覆盖WASC和OWASP两大Web安全标准组织定义的主流的各种攻击技术和手段,包括但不限于:
Brute Force、Insufficient Authentication、Credential/Session Prediction、Insufficient Authorization、Insufficient Session Expiration、Session Fixation、Content Spoofing、Cross-site Scripting、Buffer Overflow、Format String Attack、LDAP Injection、OS Commanding、SQL Injection、SSI Injection、XPath Injection、Directory Indexing、Information Leakage、Path Traversal、Predictable Resource Location、Abuse of Functionality、Denial of Service、Insufficient Process Validation等攻击技术和方法,其中,对于Cross Site Scripting,能够检测至少20种变种;对于SQL Injection,能够检测至少40种变种;