<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet href="http://feeds.feedburner.com/~d/styles/atom10full.xsl" type="text/xsl" media="screen"?><?xml-stylesheet href="http://feeds.feedburner.com/~d/styles/itemcontent.css" type="text/css" media="screen"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" xml:lang="en"><title type="html">HP Application Security Center News</title><subtitle type="html">With your host, Erik</subtitle><id>http://portal.spidynamics.com/blogs/products/atom.aspx</id><link rel="alternate" type="text/html" href="http://portal.spidynamics.com/blogs/products/default.aspx" /><generator uri="http://communityserver.org" version="2.1.60809.935">Community Server</generator><updated>2006-11-27T09:43:00Z</updated><geo:lat>33.926753</geo:lat><geo:long>-84.338776</geo:long><link rel="self" href="http://feeds.feedburner.com/SpiProductNews" type="application/atom+xml" /><entry><title>DevInspect 5.0 is now available.</title><link rel="alternate" type="text/html" href="http://feeds.feedburner.com/~r/SpiProductNews/~3/261712846/DevInspect-5.0-is-now-available_2E00_.aspx" /><id>http://portal.spidynamics.com/blogs/products/archive/2008/04/01/DevInspect-5.0-is-now-available_2E00_.aspx</id><published>2008-04-01T04:09:00Z</published><updated>2008-04-01T04:09:00Z</updated><content type="html">&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;strong&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;Introducing HP DevInspect 5.0&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;HP DevInspect extends the reach of HP&amp;rsquo;s Application Lifecycle Optimization portfolio into product development.&amp;nbsp; Combining our award-winning dynamic application scanning technology with static code analysis, HP DevInspect is the only tool available that performs true Hybrid Analysis &amp;ndash; both white-box and black-box testing.&amp;nbsp; HP DevInspect is seamlessly integrated with the Integrated Development Environment (IDE) &amp;ndash; Visual Studio for .NET or Eclipse or RAD for Java &amp;ndash; minimizing the training required to learn a new tool and eliminating any disruption of the development timeline.&amp;nbsp; The release of HP DevInspect 5.0 further enhances Hybrid Analysis and increases development efficiencies with the following features:&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="color:#1f497d;"&gt;&lt;font face="Calibri" size="3"&gt;&amp;nbsp;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;strong&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;Visual Studio 2008 Support&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;HP DevInspect &amp;nbsp;for .Net now supports Microsoft Visual Studio 2008 and Visual Studio 2005.&amp;nbsp; Businesses can now test for vulnerabilities with Hybrid Analysis regardless of the Visual Studio IDE preferred by their developers even in mixed environments.&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;strong&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;Struts 1.x MVC support&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;Struts is one of the most popular java frameworks used for web application development. HP DevInspect for Java 5.0 fully supports integrated security testing within Eclipse or IBM RAD for applications using the Struts framework.&amp;nbsp; Corporations using industry standard design practices can now take full advantage of the Hybrid Analysis inherent in HP DevInspect.&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;strong&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;Hybrid Analysis&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;HP DevInspect is the only product to combine static analysis of all byte-code (both Java and MSIL) with dynamic black-box vulnerability scanning in one.&amp;nbsp; The static &amp;nbsp;analysis and dynamic scan engines have both been upgraded in HP DevInspect 5.0 to increase the accuracy, performance, and repeatability of our Hybrid Analysis. The time and money spent finding and fixing security vulnerabilities can now be dramatically decreased by equipping developers with an IDE with built-in Hybrid Analysis.&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;strong&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;Vista Support&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;HP DevInspect for Java and HP DevInspect for .Net are now fully supported on Microsoft Vista.&amp;nbsp; IT organizations looking to upgrade their existing desktop environments can transition their developers without risking their ability to perform Hybrid Analysis on their applications. &lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;font face="Calibri" size="3"&gt;&amp;nbsp;&lt;/font&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;strong&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;&lt;a href="https://h10078.www1.hp.com/cda/hpms/display/main/hpms_content.jsp?zn=bto&amp;amp;cp=1-11-201-200^9564_4000_100__" title="DevInspect Home Page"&gt;Ready for Download today!&lt;/a&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;img src="http://portal.spidynamics.com/aggbug.aspx?PostID=75792" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SpiProductNews?a=wik8IwF"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpiProductNews?i=wik8IwF" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/SpiProductNews?a=ZO9itqf"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpiProductNews?i=ZO9itqf" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpiProductNews/~4/261712846" height="1" width="1"/&gt;</content><author><name>patrickwolf</name><uri>http://portal.spidynamics.com/members/patrickwolf.aspx</uri></author><category term="DevInspect" scheme="http://portal.spidynamics.com/blogs/products/archive/tags/DevInspect/default.aspx" /><feedburner:origLink>http://portal.spidynamics.com/blogs/products/archive/2008/04/01/DevInspect-5.0-is-now-available_2E00_.aspx</feedburner:origLink></entry><entry><title>QAInspect 5.0 is now available.</title><link rel="alternate" type="text/html" href="http://feeds.feedburner.com/~r/SpiProductNews/~3/261495846/QAInspect-5.0-is-now-available_2E00_.aspx" /><id>http://portal.spidynamics.com/blogs/products/archive/2008/03/31/QAInspect-5.0-is-now-available_2E00_.aspx</id><published>2008-03-31T20:02:00Z</published><updated>2008-03-31T20:02:00Z</updated><content type="html">&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;strong&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;Introducing HP QAInspect 5.0&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;HP QAInspect completes the third pillar of Application Lifecycle Optimization.&amp;nbsp; Does it work?&amp;nbsp; Does it perform?&amp;nbsp; Is it secure?&amp;nbsp; Built on the foundation of the award-winning application scanning technology in HP WebInspect, QAInspect enables quality professionals to fully manage the process of finding and fixing security defects early in the application lifecycle. This ability to manage security defect testing early in the application lifecycle mitigates risk in the application, saves money on revisions over the life of the application, and produces more holistic data &amp;nbsp;for a Go/No Go decision.&amp;nbsp; The upcoming release of HP QAInspect 5.0 extends the already robust integration with Quality Center with the following new features:&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="color:#1f497d;"&gt;&lt;font face="Calibri" size="3"&gt;&amp;nbsp;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;strong&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;Defect Staging&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;New in QAInspect 5,0 is a staging area to vet vulnerabilities before they are added to the defect table within QC.&amp;nbsp; Users can fully test and validate all vulnerabilities found by the scan to ensure that application developers are only spending development cycles fixing confirmed defects.&amp;nbsp; &lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;strong&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;Defect Consolidation&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;Vulnerabilities found during a scan can now be viewed as a consolidated list, grouped by application page or defect type.&amp;nbsp; For example, a user may view all vulnerabilities found on the login page of an application.&amp;nbsp; Similarly, a user may view all Cross-Site Scripting vulnerabilities or all SQL Injection vulnerabilities grouped into a single pane.&amp;nbsp; The ability to group vulnerabilities allows users to more quickly log specific defects and assign defect tasks to developers with greater accuracy.&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;strong&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;Folder Restrictions&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;Restrict the crawl and audit of a scan to a particular folder. This allows much more granular control of the testing allowing for better targeted security testing. Once a particular application section has been audited and all security issues mitigated to an acceptible degree it can be moved to regression; focusing new security testing and fixes on new functional areas of the application.&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;strong&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;Parameter Highlighting&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;As the size and complexity of web application pages grow the ability to quickly find a specific parameter within a vulnerable page becomes a greater burden.&amp;nbsp; In order to eliminate the time wasted by developers searching a page for a particular vulnerability all defect reports now highlight the specific vulnerable parameter within the HTTP Request/Response pair.&amp;nbsp; Developers can easily find the vulnerable part of the application and apply a fix with limited downtime.&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;strong&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;&lt;a href="https://h10078.www1.hp.com/cda/hpms/display/main/hpms_content.jsp?zn=bto&amp;amp;cp=1-11-201-200^9561_4000_100__" title="QAInspect Home Page"&gt;Trial License Now Available (Click Here)&lt;/a&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;This release includes a trial license allowing Quality Center customers to download and evaluate QAInspect for 15 days; enabling them to make better purchase decisions.&amp;nbsp; Talk to your sales representative for more details.&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;img src="http://portal.spidynamics.com/aggbug.aspx?PostID=75778" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SpiProductNews?a=moCRlpF"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpiProductNews?i=moCRlpF" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/SpiProductNews?a=odXPQOf"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpiProductNews?i=odXPQOf" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpiProductNews/~4/261495846" height="1" width="1"/&gt;</content><author><name>patrickwolf</name><uri>http://portal.spidynamics.com/members/patrickwolf.aspx</uri></author><feedburner:origLink>http://portal.spidynamics.com/blogs/products/archive/2008/03/31/QAInspect-5.0-is-now-available_2E00_.aspx</feedburner:origLink></entry><entry><title>New HP Application Security Resource Library</title><link rel="alternate" type="text/html" href="http://feeds.feedburner.com/~r/SpiProductNews/~3/215235697/New-HP-Application-Security-Resource-Library.aspx" /><id>http://portal.spidynamics.com/blogs/products/archive/2008/01/11/New-HP-Application-Security-Resource-Library.aspx</id><published>2008-01-11T21:43:00Z</published><updated>2008-01-11T21:43:00Z</updated><content type="html">&lt;p&gt;Hi everyone, we have just completed the new &lt;a href="https://h10078.www1.hp.com/cda/hpms/display/main/hpms_content.jsp?zn=bto&amp;amp;cp=1-11-201-200^14344_4000_100__" target="_blank"&gt;HP Application Security Resource Library&lt;/a&gt;. Your one stop shop for product datasheets, whitepapers and presentations. If you currently going to the &lt;a href="http://portal.spidynamics.com/files/default.aspx"&gt;downloads&lt;/a&gt; section on the Portal site for some of this information please update your links and use this new location instead.