<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://www.communities.hp.com/securitysoftware/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title /><link>http://www.communities.hp.com/securitysoftware/forums/</link><description>All Posts</description><dc:language>en-US</dc:language><generator>CommunityServer 2008.5 SP1 (Build: 31106.3070)</generator><item><title>Trouble using client certificate in WebInspect</title><link>http://www.communities.hp.com/securitysoftware/forums/thread/108537.aspx</link><pubDate>Fri, 13 Nov 2009 19:24:33 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:108537</guid><dc:creator>csgale</dc:creator><slash:comments>1</slash:comments><comments>http://www.communities.hp.com/securitysoftware/forums/thread/108537.aspx</comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/forums/commentrss.aspx?SectionID=20&amp;PostID=108537</wfw:commentRss><description>&lt;p&gt;Hello, I&amp;#39;ve tried to search around to see if anyone has posted anything about this, but haven&amp;#39;t turned anything up.&lt;/p&gt;
&lt;p&gt;I&amp;#39;m presently assessing a web application that uses client certificates. &amp;nbsp;I see that I should be able to use them in Webinspect (both from the help file, and the user manual), but after following the procedure laid out, My scan is still stopping immediately after starting and giving me a &amp;quot;No credentials are available in the security package&amp;quot; error.&lt;/p&gt;
&lt;p&gt;This is what I&amp;#39;ve done (which I hope is correct):&lt;/p&gt;
&lt;p&gt;I go into Edit -&amp;gt; Default Scan Setting -&amp;gt; Authentication and check the box for Enable client certificates. &amp;nbsp;I then select the certificate (which shows up in the drop down list) and click ok. &amp;nbsp;&lt;/p&gt;
&lt;p&gt;I&amp;#39;ve also done it for Current Scan Settings (as I assume that takes precedence over Default).&lt;/p&gt;
&lt;p&gt;I assume the error is that it somehow isn&amp;#39;t using the certificate to access the site.&lt;/p&gt;
&lt;p&gt;If should be said that for now, I&amp;#39;m not even worrying about logging into the site, I just want to verify that I can connect to the main page.&lt;/p&gt;
&lt;p&gt;Anybody have any ideas, thanks?&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Attempt to generate aggregate reports consistently failing</title><link>http://www.communities.hp.com/securitysoftware/forums/thread/100611.aspx</link><pubDate>Mon, 07 Sep 2009 05:48:44 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:100611</guid><dc:creator>whips04r</dc:creator><slash:comments>3</slash:comments><comments>http://www.communities.hp.com/securitysoftware/forums/thread/100611.aspx</comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/forums/commentrss.aspx?SectionID=120&amp;PostID=100611</wfw:commentRss><description>&lt;p&gt;Am trying to generate Aggregate, Executive Summary (aggregated), False Positive, and Compliance reports for 6x scans however each attempt yeilds only the cover page for each report and a lengthy dump to the Output Console. Howe3ver, if I only generate the Aggregate Report (i.e. 1 report at a time) I mostly (*) get a desirable outcome (i.e. a full report!), though this makes the reporting process rather time expensive experience.&lt;/p&gt;
&lt;p&gt;*see below this Output Console dump for Error Details of a WI crash after attempting to close an aggregated Executive Summary report.&lt;/p&gt;
&lt;p&gt;The Output Console dump is along the lines of:&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;[9/7/2009 2:13:47 PM]: Report Failed System.Data.SqlClient.SqlException: Timeout expired.&amp;nbsp; The timeout period elapsed prior to completion of the operation or the server is not responding.&lt;br /&gt;&amp;nbsp;&amp;nbsp; at System.Data.SqlClient.SqlConnection.OnError(SqlException exception, Boolean breakConnection)&lt;br /&gt;&amp;nbsp;&amp;nbsp; at System.Data.SqlClient.SqlInternalConnection.OnError(SqlException exception, Boolean breakConnection)&lt;br /&gt;&amp;nbsp;&amp;nbsp; at System.Data.SqlClient.TdsParser.ThrowExceptionAndWarning(TdsParserStateObject stateObj)&lt;br /&gt;&amp;nbsp;&amp;nbsp; at System.Data.SqlClient.TdsParser.Run(RunBehavior runBehavior, SqlCommand cmdHandler, SqlDataReader dataStream, BulkCopySimpleResultSet bulkCopyHandler, TdsParserStateObject stateObj)&lt;br /&gt;&amp;nbsp;&amp;nbsp; at System.Data.SqlClient.SqlCommand.RunExecuteNonQueryTds(String methodName, Boolean async)&lt;br /&gt;&amp;nbsp;&amp;nbsp; at System.Data.SqlClient.SqlCommand.InternalExecuteNonQuery(DbAsyncResult result, String methodName, Boolean sendToPipe)&lt;br /&gt;&amp;nbsp;&amp;nbsp; at System.Data.SqlClient.SqlCommand.ExecuteNonQuery()&lt;br /&gt;&amp;nbsp;&amp;nbsp; at gy.a(IDbConnection A_0, String A_1)&lt;br /&gt;&amp;nbsp;&amp;nbsp; at gy.a(String A_0, Int32 A_1)&lt;br /&gt;&amp;nbsp;&amp;nbsp; at HP.AppSec.Reporting.ReportsDB.b(ReportsDB A_0, SqlCeConnection A_1)&lt;br /&gt;&amp;nbsp;&amp;nbsp; at HP.AppSec.Reporting.ReportsDB.UpdateCache()&lt;br /&gt;&amp;nbsp;&amp;nbsp; at HP.AppSec.Reporting.DataProviders.ScanDataProvider.GetData(IQuery queryDescriptor, Boolean topZeroFlag, IRtfFontToFieldMapper rtfFontMapper, IPropertyToFieldMapper propertyMapper)&lt;br /&gt;&amp;nbsp;&amp;nbsp; at HP.AppSec.Reporting.ReportDataSource.getReportData(IQuery queryDescriptor, Boolean topZeroFlag, IRtfFontToFieldMapper rtfFontMapper, IPropertyToFieldMapper propertyMapper)&lt;br /&gt;&amp;nbsp;&amp;nbsp; at HP.AppSec.Reporting.ReportDataSource.GetReportData(IQuery queryDescriptor, IRtfFontToFieldMapper rtfFontMapper, IPropertyToFieldMapper propertyMapper)&lt;br /&gt;&amp;nbsp;&amp;nbsp; at HP.AppSec.Reporting.ReportDescriptor.getReportRunInstance(ActiveReport3 clonedReport, ReportDescriptor mainReport)&lt;br /&gt;&amp;nbsp;&amp;nbsp; at HP.AppSec.Reporting.ReportEventHandlers.SubReportFormatHandler.a(SubReport A_0, Section A_1)&lt;br /&gt;&amp;nbsp;&amp;nbsp; at HP.AppSec.Reporting.ReportEventHandlers.SubReportFormatHandler.d(Object A_0, EventArgs A_1)&lt;br /&gt;&amp;nbsp;&amp;nbsp; at System.EventHandler.Invoke(Object sender, EventArgs e)&lt;br /&gt;&amp;nbsp;&amp;nbsp; at DataDynamics.ActiveReports.Section.