| Logo | Scanner | Version | Build | Vendor | |
| W3AF | 1.2 | 5309 | W3AF developers |
| Tested Against WAVSEP Version: |
| Accurate Version | License / Technology | Last Update | Activity | 1.2 (Beta)
Build 5309 | GPL2 Python 2.6.x | 01-07-2012 | 01-07-2012
Source Code |
| GUI | Config | Usage | Stability | Performance | Report | ScanLog | Pause | Session |
| Complex | Complex | Unstable | Fast |
Cookie | Header | A S I C | I G E S T | T L M | T L M v 2 | E R B E R O S | O R M | Detection | Logout | URL | Param | |||||
O U N T | Crawl | File | Crawler | Crawler | Crawler | Crawler | Crawler | Crawler | Crawler | Autofill | Autofill | CSRF Support | Support | Bypass | Bypass |
| 5 |
O U N T | E T | O S T | O O K I E | E A D E R | E C R E T | N a m e | M L | m l A T T | m l T A G | S O N | N e t E N C | M F | a v a S E R | N e t S E R | C F | C F - B i n | e b S o c k | W R | u s t o m |
| 5 |
O U N T | Q L i | S Q L i | S J S i | X S S | X S S | X S S | S O N h | F I | F I | M D E x e c | P L O A D | E D I R E C T | R L F i | D A P i | P A P H i | X i | S I | O R M A T i | O D E i | M L i | L i | U F F E R o | N T E G E R o | O D E D i s c | A C K U P f | A D D I N G | U T H b | R I V e | X E | E S S I O N | I X A T I O N | S R F | D o S |
| 23 |
| WebServer Hardening | CGI Scanning | Dir & File Enumeration | Passive Analysis | Additional Features |
| Fuzzing Features, Exploitation Features (Metasploit, Other), Partial Autofill Support (fuzzFormComboValues), Credential Enumeration. |
| Detection Accuracy | Chart | ||||
| 59.56% Detection Rate 30.00% False Positives | (81/136) (3/10) |
| Detection Accuracy | Chart | ||||
| 30.30% Detection Rate 42.86% False Positives | (20/66) (3/7) |
| Detection Accuracy | Chart | ||||
| 57.48% Detection Rate 12.50% False Positives | (469/816) (1/8) |
| Detection Accuracy | Chart | ||||
| 11.11% Detection Rate 16.67% False Positives | (12/108) (1/6) |
| WIVET Score | Chart | |||
| 17.00% Detection Rate |
| Eval, Clickjacking, WebDAV, XST, Frontpage Issues, htAccessMethod, Generic Injection, preg_replace (PHP), SSL Issues, phishingVector, generic flaws, Partial DOM-XSS detection, RegEx DoS, Technology specific vulnerabilities and a TON of discovery plugins, evasion, fingerprinting, brute-force, enumeration and analysis features. |
| Fuzzing Features, Exploitation Features (Metasploit, Other), Partial Autofill Support (fuzzFormComboValues), Credential Enumeration. |
| The current stable version of W3AF is very easy to install, and the automatic SVN updates are an excellent feature that will help both the users and the authors resolve problems quickly; that being said, I still had my share of problems when I updated my v1.0 stable version to the latest SVN version, and I have no one to blame but myself, for obsessively pressing the update button. As it always is with W3AF, the tester needs to learn how to configure it for each type of scan. and needs to learn how avoid being greedy? Simply put, avoid using plenty of plug-ins altogether (especially grep plug-ins). |