&lt;/p&gt;&lt;p&gt;If you haven&amp;#39;t had the chance to read some of our whitepapers or presentations, take a moment to check it out, there are great articles on dealing with AJAX security issues, PCI Compliance as well as papers on SQL Injection and Cross Site Scripting (XSS). All together the new HP Application Security Resource Library might be one of the largest collections of application security focused documents available on the web.&lt;/p&gt;&lt;p&gt;We are also always looking for requests on what papers and articles you would like to see added, drop us a comment or two with your requests.&lt;/p&gt;&lt;p&gt;Thanks,&lt;/p&gt;&lt;p&gt;Erik&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;img src="http://portal.spidynamics.com/aggbug.aspx?PostID=73200" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SpiProductNews?a=6IPuEmD"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpiProductNews?i=6IPuEmD" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/SpiProductNews?a=mCqb8Xd"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpiProductNews?i=mCqb8Xd" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpiProductNews/~4/215235697" height="1" width="1"/&gt;</content><author><name>Erik</name><uri>http://portal.spidynamics.com/members/Erik.aspx</uri></author><category term="Application Security Resource Library" scheme="http://portal.spidynamics.com/blogs/products/archive/tags/Application+Security+Resource+Library/default.aspx" /><category term="whitepapers" scheme="http://portal.spidynamics.com/blogs/products/archive/tags/whitepapers/default.aspx" /><category term="datasheets" scheme="http://portal.spidynamics.com/blogs/products/archive/tags/datasheets/default.aspx" /><category term="presentations" scheme="http://portal.spidynamics.com/blogs/products/archive/tags/presentations/default.aspx" /><feedburner:origLink>http://portal.spidynamics.com/blogs/products/archive/2008/01/11/New-HP-Application-Security-Resource-Library.aspx</feedburner:origLink></entry><entry><title>WebInspect 7.7 just around the corner</title><link rel="alternate" type="text/html" href="http://feeds.feedburner.com/~r/SpiProductNews/~3/165782208/WebInspect-7.7-just-around-the-corner.aspx" /><id>http://portal.spidynamics.com/blogs/products/archive/2007/10/05/WebInspect-7.7-just-around-the-corner.aspx</id><published>2007-10-05T12:58:00Z</published><updated>2007-10-05T12:58:00Z</updated><content type="html">&lt;p&gt;&lt;strong&gt;&lt;font size="4"&gt;WebInspect 7.7 coming soon, so what&amp;#39;s new? Great question!&lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;What better way to let our customers know that HP is 100% commited to improving and delivering new functionality in WebInspect than to bring everyone a new release. This is our second WebInspect product update since getting aquired and there is a lot of things in this release that I think is going to make&amp;nbsp;everyone very happy.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;font size="3"&gt;What&amp;#39;s New&lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Re-branding to HP&lt;br /&gt;&lt;/strong&gt;WebInspect has been re-branded to show that it is now a part of the HP Software family. I had the task to pick from all sorts of images to find the one for the splash screen, i&amp;#39;m not sure I found the right one so I plan on changing it in the next release. I&amp;#39;d like to give the WebInspect community the oppertunity to suggest what we put in there next release so drop me a comment with your ideas.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;New Reports&lt;br /&gt;&lt;/strong&gt;A new False Positive report provides a list of the vulnerabilities that are currently marked as false positive. See &amp;ldquo;Improved False Positive Handling&amp;rdquo; below for more information. &lt;/li&gt;&lt;li&gt;&lt;strong&gt;Compliance Updates&lt;/strong&gt;&lt;br /&gt;Two new compliance templates will generate compliance reports based on OMB and OWASP Top 10 2007 requirements. The OMB template addresses major application security sections that were defined in December 2004 by the Office of Management and Budget (OMB) for Federal agency public websites. While the previous OWASP Top 10 list included a mix of vulnerabilities and attacks, the OWASP Top 10 2007 list focuses on vulnerabilities.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;False Positive View&lt;br /&gt;&lt;/strong&gt;WebInspect now has a False Positive view that allows you to see the vulnerabilities and sessions that are currently marked as false positive. From the False Positive view, you can select a session or a vulnerability that you have determined is not a false positive and mark it as a vulnerability again. See &amp;ldquo;Improved False Positive Handling&amp;rdquo; below for more information.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Vulnerability Filtering&lt;br /&gt;&lt;/strong&gt;You can now filter vulnerabilities to prevent multiple parameters for the same session or multiple values sent for the same parameter from appearing multiple times in the site tree and reports. Vulnerability filtering consolidates the related vulnerabilities into a single vulnerability. The Vulnerability Filter is disabled by default, but can be configured on the Settings window under Audit Settings. &lt;/li&gt;&lt;li&gt;&lt;strong&gt;Enhanced Web Services Scans&lt;br /&gt;&lt;/strong&gt;WebInspect now supports the use of log-in scripts and a means of specifying parameter values for web services scans. &lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;&lt;font size="3"&gt;What&amp;rsquo;s Improved&lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;div&gt;&lt;strong&gt;Improved IPv6 Scanning&lt;br /&gt;&lt;/strong&gt;WebInspect now has improved recognition of IPv6 literal URLs and improved scanning of IPv6 sites. You can type an IPv6 literal URL into the scan wizard and WebInspect will validate the entry, parse the URL, and recognize IPv6 literal addresses in links on web pages. Additionally, Web Discovery handles IPv6 endpoints and range enumeration. &lt;/div&gt;&lt;/li&gt;&lt;li&gt;&lt;div&gt;&lt;strong&gt;Improved SOAP Assessment&lt;br /&gt;&lt;/strong&gt;WebInspect can now assess web sites that use SOAP Version 1.2 to transmit SOAP messages. SOAP Editor modifications have been made to collect SOAP message values for WSDL scans. Additionally, several known issues involving the SOAP Editor and SOAP assessments have been resolved to generally improve overall SOAP assessments. &lt;/div&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Improved Status Communication to AMP&lt;br /&gt;&lt;/strong&gt;The WebInspect sensor now sends regular status updates to AMP. The updates are displayed as &amp;quot;Scanning X of Y; Duration:00:00:00:0000; Errors:0&amp;quot; in the Devices &amp;agrave; Sensors view on the AMP Console. &lt;/li&gt;&lt;li&gt;&lt;strong&gt;Improved False Positive Handling&lt;br /&gt;&lt;/strong&gt;In the Vulnerabilities tab, you can select a session or a vulnerability that you believe to be false positive and send an immediate notification to HP support. If a vulnerability is selected, a list of all URLs that are vulnerable appear in the Mark as False Positive window. You can select all URLs or individual URLs to mark as false positive. You can also type a comment to send to HP support along with your false positive notification.&amp;nbsp; I want to stress how cool this feature is because we have built a portal here at SPI/HP that we log into and can review this stuff. The reports you are sending us are being read by our SPI labs team to help guide the improvements and check changes they make on a daily basis. &lt;/li&gt;&lt;li&gt;&lt;strong&gt;Improved Support Channel Communication&lt;br /&gt;&lt;/strong&gt;After submitting a false positive notification to HP support, you will receive a pop-up message from SPI Monitor that includes a tracking number for the notification being sent. &lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;That&amp;#39;s it! We hope you enjoy it when it&amp;#39;s released, look for it on SmartUpdate on the usual download locations sometime next week.&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;img src="http://portal.spidynamics.com/aggbug.aspx?PostID=70009" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SpiProductNews?a=ebFi1Rbq"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpiProductNews?i=ebFi1Rbq" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/SpiProductNews?a=6wFsLz4c"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpiProductNews?i=6wFsLz4c" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpiProductNews/~4/165782208" height="1" width="1"/&gt;</content><author><name>Erik</name><uri>http://portal.spidynamics.com/members/Erik.aspx</uri></author><category term="WebInspect" scheme="http://portal.spidynamics.com/blogs/products/archive/tags/WebInspect/default.aspx" /><category term="new release" scheme="http://portal.spidynamics.com/blogs/products/archive/tags/new+release/default.aspx" /><category term="what's new" scheme="http://portal.spidynamics.com/blogs/products/archive/tags/what_2700_s+new/default.aspx" /><feedburner:origLink>http://portal.spidynamics.com/blogs/products/archive/2007/10/05/WebInspect-7.7-just-around-the-corner.aspx</feedburner:origLink></entry><entry><title>WebInspect Update planned this week</title><link rel="alternate" type="text/html" href="http://feeds.feedburner.com/~r/SpiProductNews/~3/143474392/WebInspect-Update-planned-this-week.aspx" /><id>http://portal.spidynamics.com/blogs/products/archive/2007/08/12/WebInspect-Update-planned-this-week.aspx</id><published>2007-08-12T23:55:00Z</published><updated>2007-08-12T23:55:00Z</updated><content type="html">&lt;p&gt;Quick update, there will be a minor update for all WebInspect users this week. Mainly lots of little fixes (like the broken SQL Injector start menu link, oops!) but one new feature: Deactivate License. &lt;/p&gt;&lt;p&gt;Ever since we introduced our new licensing system we have made it way too hard to move your copy of WebInspect from one machine to another requiring you to call our support guys if you wanted to move the license. The new deactivate license feature (found under application settings-&amp;gt;license) allows you to deactivate your install (returning WebInspect to a unlicensed state) which then frees up your license to be used again wherever you want. Just use the same activation token you received from us when you bought WebInspect to reactivate your new installation.&lt;/p&gt;&lt;p&gt;For those of you who move your copy of WebInspect around a lot, this should be really handy. Just remember to deactivate before you re-image that machine and you can re-use the activation token again later.&lt;/p&gt;&lt;p&gt;If you have any questions, please post them here and I&amp;#39;ll be quick to answer, thanks!&lt;/p&gt;&lt;img src="http://portal.spidynamics.com/aggbug.aspx?PostID=68475" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SpiProductNews?a=uOlL0gpH"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpiProductNews?i=uOlL0gpH" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/SpiProductNews?a=nISnrNSh"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpiProductNews?i=nISnrNSh" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpiProductNews/~4/143474392" height="1" width="1"/&gt;</content><author><name>Erik</name><uri>http://portal.spidynamics.com/members/Erik.aspx</uri></author><category term="WebInspect" scheme="http://portal.spidynamics.com/blogs/products/archive/tags/WebInspect/default.aspx" /><category term="deactivate" scheme="http://portal.spidynamics.com/blogs/products/archive/tags/deactivate/default.aspx" /><category term="License" scheme="http://portal.spidynamics.com/blogs/products/archive/tags/License/default.aspx" /><feedburner:origLink>http://portal.spidynamics.com/blogs/products/archive/2007/08/12/WebInspect-Update-planned-this-week.aspx</feedburner:origLink></entry><entry><title>QAInspect 4.0.1 for HP Quality Center is now available!</title><link rel="alternate" type="text/html" href="http://feeds.feedburner.com/~r/SpiProductNews/~3/141229716/QAInspect-4.01-for-HP-Quality-Center-is-now-available_2100_.aspx" /><id>http://portal.spidynamics.com/blogs/products/archive/2007/08/06/QAInspect-4.01-for-HP-Quality-Center-is-now-available_2100_.aspx</id><published>2007-08-06T14:27:00Z</published><updated>2007-08-06T14:27:00Z</updated><content type="html">&lt;p&gt;Hot on the heels of WebInspect 7.5 is HP QAInspect 4.0.1 for HP Quality Center (say that 5 times fast!)