Logo | Scanner | Version | Vendor | |
![]() | Netsparker Community Edition | 3.1.6.0 | Netsparker Ltd |
Tested Against WAVSEP Version: |
Accurate Version | License / Technology | Last Update | Activity | 3.1.6.0 (GA) | Freeware .Net 3.5 | 03-12-2013 |
GUI | Config | Usage | Stability | Performance | Report | ScanLog | Pause | Session |
![]() | Very Simple | Very Simple | Stable | Very Fast | ![]() | ![]() | ![]() | ![]() |
Cookie | Header | A S I C | I G E S T | T L M | T L M v 2 | E R B E R O S | O R M | Detection | Logout | URL | Param | |||||
![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() |
O U N T | Crawl | File | Crawler | Crawler | Crawler | Crawler | Crawler | Crawler | Crawler | Autofill | Autofill | CSRF Support | Support | Bypass | Bypass |
5 | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() |
O U N T | E T | O S T | O O K I E | E A D E R | E C R E T | N a m e | M L | m l A T T | m l T A G | S O N | N e t E N C | M F | a v a S E R | N e t S E R | C F | C F - B i n | e b S o c k | W R | u s t o m |
9 | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() |
O U N T | Q L i | S Q L i | S J S i | X S S | X S S | X S S | S O N h | F I | F I | M D E x e c | P L O A D | E D I R E C T | R L F i | D A P i | P A P H i | X i | S I | O R M A T i | O D E i | M L i | L i | U F F E R o | N T E G E R o | O D E D i s c | A C K U P f | A D D I N G | U T H b | R I V e | X E | E S S I O N | I X A T I O N | S R F | D o S |
4 | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() |
WebServer Hardening | CGI Scanning | Dir & File Enumeration | Passive Analysis | Additional Features |
![]() | ![]() | ![]() | ![]() |
Detection Accuracy | Chart | ||||
72.06% Detection Rate 30.00% False Positives | (98/136) (3/10) |
Detection Accuracy | Chart | ||||
78.79% Detection Rate 0.00% False Positives | (52/66) (0/7) |
WIVET Score | Chart | |||
91.00% Detection Rate |
In the free edition, the blind SQL injection feature is limited to boolean (binary) SQL injection. The current version of Netsparker CE does not present obsolete files detected (listed but never verified in previous Netsparker CE versions). Various passive checks are also embedded, and include (among other features): Password Transmitted over Query String, Password Transmitted over HTTP, Autocomplete Enabled, Web Server Version Disclosure, Viewstate Not Encrypted, Email Address Disclosure, Internal Path Disclosure (Windows/Unix), Internal Server Errors, Cookie not HttpOnly, and more. |
None |
Many features are reserved for the commercial version, but in the overall, the tool is VERY user friendly and simple to use, and the tester can still benefit a lot from running it, in spite of the missing features. |