Changelog

These are the latest updates we've made to our platform. If you have any questions about any of the updates you see below, please feel free to contact us!

Date

August 2024

  1. We're giving you even more control over our most powerful offensive security tool - Sniper Auto-Exploiter.

    You can now automatically get proof of exploitation for specific CVEs.

    Plus, our team developed new custom exploits for these critical CVEs:

    • CVE-2024-36401 (CVSSv3 9.8) - this GeoServer RCE can fully compromise your server and allow unauthenticated attackers to pivot to your internal network.

    • CVE-2024-28995 (CVSSv3 7.5) - prove this Arbitrary File Read vulnerability found in SolarWinds Serv-U is exploitable.

    Don’t forget that, whenever we add new exploits in Sniper, it means our Network Scanner can also detect those CVEs for you.

    Want to see it in action? Here’s a practical demo on how Sniper works:

    How to get validation proof with Sniper Auto-exploiter

July 2024

  1. Better detection with the Password Auditor

    Copy link to “Better detection with the Password Auditor”

    Our Password Auditor expands its effectiveness and can now find weak credentials in a broader range of network services and web technologies:

    • We've improved the weak credentials checks on Joomla, Kibana, Grafana, Plesk, and Webmin.

    • Plus, bruteforce attacks with this tool now run in parallel for open services to speed up your workflow.

  2. Even more integrations for more focused security workflows

    Copy link to “Even more integrations for more focused security workflows”

    Are you on the lookout for more efficiency in your workflows? (Who isn't, right?)

    We've got a growing list of integrations so you run your security operations smoothly.

    Just added:

    • Discord - a popular request in our community! Get custom notifications for scan results, set different channels for specific alerts, and make sure everyone sees the relevant findings.

    • Vanta - another popular request! Use it to automatically get PDF reports from scheduled scans only straight to your Vanta account and make compliance operations a bit smoother.

    • You can now use the CLI version for our Website Vulnerability Scanner to set up vulnerability tests in your CI/CD flow.

    Our colleague Mihai explains how to use it in this quick video:

    Use automated GitHub Actions to test web app configurations & deployments for vulnerabilities
  3. Run precision network scans with new detectors and findings

    Copy link to “Run precision network scans with new detectors and findings”

    The Network Vulnerability Scanner is always expanding its reach and getting stronger for you.

    New CVEs you can now detect cover:

    • CVE-2016-7406 (CVSSv3 9.8) - RCE in Dropbear SSH. A remote attacker can execute arbitrary code via format string specifiers in the username or hostname argument and fully compromise the server.

    • CVE-2024-0692 (CVSSv3 8.8) - RCE in SolarWinds Security Event Manager. This vulnerability allows an attacker to abuse SolarWinds' service.

    • CVE-2024-6387 (CVSSv3 8.1) - RegreSShion - the critical OpenSSH vulnerability and its technical details are still relevant, so you may want to get up to speed if you haven't had a chance.

    Other improvements to the Network Scanner include:

    • Get informational findings when a version-based engine doesn't return anything on a port, so you are aware of it.

    • Get end-of-life findings for products Wappalyzer detects.

    • Scan logs are now available to easily keep track of all your active scans.

  4. New tool: Kubernetes Vulnerability Scanner

    Copy link to “New tool: Kubernetes Vulnerability Scanner”

    Find security vulnerabilities and misconfigurations in your Kubernetes clusters - from reconnaissance (e.g. Node/Master cluster components) to initial access vulnerabilities (e.g. exposed Kubelet API critical endpoints, etc.).

    Light, deep, and custom scan settings let you control port ranges and even give you the option to emulate an authenticated adversary - if you have a service account token.

    Curious to see how we report findings? See a sample below or log in and check it out for yourself!

