If you are running a web server, it often shows the world what type of server it is, its version number, and sometimes even the operating system. This information is exposed in HTTP response headers and can be obtained with a simple request using a…
Author Archives Nicholas Sciberras
Invicti releases support for RHEL 9, updates CWE report, and improves PHP IAST AcuSensor
A new Invicti Premium update has been released for Windows and Linux: 15.0.221007170. This Invicti release introduces support for Red Hat Enterprise Linux (RHEL) 9, which has been released earlier this year. The PHP IAST AcuSensor can now be used with web applications that take…
Invicti releases IAST support for WebSphere and improves crawling of SPAs
A new Invicti Premium update has been released for Windows, Linux, and macOS: 14.9.220713150 This Invicti release introduces IAST support for WebSphere enabling the use of the Java IAST sensor (AcuSensor) with this Java server. In addition, Invicti DeepScan has been updated to better scan…
Invicti releases IAST support for JBoss, Jetty and WildFly Java servers as well as Servlet 3 and Jersey Java frameworks
A new Invicti Premium update has been released for Windows, Linux, and macOS: 14.8.220519149. This Invicti release introduces support for JBoss, Jetty and WildFly, allowing the Java IAST sensor (AcuSensor) to be used with these Java servers. In addition, the Java IAST sensor has been…
Invicti introduces IAST updates improving vulnerability and misconfiguration detection as well as scan coverage
A new Invicti Premium update has been released for Windows, Linux, and macOS: 14.7.220228146 This Invicti release introduces multiple IAST updates that will help detect several high severity vulnerabilities, provide full coverage for the newly supported web frameworks, and improve the detection of server-side misconfigurations….
Invicti releases multiple updates to detect Log4j vulnerabilities
Over the past week, we have been busy updating Invicti to detect Log4j vulnerabilities that have been making the headlines. Invicti is detecting the CVE-2021-44228 vulnerability (Log4Shell) as an out-of-band vulnerability using the AcuMonitor service. In addition, the AcuMonitor service and Invicti have been updated…
Invicti introduces support for the detection of HTTP/2 vulnerabilities and improves handling of Laravel CSRF tokens
A new Invicti Premium update has been released for Windows, Linux, and macOS: 14.6.211207099. This Invicti release introduces support for the detection of HTTP/2 vulnerabilities. HTTP/2 is an upgrade to the HTTP protocol and is used more and more frequently. It does however introduce a…
Invicti introduces support for Brotli encoding, IAST support for new Node.js frameworks, and many new vulnerability checks
A new Invicti Premium update has been released for Windows, Linux, and macOS: 14.5.211008143. This Invicti release introduces support for the Brotli encoding and URL optional fields. The Node.js IAST AcuSensor has been updated to support numerous frameworks and the JAVA IAST AcuSensor can now…
Invicti introduces pre-request scripts, log data retention options, and many new vulnerability checks
A new Invicti Premium update has been released for Windows, Linux, and macOS: 14.4.210816098. This Invicti release introduces pre-request scripts that can be developed using the existing custom vulnerability scripts syntax, new log data retention options, and new vulnerability checks for Oracle E-Business Suite, Alibaba…