Invicti v10.5 build 20160504 has been released. This new build updates the PCI DSS and the NIST compliance reports with the requirements of PCI DSS 3.2 and NIST 800-53 rev4 respectively. The new build also fixes an important bug uncovered earlier this week. Improvements Updated…
Tag Archives v10
Latest build of Invicti includes new version of .NET AcuSensor, checks for JSP source code disclosure and improves crawling capabilities
Invicti v10.5 (build 20160427) has been released. This new build includes a new version of the .NET AcuSensor registers with .NET web applications in a way that supports signed .NET Assemblies. In addition, it includes new and improved vulnerability checks and a number of minor…
Alliance Technology Partners offering introductory and advanced Invicti training courses
Alliance Technology Partners, Invicti Partners since 2007, have announced they shall be offering Invicti Training Courses, delivered via the web, by their highly experienced senior security engineer. The 3 hour courses on offer are at introductory and advanced level, as well as providing on-going consulting. Training…
Invicti v10.5 assigns CVSS 3.0 scoring to its vulnerabilities
The Common Vulnerability Scoring System (CVSS) is an open standard for assessing the severity of security vulnerabilities. “Common” being the keyword, indicating that CVSS is designed to not only be independent to a specific vendor or industry, but also interoperable across systems that vary in…
Invicti v10.5 adds support for Joomla! Drupal and CVSS3.0
A new version of Invicti Web Vulnerability Scanners v10.5 has been released. The new version tests for Joomla! and Drupal vulnerabilities, supports CVSS 3.0 and includes other improvements/bug fixes. Joomla! and Drupal Support Invicti v10.5 now reports vulnerabilities in popular content management systems Joomla! and Drupal. The…
New Invicti update includes security checks for Joomla! Core RCE, improved XXE tests and more
New updates have been released that test for a new Joomla! remote code execution vulnerability affecting versions 1.5.0 through 3.4.5 CVE-2015-8562. Other updates also include improved XML External Entity (XXE) testing, multiple Cross-site Scripting tests in commonly used libraries and other improvements/bug fixes. Below is the…
Invicti 10 build includes security checks in CORS configurations, Rails web applications and identifies the vBulletin 5 RCE
Invicti 10 (build 20151125) has been released. This new build checks for insecure DNS records, insecure CORS configurations, Rails web applications running in development mode, web applications running Tornado and Pyramid in debug mode and various new and updated vulnerability checks including one for vBulletin…
Invicti Port Scanner
The Invicti Port Scanner performs a port scan against the server hosting the scanned website. When open ports are found, Invicti Web Vulnerability Scanner will proceed with network level security checks against the network service running on that port, such as DNS Open Recursion tests,…
Invicti 10 new build checks for vulnerabilities in Composer, Zend Framework, AjaxControlToolkit
Invicti WVS v.10 (build 20150921) has been released. This new build checks for Cross Site Scripting in mobile-touch event handlers and for various vulnerabilities in products such as Composer, Zend Framework, AjaxControlToolkit and others. Below is a full list of updates. New Features Added a…