<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr="http://purl.org/syndication/thread/1.0" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" gd:etag="W/&quot;A0IFRnc-fip7ImA9WhVTE0o.&quot;"><id>tag:blogger.com,1999:blog-3792178847867987053</id><updated>2012-02-27T13:51:57.956-08:00</updated><category term="scanner" /><category term="vulnerability scanner" /><category term="Session Puzzling" /><category term="security benchmark" /><category term="security" /><category term="sectoolmarket" /><category term="security tools" /><category term="clarification" /><category term="benchmarking" /><category term="benchmark" /><category term="vulnerable application" /><category term="followup" /><category term="web application scanner" /><category term="ADoS" /><category term="conclusions" /><category term="Temporal Session Race Conditions" /><category term="the best web application vulnerability scanner" /><title>Security Tools Benchmarking</title><subtitle type="html">Security Tools Benchmarking - A blog dedicated to aiding pen-testers in choosing tools that make a difference.</subtitle><link rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml" href="http://sectooladdict.blogspot.com/feeds/posts/default" /><link rel="alternate" type="text/html" href="http://sectooladdict.blogspot.com/" /><author><name>Shay-Chen</name><uri>http://www.blogger.com/profile/16490521389991462247</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="30" height="32" src="http://4.bp.blogspot.com/_59wTD1pGfP8/TRZdDx_oBiI/AAAAAAAAAAY/PKMwqsvGCLU/S220/n847114298_305931_3159.jpg" /></author><generator version="7.00" uri="http://www.blogger.com">Blogger</generator><openSearch:totalResults>8</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/atom+xml" href="http://feeds.feedburner.com/SecurityToolsBenchmarking" /><feedburner:info uri="securitytoolsbenchmarking" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><entry gd:etag="W/&quot;C0ADQHw4fSp7ImA9WhRaF00.&quot;"><id>tag:blogger.com,1999:blog-3792178847867987053.post-1903743518632931738</id><published>2012-02-19T17:36:00.000-08:00</published><updated>2012-02-19T17:36:11.235-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-02-19T17:36:11.235-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="sectoolmarket" /><category scheme="http://www.blogger.com/atom/ns#" term="web application scanner" /><category scheme="http://www.blogger.com/atom/ns#" term="benchmark" /><title>SecToolMarket - A dynamic benchmark presentation website</title><content type="html">&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;I noticed a pattern in my behavior... and I haven't really decided if it's good or bad.&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;I have a tendency to take up a task (which always seems super-simple at first), and then somewhere in the middle, find myself investing twice the time I originally planned, due to an outburst of obsessive perfectionism. &lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;Then again, the exaggerated optimism is probably the main reason why I manage to follow through with those tasks, and end up thinking they were fun... and this one actually was.&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;Although I can't really claim that what I'm about to present is perfect (I'm learning to control that one, hopefully), and the design is not &lt;b&gt;yet&lt;/b&gt; memorable (U-N-D-E-R-S-T-A-T-E-M-E-N-T), but it's &lt;b&gt;certainly going to be useful for a lot of folks&lt;/b&gt; - pen-testers (first and foremost), vendors, analysts, researchers, security personal, and a bunch of people that stumbled upon this blog and are about to face a lot of scary words. &lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;In short, the benchmark presentation framework is up and ready, and published as a web site called &lt;b&gt;SecToolMarket&lt;/b&gt; (&lt;a href="http://www.sectoolmarket.com/"&gt;http://www.sectoolmarket.com&lt;/a&gt;).&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;I originally planned hosting it in Google sites (which is why there's no JS/AJAX/etc), but after a couple of hours of desperately trying to upload &amp;nbsp;bulks of files to Google sites, I gave up and used the conventional method.&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;Although it doesn't yet contain a lot of new information (mostly additional information &amp;amp; analysis of the products tested in &lt;b&gt;2011&lt;/b&gt;), it's much easier to navigate through the data, and the analysis of the 2011 benchmark can provide additional insights, even to those that read the 2011 benchmark post.&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;A part from adding statistics, making things simpler, adding glossaries for everything and collecting vendor and product specific stats under dedicated pages, this framework can also be updated more frequently (and hopefully on a consistent basis), contains information that wasn't published, and allows you to track my progress as I'm performing my comparisons.&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;The two new categories (input-vector-support and coverage) are still &lt;b&gt;&lt;u&gt;incomplete&lt;/u&gt;&lt;/b&gt; (and will probably be updated soon, especially for commercial scanners - which will hopefully notify me if there's any missing information), but they already provide some insights, that might be relevant for some us.&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;And for all the kind souls... please help me spread the news... tweets, blog posts and telepathy are all welcome :) &lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;Some screen captures of the content:&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-6Ydq6-dirEc/T0GipDWX8hI/AAAAAAAAACU/ZrmMcvTeknI/s1600/sectoolmarket-main.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="190" src="http://3.bp.blogspot.com/-6Ydq6-dirEc/T0GipDWX8hI/AAAAAAAAACU/ZrmMcvTeknI/s320/sectoolmarket-main.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-GxSGziEiru8/T0Gi9R8AOQI/AAAAAAAAACc/OBly4r8skFA/s1600/sectoolmarket-audit.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="190" src="http://2.bp.blogspot.com/-GxSGziEiru8/T0Gi9R8AOQI/AAAAAAAAACc/OBly4r8skFA/s320/sectoolmarket-audit.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;I'll probably post additional information on this website, and my future plans, but in the meantime, I'm going to crash, and hope you have fun with it.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3792178847867987053-1903743518632931738?l=sectooladdict.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/gqYeLMPVafyELKQz8s3YzqGZgvE/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/gqYeLMPVafyELKQz8s3YzqGZgvE/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/gqYeLMPVafyELKQz8s3YzqGZgvE/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/gqYeLMPVafyELKQz8s3YzqGZgvE/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/SecurityToolsBenchmarking/~4/KyxKs8XYYak" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://sectooladdict.blogspot.com/feeds/1903743518632931738/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://sectooladdict.blogspot.com/2012/02/sectoolmarket-dynamic-benchmark.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3792178847867987053/posts/default/1903743518632931738?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3792178847867987053/posts/default/1903743518632931738?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SecurityToolsBenchmarking/~3/KyxKs8XYYak/sectoolmarket-dynamic-benchmark.html" title="SecToolMarket - A dynamic benchmark presentation website" /><author><name>Shay-Chen</name><uri>http://www.blogger.com/profile/16490521389991462247</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="30" height="32" src="http://4.bp.blogspot.com/_59wTD1pGfP8/TRZdDx_oBiI/AAAAAAAAAAY/PKMwqsvGCLU/S220/n847114298_305931_3159.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-6Ydq6-dirEc/T0GipDWX8hI/AAAAAAAAACU/ZrmMcvTeknI/s72-c/sectoolmarket-main.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://sectooladdict.blogspot.com/2012/02/sectoolmarket-dynamic-benchmark.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CkUFRno-eSp7ImA9WhdaFEw.&quot;"><id>tag:blogger.com,1999:blog-3792178847867987053.post-1447893863240812862</id><published>2011-10-23T15:46:00.000-07:00</published><updated>2011-10-23T15:50:17.451-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-10-23T15:50:17.451-07:00</app:edited><title>Rules of the Game – Scanner Benchmarks</title><content type="html">The last couple of months have been very interesting (thanks for all the great feedback and constructive criticism), and I have some good news and several announcements.&lt;br /&gt;
&lt;br /&gt;
&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;&lt;u&gt;First, the good news: &lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;I had several discussions with &lt;b&gt;Simon Bennetts&lt;/b&gt; (psiinon), one of the chapter leaders in OWASP and the leader / co-leader of several OWASP projects (ZAP, WAVE and OWASP-DEF). &lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;One of the sub projects Simon is leading is ZAP-WAVE, the &lt;b&gt;only &lt;/b&gt;additional web-app scanner evaluation framework which is actively maintained (the last publically available update of the third framework – "&lt;b&gt;moth&lt;/b&gt;", was in mid 2009), and he suggested we &lt;b&gt;merge &lt;/b&gt;our efforts so that everyone will benefit.&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;To make a long story short, Simon contributed the source code of the current test cases of ZAP-WAVE, allowing me adjust them into WAVSEP format and publish them under GPL 3.0 (currently available under ASF 2.0, lawyer comments aside). He even suggested that in the future, test cases that will be implemented by the ZAP team will be in WAVSEP format (structure and documentation). &lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;That's obviously great news for me (and for anyone else using the project or the benchmark results – credits to &lt;b&gt;Simon Bennetts&lt;/b&gt; and &lt;b&gt;Axel Neumann&lt;/b&gt;), since the ZAP-WAVE project already contains test cases in several exposures that are not covered by WAVSEP, and any additional contribution will only enhance my current efforts (I'm currently working on dozens of additional test cases for new exposure categories).&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;I have already started to adjust these test cases (changes and integration notes will appear in the changelog), and I hope I'll manage to release them soon.&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;&lt;u&gt;Now for several announcements that are related to the upcoming benchmark and the future versions of WAVSEP:&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;After the last benchmark was published, I got a lot of feedback, requests, interesting ideas and various suggestions. I read it all, and some of the requests and suggestions will be implemented in the upcoming benchmark and the future versions of WAVSEP.&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;The different feedbacks lead me to some important realizations:&lt;/div&gt;&lt;div class="MsoListParagraphCxSpFirst" style="direction: ltr; margin-bottom: 10.0pt; margin-left: 36.0pt; margin-right: 0cm; margin-top: 0cm; mso-add-space: auto; mso-list: l1 level1 lfo1; text-align: left; text-indent: -18.0pt; unicode-bidi: embed;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;The rules of the test &lt;b&gt;must&lt;/b&gt; be made &lt;b&gt;public and clear&lt;/b&gt; to all vendors, in order to make sure that the process will be fair. In order to achieve this goal, certain changes must be implemented in the testing process.&lt;/div&gt;&lt;div class="MsoListParagraphCxSpLast" style="direction: ltr; margin-bottom: 10.0pt; margin-left: 36.0pt; margin-right: 0cm; margin-top: 0cm; mso-add-space: auto; mso-list: l1 level1 lfo1; text-align: left; text-indent: -18.0pt; unicode-bidi: embed;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;In order to enable vendors to show improvement &lt;b&gt;quickly&lt;/b&gt; and in order to prevent any previous "negative" results from being perceived as a long term "punishment", the result presentation method must be updated more frequently, even between benchmarks.&lt;/div&gt;&lt;div class="MsoListParagraphCxSpLast" style="direction: ltr; margin-bottom: 10.0pt; margin-left: 36.0pt; margin-right: 0cm; margin-top: 0cm; mso-add-space: auto; mso-list: l1 level1 lfo1; text-align: left; text-indent: -18.0pt; unicode-bidi: embed;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;As a result, I have constructed the following set of rules which will govern the testing processes in any future benchmark I will perform, and also require some changes in the publication cycles of WAVSEP:&lt;/div&gt;&lt;div class="MsoListParagraphCxSpFirst" style="direction: ltr; margin-bottom: 10.0pt; margin-left: 36.0pt; margin-right: 0cm; margin-top: 0cm; mso-add-space: auto; mso-list: l0 level1 lfo2; text-align: left; text-indent: -18.0pt; unicode-bidi: embed;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;In order to enable vendors to show &lt;b&gt;&lt;u&gt;improvement&lt;/u&gt;&lt;/b&gt;, all the future benchmarks will be &lt;b&gt;based&lt;/b&gt; on the &lt;b&gt;WAVSEP test cases&lt;/b&gt; used in the &lt;u&gt;previous&lt;/u&gt; benchmark, &lt;b&gt;in addition&lt;/b&gt; to any other tests (interpretation: the upcoming benchmark will &lt;b&gt;also&lt;/b&gt; include tests against all the SQLi and RXSS test cases of WAVSEP 1.0.3).&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="direction: ltr; margin-bottom: 10.0pt; margin-left: 36.0pt; margin-right: 0cm; margin-top: 0cm; mso-add-space: auto; mso-list: l0 level1 lfo2; text-align: left; text-indent: -18.0pt; unicode-bidi: embed;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;Since a benchmark is much more interesting if the content in it is new, each &lt;b&gt;major&lt;/b&gt; benchmark will include different test aspects and / or detection results for test cases in additional exposure categories.&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="direction: ltr; margin-bottom: 10.0pt; margin-left: 36.0pt; margin-right: 0cm; margin-top: 0cm; mso-add-space: auto; mso-list: l0 level1 lfo2; text-align: left; text-indent: -18.0pt; unicode-bidi: embed;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;In order for the contest to be even more interesting (and in order to prevent one vendor from preparing for &lt;b&gt;everything&lt;/b&gt; while another was not even notified, was not aware of the WAVSEP platform, has insufficient time to improve the tool prior to the benchmark, etc), &lt;b&gt;the test cases of&amp;nbsp;&lt;u&gt;some&lt;/u&gt;&lt;/b&gt; &lt;b&gt;of the&lt;/b&gt; &lt;b&gt;new exposure categories&lt;/b&gt; will only be published &lt;b&gt;&lt;u&gt;after&lt;/u&gt;&lt;/b&gt; the first major benchmark that included tests against them – something that will &lt;b&gt;add some spice&lt;/b&gt; to the results, make sure the process will be fair, but will still &lt;b&gt;enable vendors to improve their previous score&lt;/b&gt;.&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="direction: ltr; margin-bottom: 10.0pt; margin-left: 36.0pt; margin-right: 0cm; margin-top: 0cm; mso-add-space: auto; mso-list: l0 level1 lfo2; text-align: left; text-indent: -18.0pt; unicode-bidi: embed;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;The upcoming benchmark will include tests in some new categories: I'm currently aiming for at least 3 &lt;b&gt;&lt;u&gt;additional&lt;/u&gt;&lt;/b&gt; categories, in addition to the previous (and I hope that I'll manage to finish all the developments and tests before my next deadline… at least for most tools).&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="direction: ltr; margin-bottom: 10.0pt; margin-left: 36.0pt; margin-right: 0cm; margin-top: 0cm; mso-add-space: auto; mso-list: l0 level1 lfo2; text-align: left; text-indent: -18.0pt; unicode-bidi: embed;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;Vendors that wish to update their score will be given an opportunity to do so, &lt;b&gt;even between major benchmarks&lt;/b&gt;, by using a presentation method that will support dynamically updated content. The terms for these tests will be published separately, as soon as the presentation framework will be available (soon). &lt;b&gt;Re-tests&lt;/b&gt; of additional versions of the same product will be performed under these terms.&lt;/div&gt;&lt;div class="MsoListParagraphCxSpLast" style="direction: ltr; margin-bottom: 10.0pt; margin-left: 36.0pt; margin-right: 0cm; margin-top: 0cm; mso-add-space: auto; mso-list: l0 level1 lfo2; text-align: left; text-indent: -18.0pt; unicode-bidi: embed;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;Since my&lt;b&gt;&lt;u&gt; final goal&lt;/u&gt;&lt;/b&gt;&amp;nbsp;is to test&amp;nbsp;&lt;b&gt;&lt;u&gt;all the vendors&lt;/u&gt;&lt;/b&gt; (almost 100), test additional types of scanning services / products, and eventually, test as many features of these tools as I possibly can, my time is a valuable asset, and contacting commercial vendors that don't offer a publically available evaluation version is very difficult. Although I will try my best to go through official channels and perform all the tests myself (or through members of the WAVSEP project)&lt;b&gt;, &lt;/b&gt;my experience shows that in some cases, the&lt;b&gt; &lt;/b&gt;official channels might be time consuming, and sadly, sometimes more then I can afford. &amp;nbsp;Therefore,&lt;b&gt;&lt;u&gt; I encourage vendors to contact me directly, starting of&amp;nbsp;November 15, so I could test them properly, on equal terms&lt;/u&gt;&lt;/b&gt;. &lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;&lt;b&gt;&lt;u&gt;Summary:&lt;/u&gt;&lt;/b&gt; future benchmarks will include test cases used in previous benchmarks (&lt;b&gt;to enable vendors to show improvement&lt;/b&gt;), new test cases which will only be published &lt;b&gt;after&lt;/b&gt; the benchmark (&lt;b&gt;so that the tests will be fair and the content more interesting&lt;/b&gt;), and finally -&amp;nbsp; the results will be more dynamic, to disable one more participation barrier.&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;As I said in my previous posts - I'm planning to continue to perform these comparisons for a long time, and intend &lt;b&gt;&lt;u&gt;to make sure&lt;/u&gt;&lt;/b&gt; that the community and vendors will both be able benefit from this initiative, if they only choose to.&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;Cheers&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3792178847867987053-1447893863240812862?l=sectooladdict.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/NiosWDwiXPRuGVi1fAqqC7Ruyac/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/NiosWDwiXPRuGVi1fAqqC7Ruyac/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/NiosWDwiXPRuGVi1fAqqC7Ruyac/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/NiosWDwiXPRuGVi1fAqqC7Ruyac/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/SecurityToolsBenchmarking/~4/TRU9I2XHcBU" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://sectooladdict.blogspot.com/feeds/1447893863240812862/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://sectooladdict.blogspot.com/2011/10/rules-of-game-scanner-benchmarks.html#comment-form" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3792178847867987053/posts/default/1447893863240812862?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3792178847867987053/posts/default/1447893863240812862?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SecurityToolsBenchmarking/~3/TRU9I2XHcBU/rules-of-game-scanner-benchmarks.html" title="Rules of the Game – Scanner Benchmarks" /><author><name>Shay-Chen</name><uri>http://www.blogger.com/profile/16490521389991462247</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="30" height="32" src="http://4.bp.blogspot.com/_59wTD1pGfP8/TRZdDx_oBiI/AAAAAAAAAAY/PKMwqsvGCLU/S220/n847114298_305931_3159.jpg" /></author><thr:total>1</thr:total><feedburner:origLink>http://sectooladdict.blogspot.com/2011/10/rules-of-game-scanner-benchmarks.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DUYDQH46cSp7ImA9WhdVFE8.&quot;"><id>tag:blogger.com,1999:blog-3792178847867987053.post-2170804124815520540</id><published>2011-09-18T08:54:00.000-07:00</published><updated>2011-09-19T03:12:51.019-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-09-19T03:12:51.019-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Temporal Session Race Conditions" /><category scheme="http://www.blogger.com/atom/ns#" term="ADoS" /><category scheme="http://www.blogger.com/atom/ns#" term="Session Puzzling" /><title>Session Puzzling and Session Race Conditions</title><content type="html">&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;&lt;b&gt;&lt;u&gt;&lt;br /&gt;
&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: center; unicode-bidi: embed;"&gt;&lt;b&gt;&lt;b&gt;&lt;span style="font-family: Calibri, sans-serif; font-size: 18pt; line-height: 115%;"&gt;Is It Really That Complicated?&lt;/span&gt;&lt;/b&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;&lt;b&gt;&lt;u&gt;&lt;br /&gt;
&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;&lt;b&gt;&lt;u&gt;Session Puzzling – An Indirect Application Attack Vector – Now Simplified&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;u&gt;&lt;br /&gt;
&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;A couple of months ago, I published a paper on an&amp;nbsp;&lt;b&gt;under-emphasized application level attack vector&lt;/b&gt; nicknamed "&lt;b&gt;&lt;i&gt;Session Puzzling&lt;/i&gt;&lt;/b&gt;" – an attack pattern that can abuse improper usage of session variables (a.k.a "&lt;b&gt;&lt;i&gt;Session Puzzles&lt;/i&gt;&lt;/b&gt;") in order to impersonate users, elevate privileges, bypass security restrictions and even execute "traditional" attack vectors against applications, &lt;b&gt;while bypassing any existing security mechanisms by attacking the application using a trusted input source&lt;/b&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;Even though the paper was published alongside a training kit&lt;b&gt; &lt;/b&gt;that was meant to demonstrate the various attack vectors (a vulnerable application called "&lt;b&gt;&lt;i&gt;puzzlemall&lt;/i&gt;"&lt;/b&gt;), the vast majority of responses I got have made me realize that most of the 2000 security professionals that were exposed to this attack &lt;b&gt;did not manage to understand it.&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;Some of the responses associated the paper to unrelated attacks, some didn't understand the impact or the mechanics, and some responses even claimed that the attacks &lt;b&gt;is too complicated to perform (!?!)&lt;/b&gt;. &lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;Although I know that the attack is not simple, and that several session puzzling vectors require 10+ requests, I &lt;b&gt;refuse&lt;/b&gt; to believe it's that complicated.&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;Over the last couple of years, I have seen &lt;b&gt;many &lt;/b&gt;commercial&lt;b&gt; &lt;/b&gt;applications that were &lt;b&gt;vulnerable&lt;/b&gt; to this attack (Oracle E-Business Suite Included), so I'm giving it one more shot before I'll let the attack fall into the "&lt;b&gt;too complicated to explain&lt;/b&gt;" category, and keep it all to myself.&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;The original whitepaper/presentation can be downloaded from the following addresses (contains background, additional attack vectors and mitigations):&lt;br /&gt;
&lt;a href="http://puzzlemall.googlecode.com/files/Session%20Puzzles%20-%20Indirect%20Application%20Attack%20Vectors%20-%20May%202011%20-%20Whitepaper.pdf"&gt;&lt;b&gt;Whitepaper&lt;/b&gt;&lt;/a&gt;&lt;br /&gt;
&lt;b&gt;&lt;a href="http://puzzlemall.googlecode.com/files/Session%20Puzzles%20-%20Indirect%20Application%20Attack%20Vectors%20-%2017%20May%202011%20-%20Presentation.pptx"&gt;Presentation&lt;/a&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;&lt;br /&gt;
The project homepage:&lt;br /&gt;
&lt;a href="http://puzzlemall.googlecode.com/"&gt;http://puzzlemall.googlecode.com/&amp;nbsp;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;&lt;b&gt;The following &lt;u&gt;short&lt;/u&gt; movies demonstrate a few simple session puzzling sequences:&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;Authentication Bypass via Session Puzzling (Abusing common session variables):&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;&lt;a href="http://www.youtube.com/watch?v=-DackF8HsIE"&gt;http://www.youtube.com/watch?v=-DackF8HsIE&lt;/a&gt; &lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;User Impersonation via Session Puzzling (Abusing common session variables):&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;&lt;a href="http://www.youtube.com/watch?v=ikIyInm0wAg"&gt;http://www.youtube.com/watch?v=ikIyInm0wAg&lt;/a&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;Session Puzzling via Redirection Prevention (Abusing Premature Session Population):&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;&lt;a href="http://www.youtube.com/watch?v=iTcOooHbgog"&gt;http://www.youtube.com/watch?v=iTcOooHbgog&lt;/a&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;Bypassing Restrictions in Multiphase Processes via Session Puzzling (Abusing Common Session Flags)&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;&lt;a href="http://www.youtube.com/watch?v=HeP54b52IeQ"&gt;http://www.youtube.com/watch?v=HeP54b52IeQ&lt;/a&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;The following POC movie demonstrates the attack against Oracle E-Business Suite (&lt;b&gt;exception scenario -&lt;/b&gt;&amp;nbsp;&lt;b&gt;not relying on input&lt;/b&gt;):&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;&lt;a href="http://www.hacktics.com/content/advisories/AdvORA20091214.html"&gt;http://www.hacktics.com/content/advisories/AdvORA20091214.html&lt;/a&gt; &lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;The training kit can be downloaded from the following address:&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;&lt;a href="http://puzzlemall.googlecode.com/files/puzzlemall.war"&gt;http://puzzlemall.googlecode.com/files/puzzlemall.war&lt;/a&gt; (derby version)&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;&lt;b&gt;&lt;u&gt;Temporal Session Race Conditions and Layer Targeted ADoS&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;u&gt;&lt;br /&gt;
&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;Although the original attack relied on the existence of persistent session values, an extended attack was presented last week (15&lt;sup&gt;th&lt;/sup&gt; of September), in a local OWASP chapter meeting. &lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;The extended method (nicknamed "&lt;b&gt;Temporal Session Race Conditions&lt;/b&gt;") enables detecting &amp;amp; exploiting session puzzles even if the session variables have a lifespan of milliseconds (session-level race conditions), by increasing the latency of certain lines of code through the use of layer targeted denial of service attacks.&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;The original OWASP presentation:&lt;br /&gt;
&lt;b&gt;&lt;a href="http://puzzlemall.googlecode.com/files/Temporal%20Session%20Race%20Conditions%20%28TSRC%29%20-%20Sept%202011%20-%20Presentation.pptx"&gt;Presentation&lt;/a&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;&lt;b&gt;The following movies demonstrate a few simple TSRC attacks:&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;Exploiting Temporal Session Race Conditions via Connection Pool Consumption:&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;&lt;a href="http://www.youtube.com/watch?v=woWECWwrsSk"&gt;http://www.youtube.com/watch?v=woWECWwrsSk&lt;/a&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;Exploiting Temporal Session Race Conditions via RegEx DoS:&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;&lt;a href="http://www.youtube.com/watch?v=3k_eJ1bcCro"&gt;http://www.youtube.com/watch?v=3k_eJ1bcCro&lt;/a&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;An extended version of "puzzlemall" which includes TSRC vulnerabilities (premium login page, requires MySQL):&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;&lt;a href="http://puzzlemall.googlecode.com/files/puzzlemall-v.1.1.2-mysql.zip"&gt;http://puzzlemall.googlecode.com/files/puzzlemall-v.1.1.2-mysql.zip&lt;/a&gt; &lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;A simple tool that can assist in the detection of TSRC connection pool consumption scenarios:&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;&lt;a href="http://puzzlemall.googlecode.com/files/SessionKeepAlive.exe"&gt;http://puzzlemall.googlecode.com/files/SessionKeepAlive.exe&lt;/a&gt; &lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;&lt;b&gt;&lt;u&gt;Acknowledgements&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;The following individuals contributed to the Session Puzzling / TSRC research in various ways, and helped me turn a bunch of ideas into a consistent methodology:&lt;/div&gt;&lt;div class="MsoNormal" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;Oren Ofer, Oren Hafif, Alex Ganelis, Liran Sheinbox and Zafrir Grossman.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;u&gt;Additional Resources&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
An attack similar to session puzzling is mentioned under the name "&lt;a href="http://en.wikipedia.org/wiki/Session_poisoning"&gt;session poisoning&lt;/a&gt;", but the session puzzling/TSRC sequences differ from this attack mainly by the &lt;b&gt;lack of direct input dependency&lt;/b&gt; (see the multiphase restriction bypass scenario and the e-business suite exploit for the exception scenario), and expand the attack&amp;nbsp;tool-set&amp;nbsp;in the aspect of &lt;b&gt;methodology&lt;/b&gt;, &lt;b&gt;predefined sequences&lt;/b&gt;,&amp;nbsp;&lt;b&gt;scope of modules&lt;/b&gt;, &lt;b&gt;complementary methods&lt;/b&gt; and usage of &lt;b&gt;denial of service&lt;/b&gt; for &lt;b&gt;extending the lifespan&lt;/b&gt; of temporary session variables.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3792178847867987053-2170804124815520540?l=sectooladdict.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/dpaVBSAh1iGWg0URHTh1LTDZg38/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/dpaVBSAh1iGWg0URHTh1LTDZg38/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/dpaVBSAh1iGWg0URHTh1LTDZg38/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/dpaVBSAh1iGWg0URHTh1LTDZg38/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/SecurityToolsBenchmarking/~4/8daNGQLH5AY" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://sectooladdict.blogspot.com/feeds/2170804124815520540/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://sectooladdict.blogspot.com/2011/09/session-puzzling-and-session-race.html#comment-form" title="3 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3792178847867987053/posts/default/2170804124815520540?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3792178847867987053/posts/default/2170804124815520540?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SecurityToolsBenchmarking/~3/8daNGQLH5AY/session-puzzling-and-session-race.html" title="Session Puzzling and Session Race Conditions" /><author><name>Shay-Chen</name><uri>http://www.blogger.com/profile/16490521389991462247</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="30" height="32" src="http://4.bp.blogspot.com/_59wTD1pGfP8/TRZdDx_oBiI/AAAAAAAAAAY/PKMwqsvGCLU/S220/n847114298_305931_3159.jpg" /></author><thr:total>3</thr:total><feedburner:origLink>http://sectooladdict.blogspot.com/2011/09/session-puzzling-and-session-race.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEIDRX8-eyp7ImA9WhdQE0g.&quot;"><id>tag:blogger.com,1999:blog-3792178847867987053.post-5660944376278622097</id><published>2011-08-01T20:48:00.000-07:00</published><updated>2011-08-14T14:16:14.153-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-08-14T14:16:14.153-07:00</app:edited><title>Commercial Web Application Scanner Benchmark</title><content type="html">&lt;div align="center" class="MsoNormal" style="text-align: center;"&gt;&lt;b&gt;&lt;span style="font-size: 44pt; line-height: 115%;"&gt;The Scanning Legion:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div align="center" class="MsoNormal" style="text-align: center;"&gt;&lt;b&gt;&lt;span style="font-size: 44pt; line-height: 115%;"&gt;Web Application Scanners Accuracy Assessment &amp;amp; Feature Comparison&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div align="center" class="MsoNormal" style="text-align: center;"&gt;&lt;b&gt;&lt;span style="font-size: 30pt; line-height: 115%;"&gt;Commercial &amp;amp; Open Source Scanners&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div align="center" class="MsoNormal" style="text-align: center;"&gt;A Comparison of &lt;b&gt;&lt;span style="font-size: 14pt; line-height: 115%;"&gt;60&lt;/span&gt;&lt;/b&gt; Commercial &amp;amp; Open Source Black Box Web Application Vulnerability Scanners&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;i&gt;By Shay Chen&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;i&gt;Security Consultant, Researcher &amp;amp; Instructor&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;a href="http://sectooladdict.blogspot.com/"&gt;http://sectooladdict.blogspot.com/&lt;/a&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;sectooladdict-$at$-gmail-$dot$-com&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;i&gt;August 2011&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;i&gt;Assessment Environments:&lt;/i&gt;&lt;/b&gt; WAVSEP 1.0 / WAVSEP 1.0.3 (&lt;a href="http://code.google.com/p/wavsep/"&gt;http://code.google.com/p/wavsep/&lt;/a&gt;)&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;
&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:WordDocument&gt;   &lt;w:View&gt;Normal&lt;/w:View&gt;   &lt;w:Zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:TrackMoves/&gt;   &lt;w:TrackFormatting/&gt;   &lt;w:PunctuationKerning/&gt;   &lt;w:ValidateAgainstSchemas/&gt;   &lt;w:SaveIfXMLInvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:IgnoreMixedContent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:AlwaysShowPlaceholderText&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:DoNotPromoteQF/&gt;   &lt;w:LidThemeOther&gt;EN-US&lt;/w:LidThemeOther&gt;   &lt;w:LidThemeAsian&gt;X-NONE&lt;/w:LidThemeAsian&gt;   &lt;w:LidThemeComplexScript&gt;HE&lt;/w:LidThemeComplexScript&gt;   &lt;w:Compatibility&gt;    &lt;w:BreakWrappedTables/&gt;    &lt;w:SnapToGridInCell/&gt;    &lt;w:WrapTextWithPunct/&gt;    &lt;w:UseAsianBreakRules/&gt;    &lt;w:DontGrowAutofit/&gt;    &lt;w:SplitPgBreakAndParaMark/&gt;    &lt;w:DontVertAlignCellWithSp/&gt;    &lt;w:DontBreakConstrainedForcedTables/&gt;    &lt;w:DontVertAlignInTxbx/&gt;    &lt;w:Word11KerningPairs/&gt;    &lt;w:CachedColBalance/&gt;   &lt;/w:Compatibility&gt;   &lt;w:BrowserLevel&gt;MicrosoftInternetExplorer4&lt;/w:BrowserLevel&gt;   &lt;m:mathPr&gt;    &lt;m:mathFont m:val="Cambria Math"/&gt;    &lt;m:brkBin m:val="before"/&gt;    &lt;m:brkBinSub m:val="&amp;#45;-"/&gt;    &lt;m:smallFrac m:val="off"/&gt;    &lt;m:dispDef/&gt;    &lt;m:lMargin m:val="0"/&gt;    &lt;m:rMargin m:val="0"/&gt;    &lt;m:defJc m:val="centerGroup"/&gt;    &lt;m:wrapIndent m:val="1440"/&gt;    &lt;m:intLim m:val="subSup"/&gt;    &lt;m:naryLim m:val="undOvr"/&gt;   &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:LatentStyles DefLockedState="false" DefUnhideWhenUsed="true"
  DefSemiHidden="true" DefQFormat="false" DefPriority="99"
