Security of Information, Threat Intelligence, Hacking, Offensive Security, Pentest, Open Source, Hackers Tools, Leaks, Pr1v8, Premium Courses Free, etc

Sunday, January 24, 2016

Vulnerabile Evaluation Platform - WAVSEP



A vulnerable web application designed to help assessing the features, quality and accuracy of web application vulnerability scanners. This evaluation platform contains a collection of unique vulnerable web pages that can be used to test the various properties of web application scanners.


Vulnerabilities:

ÂşPath Traversal/LFI: 816 test cases, implemented in 816 jsp pages (GET & POST)
ÂşRemote File Inclusion (XSS via RFI): 108 test cases, implemented in 108 jsp pages (GET & POST)
ÂşReflected XSS: 66 test cases, implemented in 64 jsp pages (GET & POST)
ÂşError Based SQL Injection: 80 test cases, implemented in 76 jsp pages (GET & POST)
ÂşBlind SQL Injection: 46 test cases, implemented in 44 jsp pages (GET & POST)
ÂşTime Based SQL Injection: 10 test cases, implemented in 10 jsp pages (GET & POST)
ÂşPassive Information Disclosure/Session Vulnerabilities (inspired/imported from ZAP-WAVE): 3 test cases of erroneous information leakage, and 2 cases of improper authentication / information disclosure – implemented in 5 jsp pages
ÂşExperimental Tase Cases (inspired/imported from ZAP-WAVE): 9 additional RXSS test cases (anticsrf tokens, secret input vectors, tag signatures, etc), and 2 additional SQLi test cases (INSERT) – implemented in 11 jsp pages (GET & POST)

False Positives:

Âş7 different categories of false positive Reflected XSS vulnerabilities (GET & POST )
Âş10 different categories of false positive SQL Injection vulnerabilities (GET & POST)
Âş8 different categories of false positive path traversal/LFI vulnerabilities (GET & POST)
Âş6 different categories of false positive remote file inclusion vulnerabilities (GET & POST)

Additional Features:

ÂşA simple web interface for accessing the vulnerable pages
ÂşAn auto-installer for the mysql database schema (/wavsep-install/install.jsp)
ÂşSample detection & exploitation payloads for each and every test case
ÂşDatabase connection pool support, ensuring the consistency of scanning results



Share:

0 comentários:

Post a Comment

Note: Only a member of this blog may post a comment.

Established in 2015. Offensive Sec Blog has been sharing security research, hacking tools, threat intelligence, and offensive security content since 2015.
Copyright © OffSec Blog | Powered by OffensiveSec
Design by OffSec | Built for the security community