New Features
- New Acunetix web UI
- Improved Network Scanner integration
- Malware Detection using Windows Defender on Windows and ClamAv on Linux
- Smart Scan
- New scanning algorithm prioritises scanning tasks and reduces scanning time
- Proof of exploit is reported in the vulnerability alerts
- Incremental Scans
- Vulnerability Confidence Rating for web vulnerabilities
- New GitLab Issue Tracker Integration
- New Bugzilla Issue Tracker Integration
- New Mantis Issue Tracker Integration
- Ability to create Login Sequence from Selenium script
- New WADL import file
- New ASP.NET Webforms import file
- New Postman import file
- New Paros import file
- Ability to create custom checks
- Highlighting of vulnerability in HTTP response
- DeepScan provides better support for Angular 2, Vue and React JavaScript Frameworks
- Unlimited network scanning for Acunetix Premium customers
- Account Session Timeout settings
- Account Maximum Consecutive Login Failure settings
New Vulnerability Checks
Updates
- Improved memory consumption for the scanner
- PDF reports now have page numbers
- Generic User-agent will be used for communication with issue trackers
- All lists in Acunetix UI can be sorted
- Easier filtering options in the Acunetix UI
- Settings can now be accessed from the side-bar
- Links discovered by AcuSensor are given more prominence
- Improved processing of XML and JSON POST input schemes
- Scanner will try to replay the LSR playback actions a number of times before failing
- Improved Auto-Login
- Multiple updates in the Login Sequence Recorder
- Developer report updated to include Source file, line number and other details provided by AcuSensor
- Acunetix now supports scanning domains with international characters
- Increase page size limit to 20Mb in scanner and LSR
- Improved detection of Possible Sensitive Files
- Improved detection of email addresses
- Improved detection of Command Injection
- Improved detection of database backup files
- Improved detection of XXE
Fixes
- Fixed issue in Developer report showing incorrect parameter name for detected vulnerabilities
- Fixed: "Tester" user role will not be able to create reports
- upgrades on Linux were not removing all files from previous installation
- Fixed issue with Manual Intervention
- Fixed: Session cookies where not always collected by LSR
- Fixed: Incorrect processing of URLs with "{" character
- Fixed a number of crashes in scanner
- Fixed issue causing scanner proxy to unintentionally transform parts of the HTTP request
- Fixed false positive in the detection of Apache Tomcat Remote Code Execution
- Fixed issues causing some links not to be properly imported by the importer
- Fixed issue with license activation when proxy and authentication is used
- Fixed issue causing session to get lost when Deepscan is used