  LatentStyleCount="267"&gt;   &lt;w:LsdException Locked="false" Priority="0" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Normal"/&gt;   &lt;w:LsdException Locked="false" Priority="9" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="heading 1"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 2"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 3"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 4"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 5"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 6"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 7"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 8"/&gt;   &lt;w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 9"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 1"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 2"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 3"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 4"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 5"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 6"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 7"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 8"/&gt;   &lt;w:LsdException Locked="false" Priority="39" Name="toc 9"/&gt;   &lt;w:LsdException Locked="false" Priority="35" QFormat="true" Name="caption"/&gt;   &lt;w:LsdException Locked="false" Priority="10" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Title"/&gt;   &lt;w:LsdException Locked="false" Priority="1" Name="Default Paragraph Font"/&gt;   &lt;w:LsdException Locked="false" Priority="11" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Subtitle"/&gt;   &lt;w:LsdException Locked="false" Priority="22" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Strong"/&gt;   &lt;w:LsdException Locked="false" Priority="20" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Emphasis"/&gt;   &lt;w:LsdException Locked="false" Priority="59" SemiHidden="false"
   UnhideWhenUsed="false" Name="Table Grid"/&gt;   &lt;w:LsdException Locked="false" UnhideWhenUsed="false" Name="Placeholder Text"/&gt;   &lt;w:LsdException Locked="false" Priority="1" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="No Spacing"/&gt;   &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading"/&gt;   &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List"/&gt;   &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid"/&gt;   &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1"/&gt;   &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2"/&gt;   &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1"/&gt;   &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2"/&gt;   &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1"/&gt;   &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2"/&gt;   &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3"/&gt;   &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List"/&gt;   &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading"/&gt;   &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List"/&gt;   &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid"/&gt;   &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 1"/&gt;   &lt;w:LsdException Locked="false" UnhideWhenUsed="false" Name="Revision"/&gt;   &lt;w:LsdException Locked="false" Priority="34" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="List Paragraph"/&gt;   &lt;w:LsdException Locked="false" Priority="29" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Quote"/&gt;   &lt;w:LsdException Locked="false" Priority="30" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Intense Quote"/&gt;   &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 1"/&gt;   &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 2"/&gt;   &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 3"/&gt;   &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 4"/&gt;   &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 5"/&gt;   &lt;w:LsdException Locked="false" Priority="60" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Shading Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="61" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light List Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="62" SemiHidden="false"
   UnhideWhenUsed="false" Name="Light Grid Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="63" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 1 Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="64" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Shading 2 Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="65" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 1 Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="66" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium List 2 Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="67" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 1 Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="68" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 2 Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="69" SemiHidden="false"
   UnhideWhenUsed="false" Name="Medium Grid 3 Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="70" SemiHidden="false"
   UnhideWhenUsed="false" Name="Dark List Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="71" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Shading Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="72" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful List Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="73" SemiHidden="false"
   UnhideWhenUsed="false" Name="Colorful Grid Accent 6"/&gt;   &lt;w:LsdException Locked="false" Priority="19" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Subtle Emphasis"/&gt;   &lt;w:LsdException Locked="false" Priority="21" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Intense Emphasis"/&gt;   &lt;w:LsdException Locked="false" Priority="31" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Subtle Reference"/&gt;   &lt;w:LsdException Locked="false" Priority="32" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Intense Reference"/&gt;   &lt;w:LsdException Locked="false" Priority="33" SemiHidden="false"
   UnhideWhenUsed="false" QFormat="true" Name="Book Title"/&gt;   &lt;w:LsdException Locked="false" Priority="37" Name="Bibliography"/&gt;   &lt;w:LsdException Locked="false" Priority="39" QFormat="true" Name="TOC Heading"/&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
	{mso-style-name:"Table Normal";
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-priority:99;
	mso-style-qformat:yes;
	mso-style-parent:"";
	mso-padding-alt:0cm 5.4pt 0cm 5.4pt;
	mso-para-margin-top:0cm;
	mso-para-margin-right:0cm;
	mso-para-margin-bottom:10.0pt;
	mso-para-margin-left:0cm;
	line-height:115%;
	mso-pagination:widow-orphan;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";
	mso-ascii-font-family:Calibri;
	mso-ascii-theme-font:minor-latin;
	mso-fareast-font-family:"Times New Roman";
	mso-fareast-theme-font:minor-fareast;
	mso-hansi-font-family:Calibri;
	mso-hansi-theme-font:minor-latin;}
&lt;/style&gt; &lt;![endif]--&gt;  &lt;br /&gt;
&lt;div class="MsoNormal" dir="LTR" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;&lt;u&gt;&lt;b&gt;Disclaimer&lt;/b&gt;&lt;/u&gt;&lt;/div&gt;&lt;div class="MsoNormal" dir="LTR" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;The results of this research are &lt;b&gt;only&lt;/b&gt; valid for estimating the detection accuracy of SQLi &amp;amp; RXSS exposures, and for counting and comparing the various features of the tested tools.&lt;/div&gt;&lt;div class="MsoNormal" dir="LTR" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;The author did &lt;b&gt;not&lt;/b&gt; evaluate every possible feature of each product, only the categories tested within the research, and thus, does not claim to be able to estimate the ROI from each individual product.&lt;/div&gt;&lt;div class="MsoNormal" dir="LTR" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal" dir="LTR" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;Furthermore, several vendors invested resources in improving their tools according to the recommendations of the &lt;b&gt;WAVSEP&lt;/b&gt; platform which was &lt;b&gt;publically available&lt;/b&gt; since December 2010. Some of them did so without any relation to the benchmark (and before they were aware of it), and some in preparation for it. Since the special structure of the WAVSEP testing platform &lt;b&gt;actually&lt;/b&gt; requires the vendor to &lt;b&gt;cover more vulnerable test scenarios&lt;/b&gt;, that action actually improves the detection ratio of the tool in any application (for the exposures covered by WAVSEP).&lt;/div&gt;&lt;div class="MsoNormal" dir="LTR" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal" dir="LTR" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;It is however, &lt;b&gt;important&lt;/b&gt; to mention that a few vendors were not notified on this benchmark, &lt;b&gt;and&lt;/b&gt; were not aware of the existence of the WAVSEP platform, and thus, could not have enhanced their tools in preparation for this benchmark (&lt;b&gt;HP Webinspect&lt;/b&gt;, &lt;b&gt;Tenable Nessus&lt;/b&gt;, and &lt;b&gt;Janus security Webcruiser&lt;/b&gt;), while other vendors that were tested in the initial research phases released updated versions that were &lt;b&gt;&lt;u&gt;not&lt;/u&gt;&lt;/b&gt; tested (&lt;b&gt;&lt;i&gt;Portswigger Burpsuite&lt;/i&gt;&lt;/b&gt; and &lt;b&gt;&lt;i&gt;Cenzic Hailstorm&lt;/i&gt;&lt;/b&gt;)&lt;/div&gt;&lt;div class="MsoNormal" dir="LTR" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal" dir="LTR" style="direction: ltr; text-align: left; unicode-bidi: embed;"&gt;That being said, the benchmark does represent the accuracy level of each tool in the date it was tested (the results of the &lt;b&gt;&lt;i&gt;vast majority&lt;/i&gt;&lt;/b&gt; of the tools are valid for the date this research was released), &lt;b&gt;but&lt;/b&gt; future benchmark will use a different research model in order to ensure that the competition will be fair for all vendors.&lt;/div&gt;&lt;/div&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-family: Calibri,sans-serif; font-size: 11pt; line-height: 115%;"&gt; &lt;/span&gt;&lt;/u&gt;&lt;/b&gt;  &lt;br /&gt;
&lt;div class="MsoNormal"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;w:sdt docparttype="Table of Contents" docpartunique="t" id="97746473" sdtdocpart="t"&gt;  &lt;/w:sdt&gt;&lt;br /&gt;
&lt;div class="MsoTocHeading"&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: large;"&gt;Table of Contents&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;span style="color: black; font-size: 11pt; font-weight: normal; line-height: 115%;"&gt;&lt;w:sdtpr&gt;&lt;/w:sdtpr&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="MsoToc1"&gt;&lt;span class="MsoHyperlink"&gt;&lt;span lang="AR-SA" style="font-family: Arial,sans-serif;"&gt;&lt;b&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;1. Prologue&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN-US" style="color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;"&gt;. &lt;/span&gt;&lt;span lang="EN-US" style="color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;"&gt;3&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoToc1"&gt;&lt;span class="MsoHyperlink"&gt;&lt;span lang="AR-SA" style="font-family: Arial,sans-serif;"&gt;&lt;b&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;2. List of Tested Web Application Scanners&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN-US" style="color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;"&gt;. &lt;/span&gt;&lt;span lang="EN-US" style="color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;"&gt;4&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoToc1"&gt;&lt;span class="MsoHyperlink"&gt;&lt;span lang="AR-SA" style="font-family: Arial,sans-serif;"&gt;&lt;b&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;3. Benchmark Overview &amp;amp; Assessment  Criteria&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN-US" style="color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;"&gt;. &lt;/span&gt;&lt;span lang="EN-US" style="color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;"&gt;5&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoToc1"&gt;&lt;span class="MsoHyperlink"&gt;&lt;span lang="AR-SA" style="font-family: Arial,sans-serif;"&gt;&lt;b&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;4. Test I – The More The Merrier – Counting  Audit Features&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN-US" style="color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;"&gt;. &lt;/span&gt;&lt;span lang="EN-US" style="color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;"&gt;6&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoToc1"&gt;&lt;span class="MsoHyperlink"&gt;&lt;span lang="AR-SA" style="font-family: Arial,sans-serif;"&gt;&lt;b&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;5. Test II – To the Victor Go the Spoils –  SQL Injection&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN-US" style="color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;"&gt;. &lt;/span&gt;&lt;span lang="EN-US" style="color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;"&gt;6&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoToc1"&gt;&lt;span class="MsoHyperlink"&gt;&lt;span lang="AR-SA" style="font-family: Arial,sans-serif;"&gt;&lt;b&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;6. Test III – I Fight (For) the Users –  Reflected XSS&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN-US" style="color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;"&gt;. &lt;/span&gt;&lt;span lang="EN-US" style="color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;"&gt;7&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoToc1"&gt;&lt;span class="MsoHyperlink"&gt;&lt;span lang="AR-SA" style="font-family: Arial,sans-serif;"&gt;&lt;b&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;7. Test IV – Knowledge is Power - Feature  Comparison&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN-US" style="color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;"&gt;. &lt;/span&gt;&lt;span lang="EN-US" style="color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;"&gt;7&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoToc1"&gt;&lt;span class="MsoHyperlink"&gt;&lt;span lang="AR-SA" style="font-family: Arial,sans-serif;"&gt;&lt;b&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;8. What Changed?&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN-US" style="color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;"&gt;. &lt;/span&gt;&lt;span lang="EN-US" style="color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;"&gt;8&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoToc1"&gt;&lt;span class="MsoHyperlink"&gt;&lt;span lang="AR-SA" style="font-family: Arial,sans-serif;"&gt;&lt;b&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;9. Initial Conclusions – Open Source vs.  Commercial&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN-US" style="color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;"&gt; &lt;/span&gt;&lt;span lang="EN-US" style="color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;"&gt;9&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoToc1"&gt;&lt;span class="MsoHyperlink"&gt;&lt;span lang="AR-SA" style="font-family: Arial,sans-serif;"&gt;&lt;b&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;10. Morale Issues in Commercial Product  Benchmarks&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN-US" style="color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;"&gt;. &lt;/span&gt;&lt;span lang="EN-US" style="color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;"&gt;9&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoToc1"&gt;&lt;span class="MsoHyperlink"&gt;&lt;span lang="AR-SA" style="font-family: Arial,sans-serif;"&gt;&lt;b&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;11. Verifying The Benchmark Results&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN-US" style="color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;"&gt;. &lt;/span&gt;&lt;span lang="EN-US" style="color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;"&gt;11&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoToc1"&gt;&lt;span class="MsoHyperlink"&gt;&lt;span lang="AR-SA" style="font-family: Arial,sans-serif;"&gt;&lt;b&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;12. Notifications and Clarifications&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN-US" style="color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;"&gt;. &lt;/span&gt;&lt;span lang="EN-US" style="color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;"&gt;11&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoToc1"&gt;&lt;span class="MsoHyperlink"&gt;&lt;span lang="AR-SA" style="font-family: Arial,sans-serif;"&gt;&lt;b&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;13. List of Tested Scanners&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN-US" style="color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;"&gt;. &lt;/span&gt;&lt;span lang="EN-US" style="color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;"&gt;12&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoToc1"&gt;&lt;span class="MsoHyperlink"&gt;&lt;span lang="AR-SA" style="font-family: Arial,sans-serif;"&gt;&lt;b&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;14. Source, License and Technical Details of  Tested Scanners&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN-US" style="color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;"&gt;. &lt;/span&gt;&lt;span lang="EN-US" style="color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;"&gt;12&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoToc1"&gt;&lt;span class="MsoHyperlink"&gt;&lt;span lang="AR-SA" style="font-family: Arial,sans-serif;"&gt;&lt;b&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;15. Comparison of Active Vulnerability  Detection Features&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN-US" style="color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;"&gt;. &lt;/span&gt;&lt;span lang="EN-US" style="color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;"&gt;13&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoToc1"&gt;&lt;span class="MsoHyperlink"&gt;&lt;span lang="AR-SA" style="font-family: Arial,sans-serif;"&gt;&lt;b&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;16. Comparison of Complementary Scanning  Features&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN-US" style="color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;"&gt;. &lt;/span&gt;&lt;span lang="EN-US" style="color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;"&gt;14&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoToc1"&gt;&lt;span class="MsoHyperlink"&gt;&lt;span lang="AR-SA" style="font-family: Arial,sans-serif;"&gt;&lt;b&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;17. Comparison of Usability and Coverage  Features&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN-US" style="color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;"&gt;. &lt;/span&gt;&lt;span lang="EN-US" style="color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;"&gt;15&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoToc1"&gt;&lt;span class="MsoHyperlink"&gt;&lt;span lang="AR-SA" style="font-family: Arial,sans-serif;"&gt;&lt;b&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;18. Comparison of Connection and  Authentication Features&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN-US" style="color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;"&gt;. &lt;/span&gt;&lt;span lang="EN-US" style="color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;"&gt;15&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoToc1"&gt;&lt;span class="MsoHyperlink"&gt;&lt;span lang="AR-SA" style="font-family: Arial,sans-serif;"&gt;&lt;b&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;19. Comparison of Advanced Features&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN-US" style="color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;"&gt;. &lt;/span&gt;&lt;span lang="EN-US" style="color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;"&gt;16&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoToc1"&gt;&lt;span class="MsoHyperlink"&gt;&lt;span lang="AR-SA" style="font-family: Arial,sans-serif;"&gt;&lt;b&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;20. Detailed Results: Reflected XSS  Detection Accuracy&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN-US" style="color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;"&gt;. &lt;/span&gt;&lt;span lang="EN-US" style="color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;"&gt;16&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoToc1"&gt;&lt;span class="MsoHyperlink"&gt;&lt;span lang="AR-SA" style="font-family: Arial,sans-serif;"&gt;&lt;b&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;21. Detailed Results: SQL Injection  Detection Accuracy&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN-US" style="color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;"&gt;. &lt;/span&gt;&lt;span lang="EN-US" style="color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;"&gt;16&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoToc1"&gt;&lt;span class="MsoHyperlink"&gt;&lt;span lang="AR-SA" style="font-family: Arial,sans-serif;"&gt;&lt;b&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;22. Drilldown – Error Based SQL Injection  Detection&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN-US" style="color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;"&gt;. &lt;/span&gt;&lt;span lang="EN-US" style="color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;"&gt;16&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoToc1"&gt;&lt;span class="MsoHyperlink"&gt;&lt;span lang="AR-SA" style="font-family: Arial,sans-serif;"&gt;&lt;b&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;23. Drilldown – Blind &amp;amp; Time Based SQL  Injection Detection&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN-US" style="color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;"&gt;. &lt;/span&gt;&lt;span lang="EN-US" style="color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;"&gt;16&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoToc1"&gt;&lt;span class="MsoHyperlink"&gt;&lt;span lang="AR-SA" style="font-family: Arial,sans-serif;"&gt;&lt;b&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;24. Technical Benchmark Conclusions –  Vendors &amp;amp; Users&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN-US" style="color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;"&gt;. &lt;/span&gt;&lt;span lang="EN-US" style="color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;"&gt;17&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoToc1"&gt;&lt;span class="MsoHyperlink"&gt;&lt;span lang="AR-SA" style="font-family: Arial,sans-serif;"&gt;&lt;b&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;25. So What Now?&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN-US" style="color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;"&gt;. &lt;/span&gt;&lt;span lang="EN-US" style="color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;"&gt;17&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoToc1"&gt;&lt;span class="MsoHyperlink"&gt;&lt;span lang="AR-SA" style="font-family: Arial,sans-serif;"&gt;&lt;b&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;26. Recommended Reading List: Scanner  Benchmarks&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN-US" style="color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;"&gt;. &lt;/span&gt;&lt;span lang="EN-US" style="color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;"&gt;18&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoToc1"&gt;&lt;span class="MsoHyperlink"&gt;&lt;span lang="AR-SA" style="font-family: Arial,sans-serif;"&gt;&lt;b&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;27. Thank-You Note&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN-US" style="color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;"&gt;. &lt;/span&gt;&lt;span lang="EN-US" style="color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;"&gt;19&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoToc1"&gt;&lt;span class="MsoHyperlink"&gt;&lt;span lang="AR-SA" style="font-family: Arial,sans-serif;"&gt;&lt;b&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;28. Frequently Asked Questions&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN-US" style="color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;"&gt;. &lt;/span&gt;&lt;span lang="EN-US" style="color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;"&gt;19&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoToc1"&gt;&lt;span class="MsoHyperlink"&gt;&lt;span lang="AR-SA" style="font-family: Arial,sans-serif;"&gt;&lt;b&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;29. Appendix A – Assessing Web Application  Scanners&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN-US" style="color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;"&gt;. &lt;/span&gt;&lt;span lang="EN-US" style="color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;"&gt;20&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoToc1"&gt;&lt;span class="MsoHyperlink"&gt;&lt;span lang="AR-SA" style="font-family: Arial,sans-serif;"&gt;&lt;b&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;30. Appendix B – A List of Tools Not  Included In the Test&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN-US" style="color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;"&gt;. &lt;/span&gt;&lt;span lang="EN-US" style="color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;"&gt;21&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoToc1"&gt;&lt;span class="MsoHyperlink"&gt;&lt;span lang="AR-SA" style="font-family: Arial,sans-serif;"&gt;&lt;b&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;31. Appendix C – WAVSEP Scan Logs&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN-US" style="color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;"&gt;. &lt;/span&gt;&lt;span lang="EN-US" style="color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;"&gt;25&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoToc1"&gt;&lt;span class="MsoHyperlink"&gt;&lt;span lang="AR-SA" style="font-family: Arial,sans-serif;"&gt;&lt;b&gt;&lt;span lang="EN-US" style="font-family: Calibri,sans-serif;"&gt;32. Appendix D – Scanners with Abnormal  Behavior&lt;/span&gt;&lt;/b&gt;&lt;span lang="EN-US" style="color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;"&gt;. &lt;/span&gt;&lt;span lang="EN-US" style="color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;"&gt;25&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;br /&gt;
&lt;div class="MsoListParagraph" style="margin-left: 18pt; text-indent: -18pt;"&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097" name="_Toc300025789"&gt;&lt;b&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;1. &lt;/span&gt;&lt;/b&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;Prologue&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;I've always been curious about it… from the first moment I executed a commercial scanner, almost seven years ago, to the day I started performing this research. Although manual penetration testing has always been the main focus of the test, most of us use automated tools to easily detect "low hanging fruit" exposures, increase the coverage when testing large scale applications in limited timeframes and even to double check locations that were manually tested. The questions always pops up, in every penetration test in which these tools are used…&lt;/div&gt;&lt;div class="MsoNormal"&gt;"Is it any good?", "Is it better than…" and "Can I rely on it to…" are questions that every pen-tester asks himself whenever he hits the scan button.&lt;/div&gt;&lt;div class="MsoNormal"&gt;Well, curiosity is a strange beast… it can drive you to wander and search, consume all your time in a search for obscure solutions.&lt;/div&gt;&lt;div class="MsoNormal"&gt;So recently, because of curiosity, I decided that I want to find out for myself, and invest whatever resources necessary to solve this mystery once and for all.&lt;/div&gt;&lt;div class="MsoNormal"&gt;Although I can hardly state that all my questions were answered, I can definitely sate your curiosity for the moment, by sharing insights, interesting facts, useful information and even some surprises, all derived from my latest research which is focused on the subject of commercial &amp;amp; open source web application scanners.&lt;/div&gt;&lt;div class="MsoNormal"&gt;This research covers the latest versions of &lt;b&gt;12&lt;/b&gt; commercial web application scanners and &lt;b&gt;48&lt;/b&gt; free &amp;amp; open source web application scanners, while comparing the following aspects of these tools:&lt;/div&gt;&lt;div class="MsoListParagraphCxSpFirst" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;Number &amp;amp; Type of Vulnerability Detection Features&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;SQL Injection Detection Accuracy&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;Reflected Cross Site Scripting&lt;/i&gt;&lt;/b&gt; &lt;b&gt;&lt;i&gt;Detection Accuracy&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpLast" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;General &amp;amp; Special Scanning Features&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Although my previous research included similar information, I regretted one thing after it was published; I did not present the information in a format that was useful to the common reader. In fact, as I found out later, many readers skipped the actual content, and focused on sections of the article that were actually a side effect of the main research.&lt;/div&gt;&lt;div class="MsoNormal"&gt;As a result, the following article will focus on presenting the information in a &lt;b&gt;simple comprehendible graphical format&lt;/b&gt;, while still providing the detailed research information to those interested… and there's &lt;b&gt;&lt;i&gt;a lot of new information to be shared&lt;/i&gt;&lt;/b&gt; – knowledge that can aid pen-testers in choosing the right tools, managers in budget related decisions, and visionaries, in properly reading the map;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;But&lt;/b&gt; before you read the statistics and insights presented in this report, and reach a conclusion as to which tool is the "best", it is crucial that you read &lt;b&gt;&lt;u&gt;&lt;span lang="HE" style="font-family: Arial,sans-serif;"&gt;‎&lt;/span&gt;Appendix A - Section 29&lt;/u&gt;&lt;/b&gt;, which explains the complexity of assessing the overall quality of web application scanners… &amp;nbsp;As you're about to find out, this question cannot be answered so easily… at least not yet.&lt;/div&gt;&lt;div class="MsoNormal"&gt;…&lt;/div&gt;&lt;div class="MsoNormal"&gt;So without any further delay, let's focus on the information you seek, and discuss the insights and conclusions later.&lt;br /&gt;
&amp;nbsp; &lt;/div&gt;&lt;div class="MsoListParagraph" style="margin-left: 18pt; text-indent: -18pt;"&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097" name="_Toc300025790"&gt;&lt;b&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;2. &lt;/span&gt;&lt;/b&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;List of Tested Web Application Scanners&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;u&gt;The following &lt;b&gt;commercial&lt;/b&gt; scanners were &lt;b&gt;included&lt;/b&gt; in the benchmark:&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpFirst" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;IBM Rational AppScan &lt;/i&gt;&lt;/b&gt;v8.0.03 - iFix Version (IBM)&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;WebInspect&lt;/i&gt;&lt;/b&gt; v9.10.78.0, SecureBase 4.05.99 (HP)&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;Hailstorm&lt;/i&gt;&lt;/b&gt; &lt;b&gt;&lt;i&gt;Professional&lt;/i&gt;&lt;/b&gt; v6.5-5267(Cenzic)&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;Acunetix WVS&lt;/i&gt;&lt;/b&gt; v7.0-20110608 (Acunetix)&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;NTOSpider&lt;/i&gt;&lt;/b&gt; v 5.4.098 (NT Objectives)&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;Netsparker&lt;/i&gt;&lt;/b&gt; v2.0.0.0 (Mavituna Security)&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;Burp Suite&lt;/i&gt;&lt;/b&gt; v1.3.09 (Portswigger)&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;Sandcat &lt;/i&gt;&lt;/b&gt;v4.2.4.0 (Syhunt)&lt;b&gt;&lt;i&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;ParosPro&lt;/i&gt;&lt;/b&gt; v1.9.12 (Milescan)&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;JSky&lt;/i&gt;&lt;/b&gt; v3.5.1-905 (NoSec)&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;WebCruiser&lt;/i&gt;&lt;/b&gt; v2.5.0 EE (Janus Security)&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpLast" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;Nessus&lt;/i&gt;&lt;/b&gt; v4.41-15078 (Tenable Network Security) – Only the Web Application Scanning Features&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;u&gt;The following &lt;b&gt;new&lt;/b&gt; &lt;b&gt;free &amp;amp; open source&lt;/b&gt; scanners were &lt;b&gt;included&lt;/b&gt; in the benchmark:&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;i&gt;VEGA&lt;/i&gt;&lt;/b&gt; 1.0 beta (Subgraph), &lt;b&gt;&lt;i&gt;Safe3WVS&lt;/i&gt;&lt;/b&gt; v9.2 FE (Safe3 Network Center), &lt;b&gt;&lt;i&gt;N-Stalker 2012&lt;/i&gt;&lt;/b&gt; &lt;b&gt;&lt;i&gt;Free Edition&lt;/i&gt;&lt;/b&gt; v7.1.1.106 (N-Stalker), &lt;b&gt;&lt;i&gt;DSSS (Damn Simple SQLi Scanner)&lt;/i&gt;&lt;/b&gt; v0.1h, &lt;b&gt;&lt;i&gt;SandcatCS&lt;/i&gt;&lt;/b&gt; v4.2.3.0&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;u&gt;The updated versions of the following &lt;b&gt;free &amp;amp; open source&lt;/b&gt; scanners were &lt;b&gt;re-tested&lt;/b&gt; in the benchmark:&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;i&gt;Zed Attack Proxy (ZAP) &lt;/i&gt;&lt;/b&gt;v1.3.0, &lt;b&gt;&lt;i&gt;sqlmap&lt;/i&gt;&lt;/b&gt; v0.9-rev4209 (SVN), &lt;b&gt;&lt;i&gt;W3AF&lt;/i&gt;&lt;/b&gt; 1.1-rev4350 (SVN), &lt;b&gt;&lt;i&gt;Watobo&lt;/i&gt;&lt;/b&gt; v0.9.7-rev544, &lt;b&gt;&lt;i&gt;Acunetix Free Edition&lt;/i&gt;&lt;/b&gt; v7.0-20110711, &lt;b&gt;&lt;i&gt;Netsparker Community Edition&lt;/i&gt;&lt;/b&gt; v1.7.2.13, &lt;b&gt;&lt;i&gt;WebSecurify&lt;/i&gt;&lt;/b&gt; v0.8, &lt;b&gt;&lt;i&gt;WebCruiser&lt;/i&gt;&lt;/b&gt; v2.4.2 FE (corrections), &lt;b&gt;&lt;i&gt;arachni&lt;/i&gt;&lt;/b&gt; v0.2.4 / v0.3, &lt;b&gt;&lt;i&gt;XSSer&lt;/i&gt;&lt;/b&gt; v1.5-1, &lt;b&gt;&lt;i&gt;Skipfish&lt;/i&gt;&lt;/b&gt; 2.02b, &lt;b&gt;&lt;i&gt;aidSQL&lt;/i&gt;&lt;/b&gt; 02062011&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;u&gt;The results were compared to those of unmaintained scanners tested in the original benchmark:&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;i&gt;Andiparos&lt;/i&gt;&lt;/b&gt; v1.0.6, &lt;b&gt;&lt;i&gt;ProxyStrike&lt;/i&gt;&lt;/b&gt; v2.2,&lt;b&gt;&lt;i&gt; Wapiti&lt;/i&gt;&lt;/b&gt; v2.2.1, &lt;b&gt;&lt;i&gt;Paros Proxy&lt;/i&gt;&lt;/b&gt; v3.2.13, &lt;b&gt;&lt;i&gt;PowerFuzzer&lt;/i&gt;&lt;/b&gt; v1.0, &lt;b&gt;&lt;i&gt;Grendel Scan&lt;/i&gt;&lt;/b&gt; v1.0, &lt;b&gt;&lt;i&gt;Oedipus&lt;/i&gt;&lt;/b&gt; v1.8.1, &lt;b&gt;&lt;i&gt;Scrawler&lt;/i&gt;&lt;/b&gt; v1.0, &lt;b&gt;&lt;i&gt;Sandcat Free Edition&lt;/i&gt;&lt;/b&gt; v4.0.0.1,&lt;b&gt;&lt;i&gt; JSKY Free Edition&lt;/i&gt;&lt;/b&gt; v1.0.0,&lt;b&gt;&lt;i&gt; N-Stalker 2009 Free Edition&lt;/i&gt;&lt;/b&gt; v7.0.0.223,&lt;b&gt;&lt;i&gt; UWSS (Uber Web Security Scanner)&lt;/i&gt;&lt;/b&gt; v0.0.2,&lt;b&gt;&lt;i&gt; Grabber&lt;/i&gt;&lt;/b&gt; v0.1, &lt;b&gt;&lt;i&gt;WebScarab&lt;/i&gt;&lt;/b&gt; v20100820,&lt;b&gt;&lt;i&gt; Mini MySqlat0r&lt;/i&gt;&lt;/b&gt; v0.5, &lt;b&gt;&lt;i&gt;WSTool&lt;/i&gt;&lt;/b&gt; v0.14001,&lt;b&gt;&lt;i&gt; crawlfish&lt;/i&gt;&lt;/b&gt; v0.92, &lt;b&gt;&lt;i&gt;Gamja&lt;/i&gt;&lt;/b&gt; v1.6, &lt;b&gt;&lt;i&gt;iScan&lt;/i&gt;&lt;/b&gt; v0.1, &lt;b&gt;&lt;i&gt;LoverBoy&lt;/i&gt;&lt;/b&gt; v1.0, &lt;b&gt;&lt;i&gt;openAcunetix&lt;/i&gt;&lt;/b&gt; v0.1, &lt;b&gt;&lt;i&gt;ScreamingCSS&lt;/i&gt;&lt;/b&gt; v1.02, &lt;b&gt;&lt;i&gt;Secubat&lt;/i&gt;&lt;/b&gt; v0.5, &lt;b&gt;&lt;i&gt;SQID (SQL Injection Digger)&lt;/i&gt;&lt;/b&gt; v0.3, &lt;b&gt;&lt;i&gt;SQLiX&lt;/i&gt;&lt;/b&gt; v1.0, &lt;b&gt;&lt;i&gt;VulnDetector&lt;/i&gt;&lt;/b&gt; v0.0.2, &lt;b&gt;&lt;i&gt;Web Injection Scanner&lt;/i&gt;&lt;/b&gt; &amp;nbsp;(WIS) v0.4, &lt;b&gt;&lt;i&gt;Xcobra&lt;/i&gt;&lt;/b&gt; v0.2, &lt;b&gt;&lt;i&gt;XSSploit&lt;/i&gt;&lt;/b&gt; v0.5, &lt;b&gt;&lt;i&gt;XSSS&lt;/i&gt;&lt;/b&gt; v0.40, &lt;b&gt;&lt;i&gt;Priamos&lt;/i&gt;&lt;/b&gt; v1.0 &lt;/div&gt;&lt;div class="MsoNormal"&gt;For the full list of commercial &amp;amp; open source tools that were &lt;b&gt;not&lt;/b&gt; tested in this benchmark, refer to &lt;b&gt;&lt;u&gt;&lt;span lang="HE" style="font-family: Arial,sans-serif;"&gt;‎&lt;/span&gt;Appendix B - Section 30&lt;/u&gt;&lt;/b&gt;.&lt;br /&gt;
