The Complimentary Features of Web Application Scanners

The current information is based on the results of the *2011/2012/2014/2016* benchmarks (excpet for entries marked as updated or new )

Last updated: 18/09/2016
Sorted in a descending order according to the scanner's number of audit features.
Hint: hover over the marks and titles to get additional information on the various features.
Glossary
Unified List   Commercial Scanners   Free / Open Source Scanners


#
LogoVulnerability ScannerC
O
U
N
T
WebServer
Hardening
CGI
Scanning
Dir & File
Enumeration
Passive
Analysis
Additional
Features
1
IBM AppScan30The Session Id Analysis is implemented within Appscan Powertools, Null Byte, Parameter Tampering (eShopLifting, Debug Mode, Boolean Parameters), Range Restriction Bypass, HTML5 Attacks (HTML5 SQLi, Client Command Execution, Client Side Open Redirect), Flash Specific Attacks (XSF, XSS via Flash, Flash Permissions, Phishing via Flash), XML Specific Attacks (XXE - XML External Entity, SOAP Array Overflow), Account Lockout, Floating Point DoS, Code Injection (Perl, Partial PHP)
2
Acunetix WVS29CVE Specific Buffer Overflows, CVE Specific Privilege Escalation, Mass Assignment (Rails), Expression Language Injection (EL Injection), Http Parameter Pollution (HPP), Mongo DB & node.js SSJS Injection Support, SQLi & RXSS In URI, Fuzzer, Code Injection (PHP/ASP), Reverse Proxy Bypass, File Tampering, Server-Specific audit policies, a large number of CGI detection modules, Numerous general & tech-specific passive analysis features, Network scanning features, Detection of Stored XSS, SQLi, File Inclusion, Directory Traversal, Code Execution, File GTampering and PHP Code Execution (Most Stored Detection Features are Unique!).
3
WebInspect29Partial URL Input Vector Support (Cross Site Scripting), Partial LDAP Injection (Error/Query Detection) & Xpath Injection support, HTML Injection, Parameter Manipulations, Flash Attacks (XSS via Flash, Flash Analysis, Information Disclosure), Web Service Attacks, Numerous Product Specific Plugins, Java Double Parsing DoS, External Session Id Complexity Analysis via the Cookie Cruncher feature.
4
Tinfoil Security24Heartbleed, YAML Injection (RoR), Shellshock, WebDAV features, POODLE, HTTP PUT, Directory Listing, CVS/SVN Code Disclosure, Clickjacking, Various Passive Analysis Features. According to the vendor Session Fixation is only available to enterprise customers. ADoS refers to XML DoS variations being performed as a part of XXE.
5
Burp Suite Professional23Header Manipulation, Stored DOM Injection, Server Side Template Injection, Clickjacking, Dir/File enumeration via the discover content feature in the sitemap.
6
AppSpider19SSL Strength, Credential Brute Force / Dictionary Attacks (Form/Http), Business Logic Abuse Attacks, XST, Directory Indexing, Parameter Analysis, Basic flash/java analysis, Malicious frame/script analysis, Java Grinder, Reverse Proxy.
7
Netsparker Cloud18RFD (Rare!), Form/Basetag Hijacking, User/Pass Bruteforce, Insecure JSONP, Content Spoofing, Malicious File Upload, Remote Code Evaluation (ASP,PHP,Perl), RoR YAML Injection, HTTP and WebDAV Methods, SSL Checks, Heartbleed, HTTP.sys, HSTS Bypass, Admin Interfaces, Source Code Disclosure (PHP), Insecure CORS configuration.
8
Netsparker18RFD (Rare!), Form/Basetag Hijacking, User/Pass Bruteforce, Insecure JSONP, Content Spoofing, Malicious File Upload, Remote Code Evaluation (ASP,PHP,Perl), RoR YAML Injection, HTTP and WebDAV Methods, SSL Checks, Heartbleed, HTTP.sys, HSTS Bypass, Admin Interfaces, Source Code Disclosure (PHP), Insecure CORS configuration.
9
QualysGuard WAS16Flash XSS, Clickjacking, NullByte Poisoning, Generic Vulnerabilities, Numerous Passive Analysis, Hardening and vulnerable-CGI plugins, Network Scanning Features, password bruteforcing. Generic application plugins classified as either web application or web server plugins.
10
Syhunt Dynamic16NoSQL (SSJS) Injection, Parameter Tampering, Code Injection (PHP) and various other checks and features.
#
LogoVulnerability ScannerC
O
U
N
T
WebServer
Hardening
CGI
Scanning
Dir & File
Enumeration
Passive
Analysis
Additional
Features
11
JSky (Commercial Edition)13Captcha Cracker (Unique!).
12
N-Stalker10WebDAV (PUT), SSL Scanning, Insecure crossdomain.xml and clientaccesspolicy.xml policies, Insecure cookies, HPP, Clickjacking, Incorrect error handling, path disclosure, Remote Execution (Shellshock)
13
Ammonite9Limited PXSS Detection, Identifier Enumeration, Unpublished Content Discovery. Passive Detection Features: Cleartext CC#s in Responses, Hidden Form Fields in Responses, HTML Comments in Responses, HTTP/500 Errors in Responses, Verbose Errors in Responses.
14
ParosPro8Parameter Tampering, Potential File Path Manipulation (Covers some Traversal/LFI cases, without actual verification).
15
WebCruiser Enterprise Edition4Injection features support MSSQL, MySQL, Oracle, DB2 and MS Access..


Statistics
#
WebServer
Hardening
CGI
Scanning
DirAndFile
Enumeration
Passive
Analysis
Scanners:13131113



Glossary
AliasGeneral FeatureDescriptionReferences
Web Server HardeningInsecure Server ConfigurationInsecure Web Server / Application Server Configuration (Admin Interfaces, Permissions, Etc)1, 2, 3, 4
CGI ScanningInsecure CGI Modules DetectionDetect Well-Known Issues and Insecure/Obsolete/Default Components1, 2
Dir & File EnumerationDirectory & Files EnumerationDetect Well-Known / Hidden Files and Directories Using Spiders and Dictionary Attacks1, 2
Passive AnalysisPassive Analysis of Security IssuesDetect Security Issues Without any Active Tests (Caching, Autocomplete, Info Leakage, Etc)



Copyright © 2010-2015 by Shay Chen. All rights reserved.
Click here to learn how this information may be published or reused.