#7kf()&lt;br /&gt;&amp;nbsp;&amp;nbsp; at DataDynamics.ActiveReports.Section.#Clf(ActiveReport3 report)&lt;br /&gt;&amp;nbsp;&amp;nbsp; at #kyd.#TD.#1mf(Section section)&lt;br /&gt;&amp;nbsp;&amp;nbsp; at #kyd.#TD.#Nqf()&lt;br /&gt;&amp;nbsp;&amp;nbsp; at #kyd.#TD.#Iqf(Page newPage, Single left, Single top, Single right, Single bottom, UInt32 flags, UInt32&amp;amp; status)&lt;br /&gt;&amp;nbsp;&amp;nbsp; at DataDynamics.ActiveReports.Section.#wlf(ActiveReport3 parentReport, #Oaf rData)&lt;br /&gt;&amp;nbsp;&amp;nbsp; at #kyd.#Haf.#Ukf(Int32 pieceIndex)&lt;br /&gt;&amp;nbsp;&amp;nbsp; at #kyd.#Haf.#Skf()&lt;br /&gt;&amp;nbsp;&amp;nbsp; at #kyd.#Haf.#lW(Section section, Int32 insPos)&lt;br /&gt;&amp;nbsp;&amp;nbsp; at #kyd.#Haf.#lW(Section section)&lt;br /&gt;&amp;nbsp;&amp;nbsp; at #kyd.#TD.#Nqf()&lt;br /&gt;&amp;nbsp;&amp;nbsp; at #kyd.#TD.#Iqf(Page newPage, Single left, Single top, Single right, Single bottom, UInt32 flags, UInt32&amp;amp; status)&lt;br /&gt;&amp;nbsp;&amp;nbsp; at DataDynamics.ActiveReports.ActiveReport3.#Smf()&lt;br /&gt;&amp;nbsp;&amp;nbsp; at DataDynamics.ActiveReports.ActiveReport3.Run(Boolean syncDocument)&lt;br /&gt;&amp;nbsp;&amp;nbsp; at HP.AppSec.Reporting.ReportDescriptor.runReport(Boolean syncDocument)&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;WebInspect crashed with following Error Details after I&amp;#39;d generated a solo Aggregate Report, saved and closed that report, then generated an aggregated Executive Summary report:&lt;/p&gt;
&lt;p&gt;System.Threading.Thread&lt;br /&gt;Build:8.1.524.2&lt;br /&gt;&lt;br /&gt;Index was out of range. Must be non-negative and less than the size of the collection.&lt;br /&gt;Parameter name: index&lt;br /&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp; at System.Collections.CollectionBase.System.Collections.IList.get_Item(Int32 index)&lt;br /&gt;&amp;nbsp;&amp;nbsp; at #gwd.#nAd.get_Item(Int32 index)&lt;br /&gt;&amp;nbsp;&amp;nbsp; at DataDynamics.ActiveReports.Document.Page.Draw(Graphics graphics, RectangleF bounds, TextRenderingHint textRenderHint, Single scaleFactorX, Single scaleFactorY, Boolean printing)&lt;br /&gt;&amp;nbsp;&amp;nbsp; at DataDynamics.ActiveReports.Document.Page.Draw(Graphics graphics, RectangleF bounds, Single scaleFactorX, Single scaleFactorY)&lt;br /&gt;&amp;nbsp;&amp;nbsp; at DataDynamics.ActiveReports.Document.Page.Draw(Graphics graphics, RectangleF bounds)&lt;br /&gt;&amp;nbsp;&amp;nbsp; at #Cwd.#oAd.OnPaint(PaintEventArgs e)&lt;br /&gt;&amp;nbsp;&amp;nbsp; at System.Windows.Forms.Control.PaintWithErrorHandling(PaintEventArgs e, Int16 layer, Boolean disposeEventArgs)&lt;br /&gt;&amp;nbsp;&amp;nbsp; at System.Windows.Forms.Control.WmPaint(Message&amp;amp; m)&lt;br /&gt;&amp;nbsp;&amp;nbsp; at System.Windows.Forms.Control.WndProc(Message&amp;amp; m)&lt;br /&gt;&amp;nbsp;&amp;nbsp; at System.Windows.Forms.ScrollableControl.WndProc(Message&amp;amp; m)&lt;br /&gt;&amp;nbsp;&amp;nbsp; at #Cwd.#oAd.WndProc(Message&amp;amp; m)&lt;br /&gt;&amp;nbsp;&amp;nbsp; at System.Windows.Forms.Control.ControlNativeWindow.OnMessage(Message&amp;amp; m)&lt;br /&gt;&amp;nbsp;&amp;nbsp; at System.Windows.Forms.Control.ControlNativeWindow.WndProc(Message&amp;amp; m)&lt;br /&gt;&amp;nbsp;&amp;nbsp; at System.Windows.Forms.NativeWindow.Callback(IntPtr hWnd, Int32 msg, IntPtr wparam, IntPtr lparam)&lt;/p&gt;
&lt;p&gt;...resulting in WI closing. And immediately another Error was reported with following Error Details:&lt;/p&gt;
&lt;p&gt;System.ArgumentOutOfRangeException&lt;br /&gt;&lt;br /&gt;Index was out of range. Must be non-negative and less than the size of the collection.&lt;br /&gt;Parameter name: index&lt;br /&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp; at SPI.UI.ErrorForm.a(Object A_0, Exception A_1)&lt;br /&gt;&amp;nbsp;&amp;nbsp; at SPI.UI.ErrorForm.a(Object A_0, ThreadExceptionEventArgs A_1)&lt;br /&gt;&amp;nbsp;&amp;nbsp; at System.Windows.Forms.Application.ThreadContext.OnThreadException(Exception t)&lt;br /&gt;&amp;nbsp;&amp;nbsp; at System.Windows.Forms.Control.WndProcException(Exception e)&lt;br /&gt;&amp;nbsp;&amp;nbsp; at System.Windows.Forms.Control.ControlNativeWindow.OnThreadException(Exception e)&lt;br /&gt;&amp;nbsp;&amp;nbsp; at System.Windows.Forms.NativeWindow.Callback(IntPtr hWnd, Int32 msg, IntPtr wparam, IntPtr lparam)&lt;br /&gt;&amp;nbsp;&amp;nbsp; at System.Windows.Forms.UnsafeNativeMethods.DispatchMessageW(MSG&amp;amp; msg)&lt;br /&gt;&amp;nbsp;&amp;nbsp; at System.Windows.Forms.Application.ComponentManager.System.Windows.Forms.UnsafeNativeMethods.IMsoComponentManager.FPushMessageLoop(Int32 dwComponentID, Int32 reason, Int32 pvLoopData)&lt;br /&gt;&amp;nbsp;&amp;nbsp; at System.Windows.Forms.Application.ThreadContext.RunMessageLoopInner(Int32 reason, ApplicationContext context)&lt;br /&gt;&amp;nbsp;&amp;nbsp; at System.Windows.Forms.Application.ThreadContext.RunMessageLoop(Int32 reason, ApplicationContext context)&lt;br /&gt;&amp;nbsp;&amp;nbsp; at System.Windows.Forms.Application.Run(Form mainForm)&lt;br /&gt;&amp;nbsp;&amp;nbsp; at aba.h()&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Not able to access the AMP Manager running on localhost from different machine</title><link>http://www.communities.hp.com/securitysoftware/forums/thread/108529.aspx</link><pubDate>Wed, 11 Nov 2009 11:24:14 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:108529</guid><dc:creator>sutapa.hp</dc:creator><slash:comments>2</slash:comments><comments>http://www.communities.hp.com/securitysoftware/forums/thread/108529.aspx</comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/forums/commentrss.aspx?SectionID=106&amp;PostID=108529</wfw:commentRss><description>&lt;p&gt;Hi,&lt;/p&gt;
&lt;p&gt;I have successfully installed and initialized AMP Manager and AMP Console. I can access both AMP Console and AMP Web Console from the VM in which I have installed the manager.&lt;/p&gt;
