanning of AJAX heavy web applications along with enhanced support for Single Page Applications (SPA) and also advanced frameworks such as AngularJS and bootstrap. We also are introducing enhanced support for Google Web Toolkit (GWT) and Direct Web Remoting (DWR) as well. Please note that this is our first phase and limited release of these new features and capabilities. We will be releasing many enhancements to this SmartScan in upcoming WAS versions including, but not limited to; enhanced JSON formatted data testing, enhanced URL rewriting support along with additional framework support. *SmartScan will be available in limited release only for the first phase of deployment and will only be available upon request from Technical Account Managers (TAMs).

Upload: others

Post on 31-Jul-2020

21 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Qualys WAS 4.6 New Features...• Introduction of SmartScan • Enhanced Sitemap Reporting • Enhanced Option Profile Scope Selection SmartScan SmartScan allows for enhanced and advanced

Qualys WAS 4.6 New Features WewelcomesomelongawaitedexcitingnewfeatureswithWAS4.6.TheyareencompassedinwhatwecallSmartScan.SmartScanallowsforenhancedandadvancedscanningofAJAXheavywebapplicationsalongwithenhancedsupportforSinglePageApplications(SPA)andalsoadvancedframeworkssuchasAngularJSandbootstrap.WealsoareintroducingenhancedsupportforGoogleWebToolkit(GWT)andDirectWebRemoting(DWR)aswell.Pleasenotethatthisisourfirstphaseandlimitedreleaseofthesenewfeaturesandcapabilities.WewillbereleasingmanyenhancementstothisSmartScaninupcomingWASversionsincluding,butnotlimitedto;enhancedJSONformatteddatatesting,enhancedURLrewritingsupportalongwithadditionalframeworksupport.*SmartScanwillbeavailableinlimitedreleaseonlyforthefirstphaseofdeploymentandwillonlybeavailableuponrequestfromTechnicalAccountManagers(TAMs).Thisfeaturewillrequireapproval.MinimumdependenciesareWAS4.6,Portal2.12andEngine3.15.Withthisreleasewearealsointroducingadditionalsitemapreportingfunctionalityaswellasvariousbugfixes.FeatureHighlights:

• IntroductionofSmartScan• EnhancedSitemapReporting• EnhancedOptionProfileScopeSelection

SmartScanSmartScanallowsforenhancedandadvancedscanningofAJAXheavywebapplicationsalongwithenhancedsupportforSinglePageApplications(SPA)andalsoadvancedframeworkssuchasAngularJSandbootstrap.WealsoareintroducingenhancedsupportforGoogleWebToolkit(GWT)andDirectWebRemoting(DWR)aswell.Pleasenotethatthisisourfirstphaseandlimitedreleaseofthesenewfeaturesandcapabilities.WewillbereleasingmanyenhancementstothisSmartScaninupcomingWASversionsincluding,butnotlimitedto;enhancedJSONformatteddatatesting,enhancedURLrewritingsupportalongwithadditionalframeworksupport.*SmartScanwillbeavailableinlimitedreleaseonlyforthefirstphaseofdeploymentandwillonlybeavailableuponrequestfromTechnicalAccountManagers(TAMs).

Page 2: Qualys WAS 4.6 New Features...• Introduction of SmartScan • Enhanced Sitemap Reporting • Enhanced Option Profile Scope Selection SmartScan SmartScan allows for enhanced and advanced

Thisfeaturewillrequireapproval.MinimumdependenciesareWAS4.6,Portal2.12andEngine3.15.OptionProfileCreateDialogWhencreatinganewprofile,iftheSmartScanoptionhasbeenenabledforthecustomer,theScanParametersstepwilldisplayanewsectionSmartScanSupport,thatwillexplaintouserwhatthefeatureisaboutandwillproposeacheckboxtoenablethefeature.Iftheusercheckstheoption,anadditionalsettingSmartScanDepthwillbedisplayed,withsomeexplanationoftheroleofthatsetting.Thedefaultvalueforthatsettingwillbesetto5.

