Audit Settings: Session Exclusions

To access this feature, click the Edit menu and select Default Scan Settings or Current Scan Settings. Then, in the Audit Settings category, select Session Exclusions.

All items specified in the Scan Settings - Session Exclusions are automatically replicated in the Session Exclusions for both the Crawl Settings and the Audit Settings. These items are listed in gray (not black) text. If you do not want these objects to be excluded from the audit, you must remove them from the Scan Settings - Session Exclusions panel.

This panel (Audit Settings - Session Exclusions) allows you to specify additional objects to be excluded from the audit. 

Excluded or Rejected File Extensions

If you select Reject, Fortify WebInspect will not request files having the specified extension.

If you select Exclude, Fortify WebInspect will request files having the specified extension, but will not audit them.

Adding a File Extension to Exclude/Reject

To add a file extension:

  1. Click Add.

    The Exclusion Extension window opens.

  2. In the File Extension box, enter a file extension.

  3. Select either Reject, Exclude, or both.

  4. Click OK.

Excluded MIME Types

Fortify WebInspect will not audit files associated with the MIME types you specify.

Adding a MIME Type to Exclude

To add a MIME type:

  1. Click Add.

    The Provide a Mime-type to Exclude window opens.

  2. In the Exclude Mime-type box, enter a MIME type.

  3. Click OK.

Other Exclusion/Rejection Criteria

You can identify various components of an HTTP message and then specify whether you want to exclude or reject a session that contains that component.

Editing the Default Criteria

To edit the default criteria:

  1. Select a criterion and click Edit (on the right side of the Other Exclusion/Rejection Criteria list).

    The Reject or Exclude a Host or URL window opens.

  2. Select either Host or URL.
  3. In the Host/URL box, enter a URL or fully qualified host name, or a regular expression designed to match the targeted URL or host.
  4. Select either Reject, Exclude, or both.
  5. Click OK.

Adding Exclusion/Rejection Criteria

To add exclusion/rejection criteria:

  1. Click Add (on the right side of the Other Exclusion/Rejection Criteria list).

    The Create Exclusion window opens.

  2. Select an item from the Target list.

  3. If you selected Query Parameter or Post Parameter as the target, enter the Target Name.

  4. From the Match Type list, select the method to be used for matching text in the target:

    • Matches Regex - Matches the regular expression you specify in the Match String box.

    • Matches Regex Extension - Matches a syntax available from Fortify's regular expression extensions you specify in the Match String box.

    • Matches - Matches the text string you specify in the Match String box.

    • Contains - Contains the text string you specify in the Match String box.

  5. In the Match String box, enter the string or regular expression for which the target will be searched. Alternatively, if you selected a regular expression option in the Match Type, you can click the drop-down arrow and select Create Regex to launch the Regular Expression Editor.

  6. Click  (or press Enter).

  7. (Optional) Repeat steps 2-6 to add more conditions. Multiple matches are ANDed.

  8. If you are working in Current Settings, you can click Test to process the exclusions on the current scan. Any sessions from that scan that would have been filtered by the criteria will appear in the test screen, allowing you to modify your settings if required.

  9. Click OK.

  10. When the exclusion appears in the Other Exclusion/Rejection Criteria list, select either Reject, Exclude, or both.

    Note: You cannot reject Response, Response Header, and Status Code Target types during a scan. You can only exclude these Target types.

See Also

Audit Settings: Attack Exclusions

Audit Settings: Attack Expressions

Audit Settings: Smart Scan

Audit Settings: Vulnerability Filtering