&lt;p&gt;But I am not able to access the Web console from other remote systems with the hostname/IP.&lt;/p&gt;
&lt;p&gt;Please suggest a way out.&lt;/p&gt;
&lt;p&gt;Thanks and Regards,&lt;/p&gt;
&lt;p&gt;Sutapa&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Error:Connectivity issue, Reason:ServerConsecutive, Server:&lt;domain_name&gt;.com</title><link>http://www.communities.hp.com/securitysoftware/forums/thread/108482.aspx</link><pubDate>Sat, 31 Oct 2009 00:30:16 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:108482</guid><dc:creator>jaugustin@ti.com</dc:creator><slash:comments>1</slash:comments><comments>http://www.communities.hp.com/securitysoftware/forums/thread/108482.aspx</comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/forums/commentrss.aspx?SectionID=20&amp;PostID=108482</wfw:commentRss><description>&lt;p&gt;Hi All,&lt;/p&gt;
&lt;p&gt;Webinspect keeps throwing this error: Error:Connectivity issue, Reason:ServerConsecutive, Server:&amp;lt;domain_name&amp;gt;.com&lt;/p&gt;
&lt;p&gt;where domain_name is an external third party site&amp;nbsp; and is already rejected in the session exclusion in scan settings.&lt;/p&gt;
&lt;p&gt;Anyone knows how circumvent that? I have regular expressions matching the domain_name in the session exclusion as both host and url. I am using version 8.0.753.&amp;nbsp; Thanks!&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>No updates</title><link>http://www.communities.hp.com/securitysoftware/forums/thread/108503.aspx</link><pubDate>Thu, 05 Nov 2009 11:04:29 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:108503</guid><dc:creator>dssq-di</dc:creator><slash:comments>1</slash:comments><comments>http://www.communities.hp.com/securitysoftware/forums/thread/108503.aspx</comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/forums/commentrss.aspx?SectionID=20&amp;PostID=108503</wfw:commentRss><description>&lt;p&gt;Hello,&lt;/p&gt;
&lt;p&gt;I&amp;#39;ve updated webinspect to the latest SP. After that I get this message every time I clik on the Smart Update button :&lt;/p&gt;
&lt;p&gt;&amp;quot;Smart update complete. There were no new updates found&amp;quot;&lt;/p&gt;
&lt;p&gt;Before installing this SP, webinspect was updated every day oy even few times a day, have you chage the update policy?&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Regards&lt;/p&gt;
&lt;p&gt;Paulo&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Cannot connect to web service to retrieve the license</title><link>http://www.communities.hp.com/securitysoftware/forums/thread/89937.aspx</link><pubDate>Tue, 16 Jun 2009 00:48:53 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:89937</guid><dc:creator>marilyndaum</dc:creator><slash:comments>5</slash:comments><comments>http://www.communities.hp.com/securitysoftware/forums/thread/89937.aspx</comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/forums/commentrss.aspx?SectionID=20&amp;PostID=89937</wfw:commentRss><description>&lt;p&gt;I recently upgraded to WebInspect 8.&amp;nbsp; Since that time, Smart Update has not run successfully for me.&amp;nbsp; Attempts to do so yield a popup error &amp;quot;Cannot connect to web service to retrieve the license.&amp;quot;&amp;nbsp; Hopefully I&amp;#39;m just missing something simple, but I can&amp;#39;t figure out what the problem is.&amp;nbsp; Any suggestions?&lt;/p&gt;
&lt;p&gt;WebInspect is version 8.0.548.0.&lt;/p&gt;
&lt;p&gt;Thanks.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>WebInspect 8.0.625.1 Patch available via Support</title><link>http://www.communities.hp.com/securitysoftware/forums/thread/90179.aspx</link><pubDate>Wed, 24 Jun 2009 21:17:59 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:90179</guid><dc:creator>HansEnders</dc:creator><slash:comments>1</slash:comments><comments>http://www.communities.hp.com/securitysoftware/forums/thread/90179.aspx</comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/forums/commentrss.aspx?SectionID=20&amp;PostID=90179</wfw:commentRss><description>&lt;p&gt;&amp;lt;&amp;lt;&lt;br /&gt;&lt;br /&gt;HP Development is releasing this special build to Customer Support to be used as a patch for WebInspect 8.0.&amp;nbsp; This build has had limited testing, limited to the &amp;quot;HotFix CRs&amp;quot; listed below.&amp;nbsp; An addition, other CRs have been included in this build which may or may not have been verified by QA.&amp;nbsp; This patch should only be provided to customers to address those items listed under &amp;quot;Defects Fixed&amp;quot;.&lt;br /&gt;&lt;br /&gt;Build #:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8.0.625.1&lt;br /&gt;&lt;/p&gt;
&lt;p&gt;Notes:&amp;nbsp; This build is a stand-alone build and is not included or available in any SmartUpdate to the current release, WebInspect 8.0.548.0.&lt;/p&gt;
&lt;p&gt;&amp;gt;&amp;gt;&lt;br /&gt;&lt;br /&gt;This build will still receive the large SmartUpdate1 package from earlier in June 2009 that included new Reporting items, as referenced here:&amp;nbsp; http://www.communities.hp.com/securitysoftware/forums/t/8323.aspx&lt;br /&gt;&lt;br /&gt;Release Notes are attached to this posting. &lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>WebInspect 8.0.687.0 Patch available via Support</title><link>http://www.communities.hp.com/securitysoftware/forums/thread/99874.aspx</link><pubDate>Fri, 04 Sep 2009 15:17:59 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:99874</guid><dc:creator>HansEnders</dc:creator><slash:comments>1</slash:comments><comments>http://www.communities.hp.com/securitysoftware/forums/thread/99874.aspx</comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/forums/commentrss.aspx?SectionID=20&amp;PostID=99874</wfw:commentRss><description>&lt;p&gt;&amp;lt;&amp;lt;&lt;/p&gt;
