logo

Database

WASSEC

Last updated: 2023/09/18
logo

The Web Application Security Scanner Evaluation Criteria (WASSEC) is a set of guidelines to evaluate web application scanners on their ability to effectively test web applications and identify vulnerabilities. It covers areas such as crawling, parsing, session handling, testing and reporting. The version used in this section is WASSEC version 1.0.

Control-Requirement Mapping

DefinitionRequirements
1_1. Transport support
2_1. Authentication schemes
3_1. Session management capabilities
3_2_1. HTTP cookies
3_3. Session token detection configuration
3_4. Session token refresh policy
4_1. Web crawler configuration
4_1_5. Supporting concurrent sessions
5_3. Parser tolerance
5_5. Extraction of dynamic content
6_1_2. URL patterns
6_1_6. HTTP headers
6_2_1_1. Authentication - Brute force
6_2_1_2. Authentication - Insufficient authentication
6_2_1_3. Authentication - Weak password recovery validation
6_2_1_4. Authentication - Lack of SSL on login pages
6_2_2_1. Authorization - Credential/Session prediction
6_2_2_2. Authorization - Insufficient authorization
6_2_2_3. Authorization - Insufficient session expiration
6_2_2_4. Authorization - Session fixation
6_2_2_5. Authorization - Session weaknesses
6_2_3_1. Client-side attacks - Content spoofing
6_2_3_2. Client-side attacks - Cross-site scripting
6_2_3_4. Client-side attacks - HTML injection
6_2_3_5. Client-side attacks - Cross-site request forgery
6_2_3_6. Client-side attacks - Flash-related attack
6_2_4_1. Command execution - Format string attack
6_2_4_2. Command execution - LDAP injection
6_2_4_3. Command execution - OS command injection
6_2_4_4. Command execution - SQL injection
6_2_4_6. Command execution - Xpath injection
6_2_4_8. Command execution - Remote file includes
6_2_4_9. Command execution - Local file includes
6_2_4_10. Command execution - Potential malicious file uploads
6_2_5_2. Information disclosure - Information leakage
6_2_5_3. Information disclosure - Path traversal
6_2_5_5. Information disclosure - Insecure HTTP methods enabled
6_2_5_7. Information disclosure - Default web server files
8_4_1. Compliance report