顯示具有 AWVS 標籤的文章。 顯示所有文章
顯示具有 AWVS 標籤的文章。 顯示所有文章

2025年7月15日 星期二

[研究]Web弱點掃描工具 WebInspect, AWVS,AppScan 對 ASP.NET Webform 網站的誤判率 ?

[研究]Web弱點掃描工具 WebInspect, AWVS,AppScan 對 ASP.NET Webform 網站的誤判率 ?

2025-07-15

WebInspect, AWVS (Acunetix Web Application Security Scanner), HCL AppScan 對 ASP.NET Webform 網站的誤判率 ?

ChatGPT 說:

針對 ASP.NET WebForm 架構的網站來說,Web 弱點掃描工具的誤判率與其對 WebForm 特性的理解程度有關。以下是 WebInspect、Acunetix(AWVS)、HCL AppScan 在 WebForm 架構網站下的誤判率比較與特性分析:

✅ WebForm 架構特性影響

ASP.NET WebForm 的特殊點:

  • 頁面有大量 __VIEWSTATE、__EVENTVALIDATION 等隱藏欄位
  • PostBack 頻繁,網址不變但動作多
  • 事件處理器不容易被 crawler 模擬(例如 button click 對應伺服器端事件)
  • 使用 JavaScript 動態更新內容
  • Session 管理與身份驗證常綁定 ViewState

這些特性讓部分掃描工具在 模擬互動與參數注入上表現差異大,容易造成誤判(False Positive)或漏報(False Negative)。

🔍 WebInspect(對 ASP.NET WebForm)

誤判率:中至高

說明:

  • 對 WebForm 的 VIEWSTATE、EVENTVALIDATION 模擬不完整時會造成誤判。
  • 常會報出像「Potential SQLi / XSS in parameters」但實際無法利用。
  • 如未設定正確的 Session 管理(Login Macro),會導致大量 Session expired 錯誤而產生誤報。

優點:若設好 Login Macro 與 Crawl Script,可大幅提升準確度。

🔍 Acunetix(AWVS)

誤判率:低至中

說明:

  • 相對較好處理 WebForm 結構,但在多層次 PostBack 或 __doPostBack() JavaScript 驅動事件中可能不完全理解。
  • 對 VIEWSTATE 通常不誤報,但有時會錯判部分自訂參數為可注入點。
  • 很少出現「完全錯誤」的報告,但仍建議逐一驗證高風險項目。

優點:介面直觀、報告清晰,支援 JS 處理能力好於 WebInspect。

🔍 HCL AppScan Standard

誤判率:中

說明:

  • 對 ASP.NET WebForm 有相當熟悉度,能正確處理大部分隱藏欄位與 PostBack 機制。
  • 常會產生 資訊等級(Info) 風險警告,如「可能的資訊洩漏」、「自訂錯誤訊息」等,技術上非弱點,屬誤判。
  • 若 Login 探勘腳本未設定好,會造成「未驗證狀態」下掃描而產生誤判。

優點:老牌資安工具,WebForm 是其設計時就支援的核心架構之一。

🎯 ASP.NET WebForm 誤判率比較總覽

工具名稱對 WebForm 支援誤判率評估(WebForm 特定)注意事項
WebInspect普通中至高VIEWSTATE 處理要設定 Login Macro
Acunetix (AWVS)普通 ~ 良好低至中事件注入點解析不完全
HCL AppScan良好需手動引導登入與流程

✅ 建議搭配使用策略

  • 設定 Login Macro / Authentication Script,避免掃描在未登入狀態誤判
  • 設定 Session ID 跟蹤與重用(尤其 WebInspect)
  • 手動跑一次流程再掃描(AppScan、AWVS 都支援「Manual Explore」)
  • 忽略不影響的參數警告,如 __VIEWSTATE, __EVENTVALIDATION 通常不應被當作攻擊目標

(完)

[研究]Web弱點掃描工具 WebInspect, AWVS, AppScan 誤判率 ?

[研究]Web弱點掃描工具 WebInspect, AWVS (Acunetix Web Application Security Scanner), HCL AppScan 誤判率 ?

2025-07-15

WebInspect, AWVS (Acunetix Web Application Security Scanner), HCL AppScan 誤判率 ?

