Defining a CAS-based test
Vulnerability Assessments use the CAS mechanism to run-OS level tests on the database server, and identify vulnerabilities.
Before you begin
About this task
Procedure
- Open the Assessment Builder by clicking .
- From the User-defined tests, click CAS-based Tests to open the CAS-based Test Finder panel.
- Click New or Modify to create a new test.
- Enter a unique Test name.
- Select a database from the menu.
- Select a category from the menu.
- Select a category from the menu.
- Optional: Enter a Short Description for the test.
- Optional: Enter an External reference for the test.
- Enter a Result text for pass that will be displayed when the test passes.
- Enter a Result text for fail that will be displayed when the test fails.
- Enter a Recommendation text for pass that will be displayed when the test passes.
- Enter a Recommendation text for fail that will be displayed when the test fails. Recommendation text for fail - To prevent cross site hacking, any name from this list, used in the Recommendation text for fail text box, will be rewritten: expression; function; javascript; script; alert; eval; <img; ContentType
- Select a template to use from the menu.
- Select an operator to use from the menu.
- Enter a Search string that will be used with the operator to compare what is returned from the CAS template. This comparison that determines whether this test passes or fails. You may also click on the RE icon to define a regular expression for the search string.
- Optional: Check the Fail if match check box if the test should fail when a match is made with the search string.
- Click Apply to save the CAS-based test.