&lt;p&gt;HP ASC Development is releasing this build to the ASC Customer Support team to be used as a Patch for WebInspect 8.0.  This build includes all fixes from previous WebInspect 8.0 HotFixes, Patches and SmartUpdates.  Testing for this build has been limited to the CRs listed.  Therefore, provide this patch ONLY to those customers experiencing the below issues (or issues from previous WebInspect 8.0 HotFixes, Patches and SmartUpdates).&lt;/p&gt;
&lt;p&gt;&amp;gt;&amp;gt;&lt;/p&gt;
&lt;p&gt;This August release is a cumulative patch including the public release 8.0.548 and all fixes or patches released since April 2009.&amp;nbsp; This version is only available if you are experiencing one of the issues detailed in the Release Notes for those build(s).&amp;nbsp; Anyone applying this version to their installation may need to manually install the next public release as this special version may not automatically SmartUpdate whenever that version is released.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Release Notes are attached to this posting. &lt;/b&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>WebInspect 8.0.753 Service Pack 1 available via SmartUpdate</title><link>http://www.communities.hp.com/securitysoftware/forums/thread/108456.aspx</link><pubDate>Fri, 23 Oct 2009 17:48:55 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:108456</guid><dc:creator>HansEnders</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/securitysoftware/forums/thread/108456.aspx</comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/forums/commentrss.aspx?SectionID=20&amp;PostID=108456</wfw:commentRss><description>&lt;p&gt;The WebInspect 8.0 Service Pack 1, version 8.0.753, was released on October 20th 2009.&amp;nbsp; There had been advance notices regarding this release posted to the Messages section of WebInspect&amp;#39;s Start Page tab.&lt;/p&gt;
&lt;p&gt;While there have been changes to the binaries and its factory Default Scan Settings, the upgrade or reinstall will not damage or affect your custom data (scan files, macros, web form files, settings files, et al).&amp;nbsp; Since our upgrades leave your personal defaults alone, you may need to open the Default Scan Settings screen and use the Load Factory Defaults button/link to reset these to the latest values.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;If you are currently on the public release version 8.0.548, SmartUpdate will upgrade you to this version automatically.&amp;nbsp; It may require a reboot.&lt;/p&gt;
&lt;p&gt;If you instead have a Support-Only build numbered between 8.0.548 and 8.0.753, then you may not be able to SmartUpdate&amp;nbsp;and receive this new release.&amp;nbsp; If this is your situation, you should download the 8.0.753 install file directly (link below), uninstall your current version from the Control Panel, reboot, install this newest version, and then reboot one final time.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;a href="https://download.hpsmartupdate.com/webinspect/WebInspectSetup.exe"&gt;https://download.hpsmartupdate.com/webinspect/WebInspectSetup.exe&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;The following error indicates you will have to manually install this new version:&lt;/p&gt;
&lt;p&gt;&amp;quot;Another version of this product is already installed.&amp;nbsp; Installation of this version cannot continue.&amp;nbsp; To configure or remove the existing versionof this product, use Add/Remove Programs on the Control Panel.&amp;quot;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Lastly, the product documentation bundle has also been updated.&amp;nbsp; It can be retrieved from this URL:&amp;nbsp; &lt;a href="https://download.hpsmartupdate.com/webinspect"&gt;https://download.hpsmartupdate.com/webinspect&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Release Notes are attached to this posting. &lt;/strong&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Documentation</title><link>http://www.communities.hp.com/securitysoftware/forums/thread/107879.aspx</link><pubDate>Wed, 30 Sep 2009 18:48:38 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:107879</guid><dc:creator>jason.gorman</dc:creator><slash:comments>3</slash:comments><comments>http://www.communities.hp.com/securitysoftware/forums/thread/107879.aspx</comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/forums/commentrss.aspx?SectionID=43&amp;PostID=107879</wfw:commentRss><description>&lt;p&gt;Is there any better documenation that the User Guide and Getting Started guide?&amp;nbsp; I would like some advanced info on exactly what QAInspect is testing for/on when running tests such as SQL Injection, etc.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Vista 64-bit and WebInspect 8 installation recommendations</title><link>http://www.communities.hp.com/securitysoftware/forums/thread/108407.aspx</link><pubDate>Fri, 16 Oct 2009 14:49:53 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:108407</guid><dc:creator>HansEnders</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/securitysoftware/forums/thread/108407.aspx</comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/forums/commentrss.aspx?SectionID=20&amp;PostID=108407</wfw:commentRss><description>&lt;p&gt;WebInspect 8.0.548 supports 64-bit Vista OS, but it requires certain adjustments.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; * Disable User account Control (UAC).&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; * Disable themes.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; * When installing, make sure 
that you run as Administrator. &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; * Best practice is to manually install both the 32-bit and 64-bit versions of Microsoft SQL Compact Edition (CE) 3.5 SP1.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Some users have experienced trouble with the SmartUpdate, as demonstrated by the following error.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp; SmartUpdate&lt;br /&gt;&amp;nbsp;&amp;nbsp; Exception has been thrown by the target of an invocation&lt;br /&gt;&amp;nbsp;&amp;nbsp; An attempt was made to load a program with an incorrect format. (Exception from HRESULT:0x8007000B)&lt;/p&gt;
