IBM Support

How to record the traffic from an external browser in AppScan Standard

Technote (FAQ)


Question

How do you record the traffic (explored URLs) from an external browser such as Internet Explorer, FireFox, SoapUI, or Burp in IBM Security AppScan Standard?

Cause

When manually exploring your application with the AppScan browser, all HTTP/HTTPS traffic between the AppScan browser and your application is routed through the AppScan Standard instance, which records the traversed URLs.
This feature can be used to record in AppScan the URLs explored by any external browser that supports proxy, such as Internet Explorer, FireFox, SoapUI, Chrome, Safari, Opera, and more.


Answer

Notes:


Record the explored URLs in a configuration as follows:

  1. Verify that the external browser can access the site, and make sure the starting URL is correct in the scan (in Configuration > URL and Servers)
  2. Check the browser proxy settings and mimic them in AppScan, by setting Configuration > Communication and Proxy > Proxy to:
    • Don't use proxy - if the browser doesn't use any proxy
    • Use custom proxy settings - if the browser uses a proxy, and in that case also set Address and Port to the same as the external browser.
  3. Open AppScan Traffic Recorder
    Start the Traffic Recorder with Scan > Manual Explore > Using external device.


    The Traffic Recorder will look as follows. Note the port number (in red circle) of the AppScan proxy.

  4. Configure the external browser (IE, Chrome, FireFox,...) to use AppScan as its proxy:
    • In your browser, find the section for configuring a proxy server.
    • Change the address or hostname to the IP address used by the machine running AppScan (localhost is usually an acceptable entry), and change the port to the AppScan Traffic Recorder port.
    • You may need to restart the browser to apply the proxy settings.
  5. Explore your application with the external browser.
  6. When you have finished exploring, click OK in the External Traffic Recorder browser.

Note: Remember to restore the proxy setting in the external browser.


An example of configuring your IE browser to send HTTP traffic to the AppScan proxy:

  1. In AppScan Standard open Tools > Options > Scan Options.
    Assume that AppScan proxy port is set to 4744.
  2. In Internet Explorer open Tools > Internet Options > Connections > LAN Settings, and select the check box in the Proxy Server section.
    Enter: Address: localhost and Port: 4744
  3. Restart Internet Explore to apply the change.

Related information

A Japanese translation is available

Document information

More support for: IBM Security AppScan Standard
Scan: Configuration

Software version: 9.0, 9.0.0.1, 9.0.1, 9.0.1.1, 9.0.2, 9.0.2.1, 9.0.3, 9.0.3.1, 9.0.3.2, 9.0.3.3

Operating system(s): Windows

Reference #: 1287443

Modified date: 20 June 2017


Translate this page: