19.09.2017 Views

the-web-application-hackers-handbook

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

782 Chapter 20 n A Web Application Hacker’s Toolkit<br />

The main conclusions of this study were as follows:<br />

n Whole classes of vulnerabilities cannot be detected by state-of-<strong>the</strong>-art scanners,<br />

including weak passwords, broken access controls, and logic flaws.<br />

n The crawling of modern <strong>web</strong> <strong>application</strong>s can be a serious challenge for<br />

today’s <strong>web</strong> vulnerability scanners due to incomplete support for common<br />

client-side technologies and <strong>the</strong> complex stateful nature of today’s<br />

<strong>application</strong>s.<br />

n There is no strong correlation between price and capability. Some free or<br />

very cost-effective scanners perform as well as scanners that cost thousands<br />

of dollars.<br />

The study assigned each scanner a score based on its ability to identify different<br />

types of vulnerabilities. Table 20-1 shows <strong>the</strong> overall scores and <strong>the</strong> price<br />

of each scanner.<br />

Table 20-1: Vulnerability Detection Performance and Prices of Different Scanners According<br />

to <strong>the</strong> UCSB Study<br />

SCANNER SCORE PRICE<br />

Acunetix 14 $4,995 to $6,350<br />

WebInspect 13 $6,000 to $30,000<br />

Burp Scanner 13 $191<br />

N-Stalker 13 $899 to $6,299<br />

AppScan 10 $17,550 to $32,500<br />

w3af 9 Free<br />

Paros 6 Free<br />

HailStorm 6 $10,000<br />

NTOSpider 4 $10,000<br />

MileSCAN 4 $495 to $1,495<br />

Grendel-Scan 3 Free<br />

It should be noted that scanning capabilities have evolved considerably in<br />

recent years and are likely to continue to do so. Both <strong>the</strong> performance and<br />

price of individual scanners are likely to change over time. The UCSB study<br />

that reported <strong>the</strong> information shown in Table 20-1 was published in June 2010.<br />

Because of <strong>the</strong> relative scarcity of reliable public information about <strong>the</strong> performance<br />

of <strong>web</strong> vulnerability scanners, it is recommended that you do your<br />

own research before making any purchase. Most scan vendors provide detailed<br />

product documentation and free trial editions of <strong>the</strong>ir software, which you can<br />

use to help inform your product selection.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!