&lt;/p&gt;&lt;p&gt;New features include:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;div class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;font face="Calibri" size="3"&gt;Quality Center 9.2 support&lt;/font&gt;&lt;/div&gt;&lt;/li&gt;&lt;li&gt;&lt;div class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;font face="Calibri" size="3"&gt;Crawl-Only feature&lt;/font&gt;&lt;/div&gt;&lt;/li&gt;&lt;li&gt;&lt;div class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;font face="Calibri" size="3"&gt;Windows Authentication for AMP&lt;/font&gt;&lt;/div&gt;&lt;/li&gt;&lt;li&gt;&lt;div class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;font face="Calibri" size="3"&gt;Ability to update license through a proxy&lt;/font&gt;&lt;/div&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Contact your support represenatitive or our sales team today for more information. If you are an existing customer run SmartUpdate now to get the latest updates.&lt;/p&gt;&lt;img src="http://portal.spidynamics.com/aggbug.aspx?PostID=68327" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SpiProductNews?a=KfYXcvB4"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpiProductNews?i=KfYXcvB4" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/SpiProductNews?a=wo32WNda"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpiProductNews?i=wo32WNda" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpiProductNews/~4/141229716" height="1" width="1"/&gt;</content><author><name>Erik</name><uri>http://portal.spidynamics.com/members/Erik.aspx</uri></author><category term="QAInspect" scheme="http://portal.spidynamics.com/blogs/products/archive/tags/QAInspect/default.aspx" /><category term="release" scheme="http://portal.spidynamics.com/blogs/products/archive/tags/release/default.aspx" /><category term="hp" scheme="http://portal.spidynamics.com/blogs/products/archive/tags/hp/default.aspx" /><feedburner:origLink>http://portal.spidynamics.com/blogs/products/archive/2007/08/06/QAInspect-4.01-for-HP-Quality-Center-is-now-available_2100_.aspx</feedburner:origLink></entry><entry><title>WebInspect 7.5 now available!</title><link rel="alternate" type="text/html" href="http://feeds.feedburner.com/~r/SpiProductNews/~3/137620148/WebInspect-7.5-now-available_2100_.aspx" /><id>http://portal.spidynamics.com/blogs/products/archive/2007/07/26/WebInspect-7.5-now-available_2100_.aspx</id><published>2007-07-26T13:55:00Z</published><updated>2007-07-26T13:55:00Z</updated><content type="html">&lt;p&gt;Download now from &lt;a href="https://download.spidynamics.com/products/WebInspect/"&gt;https://download.spidynamics.com/products/WebInspect/&lt;/a&gt; or use SmartUpdate.&lt;/p&gt;&lt;p&gt;&lt;span class="style29"&gt;&lt;strong&gt;What&amp;#39;s New&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p class="ListItem"&gt;&lt;strong&gt;Pre-scan Profiler&lt;/strong&gt; &amp;ndash; WebInspect&amp;#39;s new pre-scan Profiler analyzes the application and offers suggestions for changes to the scan settings to optimize your assessment. The Profiler can evaluate and recommend settings for authentication, proxies, files not found, allowed hosts, and much more. &lt;br /&gt;The Profiler can be launched as a separate tool or configured in the Scan Wizard to automatically launch prior to the start of a scan. &lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p class="ListItem"&gt;&lt;strong&gt;Interactive Logout Notification&lt;/strong&gt; &amp;ndash; During an interactive mode scan, WebInspect notifies you when a logout has occurred, and displays a browser view of the page where the logout occurred, allowing you to login again. &lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p class="ListItem"&gt;&lt;strong&gt;Traffic Monitor&lt;/strong&gt; &amp;ndash; The Traffic Monitor allows you to view HTTP traffic in real time during a scan. The Traffic Monitor displays every request sent and response received by WebInspect in real time during the crawl and audit.&amp;nbsp; &lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p class="ListItem"&gt;&lt;strong&gt;Enterprise Assessment&lt;/strong&gt; &amp;ndash; Enterprise Assessment provides you with a comprehensive overview of your Web presence from an enterprise network perspective. URLs and IP addresses can be entered individually, or WebInspect can discover all available servers within a range of IP addresses and ports that you specify. &lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p class="ListItem"&gt;&lt;strong&gt;Right-click SQL Injector&lt;/strong&gt; &amp;ndash; You can now launch the SQL Injector tool by right-clicking on a vulnerable session and selecting SQL Injector from the Tools menu. &lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p class="ListItem"&gt;&lt;strong&gt;Regex in Allowed Hosts&lt;/strong&gt; &amp;ndash; You can now use Regex in the Allowed Hosts list, so that if a host matches a Regex pattern entered, it will be allowed for crawl and audit. &lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p class="ListItem"&gt;&lt;strong&gt;Launch Interactive Mode from Web Macro Recorder&lt;/strong&gt; &amp;ndash; You can now configure the Web Macro Recorder to launch Interactive Mode as part of a Macro. &lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p class="ListItem"&gt;&lt;strong&gt;Restore Factory Defaults to Application Settings&lt;/strong&gt; &amp;ndash; You can now restore Application Settings to their factory default settings. &lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p class="ListItem"&gt;&lt;strong&gt;Launch SPI Proxy from WebInspect Scan Wizard&lt;/strong&gt; &amp;ndash; You can now launch SPI Proxy from the Configure Network Proxy window in the Web Site Assessment wizard. &lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p class="ListItem"&gt;&lt;strong&gt;Windows Vista Support&lt;/strong&gt; - WebInspect 7.5 is now fully supported under windows Vista (Please note, support for 64 bit systems is still forthcoming)&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p class="SectionTitle"&gt;&lt;strong&gt;What&amp;#39;s Improved&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p class="ListItem"&gt;&lt;strong&gt;AJAX Auditing&lt;/strong&gt; &amp;ndash; AJAX Web applications can create several opportunities for possible attack if the application is not designed with security in mind. Since AJAX Web applications exist on both the client and the server, they include the following security issues:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p class="ListItem"&gt;Create a larger attack surface with many more inputs to secure&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p class="ListItem"&gt;Expose internal functions of the Web application server&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p class="ListItem"&gt;Allow a client-side script to access third-party resources with no built-in security mechanisms&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p class="ListItem"&gt;Improved AJAX auditing detects common AJAX frameworks that involve the following:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p class="ListItem"&gt;Function calls made in a client-side scripting language, such as JavaScript&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p class="ListItem"&gt;Use of the XMLHttpRequest objects to make data requests without having to reload the page&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p class="ListItem"&gt;Use of JavaScript Object Notation (JSON) format to transfer data between the server and client&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;&lt;p class="ListItem"&gt;&lt;strong&gt;Export Ability in Log Viewer&lt;/strong&gt; &amp;ndash; You can now export Audit, Crawl, Scanner, and StateRequestor logs from the Log Viewer tool. &lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p class="ListItem"&gt;&lt;strong&gt;Manage Scans Enhancement&lt;/strong&gt; &amp;ndash; You can now select and delete multiple scans in the Manage Scans window. &lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p class="ListItem"&gt;&lt;strong&gt;Export Scan Details Enhancement&lt;/strong&gt; &amp;ndash; The Export Scan Details window has been redesigned for improved usability. &lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;img src="http://portal.spidynamics.com/aggbug.aspx?PostID=67985" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SpiProductNews?a=kFAKPOk6"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpiProductNews?i=kFAKPOk6" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/SpiProductNews?a=QpwdSo9m"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpiProductNews?i=QpwdSo9m" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpiProductNews/~4/137620148" height="1" width="1"/&gt;</content><author><name>Erik</name><uri>http://portal.spidynamics.com/members/Erik.aspx</uri></author><category term="WebInspect" scheme="http://portal.spidynamics.com/blogs/products/archive/tags/WebInspect/default.aspx" /><category term="release" scheme="http://portal.spidynamics.com/blogs/products/archive/tags/release/default.aspx" /><feedburner:origLink>http://portal.spidynamics.com/blogs/products/archive/2007/07/26/WebInspect-7.5-now-available_2100_.aspx</feedburner:origLink></entry><entry><title>WebInspect 7.1 Now Available</title><link rel="alternate" type="text/html" href="http://feeds.feedburner.com/~r/SpiProductNews/~3/118793921/WebInspect-7.1-Now-Available.aspx" /><id>http://portal.spidynamics.com/blogs/products/archive/2007/05/22/WebInspect-7.1-Now-Available.aspx</id><published>2007-05-22T19:21:00Z</published><updated>2007-05-22T19:21:00Z</updated><content type="html">&lt;div align="center"&gt;&lt;table cellpadding="0" cellspacing="0" class="MsoNormalTable" style="width:487.5pt;"&gt;&lt;tr&gt;&lt;td style="width:609px;background-color:transparent;border:#e2e2e2;padding:0in;"&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="style1" style="background:#e5e4e0;width:609px;border:#e2e2e2;padding:0in;"&gt;&lt;table cellpadding="0" cellspacing="0" class="MsoNormalTable" style="width:255pt;"&gt;&lt;tr&gt;&lt;td style="width:336px;background-color:transparent;border:#ffffff;padding:5.25pt;"&gt;&lt;p class="style2"&gt;&lt;span class="style5"&gt;&lt;span style="font-size:18pt;font-family:'Arial','sans-serif';"&gt;Now Available&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:18pt;font-family:'Arial','sans-serif';"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:'Arial','sans-serif';"&gt;&lt;img border="0" height="65" id="_x0000_i1026" src="http://content3.rm04.net/ra/2007/05/22/869066/CONT_32.jpg" width="250" /&gt;&lt;br /&gt;&lt;/span&gt;&lt;strong&gt;&lt;span style="font-size:10pt;font-family:'Arial','sans-serif';"&gt;The Next Generation of Web Application Scanning&lt;/span&gt;&lt;/strong&gt;&lt;font size="3"&gt;&lt;span style="font-family:'Arial','sans-serif';"&gt; &lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height:56.25pt;"&gt;&lt;td style="width:609px;height:56.25pt;background-color:transparent;border:#e2e2e2;padding:0in;"&gt;&lt;table cellpadding="0" cellspacing="0" class="style3" style="width:487.5pt;"&gt;&lt;tr&gt;&lt;td class="style1" rowspan="2" style="width:242pt;background-color:transparent;border:#e2e2e2;padding:5.25pt;"&gt;&lt;p&gt;&lt;font size="3"&gt;&lt;strong&gt;&lt;span style="font-family:'Arial','sans-serif';"&gt;WebInspect 7.1 features Server Analyzer, a new advanced tool for pen-testers:&lt;/span&gt;&lt;/strong&gt;&lt;span style="font-family:'Arial','sans-serif';"&gt; &lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-size:10pt;font-family:'Arial','sans-serif';"&gt;Server Analyzer is a web server identification and discovery tool designed to quickly identify and understand the nature of&amp;nbsp; a web server or web-enabled device.&lt;/span&gt;&lt;font size="3"&gt;&lt;span style="font-family:'Arial','sans-serif';"&gt;&amp;nbsp; &lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;ul&gt;&lt;li class="MsoNormal" style="margin:0in 0in 0pt;tab-stops:list .5in;"&gt;&lt;span style="font-size:10pt;font-family:'Arial','sans-serif';"&gt;Identifies popular web server software, web application software, embedded/web-enabled devices, and supporting network architecture components such as proxies and load balancers.