ScannerVersionVendor
Mini MySqlat0r0.5SCRT Information Security

Tested Against WAVSEP Version:
1.0

The SQL Injection Detection Accuracy of the Scanner:
Detection AccuracyChart
26.47% Detection Rate
0.00% False Positives
(36/136)
(0/10)
Response TypeInput VectorDetection RateDetails
Errorneous 500 ResponsesHTTP GET (Query String Parameters)9 out of 20Cases Detected: 6-8,11-13,16-18 Cases Missed: 1-5,9,10,14,15,19
Errorneous 500 ResponsesHTTP POST (Body Parameters)2 out of 20Cases Detected: 11,12 Cases Missed: 1-10,13-19
Errorneous 200 ResponsesHTTP GET (Query String Parameters)9 out of 20Cases Detected: 6-8,11-13,16-18 Cases Missed: 1-5,9,10,14,15,19
Errorneous 200 ResponsesHTTP POST (Body Parameters)2 out of 20Cases Detected: 11,12 Cases Missed: 1-10,13-19
Valid 200 ResponsesHTTP GET (Query String Parameters)9 out of 20Cases Detected: 6-8,11-13,16-18 Cases Missed: 1-5,9,10,14,15,19
Valid 200 ResponsesHTTP POST (Body Parameters)2 out of 20Cases Detected: 11,12 Cases Missed: 1-10,13-19
Identical 200 ResponsesHTTP GET (Query String Parameters)3 out of 8Cases Detected: 1-3 Cases Missed: 4-8
Identical 200 ResponsesHTTP POST (Body Parameters)0 out of 8Cases Missed: 1-8
False Positive SQLi Test CasesHTTP GET (Query String Parameters)0 out of 10None

WAVSEP Scan Log:
I attempted to start crawling the index-sql.jsp page, and found out that the tool was not able to crawl the application in this manner, so I copied the content of the files index-sql.jsp & index-false.jsp to index.jsp, and scanned the folder root URL:
http://192.168.46.2:8080/wavsep/
(The tool successfully crawled all the pages).
I then selected all the parameters in the ?SQL Injection Finder? tab, and initiated the scan.


Copyright © 2010-2016 by Shay Chen. All rights reserved.
Click here to learn how this information may be published or reused.