ScannerVersionVendor
WebCruiser Enterprise Edition2.7.0Janus Security

Tested Against WAVSEP Version:
1.5

The SQL Injection Detection Accuracy of the Scanner:
Detection AccuracyChart
69.85% Detection Rate
0.00% False Positives
(95/136)
(0/10)
Response TypeInput VectorDetection RateDetails
Errorneous 500 ResponsesHTTP GET (Query String Parameters)16 out of 20Detected (New): 1(2nd),2,3,5-13,15-18 Detected (2.5.1): 1(2nd),3,6-8,11-13,15-18 Missed: 1(1st),4,14,19
Errorneous 500 ResponsesHTTP POST (Body Parameters)14 out of 20Detected (New): 1(2nd),2,3,5-13,17-18 Detected (2.5.1): 1(2nd),3,7,8,11-13,17,18 Missed: 1(1st),4,14-16,19
Errorneous 200 ResponsesHTTP GET (Query String Parameters)16 out of 20Detected (New): 1(2nd),2,3,5-13,15-18 Detected (2.5.1): 1(2nd),3,6-8,11-13,15-18 Missed: 1(1st),4,14,19
Errorneous 200 ResponsesHTTP POST (Body Parameters)14 out of 20Detected (New): 1(2nd),2,3,5-13,17-18 Detected (2.5.1): 1(2nd),3,7,8,11-13,17,18 Missed: 1(1st),4,14-16,19
Valid 200 ResponsesHTTP GET (Query String Parameters)16 out of 20Detected (New): 1(2nd),2,3,5-13,15-18 Detected (2.5.1): 1(2nd),3,6-8,11-13,15-18 Missed: 1(1st),4,14,19
Valid 200 ResponsesHTTP POST (Body Parameters)16 out of 20Detected (New): 1(1st&2nd)-13,17-18 (1-4 detected as Xpath Injection) Missed: 14-16,19
Identical 200 ResponsesHTTP GET (Query String Parameters)2 out of 8Detected (New): 1,2 Detected (2.5.1): 1,2 Cases Missed: 3-8
Identical 200 ResponsesHTTP POST (Body Parameters)1 out of 8Cases Detected: 1 Cases Missed: 2-8
False Positive SQLi Test CasesHTTP GET (Query String Parameters)0 out of 10None (But Sometimes Confuses SQLi and other exposures with XPATHi)

The Reflected XSS Detection Accuracy of the Scanner:
Detection AccuracyChart
24.24% Detection Rate
42.86% False Positives
(16/66)
(3/7)
Response TypeInput VectorDetection RateDetails
Reflected XSSHTTP GET (Query String Parameters)8 out of 33Cases Detected: 1-5,30(1st&2nd),32 Cases Missed: 6-29,31 GET-Experimental: 3
Reflected XSSHTTP POST (Body Parameters)8 out of 33Cases Detected: 1-5,30(1st&2nd),32 Cases Missed: 6-29,31 POST-Experimental: 3
False Positive RXSS Test CasesHTTP GET (Query String Parameters)3 out of 71,2,6

WAVSEP Scan Log:
Each individual directory in WAVSEP was scanned separately, while enabling all the relevant available plug-ins for each scan (The SQL Injection and Xpath plugins for the SQLi directories, and XSS plugins for the XSS directories).


Copyright © 2010-2016 by Shay Chen. All rights reserved.
Click here to learn how this information may be published or reused.