Top 13 of ’13: Qualys Community
Last updated on: September 6, 2020
It’s time for the Top 13 of '13 — the most popular and most viewed blog posts, discussions, new product features, technical documents and videos that were contributed, read, updated, and commented on in 2013 by the Qualys Community of security professionals.
Many thanks to all the Qualys Community members and site visitors for building out the reference library and active conversations that comprise Qualys Community!
Top 13 Blog Posts
- Automate the delivery of security intelligence for new assets
- Automate Host Discovery with Asset Tagging
- Announcing WAS 3.0 with Malware Detection and Burp Suite Integration
- Add Pen Testing to Web App Scanning for More Security
- RC4 in TLS is Broken: Now What?
- SSL Labs: Deploying Forward Secrecy
- Is BEAST Still a Threat?
- Configuring Apache, Nginx, and OpenSSL for Forward Secrecy
- Hacking into WordPress Using a Vulnerable Plug-in
- Defending against the BREACH Attack
- September 2013 – New IE 0-day – Update
- Updated SSL/TLS Deployment Best Practices Deprecate RC4
– this is my personal favorite, because the best practices guide is so clear. - Plus 8 blog posts from Qualys Security Conference 2013
See the most current blog posts.
Top 13 Discussion Threads
- VM: Generating report with both confirmed vulnerabilities & potential vulnerabilities
- VM: Disabling NULL sessions as a best practice
- VM: Populating Asset Lists from Excel
- VM: Authenticated scans vis-a-vis real vulnerabilities
- VM: Identify hosts in multiple scan asset groups
- PC: How to Identify Unwanted Applications (Policy Compliance)
- PC: Use of Remote Registry Service to scan Windows servers
- PCI: How to change the user authorized to run PCI scans in QualysGuard
- WAS: Adding Web Applications from a List
- WAS: Crawl Exclusion List
- API: Powershell module integrates QualysGuard w/ 3rd-party ticketing systems
- API: Give Users Access to Reports via API
- API: Proactively managing Qualys API call concurrency
Plus three extras from SSL Labs:
- SSL: Why is disabling TLS 1.2 being recommended
- SSL: How to enable Forward secrecy using Apache 2.2/OpenSSL 1.0.1 and Firefox 10 ESR?
- SSL: Adding ECDHE parameters to an SSL Certificate file
See the most current discussion threads.
New Product Features in 2013
- QualysGuard 7.12 Update: Multiple New Enhancements
- QualysGuard 7.12 New Features
- QualysGuard 7.11 Update: New Vulnerability Notification Feature
- QualysGuard 7.11 New Features
- QualysGuard 7.10 New Features
- QualysGuard 7.9 Release Notification: Available April 19, 2013
- QualysGuard 7.8: New Vulnerability Scorecards
- QualysGuard WAS 3.1 New Features
- Announcing WAS 3.0 with Malware Detection and Burp Suite Integration
- QualysGuard WAS 2.4.2: March 5, 2013
- QualysGuard WAS 2.4.1: January 31, 2013
- Add Pen Testing to Web App Scanning for More Security
- BrowserCheck Business Edition Adds "No Plugin" Download Option
- Qualys BrowserCheck Adds Automatic Daily Scanning and Improved MacOS Support
Top 13 Technical Documents and Developer Scripts
Technical Documents:
- QualysGuard WAS and OWASP TOP 10
- How to find rogue devices on your network
- How much does it cost to run a QualysGuard Virtual Scanner Appliance on Amazon EC2?
- Change the Name of Your Appliance
- Qualys scanner appliance hardware specification
- SAML Frequently Asked Questions (FAQ)
See LOTS MORE support articles and how-to’s in the Help Center.
Developer Scripts:
- python-qualysconnect: A Python QualysGuard(R) Helper Package updated with API v2 calls via BasicAuth
- QGIR: QualysGuard Integration with Reporting
- Qualys API client examples
- Script: Parse QualysGuard VM maps for live IPs not currently subscribed.
- Script: Excluding non-running kernel vulns when downloading data via API
- Automate multiple WAS scanning
- Exporting the Vulnerability KnowledgeBase to an external Database
See all developer content in the Developer Community.
QualysGuard Video Series
All video series are new or updated in 2013!
- Express Lite
- Questionnaire Service
- Vulnerability Management
- Policy Compliance
- Web Application Scanning
- Malware Detection Service
- Best Practice Videos
Plus a bonus video: DHS Director John Streufert Keynote from Qualys Security Conference 2013
Qualys wishes you a happy, productive, and secure 2014!