Starting from Invicti v11, the manual tools, are being provided as a separate installation downloadable for free from https://www.acunetix.com/vulnerability-scanner/free-manual-pen-testing-tools/ The suite of Manual Tools include: HTTP Editor –  to create, analyze, and edit client HTTP requests; as well as inspect server responses. HTTP Sniffer – to analyze HTTP requests…
Author Archives Nicholas Sciberras
New Invicti build introduces a new web API, and new set of Joomla! Core and WordPress plugin vulnerability checks
Invicti v11 (build 163541031) has been released. This new build includes a new API, which is available to all our Invicti Enterprise customers, and re-introduces the importation of Selenium IDE scripts. In addition, the new build includes a set of Joomla! Core and WordPress plugin…
How can I access Invicti v11?
In Invicti v11, the user interface is web based, and by default the web server hosting the web application is running on port 3443. Therefore, if you are logged into the machine running Invicti, you can browse to https://localhost:3443 to access Invicti. If you need…
Difference between Site Login and HTTP Authentication
When configuring a Target, you sometimes need to configure login details to the web application. This allows Invicti to check the restricted areas in your web application. There are two types of authentication that can be done with a web site – Form-based authentication and…
The latest build of Invicti updates PCI DSS and NIST compliance reports
Invicti v10.5 build 20160504 has been released. This new build updates the PCI DSS and the NIST compliance reports with the requirements of PCI DSS 3.2 and NIST 800-53 rev4 respectively. The new build also fixes an important bug uncovered earlier this week. Improvements Updated…
Latest build of Invicti includes new version of .NET AcuSensor, checks for JSP source code disclosure and improves crawling capabilities
Invicti v10.5 (build 20160427) has been released. This new build includes a new version of the .NET AcuSensor registers with .NET web applications in a way that supports signed .NET Assemblies. In addition, it includes new and improved vulnerability checks and a number of minor…
Invicti v10.5 adds support for Joomla! Drupal and CVSS3.0
A new version of Invicti Web Vulnerability Scanners v10.5 has been released. The new version tests for Joomla! and Drupal vulnerabilities, supports CVSS 3.0 and includes other improvements/bug fixes. Joomla! and Drupal Support Invicti v10.5 now reports vulnerabilities in popular content management systems Joomla! and Drupal. The…
Invicti 10 build includes security checks in CORS configurations, Rails web applications and identifies the vBulletin 5 RCE
Invicti 10 (build 20151125) has been released. This new build checks for insecure DNS records, insecure CORS configurations, Rails web applications running in development mode, web applications running Tornado and Pyramid in debug mode and various new and updated vulnerability checks including one for vBulletin…
Invicti OVS updated to allow better Vulnerability Management
Invicti Online Vulnerability Scanner (OVS) has been updated to provide better web and perimeter security, while providing an improved indication of the security of your assets. Through this update, Invicti OVS users can easily identify their long forgotten assets, rest assured that their servers are…