Scanner | Version | Vendor |
PowerFuzzer | 1.0 | Marcin Kozlowski |
Tested Against WAVSEP Version: |
Detection Accuracy | Chart | ||||
51.47% Detection Rate 40.00% False Positives | (70/136) (4/10) |
Response Type | Input Vector | Detection Rate | Details |
Errorneous 500 Responses | HTTP GET (Query String Parameters) | 20 out of 20 | Cases Detected: 1(1st&2nd)-19 |
Errorneous 500 Responses | HTTP POST (Body Parameters) | 20 out of 20 | Cases Detected: 1(1st&2nd)-19 |
Errorneous 200 Responses | HTTP GET (Query String Parameters) | 15 out of 20 | Cases Detected: 1(1st&2nd)-14 Cases Missed: 15-19 |
Errorneous 200 Responses | HTTP POST (Body Parameters) | 15 out of 20 | Cases Detected: 1(1st&2nd)-14 Cases Missed: 15-19 |
Valid 200 Responses | HTTP GET (Query String Parameters) | 0 out of 20 | Cases Missed: 1-19 |
Valid 200 Responses | HTTP POST (Body Parameters) | 0 out of 20 | Cases Missed: 1-19 |
Identical 200 Responses | HTTP GET (Query String Parameters) | 0 out of 8 | Cases Missed: 1-8 |
Identical 200 Responses | HTTP POST (Body Parameters) | 0 out of 8 | Cases Missed: 1-8 |
False Positive SQLi Test Cases | HTTP GET (Query String Parameters) | 4 out of 10 | 1,2,6,8 |
Detection Accuracy | Chart | ||||
24.24% Detection Rate 42.86% False Positives | (16/66) (3/7) |
Response Type | Input Vector | Detection Rate | Details |
Reflected XSS | HTTP GET (Query String Parameters) | 8 out of 33 | Cases Detected: 1-5,30(1st&2nd),32 Cases Missed: 6-29,31 |
Reflected XSS | HTTP POST (Body Parameters) | 8 out of 33 | Cases Detected: 1-5,30(1st&2nd),32 Cases Missed: 6-29,31 |
False Positive RXSS Test Cases | HTTP GET (Query String Parameters) | 3 out of 7 | 1,2,6 |
The tool didn?t manage to crawl the xss/false/sql index URLs, so I solved the problem by copying the content from each one of them into the index.jsp file, and executed the scan in front of the root directory:
http://192.168.46.2:8080/wavsep |