Body
Overview
Before a University website can be published it must be scanned for vulnerabilities and other security issues. This document explains how you can use Pitt SecureWeb, the University’s solution to provision security scans for websites. Any web browser running Adobe Flash can use Pitt SecureWeb.
Please allow five (5) business days for scan results.
Note: Scan requests will not be processed during University holidays.
Detail
Getting Started
To get started Using Pitt SecureWeb:
- Create a new development website.
-
Fill out an online form to provision a site project in Pitt SecureWeb.
Note: A development (or staging) version and a production version of your site are always provisioned together as part of the creation process for a project.
You will receive email notification when your project has been provisioned and is ready to be scanned.
This provisioning process only needs to be carried out one time for a project. However, for each development (staging) and production website pair, you will need to carry out these steps again to create a new project. Returning users can access BurpSuite any time to view and audit scan results.
Request a Scan
Prerequisites:
- You must be owner of the site
- Ensure that you have all necessary information about the site readily available.
Resubmit Site for Additional Scanning
Once you have remediated any Critical- or High-level issues for your site you can resubmit the site for a new SecureWeb scan using the following instructions:
- From the Projects section, select a production or development (staging) site from the list on the left-hand side of the dashboard on the Projects tab.
- Click View Details.
- From the Issues tab, click Dynamic Scan Request.
- Select + Create from the drop-down menu.
- On the form that appears, verify the information populated from the previous scan:
- URL: The web address (URL) of the site that will be scanned.
- Username: This is the username for a test website user-level account, not the administrative login credentials.
- Password: and Re-type Password: This is the password for a test website user-level account, not the administrative login credentials. Enter this information in both fields.
- Click Submit.
Frequently Asked Questions
Q1: What if I can't see my department's sites?
A: Ensure that you have the appropriate read-only access permissions. If you would like to request access, create a Help Desk ticket and specify what site you'd like Read-only access to. This will then be sent to Security to review.
Q2: Can I generate reports from the scan results?
A: As a read-only user, you can view and export scan results but cannot generate custom reports. As a reminder, please treat Vulnerability Scan exports as highly sensitive data.
Q3: What vulnerabilities should I remediate?
A: Security requires all "High" and "Medium" issues/vulnerabilities be remediated.
Q4: Can I see scans from other departments?
A: No, read-only access is restricted to sites within your department only.
Q5: How often are scans performed on my department's sites?
A: The frequency of scans is determined by your department's security policy. Check with your system administrator for specific details regarding scan schedules.
Q6: What if I encounter issues accessing the scan results?
A: If you experience any issues accessing the scan results, ensure you have a stable internet connection and are using a compatible web browser. If the problem persists, contact your Pitt IT Help Desk for further assistance.
Q7: Can I filter scan results to see specific types of vulnerabilities?
A: Yes, you can use the filtering options within the scan results tab to narrow down specific types of vulnerabilities or issues.