In addtion to full JSON and XML support (already covered in Part I), Invicti WVS version 9.5 includes other improvements that increase the scan coverage and improves its abilities to find vulnerabilities. In this blog post, I will cover CRUD support, Host header testing and…
More comprehensive scanning with Invicti WVS v9.5 – Part I
In these 2 articles, I will be detailing the new functionality introduced in Invicti WVS version 9.5. An important update introduced in the new version of Invicti WVS is full JSON and XML support. If you are scanning a web application that is exchanging data…
Scan Google Web Toolkit Applications with Invicti
Google Web Toolkit (GWT) is an open source set of tools that allows web developers to create and maintain complex JavaScript front-end applications in Java, using the Java development tools of their choice. It is a development toolkit for building and optimizing complex browser-based applications….
Latest Invicti release scans for Heartbleed Bug
Yesterday, an update was released for Invicti Vulnerability Scanner which includes a test for a critical OpenSSL vulnerability named The Heartbleed Bug (CVE-2014-0160). Quote from the report: The Heartbleed Bug is a serious vulnerability in the popular OpenSSL cryptographic software library. This weakness allows stealing the…
Invicti Web Vulnerability Scanner v9, build 20140206 includes several new tests for vulnerabilities on well-known web applications
Invicti Web Vulnerability Scanner version 9, build 20140206 is able to scan WordPress more efficiently, and includes various new checks for vulnerabilities in well-known systems such as MediaWiki, IBM Web Content Manager, Joomla! and Oracle. New Functionality in Invicti Web Vulnerability Scanner v9 Added a…
Invicti Web Vulnerability Scanner v9, build 20131216 includes a new PCI 3.0 compliance report and several new tests
Invicti Web Vulnerability Scanner version 9, build 20131216 includes a new compliance report to cover the latest version of the PCI DSS Regulations. In addition, this new build checks for several vulnerabilities in various systems including Ruby on Rails, Zend Framework, Nginx and WordPress. New…
New Security Checks Added to Invicti Web Vulnerability Scanner
The latest build of Invicti Web Vulnerability Scanner includes a lot of changes and new security tests. Here is a short summary of the most interesting tests we’ve just added. 1. Vulnerable JavaScript libraries Invicti Web Vulnerability Scanner can now identify vulnerable versions of various JavaScript…
Latest WVS v9 build with new DOM XSS checks that can be injected in HTTP GET parameters
Invicti Web Vulnerability Scanner version 9, build 20131023 includes new DOM XSS checks for the type of DOM XSS vulnerabilities that can be injected in the HTTP GET parameters. This new build also includes the option to automatically save scan results to disk after a…
Invicti WVS v9, build 20131009 checks for HTML Injection, detection of weak passwords in Joomla! and Django
Invicti Web Vulnerability Scanner version 9, build 20131009 includes checks for HTML Injection, and adds the detection of weak passwords in Joomla! and Django’s Administrative interfaces. In addition, the new build includes the detection of readme documentation files, together with various other updates and fixes….