Changelog

These are the latest updates we've made to our platform. If you have any questions about any of the updates you see below, please feel free to contact us!

Date

December 2024

  1. The scan results facelift continues! We’ve recently rolled out visual updates for:

    • Port Scanner

    • Subdomain Finder

    • Domain Finder

    • URL Fuzzer

    • Virtual Hosts Finder

    Enjoy a cleaner experience for better insights at a glance.

November 2024

  1. Our proprietary Website Vulnerability Scanner just got more powerful with these November updates:

    Validate with SQLi Exploiter button: Found an SQL Injection vulnerability? Validate it instantly in one click! Our SQLi Exploiter auto-fills details like HTTP methods, POST data, and test parameters.

    Insecure deserialization detection for Python-based applications in the scanner’s Active module. (‘Nough said!)

    Subdomain whitelisting for broader scan coverage. By default, we’re whitelisting "api", but you can customize your subdomain scanning under the Custom scan settings for even more control.

  2. Monitor targets with scheduled scans in Free!

    Copy link to “Monitor targets with scheduled scans in Free!”

    You now have access to scheduled scans so it’s even easier to maintain regular monitoring routines.

    Here’s how it works:

    • Set your preferred scans to run automatically on a weekly or monthly basis.

    • Set up scan diff email alerts to know when something changes.

    [New in free] Monitor your targets for new vulnerabilities with Pentest-Tools.com
  3. Prove these Palo Alto vulns with Sniper

    Copy link to “Prove these Palo Alto vulns with Sniper”

    Not one month passes without adding new proof of exploitation to our proprietary offensive tool —  Sniper: Auto-Exploiter.

    The tool can now exploit Authentication Bypass and Remote Code Execution vulnerabilities in Palo Alto Networks Expedition:

    • CVE-2024-0012 and CVE-2024-9474 (CVSSv3 9.8) - allow a remote attacker to bypass the authentication mechanism and compromise your internal network.

    Prove exploitation easily and integrate this update into your offensive workflows.

October 2024

  1. Continuous monitoring made (even) easier

    Copy link to “Continuous monitoring made (even) easier”

    First we introduced the scan diff notification, so you can easily track changes in your targets’ security posture.

    Now, we’ve made it even easier for you to set a complete monitoring flow for our Network & Website Vulnerability Scanners, Port Scanner, and Subdomain Finder.

    You just select your target(s) and follow the Monitor setup process. It’s that simple!

    You’ll automatically get email alerts whenever there’s an update.

  2. NEW: Import your AWS targets with ease

    Copy link to “NEW: Import your AWS targets with ease”

    There’s a new cloud integration in your Pentest-Tools.com toolkit!

    Now you can easily import AWS targets to your account with a fast setup.

    We’re constantly expanding our integrations to improve your pentesting workflow experience. If you have any preferred tool we should consider next, let us know!

  3. Even more detectors and findings for your network scans

    Copy link to “Even more detectors and findings for your network scans”

    Our Network Scanner is constantly expanding its reach so you get the most from your precision network scans.

    Detect these freshly added high-impact RCEs:

    • CVE-2024-47177 (CVSSv3 9) — RCE in CUPS, a standards-based, open-source printing system.

    • CVE-2024-28986 (CVSSv3 9.8) — RCE in SolarWinds Web Help Desk that allows an attacker to run commands on the host machine

    Get more detailed findings for:

    • misconfigured DNS (because it's always DNS!) SPF, DNS DMARC, and DNS DKIM records

    • a DNS Zone Transfer vulnerability

    Also, know what step your scan is at with real-time updates in the Network Scanner’s scan logs.

  4. Fresh detectors & findings for your website scans, too!

    Copy link to “Fresh detectors & findings for your website scans, too!”

    Our team also updated the Website Scanner's capabilities this past month so you have a more comprehensive view of your targets.

    You can:

    • detect insecure deserialization in PHP applications with the scanner’s Active module

    • automatically detect GraphQL as we’ve integrated our API Vulnerability Scanner’s test methods for this language

    We’ve also added more extensive findings to your scan results. 

    The Website Scanner now:

    • creates a new finding with all the API endpoints it detects during crawling

    • fuzzes for Open API specifications, creates a new finding with any identified results, and even adds it into the Specification Spider

    • adds exposures and exposed-panels Nuclei templates to the Interesting files finding so you detect even more publicly accessible pages that should’ve been hidden.

    Plus, to make the overall scan results easier to navigate, we’re highlighting the request/response lines for all detectors, both passive and active.

