You can find this module at the Company level only.

ConnectSecure Web Application Scanner is a security testing tool developed based on the OWASP (Open Web Application Security Project) standards to identify security vulnerabilities in web applications. It is widely used during development, testing, and pre-deployment phases to ensure web applications are secure from potential threats.

Identify and assess vulnerabilities within web applications that attackers could exploit. Automatically scan for common security issues such as SQL injection, cross-site scripting (XSS), and authentication weaknesses.

Generate detailed reports outlining discovered vulnerabilities, their severity, and recommended remediation strategies.

This tool assists in prioritizing security measures, ensuring web applications are resilient against potential threats, and maintaining compliance with security standards.


Web Application Scanner - Table of Contents


Watch The Video.png

Visit our YouTube Channel for more video content: https://www.youtube.com/@connectsecure


Web Application Scanner - Overview

Access the Web Application Scanner from the company-level module, Cloud Assessments.

image-20250318-141616.png

Web Application Scanner - Details

Configurations

This is where you Add, Edit, Remove, and manually Scan the configured endpoints.

Tap the three-dot Action menu to access the Edit, Remove, and Scan Now options.

image-20250318-142350.png

Use the Add button to create a new endpoint to scan.

image-20250318-142521.png

Complete all the required fields as shown below.

image-20250318-142705.png

Field

Description

Name

Give the entry a name of your choice; describe what you are scanning

URL

Enter the URL of the web application to scan; you must enter the prefix to include https:// or http://

Exclude Paths

Enter any path(s) to exclude during the scan; this should include the full URL with prefix (leave blank for none)

Include Paths

Enter any path(s) to include during the scan; this should include the full URL with prefix (leave blank for all)

Scan Type

Choose from Passive or Active (see below for info)

Spider Type

Select Spider or Spider Ajax (see below for info)

Parse robots.txt

Select to include analyzing the robots.txt file contents

Example: domain.com/robots.txt

Parse sitemap.xml

Select to include analyzing the sitemap.xml file contents

Example: domain.com/sitemap.xml

Duration

Enter the max duration for a scan

Scan Later

Check this box to scan later based on the Scheduler or a manual scan


(blue star) What is a Passive Scan? (Non-Intrusive)

(blue star) When to Use a Passive Scan

(blue star) Limitations


(blue star) What is an Active Scan? (Intrusive)

(blue star) When to Use an Active Scan

(blue star) Limitations:


(blue star) What is a Spider scan? (Traditional Spidering)

(blue star) How Spider Works

(blue star) When to use Spider Scan?

(blue star) Limitations


(blue star) What is an Ajax Spider scan? (For Dynamic Web Apps)

(blue star) How Ajax Spider Works?

(blue star) When to Use Ajax Spider Scan?

(blue star) Limitations


(blue star) What is robots.txt?

A robots.txt file is a plain text file located at the root of a website (e.g., https://example.com/robots.txt). It follows the Robots Exclusion Protocol (REP) and provides instructions to web crawlers on which pages or directories they can or cannot access.


(blue star) What is sitemap.xml?

A sitemap.xml is an XML file that helps search engines and crawlers understand the structure of a website. It lists URLs along with optional metadata such as last modification date, change frequency, and priority.


Best Practice Scan Combinations Based On Scenarios

Scenario

Scan Combination

Use Case

Initial Scan (Recon)

Spider + Passive Scan

To identify surface-level weaknesses and gather all endpoints.

Full Security Testing

Spider + Active Scan

To perform complete vulnerability testing.

JavaScript Applications (SPA)

Ajax Spider + Active Scan

For dynamic web applications.

Regression / Automated Scan

Ajax Spider + Passive Scan

Quick continuous testing without harming the application.


Results

View the web application scanner configuration results here.

image-20250321-154748.png

Tap on the URL to see the Scan History table data, which includes the last date/time the scan ran, the duration of the scan, and the count of vulnerabilities.

image-20250321-154840.png

Click the updated date/time stamp to see the details. Use the Word icon to print and view a report.

image-20250321-154954.png

Tap on the description (ID) to see details about the finding.

image-20250321-155031.pngimage-20250321-155058.png

Tap the vulnerabilities links to see the corresponding OWASP and CWE threat sources.

image-20250321-155146.png

There is also a built-in toggle to view the findings in a table view style.

image-20250321-155300.png

Web Application Scanner - Action Toolbar Overview

image-20250318-142002.png

Web Application Scanner - Action Toolbar Details

Jobs

Tap to view the web application scanner-related jobs data.

image-20250318-141827.png

Alerts

Tap to view the timeline style of System Events with filtering options.

image-20240426-160844.png

Info

Tap to view the Getting Started info; see the link below for additional information.

https://cybercns.atlassian.net/wiki/x/MIDKfw


Need Support?

You can contact our support team by emailing support@connectsecure.com or visiting our Partner Portal, where you can create, view, and manage your tickets.

https://cybercns.freshdesk.com/en/support/login

image-20240206-144508.png