&amp;nbsp; &lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin:0in 0in 0pt;tab-stops:list .5in;"&gt;&lt;span style="font-size:10pt;font-family:'Arial','sans-serif';"&gt;Uses a special characteristic-based identification technology that is capable of deducing the server software type despite attempts to hide the server software&amp;#39;s true identity. &lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin:0in 0in 0pt;tab-stops:list .5in;"&gt;&lt;span style="font-size:10pt;font-family:'Arial','sans-serif';"&gt;Improves server identification accuracy reduces false-positive identifications due to configuration obfuscation. &lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin:0in 0in 0pt;tab-stops:list .5in;"&gt;&lt;span style="font-size:10pt;font-family:'Arial','sans-serif';"&gt;Performs deep SSL SSL analysis on HTTPS sites, showing various information related to the server&amp;#39;s SSL configuration.&lt;/span&gt;&lt;font size="3"&gt;&lt;span style="font-family:'Arial','sans-serif';"&gt; &lt;/span&gt;&lt;/font&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/td&gt;&lt;td style="background-color:transparent;border:#e2e2e2;padding:5.25pt;"&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;a name="httpwww.spidynamics.comassetsdocumentsWe" title="httpwww.spidynamics.comassetsdocumentsWe"&gt;&lt;/a&gt;&lt;a href="http://www.spidynamics.com/assets/documents/WebInspect_DataSheets.pdf"&gt;&lt;span style="font-family:'Arial','sans-serif';text-decoration:none;text-underline:none;"&gt;&lt;font size="3"&gt;&lt;img border="0" height="108" id="_x0000_i1028" src="http://content3.rm04.net/ra/2007/05/22/869066/CONT_34.jpg" style="float:left;" width="144" /&gt;&lt;/font&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="background-color:transparent;border:#e2e2e2;padding:5.25pt;"&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;a name="Free_15-day_Trial" title="Free_15-day_Trial"&gt;&lt;/a&gt;&lt;a href="https://download.spidynamics.com/1/ad/fwi.asp?Campaign_ID=70160000000Cq9A"&gt;&lt;span style="font-family:'Arial','sans-serif';text-decoration:none;text-underline:none;"&gt;&lt;font size="3"&gt;&lt;img border="0" height="108" id="_x0000_i1029" src="http://content3.rm04.net/ra/2007/05/22/869066/CONT_35.jpg" style="float:left;" width="144" /&gt;&lt;/font&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="width:609px;background-color:transparent;border:#e2e2e2;padding:0in;"&gt;&lt;table cellpadding="0" cellspacing="0" class="MsoNormalTable" style="width:487.5pt;"&gt;&lt;tr style="height:140.25pt;"&gt;&lt;td class="style1" style="width:331px;height:140.25pt;background-color:transparent;border:#e2e2e2;padding:5.25pt;"&gt;&lt;p&gt;&lt;span style="font-size:10pt;font-family:'Arial','sans-serif';"&gt;The following additional WebInspect 7.1 enhancements were designed to further simplify and speed up the installation and assessment processes. &lt;/span&gt;&lt;/p&gt;&lt;ul&gt;&lt;li class="MsoNormal" style="margin:0in 0in 0pt;tab-stops:list .5in;"&gt;&lt;span style="font-size:10pt;font-family:'Arial','sans-serif';"&gt;New simple scan enabling users to conduct a comprehensive scan by entering only the URL, user name and password. &lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin:0in 0in 0pt;tab-stops:list .5in;"&gt;&lt;span style="font-size:10pt;font-family:'Arial','sans-serif';"&gt;Faster scans through redundant page detection. &lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin:0in 0in 0pt;tab-stops:list .5in;"&gt;&lt;span style="font-size:10pt;font-family:'Arial','sans-serif';"&gt;Simplified installation process by removing the dependency on SQL Server Express. &lt;/span&gt;&lt;/li&gt;&lt;li class="MsoNormal" style="margin:0in 0in 0pt;tab-stops:list .5in;"&gt;&lt;span style="font-size:10pt;font-family:'Arial','sans-serif';"&gt;Enhanced Quality Center integration.&amp;nbsp; Send defects directly to QC from WebInspect&amp;#39;s site tree or vulnerability pane.&lt;/span&gt;&lt;font size="3"&gt;&lt;span style="font-family:'Arial','sans-serif';"&gt; &lt;/span&gt;&lt;/font&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="width:609px;background-color:transparent;border:#e2e2e2;padding:0in;"&gt;&lt;p class="style4"&gt;&lt;strong&gt;Already a Customer?&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="width:609px;background-color:transparent;border:#e2e2e2;padding:0in;"&gt;&lt;table cellpadding="0" cellspacing="0" class="MsoNormalTable" style="width:487.5pt;"&gt;&lt;tr&gt;&lt;td class="style1" style="width:224pt;background-color:transparent;border:#e2e2e2;padding:3.75pt;"&gt;&lt;p&gt;&lt;span style="font-size:10pt;font-family:'Arial','sans-serif';"&gt;If you are already a WebInspect 7.0 customer and need to upgrade, please run WebInspect and click on the SmartUpdate icon at the bottom of your screen. &lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-size:10pt;font-family:'Arial','sans-serif';"&gt;If you would like to download the installer, please click &lt;/span&gt;&lt;a name="httpsdownload.spidynamics.comproductsweb" title="httpsdownload.spidynamics.comproductsweb"&gt;&lt;/a&gt;&lt;a href="https://download.spidynamics.com/products/webinspect/"&gt;&lt;span style="font-size:10pt;font-family:'Arial','sans-serif';"&gt;here&lt;/span&gt;&lt;/a&gt;&lt;font size="3"&gt;&lt;span style="font-family:'Arial','sans-serif';"&gt;. &lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;/td&gt;&lt;td style="width:212pt;background-color:transparent;border:#e2e2e2;padding:3.75pt;"&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;font size="3"&gt;&lt;span style="font-family:'Arial','sans-serif';"&gt;&lt;img border="0" height="108" id="_x0000_i1031" src="http://content3.rm04.net/ra/2007/05/22/869066/CONT_37.jpg" style="float:left;" width="144" /&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="width:609px;height:102px;background-color:transparent;border:#e2e2e2;padding:0in;"&gt;&lt;p class="style2"&gt;&lt;span style="font-family:'Arial','sans-serif';"&gt;&lt;font size="3"&gt;&lt;img border="0" height="28" id="_x0000_i1032" src="http://content3.rm04.net/ra/2007/05/22/869066/CONT_38.jpg" width="100" /&gt;&lt;br /&gt;&lt;/font&gt;&lt;/span&gt;&lt;span style="font-size:10pt;font-family:'Arial','sans-serif';"&gt;Join the SPI Community &lt;br /&gt;&lt;/span&gt;&lt;a name="httpportal.spidynamics.comblogsdefault.a" title="httpportal.spidynamics.comblogsdefault.a"&gt;&lt;/a&gt;&lt;a href="http://portal.spidynamics.com/blogs/default.aspx"&gt;&lt;span style="font-size:10pt;font-family:'Arial','sans-serif';"&gt;Blogs&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:10pt;font-family:'Arial','sans-serif';"&gt;, &lt;/span&gt;&lt;a name="httpportal.spidynamics.comforumsdefault." title="httpportal.spidynamics.comforumsdefault."&gt;&lt;/a&gt;&lt;a href="http://portal.spidynamics.com/forums/default.aspx"&gt;&lt;span style="font-size:10pt;font-family:'Arial','sans-serif';"&gt;Forums&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:10pt;font-family:'Arial','sans-serif';"&gt;, &lt;/span&gt;&lt;a name="httpportal.spidynamics.comfilesdefault.a" title="httpportal.spidynamics.comfilesdefault.a"&gt;&lt;/a&gt;&lt;a href="http://portal.spidynamics.com/files/default.aspx"&gt;&lt;span style="font-size:10pt;font-family:'Arial','sans-serif';"&gt;Downloads&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:10pt;font-family:'Arial','sans-serif';"&gt; and &lt;/span&gt;&lt;a name="httpportal.spidynamics.com(3)" title="httpportal.spidynamics.com(3)"&gt;&lt;/a&gt;&lt;a href="http://portal.spidynamics.com/"&gt;&lt;span style="font-size:10pt;font-family:'Arial','sans-serif';"&gt;more&lt;/span&gt;&lt;/a&gt;&lt;font face="Times New Roman" size="3"&gt;&amp;nbsp;&lt;/font&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;/div&gt;&lt;img src="http://portal.spidynamics.com/aggbug.aspx?PostID=29809" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SpiProductNews?a=7Rm5adjm"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpiProductNews?i=7Rm5adjm" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/SpiProductNews?a=6r0TTLy0"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpiProductNews?i=6r0TTLy0" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpiProductNews/~4/118793921" height="1" width="1"/&gt;</content><author><name>Erik</name><uri>http://portal.spidynamics.com/members/Erik.aspx</uri></author><category term="WebInspect" scheme="http://portal.spidynamics.com/blogs/products/archive/tags/WebInspect/default.aspx" /><feedburner:origLink>http://portal.spidynamics.com/blogs/products/archive/2007/05/22/WebInspect-7.1-Now-Available.aspx</feedburner:origLink></entry><entry><title>DevInspect for Java SP1 (version 3.0.1.0) now available</title><link rel="alternate" type="text/html" href="http://feeds.feedburner.com/~r/SpiProductNews/~3/106377705/DevInspect-for-Java-SP1-_2800_version-3.0.1.0_2900_-now-available.aspx" /><id>http://portal.spidynamics.com/blogs/products/archive/2007/04/03/DevInspect-for-Java-SP1-_2800_version-3.0.1.0_2900_-now-available.aspx</id><published>2007-04-03T18:50:00Z</published><updated>2007-04-03T18:50:00Z</updated><content type="html">We released last Friday (3/30/07) a service pack to DevInspect for Java to fix some critical installation issues that were causing customers a lot of pains in their installation process when trying to evaluate the Java product. They were minor issues, but were popping up a lot, so we decided we needed to get them fixed as soon as possible to smooth the evaluation process. We also included a new and improved QuickStart guide with more detailed instructions on getting started. The getting started information is also available as an Eclipse &amp;ldquo;cheat sheet&amp;rdquo; within the software, so users will see a guided tutorial that helps them get licenses and scanning after installation.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;This version of the DevInspect for Java product is 3.0.1.0, but is functionally identical to the 3.0.0 version. The DevInspect 3.0.1.0 for Java version contains the following:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Fixed an issue with the DevInspect 3.0.0 installation package that in some instances failed to recognize that the required Windows Installer version was present on the installation target.&lt;/li&gt;&lt;li&gt;Fixed an issue with the DevInspect 3.0.0 installation package that failed to recognize that the .NET Framework 2.0 was present when .NET Framework 3.0 had been installed.&lt;/li&gt;&lt;li&gt;Enhancements to the QuickStart and User Guide documentation to help users get started with configuring and using DevInspect.&lt;/li&gt;&lt;li&gt;Introduction of an Eclipse &amp;ldquo;cheat sheet&amp;rdquo; that walks the user through the steps to get started with DevInspect. The cheat sheet will appear upon initial startup of the standalone version of DevInspect. In other versions, or after closing the cheat sheet, you can open it by opening Window&amp;hellip;Show View&amp;hellip;Other and selecting the Cheat Sheets view.&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;Since these items are in response to installation and ease-of-use issues, if a customer is up and running, they do not need to pick up this service pack. For those that need the service pack to address installer issues, it is distributed in two ways:&lt;br /&gt;&lt;br /&gt;A new installation program is available at: &lt;a href="https://download.spidynamics.com/products/DevInspect/Java/DevInspectJavaSetup.exe"&gt;https://download.spidynamics.com/products/DevInspect/Java/DevInspectJavaSetup.exe&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Existing users can update to this version through the Eclipse Update Manager. To check for DevInspect feature updates, or if you have received notification from SPI Dynamics that a new release is available, follow these steps. Go to Help&amp;hellip;Software Updates&amp;hellip;Manage Configuration. In the Product Configuration dialog, locate and select DevInspect for Java. In the right-hand pane, select Scan for Updates. If updates are found, follow the on-screen instructions to upgrade to the latest version of DevInspect.