<?xml version="1.0" encoding="UTF-8"?><rss version="0.92">
<channel>
	<title>Acunetix Web Application Security Blog</title>
	<link>http://www.acunetix.com/blog</link>
	<description>Acunetix Web Application Security Blog</description>
	<lastBuildDate>Tue, 07 Sep 2010 13:10:27 +0000</lastBuildDate>
	<docs>http://backend.userland.com/rss092</docs>
	<language>en</language>
	<!-- generator="WordPress/3.0.1" -->

	<item>
		<title>Web Security problems in Zenphoto version 1.3</title>
		<description><![CDATA[We are continuing with the list of security vulnerabilities found in a number of web applications while testing our latest version of Acunetix WVS v7 . In this blog post, we will look into the ...]]></description>
		<link>http://www.acunetix.com/blog/web-security-zone/articles/zenphoto-13-advisory/</link>
			</item>
	<item>
		<title>Security vulnerabilities in Pligg CMS version 1.0.4</title>
		<description><![CDATA[While beta testing the latest version of Acunetix WVS v7, we found a large number of security vulnerabilities in various web applications. In the following days we will publish some of these vulnerabilities.  Note that ...]]></description>
		<link>http://www.acunetix.com/blog/web-security-zone/articles/web-vulnerabilities-pligg/</link>
			</item>
	<item>
		<title>Acunetix 7 makes web application security checking easier and more cost effective</title>
		<description><![CDATA[New scanning engine with improved vulnerability detection AND verification makes finding and fixing security issues in web applications easier.
London, 1st September 2010 – Acunetix, a market leader in web application security scanning technology, today announced ...]]></description>
		<link>http://www.acunetix.com/blog/releases/acunetix-7-web-security-easier-cost-effective/</link>
			</item>
	<item>
		<title>VIDEO: What&#8217;s new in Acunetix WVS v7?</title>
		<description><![CDATA[Check out this 4 minutes YouTube video to find out what&#8217;s new in the new and revolutionary Acunetix Web Vulnerability Scanner Version 7.

Click here to watch the high quality version of this video
]]></description>
		<link>http://www.acunetix.com/blog/docs/video-acunetix-wvs-v7/</link>
			</item>
	<item>
		<title>Acunetix WVS V7 RC1 is available</title>
		<description><![CDATA[The Release Candidate build for Acunetix Web Vulnerability Scanner Version 7 (20100825) is now available for download.  All of the bugs reported during the Beta were fixed.  We also added some improvements in this RC ...]]></description>
		<link>http://www.acunetix.com/blog/releases/acunetix-wvs-v7-rc1/</link>
			</item>
	<item>
		<title>Acunetix WVS Version 7 BETA 2 is available</title>
		<description><![CDATA[An updated build of Acunetix WVS Version 7 BETA has been released.  This build includes the following number of improvements:

Improved Cross-Site scripting (XSS) vulnerabilities detection scripts
Improved blind SQLl injection vulnerability checks to reduce false positives
Added ...]]></description>
		<link>http://www.acunetix.com/blog/releases/acunetix-wvs-version-7-beta-2/</link>
			</item>
	<item>
		<title>Creating custom vulnerability checks for Acunetix WVS Version 7</title>
		<description><![CDATA[Vulnerability checks in Acunetix Web Vulnerability Scanner version 7 consists of two files;

*.script &#8211; The actual vulnerability check written in JavaScript.  Such scripts are stored in the ‘\Data\Scripts\’ sub directory in the Acunetix WVS installation ...]]></description>
		<link>http://www.acunetix.com/blog/docs/creating-vulnerability-checks/</link>
			</item>
	<item>
		<title>Acunetix WVS Version 7 BETA is available!</title>
		<description><![CDATA[A new version of Acunetix Web Vulnerability Scanner is available in beta, and what a version!
It has been one long year of development, testing and late nights at the office, though it was all worth ...]]></description>
		<link>http://www.acunetix.com/blog/releases/acunetix-wvs-7-beta/</link>
			</item>
	<item>
		<title>Manual crawling with HTTP Sniffer Tool</title>
		<description><![CDATA[It is possible to manually crawl your website using a web browser. From these manually crawled links, then it is possible to build a website structure which the final scan will target.  This is useful ...]]></description>
		<link>http://www.acunetix.com/blog/docs/manual-crawling-http-sniffer/</link>
			</item>
	<item>
		<title>HTTP Editor Tool</title>
		<description><![CDATA[The HTTP Editor tool allows you to create, analyze and edit client HTTP requests and server responses. This allows you to further fine tune attacks and check if vulnerabilities were solved.
You can start the HTTP ...]]></description>
		<link>http://www.acunetix.com/blog/docs/http-editor/</link>
			</item>
	<item>
		<title>Authentication Tester Tool</title>
		<description><![CDATA[The Authentication Tester tool in Acunetix WVS is used to test the strength of both usernames and passwords within HTTP and web forms authentication environments via a dictionary attack.

