<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; acunetix web vulnerability scanner</title>
	<atom:link href="http://www.darknet.org.uk/tag/acunetix-web-vulnerability-scanner/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Independent Web Vulnerability Scanner Comparison &#8211; Acunetix WVS, IBM Rational AppScan &amp; HP WebInspect</title>
		<link>http://www.darknet.org.uk/2009/01/independent-web-vulnerability-scanner-comparison-acunetix-wvs-ibm-rational-appscan-hp-webinspect/</link>
		<comments>http://www.darknet.org.uk/2009/01/independent-web-vulnerability-scanner-comparison-acunetix-wvs-ibm-rational-appscan-hp-webinspect/#comments</comments>
		<pubDate>Wed, 28 Jan 2009 08:26:00 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Countermeasures]]></category>
		<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Security Software]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[acunetix]]></category>
		<category><![CDATA[acunetix web vulnerability scanner]]></category>
		<category><![CDATA[acunetix wvs]]></category>
		<category><![CDATA[anantasec]]></category>
		<category><![CDATA[hacking-websites]]></category>
		<category><![CDATA[hp webinspect]]></category>
		<category><![CDATA[ibm rational appscan]]></category>
		<category><![CDATA[web vulnerability scanner]]></category>
		<category><![CDATA[website security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1440</guid>
		<description><![CDATA[I saw a relevant paper published today by an individual that claims the comparison was ordered by a penetration testing company (a company which remains unnamed). The vendors were not contacted during or after the evaluation. Testing Procedure The author tested 13 web applications (some of them containing a lot of vulnerabilities), 3 demo applications [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>I saw a relevant paper published today by an individual that claims the comparison was ordered by a penetration testing company (a company which remains unnamed).</p>
<p>The vendors were not contacted during or after the evaluation.</p>
<p><strong>Testing Procedure</strong></p>
<p>The author tested 13 web applications (some of them containing a lot of vulnerabilities), 3 demo applications provided by the vendors:</p>
<ul>
<li><a href="http://testphp.acunetix.com">testphp.acunetix.com</a></li>
<li><a href="http://demo.testfire.net">demo.testfire.net</a></li>
<li><a href="http://zero.webappsecurity.com">zero.webappsecurity.com</a></li>
</ul>
<p>And some tests were done to verify JavaScript execution capabilities.</p>
<p>In total, 16 applications were tested.</p>
<p>An attempt was made to try and cover all the major platforms, so applications in PHP, ASP, ASP.NET and Java were used.</p>
<p><em>Note for Application Tests: </em></p>
<p>The report only included &#8220;important/critical/major&#8221; vulnerabilities like SQL injection, Local/Remote File Inclusion, XSS &#8211; Vulnerabilities like &#8220;Unencrypted Login Form&#8221;, &#8220;Directory listing found&#8221;, &#8220;Email address  found&#8221; were not included to avoid clutter. </p>
<p>SQL injection vulnerabilities can be discovered through error messages or blind SQL injection.  Some scanners are showing 2 alerts: one for the vulnerability found through error message and another for the blind technique. In these cases only one vulnerability has been counted.</p>
<p>The scanners were rated as follows:</p>
<p align="center"><img src="http://farm4.static.flickr.com/3297/3232921645_4f90c62222.jpg?v=0" alt="Scanner Scoring" /></p>
<p>You can download the full PDF report here:</p>
<p><a href=" http://www.darknet.org.uk/content/files/WebVulnScanners.pdf">WebVulnScanners.pdf</a></p>
<p>And the associated JavaScript files used for testing here:</p>
<p><a href=" http://www.darknet.org.uk/content/files/WebVulnScanners-JS.zip">WebVulnScanners-JS.zip</a></p>
<p>The original file location is:</p>
<p><a href="http://drop.io/anantasecfiles/">http://drop.io/anantasecfiles/</a></p>
<p></p>
<p>Author&#8217;s blog &#8211; <a href="http://anantasec.blogspot.com/">http://anantasec.blogspot.com/</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Independent+Web+Vulnerability+Scanner+Comparison+%E2%80%93+Acunetix+WVS%2C+IBM+Rational+AppScan+%26+HP+WebInspe...+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D1440+from+%40THEdark..." title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/01/independent-web-vulnerability-scanner-comparison-acunetix-wvs-ibm-rational-appscan-hp-webinspect/&amp;t=Independent+Web+Vulnerability+Scanner+Comparison+%E2%80%93+Acunetix+WVS%2C+IBM+Rational+AppScan+%26+HP+WebInspect" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2009/01/independent-web-vulnerability-scanner-comparison-acunetix-wvs-ibm-rational-appscan-hp-webinspect/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/01/independent-web-vulnerability-scanner-comparison-acunetix-wvs-ibm-rational-appscan-hp-webinspect/&amp;title=Independent+Web+Vulnerability+Scanner+Comparison+%E2%80%93+Acunetix+WVS%2C+IBM+Rational+AppScan+%26+HP+WebInspect" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/01/independent-web-vulnerability-scanner-comparison-acunetix-wvs-ibm-rational-appscan-hp-webinspect/&amp;title=Independent+Web+Vulnerability+Scanner+Comparison+%E2%80%93+Acunetix+WVS%2C+IBM+Rational+AppScan+%26+HP+WebInspect" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2009/01/independent-web-vulnerability-scanner-comparison-acunetix-wvs-ibm-rational-appscan-hp-webinspect/&amp;title=Independent+Web+Vulnerability+Scanner+Comparison+%E2%80%93+Acunetix+WVS%2C+IBM+Rational+AppScan+%26+HP+WebInspect" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/01/independent-web-vulnerability-scanner-comparison-acunetix-wvs-ibm-rational-appscan-hp-webinspect/&amp;title=Independent+Web+Vulnerability+Scanner+Comparison+%E2%80%93+Acunetix+WVS%2C+IBM+Rational+AppScan+%26+HP+WebInspect" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2009%2F01%2Findependent-web-vulnerability-scanner-comparison-acunetix-wvs-ibm-rational-appscan-hp-webinspect%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/01/independent-web-vulnerability-scanner-comparison-acunetix-wvs-ibm-rational-appscan-hp-webinspect/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
	</channel>
</rss>