&lt;p&gt;This is a symptom that indicates the SQL CE product needs to be updated per the steps below.&amp;nbsp;
The cause of this is that WebInspect incorporates a 32-bit installation
of Microsoft SQL Compact Edition (CE), but not a 64-bit version.&amp;nbsp; Even
if the 64-bit version is already installed, that same Microsoft&amp;#39;s article
suggests the 32-bit version may be necessary.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;This is the link we currently use and provide for installing SQL CE 3.5 SP1:&amp;nbsp; http://www.microsoft.com/downloads/details.aspx?FamilyId=DC614AEE-7E1C-4881-9C32-3A6CE53384D9&amp;amp;displaylang=en#filelist&lt;br /&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; (Reference source:&amp;nbsp;&amp;nbsp; https://download.hpsmartupdate.com/webinspect/ )&lt;br /&gt;&amp;nbsp;&lt;br /&gt;&amp;nbsp;&lt;br /&gt;Steps:&lt;br /&gt;&amp;nbsp;&lt;br /&gt;1.&amp;nbsp; Download the 32-bit install file &amp;quot;SSCERuntime-ENU-x86.msi&amp;quot;&lt;br /&gt;&amp;nbsp;&lt;br /&gt;2.&amp;nbsp; Download the 64-bit install file &amp;quot;DSSCERuntime-ENU-x64.msi&amp;quot;&lt;br /&gt;&amp;nbsp;&lt;br /&gt;3.&amp;nbsp; Install using SSCERuntime-ENU-x86.msi.&lt;br /&gt;&amp;nbsp;&lt;br /&gt;4.&amp;nbsp; Reboot.&lt;br /&gt;&amp;nbsp;&lt;br /&gt;5.&amp;nbsp; Install using DSSCERuntime-ENU-x64.msi&lt;br /&gt;&amp;nbsp;&lt;br /&gt;6.&amp;nbsp; Reboot.&lt;br /&gt;&amp;nbsp;&lt;br /&gt;7.&amp;nbsp; Open WebInspect and verify the SmartUpdate no longer fails with this &amp;quot;incorrect format&amp;quot; error.&lt;/p&gt;
&lt;p&gt;8.&amp;nbsp; Done.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Reference regarding the need for 32-bit CE on 64-bit Vista:&amp;nbsp; http://www.microsoft.com/downloads/details.aspx?FamilyId=DC614AEE-7E1C-4881-9C32-3A6CE53384D9&amp;amp;displaylang=en#filelist&lt;/p&gt;
&lt;p&gt;&amp;lt;&amp;lt;Due to changes in SQL Server Compact SP1 and additional 64-bit version support, centrally installed and mixed mode environments of 32-bit version of SQL Server Compact 3.5 and 64-bit version of SQL Server Compact 3.5 SP1 can create what appear to be intermittent problems. To minimize the potential for conflicts, and to enable platform neutral deployment of managed client applications, centrally installing the 64-bit version of SQL Server Compact 3.5 SP1 using the Windows Installer (MSI) file also requires installing the 32-bit version of SQL Server Compact 3.5 SP1 MSI file. For applications that only require native 64-bit, private deployment of the 64-bit version of SQL Server Compact 3.5 SP1 can be utilized.&amp;gt;&amp;gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Server Error Reponses</title><link>http://www.communities.hp.com/securitysoftware/forums/thread/108354.aspx</link><pubDate>Wed, 07 Oct 2009 21:05:17 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:108354</guid><dc:creator>mpgoug</dc:creator><slash:comments>1</slash:comments><comments>http://www.communities.hp.com/securitysoftware/forums/thread/108354.aspx</comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/forums/commentrss.aspx?SectionID=20&amp;PostID=108354</wfw:commentRss><description>&lt;p&gt;Is there anyway to disable a check once a audit is underway?&lt;/p&gt;
&lt;p&gt;Very often we test webservers who have incorrect error handling - so for every malformed request WI sends to the server it recives a 500* Server Error in return. This can dramtically fill the scan with False Positves and slow the assessment considerably. We will still advise the client of the issue however we do not need to see 000&amp;#39;s of &amp;#39;Server Error Responses&amp;#39; in the report.&lt;/p&gt;
&lt;p&gt;I cannot see a way to disable a check once the audit is running?&lt;/p&gt;
&lt;p&gt;Also how do I save a crawl so I can audit it serveral times?&lt;/p&gt;
&lt;p&gt;Kind Regards, Matt Gough UK&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>HP WebInspect End of Life Policy</title><link>http://www.communities.hp.com/securitysoftware/forums/thread/108357.aspx</link><pubDate>Thu, 08 Oct 2009 18:42:07 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:108357</guid><dc:creator>michaelspaulding</dc:creator><slash:comments>1</slash:comments><comments>http://www.communities.hp.com/securitysoftware/forums/thread/108357.aspx</comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/forums/commentrss.aspx?SectionID=20&amp;PostID=108357</wfw:commentRss><description>&lt;p&gt;How long after a major release of WebInspect does HP EOL the previous version?&amp;nbsp; Also, is there a date set for 9.X? Even a rough one for an estimate?&lt;/p&gt;
&lt;p&gt;Thanks,&lt;/p&gt;
&lt;p&gt;Mike&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Smart Update Note Working</title><link>http://www.communities.hp.com/securitysoftware/forums/thread/108387.aspx</link><pubDate>Tue, 13 Oct 2009 18:29:07 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:108387</guid><dc:creator>bukpu</dc:creator><slash:comments>1</slash:comments><comments>http://www.communities.hp.com/securitysoftware/forums/thread/108387.aspx</comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/forums/commentrss.aspx?SectionID=98&amp;PostID=108387</wfw:commentRss><description>&lt;p&gt;I just upgraded my version 7.7 WebInspect to version8 using my enterprise license.&amp;nbsp; The upgrade was successful but&amp;nbsp;the Smart update is not woking on the&amp;nbsp;WebInspect 8. when I click on Smart update or try to update through the pup up update window I&amp;#39;m getting this error: &amp;quot;cannot connect to web service to retrieve the license.&amp;quot; What do have to do to fix this issue?&lt;/p&gt;
