Logo | Scanner | Version | Vendor | |
![]() | ZAP | 2.2.2 | OWASP |
Tested Against WAVSEP Version: |
Accurate Version | License / Technology | Last Update | Activity | 2.2.2 (GA) | ASF2 Java 1.6.x | 27-09-2013 | 28-11-2013
Source Code |
GUI | Config | Usage | Stability | Performance | Report | ScanLog | Pause | Session |
![]() | Very Simple | Very Simple | Very Stable | Fast | ![]() | ![]() | ![]() | ![]() |
Cookie | Header | A S I C | I G E S T | T L M | T L M v 2 | E R B E R O S | O R M | Detection | Logout | URL | Param | |||||
![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() |
O U N T | Crawl | File | Crawler | Crawler | Crawler | Crawler | Crawler | Crawler | Crawler | Autofill | Autofill | CSRF Support | Support | Bypass | Bypass |
5 | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() |
O U N T | E T | O S T | O O K I E | E A D E R | E C R E T | N a m e | M L | m l A T T | m l T A G | S O N | N e t E N C | M F | a v a S E R | N e t S E R | C F | C F - B i n | e b S o c k | W R | u s t o m |
11 | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() |
O U N T | Q L i | S Q L i | S J S i | X S S | X S S | X S S | S O N h | F I | F I | M D E x e c | P L O A D | E D I R E C T | R L F i | D A P i | P A P H i | X i | S I | O R M A T i | O D E i | M L i | L i | U F F E R o | N T E G E R o | O D E D i s c | A C K U P f | A D D I N G | U T H b | R I V e | X E | E S S I O N | I X A T I O N | S R F | D o S |
17 | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() |
WebServer Hardening | CGI Scanning | Dir & File Enumeration | Passive Analysis | Additional Features |
![]() | ![]() | ![]() | ![]() | Brute force, Fuzzing, Beanshell integration, port scanner, break points, external plugins and extensions. Manual postback viewstate/validations manipulations via the VEHICLE extension, external obsolete file detection via the good-old-files extension. |
Detection Accuracy | Chart | ||||
100.00% Detection Rate 30.00% False Positives | (136/136) (3/10) |
Detection Accuracy | Chart | ||||
100.00% Detection Rate 0.00% False Positives | (66/66) (0/7) |
Detection Accuracy | Chart | ||||
75.00% Detection Rate 0.00% False Positives | (612/816) (0/8) |
Detection Accuracy | Chart | ||||
100.00% Detection Rate 16.67% False Positives | (108/108) (1/6) |
WIVET Score | Chart | |||
73.00% Detection Rate |
Forced Browsing (Options Menu), Username Enumeration, Parameter Tampering, AntiCSRF token scanner, HPP, Http Parameter Override. Session Fixation & Backup file enumeration available as extensions (https://code.google.com/p/zap-extensions/). Many passive analysis features from there Casaba Security Fiddler Extension - Watcher, Were implemented as well. CGI scanning features & fuzzing enabled through the integrated use of fuzz-db and JBroFuzz. |
Brute force, Fuzzing, Beanshell integration, port scanner, break points, external plugins and extensions. Manual postback viewstate/validations manipulations via the VEHICLE extension, external obsolete file detection via the good-old-files extension. |
An actively developed fork of the Paros project. |