March 3, 2010 – 5:31 pm | No Comment

An updated build of Acunetix WVS Version 6.5 has been released.  This build includes a new feature and new security checks, improvements and addresses a number of bug fixes.
New Feature:

Added new option to export results …

Read the full story »
releases

Acunetix Web Vulnerability Scanner Product Releases

acunetix how to

Technical tips and videos about Acunetix WVS and Web Security

news

Acunetix Company and Web Security news, & Press Releases

events

Acunetix Webinars and Training around the world

web security zone

Everything you need to know about Web Security

Looking past layer 7
January 19, 2010 – 8:01 pm | 3 Comments

When it comes to Web security why is it we always seem to focus on layer 7 only? Sure, it can be argued that XSS, SQL injection, flawed application logic and so on are the …

Statistics from the top 1,000,000 websites
January 12, 2010 – 2:00 pm | 7 Comments

The next version of Acunetix Web Vulnerability Scanner (version 7), will contain a much more improved HTTP stack.   While testing, we wanted to test the new HTTP stack on as many sites as possible to …

Acunetix WVS Version 6.5 build 20100111 released
January 11, 2010 – 7:35 pm | No Comment

An updated build of Acunetix WVS Version 6.5 has been released with a number of new security checks and bug fixes.

New security checks:

Test for File Upload IIS bug filename.asp;.jpg
Test for WP-Forum 2.3 vulnerabilities
JBoss rmi ping …

Acunetix WVS Version 6.5 build 20091215 released
December 16, 2009 – 4:52 am | 3 Comments

An updated build for Acunetix WVS Version 6.5 has been released with a number of improvements, bug fixes, and a number of new security checks.
New security checks:

JBoss BSHDeployer MBean
JBoss checks from RedTeam’s paper
JBoss HttpAdaptor JMXInvokerServlet
JBoss …

AcuSensor, curl and Zen Cart
December 9, 2009 – 7:10 pm | 7 Comments

Recently we’ve released a new build, build number 20091124. This build includes a new AcuSensor check named “curl_exec() url is controlled by user”. This new check will verify if the user can control the URL passed to curl_exec.
In …

Changes coming to the OWASP Top 10 in 2010
December 3, 2009 – 8:24 pm | 8 Comments

In the spirit of improving Web application security worldwide the folks at OWASP have released the OWASP Top 10 2010 “release candidate”. It’s currently open for comments and scheduled for final release the first quarter …

Invasive vs. non invasive web application security scan
November 26, 2009 – 7:59 pm | 3 Comments

When evaluating an automated web application security tool, such as Acunetix WVS, the first two questions that typically one would ask are “Does this tool perform an invasive scan or not?”, “Will it damage my …

Acunetix WVS Version 6.5 build 20091124 released
November 24, 2009 – 4:05 pm | 2 Comments

An updated build for Acunetix WVS Version 6.5 has been released with a number of improvements, bug fixes, and most important of all, a good number of new security checks.
New:

New security checks of AcuSensor Technology

curl_exec() …

PHP “multipart/form-data” denial of service
November 20, 2009 – 7:07 pm | 4 Comments

PHP version 5.3.1 was just released. This release contains a patch for a denial of service condition we’ve reported some time ago.
The problem is related with PHP’s handling of RFC 1867 (Form-based File Upload in …

US Air Force uses Acunetix WVS to identify and mitigate web application vulnerabilities
November 16, 2009 – 7:03 pm | 4 Comments

The US Air Force’s mission is to fly, fight and win… in air, space and Cyberspace.  US Air Force has an elite force defending people from millions of cyber attacks every day in their newest …