&lt;p&gt;Bukpu&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Test of web services that requires authentication</title><link>http://www.communities.hp.com/securitysoftware/forums/thread/99088.aspx</link><pubDate>Thu, 27 Aug 2009 12:34:09 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:99088</guid><dc:creator>o_pedersen</dc:creator><slash:comments>2</slash:comments><comments>http://www.communities.hp.com/securitysoftware/forums/thread/99088.aspx</comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/forums/commentrss.aspx?SectionID=20&amp;PostID=99088</wfw:commentRss><description>&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span lang="EN-GB" style="mso-bidi-font-family:Verdana;mso-ansi-language:EN-GB;"&gt;&lt;span style="font-family:Verdana;"&gt;I&amp;rsquo;m not sure this is the right place to ask this question, but now I&amp;rsquo;m trying.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span lang="EN-GB" style="mso-bidi-font-family:Verdana;mso-ansi-language:EN-GB;"&gt;&lt;span style="font-family:Verdana;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span lang="EN-GB" style="mso-bidi-font-family:Verdana;mso-ansi-language:EN-GB;"&gt;&lt;span style="font-family:Verdana;"&gt;I&amp;rsquo;m trying to test a web service that requires authentication. The credential has to be send as header in the SOAP request, the problem is that the authentication header isn&amp;rsquo;t defined in the WSDL file and it seems that Webinspect is only capable of testing values defined here. I hoped to be able to modify the request that Webinspect uses by means of the function &amp;ldquo;Auto-fill SOAP messages during crawl&amp;rdquo; and the SOAP-tool.&lt;span style="mso-spacerun:yes;"&gt;&amp;nbsp; &lt;/span&gt;That is apparently not possible. I can however successfully modify a request with the HTTP editor, but that can&amp;rsquo;t be used by the automatic test engine. &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span lang="EN-GB" style="mso-bidi-font-family:Verdana;mso-ansi-language:EN-GB;"&gt;&lt;span style="font-family:Verdana;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span lang="EN-GB" style="mso-bidi-font-family:Verdana;mso-ansi-language:EN-GB;"&gt;&lt;span style="font-family:Verdana;"&gt;How can I do this in Webinspect?&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>General Report Questions</title><link>http://www.communities.hp.com/securitysoftware/forums/thread/108343.aspx</link><pubDate>Tue, 06 Oct 2009 21:39:51 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:108343</guid><dc:creator>corkrejl</dc:creator><slash:comments>2</slash:comments><comments>http://www.communities.hp.com/securitysoftware/forums/thread/108343.aspx</comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/forums/commentrss.aspx?SectionID=120&amp;PostID=108343</wfw:commentRss><description>&lt;p&gt;I&amp;#39;m going to start this by asking a&amp;nbsp;questions to determine if my problem is a installation issure or a complete lack of understanding of how the application works.&amp;nbsp;&amp;nbsp;I&amp;#39;m running a&amp;nbsp;trial version &amp;nbsp;Webinspect Version 8.0 .1.548 &lt;/p&gt;
&lt;p&gt;&amp;nbsp;In Report Designer I open the Compliance Report under Scan Reports, &amp;nbsp;I then select preview, chose one of the available scans then select the &amp;quot;OWASP Top 10&amp;quot; for the compliance template.&amp;nbsp; Everythings works as expected.&lt;/p&gt;
&lt;p&gt;I go back to design tab and save the report under a new name, creating a new custom report,&amp;nbsp;and then select the preview tab&amp;nbsp;the report will only show the top level report, the subreport data is not there even though the report contains the subreports controls.&amp;nbsp; Even restarting&amp;nbsp;Report Designer made no difference.&lt;/p&gt;
&lt;p&gt;Should the copy of the report have produced the same results?&amp;nbsp; If not could someone please recommend a good book so that I may&amp;nbsp;get a better understanding of how the Report Designer works.&lt;/p&gt;
&lt;p&gt;Thanks,&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>AMP 8.0.643 now supports SQL 2008 server</title><link>http://www.communities.hp.com/securitysoftware/forums/thread/108364.aspx</link><pubDate>Fri, 09 Oct 2009 21:03:48 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:108364</guid><dc:creator>HansEnders</dc:creator><slash:comments>0</slash:comments><comments>http://www.communities.hp.com/securitysoftware/forums/thread/108364.aspx</comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/forums/commentrss.aspx?SectionID=41&amp;PostID=108364</wfw:commentRss><description>&lt;p&gt;AMP 8.0.643 now supports Microsoft SQL Server 2008 for its database.&amp;nbsp; Previously it only supported SQL Server 2005 (SP3 or SP2).&amp;nbsp; The documentation is being updated at this time.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Ref:&amp;nbsp;&amp;nbsp; &lt;a href="https://download.hpsmartupdate.com/amp/"&gt;https://download.hpsmartupdate.com/amp/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;This change only affects the AMP Server&amp;#39;s database.&amp;nbsp; The AMP Sensors (as well as WebInspect and QAInspect) still only support SQL Server 2005, either Express or full, as their scan repositories and/or reporting workspace.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>WebInspect shortcomings</title><link>http://www.communities.hp.com/securitysoftware/forums/thread/108349.aspx</link><pubDate>Wed, 07 Oct 2009 15:30:26 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:108349</guid><dc:creator>brite_crawler</dc:creator><slash:comments>2</slash:comments><comments>http://www.communities.hp.com/securitysoftware/forums/thread/108349.aspx</comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/forums/commentrss.aspx?SectionID=98&amp;PostID=108349</wfw:commentRss><description>A few gripes to hopefully server to improve the product WebInspect:

1) Identifying the same issue multiple times.  Particularly I am referring to XSS where there is the same base URI and vulnerable parameter (although often there are slight changes to the query string).  Seem to me that if you have the same base URI and vulnerable parameter, you have the same vulnerability.  Also, WebInspect likes to think that  and  are different in the mentioned case.

