Kindly note that the Acunetix Support Team will operate normally the last week of December 2012 and the first week of January 2013 with the following exceptions: 24 December – open until 6pm CET (GMT +1). 25, 26 December – closed 27 and 28 December…
WordPress Pingback Vulnerability
Recently somebody posted on Reddit about a WordPress scanner that is taking advantage of a new WordPress vulnerability. The vulnerability is abusing the Pingback system, which is a well-known feature that’s used by a lot of bloggers. What is a Pingback? Quoting Wikipedia: A pingback…
New Acunetix WVS Build Includes ISO 27001 Template
We’ve just released a new version of Acunetix WVS version 8 – build 20121213 – which includes several new security checks such as the new module that tests Slow HTTP Denial of Service attacks like Slowloris. We’ve also added a good number of improvements and bug…
Your Scanning Experience Determines Your Scanning Success
You know the saying about riding a bicycle – do it once and you’ll remember it forever? That may be true for bicycles, but it’s certainly not the case when it comes to web security testing. The tools we use and the flaws we’re attempting…
Finding Web Flaws is not Point and Click
Successful web security testing is not as simple as point and click. Unfortunately, many people treat it as such. The thought process goes something like this: 1. Load web vulnerability scanner. 2. Enter URL to scan. 3. Click Go. 4. Generate report for the auditors….
2012 – The Year Hacking Became a Political Weapon
On 30 November Reuters reported that Anonymous will shut down Syrian government websites worldwide to fight the government’s countrywide Internet blackout, which many believe was put into effect to silence opposition to President Bashar al-Assad. According to Martin Chulov of The Guardian, in his 29…
It Fell Off a Truck: Top Ten US Data Breaches for 2012
According to Ericka Chickowski in her 29 November article for Dark Reading, “10 Top Government Data Breaches Of 2012,” SQL injection, post-phishing and inadequately secured back-up information all contributed to spectacular comprises of data across the USA in 2012. Some of the breaches were the…
The Email that Hacks You
Update: Seems to be working on TP-Link Routers as well (tested on TL-WR841N). Update2: Arcor EasyBox A600 also seems vulnerable. Opening a legitimate looking email on an iPhone, iPad or Mac while using an Asus router with a default or guessable password could compromise the security of…
It’s No Picnic: NBC Websites Hacked
On November 4th, Steven J. Vaughan-Nichols of ZDNet, who covers security, posted on his blog that NBC had suffered a hack on a number of its websites during the early morning of Sunday, November 4th. According to Vaughn-Nichols, as of noon Eastern Standard Time the…