The Complimentary Features of Web Application Scanners

The current information is based on the results of the *2011/2012/2014/2016* benchmarks (excpet for entries marked as updated or new )

Last updated: 18/09/2016
Sorted in a descending order according to the scanner's number of audit features.
Hint: hover over the marks and titles to get additional information on the various features.
Glossary
Unified List   Commercial Scanners   Free / Open Source Scanners


#
LogoVulnerability ScannerC
O
U
N
T
WebServer
Hardening
CGI
Scanning
Dir & File
Enumeration
Passive
Analysis
Additional
Features
1
W3AF23Eval, Clickjacking, WebDAV, XST, Frontpage Issues, htAccessMethod, Generic Injection, preg_replace (PHP), SSL Issues, phishingVector, generic flaws, Partial DOM-XSS detection, RegEx DoS, Technology specific vulnerabilities and a TON of discovery plugins, evasion, fingerprinting, brute-force, enumeration and analysis features.
2
arachni20WebDAV methods, Code Injection (PHP, Ruby, Python, JSP, ASP.Net), XSS in both path & URI, etc.
3
IronWASP17IronSAP (SAP testing), HAWAS (Hybrid), SSL Scanner, Exploitation (SSRF, CSRF), A partial list of passive features: Password in URL, Password sent in cleartext HTTP, Basic Authentication over Cleartext Communication, Cookie without http-only flag, Cookie without secure flag (in SSL), Cross-domain xml policy analysis, Server Version Disclosure, Various session & html issues, Autocomplete. Partial support for PXSS, DXSS and External Redirect (potential detection - without verification), SSRF.
4
ZAP17Forced Browsing (Options Menu), Username Enumeration, Parameter Tampering, AntiCSRF token scanner, HPP, Http Parameter Override. Session Fixation & Backup file enumeration available as extensions (https://code.google.com/p/zap-extensions/). Many passive analysis features from there Casaba Security Fiddler Extension - Watcher, Were implemented as well. CGI scanning features & fuzzing enabled through the integrated use of fuzz-db and JBroFuzz.
5
Syhunt Mini (Sandcat Mini)16Parameter Tampering, Code Injection (PHP) and various other checks and features.
6
SkipFish15XSSI , Client SQL Execution, Null Byte file disclosure, JSP Inclusion error check, Code Injection (PHP), Many Passive Analysis Features.
7
Wapiti15Htaccess bypass, Resource consumption, Potentially dangerous file detection.
8
Sandcat Free Edition13Code Injection (PHP)
9
Vega11Several Passive Analysis Modules.
10
Grendel Scan9Fuzzing
#
LogoVulnerability ScannerC
O
U
N
T
WebServer
Hardening
CGI
Scanning
Dir & File
Enumeration
Passive
Analysis
Additional
Features
11
WATOBO8Fuzzer, various SAP & JBoss tests (unique feature!), Source Code Disclosure (ASP Snippets, etc), Siebel Checks, .NET Checks for well-known files, Lotus domino DB enumeration, Unencrypted password transmissions, Session related issues, Web server hardening, Autocomplete (passive).
12
PowerFuzzer7Detect exceptions.
13
Andiparos7Parameter Tampering, XSS in path.
14
Oedipus6Simple fuzzing (error detection).
15
Uber Web Security Scanner6claims to fuzz for XML/SOAP injection, Code Injection (PHP, Perl), Detailed RFI. Supports detailed SQL Injection configuration.
16
JSky Free Edition6
17
Paros Proxy6Parameter Tampering
18
safe3wvs (limited free edition)5CGI Scanning is possible by checking the others plugin. The commercial version also supports the detection of admin applications, file upload vulnerabilities, directory listing and additional vulnerabilities.
19
Grabber5A few QA features.
20
WebSecurify (Opensource Version)5Partial list of passive analysis features: Full path disclosure, Error Disclosure, Email disclosure, Banner Disclosure, Session Cookie not flagged as HTTP Only, Autocomplete Enabled, WWW Authentication
#
LogoVulnerability ScannerC
O
U
N
T
WebServer
Hardening
CGI
Scanning
Dir & File
Enumeration
Passive
Analysis
Additional
Features
21
WebCruiser Free Edition4
22
Netsparker Community Edition4In the free edition, the blind SQL injection feature is limited to boolean (binary) SQL injection. The current version of Netsparker CE does not present obsolete files detected (listed but never verified in previous Netsparker CE versions). Various passive checks are also embedded, and include (among other features): Password Transmitted over Query String, Password Transmitted over HTTP, Autocomplete Enabled, Web Server Version Disclosure, Viewstate Not Encrypted, Email Address Disclosure, Internal Path Disclosure (Windows/Unix), Internal Server Errors, Cookie not HttpOnly, and more.
23
ProxyStrike4
24
iScan4GET/POST coverage. Port scanner. Many known vulnerabilities in web server default application.
25
Acunetix WVS Free Edition3It is unclear whether or not the free version actually performs persistent XSS tests.
26
Xcobra3
27
WebScarab3Fuzzing
28
WSTool2SQL injection is limited to MSSQL, CGI scanning is limited to administrative pages. Attempts to locate 5xx and 4xx errors.
29
Secubat2
30
Mini MySqlat0r2SQL Exploitation Framework.
#
LogoVulnerability ScannerC
O
U
N
T
WebServer
Hardening
CGI
Scanning
Dir & File
Enumeration
Passive
Analysis
Additional
Features
31
openAcunetix2
32
N-Stalker 2012 Free Edition2
33
Damn Small SQLi Scanner (DSSS)2
34
VulnDetector2
35
Priamos2SQL exploitation module.
36
SQLiX2
37
Gamja2Validation error detection.
38
sqlmap2Full support for MySQL, Oracle, PostgreSQL, Microsoft SQL Server, Microsoft Access, SQLite, Firebird, Sybase and SAP MaxDB.
39
XSSer2Plenty of different XSS flavors, waf bypass methods, stealth mode, etc.
40
XSSploit2Exploit code generation, XSRF generation.
#
LogoVulnerability ScannerC
O
U
N
T
WebServer
Hardening
CGI
Scanning
Dir & File
Enumeration
Passive
Analysis
Additional
Features
41
LoverBoy1
42
N-Stalker 2009 Free Edition1
43
SQID (SQL Injection Digger)1
44
Web Injection Scanner (WIS)1
45
aidSQL1
46
crawlfish1
47
Scrawlr1Scans ONLY GET parameters, 1500 Max Crawled URLs.
48
ScreamingCSS1
49
XSSS1


Statistics
#
WebServer
Hardening
CGI
Scanning
DirAndFile
Enumeration
Passive
Analysis
Scanners:18161019



Glossary
AliasGeneral FeatureDescriptionReferences
Web Server HardeningInsecure Server ConfigurationInsecure Web Server / Application Server Configuration (Admin Interfaces, Permissions, Etc)1, 2, 3, 4
CGI ScanningInsecure CGI Modules DetectionDetect Well-Known Issues and Insecure/Obsolete/Default Components1, 2
Dir & File EnumerationDirectory & Files EnumerationDetect Well-Known / Hidden Files and Directories Using Spiders and Dictionary Attacks1, 2
Passive AnalysisPassive Analysis of Security IssuesDetect Security Issues Without any Active Tests (Caching, Autocomplete, Info Leakage, Etc)



Copyright © 2010-2015 by Shay Chen. All rights reserved.
Click here to learn how this information may be published or reused.