&amp;nbsp; &lt;/div&gt;&lt;div class="MsoListParagraph" style="margin-left: 18pt; text-indent: -18pt;"&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097" name="_Toc300025791"&gt;&lt;b&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;3. &lt;/span&gt;&lt;/b&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;Benchmark Overview &amp;amp; Assessment Criteria&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;The benchmark focused on testing commercial &amp;amp; open source tools that are able to &lt;b&gt;detect&lt;/b&gt; (and not necessarily exploit) security vulnerabilities on a wide range of URLs, and thus, each tool tested was required to support the following features:&lt;/div&gt;&lt;div class="MsoListParagraphCxSpFirst" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;The ability to detect Reflected XSS and/or SQL Injection vulnerabilities.&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;The ability to scan multiple URLs at once (using either a crawler/spider feature, URL/Log file parsing feature or a built-in proxy).&lt;/div&gt;&lt;div class="MsoListParagraphCxSpLast" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;The ability to control and limit the scan to internal or external host (domain/IP).&lt;/div&gt;&lt;div class="MsoNormal"&gt;The testing procedure of all the tools included the following phases:&lt;/div&gt;&lt;div class="MsoListParagraphCxSpFirst" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;The scanners were all tested against the latest version of &lt;a href="http://code.google.com/p/wavsep/"&gt;WAVSEP&lt;/a&gt; (v1.0.3), a benchmarking platform designed to assess the detection accuracy of web application scanners. The purpose of WAVSEP’s test cases is to provide a scale for understanding which detection barriers each scanning tool can bypass, and which vulnerability variations can be detected by each tool. The various scanners were tested against the following test cases (GET and POST attack vectors):&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;66&lt;/b&gt; test cases that were vulnerable to Reflected Cross Site Scripting attacks.&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;80&lt;/b&gt; test cases that contained Error Disclosing SQL Injection exposures.&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;46&lt;/b&gt; test cases that contained Blind SQL Injection exposures.&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;10&lt;/b&gt; test cases that were vulnerable to Time Based SQL Injection attacks.&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;7&lt;/b&gt; different categories of &lt;b&gt;&lt;i&gt;false positive&lt;/i&gt;&lt;/b&gt; RXSS vulnerabilities.&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;10&lt;/b&gt; different categories of &lt;b&gt;&lt;i&gt;false positive&lt;/i&gt;&lt;/b&gt; SQLi vulnerabilities.&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;In order to ensure the result consistency, the directory of each exposure sub category was individually scanned multiple times using various configurations.&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;The features of each scanner were documented and compared, according to documentation, configuration, plugins and information received from the vendor.&lt;/div&gt;&lt;div class="MsoListParagraphCxSpLast" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;In order to ensure that the detection features of each scanner were truly effective, most of the scanners were tested against an additional benchmarking application that was prone to the same vulnerable test cases as the WAVSEP platform, but had a different design, slightly different behavior and different entry point format (currently nicknamed "bullshit"). &lt;/div&gt;&lt;div class="MsoNormal"&gt;The results of the main test categories are presented within three graphs (commercial graph, free &amp;amp; open source graph, unified graph), and the detailed information of each test is presented in a dedicated report. &lt;/div&gt;&lt;div class="MsoNormal"&gt;So, now that you've learned about the testing process, it's time for the results…&lt;br /&gt;
&amp;nbsp; &lt;/div&gt;&lt;div class="MsoListParagraph" style="margin-left: 18pt; text-indent: -18pt;"&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097" name="_Toc300025792"&gt;&lt;b&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;4. &lt;/span&gt;&lt;/b&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;Test I – The More The Merrier – Counting Audit Features&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;The first assessment criterion was the &lt;b&gt;number&lt;/b&gt; of audit features each tool supports.&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;Reasoning&lt;/b&gt;: An automated tool can't detect an exposure that it can't recognize (at least not directly, and not without manual analysis), and therefore, the number of audit features will affect the amount of exposures that the tool will be able to detect (assuming the audit features are &lt;b&gt;&lt;i&gt;implemented properly&lt;/i&gt;&lt;/b&gt;, that vulnerable &lt;b&gt;&lt;i&gt;entry points will be detected&lt;/i&gt;&lt;/b&gt; and that the tool will &lt;b&gt;&lt;i&gt;manage to scan the vulnerable input vectors&lt;/i&gt;&lt;/b&gt;).&lt;/div&gt;&lt;div class="MsoNormal"&gt;For the purpose of the benchmark, an audit feature was defined as a &lt;b&gt;common&lt;/b&gt; &lt;b&gt;generic application-level &lt;/b&gt;scanning feature, supporting the detection of exposures which could be used to attack the tested web application, gain access to sensitive assets or attack legitimate clients.&lt;/div&gt;&lt;div class="MsoNormal"&gt;The definition of the assessment criterion rules out product specific exposures and infrastructure related vulnerabilities, while unique and extremely rare features were documented and presented in a different section of this research, and were not taken into account when calculating the results. Exposures that were specific to Flash/Applet/Silverlight and Web Services Assessment were treated in the same manner. &lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;u&gt;The Number of Audit Features in Web Application Scanners – Commercial Tools&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-s17Pvrw01g8/Tjdz6D7bG5I/AAAAAAAAABQ/xDQza3-pcKw/s1600/FeatureCount-Commercial.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-s17Pvrw01g8/Tjdz6D7bG5I/AAAAAAAAABQ/xDQza3-pcKw/s1600/FeatureCount-Commercial.PNG" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;u&gt;The Number of Audit Features in Web Application Scanners - Free &amp;amp; Open Source Tools&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-j1-DcWoMz6E/Tjd0AeugQ-I/AAAAAAAAABY/YOy-mS0SyXw/s1600/FeatureCount-OpenSourceAndFree.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-j1-DcWoMz6E/Tjd0AeugQ-I/AAAAAAAAABY/YOy-mS0SyXw/s1600/FeatureCount-OpenSourceAndFree.PNG" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;u&gt;The Number of Audit Features in Web Application Scanners – Unified List&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-xgLj-pO5nDg/Tjd0A_IR8JI/AAAAAAAAABc/_f8_Dv2I0-E/s1600/FeatureCount-Unified.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/-xgLj-pO5nDg/Tjd0A_IR8JI/AAAAAAAAABc/_f8_Dv2I0-E/s1600/FeatureCount-Unified.PNG" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;
So, now that were done with the quantity, let's get to the quality…&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoListParagraph" style="margin-left: 18pt; text-indent: -18pt;"&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097" name="_Toc300025793"&gt;&lt;b&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;5. &lt;/span&gt;&lt;/b&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;Test II – To the Victor Go the Spoils – SQL Injection&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;The second assessment criterion was the detection accuracy of SQL Injection, one of the most famous exposures and the most commonly implemented attack vector in web application scanners.&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;Reasoning&lt;/b&gt;: a scanner that is not accurate enough will miss many exposures, and classify non-vulnerable entry points as vulnerable. This test aims to assess how good is each tool at detecting SQL Injection exposures in a&lt;b&gt; supported input vector, &lt;/b&gt;which is located in&lt;b&gt; a known entry point&lt;/b&gt;, without any restrictions that can prevent the tool from operating properly.&lt;/div&gt;&lt;div class="MsoNormal"&gt;The evaluation was performed on an application that uses MySQL 5.5.x as its data repository, and thus, will reflect the detection accuracy of the tool when scanning similar data repositories.&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;u&gt;Result Chart Glossary&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Note that the &lt;b&gt;&lt;span style="color: #0070c0;"&gt;BLUE&lt;/span&gt;&lt;/b&gt; bar represents the vulnerable test case detection accuracy, while the &lt;b&gt;&lt;span style="color: red;"&gt;RED&lt;/span&gt; &lt;/b&gt;bar represents false positive &lt;u&gt;categories&lt;/u&gt; detected by the tool (which may result in more instances then what the bar actually presents, when compared to the detection accuracy bar).&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;u&gt;The SQL Injection Detection Accuracy of Web Application Scanners – Commercial Tools&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-KpBo2d1kXJA/Tjd0CsNuPoI/AAAAAAAAABs/3KccKdr_KOk/s1600/SQLi-Commercial.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/-KpBo2d1kXJA/Tjd0CsNuPoI/AAAAAAAAABs/3KccKdr_KOk/s1600/SQLi-Commercial.PNG" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;b&gt;&lt;u&gt;&lt;br /&gt;
&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;u&gt;&lt;br /&gt;
&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;u&gt;The SQL Injection Detection Accuracy of Web Application Scanners – Open Source &amp;amp; Free Tools&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-htwsX7PjC-k/Tjd0CzEc41I/AAAAAAAAABw/lWK8lGiIL7U/s1600/SQLi-OpenSourceAndFree.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="640" src="http://1.bp.blogspot.com/-htwsX7PjC-k/Tjd0CzEc41I/AAAAAAAAABw/lWK8lGiIL7U/s640/SQLi-OpenSourceAndFree.PNG" width="554" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;u&gt;The SQL Injection Detection Accuracy of Web Application Scanners – Unified List&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-jamtGlcfeOE/Tjdz_6Ppq6I/AAAAAAAAABU/VrHEp9Q-uzo/s1600/SQLi-Unified.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/-jamtGlcfeOE/Tjdz_6Ppq6I/AAAAAAAAABU/VrHEp9Q-uzo/s1600/SQLi-Unified.PNG" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;It's obvious that testing one feature is not enough; ideally, the detection accuracy of all audit features should be assessed, but in the meantime, we will settle for one more…&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoListParagraph" style="margin-left: 18pt; text-indent: -18pt;"&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097" name="_Toc300025794"&gt;&lt;b&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;6. &lt;/span&gt;&lt;/b&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;Test III – I Fight (For) the Users – Reflected XSS&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;The third assessment criterion was the detection accuracy of Reflected Cross Site Scripting, a common exposure which is the 2nd most commonly implemented feature in web application scanners.&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;u&gt;Result Chart Glossary&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Note that the &lt;b&gt;&lt;span style="color: #0070c0;"&gt;BLUE&lt;/span&gt;&lt;/b&gt; bar represents the vulnerable test case detection accuracy, while the &lt;b&gt;&lt;span style="color: red;"&gt;RED&lt;/span&gt; &lt;/b&gt;bar represents false positive &lt;u&gt;categories&lt;/u&gt; detected by the tool (which may result in more instances then what the bar actually presents, when compared to the detection accuracy bar).&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;u&gt;The Reflected XSS Detection Accuracy of Web Application Scanners – Commercial Tools&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-ZLEnKWAwMA0/Tjd0BEkVukI/AAAAAAAAABg/GjacfCuaTq0/s1600/RXSS-Commercial.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/-ZLEnKWAwMA0/Tjd0BEkVukI/AAAAAAAAABg/GjacfCuaTq0/s1600/RXSS-Commercial.PNG" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;u&gt;The Reflected XSS Detection Accuracy of Web Application Scanners – Open Source &amp;amp; Free Tools&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-XfeJ8mgiLIk/Tjd0BnhedyI/AAAAAAAAABk/TKEFPxLpRnI/s1600/RXSS-OpenSourceAndFree.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/-XfeJ8mgiLIk/Tjd0BnhedyI/AAAAAAAAABk/TKEFPxLpRnI/s1600/RXSS-OpenSourceAndFree.PNG" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;u&gt;The Reflected XSS Detection Accuracy of Web Application Scanners – Unified List&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-2B3a5j5g0WA/Tjd0COjgqLI/AAAAAAAAABo/3k56aWy0Up8/s1600/RXSS-Unified.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/-2B3a5j5g0WA/Tjd0COjgqLI/AAAAAAAAABo/3k56aWy0Up8/s1600/RXSS-Unified.PNG" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoListParagraph" style="margin-left: 18pt; text-indent: -18pt;"&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097" name="_Toc300025795"&gt;&lt;b&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;7. &lt;/span&gt;&lt;/b&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;Test IV – Knowledge is Power - Feature Comparison&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;The list of tools tested in this benchmark is organized within the following reports:&lt;/div&gt;&lt;div class="MsoListParagraphCxSpFirst" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;a href="http://sectooladdict-benchmarks.googlecode.com/files/List%20of%20Tested%20Web%20Application%20Vulnerability%20Scanners%20-%20WAVSEP%20Benchmark%202011.pdf"&gt;&lt;b&gt;List of Tested Scanners&lt;/b&gt;&lt;/a&gt;&lt;b&gt; &lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpLast" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;a href="http://sectooladdict-benchmarks.googlecode.com/files/Details%20of%20Tested%20Web%20Application%20Vulnerability%20Scanners%20-%20WAVSEP%20Benchmark%202011.pdf"&gt;&lt;b&gt;Source, License and Technical Details of Tested Scanners&lt;/b&gt;&lt;/a&gt; &lt;/div&gt;&lt;div class="MsoNormal"&gt;Additional information was gathered during the benchmark, including information related to the different features of the various scanners. These details are organized in the following reports, and might prove useful when searching for tools for specific tasks or tests:&lt;/div&gt;&lt;div class="MsoListParagraphCxSpFirst" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;a href="http://sectooladdict-benchmarks.googlecode.com/files/Application%20Active%20Scan%20Features%20Comparison%201of2%20-%20WAVSEP%20Benchmark%202011.pdf"&gt;&lt;b&gt;Comparison of Active Vulnerability Detection Features (Audit Features) – 1 of 2&lt;/b&gt;&lt;/a&gt;&lt;b&gt; &lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;a href="http://sectooladdict-benchmarks.googlecode.com/files/Application%20Active%20Scan%20Features%20Comparison%202of2%20-%20WAVSEP%20Benchmark%202011.pdf"&gt;&lt;b&gt;Comparison of Active Vulnerability Detection Features (Audit Features) – 2 of 2&lt;/b&gt;&lt;/a&gt;&lt;b&gt; &lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;a href="http://sectooladdict-benchmarks.googlecode.com/files/Complementary%20Scan%20Features%20Comparison%20-%20WAVSEP%20Benchmark%202011.pdf"&gt;&lt;b&gt;Comparison of Complementary Scanning Features - Passive Analysis, CGI Scanning, Etc&lt;/b&gt;&lt;/a&gt;&lt;b&gt; &lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;a href="http://sectooladdict-benchmarks.googlecode.com/files/List%20of%20Scanner%20Features%20%281%20of%203%29%20-%20WAVSEP%20Benchmark%202011%20-%20Final3.pdf"&gt;&lt;b&gt;Comparison of Usability, Coverage and Scan Initiation Features&lt;/b&gt;&lt;/a&gt; &lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;a href="http://sectooladdict-benchmarks.googlecode.com/files/List%20of%20Scanner%20Features%20%282%20of%203%29%20-%20WAVSEP%20Benchmark%202011%20-%20Final.pdf"&gt;&lt;b&gt;Comparison of Authentication, Scan Control and Connection Support Features&lt;/b&gt;&lt;/a&gt; &lt;/div&gt;&lt;div class="MsoListParagraphCxSpLast" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;a href="http://sectooladdict-benchmarks.googlecode.com/files/List%20of%20Scanner%20Features%20%283%20of%203%29%20-%20WAVSEP%20Benchmark%202011.pdf"&gt;&lt;b&gt;Comparison of Advanced and Uncommon Features&lt;/b&gt;&lt;/a&gt; &lt;/div&gt;&lt;div class="MsoNormal"&gt;For detailed information on the accuracy assessment results, refer to the following reports:&lt;/div&gt;&lt;div class="MsoListParagraphCxSpFirst" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;a href="http://sectooladdict-benchmarks.googlecode.com/files/Web%20Application%20Scanner%20RXSS%20Detection%20Accuracy%20-%20WAVSEP%20ScoreChart%202011.pdf"&gt;&lt;b&gt;Benchmark Results – Reflected XSS Detection Accuracy&lt;/b&gt;&lt;/a&gt; &lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;a href="http://sectooladdict-benchmarks.googlecode.com/files/Web%20Application%20Scanner%20SQLi%20Detection%20Accuracy%20-%20WAVSEP%20ScoreChart%202011.pdf"&gt;&lt;b&gt;Benchmark Results – SQL Injection Detection Accuracy – Unified&lt;/b&gt;&lt;/a&gt;&lt;b&gt; &lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;a href="http://sectooladdict-benchmarks.googlecode.com/files/Web%20Application%20Scanner%20Blind%20SQLi%20Detection%20Accuracy%20-%20WAVSEP%20ScoreChart%202011.pdf"&gt;&lt;b&gt;Benchmark Drilldown – Blind &amp;amp; Time Based SQL Injection Detection Accuracy&lt;/b&gt;&lt;/a&gt; &lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;a href="http://sectooladdict-benchmarks.googlecode.com/files/Web%20Application%20Scanner%20Error-Based%20SQLi%20Detection%20Accuracy%20-%20WAVSEP%20ScoreChart%202011.pdf"&gt;&lt;b&gt;Benchmark Drilldown – Error Dependant SQL Injection Detection Accuracy&lt;/b&gt;&lt;/a&gt;&lt;b&gt; &lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpLast" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;a href="http://sectooladdict-benchmarks.googlecode.com/files/Scan%20Log%20-%20WAVSEP%20Benchmark%202011.pdf"&gt;&lt;b&gt;The Scan Logs&lt;/b&gt;&lt;/a&gt; (describing the executing process and configuration of each scanner) &lt;/div&gt;&lt;div class="MsoNormal"&gt;Additional information on the scan logs, the list of untested tools and the abnormal behaviors of scanners can be found in the article appendix sections (at the end of the article):&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;u&gt;&lt;span lang="HE" style="font-family: Arial,sans-serif;"&gt;‎&lt;/span&gt;Appendix B - Section 30&lt;/u&gt;&lt;/b&gt; – an appendix that contains a list of tools that were not included in the benchmark &lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;u&gt;&lt;span lang="HE" style="font-family: Arial,sans-serif;"&gt;‎&lt;/span&gt;Appendix D - Section 32&lt;/u&gt;&lt;/b&gt; – an appendix that describes scanners with abnormal behavior&lt;br /&gt;
&amp;nbsp; &lt;/div&gt;&lt;div class="MsoListParagraph" style="margin-left: 18pt; text-indent: -18pt;"&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097" name="_Toc300025796"&gt;&lt;b&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;8. &lt;/span&gt;&lt;/b&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;What Changed?&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Since the latest benchmark, many open source &amp;amp; commercial tools added new features and improved their detection accuracy. &lt;/div&gt;&lt;div class="MsoNormal"&gt;The following list presents a summary of changes in the detection accuracy of &lt;b&gt;free &amp;amp; open source&lt;/b&gt; tools that were tested in the previous benchmark:&lt;/div&gt;&lt;div class="MsoListParagraphCxSpFirst" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;&lt;u&gt;arachni&lt;/u&gt;&lt;/i&gt;&lt;/b&gt; – a &lt;b&gt;dramatic improvement &lt;/b&gt;in the detection accuracy of Reflected XSS exposures, and a &lt;b&gt;dramatic improvement&lt;/b&gt; in the detection accuracy of SQL Injection exposures (verified on mysql).&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;&lt;u&gt;sqlmap&lt;/u&gt;&lt;/i&gt;&lt;/b&gt; – a &lt;b&gt;dramatic improvement&lt;/b&gt; in the detection accuracy of SQL Injection exposures (verified on mysql).&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;&lt;u&gt;Acunetix Free Edition&lt;/u&gt;&lt;/i&gt;&lt;/b&gt; – a &lt;b&gt;major&lt;/b&gt; &lt;b&gt;improvement&lt;/b&gt; in the detection accuracy of RXSS exposures.&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;&lt;u&gt;Watobo&lt;/u&gt; &lt;/i&gt;&lt;/b&gt;– a &lt;b&gt;major&lt;/b&gt; &lt;b&gt;improvement&lt;/b&gt; in the detection accuracy of SQL Injection exposures (verified on mysql).&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;&lt;u&gt;N&lt;/u&gt;&lt;/i&gt;&lt;u&gt;-Stalker 2009 FE vs. 2012 &lt;i&gt;FE&lt;/i&gt;&lt;/u&gt; &lt;/b&gt;– although this tool is a very similar to N-Stalker 2009 FE, the surprising discovery I had was that the detection accuracy of N-Stalker 2012 is very different – it detects only a quarter of what N-Stalker 2009 used to detect. Assuming this result is not related to a bug in the product or in my testing procedure, it means that the newer free version is significantly &lt;b&gt;less effective&lt;/b&gt; than the previous free version, at least at detecting reflected XSS. A legitimate business decision, true, but surprising nevertheless.&lt;b&gt;&lt;u&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;&lt;u&gt;aidSQL&lt;/u&gt;&lt;/i&gt;&lt;/b&gt; – a &lt;b&gt;&lt;i&gt;major improvement&lt;/i&gt;&lt;/b&gt; in the detection accuracy of SQL Injection exposures (verified on mysql).&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;&lt;u&gt;XSSer&lt;/u&gt;&lt;/i&gt;&lt;/b&gt; – a &lt;b&gt;major improvement &lt;/b&gt;in the detection accuracy of Reflected XSS exposures, even though the results were not consistent.&lt;b&gt;&lt;u&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;&lt;u&gt;Skipfish &lt;/u&gt;&lt;/i&gt;&lt;/b&gt;– a slight improvement in the detection accuracy of RXSS exposures (it is currently unknown if the RXSS detection improvement is related to changes in code or to the enhanced testing method), and a slight decrease in the detection accuracy of SQLi exposures (might be related to the different testing environment and the different method used to count the results).&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;&lt;u&gt;WebSecurify&lt;/u&gt;&lt;/i&gt;&lt;/b&gt; – a slight improvement in the detection accuracy of RXSS exposures (it is currently unknown if the RXSS detection improvement is related to changes in code or to the enhanced testing method). &lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;&lt;u&gt;Zed Attack Proxy (ZAP)&lt;/u&gt;&lt;/i&gt;&lt;/b&gt; – Identical results. Any minor difference was probably caused due to the testing environment, configuration or minor issues.&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;&lt;u&gt;W3AF&lt;/u&gt;&lt;/i&gt;&lt;/b&gt; – slight improvement in the detection accuracy of RXSS exposures and slight decrease in the detection accuracy of SQL Injection exposures. &lt;b&gt;&lt;u&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;&lt;u&gt;Netsparker Community Edition&lt;/u&gt;&lt;/i&gt;&lt;/b&gt; – Identical results.&lt;b&gt;&lt;u&gt; &lt;/u&gt;&lt;/b&gt;Any minor difference was probably caused due to the testing environment, configuration or minor issues.&lt;b&gt;&lt;u&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;&lt;u&gt;WebCruiser&lt;/u&gt;&lt;/i&gt;&lt;/b&gt;&lt;u&gt; &lt;b&gt;&lt;i&gt;Free Edition&lt;/i&gt;&lt;/b&gt;&lt;/u&gt; – a minor decrease in accuracy, due to fixing documentation mistakes from the previous benchmark.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;u&gt;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;u&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpLast" style="margin-left: 18pt; text-indent: -18pt;"&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097" name="_Toc300025797"&gt;&lt;b&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;9. &lt;/span&gt;&lt;/b&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;Initial Conclusions – Open Source vs. Commercial&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;The following section presents &lt;b&gt;my own personal&lt;/b&gt; &lt;b&gt;opinions&lt;/b&gt; on the results of the benchmark, and since opinions are &lt;b&gt;beliefs&lt;/b&gt;, which are affected by emotions and circumstances, you are entitled to your own. &lt;/div&gt;&lt;div class="MsoNormal"&gt;After testing over &lt;b&gt;48&lt;/b&gt; open source scanners multiple times, and after comparing the results and experiences to the ones I had after testing &lt;b&gt;12&lt;/b&gt; commercial ones (and those are just the ones that I reported), I have reached the following conclusions:&lt;/div&gt;&lt;div class="MsoListParagraphCxSpFirst" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;As far as accuracy &amp;amp; features, the distance between open source tools and commercial tools is not as big as it used to be – tools such as sqlmap, arachni, wapiti, w3af and others are slowly closing the gap. That being said, there still is a significant difference in stability &amp;amp; false positives, in which most open source tools tend to have more false positives and be relatively unstable when compared to most commercial tools.&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;Some open source tools, even the most accurate ones, are relatively difficult to install &amp;amp; use, and still require fine-tuning in various fields. In my opinion, a non-technical QA engineer will have difficulties using these tools, and as a general rule, I'll recommend using them if your background is relatively technical (consultant, developer, etc). For all the rest, especially non-technical enterprise employees that prefer a decent usage experience - stick with commercial produces, with their free versions, or with the simple variations of open source tools.&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;If you are using a commercial product, it's best to merge the use of tools with a wide variety of features with tools with high detection accuracy.&amp;nbsp; It's possible to use tools that have relatively good scores in both of these aspects, or use a tool with a wide variety of features with another tool that has enhanced accuracy. Yes, this statement can be interpreted to using combinations of commercial and open source tools, and even to using two different commercial tools, so that one tool will complete the other. Budget? Take a look at the cost diversity of the tools, before you make any harsh decisions; I promise you'll be surprised. &lt;br /&gt;
&amp;nbsp; &lt;/div&gt;&lt;div class="MsoListParagraphCxSpLast" style="margin-left: 18pt; text-indent: -18pt;"&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097" name="_Toc300025798"&gt;&lt;b&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;10. &lt;/span&gt;&lt;/b&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;Morale Issues in Commercial Product Benchmarks&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;While testing the various commercial tools, I have dealt with certain moral issues that I want to share. Many vendors that were aware of this research enhanced their tools in preparation for it, an action I respect, and consider a positive step. Since the testing platform that included most of the tests was available online, preparing for the benchmark was a relatively easy task for any vendor that invested the resources.&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;i&gt;So, is the benchmark fair for vendors that couldn’t improve their tools due to various circumstances?&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;The testing process of a commercial tool is usually much more complicated and restrictive then testing a free or open source tool; it is necessary to contact the vendor to obtain an evaluation license, and the latest version of the tool (a process that can take several weeks), the evaluation licenses are usually restricted to a short evaluation timeframe (usually two weeks), and thus, updating and testing the tools in a future date can become a hassle (since some of the process will have to be performed all over again)… but why am I telling you all this?&lt;/div&gt;&lt;div class="MsoNormal"&gt;Simply, because I believe that the relevance of the test I performed for vendors that provided me an extended evaluation period and access to new builds was better; for example, a few days before the latest benchmark, immediately after testing the latest versions of two major vendors, I decided to rescan the platform using the latest versions of all the commercial tools I have, to ensure that the benchmark will be published with the most updated results.&lt;/div&gt;&lt;div class="MsoNormal"&gt;I verified that JSky, WebCruiser, and ParosPro didn't release a new version, tested the latest versions of AppScan, WebInspect, Acunetix, Netsparker, Sandcat and Nessus.&lt;/div&gt;&lt;div class="MsoNormal"&gt;It made sense that builds that were tested a short while ago (like NTO spider), were also something that I can rely on to represent the currently state of the tool (I hope&lt;span style="font-family: Wingdings;"&gt;J&lt;/span&gt;).&lt;/div&gt;&lt;div class="MsoNormal"&gt;I did however, have a problem with Cenzic and Burp, two of the first tools that I tested in this research, since my evaluation licenses were no longer valid, and I couldn't update the tools to their latest version and scan again, and since I had 2-3 days until the end of my planned schedule, with a million tasks pending, I simply couldn't afford going through the evaluation request phase again, with all of my good intentions, and the willingness to sacrifice my spare time to ensure these tools will be properly represented.&lt;/div&gt;&lt;div class="MsoNormal"&gt;Even though the results of some updated products (WebInspect and Nessus being the best examples) didn't change at all, even after I updated them to the latest version, who could say that the result would be the same for other vendors?&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;i&gt;So, were the terms unfair to burp and cenzic?&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Finally, several vendors sent me multiple versions and builds – they all wanted to succeed, a legitimate desire of any human being, even more so for a firm. Apart from the time each test took (a price I was willing to pay at the time), the new builds were sent even in the last day of the benchmark, and afterwards. &lt;/div&gt;&lt;div class="MsoNormal"&gt;But if the new version is better, and more accurate, by limiting the amount of tests I perform for a given vendor, isn't that against what I'm trying to achieve in all my benchmarks, which is to release the benchmark with the most updated results, for all the tools?&lt;/div&gt;&lt;div class="MsoNormal"&gt;(For example, Syhunt, a vendor that did very well in the last benchmark, sent me its final build (2.4.2.5) a day after the deadline, and included a time based SQL injection detection feature in that build, but since I couldn't afford the time anymore, I couldn't test the build, so, am I really reflecting the tool's current state in the most accurate manner? But if I would have tested this build, shouldn't I provide the rest of the vendors the same opportunity?)&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;i&gt;One of the questions I believe I can answer – the accuracy question.&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;A benchmark is, in a very real sense, a competition, and since I take the scientific approach, I believe that the results are absolute, at least for the subject that is being tested. Since I'm not claiming that one tool is "better" than the other in every category, only at the tested criterion, I believe that priorities do not matter – as long as the test really reflects the current situation, the result is reliable.&lt;/div&gt;&lt;div class="MsoNormal"&gt;I leave the interpretation of the results to the reader, at least until I'll cover enough aspects of the tools.&lt;/div&gt;&lt;div class="MsoNormal"&gt;As for the rest of the open issues, I don't have good answers for all of those questions, and although I did my very best in this benchmark, and even exceeded what I thought I'm capable of, I will probably have to think of some solutions that will make the next benchmark terms equal, even for scanners that were tested in the beginning of the benchmark, and less time consuming then it has been.&lt;br /&gt;
&amp;nbsp; &lt;/div&gt;&lt;div class="MsoListParagraph" style="margin-left: 18pt; text-indent: -18pt;"&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097" name="_Toc300025799"&gt;&lt;b&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;11. &lt;/span&gt;&lt;/b&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;Verifying The Benchmark Results&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;The results of the benchmark can be verified by replicating the scan methods described in the scan log of each scanner, and by testing the scanner against WAVSEP v1.0.3.&lt;/div&gt;&lt;div class="MsoNormal"&gt;The latest version of WAVSEP can be downloaded from the web site of project WAVSEP (binary/source code distributions, installation instructions and the test case description are provided in the web site download section):&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;a href="http://code.google.com/p/wavsep/"&gt;http://code.google.com/p/wavsep/&lt;/a&gt;&lt;br /&gt;
