False-Positive Settings

Top  Previous  Next

False-positive settings allow you to configure scan settings to avoid incorrect vulnerability detection. N-Stalker currently allows for two kind of false-positive mechanisms:

 

Automatic detection
Manual filtering

 

These are the available options:

 

getting-started-6

 

Enable False-positive mechanism for multiple file extensions

Allow N-Stalker to automatically detect false-positive patterns for different file extensions

Enable False-positive auto-filter mechanism for 404 not found pages

Sometimes web servers will provide non-standard responses to a not found resource (instead of 404 status code). When this happen, invalid resources can be mistakenly taken as a vulnerability. When this option is enabled, N-Stalker will search for these patterns and create automatic filters to avoid it

Disable New Server Discovery to avoid false-positive

Certain web servers might incorrectly provide different server strings on each distinct connection. This situation might cause N-Stalker to detect a large number of different web servers. We strongly advise you to keep this configuration unchecked unless you are sure that a web server has such behavior (we suggest using "automatic optimization" tool)

False-positive Regex Filter

Add custom keywords that will be used to match and filter false-positive responses (regular expression is allowed).

 

Important Note: You may use the "wand" button to generate a sample set of common keywords to filter false-positive responses.