&lt;br /&gt;&lt;br /&gt;Finally, for those that just need the new and improved QuickStart information, you can get that document here: &lt;a href="https://download.spidynamics.com/products/DevInspect/Java/DevInspectJavaQuickStart.pdf"&gt;https://download.spidynamics.com/products/DevInspect/Java/DevInspectJavaQuickStart.pdf&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;img src="http://portal.spidynamics.com/aggbug.aspx?PostID=28113" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SpiProductNews?a=aWnFQI4y"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpiProductNews?i=aWnFQI4y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/SpiProductNews?a=JB2Zo16u"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpiProductNews?i=JB2Zo16u" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpiProductNews/~4/106377705" height="1" width="1"/&gt;</content><author><name>Erik</name><uri>http://portal.spidynamics.com/members/Erik.aspx</uri></author><category term="DevInspect" scheme="http://portal.spidynamics.com/blogs/products/archive/tags/DevInspect/default.aspx" /><category term="Service Pack" scheme="http://portal.spidynamics.com/blogs/products/archive/tags/Service+Pack/default.aspx" /><category term="Java" scheme="http://portal.spidynamics.com/blogs/products/archive/tags/Java/default.aspx" /><category term="Update" scheme="http://portal.spidynamics.com/blogs/products/archive/tags/Update/default.aspx" /><feedburner:origLink>http://portal.spidynamics.com/blogs/products/archive/2007/04/03/DevInspect-for-Java-SP1-_2800_version-3.0.1.0_2900_-now-available.aspx</feedburner:origLink></entry><entry><title>WebInspect Update now Available</title><link rel="alternate" type="text/html" href="http://feeds.feedburner.com/~r/SpiProductNews/~3/102438867/WebInspect-Update-now-Available.aspx" /><id>http://portal.spidynamics.com/blogs/products/archive/2007/03/17/WebInspect-Update-now-Available.aspx</id><published>2007-03-17T17:31:00Z</published><updated>2007-03-17T17:31:00Z</updated><content type="html">&lt;p&gt;Hot on the heels of our 7.0 release on Feb 14th, i&amp;#39;m happy to announce that our next WebInspect update release, version &lt;strong&gt;7.0.286.3&lt;/strong&gt;, is now available via SmartUpdate and download. This update delivers close to 250 issues and minor enhancements to the new WebInspect 7 platform. If you haven&amp;#39;t already downloaded it, please check it out now by hitting SmartUpdate.&lt;/p&gt;&lt;p&gt;We have also already started on the next update release as part of our new rapid release strategy, expect to see a steady stream of continuous updates throughout the year all made possible by our new Phoenix architecture. If you are looking for a new feature or have a particular annoyance you would love to see us address let us know by heading over to our &lt;a href="http://portal.spidynamics.com/forums/default.aspx?GroupID=14"&gt;WebInspect product forums&lt;/a&gt; and letting us know. For those of you who are customers and haven&amp;#39;t already done so, make sure you have activated your portal account for full customer access and to gain access to the product support forums as well by sending an e-mail to &lt;a href="mailto:portal@spidynamics.com"&gt;portal@spidynamics.com&lt;/a&gt;. &lt;br /&gt;&lt;/p&gt;&lt;img src="http://portal.spidynamics.com/aggbug.aspx?PostID=27685" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SpiProductNews?a=EgT5ECNA"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpiProductNews?i=EgT5ECNA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/SpiProductNews?a=pyAvxrPk"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpiProductNews?i=pyAvxrPk" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpiProductNews/~4/102438867"/&gt;</content><author><name>Erik</name><uri>http://portal.spidynamics.com/members/Erik.aspx</uri></author><category term="WebInspect" scheme="http://portal.spidynamics.com/blogs/products/archive/tags/WebInspect/default.aspx" /><category term="software update" scheme="http://portal.spidynamics.com/blogs/products/archive/tags/software+update/default.aspx" /><feedburner:origLink>http://portal.spidynamics.com/blogs/products/archive/2007/03/17/WebInspect-Update-now-Available.aspx</feedburner:origLink></entry><entry><title>Vote for SPI Products Today!</title><link rel="alternate" type="text/html" href="http://feeds.feedburner.com/~r/SpiProductNews/~3/101477654/Vote-for-SPI-Products-Today_2100_.aspx" /><id>http://portal.spidynamics.com/blogs/products/archive/2007/03/13/Vote-for-SPI-Products-Today_2100_.aspx</id><published>2007-03-13T19:26:00Z</published><updated>2007-03-13T19:26:00Z</updated><content type="html">
&lt;p&gt; SPI Dynamics&amp;rsquo; products and services have been nominated for several Info Security Products Guide Global Product Excellence Awards!&lt;br /&gt;We encourage you to vote for your favorite SPI Dynamics&amp;rsquo; product
and services today. Voting begins March 8th 00:01AM (PST) and ends
March 28th 11:59PM (PST).&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.infosecurityproductsguide.com/votingbooth/index.php"&gt;Vote now&lt;/a&gt; on the following SPI Dynamics products services&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt; Excellence in Application Security &amp;ndash; WebInspect&amp;trade; 7 &lt;/strong&gt;&lt;/li&gt;&lt;/ul&gt;
&lt;ul&gt;&lt;li&gt;&lt;strong&gt; Excellence in Auditing &amp;ndash; WebInspect&amp;trade; 7 &lt;/strong&gt;&lt;/li&gt;&lt;/ul&gt;
&lt;ul&gt;&lt;li&gt;&lt;strong&gt; Excellence in Security Audit - WebInspect&amp;trade; 7 &lt;/strong&gt;&lt;/li&gt;&lt;/ul&gt;
&lt;ul&gt;&lt;li&gt;&lt;strong&gt; Excellence in Vulnerability Assessment - WebInspect&amp;trade; 7 &lt;/strong&gt;&lt;/li&gt;&lt;/ul&gt;
&lt;ul&gt;&lt;li&gt;&lt;strong&gt; Excellence in Application Security Management &amp;ndash; Assessment Management Platform&amp;reg; (AMP) 2.5 &lt;/strong&gt;&lt;/li&gt;&lt;/ul&gt;
&lt;ul&gt;&lt;li&gt;&lt;strong&gt; Excellence in Large Enterprise Security Solution - Assessment Management Platform&amp;reg; (AMP) 2.5 &lt;/strong&gt;&lt;/li&gt;&lt;/ul&gt;
&lt;ul&gt;&lt;li&gt;&lt;strong&gt; Excellence in Security Testing &amp;ndash; QAInspect&amp;reg; 3.0 &lt;/strong&gt;&lt;/li&gt;&lt;/ul&gt;
&lt;ul&gt;&lt;li&gt;&lt;strong&gt; Excellence in Vulnerability Remediation - DevInspect&amp;reg; 3.0 &lt;/strong&gt;&lt;/li&gt;&lt;/ul&gt;
&lt;ul&gt;&lt;li&gt;&lt;strong&gt; Excellence in Managed Security Service &amp;ndash; WebInspect&amp;trade; Direct &lt;/strong&gt;&lt;/li&gt;&lt;/ul&gt;
&lt;ul&gt;&lt;li&gt;&lt;strong&gt; Excellence in Professional Security Training - Educational Services and Free Secure Software Workshops &lt;/strong&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;img src="http://portal.spidynamics.com/aggbug.aspx?PostID=27611" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SpiProductNews?a=gnswCntA"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpiProductNews?i=gnswCntA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/SpiProductNews?a=dr6aEGEE"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpiProductNews?i=dr6aEGEE" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpiProductNews/~4/101477654"/&gt;</content><author><name>Erik</name><uri>http://portal.spidynamics.com/members/Erik.aspx</uri></author><category term="WebInspect" scheme="http://portal.spidynamics.com/blogs/products/archive/tags/WebInspect/default.aspx" /><category term="AMP" scheme="http://portal.spidynamics.com/blogs/products/archive/tags/AMP/default.aspx" /><category term="DevInspect" scheme="http://portal.spidynamics.com/blogs/products/archive/tags/DevInspect/default.aspx" /><category term="QAInspect" scheme="http://portal.spidynamics.com/blogs/products/archive/tags/QAInspect/default.aspx" /><category term="awards" scheme="http://portal.spidynamics.com/blogs/products/archive/tags/awards/default.aspx" /><category term="Vote" scheme="http://portal.spidynamics.com/blogs/products/archive/tags/Vote/default.aspx" /><feedburner:origLink>http://portal.spidynamics.com/blogs/products/archive/2007/03/13/Vote-for-SPI-Products-Today_2100_.aspx</feedburner:origLink></entry><entry><title>Playing with FeedBurner (Administrivia)</title><link rel="alternate" type="text/html" href="http://feeds.feedburner.com/~r/SpiProductNews/~3/93553403/Playing-with-FeedBurner-_2800_Administrivia_2900_.aspx" /><id>http://portal.spidynamics.com/blogs/products/archive/2007/02/18/Playing-with-FeedBurner-_2800_Administrivia_2900_.aspx</id><published>2007-02-19T02:24:00Z</published><updated>2007-02-19T02:24:00Z</updated><content type="html">&lt;p&gt;I&amp;#39;m experimenting with Feedburner and considering using it for all the blogs on SPI Portal. I&amp;#39;ve moved the RSS and ATOM feeds for this blog over to FeedBurner to see how it all works out. If you have subscribed to this blog, now would be a good time to change the link to &lt;a class="popup" href="http://feeds.feedburner.com/SpiProductNews" target="_blank"&gt;http://feeds.feedburner.com/SpiProductNews&lt;/a&gt; &lt;/p&gt;&lt;p&gt;BTW, If you have had bad experience with FeedBurner, I&amp;#39;d like to know so feel free to drop me a comment or two before I move all of SPI Portal over ;)&lt;br /&gt;&lt;/p&gt;&lt;img src="http://portal.spidynamics.com/aggbug.aspx?PostID=2664" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SpiProductNews?a=9VUS56wl"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpiProductNews?i=9VUS56wl" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/SpiProductNews?a=OCflWJrr"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpiProductNews?i=OCflWJrr" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpiProductNews/~4/93553403"/&gt;</content><author><name>Erik</name><uri>http://portal.spidynamics.com/members/Erik.aspx</uri></author><category term="Administrivia" scheme="http://portal.spidynamics.com/blogs/products/archive/tags/Administrivia/default.aspx" /><feedburner:origLink>http://portal.spidynamics.com/blogs/products/archive/2007/02/18/Playing-with-FeedBurner-_2800_Administrivia_2900_.aspx</feedburner:origLink></entry><entry><title>WebInspect 7 is LIVE</title><link rel="alternate" type="text/html" href="http://feeds.feedburner.com/~r/SpiProductNews/~3/93553404/WebInspect-7-is-LIVE.aspx" /><id>http://portal.spidynamics.com/blogs/products/archive/2007/02/14/WebInspect-7-is-LIVE.aspx</id><published>2007-02-14T16:47:00Z</published><updated>2007-02-14T16:47:00Z</updated><content type="html">&lt;p&gt;It is with awesome excitement that I announce that WebInspect 7 is now available for download. For those who want to beat the rush, please visit &lt;a href="https://download.spidynamics.com/products/webinspect/"&gt;https://download.spidynamics.com/products/webinspect/&lt;/a&gt; for install and download instructions.&lt;/p&gt;&lt;p&gt;Please note, if you are an existing customer, you will require a new license key which you should receive later today around 2:00, I recommend you beat the download rush, start your downloads now and go to lunch, by the time you get back your license should be waiting for you.&lt;/p&gt;&lt;p&gt;If however 3:00 rolls around and you haven&amp;#39;t received it, check your SPAM filter and then call our support team, they will be happy to help.&lt;/p&gt;&lt;p&gt;I&amp;#39;d like to hear some of the first reactions to the new release, please let me know what your first impressions are by commenting here.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Enjoy!&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;-Erik&lt;br /&gt;&amp;nbsp;&lt;/p&gt;&lt;img src="http://portal.spidynamics.com/aggbug.aspx?PostID=2541" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SpiProductNews?a=lYYzbilT"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpiProductNews?i=lYYzbilT" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/SpiProductNews?a=1A46eykU"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpiProductNews?i=1A46eykU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpiProductNews/~4/93553404"/&gt;</content><author><name>Erik</name><uri>http://portal.spidynamics.com/members/Erik.aspx</uri></author><category term="WebInspect" scheme="http://portal.spidynamics.com/blogs/products/archive/tags/WebInspect/default.aspx" /><category term="7" scheme="http://portal.spidynamics.com/blogs/products/archive/tags/7/default.aspx" /><category term="WebInspect 7" scheme="http://portal.spidynamics.com/blogs/products/archive/tags/WebInspect+7/default.aspx" /><feedburner:origLink>http://portal.spidynamics.com/blogs/products/archive/2007/02/14/WebInspect-7-is-LIVE.aspx</feedburner:origLink></entry><entry><title>WebInspect 7</title><link rel="alternate" type="text/html" href="http://feeds.feedburner.com/~r/SpiProductNews/~3/93553405/WebInspect-7.aspx" /><id>http://portal.spidynamics.com/blogs/products/archive/2007/02/04/WebInspect-7.aspx</id><published>2007-02-04T22:00:00Z</published><updated>2007-02-04T22:00:00Z</updated><content type="html">
&lt;blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;&amp;nbsp;&lt;a href="http://www.rsaconference.com/images/banner_2007us.gif" target="_blank"&gt;&lt;img border="0" height="142" src="http://portal.spidynamics.com/photos/webinspect/images/2226/original.aspx" width="300" /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;/blockquote&gt;

