ScannerVersionVendor
safe3wvs (limited free edition)10.1Safe3 Network Center

Tested Against WAVSEP Version:
1.2

The SQL Injection Detection Accuracy of the Scanner:
Detection AccuracyChart
40.44% Detection Rate
30.00% False Positives
(55/136)
(3/10)
Response TypeInput VectorDetection RateDetails
Errorneous 500 ResponsesHTTP GET (Query String Parameters)20 out of 20Detected: 1(1st&2nd),2-19
Errorneous 500 ResponsesHTTP POST (Body Parameters)0 out of 20Missed: 1(1st&2nd)-19
Errorneous 200 ResponsesHTTP GET (Query String Parameters)20 out of 20Detected: 1(1st&2nd),2-19 200Error-Experimental-GET: 1
Errorneous 200 ResponsesHTTP POST (Body Parameters)0 out of 20Missed: 1(st&2nd)-19
Valid 200 ResponsesHTTP GET (Query String Parameters)15 out of 20Cases Detected: 1(1st&2nd)-3,5-7,9,10,12,14-17,19 Cases Missed: 4,8,11,13,18
Valid 200 ResponsesHTTP POST (Body Parameters)0 out of 20Cases Missed: 1(st&2nd)-19
Identical 200 ResponsesHTTP GET (Query String Parameters)0 out of 8Cases Missed: 1-8
Identical 200 ResponsesHTTP POST (Body Parameters)0 out of 8Cases Missed: 1-8
False Positive SQLi Test CasesHTTP GET (Query String Parameters)3 out of 102,6,7

The Reflected XSS Detection Accuracy of the Scanner:
Detection AccuracyChart
12.12% Detection Rate
42.86% False Positives
(8/66)
(3/7)
Response TypeInput VectorDetection RateDetails
Reflected XSSHTTP GET (Query String Parameters)8 out of 33Cases Detected: 1-5,30(1st&2nd),32 RXSS-Experimental-GET: 1 Cases Missed: 6-29,31
Reflected XSSHTTP POST (Body Parameters)0 out of 33Cases Missed: 1-32
False Positive RXSS Test CasesHTTP GET (Query String Parameters)3 out of 71,2,6

The Local File Inclusion Detection Accuracy of the Scanner:
Detection AccuracyChart
8.58% Detection Rate
12.50% False Positives
(70/816)
(1/8)
Response TypeInput VectorDetection RateDetails
Errorneous 500 ResponsesHTTP GET (Query String Parameters)35 out of 68Detected: 1-7,9-24,38,40,42,44,53-60
Errorneous 500 ResponsesHTTP POST (Body Parameters)0 out of 68null
Errorneous 200 ResponsesHTTP GET (Query String Parameters)35 out of 68Detected: 1-7,9-24,38,40,42,44,53-60
Errorneous 200 ResponsesHTTP POST (Body Parameters)0 out of 68null
Valid 200 ResponsesHTTP GET (Query String Parameters)0 out of 68null
Valid 200 ResponsesHTTP POST (Body Parameters)0 out of 68null
Identical 200 ResponsesHTTP GET (Query String Parameters)0 out of 68null
Identical 200 ResponsesHTTP POST (Body Parameters)0 out of 68null
Redirect (302) ResponsesHTTP GET (Query String Parameters)0 out of 68null
Redirect (302) ResponsesHTTP POST (Body Parameters)0 out of 68null
Erroneous 404 ResponsesHTTP GET (Query String Parameters)0 out of 68null
Erroneous 404 ResponsesHTTP POST (Body Parameters)0 out of 68null
False Positive Lfi Test CasesHTTP GET (Query String Parameters)1 out of 87

WAVSEP Scan Log:
I Checked the JS Resolve, POST resolve and URL Redirect features in
the scan settings, reduced the number of threads to 1, and extended
the scan timeout to 3000.
I then executed the tool against each individual directory, while
enabling the following plugins (each for his own relevant
directories): XSS, SQL Injection, File Hanldling, Others, alongside
all of the crawling plugins.
The WIVET scans failed regardless of what I configured in the cookie,
threads or other sections, regardless of logout URL (100.php)
exclusions, and regardless of the scanning method (GET,POST,Cookie).

The free version seemed to ignore POST parameters, even when the form
submission flag was activated and the scan target set to POST- a serios limitation (or bug?) to the free version - however, without it, the path traversal detection score would have been impressive.


Copyright © 2010-2016 by Shay Chen. All rights reserved.
Click here to learn how this information may be published or reused.