&amp;nbsp; &lt;/div&gt;&lt;div class="MsoListParagraph" style="margin-left: 18pt; text-indent: -18pt;"&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097" name="_Toc300025800"&gt;&lt;b&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;12. &lt;/span&gt;&lt;/b&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;Notifications and Clarifications&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;How to use the results of the benchmark&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;The results of the benchmark clearly show how accurate each tool is in detecting the tested vulnerabilities (SQL Injection (MySQL ) &amp;amp; Reflected Cross Site Scripting), as long as it is able to locate and scan the vulnerable entry points. The results might even help to &lt;b&gt;estimate&lt;/b&gt; how accurate each tool is in detecting related vulnerabilities (for example SQL Injection vulnerabilities which are based on other databases), and determine which exposure instances &lt;b&gt;cannot be detected&lt;/b&gt; by certain tools; &lt;/div&gt;&lt;div class="MsoNormal"&gt;However, currently, the results DO NOT evaluate the overall quality of the tool, since they don't &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; include detailed information on the subjects such as crawling quality, technology support, scoping, profiling, stability in extreme cases, tolerance, detection accuracy of other exposures and so on... at least NOT YET.&lt;/div&gt;&lt;div class="MsoNormal"&gt;I highly recommend reading the detailed results, and the appendix that deals with web application scanner evaluation, before getting to any conclusions.&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;Additional Notifications&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;During the benchmark, I have reported bugs that had a major affect on the detection accuracy to several commercial and open source vendors:&lt;/div&gt;&lt;div class="MsoListParagraphCxSpFirst" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;A performance improvement feature in NTOSpider caused it not to scan many POST XSS test cases, and thus, the detection accuracy of RXSS POST test cases was significantly smaller then the RXSS GET detection accuracy. The vendor was notified on this issue, and provided me with a special build that overrides this feature (at least until they will have a feature in the GUI to disable this mechanism).&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;A similar performance improvement feature in Netsparker caused the same issue, however, the feature could have been disabled in Netsparker, and thus, with the support of the relevant personal at Netsparker, I was able to work around the problem.&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;A few bugs in arachni prevented the blind sql injection diff plugins from working properly. I notified the author, Tasos, on the issue, and he quickly fixed the issue and released the new version.&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;Acunetix RXSS detection result was updated to match the results of the latest free version (one version above the tested commercial version) - Since the tested commercial version of Acunetix was older than the tested free version (20110608 vs 20110711), and since the results of the upgraded free version were actually better than the older commercial version I had tested, I changed the results of the commercial tool to match the ones of the new free version (from 22 to 24 in both the GET &amp;amp; POST RXSS detection scores).&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;Changes in results from the previous benchmark might be attributed to enhanced scanning features, and/or to enhanced stability in the test environment &amp;amp; method (connection pool, limited &amp;amp; divided scope).&lt;/div&gt;&lt;div class="MsoListParagraphCxSpLast" style="margin-left: 18pt; text-indent: -18pt;"&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097" name="_Toc300025801"&gt;&lt;b&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;13. &lt;/span&gt;&lt;/b&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;List of Tested Scanners&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;The following report contains the list of scanners tested in this benchmark, and provides information on the tested version, the tool's vendor/author and the current status of product:&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;a href="http://sectooladdict-benchmarks.googlecode.com/files/List%20of%20Tested%20Web%20Application%20Vulnerability%20Scanners%20-%20WAVSEP%20Benchmark%202011.pdf"&gt;http://sectooladdict-benchmarks.googlecode.com/files/List%20of%20Tested%20Web%20Application%20Vulnerability%20Scanners%20-%20WAVSEP%20Benchmark%202011.pdf&lt;/a&gt; &lt;/div&gt;&lt;div class="MsoListParagraph" style="margin-left: 18pt; text-indent: -18pt;"&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097" name="_Toc300025802"&gt;&lt;b&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;14. &lt;/span&gt;&lt;/b&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;Source, License and Technical Details of Tested Scanners&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;The following report compares the licenses, development technology and sources (home page) of the various scanners:&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;a href="http://sectooladdict-benchmarks.googlecode.com/files/Details%20of%20Tested%20Web%20Application%20Vulnerability%20Scanners%20-%20WAVSEP%20Benchmark%202011.pdf"&gt;http://sectooladdict-benchmarks.googlecode.com/files/Details%20of%20Tested%20Web%20Application%20Vulnerability%20Scanners%20-%20WAVSEP%20Benchmark%202011.pdf&lt;/a&gt; &lt;/div&gt;&lt;div class="MsoListParagraph" style="margin-left: 18pt; text-indent: -18pt;"&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097" name="_Toc300025803"&gt;&lt;b&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;15. &lt;/span&gt;&lt;/b&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;Comparison of Active Vulnerability Detection Features&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;The following reports compare the active vulnerability detection features (audit features) of the various tested scanners:&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;i&gt;First Report:&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;a href="http://sectooladdict-benchmarks.googlecode.com/files/Application%20Active%20Scan%20Features%20Comparison%201of2%20-%20WAVSEP%20Benchmark%202011.pdf"&gt;http://sectooladdict-benchmarks.googlecode.com/files/Application%20Active%20Scan%20Features%20Comparison%201of2%20-%20WAVSEP%20Benchmark%202011.pdf&lt;/a&gt; &lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;i&gt;Second Report:&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;a href="http://sectooladdict-benchmarks.googlecode.com/files/Application%20Active%20Scan%20Features%20Comparison%202of2%20-%20WAVSEP%20Benchmark%202011.pdf"&gt;http://sectooladdict-benchmarks.googlecode.com/files/Application%20Active%20Scan%20Features%20Comparison%202of2%20-%20WAVSEP%20Benchmark%202011.pdf&lt;/a&gt; &lt;/div&gt;&lt;div class="MsoNormal"&gt;Aside from the &lt;b&gt;Count&lt;/b&gt; column (which represents the total amount of audit features supported by the tool, not including complementary features such as web server scanning and passive analysis), each column in the report represents an audit feature. The description of each column is presented in the following glossary table:&lt;/div&gt;&lt;table border="1" cellpadding="0" cellspacing="0" class="MsoTableGrid" style="border-collapse: collapse; border: medium none; margin-left: 5.4pt;"&gt;&lt;tbody&gt;
&lt;tr&gt;   &lt;td style="background: none repeat scroll 0% 0% rgb(196, 188, 150); border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;" valign="top" width="142"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;&lt;b&gt;&lt;u&gt;Title&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style="background: none repeat scroll 0% 0% rgb(196, 188, 150); border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 240.95pt;" valign="top" width="321"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;&lt;b&gt;&lt;u&gt;Description&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style="border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;" valign="top" width="142"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;&lt;b&gt;SQL&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style="border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;" valign="top" width="321"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;Error Dependant SQL Injection&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style="border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;" valign="top" width="142"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;&lt;b&gt;BSQL&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style="border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;" valign="top" width="321"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;Blind &amp;amp; Intentional Time Delay SQL Injection&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style="border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;" valign="top" width="142"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;&lt;b&gt;RXSS&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style="border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;" valign="top" width="321"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;Reflected Cross Site Scripting&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style="border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;" valign="top" width="142"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;&lt;b&gt;PXSS&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style="border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;" valign="top" width="321"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;Persistent / Stored Cross Site Scripting&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style="border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;" valign="top" width="142"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;&lt;b&gt;DXSS&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style="border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;" valign="top" width="321"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;DOM XSS&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style="border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;" valign="top" width="142"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;&lt;b&gt;Redirect&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style="border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;" valign="top" width="321"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;External Redirect / Phishing via Redirection&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style="border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;" valign="top" width="142"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;&lt;b&gt;Bck&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style="border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;" valign="top" width="321"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;Backup File Detection&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style="border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;" valign="top" width="142"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;&lt;b&gt;Auth&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style="border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;" valign="top" width="321"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;Authentication Bypass&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style="border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;" valign="top" width="142"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;&lt;b&gt;CRLF&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style="border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;" valign="top" width="321"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;CRLF Injection / Response Splitting&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style="border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;" valign="top" width="142"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;&lt;b&gt;LDAP&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style="border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;" valign="top" width="321"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;LDAP Injection&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style="border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;" valign="top" width="142"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;&lt;b&gt;XPath&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style="border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;" valign="top" width="321"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;X-Path Injection&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style="border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;" valign="top" width="142"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;&lt;b&gt;MX&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style="border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;" valign="top" width="321"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;MX / SMTP / IMAP Injection&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style="border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;" valign="top" width="142"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;&lt;b&gt;Session Test&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style="border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;" valign="top" width="321"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;Session Identifier Complexity Analysis&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style="border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;" valign="top" width="142"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;&lt;b&gt;SSI&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style="border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;" valign="top" width="321"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;Server Side Include&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style="border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;" valign="top" width="142"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;&lt;b&gt;RFI-LFI&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style="border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;" valign="top" width="321"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;Directory Traversal / Remote File Include / Local File Include (Will   be separated into different categories in future benchmarks)&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style="border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;" valign="top" width="142"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;&lt;b&gt;Cmd&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style="border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;" valign="top" width="321"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;Command Injection / OS Command Injection&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style="border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;" valign="top" width="142"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;&lt;b&gt;Buffer&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style="border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;" valign="top" width="321"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;Buffer Overflow&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style="border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;" valign="top" width="142"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;&lt;b&gt;CSRF&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style="border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;" valign="top" width="321"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;Cross Site Request Forgery&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style="border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;" valign="top" width="142"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;&lt;b&gt;A-Dos&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style="border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;" valign="top" width="321"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;Application Denial of Service / RegEx DoS&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style="border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;" valign="top" width="142"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;&lt;b&gt;Privilege Escalation&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style="border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;" valign="top" width="321"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;Privilege Escalation Between Different Roles and User Accounts   (Resources / Features)&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style="border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;" valign="top" width="142"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;&lt;b&gt;Format String&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style="border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;" valign="top" width="321"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;Format String Injection&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style="border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;" valign="top" width="142"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;&lt;b&gt;File Upload&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style="border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;" valign="top" width="321"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;File Upload / Insecure File Upload&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style="border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;" valign="top" width="142"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;&lt;b&gt;Code Injection&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style="border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;" valign="top" width="321"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;Code Injection (ASP/JSP/PHP/Perl/etc)&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style="border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;" valign="top" width="142"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;&lt;b&gt;XML Injection&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style="border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;" valign="top" width="321"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;XML / SOAP Injection&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style="border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;" valign="top" width="142"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;&lt;b&gt;Source Code Disclosure&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style="border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;" valign="top" width="321"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;Source Code Disclosure Detection&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style="border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;" valign="top" width="142"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;&lt;b&gt;Integer Overflow&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style="border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;" valign="top" width="321"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;Integer Overflow&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style="border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;" valign="top" width="142"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;&lt;b&gt;Padding Oracle&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style="border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;" valign="top" width="321"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;Padding Oracle Detection / Exploitation&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style="border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;" valign="top" width="142"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;&lt;b&gt;Session Fixation&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style="border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;" valign="top" width="321"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;Session Fixation&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoListParagraph" style="margin-left: 18pt; text-indent: -18pt;"&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097" name="_Toc300025804"&gt;&lt;b&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;16. &lt;/span&gt;&lt;/b&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;Comparison of Complementary Scanning Features&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;The following report compares complementary vulnerability detection features in the tested scanners:&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;a href="http://sectooladdict-benchmarks.googlecode.com/files/Complementary%20Scan%20Features%20Comparison%20-%20WAVSEP%20Benchmark%202011.pdf"&gt;http://sectooladdict-benchmarks.googlecode.com/files/Complementary%20Scan%20Features%20Comparison%20-%20WAVSEP%20Benchmark%202011.pdf&lt;/a&gt; &lt;/div&gt;&lt;div class="MsoNormal"&gt;In order to clarify what each column in the report table means, use the following glossary table:&lt;/div&gt;&lt;table border="1" cellpadding="0" cellspacing="0" class="MsoTableGrid" style="border-collapse: collapse; border: medium none; margin-left: 5.4pt;"&gt;&lt;tbody&gt;
&lt;tr&gt;   &lt;td style="background: none repeat scroll 0% 0% rgb(196, 188, 150); border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;" valign="top" width="142"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;&lt;b&gt;&lt;u&gt;Title&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style="background: none repeat scroll 0% 0% rgb(196, 188, 150); border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 240.95pt;" valign="top" width="321"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;&lt;b&gt;&lt;u&gt;Description&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style="border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;" valign="top" width="142"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;&lt;b&gt;Web Server Hardening&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style="border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;" valign="top" width="321"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;Features that are able to detect Insecure HTTP method support (PUT,   Trace, WebDAV), directory listing, robots and cross-domain files information   disclosure, version specific vulnerabilities, etc.&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style="border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;" valign="top" width="142"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;&lt;b&gt;CGI Scanning&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style="border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;" valign="top" width="321"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;Default files, common vulnerable applications, etc.&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style="border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;" valign="top" width="142"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;&lt;b&gt;Passive Analysis&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style="border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;" valign="top" width="321"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;Security tests that don’t require any actual attacks, and are instead   based on information gathering and analysis of responses, including   certificate &amp;amp; cipher tests, content &amp;amp; metadata analysis, mime type   analysis, autocomplete detection, insecure transmission of credentials,   google hacking, etc.&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style="border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;" valign="top" width="142"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;&lt;b&gt;File / Dir Enumeration&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style="border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;" valign="top" width="321"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;Directory and file enumeration features&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style="border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;" valign="top" width="142"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;&lt;b&gt;Notes and Other Features&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style="border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;" valign="top" width="321"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;Uncommon or Unique features&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoListParagraph" style="margin-left: 18pt; text-indent: -18pt;"&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097" name="_Toc300025805"&gt;&lt;b&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;17. &lt;/span&gt;&lt;/b&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;Comparison of Usability and Coverage Features&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;The following report compares the usability, coverage and scan initiation features of the tested scanners:&lt;br /&gt;
&lt;a href="http://sectooladdict-benchmarks.googlecode.com/files/List%20of%20Scanner%20Features%20%281%20of%203%29%20-%20WAVSEP%20Benchmark%202011%20-%20Final3.pdf"&gt;http://sectooladdict-benchmarks.googlecode.com/files/List%20of%20Scanner%20Features%20(1%20of%203)%20-%20WAVSEP%20Benchmark%202011%20-%20Final3.pdf&lt;/a&gt; &lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;
In order to clarify what each column in the report table means, use the following glossary table:&lt;/div&gt;&lt;table border="1" cellpadding="0" cellspacing="0" class="MsoTableGrid" style="border-collapse: collapse; border: medium none; margin-left: 5.4pt;"&gt;&lt;tbody&gt;
&lt;tr&gt;   &lt;td style="background: none repeat scroll 0% 0% rgb(196, 188, 150); border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;" valign="top" width="142"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;&lt;b&gt;&lt;u&gt;Title&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style="background: none repeat scroll 0% 0% rgb(196, 188, 150); border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 240.95pt;" valign="top" width="321"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;&lt;b&gt;&lt;u&gt;Possible Values&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style="border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;" valign="top" width="142"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;&lt;b&gt;Configuration &amp;amp; Usage Scale&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style="border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;" valign="top" width="321"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;&lt;b&gt;Very Simple &lt;/b&gt;- GUI + Wizard&lt;/div&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;&lt;b&gt;Simple&lt;/b&gt; - GUI with simple options, Command line with scan   configuration file or simple options&lt;/div&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;&lt;b&gt;Complex&lt;/b&gt; - GUI with numerous options, Command line with   multiple options&lt;/div&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;&lt;b&gt;Very Complex&lt;/b&gt; - Manual scanning feature dependencies, multiple   configuration requirements&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style="border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;" valign="top" width="142"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;&lt;b&gt;Stability Scale&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style="border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;" valign="top" width="321"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;&lt;b&gt;Very Stable&lt;/b&gt; - Rarely crashes, Never gets stuck&lt;/div&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;&lt;b&gt;Stable&lt;/b&gt; - Rarely crashes, Gets stuck only in extreme scenarios&lt;/div&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;&lt;b&gt;Unstable&lt;/b&gt; - Crashes every once in a while, Freezes on a   consistent basis&lt;/div&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;&lt;b&gt;Fragile &lt;/b&gt;– Freezes or Crashes on a consistent basis, Fails   performing the operation in many cases&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style="border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;" valign="top" width="142"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;&lt;b&gt;Performance Scale&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style="border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;" valign="top" width="321"&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;&lt;b&gt;Very Fast&lt;/b&gt; - Fast implementation with limited amount of   scanning tasks&lt;/div&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;&lt;b&gt;Fast&lt;/b&gt; - Fast implementation with plenty of scanning tasks&lt;/div&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;&lt;b&gt;Slow&lt;/b&gt; - Slow implementation with limited amount of scanning   tasks&lt;/div&gt;&lt;div class="MsoNormal" style="line-height: normal; margin-bottom: 0cm;"&gt;&lt;b&gt;Very Slow&lt;/b&gt; - Slow implementation with plenty of scanning tasks&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoListParagraph" style="margin-left: 18pt; text-indent: -18pt;"&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097" name="_Toc300025806"&gt;&lt;b&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;18. &lt;/span&gt;&lt;/b&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;Comparison of Connection and Authentication Features&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;The following report compares the connection, authentication and scan control features of the tested scanners:&lt;br /&gt;
&lt;a href="http://sectooladdict-benchmarks.googlecode.com/files/List%20of%20Scanner%20Features%20%282%20of%203%29%20-%20WAVSEP%20Benchmark%202011%20-%20Final.pdf"&gt;http://sectooladdict-benchmarks.googlecode.com/files/List%20of%20Scanner%20Features%20(2%20of%203)%20-%20WAVSEP%20Benchmark%202011%20-%20Final.pdf&lt;/a&gt; &lt;/div&gt;&lt;div class="MsoListParagraph" style="margin-left: 18pt; text-indent: -18pt;"&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097" name="_Toc300025807"&gt;&lt;b&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;19. &lt;/span&gt;&lt;/b&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;Comparison of Advanced Features&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;The following report contains a comparison of advanced and uncommon scanner features:&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;a href="http://sectooladdict-benchmarks.googlecode.com/files/List%20of%20Scanner%20Features%20%283%20of%203%29%20-%20WAVSEP%20Benchmark%202011.pdf"&gt;http://sectooladdict-benchmarks.googlecode.com/files/List%20of%20Scanner%20Features%20%283%20of%203%29%20-%20WAVSEP%20Benchmark%202011.pdf&lt;/a&gt; &lt;/div&gt;&lt;div class="MsoListParagraph" style="margin-left: 18pt; text-indent: -18pt;"&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097" name="_Toc300025808"&gt;&lt;b&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;20. &lt;/span&gt;&lt;/b&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;Detailed Results: Reflected XSS Detection Accuracy&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;The results of the Reflected Cross Site Scripting (RXSS) accuracy assessment are presented in the following report (the graphical results representation is provided in the beginning of the article):&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;a href="http://sectooladdict-benchmarks.googlecode.com/files/Web%20Application%20Scanner%20RXSS%20Detection%20Accuracy%20-%20WAVSEP%20ScoreChart%202011.pdf"&gt;http://sectooladdict-benchmarks.googlecode.com/files/Web%20Application%20Scanner%20RXSS%20Detection%20Accuracy%20-%20WAVSEP%20ScoreChart%202011.pdf&lt;/a&gt; &lt;/div&gt;&lt;div class="MsoNormal"&gt;The results that were taken into account only include vulnerable pages linked from the index-xss.jsp index page (the RXSS-GET and/or RXSS-POST directories, in addition to the RXSS-FalsePositive directory). XSS Vulnerable entry points in the SQL injection vulnerable pages were not taken into account, since they don’t necessarily represent a unique scenario (or at least, not until the “layered vulnerabilities” scenario will be implemented).&lt;/div&gt;&lt;div class="MsoListParagraph" style="margin-left: 18pt; text-indent: -18pt;"&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097" name="_Toc300025809"&gt;&lt;b&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;21. &lt;/span&gt;&lt;/b&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;Detailed Results: SQL Injection Detection Accuracy&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;The overall results of the SQL Injection accuracy assessment are presented in the following report (the graphical results representation is provided in the beginning of the article):&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;a href="http://sectooladdict-benchmarks.googlecode.com/files/Web%20Application%20Scanner%20SQLi%20Detection%20Accuracy%20-%20WAVSEP%20ScoreChart%202011.pdf"&gt;http://sectooladdict-benchmarks.googlecode.com/files/Web%20Application%20Scanner%20SQLi%20Detection%20Accuracy%20-%20WAVSEP%20ScoreChart%202011.pdf&lt;/a&gt; &lt;/div&gt;&lt;div class="MsoListParagraph" style="margin-left: 18pt; text-indent: -18pt;"&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097" name="_Toc300025810"&gt;&lt;b&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;22. &lt;/span&gt;&lt;/b&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;Drilldown – Error Based SQL Injection Detection&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;The results of the Error-Based SQL Injection benchmark are presented in the following report:&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;a href="http://sectooladdict-benchmarks.googlecode.com/files/Web%20Application%20Scanner%20Error-Based%20SQLi%20Detection%20Accuracy%20-%20WAVSEP%20ScoreChart%202011.pdf"&gt;http://sectooladdict-benchmarks.googlecode.com/files/Web%20Application%20Scanner%20Error-Based%20SQLi%20Detection%20Accuracy%20-%20WAVSEP%20ScoreChart%202011.pdf&lt;/a&gt; &lt;/div&gt;&lt;div class="MsoListParagraph" style="margin-left: 18pt; text-indent: -18pt;"&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097" name="_Toc300025811"&gt;&lt;b&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;23. &lt;/span&gt;&lt;/b&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;Drilldown – Blind &amp;amp; Time Based SQL Injection Detection&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;The results of the Blind &amp;amp; Time based SQL Injection benchmarks are presented in the following report:&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;a href="http://sectooladdict-benchmarks.googlecode.com/files/Web%20Application%20Scanner%20Blind%20SQLi%20Detection%20Accuracy%20-%20WAVSEP%20ScoreChart%202011.pdf"&gt;http://sectooladdict-benchmarks.googlecode.com/files/Web%20Application%20Scanner%20Blind%20SQLi%20Detection%20Accuracy%20-%20WAVSEP%20ScoreChart%202011.pdf&lt;/a&gt; &lt;/div&gt;&lt;div class="MsoListParagraph" style="margin-left: 18pt; text-indent: -18pt;"&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097" name="_Toc300025812"&gt;&lt;b&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;24. &lt;/span&gt;&lt;/b&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;Technical Benchmark Conclusions – Vendors &amp;amp; Users&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;While testing the various tools in this benchmark, I dealt with numerous difficulties, witnessed many inconsistent results and noticed that some tools had difficulties optimizing their scanning features on the tested platform. I had however, dealt with the other end of the spectrum, and used tools the easily overcome most of the difficulties related to detecting the tested vulnerabilities. &lt;/div&gt;&lt;div class="MsoNormal"&gt;I'd like to share my conclusions, with the authors and vendors that are interested in improving their tools, and aren't offended by someone that's giving advice. &lt;/div&gt;&lt;div class="MsoNormal"&gt;As far as detecting SQL injection exposures, I have noticed that tools that implemented the following features, detected more exposures, had less false positives, and provided consistent results:&lt;/div&gt;&lt;div class="MsoListParagraphCxSpFirst" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;Time based SQL Injection detection vectors are very effective. They are, however, very tricky to use, since they might be affected by other attacks that are simultaneously executed, or affect the detection of other tests in the same manner. As a result, I recommended to all the authors &amp;amp; vendors to implement the following behavior in their product: &lt;b&gt;execute time based attacks at the end of the scanning process, after all the rest of the tests are done, while using a reduced number of concurrent connections&lt;/b&gt;. Executing other tests in parallel might have a negative effect on the detection accuracy.&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;Since the upper/lower timeout values used to determine whether or not a time based exploit was successful may change due to various circumstances, I recommend calculating and re-calculating this value during the scan, and revalidating each time based result independently, after verifying that the timeout values are "normal".&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;Implement various payloads of time based attacks – the sleep method is not enough to cover all the databases, and not even all the versions of mysql.&lt;/div&gt;&lt;div class="MsoListParagraphCxSpLast" style="margin-left: 18pt; text-indent: -18pt;"&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097" name="_Toc300025813"&gt;&lt;b&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;25. &lt;/span&gt;&lt;/b&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;So What Now?&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;So now that we have all those statistics, it's time to analyze them properly, and see which conclusions we can get to. Since this process will take time, I have to set some priorities;&lt;/div&gt;&lt;div class="MsoNormal"&gt;In the near future, I will try to achieve the following goals:&lt;/div&gt;&lt;div class="MsoListParagraphCxSpFirst" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;Find &lt;b&gt;a better way&lt;/b&gt; to present the vast amount of information on web application scanners features &amp;amp; accuracy. I have been struggling with this issue for almost 2 years, but I think that I finally found a solution that will make the information more useful for the common reader… stay tuned for updates.