2) Blind SQL Injection (confirmed) false positive and/or SQL Injection reported by WebInspect is declared not possible by SQL Injector.  You would think WebInspect and SQL Injector would use the same engine/logic but that does not appear to be the case.

3)  Blind SQL Injection reporting is insufficient.   Already discussed here: http://www.communities.hp.com/securitysoftware/forums/t/7870.aspx.  Basically it is impossible to verify blind SQL injection without having multiple requests and responses but WebInspect only provides a single request and response.

4) Trouble adding arbitrary page to the site list/tree.  A lot of times I discover issues that WebInspect doesn&amp;#39;t and I want to add the vulnerabilities to WebInspect.  The product allows you to add vulnerabilities but only to specific pages in the site that it has identified.  If it hasn&amp;#39;t identified it, there is no appropriate place to add it.  There doesn&amp;#39;t seem to be the ability to add an arbitrary page.  Even operating in Step Mode and manually visiting the page, WebInspect has trouble picking up on it.

5) False negatives.  Using other products like Burp Suite I find a significantly higher number of common issues like XSS and SQL injection.

6) Automatic crawling failures.  Often, WebInspect fails to fully cover a site, leaving portions untested.  This is largely due to complex javascript and other Web 2.0 atrocities that are out there.

7) Never ending scans.  Most of the scans I do never finish.  Again, largely due to Web 2.0 bloatware.

8) Clicking the &amp;quot;Save and Close&amp;quot; button in the Web macro Recorder prompts you with a dialog asking if you want to save.  I think, &amp;quot;Really?  Of course I want to save otherwise I wouldn&amp;#39;t have pressed the &amp;quot;Save and Close&amp;quot; button&amp;quot;. (Yes, I know I&amp;#39;m being pedantic.)

9) WebInspect runs on Windows only.  it uses the .NET framework so porting it to other operating systems is non-trivial.

10) Frequent lockups and/or crashes.  Crashing WebInspect is a way of life for me.&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>DataBase Full on 2005 MS SQL Express</title><link>http://www.communities.hp.com/securitysoftware/forums/thread/106104.aspx</link><pubDate>Tue, 22 Sep 2009 16:22:11 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:106104</guid><dc:creator>retroj100</dc:creator><slash:comments>2</slash:comments><comments>http://www.communities.hp.com/securitysoftware/forums/thread/106104.aspx</comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/forums/commentrss.aspx?SectionID=20&amp;PostID=106104</wfw:commentRss><description>&lt;p&gt;Has anyone come across an issue of a large file filling DB to capacity?&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Where is the users manual?</title><link>http://www.communities.hp.com/securitysoftware/forums/thread/107644.aspx</link><pubDate>Tue, 29 Sep 2009 16:12:04 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:107644</guid><dc:creator>asterix2112</dc:creator><slash:comments>1</slash:comments><comments>http://www.communities.hp.com/securitysoftware/forums/thread/107644.aspx</comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/forums/commentrss.aspx?SectionID=20&amp;PostID=107644</wfw:commentRss><description>&lt;p&gt;Does anyone know where uou can download the 8.0 users manual?&lt;/p&gt;
&lt;p&gt;Thanks,&lt;/p&gt;
&lt;p&gt;- John Connor&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Passive Check fails (freezes crawl and audit) in some sites, seems to do with JavaScript sessions</title><link>http://www.communities.hp.com/securitysoftware/forums/thread/102327.aspx</link><pubDate>Fri, 11 Sep 2009 01:46:38 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:102327</guid><dc:creator>whips04r</dc:creator><slash:comments>7</slash:comments><comments>http://www.communities.hp.com/securitysoftware/forums/thread/102327.aspx</comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/forums/commentrss.aspx?SectionID=98&amp;PostID=102327</wfw:commentRss><description>&lt;p&gt;I&amp;#39;ve submitted the following to HP ASC Support, case ID 4603600629 and uploaded with that case an exported scan that manifests the problem. Posting here coz I respect the Freedom of Information act ;)&lt;/p&gt;
&lt;p&gt;In various websites I&amp;#39;ve been scanning over the past months, the crawler has failed, essentially freezing yet the scan can be paused and restarted but does not proceed from the point at which it freezes. This only occurs when &amp;#39;Follow JavaScript links&amp;#39; checkbox is checked, perhaps indicating that a certain JavaScript file is yeilding the problem. This occurs for Crawl Only and Audits, during the Audit the scanner tends to freeze during the following check (indicated in the Status Bar at bottom-left of UI):&lt;br /&gt;&lt;br /&gt;DOS Filename Source Disclosure&lt;br /&gt;&lt;br /&gt;I have tested this on various instances of WebInspect 8.0, running on Windows XP and Windows Server 2003. Previously I was experiencing this along with many OutOfMemory errors, so I thought it was just a side-effect of the OutOfMemory problem, however now expierencing this problem without OutOfMemory.&lt;br /&gt;&lt;br /&gt;Am running WebInspect 8.0 updated by SmartUpdate only (i.e. I have not installed any manual patches). I do not see anything in release notes for the various recent manual patch builds that relate to this problem, except one for AMP:&lt;br /&gt;&lt;br /&gt;From release notes for build 8.0.589.1:&lt;br /&gt;10195&amp;nbsp;&amp;nbsp; AMP 8.0 - Scan never completes and is not sending out any requests, even though it can be controlled (pause/stop/restart).&lt;br /&gt;&lt;br /&gt;But since I&amp;#39;m experiencing this with WebInspect I don&amp;#39;t see the need to install the manual patch.