| Scanner | Version | Vendor | |
| Secubat | 0.5 | Stefan Kals |
| Tested Against WAVSEP Version: |
| Accurate Version | License / Technology | Last Update | Activity | 0.5 (Alpha) | LGPL .Net 2.0 | 27-01-2010 | 27-01-2010
Source Code |
| GUI | Config | Usage | Stability | Performance | Report | ScanLog | Pause | Session |
| Simple | Simple | Unstable | Fast |
Cookie | Header | A S I C | I G E S T | T L M | T L M v 2 | E R B E R O S | O R M | Detection | Logout | URL | Param | |||||
O U N T | Crawl | File | Crawler | Crawler | Crawler | Crawler | Crawler | Crawler | Crawler | Autofill | Autofill | CSRF Support | Support | Bypass | Bypass |
| 1 |
O U N T | E T | O S T | O O K I E | E A D E R | E C R E T | N a m e | M L | m l A T T | m l T A G | S O N | N e t E N C | M F | a v a S E R | N e t S E R | C F | C F - B i n | e b S o c k | W R | u s t o m |
| 2 |
O U N T | Q L i | S Q L i | S J S i | X S S | X S S | X S S | S O N h | F I | F I | M D E x e c | P L O A D | E D I R E C T | R L F i | D A P i | P A P H i | X i | S I | O R M A T i | O D E i | M L i | L i | U F F E R o | N T E G E R o | O D E D i s c | A C K U P f | A D D I N G | U T H b | R I V e | X E | E S S I O N | I X A T I O N | S R F | D o S |
| 2 |
| WebServer Hardening | CGI Scanning | Dir & File Enumeration | Passive Analysis | Additional Features |
| Detection Accuracy | Chart | ||||
| 18.38% Detection Rate 70.00% False Positives | (25/136) (7/10) |
| Detection Accuracy | Chart | ||||
| 7.58% Detection Rate 0.00% False Positives | (5/66) (0/7) |
| None |
| None |
| The tool is pretty difficult to install (requires installation of MSSQL, manual execution of a database creation script and initially loading the plug-ins through the GUI). It seems to succeed in the crawling process (the database is populated with information and the data is available for future usage in the GUI), but did not detect exposures in a consistent manner, regardless of the scan execution method (scan alongside the crawling process, immediately after crawling or in a separate time and instance) and the scan plug-ins selected (but depending on the application tested). The crawler does not seem to handle malformed HTML very well, and gets stuck or stops the crawling process when referred to pages that contain it (Probably related to the fact the tool is in early beta). The tool detects multiple locations of the same instance of XSS exposures, and also assigns unclear description to the SQL injections detected. |