Independent Web Vulnerability Scanner Comparison – Acunetix WVS, IBM Rational AppScan & HP WebInspect


I saw a relevant paper published today by an individual that claims the comparison was ordered by a penetration testing company (a company which remains unnamed).

The vendors were not contacted during or after the evaluation.

Testing Procedure

The author tested 13 web applications (some of them containing a lot of vulnerabilities), 3 demo applications provided by the vendors:

And some tests were done to verify JavaScript execution capabilities.

In total, 16 applications were tested.

An attempt was made to try and cover all the major platforms, so applications in PHP, ASP, ASP.NET and Java were used.

Note for Application Tests:

The report only included “important/critical/major” vulnerabilities like SQL injection, Local/Remote File Inclusion, XSS – Vulnerabilities like “Unencrypted Login Form”, “Directory listing found”, “Email address found” were not included to avoid clutter.

SQL injection vulnerabilities can be discovered through error messages or blind SQL injection. Some scanners are showing 2 alerts: one for the vulnerability found through error message and another for the blind technique. In these cases only one vulnerability has been counted.

The scanners were rated as follows:

Scanner Scoring

You can download the full PDF report here:

WebVulnScanners.pdf

And the associated JavaScript files used for testing here:

WebVulnScanners-JS.zip

The original file location is:

http://drop.io/anantasecfiles/

Author’s blog – http://anantasec.blogspot.com/

Posted in: Countermeasures, Exploits/Vulnerabilities, Security Software, Web Hacking

, , , ,


Latest Posts:


tko-subs - Detect & Takeover Subdomains With Dead DNS Records tko-subs – Detect & Takeover Subdomains With Dead DNS Records
tko-subs is a tool that helps you to detect & takeover subdomains with dead DNS records, this could be dangling CNAMEs point to hosting services and more.
Arcane - Tool To Backdoor iOS Packages (iPhone ARM) Arcane – Tool To Backdoor iOS Packages (iPhone ARM)
Arcane is a simple script tool to backdoor iOS packages (iPhone ARM) and create the necessary resources for APT repositories.
SharpHose - Asynchronous Password Spraying Tool SharpHose – Asynchronous Password Spraying Tool
SharpHose is an asynchronous password spraying tool in C# for Windows environments that takes into consideration fine-grained password policies and can be run over Cobalt Strike's execute-assembly.
Axiom - Pen-Testing Server For Collecting Bug Bounties Axiom – Pen-Testing Server For Collecting Bug Bounties
Project Axiom is a set of utilities for managing a small dynamic infrastructure setup for bug bounty, basically a pen-testing server out of the box with 1-line.
Quasar RAT - Windows Remote Administration Tool Quasar RAT – Windows Remote Administration Tool
Quasar is a fast and light-weight Windows remote administration tool coded in C#. Used for user support through day-to-day administrative work to monitoring.
Pingcastle - Active Directory Security Assessment Tool Pingcastle – Active Directory Security Assessment Tool
PingCastle is a Active Directory Security Assessment Tool designed to quickly assess the Active Directory security level based on a risk and maturity framework.


4 Responses to Independent Web Vulnerability Scanner Comparison – Acunetix WVS, IBM Rational AppScan & HP WebInspect

  1. phage101 January 28, 2009 at 12:54 pm #

    That’s brutal at best…

  2. navin January 28, 2009 at 2:01 pm #

    This simply proves what I’ve always felt: Acunetix +Acusensor is the best choice out there

    A bit slower, but extremely valuable!!

    Nice report though!!

    Thanks

  3. Sploo January 28, 2009 at 6:09 pm #

    I think it’s stupid to use the WebInspect demo page. Why wouldn’t WI win for that one!?!

  4. Pantagruel January 29, 2009 at 8:35 am #

    With Navin,

    Yep nice report.
    The amount of missed and false negatives is worrying and it’s a good thing for Acunetix that they appear to do so well. The other should definitely wake up and get improving.