| Scanner | Version | Vendor | |
| Oedipus | 1.8.1 | Jordan Del Grande |
| Tested Against WAVSEP Version: |
| Accurate Version | License / Technology | Last Update | Activity | 1.8.1 (Beta)
| GPL2 Ruby 1.8.x | 08-04-2006 |
| GUI | Config | Usage | Stability | Performance | Report | ScanLog | Pause | Session |
| Simple | Complex | Stable | Fast |
Cookie | Header | A S I C | I G E S T | T L M | T L M v 2 | E R B E R O S | O R M | Detection | Logout | URL | Param | |||||
O U N T | Crawl | File | Crawler | Crawler | Crawler | Crawler | Crawler | Crawler | Crawler | Autofill | Autofill | CSRF Support | Support | Bypass | Bypass |
| 2 |
O U N T | E T | O S T | O O K I E | E A D E R | E C R E T | N a m e | M L | m l A T T | m l T A G | S O N | N e t E N C | M F | a v a S E R | N e t S E R | C F | C F - B i n | e b S o c k | W R | u s t o m |
| 2 |
O U N T | Q L i | S Q L i | S J S i | X S S | X S S | X S S | S O N h | F I | F I | M D E x e c | P L O A D | E D I R E C T | R L F i | D A P i | P A P H i | X i | S I | O R M A T i | O D E i | M L i | L i | U F F E R o | N T E G E R o | O D E D i s c | A C K U P f | A D D I N G | U T H b | R I V e | X E | E S S I O N | I X A T I O N | S R F | D o S |
| 6 |
| WebServer Hardening | CGI Scanning | Dir & File Enumeration | Passive Analysis | Additional Features |
| manual crawling is supported due to the burp log parsing feature and URL file parsing feature (including POST support). |
| Detection Accuracy | Chart | ||||
| 58.82% Detection Rate 40.00% False Positives | (80/136) (4/10) |
| Detection Accuracy | Chart | ||||
| 24.24% Detection Rate 42.86% False Positives | (16/66) (3/7) |
| Simple fuzzing (error detection). |
| manual crawling is supported due to the burp log parsing feature and URL file parsing feature (including POST support). |
| A wide variety of features, relatively easy execution (once you figured out how to do it), a high detection rate and a low false positive rate make this tool a must have in any hacking arsenal. The tool uses blind & union SQL injection exploits to verify vulnerabilities, a very advanced feature for a scanner that old, not to mention the fact that this tool was the only one that found the obvious internal SQL injection (!) in the dot net banking application. The tool has some faults (such as the inability to handle non standard ports in windows, due to the character ?:? which has a unique significance when writing files), but those limitations can eventually be bypassed (replacing the string in the log, using port forwarding, etc). |