ChatGPT 說:

WebInspect、AWVS(Acunetix)、HCL AppScan 都是主流的 Web 應用程式弱點掃描工具,各自有優缺點。以下是關於這三款工具在實務中常見的**誤判率(False Positive Rate)**比較與說明,供您參考:

🔍 1. WebInspect(Micro Focus/Fortify)

誤判率:中偏高

說明:

  • WebInspect 預設配置下會產生較多 False Positives,尤其在模糊測試與複雜邏輯驗證上(例如:登入流程、CSRF Token、客製 API)。
  • 需搭配 手動驗證與微調掃描策略,否則報告常見較多誤報。

優點:支援多樣化 Web 技術與身份驗證方式,整合性強(與 Fortify 一起使用最佳)。

🔍 2. AWVS / Acunetix Premium

誤判率:低至中

說明:

  • Acunetix 的自動化邏輯較精準,誤報率相對較低,是三者中最著名的 低誤報工具。
  • 但在遇到特殊環境(如 JS-heavy SPA、GraphQL、自定義登入)時,誤判仍可能出現。
  • 有提供「Confidence Level」作為可信度指標,有助於辨識真假陽性。

優點:介面友善、自動化程度高、報表結構清晰。

🔍 3. HCL AppScan Standard

誤判率:中

說明:

  • 在傳統 WebForm 或 MVC 架構下表現穩定,但對 JavaScript-heavy 網站(如 React/Vue)與 RESTful API 有時誤判或掃描不完全。
  • 會報出不少警示性質(Info 等級)的風險,不一定為真正弱點。
  • 支援「Manual Explore + Scan」,手動點擊流程可降低誤判率。

優點:資安業界老牌、與企業整合性高、可微調的掃描策略較完整。

🎯 三者誤判率粗略比較表

工具名稱誤判率評估(相對)自動化程度API / JS-heavy 網站支援適合對象
WebInspect中 ~ 高普通企業內部測試、需資安部門熟操作
Acunetix (AWVS)低 ~ 中中小企業、快速開發驗證、Pentester
HCL AppScan中等傳統大型企業應用、具資安人員

✅ 實務建議

  • 多工具比對:建議搭配多個工具交叉比對結果,提高準確性。
  • 手動驗證:不論哪一套工具,重要弱點(如 SQLi、XSS)都應手動驗證。
  • 進階設定:根據網站架構調整登入腳本、黑名單/白名單路徑、Header 模擬等,可大幅降低誤判。

(完)

2023年11月21日 星期二

[研究][ASP.NET]ZAP 與 AWVS 黑箱弱點掃描工具結果比較

[研究][ASP.NET]ZAP 與 AWVS 黑箱弱點掃描工具結果比較

2023-11-21

ZAP  是 OWASP Zed Attack Proxy (敝人用 14.2.0)

AWVS 是 Acunetix Web Vulnerability Scanner , Acunetix Web Application Security Scanner (可能是 15.x,不確定)

環境:Visual Studio 2022 + ASP.NET + WebForm + Web Application + C#

敝人沒有 AWVS 修復後掃描結果,因該修復前 AWVS 不是敝人掃描。敝人想測試修復是否成功,故找了免費的 ZAP 來測試。

********************************************************************************

某些低等級弱點修復前,AWVS掃描結果

Low:

  • Cookies without Secure flag set(Cookies 未設定 Secure flag)
  • HTTP Strict Transport Security (HSTS) not implemented(未使用 HSTS 強制安全傳輸技術)
  • Possible virtual host found(可能虛擬主機存在)
  • Clickjacking: X-Frame-Options header(點閱綁架, User Interface redress attack, UI redress attack, UI redressing)
  • Cookies with missing, inconsistent or contradictory properties(部分Cookie屬性設定有衝突、缺少或不符合格式)

********************************************************************************

某些等級弱點修復,ZAP掃描結果

Medium:

  • Absence of Anti-CSRF Tokens (11)
  • Content Security Policy (CSP) Header Not Set (12)
  • ELMAH 資訊外洩
  • Vulnerable JS Library (2)
Low:
  • Cookie Without Secure Flag (3)
  • Cookie without SameSite Attribute
  • Cross-Domain JavaScript Source File Inclusion (3)
  • Strict-Transport-Security Header Not Set (46)
Info:
  • Authentication Request Identified
  • Information Disclosure - Suspicious Comments (51)
  • Modern Web Application (11)
  • Re-examine Cache-control Directives (14)
  • Session Management Response Identified (5)
  • User Agent Fuzzer (12)
  • User Controllable HTML Element Attribute (Potential XSS) (11)

********************************************************************************

某些低等級弱點修復,ZAP掃描結果

Medium:
  • Absence of Anti-CSRF Tokens (11)
  • Content Security Policy (CSP) Header Not Set (12)
  • ELMAH 資訊外洩
  • Vulnerable JS Library (2)
Low:
  • Cookie without SameSite Attribute
  • Cross-Domain JavaScript Source File Inclusion (3)
Info:
  • Authentication Request Identified
  • Information Disclosure - Suspicious Comments (17)
  • Modern Web Application (11)
  • Re-examine Cache-control Directives (14)
  • Session Management Response Identified (18)
  • User Agent Fuzzer (12)
  • User Controllable HTML Element Attribute (Potential XSS) (11) 

