28 January 2009 | 13,468 views

Independent Web Vulnerability Scanner Comparison – Acunetix WVS, IBM Rational AppScan & HP WebInspect

Want to Learn Penetration Testing

I saw a relevant paper published today by an individual that claims the comparison was ordered by a penetration testing company (a company which remains unnamed).

The vendors were not contacted during or after the evaluation.

Testing Procedure

The author tested 13 web applications (some of them containing a lot of vulnerabilities), 3 demo applications provided by the vendors:

And some tests were done to verify JavaScript execution capabilities.

In total, 16 applications were tested.

An attempt was made to try and cover all the major platforms, so applications in PHP, ASP, ASP.NET and Java were used.

Note for Application Tests:

The report only included “important/critical/major” vulnerabilities like SQL injection, Local/Remote File Inclusion, XSS – Vulnerabilities like “Unencrypted Login Form”, “Directory listing found”, “Email address found” were not included to avoid clutter.

SQL injection vulnerabilities can be discovered through error messages or blind SQL injection. Some scanners are showing 2 alerts: one for the vulnerability found through error message and another for the blind technique. In these cases only one vulnerability has been counted.

The scanners were rated as follows:

Scanner Scoring

You can download the full PDF report here:

WebVulnScanners.pdf

And the associated JavaScript files used for testing here:

WebVulnScanners-JS.zip

The original file location is:

http://drop.io/anantasecfiles/

Author’s blog – http://anantasec.blogspot.com/

Post to Twitter Post to Facebook Post to Google Buzz Post to Delicious Post to Digg Post to Reddit Post to StumbleUpon






Recent in Countermeasures:
- No BEAST Fix From Microsoft In December Patch Tuesday – But They Fixed Duqu Bug
- sslyze – Fast and Full-Featured SSL Configuration Scanner
- Twitter Purchases WhisperCore – Full Disk Encryption For Android Phones

Related Posts:
- Acunetix Web Vulnerability Scanner (WVS) 6.5 Released
- Acunetix WVS (Web Vulnerability Scanner) 7 Review – Engine & Scanning Improvements
- Acunetix Web Vulnerability Scanner 6 Review

Most Read in Countermeasures:
- AJAX: Is your application secure enough? - 115,526 views
- Password Hasher Firefox Extension - 109,715 views
- NDR or Backscatter Spam – How Non Delivery Reports Become a Nuisance - 55,020 views

Advertise on Darknet


4 Responses to “Independent Web Vulnerability Scanner Comparison – Acunetix WVS, IBM Rational AppScan & HP WebInspect”

  1. phage101 28 January 2009 at 12:54 pm Permalink

    That’s brutal at best…

  2. navin 28 January 2009 at 2:01 pm Permalink

    This simply proves what I’ve always felt: Acunetix +Acusensor is the best choice out there

    A bit slower, but extremely valuable!!

    Nice report though!!

    Thanks

  3. Sploo 28 January 2009 at 6:09 pm Permalink

    I think it’s stupid to use the WebInspect demo page. Why wouldn’t WI win for that one!?!

  4. Pantagruel 29 January 2009 at 8:35 am Permalink

    With Navin,

    Yep nice report.
    The amount of missed and false negatives is worrying and it’s a good thing for Acunetix that they appear to do so well. The other should definitely wake up and get improving.