Misleading Reports of 0-Day in Invicti WVS

Reports of a 0-day vulnerability in Invicti Web Vulnerability Scanner turn out to affect only an old version from 2012 which was subsequently fixed. A blog post has recently come to our attention that claims a successful attack against Invicti v8 (build 20120704), and in…

Read more

Scanning for Heartbleed using Invicti

Soon after the Heartbleed bug was made public, Invicti released an update to detect the vulnerability in websites and web applications. The script that detects this is called Heartbleed_Bug.script, and is included in the following Scanning Profiles: Default High_Risk_Alerts The newly created heartbleed profile The…

Read more

The Aftermath of the Heartbleed Bug

The Heartbleed bug, a security flaw in the popular OpenSSL library used for data encryption, has taken the web security world by storm, and the victim toll has started to rise. The first reported victims include the Canada Revenue Agency (with 900 social security numbers…

Read more

Elaborate Ways to Exploit XSS: XSS Proxies

In his book “Web Application Vulnerabilities: Detect, Exploit, Prevent”, Steve Palmer describes XSS Proxies as cross-site scripting exploitation tools that allow attackers to temporarily take control over the victim’s browser. XSS Proxy functions as a web server which takes commands from the attacker via a…

Read more

CSRF and XSS – Brothers in Arms

What is CSRF (XSRF)? Cross-Site Request Forgery is a type of web attack which exploits the trust of a website in the user’s browser. In essence, the attacker manipulates the victim’s browser to send requests in the user’s name to websites that have been visited…

Read more

Visit the Invicti Stand at Infosecurity Europe 2014

Invicti is to be exhibited in the New Exhibitor’s Zone at Infosecurity Europe at Earls Court from the 29th of April till the 1st of May. Infosecurity Europe is the largest free-to attend information security business and education event in Europe – offering attendees the…

Read more