********************************************************************************

不同的工具,判定結果本就可能不同。

********************************************************************************

SameSite 問題在 AWVS 是在 Cookies with missing, inconsistent or contradictory properties 弱點,因為 ASP.NET WebForm 的 Web.Config 並沒有直接支援該屬性,是以程式方式解決,但 ZAP 似乎仍判定有問題。

[研究][ASP.NET]弱點掃描出現Cookies with missing, inconsistent or contradictory properties之解決
https://shaurong.blogspot.com/2023/11/aspnetcookies-with-missing-inconsistent.html

敝人沒有 AWVS 修復後掃描結果,因該修復前 AWVS 不是敝人掃描。敝人想測試修復是否成功,故找了免費的 ZAP 來測試。

(完)

相關

[研究][ASP.NET]ZAP 與 AWVS 黑箱弱點掃描工具結果比較https://shaurong.blogspot.com/2023/11/aspnetzap-awvs.html

[研究][ASP.NET]OWASP Zed Attack Proxy (ZAP) 2.14.0 弱掃試用https://shaurong.blogspot.com/2023/11/aspnetowasp-zed-attack-proxy-zap-2140.html

[研究] OWASP Zed Attack Proxy (ZAP) v2.7.0 黑箱弱點掃描工具安裝與試用
http://shaurong.blogspot.com/2018/06/owasp-zed-attack-proxy-zap-v270.html

[研究] OWASP WebGoat 8.0 安裝
http://shaurong.blogspot.com/2018/06/owasp-webgoat-80.html

[研究] OWASP WebGoatFor.Net 安裝
http://shaurong.blogspot.com/2016/12/owasp-webgoatfornet.html

[研究] OWASP WebGoat 7.1 安裝
http://shaurong.blogspot.com/2016/12/owasp-webgoat-71.html

[研究] OWASP Zed Attack Proxy (ZAP) 2.4.2、2.6.0 滲透測試、弱點掃描工具安裝與試用
http://shaurong.blogspot.com/2015/10/owasp-zed-attack-proxy-zap-242.html

2017年6月17日 星期六

[研究] Acunetix Web Vulnerability Scanner (AWVS) 11 Trial 下載、安裝、試用

[研究] Acunetix Web Vulnerability Scanner (AWVS) 11 Trial 下載、安裝、試用

2017-06-17
2017-09-21 更新
2017-09-25 更新
2017-10-06 更新 
2020-05-27 更新 
2020-11-12 更新 

********************************************************************************
會自動轉網址到
只能下載正式版,需要 License Key, Full Name, Company ... 等資訊,沒有試用版了。

********************************************************************************
2020-05-27

試用版 or DEMO 版好像申請改用人工審核,不會直接發 Email 告知下載地點。

********************************************************************************

11.0 和舊版 10.x、9.x、8.x 差異很大,變成本機的 Web-Based 介面的軟體。

Acunetix Web Vulnerability Scanner (AWVS) 11

Acunetix Web Vulnerability Scanner (AWVS) 11 - 14 Days Trial

????-??-?? 下載,時間戮記 2017-04-05,版本 11.0.170951158
2017-05-26 下載,時間戮記 2017-05-18,版本 11.0.171381251
2017-09-21 下載,時間戮記 2017-08-23,版本 11.0.172351036
2017-09-25 下載,時間戮記 2017-09-21,版本 11.0.172641450
2017-10-13 下載,時間戮記 2017-09-27,版本 11.0.172701313
2017-10-20 下載,時間戮記 2017-10-17,版本 11.0.172901635
2017-11-03 下載,時間戮記 2017-10-17,版本 11.0.172901635 (版本依舊)
2017-11-06 下載,時間戮記 2017-10-17,版本 11.0.172901635 (版本依舊)
2017-11-08 下載,時間戮記 2017-10-17,版本 11.0.172901635 (版本依舊)
2017-11-13 下載,時間戮記 2017-11-09,版本 11.0.173131028
2017-11-20 下載,時間戮記 2017-11-09,版本 11.0.173131028 (版本依舊)
2017-12-11 下載,時間戮記 2017-11-23,版本 11.0.173271618
2017-12-14 下載,時間戮記 2017-11-23,版本 11.0.173271618 (版本依舊)
2018-05-26 下載,時間戮記 2018-05-23,版本 12

Acunetix Web Vulnerability Scanner 簡稱 AWVS,或 Acunetix WVS,是出名的黑箱測試、滲透測試掃描工具。

官方網站
http://www.acunetix.com/

14天試用版下載 (舊版只提供 SQL Injection 和 Cross-Site Scripting 掃描,不提供產生報告功能)
http://www.acunetix.com/vulnerability-scanner/download/
輸入資料後,會寄出 Email 到你輸入的 Email 信箱中,裡面包含下載網址和相關資訊。

Dear  *****,

Thank you for your interest in Acunetix!

