| Logo | Scanner | Version | Build | Vendor | |
| Watobo | 0.9.8 | 724 | Andreas Schmidt |
| Tested Against WAVSEP Version: |
| Accurate Version | License / Technology | Last Update | Activity | 0.9.8 (Beta)
Build 724 | GPL2 Ruby 1.8.x | 18-04-2012 | 18-04-2012
Source Code |
| GUI | Config | Usage | Stability | Performance | Report | ScanLog | Pause | Session |
| Very Simple | Very Simple | Unstable | Fast |
Cookie | Header | A S I C | I G E S T | T L M | T L M v 2 | E R B E R O S | O R M | Detection | Logout | URL | Param | |||||
O U N T | Crawl | File | Crawler | Crawler | Crawler | Crawler | Crawler | Crawler | Crawler | Autofill | Autofill | CSRF Support | Support | Bypass | Bypass |
| 2 |
O U N T | E T | O S T | O O K I E | E A D E R | E C R E T | N a m e | M L | m l A T T | m l T A G | S O N | N e t E N C | M F | a v a S E R | N e t S E R | C F | C F - B i n | e b S o c k | W R | u s t o m |
| 2 |
O U N T | Q L i | S Q L i | S J S i | X S S | X S S | X S S | S O N h | F I | F I | M D E x e c | P L O A D | E D I R E C T | R L F i | D A P i | P A P H i | X i | S I | O R M A T i | O D E i | M L i | L i | U F F E R o | N T E G E R o | O D E D i s c | A C K U P f | A D D I N G | U T H b | R I V e | X E | E S S I O N | I X A T I O N | S R F | D o S |
| 6 |
| WebServer Hardening | CGI Scanning | Dir & File Enumeration | Passive Analysis | Additional Features |
| Supports Anti-CSRF-Tokens / Detect One-Time-Token. |
| Detection Accuracy | Chart | ||||
| 65.44% Detection Rate 30.00% False Positives | (89/136) (3/10) |
| Detection Accuracy | Chart | ||||
| 24.24% Detection Rate 57.14% False Positives | (16/66) (4/7) |
| Detection Accuracy | Chart | ||||
| 41.18% Detection Rate 0.00% False Positives | (336/816) (0/8) |
| Fuzzer, various SAP & JBoss tests (unique feature!), Lotus domino DB enumeration, Unencrypted password transmissions, Session related issues, Web server hardeniing. |
| Supports Anti-CSRF-Tokens / Detect One-Time-Token. |
| None |