&lt;p&gt;I&amp;#39;m heading out this week to make the yearly security pilgrimage to RSA where lots of SPI Dynamics folks will be presenting WebInspect 7, speaking and having fun. For many of you this will be your first chance to see the new &lt;span style="font-weight:bold;"&gt;WebInspect 7&lt;/span&gt; powered by our new Phoenix architecture up close. &lt;span style="font-weight:bold;"&gt;Stop by booth Booth #505&lt;/span&gt; where we will be giving out cool Phoenix T-Shirts and providing demos. I&amp;#39;ll certainly be in the booth as well helping out, answering your questions and listening for cool ideas for future releases.&lt;/p&gt;

&lt;p&gt;On Wed. night we also have big plans with our WebInspect 7 Launch party (&lt;a href="http://portal.spidynamics.com/blogs/spi_events/archive/2007/02/03/WebInspect-7-Casino-Night-Launch-Party-at-RSA.aspx" target="_blank"&gt;learn more and RSVP here&lt;/a&gt;) at the W hotel in San Francisco. I hope to see many of you all there.&lt;/p&gt;

&lt;p&gt;&lt;span style="font-weight:bold;"&gt;So what&amp;#39;s new in WebInspect 7 and what is Phoenix?&lt;br /&gt;
&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;WebInspect 7 is a total re-architecture of the product and represents about 3 years of work. It was a huge undertaking, but something we realized several years back had to be done. Why? If you look at the web application scanning market today you see a lot of products, most of which got their start around 1999 and pretty much everything since has followed the same pattern - 1) Crawl 2) Audit 3) Report. This process works great for the web of 1999 but what about today? Imagine trying to apply this same process to an assessment of a desktop application, it clearly doesn&amp;#39;t apply and with web applications looking a lot more like desktop applications these days, it doesn&amp;#39;t apply to the web very much either. We had to rethink the very foundations of our scanner and we gave this project a codename: Phoenix.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The Phoenix Architecture&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Phoenix is much more than a set of technologies for WebInspect, it&amp;#39;s going to be the foundation for all of our products. DevInspect, released in 2005 was the first product from SPI to be based on Phoenix and allowed us to deliver the first assessment product to perform both source code and balckbox testing simultaneously in a single product (what SPI calls Hybrid Analysis). But there was so much more we wanted to do, for starters we knew we needed a new way to analyze web applications and the old legacy 1) Crawl 2) Audit 3) Report process had to go. So with WebInspect 7 we introduce a first for our industry Simultaneous Crawl and Audit (SCA). SCA takes all of the old assumptions for testing web sites and turns them on their head. The moment a session is found we go to work and don&amp;#39;t wait around to do the audit work later. A session is what we call a request/response pair and as WebInspect assesses your web site it maps out the sessions across your site and points out vulnerabilities immediately (just don&amp;#39;t call sessions pages, web pages are soooooo 1999 and they can be much more than that). In addition to SCA we also built an entirely new state management engine that tracks the progress of your assessment and if WebInspect gets logged out or disconnected from the web site, it transparently takes care of pausing the scan and reconnecting when things get into trouble. Additionally if the scan encounters authentications schemes that can&amp;#39;t be automated like two factor or &lt;a href="http://en.wikipedia.org/wiki/Captcha" title="Completely Automated Public Turing test to tell Computers and Humans Apart" target="_blank"&gt;CAPTCHA&lt;/a&gt; it will pause the scan and ask for input.&lt;/p&gt;

