HP WebInspect Enterprise
This document provides an overview of WebInspect Enterprise 9.3. It contains important information that may not be included in the manuals or in online help. For the most recent version of this document please see the WebInspect Enterprise Landing Page.
WebInspect Enterprise 9.3 Features
System
Requirements
Getting Started
Support
Known Problems, Limitations and Workarounds
WebInspect Enterprise
is a component of Software Security Center that supports managing your dynamic
scanning program. The vulnerabilities discovered during dynamic testing are now
integrated into Software Security Center to provide a central place to manage
static and dynamic vulnerabilities. This unifies the remediation workflow for
vulnerabilities regardless of whether they were found by dynamic or static
testing techniques.
Onboarding dynamic applications into WebInspect Enterprise can be accomplished through Project Version Import. This feature has support for importing specific project versions that are only dynamic in nature or ensuring all project versions within SSC are imported in a single operation.
For
organizations that want to segment their application teams from their dynamic
testing teams, the scan request feature can be used to track work & needs
across the two teams. In this type of environment the core responsibilities for
performing scans are placed on the security team. The scan request feature
allows the application teams to quickly and easily create scan requests that are
monitored and fulfilled by the security team.
WebInspect Enterprise is the user interface that provides security professionals with the tools to confirm the comprehensiveness of a scan and the validity of the vulnerabilities it contains. Once this process has been completed, the results need to be delivered to development for remediation. To perform this action the dynamic scan can be published transferring the vulnerabilities into issues to be consumed by developers through Software Security Center.
WebInspect Enterprise provides an easy to user scan wizard that will enable individuals throughout the organization.
For a security professional to thoroughly scan a project version they may need to perform several scans. A typical example would be a site that needs the following scans to implement a comprehensive audit: one scan to determine vulnerabilities exposed to unauthenticated user, another scan to expose vulnerabilities of authenticated users and another scan to expose the vulnerabilities found in Web Services. Scan templates were created to allow users to easily manage the different settings files that are need to perform a thorough dynamic audit. Scan Templates are associated to the specific project version they are designed to attack. In this way a security professional, can ensure that products meet their security standard even when the responsibility of running the scans is distributed to the QA and or development teams.
The visualization provided through the WebInspect desktop environment is the standard by which users can easily verify and remediate vulnerabilities. With the release of WebInspect Enterprise, HP has brought this high power interface to the Web. This will allow organizations to more readily rollout dynamic scanning efforts to individuals outside of the core security team.
To scale the dynamic program within an organization requires the ability to manage a pool of scanners. Within the WebInspect Enterprise product we refer to these scanners as sensors. Using these resources, users can run scans on demand, schedule scanning to occur at appropriate times, and retest specific vulnerabilities. Special security features are provided within WebInspect Enterprise to allow administrative control over these powerful resources. The security features include but are not limited to the following: blackout periods, policy management, restricted sensor access, and ip address range validation.
Before
installing WebInspect Enterprise version 9.30, make sure that your system meets
the following requirements:
·
Browser
§ Internet Explorer 7.0 (Minimum)
§ Internet Explorer 8.0
§ Internet Explorer 9.0 (Recommended)
§ Firefox 9.0 (Minimum)
§ Firefox 14 (Recommended)
·
Network
§ An active Internet connection (Recommended)
·
Processor
§ 2.5 GHz or better
·
RAM
§ 4 GB (Minimum)
·
Hard
Disk
§ 5 GB (using remote database)
§ 20 GB (using local database) (Minimum)
§ 100+ GB (Recommended)
·
Web
Server Platform
§ Microsoft IIS 6.0 (Minimum)
§ Microsoft IIS 7.0
§ Microsoft IIS 7.5 (Recommended)
·
CLR
Platform
§ Microsoft .NET Framework 4.0
·
Operating
System
§ Windows Server 2003 Standard SP2 (32-/64-bit)
§ Windows Server 2008 SP2 (32-/64-bit)
§ Windows Server 2008 R2 (64-bit)
·
Integrations
§ HP Fortify Software Security Center 3.6
·
Processor
§ 2.5 GHz or better
·
RAM
§ 4 GB (Minimum)
·
Hard
Disk
§ 20 GB (Minimum)
§ 100+ GB (Recommended)
·
Operating
System
§ Windows Server 2003 SP2 (32-/64-bit)
§ Windows Server 2008 SP2 (32-/64-bit)
§ Windows Server 2008 R2 (64-bit)
·
Supported
Database
§ Microsoft SQL Server 2005 SP4
§ Microsoft SQL Server 2008 SP2
§ Microsoft SQL Server 2008 R2 (Recommended)
Note:
Assessment Management Platform does not support SQL Server Express.
