| Logo | Scanner | Version | Vendor | |
| IronWASP | 0.9.1.0 | Lavakumar Kuppan |
| Tested Against WAVSEP Version: |
| Accurate Version | License / Technology | Last Update | Activity | 0.9.1.0 (GA)
| GPL3 .Net 2.0 | 02-07-2012 | 02-07-2012
Source Code |
| GUI | Config | Usage | Stability | Performance | Report | ScanLog | Pause | Session |
| Very Simple | Very Simple | Stable | Slow |
Cookie | Header | A S I C | I G E S T | T L M | T L M v 2 | E R B E R O S | O R M | Detection | Logout | URL | Param | |||||
O U N T | Crawl | File | Crawler | Crawler | Crawler | Crawler | Crawler | Crawler | Crawler | Autofill | Autofill | CSRF Support | Support | Bypass | Bypass |
| 4 |
O U N T | E T | O S T | O O K I E | E A D E R | E C R E T | N a m e | M L | m l A T T | m l T A G | S O N | N e t E N C | M F | a v a S E R | N e t S E R | C F | C F - B i n | e b S o c k | W R | u s t o m |
| 10 |
O U N T | Q L i | S Q L i | S J S i | X S S | X S S | X S S | S O N h | F I | F I | M D E x e c | P L O A D | E D I R E C T | R L F i | D A P i | P A P H i | X i | S I | O R M A T i | O D E i | M L i | L i | U F F E R o | N T E G E R o | O D E D i s c | A C K U P f | A D D I N G | U T H b | R I V e | X E | E S S I O N | I X A T I O N | S R F | D o S |
| 15 |
| WebServer Hardening | CGI Scanning | Dir & File Enumeration | Passive Analysis | Additional Features |
| Supports custom input vectors (!): fuzzing a custom part of the protocol - almost unique among open source scanners. Ready to use format plugins for Multipart, etc - and as far as I know its the only open source scanner that can scan these input vectors. |
| Detection Accuracy | Chart | ||||
| 100.00% Detection Rate 50.00% False Positives | (136/136) (5/10) |
| Detection Accuracy | Chart | ||||
| 75.76% Detection Rate 0.00% False Positives | (50/66) (0/7) |
| Detection Accuracy | Chart | ||||
| 35.29% Detection Rate 12.50% False Positives | (288/816) (1/8) |
| Detection Accuracy | Chart | ||||
| 100.00% Detection Rate 0.00% False Positives | (108/108) (0/6) |
| A partial list of passive features: Password in URL, Password sent in cleartext HTTP, Basic Authentication over Cleartext Communication, Cookie without http-only flag, Cookie without secure flag (in SSL), Cross-domain xml policy analysis, Server Version Disclosure, Various session & html issues, Autocomplete. Partial support for PXSS, DXSS and External Redirect (potential detection - without verification). |
| Supports custom input vectors (!): fuzzing a custom part of the protocol - almost unique among open source scanners. Ready to use format plugins for Multipart, etc - and as far as I know its the only open source scanner that can scan these input vectors. |
| Authentication support & antiCSRF support & complex multiphase scenarios can be implemented via the session plugins. A great tool for testing applications that use non-standard input delivery methods. Specifically useful for manual testing. |