Scan APIs via Postman collections
Copy link to “Scan APIs via Postman collections”API Scanner: You can now scan APIs by uploading Postman collections. We convert the URLs from the Postman into a swagger file and scan it accordingly.
These are the latest updates we've made to our platform. If you have any questions about any of the updates you see below, please feel free to contact us!
API Scanner: You can now scan APIs by uploading Postman collections. We convert the URLs from the Postman into a swagger file and scan it accordingly.
Sniper can exploit a RCE vulnerability discovered in Wago (CVE-2023-1698).
Sniper can exploit this RCE vulnerability found in Adobe ColdFusion (CVE-2023-29300).
We are happy to announce that Pentest-Tools.com is officially listed on the AWS Marketplace. This listing meets security and compliance standards, allowing you to simplify your purchase flow through your existing AWS account.
Sniper can exploit a RCE vulnerability discovered in OpenTSDB (CVE-2023-25826).
Sniper can exploit a RCE vulnerability discovered in Metabase (CVE-2023-38646).
Our tools that accept requests (XSS Exploiter, HTTP Request Logger, and Sniper Client-side attacks) are now structured and placed into a single page called Handlers.
Network Scanner: The Pentest-Tools.com research team contributes to the official Nuclei templates by improving and fixing false positives. We are now ranked among the top 75 contributors on the official repository.
You can now select if you want to detect the cloud provider and/or detect cloud vulnerabilities & misconfigurations in the Cloud Scanner.
The Findings page got a fresh look! But that’s not all. With improved filtering and performance, it’s now faster than ever to manage your findings and find exactly what you are looking for. Moreover, the new Finding editor creates an improved writing experience and a more reliable output. Give it a try by creating a manual finding.
Nuclei templates now receive automatic updates daily, ensuring the scanner Nuclei detections are always up-to-date.
Network Scanner can now detect if CVE-2023-3519 (Citrix ADC & Gateway) affect your targets.
Sniper can exploit a RCE vulnerability discovered in Apache RocketMQ (CVE-2023-33246).
Sniper can exploit a RCE vulnerability discovered in Chamilo (CVE-2023-34960).
Sniper can exploit an Unauthenticated API Access vulnerability discovered in Ivanti Endpoint Manager Mobile (CVE-2023-35078).
Pentest Ground is a free playground with deliberately vulnerable web applications and network services. You can use it to benchmark your tools and learn new offensive security techniques.
Network Scanner can now detect if CVE-2023-35078 (Ivanti EPMM) and CVE-2023-35078 (Ivanti EPMM) affect your targets.
The HTTP request/response from Network Scanner is now displayed when a finding is generated by the Nuclei scanning engine. This will add more details to the finding and will help validate the generated result.
The Cloud Vulnerability Scanner can now detect multiple misconfigurations in GCP using a dedicated Google account set by Pentest-Tools.
Sniper can exploit a RCE vulnerability discovered in Nuxt (CVE-2023-3224).