appscan只要关注应用层的安全问题
一,appscan扫描
1,白盒扫描=静态扫描,扫描源代码。
2,动态扫描=黑盒扫描,用工具来模拟黑客的攻击,查看应用层的响应。产品内部会有大量受攻击的库,当我们把一个模拟攻击发给我们的应用的时候,然后用工具来分析响应。
二,AppScan Web应用扫描流程
一,appscan扫描
1,白盒扫描=静态扫描,扫描源代码。
2,动态扫描=黑盒扫描,用工具来模拟黑客的攻击,查看应用层的响应。产品内部会有大量受攻击的库,当我们把一个模拟攻击发给我们的应用的时候,然后用工具来分析响应。
二,AppScan Web应用扫描流程
![](https://images2017.cnblogs.com/blog/820545/201707/820545-20170728111950743-1200607992.png)
三,自动网络探索能力优势
![](https://images2017.cnblogs.com/blog/820545/201707/820545-20170728112020290-2014010092.png)
四,设置配置向导
测试网址:http://demo.testfire.net/bank/login.aspx
文件----->新建----->预定义模板(选择“常规扫描"为例)----->web应用程序扫描------>输入需要测试网址
![](https://images2017.cnblogs.com/blog/820545/201707/820545-20170728112126477-595694008.png)
点击"记录”
![](https://images2017.cnblogs.com/blog/820545/201707/820545-20170728112202180-312729218.png)
Username:jsmith
password:demo1234
![](https://images2017.cnblogs.com/blog/820545/201707/820545-20170728112247399-1341805832.png)
然后关闭Altoro Mutual:Online Banking Longin-Appscan 浏览器,在扫描配置向导页面的“使用以下登录序列登录应用程序”框中会显示登录的会员登录成功后的网址信息,然后点击“下一步”
![](https://images2017.cnblogs.com/blog/820545/201707/820545-20170728112306493-1677971538.png)
再点击下一步
![](https://images2017.cnblogs.com/blog/820545/201707/820545-20170728112341102-949298018.png)
点击完成
![](https://images2017.cnblogs.com/blog/820545/201707/820545-20170728112354649-84949688.png)
选择"是“自动保存
![](https://images2017.cnblogs.com/blog/820545/201707/820545-20170728112406977-2129809751.png)
保存扫描结果
![](https://images2017.cnblogs.com/blog/820545/201707/820545-20170728112420836-1619832186.png)
五,web services扫描
![](https://images2017.cnblogs.com/blog/820545/201707/820545-20170728112451055-1153263928.png)
接口测试网址:http://demo.testfire.net/transfer/transfer.asmx?wsdl
在扫描配置向导中选择通用服务客户机
![](https://images2017.cnblogs.com/blog/820545/201707/820545-20170728112520086-564154761.png)
设置起始URL
![](https://images2017.cnblogs.com/blog/820545/201707/820545-20170728112533336-1820736027.png)
默认测试策略web Service
![](https://images2017.cnblogs.com/blog/820545/201707/820545-20170728112545665-44105141.png)
完成
![](https://images2017.cnblogs.com/blog/820545/201707/820545-20170728112555555-1780678711.png)
显示通用服务窗口
![](https://images2017.cnblogs.com/blog/820545/201707/820545-20170728112606961-620132018.png)
输入用户id选择调用
![](https://images2017.cnblogs.com/blog/820545/201707/820545-20170728112619930-824456501.png)
转账接口数据的输入
![](https://images2017.cnblogs.com/blog/820545/201707/820545-20170728112642055-850580929.png)
方法调用
![](https://images2017.cnblogs.com/blog/820545/201707/820545-20170728112653149-1174628445.png)
探索完成之后关闭Generic Sercice Client窗口,appscan就会对探索的结果进行分析扫描,
然后在扫描选项中选择仅测试
![](https://images2017.cnblogs.com/blog/820545/201707/820545-20170728112718618-830899517.png)
显示扫描结果
![](https://images2017.cnblogs.com/blog/820545/201707/820545-20170728112736368-452433321.png)
六、Glass Box Scanning-架构
![](https://images2017.cnblogs.com/blog/820545/201707/820545-20170728112755461-698301088.png)
![](https://images2017.cnblogs.com/blog/820545/201707/820545-20170728112805540-331351376.png)
打开wed应用扫描的文件,在工具菜单选项中选择Glass box代理程序管理-----玻璃盒代理
![](https://images2017.cnblogs.com/blog/820545/201707/820545-20170728112825524-1356222991.png)
可以帮助用户发现隐藏的参数,页面
![](https://images2017.cnblogs.com/blog/820545/201707/820545-20170728112845758-459753906.png)
七、记录代理