Testing HTTP Authentication


HTTP authentication is part of ...]]></description>
		<link>http://www.acunetix.com/blog/docs/authentication-tester/</link>
			</item>
	<item>
		<title>Blind SQL Injector Tool</title>
		<description><![CDATA[Ideal for penetration testers, the Blind SQL injector is an automated database data extraction tool. By importing SQL injections discovered when scanning a website, you can see what a serious impact an SQL injection can ...]]></description>
		<link>http://www.acunetix.com/blog/docs/blind-sql-injector-tool/</link>
			</item>
	<item>
		<title>HTTP Fuzzer Tool</title>
		<description><![CDATA[With the HTTP Fuzzer tool in Acunetix WVS you can automatically send a large number / volume of HTTP Requests including invalid, unexpected and random data to a website, to test its input validation capabilities.  ...]]></description>
		<link>http://www.acunetix.com/blog/docs/http-fuzzer-tool/</link>
			</item>
	<item>
		<title>Subdomain Scanner</title>
		<description><![CDATA[The Subdomain Scanner in Acunetix WVS scans a top-level domain to discover subdomains configured in its hierarchy, by using the target domain’s DNS server, or any other DNS server specified by the user.  While scanning, ...]]></description>
		<link>http://www.acunetix.com/blog/docs/subdomain-scanner/</link>
			</item>
	<item>
		<title>Target Finder tool</title>
		<description><![CDATA[The Target Finder tool in Acunetix WVS is a port scanner which can be used to discover running web servers on a given IP or within a specified range of IP’s.  The list of ports ...]]></description>
		<link>http://www.acunetix.com/blog/docs/target-finder/</link>
			</item>
	<item>
		<title>Getting developers on board with security &#8211; once and for all</title>
		<description><![CDATA[Making Web application security work is more than simply telling developers they need to write better code. We can scream “Write better code!” and “Integrate security into the application lifecycle!” at developers until end of ...]]></description>
		<link>http://www.acunetix.com/blog/web-security-zone/articles/getting-developers-security/</link>
			</item>
	<item>
		<title>Discovered XSS on Facebook can lead to account hijack</title>
		<description><![CDATA[Facebook rates as the second most popular website on the internet with 400 million active users. When such a website has common web application security flaws, they are going to be abused for one’s gain. ...]]></description>
		<link>http://www.acunetix.com/blog/news/cross-site-scripting-xss-facebook/</link>
			</item>
	<item>
		<title>Web security oversights: Don&#8217;t overlook the “small” stuff</title>
		<description><![CDATA[I was reviewing the most recent SANS @RISK Consensus Security Vulnerability Alert and it reminded me of how easy it is to get caught up in the big stuff and overlook the seemingly innocuous when ...]]></description>
		<link>http://www.acunetix.com/blog/web-security-zone/articles/web-security-oversights/</link>
			</item>
	<item>
		<title>Dangerous XSS vulnerability found on YouTube – the vulnerability explained</title>
		<description><![CDATA[On the 4th of July 2010 YouTube users began complaining that their videos had been hijacked, the comments section of their videos seemed to be most severely affected, many complained that old comments vanished and new comments could not be added. Others reported that offensive messages were popping up on their screen or scrolling horizontally in large fonts and striking colors. Some users also seemed to suggest that there were experiencing page redirects, often to sites promoting pornographic content.]]></description>
		<link>http://www.acunetix.com/blog/web-security-zone/articles/dangerous-xss-vulnerability-found-on-youtube-the-vulnerability-explained/</link>
			</item>
	<item>
		<title>Acunetix WVS takes first place in black box web vulnerability scanners comparison</title>
		<description><![CDATA[Acunetix Web Vulnerability Scanner placed first in a paper released by Adam Doup´e, Marco Cova, and Giovanni Vigna from the University of California, Santa Barbara.  In the paper &#8220;Why Johnny Can’t Pentest: An Analysis of ...]]></description>
		<link>http://www.acunetix.com/blog/news/acunetix-wvs-first-place-black-box-web-vulnerability-scanners-comparison/</link>
			</item>
	<item>
		<title>OWASP AppSec US 2010, California</title>
		<description><![CDATA[Acunetix will be exhibiting at the OWASP AppSec US 2010 in California.  The event will take place between 7th and 10th of September 2010.  The event will be held at UC Irvine Conference Center, in ...]]></description>