&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;Provide recommendations for the best current method of executing free &amp;amp; open source web application scanners; the most useful combinations, and the tiny tweaks required to achieve the best results. &lt;/div&gt;&lt;div class="MsoListParagraphCxSpLast" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;Release the new test case categories of WAVSEP that I have been working on. Yep, help needed.&lt;/div&gt;&lt;div class="MsoNormal"&gt;In addition to the short term goals, the following long term goals will still have a high priority:&lt;/div&gt;&lt;div class="MsoListParagraphCxSpFirst" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;Improve the testing framework (WAVSEP); add additional test cases and additional security vulnerabilities.&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;Perform additional benchmarks on the framework, and on a consistent basis. I previously aimed for &lt;b&gt;one major benchmark per year&lt;/b&gt;, but that formula might completely change, if I'll manage to work a few issues around a new initiative I have in this field. &lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;Integration with external frameworks for assessing crawling capabilities, technology support, etc.&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;Publish the results of tests against sample vulnerable web applications, so that some sort of feedback on other types of exposures will be available (until other types of vulnerabilities will be implemented in the framework), as well as features such as authentication support, crawling, etc.&lt;/div&gt;&lt;div class="MsoListParagraphCxSpLast" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;Gradually develop a framework for testing additional related features, such as authentication support, malformed HTML tolerance, abnormal response support, etc.&lt;/div&gt;&lt;div class="MsoNormal"&gt;I hope that this content will help the various vendors improve their tools, help pen-testers choose the right tool for each task, and in addition, help create some method of testing the numerous tools out there. &amp;nbsp;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Since I have already been in the situation in the past, then I know what's coming… &lt;b&gt;so I apologize in advance for any delays in my responses in the next few weeks.&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoListParagraph" style="margin-left: 18pt; text-indent: -18pt;"&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097" name="_Toc300025814"&gt;&lt;b&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;26. &lt;/span&gt;&lt;/b&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;Recommended Reading List: Scanner Benchmarks&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;The following resources include additional information on previous benchmarks, comparisons and assessments in the field of web application vulnerability scanners:&lt;/div&gt;&lt;div class="MsoListParagraphCxSpFirst" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;"&lt;a href="https://www.infosecisland.com/blogview/12935-Webapp-Scanner-Review-Acunetix-Versus-Netsparker.html"&gt;Webapp Scanner Review: Acunetix versus Netsparker",&lt;/a&gt; by Mark Baldwin (commercial scanner comparison, April 2011)&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;"&lt;a href="http://staff.science.uva.nl/%7Edelaat/sne-2010-2011/p27/report.pdf"&gt;Effectiveness of Automated Application Penetration Testing Tools&lt;/a&gt;", by Alexandre Miguel Ferreira and Harald Kleppe (commercial &amp;amp; freeware scanner comparison, February 2011)&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;"&lt;a href="http://sectooladdict.blogspot.com/2010/12/web-application-scanner-benchmark.html"&gt;Web Application Scanners Accuracy Assessment&lt;/a&gt;", the predecessor of the current benchmark, by Shay Chen (a comparison of 43 free &amp;amp; open source scanners, December 2010)&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;"&lt;a href="https://www.owasp.org/images/2/28/Black_Box_Scanner_Presentation.pdf"&gt;State of the Art: Automated Black-Box Web Application Vulnerability Testing&lt;/a&gt;" (&lt;a href="http://theory.stanford.edu/%7Ejcm/papers/pci_oakland10.pdf"&gt;Original Paper&lt;/a&gt;), by Jason Bau, Elie Bursztein, Divij Gupta, John Mitchell (May 2010) – original paper&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;"&lt;a href="http://www.ntobjectives.com/files/Accuracy_and_Time_Costs_of_Web_App_Scanners.pdf"&gt;Analyzing the Accuracy and Time Costs of Web Application Security Scanners&lt;/a&gt;", by Larry Suto (commercial scanners comparison, February 2010)&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;"&lt;a href="http://www.cs.ucsb.edu/%7Eadoupe/static/black-box-scanners-dimva2010.pdf"&gt;Why Johnny Can’t Pentest: An Analysis of Black-box Web Vulnerability Scanners&lt;/a&gt;", by Adam Doup´e, Marco Cova, Giovanni Vigna (commercial &amp;amp; open source scanner comparison, 2010)&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;"&lt;a href="http://www.darknet.org.uk/content/files/WebVulnScanners.pdf"&gt;Web Vulnerability Scanner Evaluation&lt;/a&gt;", by AnantaSec (commercial scanner comparison, January 2009)&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;"&lt;a href="http://ha.ckers.org/files/CoverageOfWebAppScanners.zip"&gt;Analyzing the Effectiveness and Coverage of Web Application Security Scanners&lt;/a&gt;", by Larry Suto (commercial scanners comparison, October 2007)&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;"&lt;a href="http://www.informationweek.com/news/202201216"&gt;Rolling Review: Web App Scanners Still Have Trouble with Ajax&lt;/a&gt;", by Jordan Wiens (commercial scanners comparison, October 2007)&lt;/div&gt;&lt;div class="MsoListParagraphCxSpLast" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;"&lt;a href="http://www.virtualforge.de/whitepapers/web_scanner_benchmark.pdf"&gt;Web Application Vulnerability Scanners – a Benchmark&lt;/a&gt;" , by Andreas Wiegenstein, Frederik Weidemann, Dr. Markus Schumacher, Sebastian Schinzel (Anonymous scanners&amp;nbsp; comparison, October 2006)&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoListParagraph" style="margin-left: 18pt; text-indent: -18pt;"&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097" name="_Toc300025815"&gt;&lt;b&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;27. &lt;/span&gt;&lt;/b&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;Thank-You Note&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;During the research described in this article, I have received help from quite a few individuals and resources, and I’d like to take the opportunity to thank them all.&lt;/div&gt;&lt;div class="MsoNormal"&gt;For all the &lt;b&gt;open source&lt;/b&gt; &lt;b&gt;tool authors&lt;/b&gt; that assisted me in testing the various tools in unreasonable late night hours, for the &lt;b&gt;kind souls&lt;/b&gt; that helped me obtain evaluation licenses for commercial products, for the &lt;b&gt;QA, Support and Development teams&lt;/b&gt; of commercial vendors, which saved me tons of time and helped me overcome obstacles, and for the various individuals that helped me contact these vendors.&lt;/div&gt;&lt;div class="MsoNormal"&gt;I would also like to continue my tradition, and thank all the information sources that helped me gather the list of scanners over the years, including (but not limited to) information security sources such as &lt;b&gt;PenTestIT&lt;/b&gt; (&lt;a href="http://www.pentestit.com/"&gt;http://www.pentestit.com/&lt;/a&gt;), &lt;b&gt;Security Sh3ll&lt;/b&gt; (&lt;a href="http://security-sh3ll.blogspot.com/"&gt;http://security-sh3ll.blogspot.com/&lt;/a&gt;), &lt;b&gt;NETpeas Toolswatch Service (&lt;/b&gt;&lt;a href="http://www.vulnerabilitydatabase.com/toolswatch/"&gt;http://www.vulnerabilitydatabase.com/toolswatch/&lt;/a&gt;), &lt;b&gt;Darknet&lt;/b&gt; (&lt;a href="http://www.darknet.org.uk/"&gt;http://www.darknet.org.uk/&lt;/a&gt;), &lt;b&gt;Packet Storm&lt;/b&gt; (&lt;a href="http://packetstormsecurity.org/"&gt;http://packetstormsecurity.org/&lt;/a&gt;), &lt;b&gt;Help Net Security&lt;/b&gt; (&lt;a href="http://www.net-security.org/"&gt;http://www.net-security.org/&lt;/a&gt;), &lt;b&gt;Astalavista&lt;/b&gt; (&lt;a href="http://www.astalavista.com/"&gt;http://www.astalavista.com/&lt;/a&gt;), &lt;b&gt;Google&lt;/b&gt; (of course) and many others.&lt;/div&gt;&lt;div class="MsoNormal"&gt;I hope that the conclusions, ideas, information and payloads presented in this research (and the benchmarks and tools that will follow) will be for the benefit of all vendors, open source community projects and commercial vendors alike. &lt;/div&gt;&lt;div class="MsoListParagraph" style="margin-left: 18pt; text-indent: -18pt;"&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097" name="_Toc300025816"&gt;&lt;b&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;28. &lt;/span&gt;&lt;/b&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;Frequently Asked Questions&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;Q&lt;/b&gt;: &lt;b&gt;60&lt;/b&gt; web application scanners is an awful lot, how many scanners exist?&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;A&lt;/b&gt;: Assuming you are using the same definition for a scanner that I do, then I'm currently aware of &lt;b&gt;&lt;u&gt;95&lt;/u&gt;&lt;/b&gt; web application scanners that can claim to support the detection of &lt;b&gt;generic application level exposures, in a safe an controllable manner, and in multiple URLs&lt;/b&gt; (48 free &amp;amp; open source scanners that were tested, 12 commercial scanners that were tested, 25 open source scanners that I didn't test yet, and 10 commercial scanners that slipped my grip). And yes, I'm planning on testing them all.&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;Q&lt;/b&gt;: Why RXSS and SQLi again? Will the benchmarks ever include additional exposures?&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;A&lt;/b&gt;: Yes, they will. In fact, I'm already working on test case categories of two different exposures, and will use them both for my next research. Besides, the last benchmark focused on free &amp;amp; open source products, and I couldn't help myself, I had to test them against each other.&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;Q&lt;/b&gt;: I can't wait for the next research, what can I do to speed things up?&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;A&lt;/b&gt;: I'm currently looking for methods to speed up the processes related to these researches, so if you're willing to help, contact me.&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;Q: &lt;/b&gt;What’s with the titles that contain cheesy movie quotes?&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;A&lt;/b&gt;: That's just it - I&lt;b&gt; &lt;/b&gt;happen to like cheese. Let's see you coming up with better titles at 4AM.&lt;/div&gt;&lt;div class="MsoListParagraph" style="margin-left: 18pt; text-indent: -18pt;"&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097" name="_Toc300025817"&gt;&lt;/a&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097" name="_Ref300025565"&gt;&lt;b&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;29. &lt;/span&gt;&lt;/b&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;Appendix A – Assessing Web Application Scanners&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Although this benchmark contains tons of information, and is &lt;b&gt;very useful&lt;/b&gt; as a decision assisting tool, the content within it cannot be used to calculate the accurate ROI (return of investment) of each web application scanner. Furthermore, it can't predict on its own exactly how good will the results of each scanner be in every situation (&lt;b&gt;&lt;u&gt;but it can predict what won't be detected&lt;/u&gt;&lt;/b&gt;), since there are additional factors that need to be taken into account.&lt;/div&gt;&lt;div class="MsoNormal"&gt;The results in this benchmark could serve as an accurate evaluation formula only if the scanner will be used to scan a technology that it supports, pages that it can detect (manual crawling features can be used to overcome many obstacles in this case), and locations without technological barriers that it cannot handle (for example, web application firewalls or anti-CSRF tokens).&lt;/div&gt;&lt;div class="MsoNormal"&gt;In order for us to truly assess the full capability of web application vulnerability scanners, the following features must be tested:&lt;/div&gt;&lt;div class="MsoListParagraphCxSpFirst" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;The entry point coverage of the web application scanner must be as high as possible; meaning, the tool must be able to &lt;b&gt;locate&lt;/b&gt; and &lt;b&gt;properly&lt;/b&gt; &lt;b&gt;activate&lt;/b&gt; (or be manually "taught") all the application entry points (e.g. static &amp;amp; dynamic pages, in-page events, services, filters, etc). Vulnerabilities in an entry point that wasn't located will not be detected. The &lt;a href="http://code.google.com/p/wivet/"&gt;WIVET&lt;/a&gt; project can provide additional information on coverage and support.&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;The attack vector coverage of the web application scanner – does it support input vectors such as GET / POST / Cookie parameters? HTTP headers? Parameter Names? Ajax Parameters? Serialized Objects? Each input vector that is not supported means exposures that won't be detected, regardless of the tool's accuracy level (assuming the unsupported attack/input vector is vulnerable).&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;The scanner must be able to handle the technological barriers implemented in the application, ranging from authentication mechanism to automated access prevention mechanisms such as CAPTCHAs and anti-CSRF tokens.&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;The scanner must be able to handle any application specific problems it encounters, including malformed HTML (tolerance), stability issues and other limitations. If the best scanner in the world will consistently cause the application to crash in a couple of seconds, then it's not useful for assessing the security of that application (in matters that don't relate to DoS attacks).&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;The number of features (active &amp;amp; passive) implemented in the web application vulnerability scanner.&lt;/div&gt;&lt;div class="MsoListParagraphCxSpLast" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;The accuracy level of each and every plugin supported by the web application vulnerability scanner.&lt;/div&gt;&lt;div class="MsoNormal"&gt;That being said, it's crucial to remember that even in the most ideal scenario, with the absence of human intelligence, scanners can't detect all the instances of exposures that are truly logical – meaning, are related to specific business logic, and thus, are not perceived as an issue by an entity that can't understand the business logic. &lt;/div&gt;&lt;div class="MsoNormal"&gt;But the sheer complexity of the issue &lt;b&gt;does not mean&lt;/b&gt; that we shouldn't start somewhere, and that's exactly what I'm trying to do in my benchmarks – create a scientific, accurate foundation for obtaining that goal, with enough investment, over time.&lt;/div&gt;&lt;div class="MsoNormal"&gt;Note that my explanations describe only a portion of the actual tests that should be performed, and I'm sharing them only to emphasize the true complexity of the core issue; I haven't touched stability, bugs, and a lot of other subjects, which may affect the overall result you get.&lt;/div&gt;&lt;div class="MsoNormal"&gt;Additional information on evaluation standards for web application vulnerability scanners can be found in the &lt;a href="http://projects.webappsec.org/w/page/13246986/Web%20Application%20Security%20Scanner%20Evaluation%20Criteria"&gt;WASC Web Application Security Scanner Evaluation Criteria&lt;/a&gt; web site.&lt;/div&gt;&lt;div class="MsoListParagraph" style="margin-left: 18pt; text-indent: -18pt;"&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097" name="_Toc300025818"&gt;&lt;/a&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097" name="_Ref280855248"&gt;&lt;/a&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097" name="_Ref280855122"&gt;&lt;b&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;30. &lt;/span&gt;&lt;/b&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;Appendix B – A List of Tools &lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;Not Included In the Test&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;The following &lt;b&gt;&lt;i&gt;commercial&lt;/i&gt;&lt;/b&gt; web application vulnerability scanners were &lt;b&gt;&lt;i&gt;not included&lt;/i&gt;&lt;/b&gt;&lt;i&gt; &lt;/i&gt;in the benchmark, since I didn't manage to get an evaluation version until the article publication deadline, or in the case of one scanner (mcafee), had problems with the evaluation version that I didn't manage to work out until the benchmark's deadline:&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;u&gt;Commercial Scanners not included in this benchmark&lt;/u&gt;&lt;/b&gt;&lt;u&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpFirst" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;a href="http://www.nstalker.com/"&gt;&lt;b&gt;&lt;i&gt;N-Stalker&lt;/i&gt;&lt;/b&gt; &lt;b&gt;&lt;i&gt;Commercial Edition&lt;/i&gt;&lt;/b&gt;&lt;/a&gt; (N-Stalker) &lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;a href="http://www.mcafee.com/us/products/vulnerability-manager.aspx"&gt;&lt;b&gt;&lt;i&gt;McAfee Vulnerability Manager&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt; &lt;/i&gt;&lt;/b&gt;(McAfee / Foundstone)&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;a href="http://www.rapid7.com/products/nexpose-enterprise-edition.jsp"&gt;&lt;b&gt;&lt;i&gt;NeXpose Enterprise Edition Web Application Scanning Features&lt;/i&gt;&lt;/b&gt;&lt;/a&gt; (Rapid7)&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;a href="http://www.eeye.com/Products/Retina/Web-Security-Scanner.aspx"&gt;&lt;b&gt;&lt;i&gt;Retina Web Application Scanner&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt; &lt;/i&gt;&lt;/b&gt;(eEye Digital Security)&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;a href="http://www.ncircle.com/index.php?s=products_webapp360"&gt;&lt;b&gt;&lt;i&gt;WebApp360&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt; &lt;/i&gt;&lt;/b&gt;(NCircle)&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;a href="http://www.coresecurity.com/content/web-app-pro"&gt;&lt;b&gt;&lt;i&gt;Core Impact Pro Web Application Scanning Features&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt; &lt;/i&gt;&lt;/b&gt;(Core Impact)&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;a href="http://www.parasoft.com/jsp/products/article.jsp?label=product_info_WebKing"&gt;&lt;b&gt;&lt;i&gt;Parasoft Web Application Scanning Features&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt; &lt;/i&gt;&lt;/b&gt;(a.k.a &lt;b&gt;&lt;i&gt;WebKing, &lt;/i&gt;&lt;/b&gt;by Parasoft)&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;a href="http://www.dbappsecurity.com/webscan.html"&gt;&lt;b&gt;&lt;i&gt;MatriXay Web Application Scanner&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt; &lt;/i&gt;&lt;/b&gt;(DBAppSecurity)&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;a href="http://www.buyservers.net/falcove.htm"&gt;&lt;b&gt;&lt;i&gt;Falcove&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt; &lt;/i&gt;&lt;/b&gt;(BuyServers ltd, currently Unmaintained)&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpLast" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;a href="http://www.safe3.com.cn/en/safe3wvs.htm"&gt;&lt;b&gt;&lt;i&gt;Safe3WVS 9.2 Commercial Edition&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt; &lt;/i&gt;&lt;/b&gt;(Safe3 Network Center)&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;The following &lt;b&gt;&lt;i&gt;open source&lt;/i&gt;&lt;/b&gt; web application vulnerability scanners were &lt;b&gt;&lt;i&gt;not included&lt;/i&gt; &lt;/b&gt;in the benchmark, mainly due to time restrictions, but will be included in future benchmarks:&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;u&gt;Open Source Scanners not included in this benchmark&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpFirst" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;a href="http://sourceforge.net/projects/rabbit-vs/"&gt;&lt;b&gt;&lt;i&gt;Rabbit VS&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;a href="http://sourceforge.net/projects/spacemonkey/"&gt;&lt;b&gt;&lt;i&gt;Spacemonkey&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;a href="http://sourceforge.net/projects/kayra/"&gt;&lt;b&gt;&lt;i&gt;Kayra&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;a href="http://code.google.com/p/2gwvs/"&gt;&lt;b&gt;&lt;i&gt;2gwvs&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;a href="http://sourceforge.net/projects/webarmy/"&gt;&lt;b&gt;&lt;i&gt;Webarmy&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;a href="http://sourceforge.net/projects/springenwerk/"&gt;&lt;b&gt;&lt;i&gt;springenwerk&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;a href="http://code.google.com/p/mopest/"&gt;&lt;b&gt;&lt;i&gt;Mopset 2&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;a href="http://ha.ckers.org/blog/20060921/xssfuzz-released/"&gt;&lt;b&gt;XSSFuzz 1.1&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;a href="http://sourceforge.net/projects/witchxtool-v10/"&gt;&lt;b&gt;&lt;i&gt;Witchxtoolv&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;a href="http://sourceforge.net/projects/php-injector/"&gt;&lt;b&gt;&lt;i&gt;PHP-Injector&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;a href="http://www.whiteacid.org/xss_assistant.user.js"&gt;&lt;b&gt;XSS Assistant&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;Fiddler &lt;/i&gt;&lt;/b&gt;&lt;a href="http://www.autosectools.com/Page/Fiddler-XSS-Inspector-Overview"&gt;&lt;b&gt;&lt;i&gt;XSSInspector&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt;/&lt;/i&gt;&lt;/b&gt;&lt;a href="http://sourceforge.net/projects/xsrfinspector/"&gt;&lt;b&gt;&lt;i&gt;XSRFInspector&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt; Plugins&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;a href="http://www.gnucitizen.org/blog/javascript-xss-scanner/"&gt;&lt;b&gt;GNUCitizen JAVASCRIPT XSS SCANNER&lt;/b&gt;&lt;/a&gt;&lt;b&gt; &lt;/b&gt;- since WebSecurify, a more advanced tool from the same vendor is already tested in the benchmark.&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpLast" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;Vulnerability Scanner 1.0 (by cmiN, RST) &lt;/b&gt;- since the source code contained traces for remotely downloaded RFI lists from locations that do not exist anymore. &lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;The benchmark focused on web application scanners that are able to detect either Reflected XSS or SQL Injection vulnerabilities, can be locally installed, and are also able to scan multiple URLs in the same execution.&lt;/div&gt;&lt;div class="MsoNormal"&gt;As a result, the test &lt;b&gt;did not include&lt;/b&gt; the following types of tools:&lt;/div&gt;&lt;div class="MsoListParagraphCxSpFirst" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;Online Scanning Services&lt;/u&gt; &lt;/b&gt;– Online applications that remotely scan applications, including (but not limited to) Appscan On Demand (IBM), Click To Secure, QualysGuard Web Application Scanning (Qualys), Sentinel (WhiteHat), Veracode (Veracode), VUPEN Web Application Security Scanner (VUPEN Security), WebInspect (online service - HP), WebScanService (Elanize KG), Gamascan (GAMASEC – currently offline), Cloud Penetrator (Secpoint), &amp;nbsp;Zero Day Scan, DomXSS Scanner, etc.&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;Scanners without RXSS / SQLi detection features&lt;/u&gt;&lt;/b&gt;&lt;u&gt;:&lt;/u&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;a href="http://code.google.com/p/dominator/downloads/list"&gt;&lt;b&gt;Dominator&lt;/b&gt;&lt;/a&gt;&lt;b&gt; &lt;/b&gt;(Firefox Plugin)&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;a href="http://code.google.com/p/fimap/"&gt;&lt;b&gt;fimap&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;a href="http://code.google.com/p/lfimap/"&gt;&lt;b&gt;lfimap&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;a href="http://packetstormsecurity.org/files/view/95146/phpbbrfi-scanner.txt"&gt;&lt;b&gt;phpBB-RFI Scanner&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;a href="http://dotdotpwn.sectester.net/"&gt;&lt;b&gt;DotDotPawn&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;a href="http://sourceforge.net/projects/lfi/"&gt;&lt;b&gt;LFI (Library-level Fault Injector)&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;a href="http://packetstormsecurity.org/files/view/97149/lfi_scanner.py.txt"&gt;&lt;b&gt;lfi-scanner&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;a href="http://packetstormsecurity.org/files/view/102848/lfi-scanner-ver4.0.pl.txt"&gt;&lt;b&gt;LFI-Scanner&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;a href="http://dl.packetstormsecurity.net/UNIX/scanners/lfi-rfi2.txt"&gt;&lt;b&gt;lfi-rfi2&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;LFI/RFI Checker (astalavista)&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;a href="https://www.owasp.org/index.php/Category:OWASP_CSRFTester_Project"&gt;&lt;b&gt;CSRF Tester&lt;/b&gt;&lt;/a&gt;&lt;b&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;etc&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;Passive Scanners (response analysis without verification)&lt;/u&gt;&lt;/b&gt;&lt;u&gt;:&lt;/u&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;a href="http://websecuritytool.codeplex.com/"&gt;&lt;b&gt;Watcher&lt;/b&gt;&lt;/a&gt;&lt;b&gt; (Fiddler Plugin by Casaba Security)&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;a href="https://www.owasp.org/index.php/Category:OWASP_Skavenger_Project"&gt;&lt;b&gt;Skavanger&lt;/b&gt;&lt;/a&gt;&lt;b&gt; (OWASP)&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;a href="https://www.owasp.org/index.php/Category:OWASP_Pantera_Web_Assessment_Studio_Project"&gt;&lt;b&gt;Pantera&lt;/b&gt;&lt;/a&gt;&lt;b&gt; (OWASP)&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;a href="http://code.google.com/p/ratproxy/"&gt;&lt;b&gt;Ratproxy&lt;/b&gt;&lt;/a&gt;&lt;b&gt; (Google)&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;a href="http://www.contextis.co.uk/resources/tools/cat/"&gt;&lt;b&gt;CAT The Manual Application Proxy&lt;/b&gt;&lt;/a&gt;&lt;b&gt; (Context)&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;etc&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;Scanners of specific products or services (CMS scanners, Web Services Scanners, etc)&lt;/u&gt;&lt;/b&gt;&lt;u&gt;:&lt;/u&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;WSDigger&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;Sprajax&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;ScanAjax&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;Joomscan&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;wpscan&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;Joomlascan&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;Joomsq&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;WPSqli&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;etc&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;u&gt;Web Application Scanning Tools which are using&lt;b&gt; Dynamic Runtime Analysis&lt;/b&gt;:&lt;/u&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;PuzlBox &lt;/b&gt;(the free version was removed from the web site, and is now sold as a commercial product named &lt;a href="http://www.autosectools.com/Software"&gt;PHP Vulnerability Hunter&lt;/a&gt;)&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;a href="http://code.google.com/p/inspathx/"&gt;&lt;b&gt;Inspathx&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;etc&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;Uncontrollable Scanners&lt;/u&gt;&lt;/b&gt; - scanners that can’t be controlled or restricted to scan a single site, since they either receive the list of URLs to scan from Google Dork, or continue and scan external sites that are linked to the tested site. This list currently includes the following tools (and might include more):&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;Darkjumper 5.8 &lt;/b&gt;(scans additional external hosts that are linked to the given tested host)&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;Bako's SQL Injection Scanner&lt;/b&gt; &lt;b&gt;2.2&lt;/b&gt; (only tests sites from a google dork)&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;Serverchk&lt;/b&gt; (only tests sites from a google dork)&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;XSS Scanner &lt;/b&gt;by&lt;b&gt; Xylitol&lt;/b&gt; (only tests sites from a google dork)&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;Hexjector&lt;/b&gt; by&lt;b&gt; hkhexon &lt;/b&gt;– also falls into other categories&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;d0rk3r&lt;/b&gt; by &lt;b&gt;b4ltazar&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;etc&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;Deprecated Scanners&lt;/u&gt;&lt;/b&gt; - incomplete tools that were not maintained for a very long time. This list currently includes the following tools (and might include more):&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;Wpoison&lt;/b&gt; (development stopped in 2003, the new official version was never released, although the 2002 development version can be obtained by manually composing the sourceforge URL which does not appear in the web site- &lt;a href="http://sourceforge.net/projects/wpoison/files/"&gt;http://sourceforge.net/projects/wpoison/files/&lt;/a&gt; )&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;etc&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;De facto Fuzzers&lt;/u&gt;&lt;/b&gt; – tools that scan applications in a similar way to a scanner, but where the scanner attempts to conclude whether or not the application or is vulnerable (according to some sort of “intelligent” set of rules), the fuzzer simply collects abnormal responses to various inputs and behaviors, leaving the task of concluding to the human user. &lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;Lilith 0.4c/0.6a &lt;/b&gt;(both versions 0.4c and 0.6a were tested, and although the tool seems to be a scanner at first glimpse, it doesn’t perform any intelligent analysis on the results).&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;Spike proxy&lt;/b&gt; &lt;b&gt;1.48&lt;/b&gt; (although the tool has XSS and SQLi scan features, it acts like a fuzzer more then it acts like a scanner – it sends payloads of partial XSS and SQLi, and does not verify that the context of the returned output is sufficient for execution or that the error presented by the server is related to a database syntax injection, leaving the verification task for the user).&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;Fuzzers&lt;/u&gt;&lt;/b&gt; – scanning tools that lack the independent ability to conclude whether a given response represents a vulnerable location, by using some sort of verification method (this category includes tools such as JBroFuzz, Firefuzzer, Proxmon, st4lk3r, etc). Fuzzers that had at least one type of exposure that was verified were included in the benchmark (Powerfuzzer).&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;CGI Scanners&lt;/u&gt;:&lt;/b&gt; vulnerability scanners that focus on detecting hardening flaws and version specific hazards in web infrastructures (Nikto, Wikto, WHCC, st4lk3r, N-Stealth, etc)&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;Single URL Vulnerability Scanners&lt;/u&gt;&lt;/b&gt; - scanners that can only scan one URL at a time, or can only scan information from a google dork (uncontrollable).&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;Havij (by itsecteam.com)&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;Hexjector (by hkhexon)&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;Simple XSS Fuzzer [SiXFu] (by www.EvilFingers.com)&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;Mysqloit (by muhaimindz)&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;PHP Fuzzer (by RoMeO from DarkMindZ)&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;SQLi-Scanner (by Valentin Hoebel)&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;Etc.&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;Vulnerability Detection Assisting Tools&lt;/u&gt;&lt;/b&gt; – tools that aid in discovering a vulnerability, but do not detect the vulnerability themselves; for example:&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;a href="http://labs.securitycompass.com/exploit-me/"&gt;&lt;b&gt;Exploit-Me Suite&lt;/b&gt;&lt;/a&gt;&lt;b&gt; (XSS-Me, SQL Inject-Me, Access-Me) &lt;/b&gt;&amp;nbsp;&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;a href="http://xss.codeplex.com/wikipage?title=tutorial"&gt;&lt;b&gt;Fiddler X5s plugin&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;a href="https://chrome.google.com/webstore/detail/kkopfbcgaebdaklghbnfmjeeonmabidj"&gt;&lt;b&gt;XSSRays&lt;/b&gt;&lt;/a&gt;&lt;b&gt; (chrome Addon)&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;Exploiters&lt;/u&gt; - &lt;/b&gt;tools that can exploit vulnerabilities but have no independent ability to automatically detect vulnerabilities on a large scale. Examples:&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;MultiInjector&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;XSS-Proxy-Scanner&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;Pangolin&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;FGInjector&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;Absinth&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;Safe3 SQL Injector&lt;/b&gt; (an exploitation tool with scanning features (pentest mode) that are &lt;b&gt;not available&lt;/b&gt; in the free version).&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;etc&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;Exceptional Cases&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 72pt; text-indent: -18pt;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;SecurityQA Toolbar (iSec)&lt;/b&gt; – various lists and rumors include this tool in the collection of free/open-source vulnerability scanners, but I wasn’t able to obtain it from the vendor’s web site, or from any other legitimate source, so I’m not really sure it fits the “free to use” category.&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpLast" style="margin-left: 18pt; text-indent: -18pt;"&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097" name="_Toc300025819"&gt;&lt;/a&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097" name="_Ref281064634"&gt;&lt;b&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;31. &lt;/span&gt;&lt;/b&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;Appendix C – WAVSEP Scan Logs&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;The execution logs, installation steps and configuration used while scanning with the various tools are all described in the following report:&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;a href="http://sectooladdict-benchmarks.googlecode.com/files/Scan%20Log%20-%20WAVSEP%20Benchmark%202011.pdf"&gt;http://sectooladdict-benchmarks.googlecode.com/files/Scan%20Log%20-%20WAVSEP%20Benchmark%202011.pdf&lt;/a&gt; &lt;/div&gt;&lt;div class="MsoListParagraph" style="margin-left: 18pt; text-indent: -18pt;"&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097" name="_Toc300025820"&gt;&lt;/a&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097" name="_Ref281064854"&gt;&lt;b&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;32. &lt;/span&gt;&lt;/b&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;Appendix D – Scanners with Abnormal Behavior&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;The following appendix was published in my previous benchmark, but I decided to include in the current benchmark, mainly because I didn't manage to invest the time to get to the bottom of these mysteries, and didn't see any information on someone else that did.