&lt;p&gt;&lt;a href="http://portal.spidynamics.com/photos/technology/images/2231/original.aspx" title="Assessment Technology" target="_blank"&gt;&lt;img alt="Assessment Technology" border="0" src="http://portal.spidynamics.com/photos/technology/images/2231/original.aspx" title="Assessment Technology" /&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Immediate Results&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Because everything is running all out, all at once, results start to pour in fast the moment you fire up the assessment. If you fulfill your vulnerability quota in the first 5 minutes, go ahead a start a report. Notice I didn&amp;#39;t say stop the scan, that&amp;#39;s because you don&amp;#39;t need to stop the scan to run a report. What if you want to kick off an second scan using multiple user ID&amp;#39;s to check for privilege escalation vulnerabilities or scan a complete different site at the same time to get ahead on your work load? You can do all of that at the same time within WebInspect 7.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;New Features&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;I could most likely talk for days on every new feature, here are some of the highlights. Please drop a comment on this blog if you have questions or would like me to go into details on any of them:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Simultaneous Crawl and Audit (SCA) &lt;/strong&gt;- The crawl and audit happen together as part of one fluid process that provides immediate results within seconds of starting a scan&lt;/li&gt;

&lt;li&gt;&lt;strong&gt;Advanced Authentication Management &lt;/strong&gt;- Manage state dynamically, detect and prompt for two factor and CAPTCHA&lt;/li&gt;