		<link>http://www.acunetix.com/blog/events/owasp-appsec-us-2010/</link>
			</item>
	<item>
		<title>In-depth analysis of a PHP attack that lead to Apple information disclosure</title>
		<description><![CDATA[Recently over 100,000 Apple customers were affected by an information gathering attack on the AT&#38;T website. Security experts blame this breach on "poorly designed software". An analysis of the attack reveals that the hackers did indeed use a classic attack, in fact...]]></description>
		<link>http://www.acunetix.com/blog/web-security-zone/articles/analysis-php-attack-apple-information-disclosure/</link>
			</item>
	<item>
		<title>Seven Signs You’re Not Ready to Run a Web Vulnerability Scan</title>
		<description><![CDATA[Looking to hop aboard the Web vulnerability scanning bandwagon to see just how vulnerable your Web site or application really is? Well, not so fast. Here are some signs you’re not ready to begin just ...]]></description>
		<link>http://www.acunetix.com/blog/web-security-zone/articles/seven-signs-not-ready-run-web-vulnerability-scan/</link>
			</item>
	<item>
		<title>Web application contingency plans &#8211; the missing link in Web security?</title>
		<description><![CDATA[Why are Web applications out of the loop when it comes to contingency planning? Look at any given security incident response or disaster recovery plan (assuming they even exist) and chances are business critical Web ...]]></description>
		<link>http://www.acunetix.com/blog/web-security-zone/articles/web-application-contingency-plans-web-security/</link>
			</item>
	<item>
		<title>web application firewall bypass with a XSS attack</title>
		<description><![CDATA[In the following demo video, Sandro Gauci of EnableSecurity shows how an attacker can switch off dotDefender in order to bypass any &#8220;protection&#8221; offered by the WAF.  Such attack is possible By exploiting a cross-site ...]]></description>
		<link>http://www.acunetix.com/blog/news/web-application-firewall-bypass-xss-attack/</link>
			</item>
	<item>
		<title>Should you scan a website through a web application firewall?</title>
		<description><![CDATA[Unfortunately, it is of frequent occurrence that people launch a security scan against a website or web application sitting behind a web application firewall, or some other kind of web security gateway device.  Scanning a ...]]></description>
		<link>http://www.acunetix.com/blog/web-security-zone/articles/scan-website-web-application-firewall/</link>
			</item>
	<item>
		<title>Third Annual Meetings of Heads of Information Systems Security RSSI&#8217;2010</title>
		<description><![CDATA[Acunetix reseller Hat Web Security Labs will be exhibiting Acunetix WVS in the Third Annual Meetings of Heads of Information Systems Security RSSI&#8217;2010.  The event will take place between 3rd and 4th of June 2010 ...]]></description>
		<link>http://www.acunetix.com/blog/events/third-annual-meetings-of-heads-of-information-systems-security-rssi2010/</link>
			</item>
	<item>
		<title>Acunetix WVS helps Digicure discover web vulnerabilities</title>
		<description><![CDATA[A proper web security audit is a mixture of automated and manual tests; Acunetix WVS provides a comprehensive tool for automated testing purposes and useful toolbox Digicure can use for manual penetration testing as well.  ...]]></description>
		<link>http://www.acunetix.com/blog/news/acunetix-wvs-digicure-web-vulnerabilities/</link>
			</item>
	<item>
		<title>SQL Injection hits again; 168,000 personal records exposed</title>
		<description><![CDATA[A hacker, who calls himself &#8220;ins3cted&#8221;, has demonstrated to Webwereld via video how by exploiting a simple SQL injection, he can retrieve 168,000 personal records from a Dutch website called Experience the OV (http://www.ervaarhetov.nl).
Citizens living ...]]></description>
		<link>http://www.acunetix.com/blog/news/sql-injection-records-exposed/</link>
			</item>
	<item>
		<title>Creating a Web security testing policy</title>
		<description><![CDATA[If you’re reading this blog, Web security testing is undoubtedly on your radar.  You may have an ongoing process for testing Web vulnerabilities but do you actually have a policy for it? I’m all ...]]></description>
		<link>http://www.acunetix.com/blog/web-security-zone/articles/web-security-testing-policy/</link>
			</item>
</channel>
</rss>
