Independent Web Vulnerability Scanner Comparison – Acunetix WVS, IBM Rational AppScan & HP WebInspect

The New Acunetix V12 Engine


I saw a relevant paper published today by an individual that claims the comparison was ordered by a penetration testing company (a company which remains unnamed).

The vendors were not contacted during or after the evaluation.

Testing Procedure

The author tested 13 web applications (some of them containing a lot of vulnerabilities), 3 demo applications provided by the vendors:

And some tests were done to verify JavaScript execution capabilities.

In total, 16 applications were tested.

An attempt was made to try and cover all the major platforms, so applications in PHP, ASP, ASP.NET and Java were used.

Note for Application Tests:

The report only included “important/critical/major” vulnerabilities like SQL injection, Local/Remote File Inclusion, XSS – Vulnerabilities like “Unencrypted Login Form”, “Directory listing found”, “Email address found” were not included to avoid clutter.

SQL injection vulnerabilities can be discovered through error messages or blind SQL injection. Some scanners are showing 2 alerts: one for the vulnerability found through error message and another for the blind technique. In these cases only one vulnerability has been counted.

The scanners were rated as follows:

Scanner Scoring

You can download the full PDF report here:

WebVulnScanners.pdf

And the associated JavaScript files used for testing here:

WebVulnScanners-JS.zip

The original file location is:

http://drop.io/anantasecfiles/

Author’s blog – http://anantasec.blogspot.com/

Posted in: Countermeasures, Exploits/Vulnerabilities, Security Software, Web Hacking

, , , ,


Latest Posts:


BDFProxy - Patch Binaries via MITM - BackdoorFactory + mitmProxy BDFProxy – Patch Binaries via MiTM – BackdoorFactory + mitmproxy
BDFProxy allows you to patch binaries via MiTM with The Backdoor Factory combined with mitmproxy enabling on the fly patching of binary downloads
Domained - Multi Tool Subdomain Enumeration Domained – Multi Tool Subdomain Enumeration
Domained is a multi tool subdomain enumeration tool that uses several subdomain enumeration tools and wordlists to create a unique list of subdomains.
Acunetix Vulnerability Scanner For Linux Now Available Acunetix Vulnerability Scanner For Linux Now Available
Acunetix Vulnerability Scanner For Linux is now available, now you get all of the functionality of Acunetix, with all of the dependability of Linux.
Gerix WiFi Cracker - Wireless 802.11 Hacking Tool With GUI Gerix WiFi Cracker – Wireless 802.11 Hacking Tool With GUI
Gerix WiFi cracker is an easy to use Wireless 802.11 Hacking Tool with a GUI, it was originally made to run on BackTrack and this version has been updated for Kali (2018.1).
Malcom - Malware Communication Analyzer Malcom – Malware Communication Analyzer
Malcom is a Malware Communication Analyzer designed to analyze a system's network communication using graphical representations of network traffic.
WepAttack - WLAN 802.11 WEP Key Hacking Tool WepAttack – WLAN 802.11 WEP Key Hacking Tool
WepAttack is a WLAN open source Linux WEP key hacking tool for breaking 802.11 WEP keys using a wordlist based dictionary attack.


4 Responses to Independent Web Vulnerability Scanner Comparison – Acunetix WVS, IBM Rational AppScan & HP WebInspect

  1. phage101 January 28, 2009 at 12:54 pm #

    That’s brutal at best…

  2. navin January 28, 2009 at 2:01 pm #

    This simply proves what I’ve always felt: Acunetix +Acusensor is the best choice out there

    A bit slower, but extremely valuable!!

    Nice report though!!

    Thanks

  3. Sploo January 28, 2009 at 6:09 pm #

    I think it’s stupid to use the WebInspect demo page. Why wouldn’t WI win for that one!?!

  4. Pantagruel January 29, 2009 at 8:35 am #

    With Navin,

    Yep nice report.
    The amount of missed and false negatives is worrying and it’s a good thing for Acunetix that they appear to do so well. The other should definitely wake up and get improving.