  5. Prove these 7 new critical CVEs are exploitable with Sniper

    Copy link to “Prove these 7 new critical CVEs are exploitable with Sniper”

    Use our most powerful offensive tool, Sniper Auto-Exploiter, to exploit the following 7 newly added critical CVEs:

    • CVE-2020-3250 (CVSSv3 9.8) - this REST API vulnerability in the Directory Traversal in Cisco UCS Director allows an unauthenticated remote attacker to get sensitive info.

    • CVE-2020-3243 (CVSSv3 9.8) - exploit this RCE in Cisco UCS Director and prove how an unauthenticated remote attacker can bypass auth and execute arbitrary actions with admin privileges.

    • CVE-2019-1935 (CVSSv3 9.8) - this RCE in Cisco UCS Director enables an unauthenticated remote attacker to use the SCP User account (scpuser) to log in to the CLI.

    • CVE-2012-1823 (CVSSv3 9.8) - known as the PHP CGI Argument Injection, this RCE allows a remote attacker to fully compromise the server.

    • CVE-2024-4577 (CVSSv3 9.8)  - another critical argument injection flaw in PHP that can fully compromise the server. Yikes!

    • CVE-2020-2950 (CVSSv3 9.8) - prove how a remote attacker can fully compromise a server using this RCE in Oracle Business Intelligence.

    • CVE-2024-34102 (CVSSv3 9.8) - this XML External Entity Injection in Magento can result in arbitrary code execution and allow an unauthenticated remote attacker to compromise the server.

  6. Slice through web apps with these Website Scanner improvements

    Copy link to “Slice through web apps with these Website Scanner improvements”

    Our Website Vulnerability Scanner also has new improvements:

    • We've added an active detector for HTTP2 in the HTTP request smuggling.

    • Get new findings when scanning and detecting the H2.TE (Transfer-Encoding) and H2.CL (Content-Length) vulnerabilities.

    • File upload input detection now available in the passive scanner module.

June 2024

  1. More, clearer, better findings from the Network Scanner

    Copy link to “More, clearer, better findings from the Network Scanner”

    The latest updates to our Network Vulnerability Scanner now let you:

    • Detect CVE-2024-6387 (CVSSv3 8.1), aka RegreSSHion, the critical OpenSSH vulnerability that got a CVE assigned yesterday - and for which we integrated detection today so you can be truly ahead of attackers (technical write-up for context)

    • Detect CVE-2023-48788 (CVSSv3 9.8), the SQL Injection in Fortinet FortiClient EMS, which a remote attacker can use to run SQL commands on the vulnerable target and fully compromise the database that the FortiClient EMS uses

    • Get individual findings for publicly exposed services such as PostgreSQL, MongoDB, OracleDB, and Redis 

    • Get an informational finding when a port redirects to another port, which leads to skipping the vulnerability checks for that target

    • See the steps to replicate a finding in a dedicated section called “How to reproduce” to make it easier to browse through details

  2. Custom Sniper exploits for RCE and file disclosure vulns

    Copy link to “Custom Sniper exploits for RCE and file disclosure vulns”

    After this month’s updates, Sniper Auto-Exploiter, our most powerful offensive security tool, can gain unauthenticated RCE on the target and extract multiple artefacts as evidence for the following CVEs:

    • CVE-2024-23108 (CVSSv3 9.8) - RCE in Fortinet FortiSIEM. This exploit helps you validate that a remote, unauthenticated attacker can leverage this vulnerability to fully compromise the server and steal confidential information, install ransomware, or pivot to the internal network.

    • CVE-2024-24919 (CVSSv3 8.6) - Information Disclosure in Check Point CloudGuard Network Security. This Arbitrary File Read through a Path Traversal vulnerability can give an unauthenticated attacker remote access to any file on the target’s filesystem.

    • CVE-2020-29390 (CVSSv3 9.8) - RCE in Zeroshell. Incorrect handling of the User parameter, which doesn't correctly sanitize user-controlled input, causes this vulnerability. An attacker can use a special character to achieve RCE on the target, as the user that is running the webserver process.