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Local Scan</title><link>http://www.communities.hp.com/securitysoftware/forums/thread/105519.aspx</link><pubDate>Mon, 21 Sep 2009 02:59:51 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:105519</guid><dc:creator>campioncheng</dc:creator><slash:comments>1</slash:comments><comments>http://www.communities.hp.com/securitysoftware/forums/thread/105519.aspx</comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/forums/commentrss.aspx?SectionID=20&amp;PostID=105519</wfw:commentRss><description>&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span lang="EN-US"&gt;&lt;span style="font-family:Times New Roman;font-size:small;"&gt;Dear Support, &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span lang="EN-US"&gt;&lt;span style="font-family:Times New Roman;font-size:small;"&gt;The situation is that I am hosting a server for web applications. I have to scan each of them before they go on production. Is it possible to scan them locally before they can go live. (may be host them under localhost?)&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span lang="EN-US"&gt;&lt;span style="font-family:Times New Roman;font-size:small;"&gt;The other question is that is it possible to scan the files that are going to host in the webserver w/ webinspect locally. What I mean is not a static source code scan since I do not host those sources code. Can I scan those files/web apps (i.e. some compiled code ) for vulnerabilities?&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span lang="EN-US"&gt;&lt;span style="font-family:Times New Roman;font-size:small;"&gt;If webinspect can scan locally, is it possible to scan thoroughly if the login user name and password is not provided. &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p class="MsoNormal" style="margin:0cm 0cm 0pt;"&gt;&lt;span lang="EN-US"&gt;&lt;span style="font-family:Times New Roman;font-size:small;"&gt;Thanks for your time&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Crawl not Working as Expected</title><link>http://www.communities.hp.com/securitysoftware/forums/thread/105697.aspx</link><pubDate>Mon, 21 Sep 2009 13:16:50 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:105697</guid><dc:creator>sfink16</dc:creator><slash:comments>1</slash:comments><comments>http://www.communities.hp.com/securitysoftware/forums/thread/105697.aspx</comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/forums/commentrss.aspx?SectionID=20&amp;PostID=105697</wfw:commentRss><description>&lt;p&gt;Good morning,&lt;/p&gt;
&lt;p&gt;I have been using Webinspect 8.0 for several months after taken over for the person who left.&amp;nbsp; I had limited training/instructions of about 15 minutes.&amp;nbsp; Recently I had further instructions from another user in the organization as a result switching from automatic crawl/audit to manual mode.&amp;nbsp; Until now I have been mostly successful.&lt;/p&gt;
&lt;p&gt;My latest crawl included 4 different logons that I successfully achieved running through each area of the web site I could test in the crawl.&lt;/p&gt;
&lt;p&gt;When I finished, clicking the Audit button expecting the scan to take hours to complete, it completed in a few minutes instead.&amp;nbsp; Running the Crawled URLs report confirm that the scan did NOT crawl the desired pages.&lt;/p&gt;
&lt;p&gt;What am I doing wrong?&amp;nbsp; Does this have anything to do with the fact that it is not scanning on port 80, instead scanning on port 8000?&amp;nbsp; Further, the site is using http instead of https, is this a problem?&lt;/p&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;Steve&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Web Form Editor auto-populating values</title><link>http://www.communities.hp.com/securitysoftware/forums/thread/106606.aspx</link><pubDate>Thu, 24 Sep 2009 18:40:55 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:106606</guid><dc:creator>brite_crawler</dc:creator><slash:comments>2</slash:comments><comments>http://www.communities.hp.com/securitysoftware/forums/thread/106606.aspx</comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/forums/commentrss.aspx?SectionID=98&amp;PostID=106606</wfw:commentRss><description>&lt;p&gt;I always thought it would be nice if the Web Form Editor would auto-populate all values for you when you browse thru it.&amp;nbsp; Any idea as to why this functionality does not exist?&amp;nbsp; It seems that a few get populated but it is the ones I don&amp;#39;t need....&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Unable to load scan list from SQL Express</title><link>http://www.communities.hp.com/securitysoftware/forums/thread/99350.aspx</link><pubDate>Tue, 01 Sep 2009 14:45:42 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:99350</guid><dc:creator>seremoth</dc:creator><slash:comments>4</slash:comments><comments>http://www.communities.hp.com/securitysoftware/forums/thread/99350.aspx</comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/forums/commentrss.aspx?SectionID=20&amp;PostID=99350</wfw:commentRss><description>&lt;p&gt;Hi&lt;/p&gt;
&lt;p&gt;I get this everytime I start WebInspect 8. I managed to configure webinspect to running scans again. I have to switch to using SQL Server in the configuration instead of default (SQL Express).I&amp;#39;m using SQL Express 2005.&lt;/p&gt;
&lt;p&gt;It looks like webinspect is running fine except for the error msg but I&amp;#39;m not sure. Anyone have a idea of whats is going on?&lt;/p&gt;
&lt;p&gt;&amp;quot;Unable to load scan list from SQL Express&lt;br /&gt;Failed to generate a user instance of SQL Server due to a failure in starting the process for the user instances. The connection will be closed&amp;quot;&lt;/p&gt;
&lt;p&gt;I also tried to delete c:\Documents and Settings\&amp;lt;user&amp;gt;\Application Data\...\SQL Server Data\SQLEXPRESS folder but that just give me another error msg at startup.&lt;/p&gt;
&lt;p&gt;Thanks in advance&lt;/p&gt;
&lt;p&gt;Kim&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>