  5. New proof of exploitation for this RCE with Sniper

    Copy link to “New proof of exploitation for this RCE with Sniper”

    Our proprietary offensive tool, Sniper: Auto Exploiter, has a wide range of available exploits — but we want to make it even more up to date.

    Use Sniper to extract the proof of exploitation for a critical Palo Alto Networks Expedition RCE (CVE-2024-9463, CVSSv3 9.8) that can allow an unauthenticated attacker to inject an OS Command using special characters and fully compromise your server.

  6. Fresh AWS findings for the Cloud Scanner

    Copy link to “Fresh AWS findings for the Cloud Scanner”

    With the Cloud Vulnerability Scanner, you can assess targets across multi-cloud environments like AWS, GCP, or Azure from both within and the outside.

    There’s a fresh finding for it, too!

    Use our Cloud Scanner to detect the risk of data leaks because of a misconfiguration in your AWS bucket that gives a potential attacker public access to list your multipart uploads.

September 2024

  1. There’s a fresh, new Reports section in Pentest-Tools.com for you to manage and download scan results, findings, and custom reports — all in one place.

    Yet, our fresh makeover comes with fresh improvements for faster and smoother reporting work:

    • Asynchronous report generation, so you don’t have to worry about getting stuck on the same screen while waiting for your files. Not even for larger ones. You’ll get an in-app alert as soon as the report is ready.

    • 30 days storage for all your reports. No need to regenerate or search for a specific report, we make sure they’re all in their right place.

    See how you can leverage the power of automation to streamline your client reports in this hands-on demo:

    Improved reporting in Pentest-Tools.com: streamline your workflow!
  2. 7 new CVEs to check out with your Pentest-Tools.com toolkit!

    Copy link to “7 new CVEs to check out with your Pentest-Tools.com toolkit!”

    Detect these 2 high-risk CVEs with our powerful Network Vulnerability Scanner:

    • CVE-2024-5932 (CVSSv3 10) - this GiveWP Donation Plugin RCE can allow unauthenticated attackers to inject a PHP Object, gain full access, and compromise your server.

    • CVE-2023-43770 (CVSSv3 6.1) - this RoundCube Cross-Site Scripting vulnerability can lead to data theft, session hijacking, or defacement of the affected application.

    Get proof of exploitation for these 5 critical CVEs with our proprietary offensive tool, Sniper - Auto-Exploiter:

    • CVE-2024-29973 (CVSSv3 9.8) - RCE in Zyxel. Validate that an unauthenticated attacker can execute arbitrary commands on the device by exploiting improperly sanitized inputs in the "setCookie" endpoint.

    • CVE-2024-38856 (CVSSv3 9.8) - RCE in Apache OFBiz. Validate this RCE through an especially crafted HTTP POST request that allows an attacker to fully compromise your server.

    • CVE-2024-4358 (CVSSv3 9.8) - Prove how an attacker can fully compromise your server with this RCE in Progress Telerik Report Server through an insecure XML deserialization.

    • CVE-2022-20705 (CVSSv3 9.8) and CVE-2022-20707 - Validate these Cisco Small Business RV Series RCE and Authentication Bypass vulnerabilities.

    • CVE-2024-5932 (CVSSv3 9.8) - assess the business risk of this GiveWP Donation Plugin RCE.

August 2024

  1. Monitor critical changes with scan diff notifications

    Copy link to “Monitor critical changes with scan diff notifications”

    Scan diff for your scan results is finally here! We know you’ve been asking for it, so we’ve listened and delivered.

    Available for port scanning, vulnerabilities, and subdomains, scan diff highlights new and updated findings compared to your previous scan on the same target within a set workspace.

    • Use it for continuous monitoring of all targets in your workspace

    • Get automatic notifications when anything changes, on your preferred channel (email, Slack, Teams, Discord, etc.)

    • Create an automatic scan baseline and use scheduled scans for easier tracking

    Master vulnerability monitoring with Scan Diff notifications! Here's how
  2. Faster & better detection with our Website Scanner!

    Copy link to “Faster & better detection with our Website Scanner!”

    We've increased the URL crawling speed by 30%, making the Website Scanner more efficient from start to finish.

    Our proprietary web app scanner now uses parallelization when detecting cloud hosted URLs. Expect faster discovery, quicker scan completion, and more timely results.

    We’ve also improved the tool’s passive detection method with:

    • Disclosure of OS paths in the HTTP response

    • Detection for session tokens in the request URLs