&lt;li&gt;&lt;strong&gt;Simultaneous scanning &lt;/strong&gt;- Run more than one scan at the same time&lt;/li&gt;

&lt;li&gt;&lt;strong&gt;SQL Server storage&lt;/strong&gt; - All Scan data is stored in SQL server for high performance, high capacity scans&lt;/li&gt;

&lt;li&gt;&lt;strong&gt;Enhanced SPI Toolkit&lt;/strong&gt; - All the tools have received updates to improve their reach and capabilities&lt;/li&gt;

&lt;li&gt;&lt;strong&gt;SupportChannel&lt;/strong&gt; - Send questions, issues and enhancement reports direct to SPI from within the product&lt;/li&gt;

&lt;li&gt;&lt;strong&gt;Advanced Step Mode &lt;/strong&gt;- Run testing steps through WebInspect, recording everything and providing automated testing while you perform manual testing&lt;/li&gt;

&lt;li&gt;&lt;strong&gt;IPv6 Support -&lt;/strong&gt; Support future Internet architectures build on IPv6 networks&lt;/li&gt;

&lt;li&gt;&lt;strong&gt;Tabbed Interface&lt;/strong&gt; - Open multiple reports, scans and activities all within a simple, easy to navigate interface&amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Get Ready for the Upgrade&lt;br /&gt;
&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;WebInspect 7 will be made available to all current SPI Dynamics customers, but this time we will be doing a lot of things differently. On release you will get a notice via SmartUpdate asking you if you want to install the new version. The upgrade will not be required and you can keep on using 6.2 until you decide you want to upgrade but when you do decide the WebInspect 7 install will not replace WebInspect 6.2. You can run both side by side if you want, and both will continue to receive SmartUpdates! Before you choose to upgrade however you are going to want to follow the next few steps:&lt;br /&gt;
&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;First &lt;/strong&gt;make sure your system is ready, here are the new pre-requisites &lt;/p&gt;

&lt;p&gt;- .NET 2.0 Framework (you should NOT uninstall .NET 1.1 if you have any .NET 1.1 applications you want to keep running, like WebInspect 6.2!)&lt;br /&gt;
- Microsoft SQL Server Express SP1 or Microsoft SQL Server (feel free to run that 20 GB scan, if you have the disk space, we&amp;#39;ve got the time)&amp;nbsp;&lt;/p&gt;

&lt;p&gt;You can get both of these components &lt;a href="http://msdn.microsoft.com/vstudio/express/sql/download/" title=".NET 2.0 and SQL Server Express" target="_blank"&gt;here&lt;/a&gt; (http://msdn.microsoft.com/vstudio/express/sql/download/)&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Second&lt;/strong&gt; there are some things we couldn&amp;#39;t support anymore, if you are running &lt;a href="http://portal.spidynamics.com/blogs/products/archive/2006/05/23/Goodbye-Windows-2000.aspx" target="_blank"&gt;Windows 2000&lt;/a&gt;, have less than 512 MB of RAM or less than 1.5 GHz CPU, it&amp;#39;s time to upgrade.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;&lt;strong&gt;What to expect between now and release day&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;WebInspect 7 is truly a different product, so you will need to get a new license as well. SPI is going to be sending out new licenses to all existing companies in advance of release day. If for some reason you don&amp;#39;t receive your&amp;#39;s (perhaps we had the wrong e-mail or your SPAM filter blocked it) have no fear, just send your existing WebInspect license to support@spidynamics.com and request a new license, we will have you up and running in no time.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;When is release day?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;February 14th 2007, keep on eye on this blog for possible early release information!&lt;/p&gt;

&lt;p&gt;&amp;nbsp;&lt;a href="http://digg.com/submit?phase=2&amp;amp;url=portal.spidynamics.com%2fblogs%2fproducts%2farchive%2f2007%2f02%2f04%2fWebInspect-7.aspx&amp;amp;title=WebInspect+7&amp;amp;bodytext=WebInspect+7+is+a+fully+re-architected+version+of+our+industry+leading+web+application+security+assessment+product%2c+built+on+Phoenix.+WebInspect+7+is+the+first+and+only+solution+to+address+the+complexity+of+Web+2.0+and+identify+vulnerabilities+that+are+undetectable+by+traditional+scanners.&amp;amp;topic=security"&gt;&lt;img alt="Digg!" border="0" height="17" src="http://digg.com/img/badges/91x17-digg-button.gif" title="Digg!" width="91" /&gt;
&lt;/a&gt;&lt;/p&gt;&lt;img src="http://portal.spidynamics.com/aggbug.aspx?PostID=2230" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SpiProductNews?a=GMz9RYL9"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpiProductNews?i=GMz9RYL9" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/SpiProductNews?a=fYRBV6RT"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpiProductNews?i=fYRBV6RT" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpiProductNews/~4/93553405"/&gt;</content><author><name>Erik</name><uri>http://portal.spidynamics.com/members/Erik.aspx</uri></author><category term="WebInspect" scheme="http://portal.spidynamics.com/blogs/products/archive/tags/WebInspect/default.aspx" /><category term="7" scheme="http://portal.spidynamics.com/blogs/products/archive/tags/7/default.aspx" /><category term="rsa" scheme="http://portal.spidynamics.com/blogs/products/archive/tags/rsa/default.aspx" /><category term="launch" scheme="http://portal.spidynamics.com/blogs/products/archive/tags/launch/default.aspx" /><feedburner:origLink>http://portal.spidynamics.com/blogs/products/archive/2007/02/04/WebInspect-7.aspx</feedburner:origLink></entry><entry><title>WebInspect 6.2.155 (Service Pack) ready for download</title><link rel="alternate" type="text/html" href="http://feeds.feedburner.com/~r/SpiProductNews/~3/93553406/WebInspect-6.2.155-_2800_Service-Pack_2900_-ready-for-download.aspx" /><id>http://portal.spidynamics.com/blogs/products/archive/2006/11/27/WebInspect-6.2.155-_2800_Service-Pack_2900_-ready-for-download.aspx</id><published>2006-11-27T14:43:00Z</published><updated>2006-11-27T14:43:00Z</updated><content type="html">&lt;p&gt;Just in time for the holiday shopping season (who doesn&amp;#39;t want a copy of WebInspect in their stocking on December 25th?) it&amp;#39;s &lt;strong&gt;WebInspect 6.2.155&lt;/strong&gt;! This latest update adds additional capabilities to the SQL and
XSS Intelligent Engines and improves the stability and accuracy of the
product overall and is now available to those in the know for early download &lt;a href="http://portal.spidynamics.com/files/folders/webinspect/entry1056.aspx"&gt;here&lt;/a&gt; (Portal account required). All customers a recommended to upgrade as soon as
possible. We will be releasing this update via SmartUpdate tomorrow around 10:00 AM EDT if you prefer to get your updates pushed to you automatically. &lt;/p&gt;&lt;p&gt;If you have any questions or comments for SPI and the WebInspect team, sound off and let us know in the SPI Portal &lt;a href="http://portal.spidynamics.com/forums/default.aspx"&gt;Forums&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;&lt;img src="http://portal.spidynamics.com/aggbug.aspx?PostID=1048" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/SpiProductNews?a=DgIFvZ4L"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpiProductNews?i=DgIFvZ4L" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/SpiProductNews?a=pHHCTlt7"&gt;&lt;img src="http://feeds.feedburner.com/~f/SpiProductNews?i=pHHCTlt7" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/SpiProductNews/~4/93553406"/&gt;</content><author><name>Erik</name><uri>http://portal.spidynamics.com/members/Erik.aspx</uri></author><category term="WebInspect" scheme="http://portal.spidynamics.com/blogs/products/archive/tags/WebInspect/default.aspx" /><feedburner:origLink>http://portal.spidynamics.com/blogs/products/archive/2006/11/27/WebInspect-6.2.155-_2800_Service-Pack_2900_-ready-for-download.aspx</feedburner:origLink></entry></feed>
