Hi Folks,
I want to know if WebInspect supports IAST wherein the tool deploys agents and sensors in the running applications and analyses the applications. Something similar like Burp Infiltrator.
Thanks,
Kamalpreet
Application Delivery Management
Application Modernization & Connectivity
CyberRes by OpenText
IT Operations Management
Hi Folks,
I want to know if WebInspect supports IAST wherein the tool deploys agents and sensors in the running applications and analyses the applications. Something similar like Burp Infiltrator.
Thanks,
Kamalpreet
Yes, WebInspect has an agent for .NET and JAVA based applications. For example, "For certain checks (such as SQL injection, command execution, and cross-site scripting), Fortify WebInspect Agent intercepts Fortify WebInspect HTTP requests and conducts runtime analysis on the target module."
Do we need to do any configuration or it happens automatically while scanning?
You will need to install the WebInspect Agent on the machine you are scanning. For example, if you are scanning a site hosted on IIS you would install the WebInspect Agent for .NET per the documentation. Once the agent is installed on the server, WebInspect should detect the presence of the agent.
Here is a YouTube video on how to install the .NET Agent - www.youtube.com/watch
From where can I download the executable to install agents for java and dotnet?
Thanks for the detailed replies and your time Ethan.