WebInspect 7.5 released

WebInspect 7 is the first and only web application security assessment tool to be re-architected to thoroughly analyze today’s complex web applications built on emerging Web 2.0 technologies. The new architecture delivers faster scanning capabilities, broader assessment coverage, and the most accurate results of any web application scanner available

New features that come with this version

What’s New

  • Pre-scan Profiler – WebInspect’s new pre-scan Profiler analyzes the application and offers suggestions for changes to the scan settings to optimize your assessment. The Profiler can evaluate and recommend settings for authentication, proxies, files not found, allowed hosts, and much more.
    The Profiler can be launched as a separate tool or configured in the Scan Wizard to automatically launch prior to the start of a scan.
  • Interactive Logout Notification – During an interactive mode scan, WebInspect notifies you when a logout has occurred, and displays a browser view of the page where the logout occurred, allowing you to login again.
  • Traffic Monitor – The Traffic Monitor allows you to view HTTP traffic in real time during a scan. The Traffic Monitor displays every request sent and response received by WebInspect in real time during the crawl and audit.
  • Enterprise Assessment – Enterprise Assessment provides you with a comprehensive overview of your Web presence from an enterprise network perspective. URLs and IP addresses can be entered individually, or WebInspect can discover all available servers within a range of IP addresses and ports that you specify.
  • Right-click SQL Injector – You can now launch the SQL Injector tool by right-clicking on a vulnerable session and selecting SQL Injector from the Tools menu.
  • Regex in Allowed Hosts – You can now use Regex in the Allowed Hosts list, so that if a host matches a Regex pattern entered, it will be allowed for crawl and audit.
  • Launch Interactive Mode from Web Macro Recorder – You can now configure the Web Macro Recorder to launch Interactive Mode as part of a Macro.
  • Restore Factory Defaults to Application Settings – You can now restore Application Settings to their factory default settings.
  • Launch SPI Proxy from WebInspect Scan Wizard – You can now launch SPI Proxy from the Configure Network Proxy window in the Web Site Assessment wizard.
  • Windows Vista Support - WebInspect 7.5 is now fully supported under windows Vista (Please note, support for 64 bit systems is still forthcoming)

Post scriptum

Compliance Mandates

  • Application Scanner :

    PCI/DSS 6.3, SOX A12.4, GLBA 16 CFR 314.4(b) and (2), HIPAA 164.308(a)(1)(i), FISMA RA-5, SA-11, SI-2, ISO 27001/27002 12.6, 15.2.2

  • Vulnerability Scanner :

    PCI DSS 11.2, 6.6, SOX A13.3, GLBA 16CFR Part 314.4(c), HIPAA 164.308(a)(8), FISMA RA-5, SI-2, ISO 27001-27002 12.6, 15.2.2


Related Articles

Application Scanner
Vulnerability Scanner
WebInspect