LogoScannerVersionVendor
Syhunt Mini (Sandcat Mini)4.4.3.0Syhunt

Tested Against WAVSEP Version:
1.5

The SQL Injection Detection Accuracy of the Scanner:
Detection AccuracyChart
100.00% Detection Rate
50.00% False Positives
(136/136)
(5/10)
Response TypeInput VectorDetection RateDetails
Errorneous 500 ResponsesHTTP GET (Query String Parameters)20 out of 20Detected: 1(1st&2nd),2-19
Errorneous 500 ResponsesHTTP POST (Body Parameters)20 out of 20Detected: 1(1st&2nd),2-19
Errorneous 200 ResponsesHTTP GET (Query String Parameters)20 out of 20Detected: 1(1st&2nd),2-19 Did not detect the experimental test cases (get/post).
Errorneous 200 ResponsesHTTP POST (Body Parameters)20 out of 20Detected: 1(1st&2nd),2-19 Did not detect the experimental test cases (get/post)
Valid 200 ResponsesHTTP GET (Query String Parameters)20 out of 20Detected: 1(1st&2nd),2-19
Valid 200 ResponsesHTTP POST (Body Parameters)20 out of 20Detected: 1(1st&2nd),2-19
Identical 200 ResponsesHTTP GET (Query String Parameters)8 out of 8Detected: 1-8
Identical 200 ResponsesHTTP POST (Body Parameters)8 out of 8Detected: 1-8
False Positive SQLi Test CasesHTTP GET (Query String Parameters)5 out of 102,4,6,7,8

The Reflected XSS Detection Accuracy of the Scanner:
Detection AccuracyChart
100.00% Detection Rate
0.00% False Positives
(66/66)
(0/7)
Response TypeInput VectorDetection RateDetails
Reflected XSSHTTP GET (Query String Parameters)33 out of 33Detected: 1-30(1st&2nd),31,32 RXSS-GET-Experimental: 1,3
Reflected XSSHTTP POST (Body Parameters)33 out of 33Detected: 1-30(1st&2nd),31,32
False Positive RXSS Test CasesHTTP GET (Query String Parameters)0 out of 7None

The Remote File Inclusion Detection Accuracy of the Scanner:
Detection AccuracyChart
44.44% Detection Rate
0.00% False Positives
(48/108)
(0/6)
Response TypeInput VectorDetection RateDetails
Errorneous 500 ResponsesHTTP GET (Query String Parameters)4 out of 9Detected: 1-4
Errorneous 500 ResponsesHTTP POST (Body Parameters)4 out of 9Detected: 1-4 (tested against forms with an action property - due to a bug in the form parsing mechanism)
Errorneous 200 ResponsesHTTP GET (Query String Parameters)4 out of 9Detected: 1-4
Errorneous 200 ResponsesHTTP POST (Body Parameters)4 out of 9Detected: 1-4 (tested against forms with an action property - due to a bug in the form parsing mechanism)
Valid 200 ResponsesHTTP GET (Query String Parameters)4 out of 9Detected: 1-4
Valid 200 ResponsesHTTP POST (Body Parameters)4 out of 9Detected: 1-4 (tested against forms with an action property - due to a bug in the form parsing mechanism)
Identical 200 ResponsesHTTP GET (Query String Parameters)4 out of 9Detected: 1-4
Identical 200 ResponsesHTTP POST (Body Parameters)4 out of 9Detected: 1-4 (tested against forms with an action property - due to a bug in the form parsing mechanism)
Redirect (302) ResponsesHTTP GET (Query String Parameters)4 out of 9Detected: 1-4
Redirect (302) ResponsesHTTP POST (Body Parameters)4 out of 9Detected: 1-4 (tested against forms with an action property - due to a bug in the form parsing mechanism)
Erroneous 404 ResponsesHTTP GET (Query String Parameters)4 out of 9Detected: 1-4
Erroneous 404 ResponsesHTTP POST (Body Parameters)4 out of 9Detected: 1-4 (tested against forms with an action property - due to a bug in the form parsing mechanism)
False Positive Rfi Test CasesHTTP GET (Query String Parameters)0 out of 6Nonw

WAVSEP Scan Log:
The scans were executed against each individual directory, using the following commands:

SandcatCS.exe localhost:8080 -nodos -hm:xss -surl:/wavsep/active/index-xss.jsp

SandcatCS.exe localhost:8080 -nodos -hm:sqlinj -surl:/wavsep/active/index-sql.jsp

SandcatCS.exe localhost:8080 -nodos -hm:faultinj -surl:/wavsep/active/index-sql.jsp

SandcatCS.exe localhost:8080 -nodos -hm:complete -surl:/wavsep/active/index-obsolete.jsp

SandcatCS.exe localhost:8080 -nodos -hm:complete -surl:/wavsep/active/Obsolete-Files/ObsoleteFile-FalsePositives-GET/index.jsp

Since I could not customize the policies (and isolate the lfi/rfi plugins), I could not effectively scan the LFI test cases (816+), due to time constrains and the affect the other plugins had on accuracy.

Due to various technical issues / potential bugs, I did not manage to scan WIVET using the product.


Copyright © 2010-2016 by Shay Chen. All rights reserved.
Click here to learn how this information may be published or reused.