Using Client Certificates in Invicti

In most TLS handshakes, the client authenticates the server, therefore, the client knows that the server is who it says it is, but the server doesn’t know much about the client. In most cases, this is fine — authentication via credentials is enough in many…

Read more

Issue Tracker Integration with Invicti

An Issue Tracker such as Atlassian JIRA, GitHub and Microsoft TFS is a powerful and essential tool in the Software Development Life Cycle (SDLC) of almost any software project. It helps development teams streamline collaboration and manage their work without getting lost in an endless…

Read more

Invicti Vulnerability Testing Report 2017

Each year the Invicti Team compiles a vulnerability testing report based on data from Invicti Online. This third Vulnerability Testing Report contains data and analysis of vulnerabilities detected by Invicti throughout the period of March 2016 to March 2017, illustrating the state of security of…

Read more

What is a Host Header Attack?

It is common practice for the same web server to host several websites or web applications on the same IP address. This why the host header exists. The host header specifies which website or web application should process an incoming HTTP request. The web server…

Read more