Web application security scanners are automated testing and scanning programs that examine web applications for potential security vulnerabilities. WASec
(Web Application Security) was created as a security scanner that uses black-box
testing to scan web applications for error-based and time-based SQL injection along
with Reflected Cross-site Scripting vulnerabilities and report them. WAsec was tested against web applications of known vulnerabilities. The testing process, although
preliminary, has showed promising results. The design and implementation of this
tool was intended to tackle the current security problems in Libyan websites.