Logo | Scanner | Version | Build | Vendor | |
![]() | AppSpider | 6.0 | 773/778 | Rapid7 |
Tested Against WAVSEP Version: |
Accurate Version | License / Technology | Last Update | Activity | 6.0 (GA)
Build 773/778 ![]() | Commercial Java 1.6.x | 01-11-2013 |
GUI | Config | Usage | Stability | Performance | Report | ScanLog | Pause | Session |
![]() | Very Simple | Very Simple | Stable | Fast | ![]() | ![]() | ![]() | ![]() |
Cookie | Header | A S I C | I G E S T | T L M | T L M v 2 | E R B E R O S | O R M | Detection | Logout | URL | Param | |||||
![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() |
O U N T | Crawl | File | Crawler | Crawler | Crawler | Crawler | Crawler | Crawler | Crawler | Autofill | Autofill | CSRF Support | Support | Bypass | Bypass |
11 | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() |
O U N T | E T | O S T | O O K I E | E A D E R | E C R E T | N a m e | M L | m l A T T | m l T A G | S O N | N e t E N C | M F | a v a S E R | N e t S E R | C F | C F - B i n | e b S o c k | W R | u s t o m |
16 | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() |
O U N T | Q L i | S Q L i | S J S i | X S S | X S S | X S S | S O N h | F I | F I | M D E x e c | P L O A D | E D I R E C T | R L F i | D A P i | P A P H i | X i | S I | O R M A T i | O D E i | M L i | L i | U F F E R o | N T E G E R o | O D E D i s c | A C K U P f | A D D I N G | U T H b | R I V e | X E | E S S I O N | I X A T I O N | S R F | D o S |
19 | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() |
WebServer Hardening | CGI Scanning | Dir & File Enumeration | Passive Analysis | Additional Features |
![]() | ![]() | ![]() | ![]() | URL attack vector, Ajax & SOAP Scan, External manual crawling (via burp/paros log), Crawling & verification via multiple browser engines (IE, Firefox), Advanced form submitting engine, Report-integrated exposure verification applet, WAF rule generation. |
Detection Accuracy | Chart | ||||
97.06% Detection Rate 0.00% False Positives | (132/136) (0/10) |
Detection Accuracy | Chart | ||||
100.00% Detection Rate 0.00% False Positives | (66/66) (0/7) |
Detection Accuracy | Chart | ||||
81.13% Detection Rate 12.50% False Positives | (662/816) (1/8) |
Detection Accuracy | Chart | ||||
79.63% Detection Rate 0.00% False Positives | (86/108) (0/6) |
WIVET Score | Chart | |||
94.00% Detection Rate |
SSL Strength, Credential Brute Force / Dictionary Attacks (Form/Http), Business Logic Abuse Attacks, XST, Directory Indexing, Parameter Analysis, Basic flash/java analysis, Malicious frame/script analysis, Java Grinder, Reverse Proxy. |
URL attack vector, Ajax & SOAP Scan, External manual crawling (via burp/paros log), Crawling & verification via multiple browser engines (IE, Firefox), Advanced form submitting engine, Report-integrated exposure verification applet, WAF rule generation. |
The tool creates an application map, as a tool for the customer to inspect the test scope. The next major upcoming release of NTO (v6.x) is supposed to include AMF Support and Improved AJAX crawling. Future plans for Chrome crawling / exposure verification. The tool currently does not provide VBs exploitation payloads for XSS. |