Scanner | Version | Vendor |
Scrawlr | 1.0 | HP Application Security Center |
Tested Against WAVSEP Version: |
Detection Accuracy | Chart | ||||
13.24% Detection Rate 0.00% False Positives | (18/136) (0/10) |
Response Type | Input Vector | Detection Rate | Details |
Errorneous 500 Responses | HTTP GET (Query String Parameters) | 9 out of 20 | Cases Detected: 1(1st&2nd),2,3,7,8,11-13 Cases Missed: 4-6,9,10,14-19 |
Errorneous 500 Responses | HTTP POST (Body Parameters) | 0 out of 20 | POST values are not covered by this tool |
Errorneous 200 Responses | HTTP GET (Query String Parameters) | 9 out of 20 | Cases Detected: 1(1st&2nd),2,3,7,8,11-13 Cases Missed: 4-6,9,10,14-19 |
Errorneous 200 Responses | HTTP POST (Body Parameters) | 0 out of 20 | POST values are not covered by this tool |
Valid 200 Responses | HTTP GET (Query String Parameters) | 0 out of 20 | Cases Missed: 1-19 |
Valid 200 Responses | HTTP POST (Body Parameters) | 0 out of 20 | POST values are not covered by this tool |
Identical 200 Responses | HTTP GET (Query String Parameters) | 0 out of 8 | Cases Missed: 1-8 |
Identical 200 Responses | HTTP POST (Body Parameters) | 0 out of 8 | POST values are not covered by this tool |
False Positive SQLi Test Cases | HTTP GET (Query String Parameters) | 0 out of 10 | None |
I executed the scanner in front of the following URLs:
http://192.168.1.100:8080/wavsep/index-sql.jsp http://192.168.1.100:8080/wavsep/index-false.jsp The scanner successfully crawled all URLs. |