  3. More efficient brute-forcing with the Password Auditor

    Copy link to “More efficient brute-forcing with the Password Auditor”

    If you’re relying on our Password Auditor to test for weak credentials, we’ve improved the experience of using it in four ways.

    It’s now easier to understand why the brute force attack finished much earlier than you expected:

    • We generate a screenshot when the Password Auditor finds weak credentials using Basic Authorization.

    • If a port redirects to another port, we skip the bruteforce on that port and you get an informational finding.

    • We also generate a screenshot when the bruteforce attack exceeds current capabilities, including: account lockout detection, website access blocked during the bruteforce, CAPTCHA found, Login form could not be found, and Third Party Authentication or Two Step Authentication detected.

    • And, finally, to reduce false positives, we've added new checks when the tool finds weak credentials.

  4. Detect Weak HMAC Secrets and Algorithm Confusion

    Copy link to “Detect Weak HMAC Secrets and Algorithm Confusion”

    Our well-loved Website Vulnerability Scanner also got updates, as it does every single month:

    • SSTI code context - we've improved the capabilities of our Server Side Template Injection detector by adding payloads that work in code context.

    • JWT phase 2 - And we've finished the second part of our JWT detector by adding payloads that work in code context. It can now detect: Weak HMAC Secrets and Algorithm Confusion issues.

  5. DOCX reports now compatible with Google Docs!

    Copy link to “DOCX reports now compatible with Google Docs!”

    Until now, our DOCX reports were very dependent on Microsoft Word.

    We spent a lot of time and effort to change this and we have good news: DOCX files are now compatible with Google Docs!

    If you’re already using GDocs in your day to day work, you can work together with your team to speed up the review process. Plus, other editors can benefit from this update too.

    Choose the findings you want to report to see this new option in action!

  6. NahamSec uses Pentest-Tools.com for bug bounty hacking

    Copy link to “NahamSec uses Pentest-Tools.com for bug bounty hacking”

    How do you zero in on the assets really worth your hacking energy and focus?

    The awesome NahamSec explains how he combs through hundreds of domains that branch into even more subdomains to find targets with the highest potential of having a bounty-worthy vulnerability (which he actually finds)!

    Check out his latest video, which we had the pleasure of sponsoring:

    Hacking Large Corporations (Recon)

May 2024

  1. Web app vulnerability scanners benchmark results

    Copy link to “Web app vulnerability scanners benchmark results”

    We evaluated our Website Vulnerability Scanner with some of the most-known tools in Dynamic Web Application Security Testing, both commercial and open-source options: Burp Scanner, Acunetix, Qualys, Rapid7 InsightVM, and ZAP. Find out which was the most accurate scanner and which had the most false positives!

    For a look behind the scenes, check out our blog article.

    For all the data behind the results in the benchmark, download the white paper.

    vulnerability detection across both targets

  2. NEW: a detailed benchmark of top network vulnerability scanners

    Copy link to “NEW: a detailed benchmark of top network vulnerability scanners”

    We tested the most used network vulnerability scanners: Nessus Professional, Nmap vulnerability scripts, Nuclei, OpenVAS, Qualys, and Rapid7 Nexpose, including our own Network Vulnerability Scanner.

    Find out how these popular network vulnerability scanners perform in a benchmark so you can validate yourself.

    We explained the testing methodology and benchmark results in this blog article.

    To get all the details, download the white paper.

  3. Even more (detailed) Network Scanner findings

    Copy link to “Even more (detailed) Network Scanner findings”

    Our Network Scanner packs a big punch (which this benchmark confirms). The list of findings it can get you has just gotten stronger with:

    • IP information - uncover the physical location, Autonomous System (AS) details, and associated company names of your network hostnames

    • Wappalyzer integration - our Network Scanner now uses Wappalyzer to identify the underlying technologies of web apps, giving you richer insights for results coming from our version-based scanning engine (one of 4 engines this tool uses)

    • More individual findings for publicly exposed services, including SSH (with exposed authentication), RPC, WinRM, FTP, POP3, and Telnet