releases

Acunetix Web Vulnerability Scanner Product Releases

docs & FAQs

Acunetix technical documentation and FAQ

news

Acunetix Company and Web Security news, & Press Releases

events

Acunetix Webinars, Events and Training around the world

web security zone

Everything you need to know about Web Security

Home » Archive by Author

Articles by

AcuSensor and the pink blog
February 26, 2009 – 3:40 pm | 2 Comments
AcuSensor and the pink blog

While testing our AcuSensor technology, I downloaded a small PHP blog application from the internet. The installation went smoothly. This particular application was not using a database but it was storing everything in text files. …

The hidden dangers of XSLTProcessor – Remote XSL injection
February 3, 2009 – 10:14 pm | 3 Comments
The hidden dangers of XSLTProcessor – Remote XSL injection

Today I’m going to talk about a new vulnerability which I named Remote XSL Inclusion.  I didn’t find any references on the internet about this vulnerability, which I found while auditing some PHP code for …

URL Rewriting and AcuSensor Technology; automation and advantages
December 9, 2008 – 3:59 pm | No Comment
URL Rewriting and AcuSensor Technology; automation and advantages

Nowadays, a lot of web applications are using URL rewriting. URL rewriting involves converting normal URLs to search engine friendly URLs. Usually the reason for doing this is to improve the rankings in search engines.
A …

AcuSensor Technology in action; finding backdoors in web applications
November 25, 2008 – 8:51 pm | 2 Comments
AcuSensor Technology in action; finding backdoors in web applications

On March 2, 2007 the following was posted on the WordPress blog:
Long story short: If you downloaded WordPress 2.1.1 within the past 3-4 days, your files may include a security exploit that was added by …

SQL Injection in Mambo found with Acunetix AcuSensor Technology
November 13, 2008 – 4:22 pm | No Comment
SQL Injection in Mambo found with Acunetix AcuSensor Technology

This post shows how with Acunetix AcuSensor Technology improves scanning reliability by using sensors placed inside the web application being scanned.  It also proves that with this technology, one can detect SQL injections in INSERT …

Running AcuSensor Injector on Windows Server 2008
October 22, 2008 – 3:07 pm | No Comment
Running AcuSensor Injector on Windows Server 2008

If you try to run AcuSensor Injector on Windows Server 2008 you will receive the error “Error populating websites, Unknown error (0×80005000)”.
AcuSensor Injector is using Active Directory Service Interfaces (ADSI) to construct a list of …