Changelog

These are the latest updates we've made to our platform. If you have any questions about any of the updates you see below, please feel free to contact us!

Date

October 2024

  1. Fresh detectors & findings for your website scans, too!

    Copy link to “Fresh detectors & findings for your website scans, too!”

    Our team also updated the Website Scanner's capabilities this past month so you have a more comprehensive view of your targets.

    You can:

    • detect insecure deserialization in PHP applications with the scanner’s Active module

    • automatically detect GraphQL as we’ve integrated our API Vulnerability Scanner’s test methods for this language

    We’ve also added more extensive findings to your scan results. 

    The Website Scanner now:

    • creates a new finding with all the API endpoints it detects during crawling

    • fuzzes for Open API specifications, creates a new finding with any identified results, and even adds it into the Specification Spider

    • adds exposures and exposed-panels Nuclei templates to the Interesting files finding so you detect even more publicly accessible pages that should’ve been hidden.

    Plus, to make the overall scan results easier to navigate, we’re highlighting the request/response lines for all detectors, both passive and active.

September 2024

August 2024

  1. Faster & better detection with our Website Scanner!

    Copy link to “Faster & better detection with our Website Scanner!”

    We've increased the URL crawling speed by 30%, making the Website Scanner more efficient from start to finish.

    Our proprietary web app scanner now uses parallelization when detecting cloud hosted URLs. Expect faster discovery, quicker scan completion, and more timely results.

    We’ve also improved the tool’s passive detection method with:

    • Disclosure of OS paths in the HTTP response

    • Detection for session tokens in the request URLs

July 2024

  1. Even more integrations for more focused security workflows

    Copy link to “Even more integrations for more focused security workflows”

    Are you on the lookout for more efficiency in your workflows? (Who isn't, right?)

    We've got a growing list of integrations so you run your security operations smoothly.

    Just added:

    • Discord - a popular request in our community! Get custom notifications for scan results, set different channels for specific alerts, and make sure everyone sees the relevant findings.

    • Vanta - another popular request! Use it to automatically get PDF reports from scheduled scans only straight to your Vanta account and make compliance operations a bit smoother.

    • You can now use the CLI version for our Website Vulnerability Scanner to set up vulnerability tests in your CI/CD flow.

    Our colleague Mihai explains how to use it in this quick video:

    Use automated GitHub Actions to test web app configurations & deployments for vulnerabilities
  2. Slice through web apps with these Website Scanner improvements

    Copy link to “Slice through web apps with these Website Scanner improvements”

    Our Website Vulnerability Scanner also has new improvements:

    • We've added an active detector for HTTP2 in the HTTP request smuggling.

    • Get new findings when scanning and detecting the H2.TE (Transfer-Encoding) and H2.CL (Content-Length) vulnerabilities.

    • File upload input detection now available in the passive scanner module.

June 2024

  1. Detect Weak HMAC Secrets and Algorithm Confusion

    Copy link to “Detect Weak HMAC Secrets and Algorithm Confusion”

    Our well-loved Website Vulnerability Scanner also got updates, as it does every single month:

    • SSTI code context - we've improved the capabilities of our Server Side Template Injection detector by adding payloads that work in code context.

    • JWT phase 2 - And we've finished the second part of our JWT detector by adding payloads that work in code context. It can now detect: Weak HMAC Secrets and Algorithm Confusion issues.

May 2024

  1. Web app vulnerability scanners benchmark results

    Copy link to “Web app vulnerability scanners benchmark results”

    We evaluated our Website Vulnerability Scanner with some of the most-known tools in Dynamic Web Application Security Testing, both commercial and open-source options: Burp Scanner, Acunetix, Qualys, Rapid7 InsightVM, and ZAP. Find out which was the most accurate scanner and which had the most false positives!

    For a look behind the scenes, check out our blog article.

    For all the data behind the results in the benchmark, download the white paper.

    vulnerability detection across both targets

April 2024

  1. Leave no stone unturned with these Website Scanner upgrades

    Copy link to “Leave no stone unturned with these Website Scanner upgrades”

    Our Website Vulnerability Scanner now:

    • Detects flaws in JWT implementations by checking if web apps that use JWTs for authentication allow them to have a None or random signature, creating security risks

    • Runs faster light web app scans that also come with detailed requests and responses for each finding

    • Provides extra information about spidered responses in evidence which now includes the status code, page title, and page size for each URL

    • Extracts proof of exploitation for Linux OS command injection in the form of hostnames and usernames.

March 2024

  1. Two new modules in the Website Vulnerability Scanner

    Copy link to “Two new modules in the Website Vulnerability Scanner”

    Two new modules in the Website Vulnerability Scanner:

    • Detection for misconfigured CSP Headers - identifies misconfigured content-security-policy headers on your website, enabling you to control resource loading and their allowed URLs.

    • Enumerable Parameter Detector - explores possible enumerable parameters in your website. Some findings might reveal insecure direct object references after manual examination.

    enumerable parameter detector

February 2024

  1. Nuclei fingerprinting in our Website Scanner

    Copy link to “Nuclei fingerprinting in our Website Scanner”

    Our Website Vulnerability Scanner gets stronger with each monthly update!

    We’ve integrated the fingerprinting capabilities from Nuclei into our proprietary tool - and it’s just the kickoff!

    Soon, we’ll start incorporating many more templates. Until then, the 40+ vulnerability checks our Website Scanner runs can surely keep you - and your team - focused and making progress.

    Nuclei fingerprinting

January 2024

  1. And one more thing: we added a method to detect if the Website Scanner spider finds an OpenAPI file. When it does, you can dig deeper with the API Scanner in just one click, right from your finding.

    OpenAPI file detection

    By the way, we love to see customers truly make the most of our tools:

    We had a tool to scan our websites and endpoints automatically; the reports were not so good, and each additional URL was charged additionally (this doesn't scale in a micro-services architecture).

    Pentest-Tools.com solved all our problems; you can scan up to 1000 targets, the reports are so professional, and you can choose from dozens of different tools to analyze all aspects of an enterprise architecture.

  2. We've also introduced a new Session Fixation Detector to help you identify session hijacking risks. Using the mitigation recommendations will help you prevent unauthorized access to user sessions and sensitive data.

    Here’s a preview of what the finding looks like:

    session fixation finding

  3. We've implemented Input Reflected in DOM to enhance protection against XSS attacks, ensuring coverage of more vulnerabilities lying in the DOM. It is already implemented in the XSS detector so if you select the XSS detector you are covered.

    Here’s what it’ll look like in your report:

    Input Reflected

December 2023

November 2023

October 2023

September 2023