eldorado.tu-dortmund.de/server/api/core/bitstreams/7278ddff-e071-4d06-8f2a-7966438974c0/content
Microsoft PowerPoint - An_Analysis_of_Black-box_Vulnerability_Scanners
an POST
◦ Hailstorm No-Injection
◦ w3af No Default
Uploading a Picture ◦ 2 Scanners uploaded without help
◦ 3 Scanners unable to upload one!
WIVET ◦ 3 Scanners couldn’t complete Paros and Burp [...] Server Path Disclosure
“Actual” False Positives ◦ Hailstorm XSS, 2 Code Injection ◦ NTOSpider 3 XSS ◦ w3af PHP eval() Injection
Strictly Dominates
More Dominant
Less Dominant
Default values XSS [...] Hailstorm $10,000 Milescan $495 - $1,495 N-Stalker $899 - $6,299 NTOSpider $10,000 Paros Open source w3af Open source Webinspect $6,000 - $30,000
Each scanner run four times: ◦ WackoPicko Initial – No …