Download your Acunetix 14-day Trial Edition, and Sample Reports here:
http://www.acunetix.com/download-8991-2

The Trial Edition allows you to scan any web site operated by you. You will be informed of vulnerabilities detected but the vulnerability details and solutions are only shown for the Acunetix test web sites"

In addition, you can review the full scan results including vulnerabilities detected using AcuSensor, by running a scan against one of these Acunetix test sites:
- http://testphp.vulnweb.com
- http://testasp.vulnweb.com
- http://testaspnet.vulnweb.com
- http://testhtml5.vulnweb.com

The Acunetix user manual may be downloaded here:
http://www.acunetix.com/resources/wvsmanual.pdf

We also maintain a support FAQ and a Web Application Security blog which answers common support and web security questions:
http://www.acunetix.com/blog
http://www.acunetix.com/support/

Should you have any sales queries, please do not hesitate to email me at jma@acunetix.com or call on

Sales APAC: +44 (0)330 202 0190
Support APAC: +44 (0)330 202 0193

To stop receiving further notifications on the above, please click here: https://erp.acunetix.com/downloads/downloads/unsubscribe.aspx?i=cjjxazkqqlgjuzsh

Thanks and regards,

Jean-Michel Azzopardi
Regional Sales Executive
Acunetix
jma@acunetix.com

------------------------------------------------------------
Product ID: WVSDEMOB
Product Name: Acunetix Demo B



下載得到檔案 acunetix_trial.exe,43.8 MB (45,930,232 位元組)

商業版本定價
http://www.acunetix.com/ordering/

11.0 Trial 直接下載
http://www.acunetix.com/download-8991-2
https://s3.amazonaws.com/a280ccaaf904330a389db759e6275285/acunetix_trial.exe

舊版直接下載 ( 有可能不存在了)
http://www.acunetix.com/vulnerability-scanner/vulnerabilityscanner.exe

軟體是 2016-05-26 下載,在 Windows 7 x64上測試
























新增說明文字







Acunetix Build History
2020年 Verison 13
2019年 Verison 12
2018年 Verison 11
2017年 Verison 10

(完)

相關

[研究] Acunetix Web Vulnerability Scanner (AWVS) 11 Trial 下載、安裝、試用

[研究] Acunetix Web Vulnerability Scanner (AWVS) 10 Trial 試用
http://shaurong.blogspot.com/2016/05/acunetix-web-vulnerability-scanner-awvs.html

[研究] Acunetix Web Vulnerability Scanner (AWVS) 9.5 Trial 試用
http://shaurong.blogspot.com/2014/07/acunetix-web-vulnerability-scanner-95.html

[研究] Acunetix Web Vulnerability Scanner (AWVS) 8 Trial 試用
http://shaurong.blogspot.com/2013/08/acunetix-web-vulnerability-scanner-8_31.html

2016年5月26日 星期四

[研究] Acunetix Web Vulnerability Scanner (AWVS) 10 Trial 試用

[研究] Acunetix Web Vulnerability Scanner (AWVS) 10 Trial 試用

2016-05-26

********************************************************************************
會自動轉網址到
只能下載正式版,需要 License Key, Full Name, Company ... 等資訊,沒有試用版了。

********************************************************************************

Acunetix Web Vulnerability Scanner 簡稱 AWVS,或 Acunetix WVS,是出名的黑箱測試、滲透測試掃描工具。

官方網站
http://www.acunetix.com/

14天試用版下載 (只提供 SQL Injection 和 Cross-Site Scripting 掃描,不提供產生報告功能)
http://www.acunetix.com/vulnerability-scanner/download/

商業版本定價
http://www.acunetix.com/ordering/

直接下載
http://www.acunetix.com/vulnerability-scanner/vulnerabilityscanner.exe
(這個網址會下載最新版,所以目前只會下載到 9.5 試用版)

軟體是 2016-05-26 下載,在 Windows 2012 R2 x64 上測試









(下圖) 這裡說明了試用版的限制

















(完)

相關

[研究] Acunetix Web Vulnerability Scanner (AWVS) 10 Trial 試用
http://shaurong.blogspot.com/2016/05/acunetix-web-vulnerability-scanner-awvs.html

[研究] Acunetix Web Vulnerability Scanner (AWVS) 9.5 Trial 試用
http://shaurong.blogspot.com/2014/07/acunetix-web-vulnerability-scanner-95.html

[研究] Acunetix Web Vulnerability Scanner (AWVS) 8 Trial 試用
http://shaurong.blogspot.com/2013/08/acunetix-web-vulnerability-scanner-8_31.html