Re: Web Application Scanners Comparison
Ory Segal <[email protected]> Thu, 29 Jan 2009 16:48:44 +0200
| Newsgroups | gmane.comp.security.websecurity,gmane.comp.security.bugtraq,gmane.comp.security.penetration,gmane.comp.security.basics,gmane.comp.security.vulnerabilities,gmane.comp.security.web-applications |
|---|---|
| Message-ID | <OFDA861E49.E6C61B01-ONC225754D.005144D3-C225754D.00515DDC@il.ibm.com> |
--=_alternative 00515D23C225754D_= Content-Type: text/plain; charset="US-ASCII" Hello, Could you be kind enough and share with us the environment on which you have installed the web applications? operating system, version, service packs, web server type and version, etc.? Thank you, -Ory Segal From: anantasec <[email protected]> To: [email protected], [email protected], [email protected], [email protected], [email protected], [email protected], [email protected], [email protected] Date: 01/27/2009 07:10 PM Subject: [WEB SECURITY] Web Application Scanners Comparison Hi all, In the past weeks, I've performed an evaluation/comparison of three popular web vulnerability scanners.This evaluation was ordered by a penetration testing company that will remain anonymous. The vendors were not contacted during or after the evaluation. The applications (web scanners) included in this evaluation are: - Acunetix WVS version 6.0 (Build 20081217) - IBM Rational AppScan version 7.7.620 Service Pack 2 - HP WebInspect version 7.7.869 I've tested 13 web applications (some of them containing a lot of vulnerabilities), 3 demo applications provided by the vendors (testphp.acunetix.com, demo.testfire.net, zero.webappsecurity.com) and I've done some tests to verify Javascript execution capabilities. In total, 16 applications were tested. I've tried to cover all the major platforms, therefore I have applications in PHP, ASP, ASP.NET and Java. The report can be found at http://drop.io/anantasecfiles/ The full URL to the PDF document: http://drop.io/download/497f0f4e/c1d8b2966f85fb8549a18cbe2d789224ea665f45/759c3010-ce68-012b-dcee-f407c7ff11c2/9eeb1f00-cea5-012b-aa7b-f219675fa758/report.pdf/report_pdf.pdf I've included enough information in this report (the javascript files used for testing, exact version and URL for all the tested applications) so anybody with enough patience can verify and reproduce the results presented here. Therefore, I will not respond to emails for vendors. You have the information, fix your scanners! Best wishes & regards, anantasec -- http://anantasec.blogspot.com ---------------------------------------------------------------------------- Join us on IRC: irc.freenode.net #webappsec Have a question? Search The Web Security Mailing List Archives: http://www.webappsec.org/lists/websecurity/archive/ Subscribe via RSS: http://www.webappsec.org/rss/websecurity.rss [RSS Feed] Join WASC on LinkedIn http://www.linkedin.com/e/gis/83336/4B20E4374DBA --=_alternative 00515D23C225754D_= Content-Type: text/html; charset="US-ASCII" <br><font size=2 face="sans-serif">Hello,</font> <br> <br><font size=2 face="sans-serif">Could you be kind enough and share with us the environment on which you have installed the web applications? operating system, version, service packs, web server type and version, etc.?</font> <br> <br><font size=2 face="sans-serif">Thank you,</font> <br><font size=2 face="sans-serif">-Ory Segal</font> <br> <br> <br> <br> <table width=100%> <tr valign=top> <td><font size=1 color=#5f5f5f face="sans-serif">From:</font> <td><font size=1 face="sans-serif">anantasec <[email protected]></font> <tr valign=top> <td><font size=1 color=#5f5f5f face="sans-serif">To:</font> <td><font size=1 face="sans-serif">[email protected], [email protected], [email protected], [email protected], [email protected], [email protected], [email protected], [email protected]</font> <tr valign=top> <td><font size=1 color=#5f5f5f face="sans-serif">Date:</font> <td><font size=1 face="sans-serif">01/27/2009 07:10 PM</font> <tr valign=top> <td><font size=1 color=#5f5f5f face="sans-serif">Subject:</font> <td><font size=1 face="sans-serif">[WEB SECURITY] Web Application Scanners Comparison</font></table> <br> <hr noshade> <br> <br> <br><tt><font size=2>Hi all,<br> <br> In the past weeks, I've performed an evaluation/comparison of three<br> popular web vulnerability scanners.This evaluation was ordered by a<br> penetration testing company that will remain anonymous. The vendors<br> were not contacted during or after the evaluation.<br> <br> The applications (web scanners) included in this evaluation are:<br> - Acunetix WVS version 6.0 (Build 20081217)<br> - IBM Rational AppScan version 7.7.620 Service Pack 2<br> - HP WebInspect version 7.7.869<br> <br> I've tested 13 web applications (some of them containing a lot of<br> vulnerabilities), 3 demo applications provided by the vendors<br> (testphp.acunetix.com, demo.testfire.net, zero.webappsecurity.com) and<br> I've done some tests to verify Javascript execution capabilities.<br> <br> In total, 16 applications were tested. I've tried to cover all the<br> major platforms, therefore I have applications in PHP, ASP, ASP.NET<br> and Java.<br> <br> The report can be found at </font></tt><a href=http://drop.io/anantasecfiles/><tt><font size=2>http://drop.io/anantasecfiles/</font></tt></a><tt><font size=2><br> The full URL to the PDF document:<br> </font></tt><a href="http://drop.io/download/497f0f4e/c1d8b2966f85fb8549a18cbe2d789224ea665f45/759c3010-ce68-012b-dcee-f407c7ff11c2/9eeb1f00-cea5-012b-aa7b-f219675fa758/report.pdf/report_pdf.pdf"><tt><font size=2>http://drop.io/download/497f0f4e/c1d8b2966f85fb8549a18cbe2d789224ea665f45/759c3010-ce68-012b-dcee-f407c7ff11c2/9eeb1f00-cea5-012b-aa7b-f219675fa758/report.pdf/report_pdf.pdf</font></tt></a><tt><font size=2><br> <br> I've included enough information in this report (the javascript files<br> used for testing, exact version and URL for all the tested<br> applications) so anybody with enough patience can verify and reproduce<br> the results presented here.<br> <br> Therefore, I will not respond to emails for vendors. You have the<br> information, fix your scanners!<br> <br> Best wishes & regards,<br> anantasec<br> <br> -- <br> </font></tt><a href=http://anantasec.blogspot.com/><tt><font size=2>http://anantasec.blogspot.com</font></tt></a><tt><font size=2><br> <br> ----------------------------------------------------------------------------<br> Join us on IRC: irc.freenode.net #webappsec<br> <br> Have a question? Search The Web Security Mailing List Archives: <br> </font></tt><a href=http://www.webappsec.org/lists/websecurity/archive/><tt><font size=2>http://www.webappsec.org/lists/websecurity/archive/</font></tt></a><tt><font size=2><br> <br> Subscribe via RSS: <br> </font></tt><a href=http://www.webappsec.org/rss/websecurity.rss><tt><font size=2>http://www.webappsec.org/rss/websecurity.rss</font></tt></a><tt><font size=2> [RSS Feed]<br> <br> Join WASC on LinkedIn<br> </font></tt><a href=http://www.linkedin.com/e/gis/83336/4B20E4374DBA><tt><font size=2>http://www.linkedin.com/e/gis/83336/4B20E4374DBA</font></tt></a><tt><font size=2><br> <br> </font></tt> <br> <br> --=_alternative 00515D23C225754D_=--