Page 3: Qualys WAS 4.6 New Features...• Introduction of SmartScan • Enhanced Sitemap Reporting • Enhanced Option Profile Scope Selection SmartScan SmartScan allows for enhanced and advanced

TheReviewAndConfirmstepwilldisplaytheoptionsselectedbyuser:-Ifuserenabledtheoption:

-Ifuserlefttheoptiondisabled:

Page 4: Qualys WAS 4.6 New Features...• Introduction of SmartScan • Enhanced Sitemap Reporting • Enhanced Option Profile Scope Selection SmartScan SmartScan allows for enhanced and advanced

OptionProfileViewDialogJustlikethereviewstep,theScanParametersstepinoptionprofileViewdialogwilldisplaythevaluesselectedfortheSmartScanoptions.-Ifuserenabledtheoption:

-Ifuserlefttheoptiondisabled:

Page 5: Qualys WAS 4.6 New Features...• Introduction of SmartScan • Enhanced Sitemap Reporting • Enhanced Option Profile Scope Selection SmartScan SmartScan allows for enhanced and advanced

OptionProfileEditDialogThesamestepwillbeavailable,butthistimewiththeEnableSmartScanSupportcheckboxcheckediftheoptionhasbeenpreviouslyenabled.Inthiscase,theSmartScanDepthsettingwillalsobedisplayed,withpropervaluealreadysetfortheprofile.

OptionProfileSaveAsTheSmartScansettingswillbealsocopiedoverwhenauserperformsaSaveAsactionfromthedatalistorfromtheoptionprofileview/editdialogs.ExistingProfilesAllexistingprofileswillhavetheEnableSmartScanSupportoptiondisabledbydefault.TheSmartScanDepthvaluewillbesetto5.

Page 6: Qualys WAS 4.6 New Features...• Introduction of SmartScan • Enhanced Sitemap Reporting • Enhanced Option Profile Scope Selection SmartScan SmartScan allows for enhanced and advanced

EnhancedSitemapReportingWAS4.6nowallowsthecustomertheabilitytodownloadallURLsforasiteviatheSitemapfeatureandnothavetonavigatetoeachbranchofthesitemapindividually.WebApplication/ScanSitemapDialogThedialogusedtodisplaythesitemapforscansandwebapplicationswillhaveanewExportSitemapbuttonnowalwaysenabled.

Uponclicking,anExportSitemapLinksdialogwillbedisplayed,proposingtotheusertheformattobeusedtodownloadthesitemaplinks.Theformatandtimezonefieldsselectedbydefaultwilldependonuserpreferencesassetintheirprofile.

Page 7: Qualys WAS 4.6 New Features...• Introduction of SmartScan • Enhanced Sitemap Reporting • Enhanced Option Profile Scope Selection SmartScan SmartScan allows for enhanced and advanced

Formatofthedownloadedcontentsisthesamewhendownloadingcurrentpage,theonlydifferenceisthatthistimeallthelinkswillbedownloadedwiththeirabsolutepath.Columnswillthereforebe:

Page 8: Qualys WAS 4.6 New Features...• Introduction of SmartScan • Enhanced Sitemap Reporting • Enhanced Option Profile Scope Selection SmartScan SmartScan allows for enhanced and advanced

EnhancedOptionProfileScopeSelectionWhencreatingoreditinganOptionProfile,underSearchCriteria->DetectionScope;ifwechoose"Custom"previouslyanerrormessageimpliedthatausermustenteran"include"searchlist.Youcouldhavestillenteredan"exclude"searchlisttoexcludeonly,butthelocationofthiserrormessagewasconfusing.Wehavecorrectedandenhancedthisfunctionality.OptionProfileDialogTheSearchCriteria>DetectionScopesectionhasbeenupdatedasfollows:

• Texthasbeenaddedtointroducetousertheoption.

• ADetectioncomponenthasreplacedthe“focusthescantospecificvulnerabilities”,andproposestheoptionsCompletevs.Customasadropdownelementinsteadofradiobuttons.

InCreationmode,theoptionselectedbydefaultisComplete.

Inbothcreationandeditmode,whentheuserselectsCustom,thefollowingelementsaredisplayedbelowtheDetectioncomponent:

• Thesearchliststoinclude• Thesearchliststoexclude• Anadditionaltextmessageabovethesearchliststoexclude,thatexplains

howtheexcludedsearchlistswillbeused

Page 9: Qualys WAS 4.6 New Features...• Introduction of SmartScan • Enhanced Sitemap Reporting • Enhanced Option Profile Scope Selection SmartScan SmartScan allows for enhanced and advanced

IftheuserclickstheNextbutton,thevalidationisperformed,andifnosearchlistshavebeenselected:

• The2searchlistscomponentsarehighlightedinred• Anerrormessageisdisplayedontopofsearchliststoincludecomponentto

requestusertospecifyatleastonesearchlist

Page 10: Qualys WAS 4.6 New Features...• Introduction of SmartScan • Enhanced Sitemap Reporting • Enhanced Option Profile Scope Selection SmartScan SmartScan allows for enhanced and advanced

By selecting at least one search list, the error message is removed and the two search lists are be marked as valid.