Logo | Scanner | Version | Vendor | |
![]() | IronWASP | 0.9.7.4 | Lavakumar Kuppan |
Tested Against WAVSEP Version: |
Accurate Version | License / Technology | Last Update | Activity | 0.9.7.4 (GA) | GPL3 .Net 2.0 | 16-12-2013 | 16-12-2013
Source Code |
GUI | Config | Usage | Stability | Performance | Report | ScanLog | Pause | Session |
![]() | Very Simple | Very Simple | Stable | Fast | ![]() | ![]() | ![]() | ![]() |
Cookie | Header | A S I C | I G E S T | T L M | T L M v 2 | E R B E R O S | O R M | Detection | Logout | URL | Param | |||||
![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() |
O U N T | Crawl | File | Crawler | Crawler | Crawler | Crawler | Crawler | Crawler | Crawler | Autofill | Autofill | CSRF Support | Support | Bypass | Bypass |
4 | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() |
O U N T | E T | O S T | O O K I E | E A D E R | E C R E T | N a m e | M L | m l A T T | m l T A G | S O N | N e t E N C | M F | a v a S E R | N e t S E R | C F | C F - B i n | e b S o c k | W R | u s t o m |
13 | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() |
O U N T | Q L i | S Q L i | S J S i | X S S | X S S | X S S | S O N h | F I | F I | M D E x e c | P L O A D | E D I R E C T | R L F i | D A P i | P A P H i | X i | S I | O R M A T i | O D E i | M L i | L i | U F F E R o | N T E G E R o | O D E D i s c | A C K U P f | A D D I N G | U T H b | R I V e | X E | E S S I O N | I X A T I O N | S R F | D o S |
17 | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() | ![]() |
WebServer Hardening | CGI Scanning | Dir & File Enumeration | Passive Analysis | Additional Features |
![]() | ![]() | ![]() | ![]() | Supports custom input vectors (!): fuzzing a custom part of the protocol - almost unique among open source scanners. Ready to use format plugins for Multipart, etc - and as far as I know its the only open source scanner that can scan these input vectors. |
Detection Accuracy | Chart | ||||
99.26% Detection Rate 0.00% False Positives | (135/136) (0/10) |
Detection Accuracy | Chart | ||||
100.00% Detection Rate 0.00% False Positives | (66/66) (0/7) |
Detection Accuracy | Chart | ||||
53.06% Detection Rate 0.00% False Positives | (433/816) (0/8) |
Detection Accuracy | Chart | ||||
77.78% Detection Rate 0.00% False Positives | (84/108) (0/6) |
IronSAP (SAP testing), HAWAS (Hybrid), SSL Scanner, Exploitation (SSRF, CSRF), A partial list of passive features: Password in URL, Password sent in cleartext HTTP, Basic Authentication over Cleartext Communication, Cookie without http-only flag, Cookie without secure flag (in SSL), Cross-domain xml policy analysis, Server Version Disclosure, Various session & html issues, Autocomplete. Partial support for PXSS, DXSS and External Redirect (potential detection - without verification), SSRF. |
Supports custom input vectors (!): fuzzing a custom part of the protocol - almost unique among open source scanners. Ready to use format plugins for Multipart, etc - and as far as I know its the only open source scanner that can scan these input vectors. |
Authentication support & antiCSRF support & complex multiphase scenarios can be implemented via the session plugins. A great tool for testing applications that use non-standard input delivery methods. Specifically useful for manual testing. |