·
Processor
§ 1.5 GHz or better
·
RAM
§ 1 GB (Minimum)
·
Hard
Disk
§ 2 GB of free disk space
·
Operating
System
§ Windows XP Professional SP3 (32-bit)
§ Windows Server 2003 SP2 (32-bit/64-bit)
§ Windows Server 2008 SP2 (32-/64-bit)
§ Windows Server 2008 R2 (64-bit)
§ Windows Vista SP2 (32-bit/64-bit)
§ Windows 7 (32-bit/64 bit)
·
Database
§ Microsoft SQL Server Express Edition 2008 SP2 (4 GB
scan database limit)
§ Microsoft SQL Server Express Edition 2005 SP3 (4 GB
scan database limit)
Note:
Required only if you want to edit policies, compliance templates, or audit
inputs
·
Platform
§ Silverlight Runtime v3
Note: Required only if you want to use the Scan Link
Analyzer and Screenshot Attachments
·
Supported
Operating systems:
§ Windows XP Professional SP3 (32-bit)
§ Windows Vista SP2 (32-/64-bit)
§ Windows 7 (32-/64-bit) (Recommended)
§ Windows Server 2003 SP2 (32-bit/64-bit)
§ Windows Server 2008 SP2 (32-bit/64-bit)
§ Windows Server 2008 R2 (64-bit) (Recommended)
·
Processor
§ 1.5 GHz Single-Core (Minimum)
§ 2.5 GHz Multi-Core (Recommended)
·
RAM
§ 2 GB (Minimum)
§ 4 GB (Recommended)
·
Hard
Disk
§ 10 GB (Minimum)
§ 100+ GB (Recommended)
·
Display
§ 1024 x 768 (Minimum)
§ 1280 x 1024 (Recommended)
·
Supported
Database
§ Microsoft SQL Server Express Edition 2008 R2 (10 GB
scan database limit) (Minimum)
§ Microsoft SQL Server Express Edition 2008 SP2 (4 GB
scan database limit)
§ Microsoft SQL Server Express Edition 2005 SP3 (4 GB
scan database limit)
§ Microsoft SQL Server 2008 R2 (No scan database limit) (Recommended)
§ Microsoft SQL Server 2008 SP2 (No scan database limit)
§ Microsoft SQL Server 2005 SP4 (No scan database limit)
·
Platform
§ Microsoft .NET Framework 3.5 Service Pack 1
·
Browser
§ Internet Explorer 7.0 (Minimum)
§ Internet Explorer 8.0 (Recommended)
§ Mozilla Firefox 3.6 (Proxy Settings Only)
§
NOTE: For a
WebInspect Enterprise environment to support Internet Protocol version 6
(IPv6), the IPv6 protocol must be deployed on each WebInspect Enterprise Console,
WebInspect Enterprise Sensor, and the WebInspect Enterprise Manager
For easy-to-follow instructions on installing and using WebInspect Enterprise, see the Quick Start Guide.
1.
Browse to URL http://support.openview.com/.
2.
Login. If you have not registered before, you
will have to do so and provide your SAID (Service Agreement ID) number.
3. Select
your HP product and report the issue.
1. Call
1.800.633.3600
2. Say “Software”
3.
Say “WebInspect” or “WebInspect Enterprise” or
“QA Inspect” or “AMP”
4. Say or Key in your SAID (Service Agreement ID) number.
- When publishing dynamic results into Software Security Center, false positives will show up as issues that have been marked suppressed with an analysis value of not an Issue. If the analysis value is changed from Software Security Center, this will result in the vulnerability being marked as ignored in WebInspect Enterprise.
- WebInspect Enterprise scan visualization does not contain a tab for Soap Request.
- WebInspect Enterprise Scan Visualization does not support Security Scope Information.
- If users decide to manually add FPR’s to Software Security Center, WebInspect Enterprise will not be able to manage the list appropriately. This will result in an inability to synchronize data appropriately between SSC and WebInspect Enterprise.
- Scan Configuration details within WebInspect Enterprise do not support Restful Rules cannot be viewed are added.
- Moving a published scan from one Project Version to another in WebInspect Enterprise will result in the following side effect. Any issues that were not found by any other previously published scan will be marked fixed upon the next publish event for that project version.
- Deleting a screenshot in SSC does not propagate back to WebInspect Enterprise. If you wish this to propagate you must add, remove or modify a comment on the vulnerability.
©Copyright 2004-2012 Hewlett-Packard Development Company, L.P.
Confidential computer software. Valid license from HP required for possession, use or copying. Consistent with FAR 12.211 and 12.212, Commercial Computer Software, Computer Software Documentation, and Technical Data for Commercial Items are licensed to the U.S. Government under vendor's standard commercial license. The only warranties for HP products and services are set forth in the express warranty statements accompanying such products and services. Nothing herein should be construed as constituting an additional warranty. HP shall not be liable for technical or editorial errors or omissions contained herein. The information contained herein is subject to change without notice.