&lt;/div&gt;&lt;div class="MsoNormal"&gt;During the &lt;b&gt;current &amp;amp; previous&lt;/b&gt; assessment, parts of the source code of open source scanners and the HTTP communication of some of the scanners was analyzed; some tools behaved in an &lt;b&gt;abnormal&lt;/b&gt; manner that should be reported:&lt;/div&gt;&lt;div class="MsoListParagraphCxSpFirst" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;Priamos IP Address Lookup&lt;/i&gt;&lt;/b&gt; – The tool Priamos attempts to access “whatismyip.com” (or some similar site) whenever a scan is initiated (verified by channeling the communication through Burp proxy). This behavior might derive from a trojan horse that infected the content on the project web site, so I’m not jumping to any conclusions just yet.&lt;/div&gt;&lt;div class="MsoListParagraphCxSpLast" style="text-indent: -18pt;"&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;VulnerabilityScanner Remote RFI List Retrieval&lt;/i&gt;&lt;/b&gt; (listed in the scanners that were &lt;b&gt;not&lt;/b&gt; tested, appendix A, developed by a group called RST, &lt;a href="http://pastebin.com/f3c267935"&gt;http://pastebin.com/f3c267935&lt;/a&gt;) – In the source code of the tool VulnerabilityScanner (a python script), I found traces for remote access to external web sites for obtaining RFI lists (might be used to refer the user to external URLs listed in the list). I could not verify the purpose of this feature since I didn’t manage to activate the tool (yet); in theory, this could be a legitimate list update feature, but since all the lists the tool uses are hardcoded, I didn’t understand the purpose of the feature. Again, I’m &lt;b&gt;not&lt;/b&gt; jumping to any conclusions; this feature might be related to the tool’s initial design, which was not fully implemented due to various considerations.&lt;/div&gt;&lt;div class="MsoNormal"&gt;Although I did &lt;b&gt;not&lt;/b&gt; verify that any of these features is malicious in nature, these features and behaviors might be abused to compromise the security of the tester’s workstation (or to incriminate him in malicious actions), and thus, require additional investigation to disqualify this possibility.&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3792178847867987053-5660944376278622097?l=sectooladdict.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/n2tROxzHEQGXgnRS_7OwyaKK5Ko/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/n2tROxzHEQGXgnRS_7OwyaKK5Ko/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/n2tROxzHEQGXgnRS_7OwyaKK5Ko/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/n2tROxzHEQGXgnRS_7OwyaKK5Ko/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/SecurityToolsBenchmarking/~4/du9wzScKXkM" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://sectooladdict.blogspot.com/feeds/5660944376278622097/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://sectooladdict.blogspot.com/2011/08/commercial-web-application-scanner.html#comment-form" title="23 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3792178847867987053/posts/default/5660944376278622097?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3792178847867987053/posts/default/5660944376278622097?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SecurityToolsBenchmarking/~3/du9wzScKXkM/commercial-web-application-scanner.html" title="Commercial Web Application Scanner Benchmark" /><author><name>Shay-Chen</name><uri>http://www.blogger.com/profile/16490521389991462247</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="30" height="32" src="http://4.bp.blogspot.com/_59wTD1pGfP8/TRZdDx_oBiI/AAAAAAAAAAY/PKMwqsvGCLU/S220/n847114298_305931_3159.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-s17Pvrw01g8/Tjdz6D7bG5I/AAAAAAAAABQ/xDQza3-pcKw/s72-c/FeatureCount-Commercial.PNG" height="72" width="72" /><thr:total>23</thr:total><feedburner:origLink>http://sectooladdict.blogspot.com/2011/08/commercial-web-application-scanner.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CkQHQ3w9fSp7ImA9Wx9VEEg.&quot;"><id>tag:blogger.com,1999:blog-3792178847867987053.post-7571530788987583648</id><published>2011-01-25T14:00:00.000-08:00</published><updated>2011-01-26T05:58:52.265-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-01-26T05:58:52.265-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="benchmarking" /><category scheme="http://www.blogger.com/atom/ns#" term="the best web application vulnerability scanner" /><category scheme="http://www.blogger.com/atom/ns#" term="scanner" /><category scheme="http://www.blogger.com/atom/ns#" term="vulnerability scanner" /><category scheme="http://www.blogger.com/atom/ns#" term="security" /><category scheme="http://www.blogger.com/atom/ns#" term="web application scanner" /><category scheme="http://www.blogger.com/atom/ns#" term="security tools" /><category scheme="http://www.blogger.com/atom/ns#" term="conclusions" /><category scheme="http://www.blogger.com/atom/ns#" term="benchmark" /><title>Myth Breaker - The Best Open Source Web Application Vulnerability Scanner</title><content type="html">&lt;p class="MsoNormal"&gt;(The original benchmark post - comparison of 43 web application vulnerability scanners:&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;a href="http://sectooladdict.blogspot.com/2010/12/web-application-scanner-benchmark.html"&gt;http://sectooladdict.blogspot.com/2010/12/web-application-scanner-benchmark.html&lt;/a&gt;)&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;It’s been a couple of weeks since the initial benchmark was published, and I used that time to contact most of the vendors and to come to some conclusions, as to which tool combinations are ideal for each task;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;I believe that those of you that use these tools on a daily basis will find my conclusions interesting.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Please note that the conclusions refer to the condition of the tools in the day the benchmark was released (see the full explanation at the end of the post).&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;i&gt;&lt;u&gt;Glossary&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/i&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;AND&lt;/b&gt; – combining the tools is required to obtain the best results.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;OR&lt;/b&gt; – using either one of the tools will provide nearly identical results.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;AND/OR&lt;/b&gt; – it is currently unknown if combining them will provide additional benefits.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;SAFE scan&lt;/b&gt; – a scan method in which the tester can select which URLs to scan, in order to prevent the scanner from accessing links that could &lt;b&gt;delete&lt;/b&gt; data&lt;b&gt;, lock user accounts&lt;/b&gt; or cause any other unintentional hazard (generally requires the scanner to have a proxy/manual crawling/URL file parsing/pre-configured URL restriction module); Recommended while scanning the internal section of an application that resides in a production environment.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;UNSAFE scan&lt;/b&gt; – a scan method that scans all the URLs, without any restrictions or limitations; Recommended while scanning the public section of an application, and for scanning the internal section of an application that resides in the testing/development environment.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;u&gt;The Ideal Combination of Tools (Relevant to the release date of the initial benchmark – 26/12/2010):&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;(Constructed according to the cases detected by each tool, and according to tool capabilities and application scope restrictions)&lt;/p&gt;  &lt;table class="MsoTableGrid" border="1" cellspacing="0" cellpadding="0" style="border-collapse:collapse;border:none;mso-border-alt:solid windowtext .5pt;  mso-yfti-tbllook:1184;mso-padding-alt:0in 5.4pt 0in 5.4pt"&gt;  &lt;tbody&gt;&lt;tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes"&gt;   &lt;td width="160" valign="top" style="width:119.7pt;border:solid windowtext 1.0pt;   mso-border-alt:solid windowtext .5pt;background:#CCC0D9;mso-background-themecolor:   accent4;mso-background-themetint:102;padding:0in 5.4pt 0in 5.4pt"&gt;   &lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal"&gt;&lt;b&gt;&lt;u&gt;Scan Type &amp;amp; Target &lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td width="160" valign="top" style="width:119.7pt;border:solid windowtext 1.0pt;   border-left:none;mso-border-left-alt:solid windowtext .5pt;mso-border-alt:   solid windowtext .5pt;background:#CCC0D9;mso-background-themecolor:accent4;   mso-background-themetint:102;padding:0in 5.4pt 0in 5.4pt"&gt;   &lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal"&gt;&lt;b&gt;&lt;u&gt;Reflected XSS&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td width="160" valign="top" style="width:119.7pt;border:solid windowtext 1.0pt;   border-left:none;mso-border-left-alt:solid windowtext .5pt;mso-border-alt:   solid windowtext .5pt;background:#CCC0D9;mso-background-themecolor:accent4;   mso-background-themetint:102;padding:0in 5.4pt 0in 5.4pt"&gt;   &lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal"&gt;&lt;b&gt;&lt;u&gt;SQL Injection (MySQL)&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="mso-yfti-irow:1"&gt;   &lt;td width="160" valign="top" style="width:119.7pt;border:solid windowtext 1.0pt;   border-top:none;mso-border-top-alt:solid windowtext .5pt;mso-border-alt:solid windowtext .5pt;   padding:0in 5.4pt 0in 5.4pt"&gt;   &lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal"&gt;&lt;u&gt;Initial Public Scan&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/p&gt;   &lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal"&gt;Initial Scan on the Application’s Public (unauthenticated) Section &lt;/p&gt;   &lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal"&gt;(&lt;b&gt;Purpose:&lt;/b&gt; &lt;b&gt;gather as many “Low Hanging Fruit” exposures as possible   with a minimal amount of false positives&lt;/b&gt;)&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td width="160" valign="top" style="width:119.7pt;border-top:none;border-left:   none;border-bottom:solid windowtext 1.0pt;border-right:solid windowtext 1.0pt;   mso-border-top-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;   mso-border-alt:solid windowtext .5pt;padding:0in 5.4pt 0in 5.4pt"&gt;   &lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal"&gt;&lt;b&gt;Netsparker&lt;/b&gt; AND &lt;b&gt;Acunetix&lt;/b&gt; AND &lt;b&gt;N-Stalker&lt;/b&gt; AND &lt;b&gt;SkipFish&lt;/b&gt;&lt;/p&gt;   &lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal"&gt;(Nearly False Positive Free Combination)&lt;/p&gt;   &lt;/td&gt;   &lt;td width="160" valign="top" style="width:119.7pt;border-top:none;border-left:   none;border-bottom:solid windowtext 1.0pt;border-right:solid windowtext 1.0pt;   mso-border-top-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;   mso-border-alt:solid windowtext .5pt;padding:0in 5.4pt 0in 5.4pt"&gt;   &lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal"&gt;&lt;b&gt;ProxyStrike &lt;/b&gt;AND &lt;b&gt;WebCruiser&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/p&gt;   &lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal"&gt;(Nearly False Positive Free Combination)&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="mso-yfti-irow:2"&gt;   &lt;td width="160" valign="top" style="width:119.7pt;border:solid windowtext 1.0pt;   border-top:none;mso-border-top-alt:solid windowtext .5pt;mso-border-alt:solid windowtext .5pt;   padding:0in 5.4pt 0in 5.4pt"&gt;   &lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal"&gt;&lt;u&gt;Internal Scan - Unsafe&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/p&gt;   &lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal"&gt;The Application’s Internal (authenticated) Section &lt;/p&gt;   &lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td width="160" valign="top" style="width:119.7pt;border-top:none;border-left:   none;border-bottom:solid windowtext 1.0pt;border-right:solid windowtext 1.0pt;   mso-border-top-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;   mso-border-alt:solid windowtext .5pt;padding:0in 5.4pt 0in 5.4pt"&gt;   &lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal"&gt;&lt;b&gt;Netsparker&lt;/b&gt; AND &lt;b&gt;Acunetix&lt;/b&gt; AND &lt;b&gt;SkipFish&lt;/b&gt;&lt;/p&gt;   &lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal"&gt;(Nearly False Positive Free Combination)&lt;/p&gt;   &lt;/td&gt;   &lt;td width="160" valign="top" style="width:119.7pt;border-top:none;border-left:   none;border-bottom:solid windowtext 1.0pt;border-right:solid windowtext 1.0pt;   mso-border-top-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;   mso-border-alt:solid windowtext .5pt;padding:0in 5.4pt 0in 5.4pt"&gt;   &lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal"&gt;&lt;b&gt;Wapiti&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/p&gt;   &lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal"&gt;(Verification with other tools is recommended to reduce False Positives – &lt;b&gt;ProxyStrike &lt;/b&gt;AND &lt;b&gt;WebCruiser, &lt;/b&gt;In addition to one of the   following: W3AF/Andipaors/ZAP/ &lt;/p&gt;   &lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal"&gt;Netsparker/Sandcat/&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/p&gt;   &lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal"&gt;Oedipus)&lt;/p&gt;   &lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal"&gt;&lt;b&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/b&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="mso-yfti-irow:3"&gt;   &lt;td width="160" valign="top" style="width:119.7pt;border:solid windowtext 1.0pt;   border-top:none;mso-border-top-alt:solid windowtext .5pt;mso-border-alt:solid windowtext .5pt;   padding:0in 5.4pt 0in 5.4pt"&gt;   &lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal"&gt;&lt;u&gt;Internal Scan - Safe&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/p&gt;   &lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal"&gt;The Application’s Internal (authenticated) Section&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal"&gt;(&lt;b&gt;Method: scan internal application pages without activating any   delete, logout or other dangerous operations&lt;/b&gt;).&lt;/p&gt;   &lt;/td&gt;   &lt;td width="160" valign="top" style="width:119.7pt;border-top:none;border-left:   none;border-bottom:solid windowtext 1.0pt;border-right:solid windowtext 1.0pt;   mso-border-top-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;   mso-border-alt:solid windowtext .5pt;padding:0in 5.4pt 0in 5.4pt"&gt;   &lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal"&gt;&lt;b&gt;ZAP&lt;/b&gt; AND &lt;b&gt;W3AF&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/p&gt;   &lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal"&gt;(Safe combination with relatively efficient accuracy)&lt;/p&gt;   &lt;/td&gt;   &lt;td width="160" valign="top" style="width:119.7pt;border-top:none;border-left:   none;border-bottom:solid windowtext 1.0pt;border-right:solid windowtext 1.0pt;   mso-border-top-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;   mso-border-alt:solid windowtext .5pt;padding:0in 5.4pt 0in 5.4pt"&gt;   &lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal"&gt;&lt;b&gt;W3AF &lt;/b&gt;AND &lt;b&gt;Andiparos&lt;/b&gt;/&lt;b&gt;Paros&lt;/b&gt; AND&lt;b&gt; Oedipus &lt;/b&gt;AND&lt;b&gt;   ProxyStrike&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/p&gt;   &lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="mso-yfti-irow:4"&gt;   &lt;td width="160" valign="top" style="width:119.7pt;border:solid windowtext 1.0pt;   border-top:none;mso-border-top-alt:solid windowtext .5pt;mso-border-alt:solid windowtext .5pt;   padding:0in 5.4pt 0in 5.4pt"&gt;   &lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal"&gt;&lt;u&gt;Additional Public Scan&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/p&gt;   &lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal"&gt;Detect additional potential exposures that&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;require manual verification, and aren’t   covered by previous tools &lt;/p&gt;   &lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal"&gt;(Public Section)&lt;/p&gt;   &lt;/td&gt;   &lt;td width="160" valign="top" style="width:119.7pt;border-top:none;border-left:   none;border-bottom:solid windowtext 1.0pt;border-right:solid windowtext 1.0pt;   mso-border-top-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;   mso-border-alt:solid windowtext .5pt;padding:0in 5.4pt 0in 5.4pt"&gt;   &lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal"&gt;&lt;b&gt;ProxyStrike&lt;/b&gt; OR &lt;b&gt;Sandcat (Grabber &lt;/b&gt;detects 1-2 additional   POST cases - optional&lt;b&gt;)&lt;/b&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td width="160" valign="top" style="width:119.7pt;border-top:none;border-left:   none;border-bottom:solid windowtext 1.0pt;border-right:solid windowtext 1.0pt;   mso-border-top-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;   mso-border-alt:solid windowtext .5pt;padding:0in 5.4pt 0in 5.4pt"&gt;   &lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal"&gt;&lt;b&gt;Wapiti&lt;/b&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="mso-yfti-irow:5"&gt;   &lt;td width="160" valign="top" style="width:119.7pt;border:solid windowtext 1.0pt;   border-top:none;mso-border-top-alt:solid windowtext .5pt;mso-border-alt:solid windowtext .5pt;   padding:0in 5.4pt 0in 5.4pt"&gt;   &lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal"&gt;&lt;u&gt;2nd Internal – Unsafe&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/p&gt;   &lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal"&gt;Detect additional potential exposures that&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;require manual verification, and aren’t   covered by previous tools &lt;/p&gt;   &lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td width="160" valign="top" style="width:119.7pt;border-top:none;border-left:   none;border-bottom:solid windowtext 1.0pt;border-right:solid windowtext 1.0pt;   mso-border-top-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;   mso-border-alt:solid windowtext .5pt;padding:0in 5.4pt 0in 5.4pt"&gt;   &lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal"&gt;&lt;b&gt;ProxyStrike&lt;/b&gt; OR &lt;b&gt;Sandcat&lt;/b&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td width="160" valign="top" style="width:119.7pt;border-top:none;border-left:   none;border-bottom:solid windowtext 1.0pt;border-right:solid windowtext 1.0pt;   mso-border-top-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;   mso-border-alt:solid windowtext .5pt;padding:0in 5.4pt 0in 5.4pt"&gt;   &lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal"&gt;&lt;b&gt;Wapiti&lt;/b&gt;&lt;/p&gt;   &lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal"&gt;&lt;o:p&gt; &lt;/o:p&gt;(No substantial change, so there’s no need to run another scan)&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="mso-yfti-irow:6"&gt;   &lt;td width="160" valign="top" style="width:119.7pt;border:solid windowtext 1.0pt;   border-top:none;mso-border-top-alt:solid windowtext .5pt;mso-border-alt:solid windowtext .5pt;   padding:0in 5.4pt 0in 5.4pt"&gt;   &lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal"&gt;&lt;u&gt;2nd Internal – Safe&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/p&gt;   &lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal"&gt;Detect additional potential exposures that&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;require manual verification, and aren’t   covered by previous tools&lt;/p&gt;   &lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal"&gt;(&lt;b&gt;Method: scan internal application pages for additional exposure   instances without activating any delete, logout or other dangerous operations&lt;/b&gt;)&lt;/p&gt;   &lt;/td&gt;   &lt;td width="160" valign="top" style="width:119.7pt;border-top:none;border-left:   none;border-bottom:solid windowtext 1.0pt;border-right:solid windowtext 1.0pt;   mso-border-top-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;   mso-border-alt:solid windowtext .5pt;padding:0in 5.4pt 0in 5.4pt"&gt;   &lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal"&gt;&lt;b&gt;ProxyStrike&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td width="160" valign="top" style="width:119.7pt;border-top:none;border-left:   none;border-bottom:solid windowtext 1.0pt;border-right:solid windowtext 1.0pt;   mso-border-top-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;   mso-border-alt:solid windowtext .5pt;padding:0in 5.4pt 0in 5.4pt"&gt;   &lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal"&gt;&lt;b&gt;W3AF &lt;/b&gt;AND &lt;b&gt;Andiparos&lt;/b&gt;/&lt;b&gt;Paros&lt;/b&gt; AND&lt;b&gt; Oedipus &lt;/b&gt;AND&lt;b&gt;   ProxyStrike&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/p&gt;   &lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal"&gt;&lt;o:p&gt; &lt;/o:p&gt;(No substantial change, so there’s no need to run another scan)&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="mso-yfti-irow:7"&gt;   &lt;td width="479" colspan="3" valign="top" style="width:359.1pt;border:solid windowtext 1.0pt;   border-top:none;mso-border-top-alt:solid windowtext .5pt;mso-border-alt:solid windowtext .5pt;   background:#CCC0D9;mso-background-themecolor:accent4;mso-background-themetint:   102;padding:0in 5.4pt 0in 5.4pt"&gt;   &lt;p class="MsoNormal" align="center" style="margin-bottom:0in;margin-bottom:.0001pt;   text-align:center;line-height:normal;tab-stops:297.75pt"&gt;&lt;b&gt;&lt;u&gt;Complementary   Scan for Additional Exposures&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="mso-yfti-irow:8;mso-yfti-lastrow:yes"&gt;   &lt;td width="160" valign="top" style="width:119.7pt;border:solid windowtext 1.0pt;   border-top:none;mso-border-top-alt:solid windowtext .5pt;mso-border-alt:solid windowtext .5pt;   padding:0in 5.4pt 0in 5.4pt"&gt;   &lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal"&gt;&lt;u&gt;Complementary Scan&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/p&gt;   &lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal"&gt;Scan the applications with scanners that have a wider range of   features, to cover additional security flaws&lt;/p&gt;   &lt;/td&gt;   &lt;td width="319" colspan="2" valign="top" style="width:239.4pt;border-top:none;   border-left:none;border-bottom:solid windowtext 1.0pt;border-right:solid windowtext 1.0pt;   mso-border-top-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;   mso-border-alt:solid windowtext .5pt;padding:0in 5.4pt 0in 5.4pt"&gt;   &lt;p class="MsoNormal" style="margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal"&gt;&lt;b&gt;W3AF&lt;/b&gt; AND/OR &lt;b&gt;Arachni&lt;/b&gt; AND/OR &lt;b&gt;Skipfish&lt;/b&gt; AND/OR &lt;b&gt;Sandcat&lt;/b&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt; &lt;/tbody&gt;&lt;/table&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;u&gt;Notable Open Source &amp;amp; Freeware Tools – SQL Injection Detection&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;The highest SQLi detection ratio of open source &amp;amp; freeware tools belongs to &lt;b&gt;Wapiti&lt;/b&gt;, currently the undisputed winner in this category.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;A bit behind &lt;b&gt;Wapiti&lt;/b&gt; were &lt;b&gt;AndiParos&lt;/b&gt;, &lt;b&gt;Zapproxy&lt;/b&gt; and &lt;b&gt;Paros Proxy&lt;/b&gt; (all forks of the original Paros project), followed closely by &lt;b&gt;Netsparker&lt;/b&gt; and &lt;b&gt;W3AF (&lt;/b&gt;two tools that were prone to &lt;b&gt;less&lt;/b&gt; false positives test cases, compared&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;to all of the tools described so far - 30% compared to 40% or 50%).&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:10.0pt;line-height:115%"&gt;* it is important to mention that Netsparker CE 1.5 does &lt;b&gt;&lt;u&gt;not&lt;/u&gt;&lt;/b&gt; contain Netsparker’s Blind-SQL injection module (disabled in this version), only the regular SQL-Injection module and the Boolean SQL-Injection module.&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;However, we cannot ignore the fact that the following tools had pretty decent accuracy &lt;b&gt;with 0 false positives(!): &lt;/b&gt;WebCruiser (55.88%) and ProxyStrike (52.21%), making them &lt;b&gt;ideal&lt;/b&gt; tools for &lt;b&gt;an&lt;/b&gt; &lt;b&gt;initial scan &lt;/b&gt;(&lt;b&gt;Mini MySqlat0r&lt;/b&gt; and &lt;b&gt;Scrawler&lt;/b&gt; had 0 false positives as well, but with lower accuracy).&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;u&gt;Notable Open Source &amp;amp; Freeware Tools – XSS Detection&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;The Highest XSS detection ratio belongs to &lt;b&gt;Sandcat&lt;/b&gt;, which detected nearly 100% of the overall test-cases (although like ProxyStrike &amp;amp; Grabber, it was misled by a few extra false positive test cases).&lt;/p&gt;  &lt;p class="MsoNormal"&gt;The highest XSS detection ratio of open source tools (and 2nd best in total) belongs to &lt;b&gt;ProxyStrike &lt;/b&gt;(&lt;b&gt;Grabber &lt;/b&gt;detected&lt;b&gt; &lt;/b&gt;more POST test cases, but had a higher false positive ratio, and did not detect GET cases).&lt;/p&gt;  &lt;p class="MsoNormal"&gt;The best overall XSS detection ratio (while considering the low amount of false positives) belongs to &lt;b&gt;Netsparker CE &lt;/b&gt;(&lt;span style="font-size:9.0pt;line-height:115%;font-family:TTE4A0A428t00;mso-ascii-font-family: TTE4A0A428t00"&gt;63.64% and 3rd in the efficiency order, right after ProxyStrike)&lt;/span&gt;, followed closely by &lt;b&gt;N-Stalker&lt;/b&gt; and by &lt;b&gt;Acunetix&lt;/b&gt; &lt;b&gt;FE (&lt;/b&gt;and since &lt;b&gt;Skipfish&lt;/b&gt; and these tools “complete” missing test cases in each other, they are &lt;b&gt;ideal&lt;/b&gt; for initial scans, since they all have &lt;b&gt;0 false positives!&lt;/b&gt;).&lt;/p&gt;  &lt;p class="MsoNormal"&gt;The best overall XSS detection ratio (while considering the low amount of false positives) of open source tools belongs to &lt;b&gt;WebSecurify&lt;/b&gt;.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;The best HTTP GET XSS detection ratio (while considering the low amount of false positives) of open source tools belongs to &lt;b&gt;XSSer&lt;/b&gt;.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;The following open source tools had XSS detection modules that were free of false positives (while still having a relatively efficient detection ratio) – &lt;b&gt;Grendel-Scan (GET)&lt;/b&gt; and &lt;b&gt;Skipfish&lt;/b&gt; (&lt;b&gt;Secubat&lt;/b&gt; had 0 false positives as well, but its detection ratio was a bit lower).&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;u&gt;Notes&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;When using ProxyStrike for the initial scan, It’s probably best to use an &lt;b&gt;external&lt;/b&gt; spider instead of the built in spider (e.g. use ProxyStrike as an outgoing/upstream proxy for Burp Suite FE or Paros/ZAP/Andiparos and then use the spider feature of the external tool through ProxyStrike).&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;As mentioned before, the conclusions reflect the condition of the various tools in the date the initial benchmark was published. Since the benchmark, many vendors had released new versions (some even in response to the benchmark), so the list of conclusions &lt;b&gt;will &lt;/b&gt;change as soon as the next benchmark is released; I know for a fact that some vendors invested so much effort in improving their detection modules that some of the new versions get to nearly 100% detection ratio (but since I don’t have updated statistics, well have to wait).&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;u&gt;Conclusions&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;So… it seems that I didn't find “the best web application vulnerability scanner” after all… but I did find combinations of open source &amp;amp; freeware tools that get pretty good results.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;As I mentioned in previous posts, my work is only beginning.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Various open source vendors already released new versions that should be tested, tools that were improperly executed (or had a bug) should be retested as soon as their issues are mitigated, additional research led me to discover a couple of additional open source web application scanner projects, and at least one new open source web application scanner was released in the last couple of weeks (and I haven’t even mentioned commercial scanners).&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Time to get back to work… &lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3792178847867987053-7571530788987583648?l=sectooladdict.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/T_f_3acu3dwzbPXqDN9_Q0tiHeo/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/T_f_3acu3dwzbPXqDN9_Q0tiHeo/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/T_f_3acu3dwzbPXqDN9_Q0tiHeo/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/T_f_3acu3dwzbPXqDN9_Q0tiHeo/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/SecurityToolsBenchmarking/~4/g_9AmmweLYU" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://sectooladdict.blogspot.com/feeds/7571530788987583648/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://sectooladdict.blogspot.com/2011/01/myth-breaker-best-open-source-web.html#comment-form" title="12 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3792178847867987053/posts/default/7571530788987583648?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3792178847867987053/posts/default/7571530788987583648?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SecurityToolsBenchmarking/~3/g_9AmmweLYU/myth-breaker-best-open-source-web.html" title="Myth Breaker - The Best Open Source Web Application Vulnerability Scanner" /><author><name>Shay-Chen</name><uri>http://www.blogger.com/profile/16490521389991462247</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="30" height="32" src="http://4.bp.blogspot.com/_59wTD1pGfP8/TRZdDx_oBiI/AAAAAAAAAAY/PKMwqsvGCLU/S220/n847114298_305931_3159.jpg" /></author><thr:total>12</thr:total><feedburner:origLink>http://sectooladdict.blogspot.com/2011/01/myth-breaker-best-open-source-web.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEEBRnw_fSp7ImA9Wx9XF0U.&quot;"><id>tag:blogger.com,1999:blog-3792178847867987053.post-7552689011395458988</id><published>2011-01-11T14:51:00.000-08:00</published><updated>2011-01-11T14:57:37.245-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-01-11T14:57:37.245-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="clarification" /><category scheme="http://www.blogger.com/atom/ns#" term="followup" /><title>Follow Up &amp; Clarifications</title><content type="html">&lt;p class="MsoNormal"&gt;I’ve been pretty busy trying to contact the various vendors and deliver materials that they can use for QA &amp;amp; development, and I must mention that so far every vendor / developer that I have contacted responded kindly, and many of them responded with excitement and already started enhancing their tool (which is GREAT news for all of us).&lt;/p&gt;  &lt;p class="MsoNormal"&gt;I managed to find the time to contact about 18 vendors, and hopefully I’ll manage to contact more in the following weeks (25 left to go). This process requires me to analyze the benefits of the tools of each vendor, and as a result, is more time consuming then I originally thought; however, thanks to this process, I believe that soon it will lead me to some additional interesting conclusions and insights, which I’ll publish separately.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;In the process of contacting the vendors, I realized that I have neglected some of my duties and forgot to publish some &lt;b&gt;important clarifications&lt;/b&gt;:&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Although the test cases implemented as “False Positives” are by no means vulnerable to SQL Injection or Cross Site Scripting, some of the test cases still fall into a category of information that should be presented in the report under the context of another type of exposure:&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;!--[if !supportLists]--&gt;&lt;p&gt;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.0in;mso-add-space: auto;text-indent:-.25in;mso-list:l0 level2 lfo1"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-family:&amp;quot;Courier New&amp;quot;;mso-fareast-font-family:&amp;quot;Courier New&amp;quot;"&gt;&lt;span style="mso-list:Ignore"&gt;o&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;Pages that disclose sensitive information / exceptions (some SQL Injection False Positive test cases that are meant to simulate SQL errors that do not derive from user originating input, such as connection failures, etc).&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="margin-left:1.0in;mso-add-space: auto;text-indent:-.25in;mso-list:l0 level2 lfo1"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-family:&amp;quot;Courier New&amp;quot;;mso-fareast-font-family:&amp;quot;Courier New&amp;quot;"&gt;&lt;span style="mso-list:Ignore"&gt;o&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;Pages that fall under the category of insecure coding practices (some of the False RXSS &amp;amp; SQLi pages).&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Some tools are still in early beta, and some didn’t even publish an official alpha version (aidSQL, iScan, and some of the other tools that had zero accuracy); the accuracy of these tools was not really audited, due to limitations or bugs that will surely be mitigated in the future versions. The benchmark will be updated as soon as the tool vendors release a new stable version.&lt;/li&gt;&lt;li&gt;The execution of certain tools which were reported as having zero accuracy failed due to bugs or configuration flaws, and not accuracy related issues; These tools include SQLMap, aidSQL, VulnDetector, and a couple of more; I’m currently working with the various vendors to figure out how to execute them properly (or how to work around the specific bugs), so the test will actually reflect their accuracy level.&lt;/li&gt;&lt;/ul&gt;&lt;!--[if !supportLists]--&gt;&lt;p&gt;&lt;/p&gt;    &lt;p class="MsoNormal"&gt;As a result, I believe that the next benchmark is going to be performed sooner then I planned;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;It will probably include the same results alongside the corrected scans of the tools that had execution issues (particularly SQL tools), and maybe additional enhancements (under discussion).&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;I wish you all a Happy New Year :)&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3792178847867987053-7552689011395458988?l=sectooladdict.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/HmrCozjWfu8Qg5pVPAKaJnCQd00/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/HmrCozjWfu8Qg5pVPAKaJnCQd00/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/HmrCozjWfu8Qg5pVPAKaJnCQd00/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/HmrCozjWfu8Qg5pVPAKaJnCQd00/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/SecurityToolsBenchmarking/~4/KSbntxGrxJY" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://sectooladdict.blogspot.com/feeds/7552689011395458988/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://sectooladdict.blogspot.com/2011/01/follow-up-clarifications.html#comment-form" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3792178847867987053/posts/default/7552689011395458988?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3792178847867987053/posts/default/7552689011395458988?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SecurityToolsBenchmarking/~3/KSbntxGrxJY/follow-up-clarifications.html" title="Follow Up &amp; Clarifications" /><author><name>Shay-Chen</name><uri>http://www.blogger.com/profile/16490521389991462247</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="30" height="32" src="http://4.bp.blogspot.com/_59wTD1pGfP8/TRZdDx_oBiI/AAAAAAAAAAY/PKMwqsvGCLU/S220/n847114298_305931_3159.jpg" /></author><thr:total>1</thr:total><feedburner:origLink>http://sectooladdict.blogspot.com/2011/01/follow-up-clarifications.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CEUHQXY8cSp7ImA9WhdTEEk.&quot;"><id>tag:blogger.com,1999:blog-3792178847867987053.post-7398976696397938525</id><published>2010-12-26T03:26:00.000-08:00</published><updated>2011-07-07T05:37:10.879-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-07-07T05:37:10.879-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="vulnerable application" /><category scheme="http://www.blogger.com/atom/ns#" term="benchmarking" /><category scheme="http://www.blogger.com/atom/ns#" term="security benchmark" /><category scheme="http://www.blogger.com/atom/ns#" term="scanner" /><category scheme="http://www.blogger.com/atom/ns#" term="vulnerability scanner" /><category scheme="http://www.blogger.com/atom/ns#" term="web application scanner" /><category scheme="http://www.blogger.com/atom/ns#" term="benchmark" /><title>Web Application Scanner Benchmark (v1.0)</title><content type="html">&lt;div class="MsoNormal"&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Well, it’s finally done. What I originally thought will only take me a couple of days, and found myself doing for the past 9 months is finally ready for release, and it’s titled:&lt;/div&gt;&lt;div align="center" class="MsoNormal" style="text-align: center;"&gt;&lt;b&gt;&lt;span style="font-size: 44pt; line-height: 115%;"&gt;Web Application Scanners Accuracy Assessment&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div align="center" class="MsoNormal" style="text-align: center;"&gt;&lt;b&gt;&lt;span style="font-size: 30pt; line-height: 115%;"&gt;Freeware &amp;amp; Open Source Scanners&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Comparison &amp;amp; Assessment of &lt;b&gt;43&lt;/b&gt; Free &amp;amp; Open Source Black Box Web Application Vulnerability Scanners&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;i&gt;By Shay Chen&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;i&gt;Information Security Consultant, Researcher and Instructor&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;a href="http://sectooladdict.blogspot.com/"&gt;http://sectooladdict.blogspot.com/&lt;/a&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;sectooladdict -$at$- gmail -$dot$- com&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;i&gt;December 2010&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;i&gt;Assessment Environment:&lt;/i&gt;&lt;/b&gt; WAVSEP 1.0 (&lt;a href="http://code.google.com/p/wavsep/"&gt;http://code.google.com/p/wavsep/&lt;/a&gt;)&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;&lt;span class="Apple-style-span" style="-webkit-text-decorations-in-effect: none; font-size: small; font-weight: normal; line-height: normal;"&gt;&lt;b&gt;&lt;u&gt;&lt;span style="color: #999999; font-size: 18pt; line-height: 27px;"&gt;Introduction&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;I’ve been collecting them for years, trying to get my hands on anything that was released within the genre.  It started as a necessity, transformed into a hobby, and eventually turned into a relatively huge collection… But that’s when the problems started.&lt;/div&gt;&lt;div class="MsoNormal"&gt;While back in 2005 I could barely find freeware web application scanners, by 2008 I had SO MANY of them that I couldn’t decide which ones to use. By 2010 the collection became so big that I came to the realization that I HAVE to choose.&lt;/div&gt;&lt;div class="MsoNormal"&gt;I started searching for benchmarks in the field, but at the time, only located benchmarks the focused on comparing commercial web application scanners (with the exception of one benchmark that also covered 3 open source web application scanners), leaving the freeware &amp;amp; open source scanners in an uncharted territory;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;a href="http://www.virtualforge.de/index.php/en/library/white-papers/web-application-vulnerability-scanners-a-benchmark_en.html"&gt;http://www.virtualforge.de/index.php/en/library/white-papers/web-application-vulnerability-scanners-a-benchmark_en.html&lt;/a&gt; (Anonymous scanners)&lt;/li&gt;
