Alliance Technology Partners, partnering with Invicti since 2007, have announced they shall be offering Invicti Training Courses, delivered via the web, by two of their senior security engineers. This Basic Training 3 hour course, is highly interactive and tailored to the users’ experience level and…
Tag Archives v9
Invicti WVS v9.5 build 20140902 detects Hibernate Query Injection, Format Strings and more
Invicti Web Vulnerability Scanner version 9.5 build 20140902 has been updated to include new vulnerability checks, including detection of Hibernate Query Injection, format strings vulnerabilities, MySQL username disclosure and others, including some, in well-known web applications. This new build also optimises existing checks, including its…
Common Platform Enumeration (CPE) Explained
When running a network scan on your perimeter server using Invicti Vulnerability Scanner, one of the Informational alerts shown in the scan results is the CPE Inventory. The data that is collected during the scan is aggregated using the CPE standard, originally defined by MITRE,…
Invicti WVS v9.5 Build 20140602 – New Security Tests
Each Invicti WVS update generally includes new vulnerability tests or an improvement to existing checks. This post summarizes the new security tests added in the latest Invicti WVS update. Cross Domain Data Hijacking A website is vulnerable if an attacker can create/upload a malicious Flash (SWF) file…
Invicti WVS v9.5 build 20140602 includes new vulnerability checks for popular web applications and platforms
Invicti Web Vulnerability Scanner version 9.5, build 20140602, identifies new vulnerabilities in Google Web Toolkit™, Joomla!, Parallels Plesk, nginx, and a number of WordPress plugins including the popular All in One SEO plugin. The following is the full list of updates included in this release….
JSON/XML Input and Google Web ToolkitTM support with Latest Version of Invicti
Manipulation of JSON/XML Input, Google Web ToolkitTM support and new .NET 4.5 AcuSensor are just some of the new features available in the latest version of Invicti Vulnerability Scanner. London, May 8, 2014 – Invicti have just announced the launch of a new version of…
More comprehensive scanning with Invicti WVS v9.5 – Part II
In addtion to full JSON and XML support (already covered in Part I), Invicti WVS version 9.5 includes other improvements that increase the scan coverage and improves its abilities to find vulnerabilities. In this blog post, I will cover CRUD support, Host header testing and…
More comprehensive scanning with Invicti WVS v9.5 – Part I
In these 2 articles, I will be detailing the new functionality introduced in Invicti WVS version 9.5. An important update introduced in the new version of Invicti WVS is full JSON and XML support. If you are scanning a web application that is exchanging data…
Latest Invicti release scans for Heartbleed Bug
Yesterday, an update was released for Invicti Vulnerability Scanner which includes a test for a critical OpenSSL vulnerability named The Heartbleed Bug (CVE-2014-0160). Quote from the report: The Heartbleed Bug is a serious vulnerability in the popular OpenSSL cryptographic software library. This weakness allows stealing the…