&lt;li&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;a href="http://anantasec.blogspot.com/2009/01/web-vulnerability-scanners-comparison.html"&gt;http://anantasec.blogspot.com/2009/01/web-vulnerability-scanners-comparison.html&lt;/a&gt; (commercial scanners)&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.cs.ucsb.edu/~adoupe/static/black-box-scanners-dimva2010.pdf"&gt;http://www.cs.ucsb.edu/~adoupe/static/black-box-scanners-dimva2010.pdf&lt;/a&gt; (mostly commercial, but including W3AF, paros and grendel-scan)&lt;/li&gt;
&lt;li&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;a href="http://ha.ckers.org/files/Accuracy_and_Time_Costs_of_Web_App_Scanners.pdf"&gt;http://ha.ckers.org/files/Accuracy_and_Time_Costs_of_Web_App_Scanners.pdf&lt;/a&gt; (commercial scanners)&lt;/li&gt;
&lt;/ul&gt;&lt;div class="MsoNormal"&gt;By 2010 I had over 50 tools, so I eventually decided to test them myself using the same model used in previous benchmarks (&lt;b&gt;a big BIG mistake&lt;/b&gt;).&lt;/div&gt;&lt;div class="MsoNormal"&gt;I initially tested the various tools against a vulnerable ASP.net web application and came to conclusions as to which tool is the “best”… and if it weren’t for my curiosity, that probably would have been the end of it and my conclusions might have mislead many more.&lt;/div&gt;&lt;div class="MsoNormal"&gt;I decided to test the tools against another vulnerable web application, just to make sure the results were consistent, and arbitrarily selected “&lt;b&gt;Insecure Web App&lt;/b&gt;” (a vulnerable JEE web application) as the second target… and to my surprise, the results of the tests against it were VERY different.&lt;/div&gt;&lt;div class="MsoNormal"&gt;Some of the Tools that were efficient in the test against the vulnerable ASP.net application (which will stay anonymous for the time being) didn’t function very well and missed many exposures, while some of the tools that I previously classified as “useless” detected exposures that NONE of the other tools found.&lt;/div&gt;&lt;div class="MsoNormal"&gt;After performing an in-depth analysis for the different vulnerabilities in the tested applications, I came to the conclusion that although the applications included a similar classification of exposures (SQL Injection, RXSS, Information disclosure, etc), the properties and restrictions in the exposure instances were VERY different in each application.&lt;/div&gt;&lt;div class="MsoNormal"&gt;That’s when it dawned on me that the different methods that tools use to discover security exposures might be efficient for detecting certain common instances of a vulnerability while simultaneously being inefficient for detecting other instances of the same vulnerability, and that tools with “lesser” algorithms or different approaches (which might appear to be less effective at first) might be able to fill the gap.&lt;/div&gt;&lt;div class="MsoNormal"&gt;So the question remains… Which tool is the best? Is there one that surpasses the others? Can there be only one?&lt;/div&gt;&lt;div class="MsoNormal"&gt;I decided to find out…&lt;/div&gt;&lt;div class="MsoNormal"&gt;It started as a bunch of test cases, and ended as a project containing hundreds of scenarios (currently focusing on Reflected XSS and SQL Injection) that will hopefully help in unveiling the mystery.&lt;/div&gt;&lt;div class="MsoNormal"&gt;(A PDF version of this benchmark will be available shortly in the WAVSEP project home page at &lt;a href="http://code.google.com/p/wavsep/"&gt;http://code.google.com/p/wavsep/&lt;/a&gt;)&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal" style="mso-outline-level: 1;"&gt;&lt;b&gt;&lt;u&gt;&lt;span style="color: #999999; font-size: 18pt; line-height: 115%;"&gt;Thank-You Note&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Before I’ll describe project WAVSEP and the results of the first scanner benchmark performed using it, I’d like to thank all the tool developers and vendors that shared freeware &amp;amp; open source tools with the community over the years; if it weren’t for the long hours they’ve invested and the generosity they had to share their creations, then my job (and that of others in my profession) would have been much harder.&lt;/div&gt;&lt;div class="MsoNormal"&gt;I’d like to express my sincere gratitude for Shimi Volkovich (&lt;a href="http://il.linkedin.com/pub/shimi-volkovich/20/173/263"&gt;http://il.linkedin.com/pub/shimi-volkovich/20/173/263&lt;/a&gt;), for taking the time to design the logo I’ll soon be using.&lt;/div&gt;&lt;div class="MsoNormal"&gt;I would also like to thank all the sources that helped me gather the list of scanners over the years, including (but not limited to) information security sources such as &lt;b&gt;PenTestIT&lt;/b&gt; (&lt;a href="http://www.pentestit.com/"&gt;http://www.pentestit.com/&lt;/a&gt;), &lt;b&gt;Security Sh3ll&lt;/b&gt; (&lt;a href="http://security-sh3ll.blogspot.com/"&gt;http://security-sh3ll.blogspot.com/&lt;/a&gt;), &lt;b&gt;Security Database&lt;/b&gt; (&lt;a href="http://www.security-database.com/"&gt;http://www.security-database.com/&lt;/a&gt;), &lt;b&gt;Darknet&lt;/b&gt; (&lt;a href="http://www.darknet.org.uk/"&gt;http://www.darknet.org.uk/&lt;/a&gt;), &lt;b&gt;Packet Storm&lt;/b&gt; (&lt;a href="http://packetstormsecurity.org/"&gt;http://packetstormsecurity.org/&lt;/a&gt;), &lt;b&gt;Help Net Security&lt;/b&gt; (&lt;a href="http://www.net-security.org/"&gt;http://www.net-security.org/&lt;/a&gt;), &lt;b&gt;Astalavista&lt;/b&gt; (&lt;a href="http://www.astalavista.com/"&gt;http://www.astalavista.com/&lt;/a&gt;), &lt;b&gt;Google&lt;/b&gt; (of course) and many others that I have neglected to mention due to my failing memory.&lt;/div&gt;&lt;div class="MsoNormal"&gt;I hope that the conclusions, ideas, information and payloads presented in this research (and the benchmarks and tools that will follow) will benefit all vendors, and specifically help the open source community to locate code sections that all tool vendors could assimilate to improve their products; to that end I’ll try and contact each vendor in the next few weeks, in order to notify them on source codes that could be assimilated in their product to make it even better (on the basis of development technology and the license of each code section).&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;u&gt;&lt;span style="color: #999999; font-size: 18pt; line-height: 115%;"&gt;Phase I – The “Traditional” Benchmark&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;i&gt;Testing the scanners against vulnerable training &amp;amp; real life applications.&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;As I mentioned earlier, In the initial phase of the benchmark, I have tested the various scanners in front of different vulnerable “training” applications (&lt;b&gt;&lt;i&gt;OWASP InsecureWebApp&lt;/i&gt;&lt;/b&gt;, &lt;b&gt;&lt;i&gt;a vulnerable .Net Application&lt;/i&gt;&lt;/b&gt; and a simple vulnerable application I have written myself), and tested many of them against real life applications (ASP.Net applications, Java applications based on Spring, Web application written in PHP, etc). &lt;/div&gt;&lt;div class="MsoNormal"&gt;I decided not to publish the results just yet, and for a damn good reason which I did not predict in the first place; nevertheless, the initial process was &lt;b&gt;&lt;u&gt;very&lt;/u&gt;&lt;/b&gt; helpful because it helped me to learn about the different aspects of the tools: &lt;b&gt;features&lt;/b&gt;, &lt;b&gt;vulnerability list&lt;/b&gt;, &lt;b&gt;coverage&lt;/b&gt;, &lt;b&gt;installation processes&lt;/b&gt;, &lt;b&gt;configuration methods&lt;/b&gt;, &lt;b&gt;usage&lt;/b&gt;, &lt;b&gt;adaptability&lt;/b&gt;, &lt;b&gt;stability&lt;/b&gt;, &lt;b&gt;performance&lt;/b&gt; and a bunch of other aspects.&lt;/div&gt;&lt;div class="MsoNormal"&gt;I have found &lt;b&gt;VERY&lt;/b&gt; interesting results that prove that certain old scanners might provide great benefits in many cases that many modern projects will &lt;b&gt;not&lt;/b&gt; handle properly.&lt;/div&gt;&lt;div class="MsoNormal"&gt;The process also enabled me to &lt;b&gt;&lt;u&gt;verify&lt;/u&gt;&lt;/b&gt; the support of the various tools in their proclaimed features (which I have literally done for the vast majority of the tools, using proxies, sniffers and other experiments), and even get a general measure of their accuracy and capabilities.&lt;/div&gt;&lt;div class="MsoNormal"&gt;However, after seeing the results diversity in different applications and technologies, and after dealing with the countless challenges that came along the way, I have discovered several limitations and even a &lt;b&gt;fundamental flaw&lt;/b&gt; in testing the accuracy, coverage, stability and performance of scanners in this manner (I have managed to test around 50 free and open source scanners by this point, as insane and unbelievable as this number might sound);&lt;/div&gt;&lt;div class="MsoNormal"&gt;We may be able to estimate the general capabilities of a scanner from the amount of REAL exposures that it located, the amount of exposures that it missed (false negatives) and from the amount of FALSE exposures (false positives) it identified as security exposures, BUT on the other hand, the output of such a process will very much depend on the type of exposures that exist in the tested application, how much each scanner is adapted to the tested application technology and which private cases of exposures and barriers exist in the tested application.&lt;/div&gt;&lt;div class="MsoNormal"&gt;A scanner that will be very useful for scanning PHP web sites might completely fail the task of scanning a ASP.Net web application, and a tool perfectly suited for that task might crash when faced with certain application behaviors, or be useless in detecting a private case of a specific vulnerability that is not supported by the tool.&lt;/div&gt;&lt;div class="MsoNormal"&gt;I guess what I’m trying to say is this:&lt;/div&gt;&lt;div class="MsoNormal"&gt;There are &lt;b&gt;many forms&lt;/b&gt; and variations to each security exposure, and in order to prove my point, I’ll use the example of reflected cross site scripting;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Locations vulnerable to reflected cross site scripting might appear in many forms; they may require the attacker to send a whole HTML tag as a part of the crafted link, require the injection of an HTML event (in case the input-affected-output is printed in the context of a tag and the usage of tag-composing-characters is restricted), they may appear in locations vulnerable to SQL injection (and thus restrict the use of certain characters, or even require the usage of initial payloads that “disable” the SQL injection vulnerability first), require browser specific payloads or even direct injection of javascript/vbscript (in case the context is within a script tag, certain HTML events or even in the context of certain properties), and these cases are only a fragment of the whole list!&lt;/div&gt;&lt;div class="MsoNormal"&gt;So, how can the tester know which of these cases is handled by each scanner from the figures and numbers presented in a general benchmark?&lt;/div&gt;&lt;div class="MsoNormal"&gt;I believe he &lt;b&gt;can’t&lt;/b&gt;. No matter how solid the difference appears, he really &lt;b&gt;can’t&lt;/b&gt;.&lt;/div&gt;&lt;div class="MsoNormal"&gt;Such information may allow him to root out useless tools (tools that miss even the most obvious exposures), and even identify what appears to be a significant difference in the accuracy of locating certain exposure instances, but the latter case might have been very different if the tested applications would have been prone to certain exposure instances that are the specialty of a different scanner, or would have included a technological barrier that requires a specific feature or behavior to bypass.&lt;/div&gt;&lt;div class="MsoNormal"&gt;Thus, I have come to believe that the only way I could truly provide useful information to testers on the accuracy and coverage of freely available web application scanners is by writing detailed test cases for different exposures, starting with some core common exposures such as SQL Injection, cross site scripting and maybe a couple of others.&lt;/div&gt;&lt;div class="MsoNormal"&gt;And thus, I have ended up investing countless nights in the development of a new test-case based evaluation application, designed specifically to test the support of each tool for detecting MANY different cases of certain common exposures.&lt;/div&gt;&lt;div class="MsoNormal"&gt;The results of the original benchmark (against the vulnerable training web applications) will be published separately in a different article (since by now, many of them have been updated, and the results require modifications).&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;u&gt;&lt;span style="color: #999999; font-size: 18pt; line-height: 115%;"&gt;Phase II - Project WAVSEP&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;After documenting and testing the features of every free &amp;amp; open source web application scanner and scan script that I could get my hands on, I discovered that the most common features were &lt;b&gt;Reflected Cross Site Scripting (RXSS)&lt;/b&gt; and &lt;b&gt;SQL Injection (SQLi)&lt;/b&gt;. I decided to focus my initial efforts on these two vulnerabilities, and develop a platform that could truly evaluate how good each scanner is in &lt;b&gt;detecting&lt;/b&gt; them, which tool combinations provide the best results and which tool can bypass the largest amount of detection barriers.&lt;/div&gt;&lt;div class="MsoNormal"&gt;Project &lt;b&gt;WAVSEP&lt;/b&gt; (&lt;b&gt;Web Application Vulnerability Scanner Evaluation Project&lt;/b&gt;) was implemented as a set of vulnerable JSP pages; each page implementing a unique test case.&lt;/div&gt;&lt;div class="MsoNormal"&gt;A test case is defined as a unique combination of the following elements:&lt;/div&gt;&lt;div class="MsoListParagraphCxSpFirst" style="mso-list: l2 level1 lfo2; text-indent: -.25in;"&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;A certain instance of a given vulnerability.&lt;/li&gt;
&lt;li&gt;Attack vectors with certain input origins (either GET or POST values, and in the future, also URL/path, cookie, various headers, file upload content and other origins).&lt;/li&gt;
&lt;/ul&gt;&lt;div class="MsoNormal"&gt;Currently, only GET and POST attack vectors are covered, since most scanners support only GET and POST vectors (future versions of WAVSEP will include support for additional databases, additional response types, additional detection barriers, additional attack vector origins and additional vulnerabilities).&lt;/div&gt;&lt;div class="MsoNormal"&gt;Project WAVSEP currently consists of the following test cases:&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;span class="Apple-style-span"&gt;6&lt;/span&gt;4 Reflected XSS test cases (32 GET cases, 32 POST cases -&amp;gt; &lt;b&gt;66&lt;/b&gt; total vulnerabilities)&lt;/li&gt;
&lt;li&gt;130 SQL Injection test cases, most of them implemented for MySQL &amp;amp; MSSQL (65 GET cases, 65 POST Vases -&amp;gt; &lt;b&gt;136&lt;/b&gt; total vulnerabilities)&lt;/li&gt;
&lt;/ul&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 1.0in; mso-add-space: auto; mso-list: l8 level2 lfo3; text-indent: -.25in;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;The list of test cases includes vulnerable pages that respond with 500 HTTP errors, 200 HTTP Responses with erroneous text, 200 HTTP Responses with differentiation or completely identical 200 HTTP responses. &lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 1.0in; mso-add-space: auto; mso-list: l8 level2 lfo3; text-indent: -.25in;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;80 out of 136 cases are simple SQL injection test cases (500 &amp;amp; 200 erroneous HTTP responses), and 56 are Blind SQL Injection test cases (valid and identical 200 HTTP responses).&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="mso-list: l8 level1 lfo3; text-indent: -.25in;"&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;7 different categories of &lt;b&gt;false positive&lt;/b&gt; Reflected XSS vulnerabilities (GET OR POST).&lt;/li&gt;
&lt;li&gt;10 different categories of &lt;b&gt;false positive&lt;/b&gt; SQL Injection vulnerabilities (GET OR POST).&lt;/li&gt;
&lt;/ul&gt;&lt;div class="MsoNormal"&gt;Each exposure category in WAVSEP contains an &lt;b&gt;index&lt;/b&gt; page with descriptions of different barriers in test cases, structures of a sample detection payloads and examples of such payloads. &lt;/div&gt;&lt;div class="MsoNormal"&gt;A general description of each test case is also available in the following excel spreadsheet: &lt;a href="http://code.google.com/p/wavsep/downloads/detail?name=VulnerabilityTestCases.xlsx&amp;amp;can=2&amp;amp;q"&gt;http://code.google.com/p/wavsep/downloads/detail?name=VulnerabilityTestCases.xlsx&amp;amp;can=2&amp;amp;q&lt;/a&gt;=&lt;/div&gt;&lt;div class="MsoNormal"&gt;Those that wish to verify the results of the benchmark can download the latest source code of project WAVSEP (including the list of test cases and their description) from the project’s web site:&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;a href="http://code.google.com/p/wavsep/"&gt;http://code.google.com/p/wavsep/&lt;/a&gt; &lt;a href="http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=7398976696397938525" name="_Toc281066150"&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;Benchmark Overview&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;As mentioned before, the benchmark focused on testing free &amp;amp; open source tools that are able to &lt;b&gt;detect &lt;/b&gt;(and not necessarily exploit) security vulnerabilities on a wide range of URLs, and thus, each tool tested needed to support the following features:&lt;/div&gt;&lt;div class="MsoListParagraphCxSpFirst" style="mso-list: l6 level1 lfo5; text-indent: -.25in;"&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;Either open source or free to use, so that open source projects and vendors generous enough to contribute to the community will benefit from the benchmark first.&lt;/li&gt;
&lt;li&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;The ability to detect Reflected XSS and/or SQL Injection vulnerabilities.&lt;/li&gt;
&lt;li&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;The ability to scan multiple URLs at once (using either a crawler/spider feature, URL/Log file parsing feature or a built-in proxy).&lt;/li&gt;
&lt;li&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;The ability to control and limit the scan to internal or external host (domain/IP).&lt;/li&gt;
&lt;/ul&gt;&lt;div class="MsoNormal"&gt;As a direct implication, the test &lt;b&gt;did NOT include&lt;/b&gt; the tools listed in &lt;b&gt;&lt;u&gt;Appendix A – A List of Tools Not Included In The Test&lt;/u&gt;&lt;/b&gt;.&lt;/div&gt;&lt;div class="MsoNormal"&gt;The purpose of WAVSEP’s test cases is to provide a scale for understanding which detection barriers each scanning tool can bypass, and which vulnerability variations can be detected by each tool.&lt;/div&gt;&lt;div class="MsoNormal"&gt;The Reflected Cross Site Scripting vulnerable pages are pretty standard &amp;amp; straightforward, and should provide reliable basis for assessing the detection capabilities of different scanners. &lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;However, it is important to remember that the SQL Injection vulnerable pages used a MySQL database as a data repository, and thus, the SQL Injection detection results &lt;b&gt;&lt;i&gt;only reflect detection results of SQL Injection vulnerabilities in this type of database&lt;/i&gt;&lt;/b&gt;; the results that might vary when the back end data repository will be different (a theory that will be verified in the next benchmark).&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;u&gt;&lt;br /&gt;
&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;u&gt;&lt;span style="color: #999999; font-size: 18pt; line-height: 115%;"&gt;Description of Comparison Tables&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;The list of tools tested in this benchmark is organized within the following reports:&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;List of Tested Scanners (&lt;a href="http://wavsep.googlecode.com/files/List%20of%20Tested%20Web%20Application%20Vulnerability%20Scanners%20v1.0.pdf"&gt;http://wavsep.googlecode.com/files/List%20of%20Tested%20Web%20Application%20Vulnerability%20Scanners%20v1.0.pdf&lt;/a&gt;)&lt;/div&gt;&lt;div class="MsoNormal"&gt;Source, License and Technical Details of Tested Scanners (&lt;a href="http://wavsep.googlecode.com/files/Details%20of%20Tested%20Web%20Application%20Vulnerability%20Scanners%20v1.0.pdf"&gt;http://wavsep.googlecode.com/files/Details%20of%20Tested%20Web%20Application%20Vulnerability%20Scanners%20v1.0.pdf&lt;/a&gt;)&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;For those of you that wish to get straight to the point, the results of the accuracy assessment are organized within the following reports:&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Benchmark Results – Reflected XSS Detection Accuracy (&lt;a href="http://wavsep.googlecode.com/files/Web%20Application%20Scanner%20RXSS%20Detection%20Accuracy%20v1.0.pdf"&gt;http://wavsep.googlecode.com/files/Web%20Application%20Scanner%20RXSS%20Detection%20Accuracy%20v1.0.pdf&lt;/a&gt;)&lt;/div&gt;&lt;div class="MsoNormal"&gt;Benchmark Results – SQL Injection Detection Accuracy – Total (&lt;a href="http://wavsep.googlecode.com/files/Web%20Application%20Scanner%20SQLi%20Detection%20Accuracy%20v1.0.pdf"&gt;http://wavsep.googlecode.com/files/Web%20Application%20Scanner%20SQLi%20Detection%20Accuracy%20v1.0.pdf&lt;/a&gt;)&lt;/div&gt;&lt;div class="MsoNormal"&gt;Benchmark Drilldown – Blind SQL Injection Detection (&lt;a href="http://wavsep.googlecode.com/files/Web%20Application%20Scanner%20SQLi%20Detection%20Accuracy%20-%20Blind%20v1.0.pdf"&gt;http://wavsep.googlecode.com/files/Web%20Application%20Scanner%20SQLi%20Detection%20Accuracy%20-%20Blind%20v1.0.pdf&lt;/a&gt;)&lt;/div&gt;&lt;div class="MsoNormal"&gt;Benchmark Drilldown – Erroneous SQL Injection Detection&lt;/div&gt;&lt;div class="MsoNormal"&gt;(&lt;a href="http://wavsep.googlecode.com/files/Web%20Application%20Scanner%20SQLi%20Detection%20Accuracy%20-%20ErrorBased%20v1.0.pdf"&gt;http://wavsep.googlecode.com/files/Web%20Application%20Scanner%20SQLi%20Detection%20Accuracy%20-%20ErrorBased%20v1.0.pdf&lt;/a&gt;) &lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;Additional information was gathered during the benchmark, including information related to the different features of various scanners. These details are organized in the following reports, and might prove useful when searching for tools for specific tasks or tests:&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Comparison of Active Vulnerability Detection Features (&lt;a href="http://wavsep.googlecode.com/files/Active%20Vulnerability%20Detection%20Features%20Comparison%20v1.0.pdf"&gt;http://wavsep.googlecode.com/files/Active%20Vulnerability%20Detection%20Features%20Comparison%20v1.0.pdf&lt;/a&gt;)&lt;/div&gt;&lt;div class="MsoNormal"&gt;Comparison of Complementary Scanning Features - Passive Analysis, CGI Scanning, Brute Force, etc (&lt;a href="http://wavsep.googlecode.com/files/Complementary%20Scan%20Features%20Comparison%20v1.0.pdf"&gt;http://wavsep.googlecode.com/files/Complementary%20Scan%20Features%20Comparison%20v1.0.pdf&lt;/a&gt;)&lt;/div&gt;&lt;div class="MsoNormal"&gt;Comparison of Usability, Coverage and Scan Initiation Features (&lt;a href="http://wavsep.googlecode.com/files/List%20of%20Scanner%20Features%20%281%20of%203%29%20v1.0.pdf"&gt;http://wavsep.googlecode.com/files/List%20of%20Scanner%20Features%20%281%20of%203%29%20v1.0.pdf&lt;/a&gt;)&lt;/div&gt;&lt;div class="MsoNormal"&gt;Comparison of Authentication, Scan Control and Connection Support Features (&lt;a href="http://wavsep.googlecode.com/files/List%20of%20Scanner%20Features%20%282%20of%203%29%20v1.0.pdf"&gt;http://wavsep.googlecode.com/files/List%20of%20Scanner%20Features%20%282%20of%203%29%20v1.0.pdf&lt;/a&gt;)&lt;/div&gt;&lt;div class="MsoNormal"&gt;Comparison of Advanced and Uncommon Features (&lt;a href="http://wavsep.googlecode.com/files/List%20of%20Scanner%20Features%20%283%20of%203%29%20v1.0.pdf"&gt;http://wavsep.googlecode.com/files/List%20of%20Scanner%20Features%20%283%20of%203%29%20v1.0.pdf&lt;/a&gt;)&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;Information regarding the scan logs, list of untested tools and abnormal behaviors of scanners can be found in the article appendix sections:&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;The following appendix report contains a list of scanners that were not included in the test:&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;i&gt;Appendix A – A List of Tools not included in the Test (The end of the article)&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;The scan logs (describing the executing process and configuration of each scanner) can be viewed in the following appendix report: Appendix B – WAVSEP Scanning Logs (&lt;a href="http://wavsep.googlecode.com/files/WavsepScanLogs%20v1.0.pdf"&gt;http://wavsep.googlecode.com/files/WavsepScanLogs%20v1.0.pdf&lt;/a&gt;) &lt;/div&gt;&lt;div class="MsoNormal"&gt;During the benchmark, certain tools with abnormal behavior were identified; the list of these tools is presented in the following appendix report: &lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;i&gt;Appendix C – Scanners with Abnormal Behavior (The end of the article)&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;u&gt;&lt;o:p&gt;&lt;span style="text-decoration: none;"&gt; &lt;/span&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;u&gt;&lt;br /&gt;
&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;List of Tested Scanners&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;The following report (PDF) contains the list of scanners tested in this benchmark, in addition to their version, their author and their status: &lt;a href="http://wavsep.googlecode.com/files/List%20of%20Tested%20Web%20Application%20Vulnerability%20Scanners%20v1.0.pdf"&gt;http://wavsep.googlecode.com/files/List%20of%20Tested%20Web%20Application%20Vulnerability%20Scanners%20v1.0.pdf&lt;/a&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;For those of you that want a quick glimpse, the following scanners were tested in the benchmark:&lt;/div&gt;&lt;div class="MsoNormal"&gt;Acunetix Web Vulnerability Scanner (Free Edition), aidSQL, Andiparos, arachni, crawlfish, Gamja, Grabber, Grendel Scan, iScan, JSKY Free Edition, LoverBoy, Mini MySqlat0r, Netsparker Community Edition, N-Stalker Free Edition, Oedipus, openAcunetix, Paros Proxy, PowerFuzzer, Priamos, ProxyStrike, Sandcat Free Edition, Scrawler, ScreamingCSS, ScreamingCobra, Secubat, SkipFish, SQID (SQL Injection Digger), SQLiX, sqlmap, UWSS(Uber Web Security Scanner), VulnDetector, W3AF, Wapiti, Watobo, Web Injection Scanner (WIS), WebCruiser Free Edition, WebScarab, WebSecurify, WSTool, Xcobra, XSSer, XSSploit, XSSS, ZAP.&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span class="Apple-style-span" style="color: #999999;"&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=7398976696397938525" name="_Toc281066153"&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;Source, License and Technical Details of Tested Scanners&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;The following report (PDF) contains a comparison of licenses, development technology and sources (home page) of different scanners: &lt;a href="http://wavsep.googlecode.com/files/Details%20of%20Tested%20Web%20Application%20Vulnerability%20Scanners%20v1.0.pdf"&gt;http://wavsep.googlecode.com/files/Details%20of%20Tested%20Web%20Application%20Vulnerability%20Scanners%20v1.0.pdf&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal" style="mso-outline-level: 1;"&gt;&lt;span class="Apple-style-span" style="color: #999999;"&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=7398976696397938525" name="_Toc281066154"&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;Comparison of Active Vulnerability Detection Features&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;The following report (PDF) contains a comparison of active vulnerability detection features in the various scanners: &lt;a href="http://wavsep.googlecode.com/files/Active%20Vulnerability%20Detection%20Features%20Comparison%20v1.0.pdf"&gt;http://wavsep.googlecode.com/files/Active%20Vulnerability%20Detection%20Features%20Comparison%20v1.0.pdf&lt;/a&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Aside from the &lt;b&gt;Count&lt;/b&gt; column (which represents the total amount of &lt;b&gt;active&lt;/b&gt; vulnerability detection features supported by the tool, not including complementary features such as web server scanning and passive analysis), each column in the report represents an active vulnerability detection feature, which translates to the exposure presented in the following list: &lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;SQL&lt;/b&gt; – SQL Injection&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;BSQL&lt;/b&gt; – Blind SQL Injection&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;RXSS&lt;/b&gt; – Reflected Cross Site Scripting&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;PXSS&lt;/b&gt; – Persistent / Stored Cross Site Scripting&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;DXSS&lt;/b&gt; – DOM XSS&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;Redirect&lt;/b&gt; – External Redirect / Phishing via Redirection&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;Bck&lt;/b&gt; – Backup File Detection&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;Auth&lt;/b&gt; – Authentication Bypass&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;CRLF&lt;/b&gt; – CRLF Injection / Response Splitting&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;LDAP&lt;/b&gt; – LDAP Injection&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;XPath&lt;/b&gt; – X-Path Injection&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;MX&lt;/b&gt; – MX Injection&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;Session Test&lt;/b&gt; – Session Identifier Complexity Analysis&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;SSI&lt;/b&gt; – Server Side Include&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;RFI-LFI&lt;/b&gt; – Directory Traversal / Remote File Include / Local File Include (Will be separated into different categories in future benchmarks)&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;Cmd&lt;/b&gt; – Command Injection / OS Command Injection&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;Buffer&lt;/b&gt; – Buffer Overflow / Integer Overflow (Will be separated into different categories in future benchmarks)&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;CSRF&lt;/b&gt; – Cross Site Request Forgery&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;A-Dos&lt;/b&gt; – Application Denial of Service / RegEx DoS&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal" style="mso-outline-level: 1;"&gt;&lt;span class="Apple-style-span" style="color: #999999;"&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=7398976696397938525" name="_Toc281066155"&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;Comparison of Complementary Scanning Features&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;The following report (PDF) contains a comparison of complementary vulnerability detection features in the various scanners: &lt;a href="http://wavsep.googlecode.com/files/Complementary%20Scan%20Features%20Comparison%20v1.0.pdf"&gt;http://wavsep.googlecode.com/files/Complementary%20Scan%20Features%20Comparison%20v1.0.pdf&lt;/a&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;In order to clarify what each column in the report table means, use the following interpretation:&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;Web Server Hardening&lt;/b&gt; – plugins that scan for HTTP method support (Trace, WebDAV), directory listing, Robots and cross-domain information disclosure, version specific vulnerabilities, etc.&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;CGI Scanning&lt;/b&gt; - Default files, common vulnerable applications, etc.&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;Passive Analysis&lt;/b&gt; – security tests that don’t require any actual attacks, and are based instead on information gathering and analysis of responses, including certificate &amp;amp; cipher tests, gathering of comments, mime type analysis, autocomplete detection, insecure transmission of credentials, google hacking, etc.&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;File Enumeration&lt;/b&gt; – directory and file enumeration features.&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal" style="mso-outline-level: 1;"&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=7398976696397938525" name="_Toc281066156"&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;Comparison of Usability and Coverage Features&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;The following report (PDF) contains a comparison of usability, coverage and scan initiation features of different scanners: &lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;a href="http://wavsep.googlecode.com/files/List%20of%20Scanner%20Features%20%281%20of%203%29%20v1.0.pdf"&gt;http://wavsep.googlecode.com/files/List%20of%20Scanner%20Features%20%281%20of%203%29%20v1.0.pdf&lt;/a&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;Configuration &amp;amp; Usage Scale&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Very Simple - GUI + Wizard&lt;/div&gt;&lt;div class="MsoNormal"&gt;Simple - GUI with simple options, Command line with scan configuration file or simple options&lt;/div&gt;&lt;div class="MsoNormal"&gt;Complex - GUI with numerous options, Command line with multiple options&lt;/div&gt;&lt;div class="MsoNormal"&gt;Very Complex - Manual scanning feature dependencies, multiple configuration requirements&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;Stability Scale&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Very Stable - Rarely crashes, Never gets stuck&lt;/div&gt;&lt;div class="MsoNormal"&gt;Stable - Rarely crashes, Gets stuck only in extreme scenarios&lt;/div&gt;&lt;div class="MsoNormal"&gt;Unstable - Crashes every once in a while, Freezes on a consistent basis&lt;/div&gt;&lt;div class="MsoNormal"&gt;Fragile – Freezes or Crashes on a consistent basis, Fails performing the operation in many cases&lt;/div&gt;&lt;div class="MsoNormal"&gt;(Unlike the accuracy values presented in the benchmark for W3AF, which are up date, the stability values for W3AF represent the condition of 1.0-RC3, and &lt;b&gt;not&lt;/b&gt; 1.0-RC4; the values will be updated in the next benchmark, after the new version will be thoroughly tested)&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;Performance Scale&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Very Fast - Fast implementation with limited amount of scanning tasks&lt;/div&gt;&lt;div class="MsoNormal"&gt;Fast - Fast implementation with plenty of scanning tasks&lt;/div&gt;&lt;div class="MsoNormal"&gt;Slow - Slow implementation with limited amount of scanning tasks&lt;/div&gt;&lt;div class="MsoNormal"&gt;Very Slow - Slow implementation with plenty of scanning tasks&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal" style="mso-outline-level: 1;"&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=7398976696397938525" name="_Toc281066157"&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;Comparison of Connection and Authentication Features&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;The following report (PDF) contains a comparison of connection, authentication and scan control features of different scanners:&lt;a href="http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=7398976696397938525" name="_Toc281066158"&gt;&lt;/a&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=7398976696397938525" name="_Ref281064590"&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;a href="http://wavsep.googlecode.com/files/List%20of%20Scanner%20Features%20%282%20of%203%29%20v1.0.pdf"&gt;http://wavsep.googlecode.com/files/List%20of%20Scanner%20Features%20%282%20of%203%29%20v1.0.pdf&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;Comparison of Advanced Features&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;The following report (PDF) contains a comparison of advanced and uncommon scanner features:&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;a href="http://wavsep.googlecode.com/files/List%20of%20Scanner%20Features%20%283%20of%203%29%20v1.0.pdf"&gt;http://wavsep.googlecode.com/files/List%20of%20Scanner%20Features%20%283%20of%203%29%20v1.0.pdf&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal" style="mso-outline-level: 1;"&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=7398976696397938525" name="_Toc281066159"&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;Benchmark Results – Reflected XSS Detection Accuracy&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;The results of the Reflected Cross Site Scripting (RXSS) benchmark are presented in the following report (PDF format):&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;a href="http://wavsep.googlecode.com/files/Web%20Application%20Scanner%20RXSS%20Detection%20Accuracy%20v1.0.pdf"&gt;http://wavsep.googlecode.com/files/Web%20Application%20Scanner%20RXSS%20Detection%20Accuracy%20v1.0.pdf&lt;/a&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;The results only include vulnerable pages linked from the index-xss.jsp index page (RXSS-GET or RXSS-POST directories, in addition to the RXSS-FalsePositive directory). XSS Vulnerable locations in the SQL injection vulnerable pages were not taken into account, since they don’t necessarily represent a unique scenario (or at least not until the “layered vulnerabilities” scenario will be implemented).&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal" style="mso-outline-level: 1;"&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=7398976696397938525" name="_Toc281066160"&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;Benchmark Results – SQL Injection Detection Accuracy&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;The overall results of the SQL Injection benchmark are presented in the following report (PDF format): &lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;a href="http://wavsep.googlecode.com/files/Web%20Application%20Scanner%20SQLi%20Detection%20Accuracy%20v1.0.pdf"&gt;http://wavsep.googlecode.com/files/Web%20Application%20Scanner%20SQLi%20Detection%20Accuracy%20v1.0.pdf&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal" style="mso-outline-level: 1;"&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=7398976696397938525" name="_Toc281066161"&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;Benchmark Drilldown – Erroneous SQL Injection Detection&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;The results of the Error-Based SQL Injection benchmark are presented in the following report (PDF format):&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;a href="http://wavsep.googlecode.com/files/Web%20Application%20Scanner%20SQLi%20Detection%20Accuracy%20-%20ErrorBased%20v1.0.pdf"&gt;http://wavsep.googlecode.com/files/Web%20Application%20Scanner%20SQLi%20Detection%20Accuracy%20-%20ErrorBased%20v1.0.pdf&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal" style="mso-outline-level: 1;"&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=7398976696397938525" name="_Toc281066162"&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;Benchmark Drilldown – Blind SQL Injection Detection&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;The results of the Blind SQL Injection benchmark are presented in the following report (PDF format): &lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;a href="http://wavsep.googlecode.com/files/Web%20Application%20Scanner%20SQLi%20Detection%20Accuracy%20-%20Blind%20v1.0.pdf"&gt;http://wavsep.googlecode.com/files/Web%20Application%20Scanner%20SQLi%20Detection%20Accuracy%20-%20Blind%20v1.0.pdf&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal" style="mso-outline-level: 1;"&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;Initial Analysis &amp;amp; Conclusions&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;After performing an initial analysis on the data, I have come to a simple conclusion as to which combination of tools will be &lt;b&gt;the most effective&lt;/b&gt; in detecting &lt;b&gt;Reflected&lt;/b&gt; &lt;b&gt;XSS&lt;/b&gt; vulnerabilities in the public (unauthenticated) section of a tested web site, &lt;b&gt;while providing the least amount of false positives&lt;/b&gt;:&lt;/div&gt;&lt;div class="MsoNormal"&gt;Netsparker CE (42 cases), alongside Acunetix Free Edition (38 cases, including case 27 which is missed by Netsparker), alongside Skipfish (detects case 12 which is missed by both tools). I’d also recommend executing N-Stalker on small applications since it able to detect certain cases that none of the other tested tools can (but the XSS scanning feature is limited to 100 URLs).&lt;/div&gt;&lt;div class="MsoNormal"&gt;Using Sandcat or Proxy Strike alongside Burp Spider/Paros Spider/External Spider can help detect additional potentially vulnerable locations (cases 10, 11, 13-15 and 17-21) that could be manually verified by a human tester.&lt;/div&gt;&lt;div class="MsoNormal"&gt;So combining four tools will give the best possible result of RXSS detection in the unauthenticated section of an application, using today’s free &amp;amp; open source tools… WOW, it took some time to get to that conclusion. However, scanning the public section of the application is one thing, and scanning the internal section (authenticated section) of the application is another; effectively scanning the authenticated section requires various features such as authentication support, URL scanning restrictions, manual crawling (in case damage might be caused from crawling certain URLs), etc; so the conclusions for the public section are not necessarily fit for the internal section.&lt;/div&gt;&lt;div class="MsoNormal"&gt;During the next few days, I’ll try and analyze the results and come to additional conclusions (internal RXSS scanning, external &amp;amp; internal SQLi scanning, etc). Simply check my blog in a few days to see which conclusions were already published.&lt;/div&gt;&lt;div class="MsoNormal"&gt;An updated benchmark document will be released in the WAVSEP project homepage after each addition, conclusion or change.&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;u&gt;A comment about accuracy and inconsistent results &lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;During the benchmark, I have executed each tool more than once, and on rare occasions, dozens of times. I have discovered that some of the tools have inconsistent results in certain fields (particularly SQL injection). The following tools produced inconsistent results in the SQLi detection field: &lt;b&gt;Skipfish&lt;/b&gt; (my guess is the inconsistencies are related to crawling problems and connection timeouts), &lt;b&gt;Oedipus&lt;/b&gt;, and probably a couple of others that I can’t remember.&lt;/div&gt;&lt;div class="MsoNormal"&gt;It is important to note that the 100% Reflected XSS detection ratio that &lt;b&gt;Sandcat&lt;/b&gt; and &lt;b&gt;ProxyStrike&lt;/b&gt; produce comes with a huge amount of false positives, a fact that signifies that the detection algorithm works more like a passive scanner (such as watcher by casaba), and less like an active intelligent scanner that verifies that the injection returned is sufficient to exploit the exposure in the given scope. This conclusion &lt;b&gt;does not&lt;/b&gt; necessarily pinpoint anything about other features of these scanners (for example, the SQL injection detection module of proxystrike is pretty decent), or presume that the XSS scanning features of these tools are “useless”; on the contrary, these tools can be used as means to obtain more leads for human verification, and can be very useful in the right context.&lt;/div&gt;&lt;div class="MsoNormal"&gt;Furthermore, the 100% SQL Injection detection ratio of Wapiti needs to be further investigated since andiparos produced the same ratio when the titles of the various pages contained the word SQL (which is part of the reason that in the latest version of WAVSEP, this word does not appear anywhere).&lt;/div&gt;&lt;div class="MsoNormal"&gt;Additional conclusions will follow.&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;So What Now?&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;So now that we have plenty of statistics to analyze, and a new framework for testing scanners, it’s time to discuss the next phases.&lt;/div&gt;&lt;div class="MsoNormal"&gt;Although the calendar tells me that it took me 9 months to conduct this research, in reality, it took me a couple of years to collect all the tools, learn how to install and use them, gather everything that was freely available for more than 5 minutes and test them all together.&lt;/div&gt;&lt;div class="MsoNormal"&gt;However, since my research led me to develop a whole framework for benchmarking (aside from the WAVSEP project which was already published), I believe (or at least hope) that thanks to the platform, future benchmarks will be &lt;b&gt;much&lt;/b&gt; easier to conduct, and in fact, I’m planning on updating the content of the web site (&lt;a href="http://sectooladdict.blogspot.com/"&gt;http://sectooladdict.blogspot.com/&lt;/a&gt;) with additional related content on a regular basis. &lt;/div&gt;&lt;div class="MsoNormal"&gt;In addition to different classes of benchmarks, the following goals will be in the highest priority:&lt;/div&gt;&lt;div class="MsoListParagraphCxSpFirst" style="mso-list: l3 level1 lfo4; text-indent: -.25in;"&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;Improve the testing framework (WAVSEP); add additional test cases and additional security vulnerabilities.&lt;/li&gt;
&lt;li&gt;Perform additional benchmarks on the framework, and on a consistent basis. I'm currently aiming for &lt;b&gt;one major benchmark per year&lt;/b&gt;, although I might start with twice per year, and a couple of initial releases that might come even sooner.&lt;/li&gt;
&lt;li&gt;Publish the results of tests against sample vulnerable web applications, so that some sort of feedback on other types of exposures will be available (until other types of vulnerabilities will be implemented in the framework), as well as features such as authentication support, crawling, etc.&lt;/li&gt;
&lt;li&gt;Gradually develop a framework for testing additional related features, such as authentication support, malformed HTML tolerance, abnormal response support, etc.&lt;/li&gt;
&lt;li&gt;Integration with external frameworks for assessing crawling capabilities, technology support, etc.&lt;/li&gt;
&lt;/ul&gt;&lt;div class="MsoNormal"&gt;I hope that this content will help the various vendors improve their tools, help pen-testers choose the right tool for each task, and in addition, help create some method of testing the numerous tools out there.&lt;/div&gt;&lt;div class="MsoNormal"&gt;The different vendors will receive an email message from an email address designated for communicating with them. I urge them to try and contact me through that address, and not using alternative means, so I’ll be able to set my priorities properly. &lt;b&gt;I apologize in advance for any delays in my responses in the next few weeks.&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span class="Apple-style-span" style="color: #999999;"&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=7398976696397938525" name="_Toc281066165"&gt;&lt;/a&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=7398976696397938525" name="_Ref280855248"&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;Appendix A – A List of Tools &lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;Not Included In the Test&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;The benchmark focused on web application scanners that are free to use (freeware and/or open source), are able to detect either Reflected XSS or SQL Injection vulnerabilities, and are also able to scan multiple URLs in the same execution.&lt;/div&gt;&lt;div class="MsoNormal"&gt;As a direct implication, the test &lt;b&gt;did NOT include&lt;/b&gt; the following types of tools:&lt;/div&gt;&lt;div class="MsoListParagraphCxSpFirst" style="mso-list: l0 level1 lfo6; text-indent: -.25in;"&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;Commercial scanners&lt;/u&gt;&lt;/b&gt; - The commercial versions of AppScan, WebInspect, Cenzic, NTOSpider, Acunetix, Netsparker, N-Stalker, WebCruiser, Sandcat and many other commercial tools that I failed to mention. Any tool in the benchmark that holds the same commercial name is actually a limited free version of the same product, and does &lt;b&gt;not&lt;/b&gt; refer (or even necessarily reflect on) the full product.&lt;/li&gt;
&lt;li&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;Online Scanning Services&lt;/u&gt; &lt;/b&gt;– Online applications that remotely scan applications, including (but not limited to) Zero Day Scan, Appscan On Demand, Click To Secure, QualysGuard Web Application Scanning (Qualys), Sentinel (WhiteHat), Veracode (Veracode), VUPEN Web Application Security Scanner (VUPEN Security), WebInspect (online service - HP), WebScanService (Elanize KG), Gamascan (GAMASEC – currently offline), etc.&lt;/li&gt;
&lt;li&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;Scanners without RXSS / SQLi detection features&lt;/u&gt;&lt;/b&gt;&lt;u&gt;, including (but not limited to):&lt;/u&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;LFIMap&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;phpBB-RFI Scanner&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;DotDotPawn&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;CSRF Tester &lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;etc&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="mso-list: l0 level1 lfo6; text-indent: -.25in;"&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;Passive Scanners (response analysis without verification)&lt;/u&gt;&lt;/b&gt;&lt;u&gt;, including (but not limited to):&lt;/u&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;Watcher (Fiddler Plugin by Casaba Security)&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;Skavanger (OWASP)&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;Pantera (OWASP)&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;Rat proxy (Google)&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;Etc&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="mso-list: l0 level1 lfo6; text-indent: -.25in;"&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;Scanners for specific products or services (CMS scanners, Web Services Scanners, etc),&lt;/u&gt;&lt;/b&gt;&lt;u&gt; including (but not limited to):&lt;/u&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;WSDigger&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;Sprajax&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;ScanAjax&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;Joomscan&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;Joomlascan&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;Joomsq&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;WPSqli&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;etc&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="mso-list: l0 level1 lfo6; text-indent: -.25in;"&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;White box &amp;amp; Code Review Application Scan Tools&lt;/u&gt;&lt;/b&gt;&lt;u&gt;, including (but not limited to):&lt;/u&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;PuzlBox&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;Inspathx&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;etc&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="mso-list: l0 level1 lfo6; text-indent: -.25in;"&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;Uncontrollable Scanners&lt;/u&gt;&lt;/b&gt; - scanners that can’t be controlled or restricted to scan a single site, since they either receive the list of URLs to scan from Google Dork, or continue and scan external sites that are linked to the tested site. This list currently includes the following tools (and might include more):&lt;/li&gt;
&lt;/ul&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;Darkjumper 5.8 &lt;/b&gt;(scans additional external hosts that are linked to the given tested host)&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;Bako's SQL Injection Scanner&lt;/b&gt; &lt;b&gt;2.2&lt;/b&gt; (only tests sites from a google dork)&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;Serverchk&lt;/b&gt; (only tests sites from a google dork)&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;XSS Scanner by Xylitol&lt;/b&gt; (only tests sites from a google dork)&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;Hexjector (by hkhexon) &lt;/b&gt;– also falls into other categories&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;etc&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="mso-list: l0 level1 lfo6; text-indent: -.25in;"&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;Deprecated Scanners&lt;/u&gt;&lt;/b&gt; - incomplete tools that were not maintained for a very long time. This list currently includes the following tools (and might include more):&lt;/li&gt;
&lt;/ul&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;Wpoison&lt;/b&gt; (development stopped in 2003, the new official version was never released, although the 2002 development version can be obtained by manually composing the sourceforge URL which does not appear in the web site- &lt;a href="http://sourceforge.net/projects/wpoison/files/"&gt;http://sourceforge.net/projects/wpoison/files/&lt;/a&gt; )&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;etc&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="mso-list: l0 level1 lfo6; text-indent: -.25in;"&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;De facto Fuzzers&lt;/u&gt;&lt;/b&gt; – tools that scan applications in a similar way to a scanner, but where the scanner attempts to conclude whether or not the application or is vulnerable (according to some sort of “intelligent” set of rules), the fuzzer simply collects abnormal responses to various inputs and behaviors, leaving the task of concluding to the human user.&lt;/li&gt;
&lt;/ul&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;Lilith 0.4c/0.6a &lt;/b&gt;(both versions 0.4c and 0.6a were tested, and although the tool seems to be a scanner at first glimpse, it doesn’t perform any intelligent analysis on the results).&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;Spike proxy&lt;/b&gt; &lt;b&gt;1.48&lt;/b&gt; (although the tool has XSS and SQLi scan features, it acts like a fuzzer more then it acts like a scanner – it sends payloads of partial XSS and SQLi, and does not verify that the context of the returned output is sufficient for execution or that the error presented by the server is related to a database syntax injection, leaving the verification task for the user).&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="mso-list: l0 level1 lfo6; text-indent: -.25in;"&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;Fuzzers&lt;/u&gt;&lt;/b&gt; – scanning tools that lack the independent ability to conclude whether a given response represents a vulnerable location, by using some sort of verification method (this category includes tools such as JBroFuzz, Firefuzzer, Proxmon, st4lk3r, etc). Fuzzers that had at least one type of exposure that was verified were included in the benchmark (Powerfuzzer).&lt;/li&gt;
&lt;li&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;CGI Scanners:&lt;/b&gt; vulnerability scanners that focus on detecting hardening flaws and version specific hazards in web infrastructures (Nikto, Wikto, WHCC, st4lk3r, N-Stealth, etc)&lt;/li&gt;
&lt;li&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;Single URL Vulnerability Scanners&lt;/u&gt;&lt;/b&gt; - scanners that can only scan one URL at a time, or can only scan information from a google dork (uncontrollable).&lt;/li&gt;
&lt;/ul&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;Havij (by itsecteam.com)&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;Hexjector (by hkhexon)&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;Simple XSS Fuzzer [SiXFu] (by www.EvilFingers.com)&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;Mysqloit (by muhaimindz)&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;PHP Fuzzer (by RoMeO from DarkMindZ)&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;SQLi-Scanner (by Valentin Hoebel)&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;Etc.&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="mso-list: l0 level1 lfo6; text-indent: -.25in;"&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;The following scanners&lt;/u&gt;&lt;/b&gt;:&lt;/li&gt;
&lt;/ul&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;sandcatCS 4.0.3.0 &lt;/b&gt;- Since sandcat 4.0 free edition, a more advanced tool from the same vendor is already tested in the benchmark.&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;GNUCitizen JAVASCRIPT XSS SCANNER &lt;/b&gt;- since WebSecurify, a more advanced tool from the same vendor is already tested in the benchmark.&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;Vulnerability Scanner 1.0 (by cmiN, RST) &lt;/b&gt;- since the source code contained traces for remotely downloaded RFI lists from locations that do not exist anymore. I might attempt to test it anyway in the next benchmark.&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;XSSRays 0.5.5 - &lt;/b&gt;I might attempt to test it in the next benchmark.&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;XSSFuzz 1.1 - &lt;/b&gt;I might attempt to test it in the next benchmark.&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;XSS Assistant - &lt;/b&gt;I might attempt to test it in the next benchmark.&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="mso-list: l0 level1 lfo6; text-indent: -.25in;"&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;Vulnerability Detection Helpers&lt;/u&gt;&lt;/b&gt; – tools that aid in discovering a vulnerability, but do not detect the vulnerability themselves; for example:&lt;/li&gt;
&lt;/ul&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;Exploit-Me Suite (XSS-Me, SQL Inject-Me, Access-Me) &lt;/b&gt; &lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;Fiddler X5s plugin&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="mso-list: l0 level1 lfo6; text-indent: -.25in;"&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;Exploiters&lt;/u&gt; - &lt;/b&gt;tools that can exploit vulnerabilities but have no independent ability to automatically detect vulnerabilities on a large scale. Examples:&lt;/li&gt;
&lt;/ul&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;MultiInjector&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;XSS-Proxy-Scanner&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;Pangolin&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;FGInjector&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;Absinth&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;Safe3 SQL Injector&lt;/b&gt; (an exploitation tool with scanning features (pentest mode) that are &lt;b&gt;not available&lt;/b&gt; in the free version).&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;etc&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="mso-list: l0 level1 lfo6; text-indent: -.25in;"&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;Exceptional Cases&lt;/u&gt;&lt;/b&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;div class="MsoListParagraphCxSpLast" style="margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;"&gt;&lt;span style="font-family: 'Courier New';"&gt;o&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;SecurityQA Toolbar (iSec)&lt;/b&gt; – various lists and rumors include this tool in the collection of free/open-source vulnerability scanners, but I wasn’t able to obtain it from the vendor’s web site, or from any other legitimate source, so I’m not really sure it fits the “free to use” category.&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span class="Apple-style-span" style="color: #999999;"&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=7398976696397938525" name="_Toc281066166"&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;Appendix B – WAVSEP Scanning Logs&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;The execution logs, installation steps and configuration used while scanning with the various tools are all described in the following report (PDF format):&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;a href="http://wavsep.googlecode.com/files/WavsepScanLogs%20v1.0.pdf"&gt;http://wavsep.googlecode.com/files/WavsepScanLogs%20v1.0.pdf&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;span class="Apple-style-span" style="color: #999999;"&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=7398976696397938525" name="_Toc281066167"&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;Appendix C – Scanners with Abnormal Behavior&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size: 18pt; line-height: 115%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;During the assessment, parts of the source code of open source scanners and the HTTP communication of some of the scanners was analyzed; some tools behaved in an &lt;b&gt;abnormal&lt;/b&gt; manner that should be reported:&lt;/div&gt;&lt;div class="MsoListParagraphCxSpFirst" style="mso-list: l1 level1 lfo9; text-indent: -.25in;"&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;Priamos IP Address Lookup&lt;/i&gt;&lt;/b&gt; – The tool Priamos attempts to access “whatismyip.com” (or some similar site) whenever a scan is initiated (verified by channeling the communication through Burp proxy). This behavior might derive from a trojan horse that infected the content on the project web site, so I’m not jumping to any conclusions just yet.&lt;/li&gt;
&lt;li&gt;&lt;span style="font-family: Symbol;"&gt;·&lt;span style="font: normal normal normal 7pt/normal 'Times New Roman';"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;span dir="LTR"&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;VulnerabilityScanner Remote RFI List Retrieval&lt;/i&gt;&lt;/b&gt; (listed in the scanners that were &lt;b&gt;not&lt;/b&gt; tested, appendix A, developed by a group called RST, &lt;a href="http://pastebin.com/f3c267935"&gt;http://pastebin.com/f3c267935&lt;/a&gt;) – In the source code of the tool VulnerabilityScanner (a python script), I found traces for remote access to external web sites for obtaining RFI lists (might be used to refer the user to external URLs listed in the list). I could not verify the purpose of this feature since I didn’t manage to activate the tool (yet); in theory, this could be a legitimate list update feature, but since all the lists the tool uses are hardcoded, I didn’t understand the purpose of the feature. Again, I’m &lt;b&gt;not&lt;/b&gt; jumping to any conclusions; this feature might be related to the tool’s initial design, which was not fully implemented due to various considerations. I’ll try and drill deeper in the next benchmark (and hopefully, manage to test the tool’s accuracy as well).&lt;/li&gt;
&lt;/ul&gt;&lt;div class="MsoNormal"&gt;Although I did &lt;b&gt;not&lt;/b&gt; verify that any of these features is malicious in nature, these features and behaviors might be abused to compromise the security of the tester’s workstation (or to incriminate him in malicious actions), and thus, require additional investigation to disqualify this possibility.&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/div&gt;&lt;br /&gt;
&lt;span style="font-family: Calibri, sans-serif; font-size: 11pt; line-height: 115%;"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3792178847867987053-7398976696397938525?l=sectooladdict.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/HGbb8wq2j6EGmXCIdXjzwY7Fjy8/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/HGbb8wq2j6EGmXCIdXjzwY7Fjy8/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/HGbb8wq2j6EGmXCIdXjzwY7Fjy8/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/HGbb8wq2j6EGmXCIdXjzwY7Fjy8/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/SecurityToolsBenchmarking/~4/roaP7Ymd_z8" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://sectooladdict.blogspot.com/feeds/7398976696397938525/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://sectooladdict.blogspot.com/2010/12/web-application-scanner-benchmark.html#comment-form" title="7 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3792178847867987053/posts/default/7398976696397938525?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3792178847867987053/posts/default/7398976696397938525?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SecurityToolsBenchmarking/~3/roaP7Ymd_z8/web-application-scanner-benchmark.html" title="Web Application Scanner Benchmark (v1.0)" /><author><name>Shay-Chen</name><uri>http://www.blogger.com/profile/16490521389991462247</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="30" height="32" src="http://4.bp.blogspot.com/_59wTD1pGfP8/TRZdDx_oBiI/AAAAAAAAAAY/PKMwqsvGCLU/S220/n847114298_305931_3159.jpg" /></author><thr:total>7</thr:total><feedburner:origLink>http://sectooladdict.blogspot.com/2010/12/web-application-scanner-benchmark.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CEUNQnk8cCp7ImA9WxFWGE4.&quot;"><id>tag:blogger.com,1999:blog-3792178847867987053.post-3801935075883843225</id><published>2010-04-16T05:18:00.000-07:00</published><updated>2010-06-06T06:51:33.778-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-06-06T06:51:33.778-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="benchmarking" /><category scheme="http://www.blogger.com/atom/ns#" term="security" /><category scheme="http://www.blogger.com/atom/ns#" term="security tools" /><title>Where to begin…</title><content type="html">&lt;p class="MsoNormal"&gt;There’s a ton of security tools out there.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;From the point of view of security consultants (pen-testers to be exact), most of these tools are there to make their job easier, aid them in improving test results and enable them to reduce the time required to perform their tests.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;But that’s not how it works in reality...&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Lately there so much tools that it’s hard to know what to use;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Some of these tools are obsolete, some contain numerous bugs that prevents their execution from being effective, and some simply don’t justify the time required to execute them. On the other hand, some relatively anonymous tools generate spectacular results and can provide great benefits, but for some unknown reason (that has nothing to do with their quality), do not receive the credit and recognition they deserve.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;After several years in the profession, and as an &lt;b&gt;official security tool addict&lt;/b&gt;, I have decided to invest some time in sharing my experiences from using these tools, and from time to time, publish &lt;b&gt;detailed &lt;/b&gt;benchmarking articles that compare between the various tools features, usability, accuracy, advantages and disadvantages.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;In hopes that the community will benefit from this initiative, and in hopes that it will inspire the various tool vendors to compete and improve their tools,&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Let the contest begin.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3792178847867987053-3801935075883843225?l=sectooladdict.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/m2U-U5cMe9boWaP8KnXM3R1x8CA/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/m2U-U5cMe9boWaP8KnXM3R1x8CA/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/m2U-U5cMe9boWaP8KnXM3R1x8CA/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/m2U-U5cMe9boWaP8KnXM3R1x8CA/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/SecurityToolsBenchmarking/~4/ZqYbFjm9Gtw" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://sectooladdict.blogspot.com/feeds/3801935075883843225/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://sectooladdict.blogspot.com/2010/04/where-to-begin.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3792178847867987053/posts/default/3801935075883843225?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3792178847867987053/posts/default/3801935075883843225?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/SecurityToolsBenchmarking/~3/ZqYbFjm9Gtw/where-to-begin.html" title="Where to begin…" /><author><name>Shay-Chen</name><uri>http://www.blogger.com/profile/16490521389991462247</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="30" height="32" src="http://4.bp.blogspot.com/_59wTD1pGfP8/TRZdDx_oBiI/AAAAAAAAAAY/PKMwqsvGCLU/S220/n847114298_305931_3159.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://sectooladdict.blogspot.com/2010/04/where-to-begin.html</feedburner:origLink></entry></feed>

