Changelogs

Acunetix Standard & Premium

RSS Feed

v7.0.20110124 - 24 Jan 2011

Build v7.0.20110124- 24th January 2011

New features

  • New type of XSS test introduced (parameter was set to javascript:…)

Bug fixes

  • Fixed: Scanner crash when scanning https sites with client certificates.
  • Fixed: A number of particular checks were not performed when scanning from crawl results.
  • Fixed: Login Sequence Recorder: different user agent string was sent with XHR.
  • Fixed: Reports were not sent as attachments when scanning a list of URLs from the Scheduler.
  • Fixed: Fixed incorrect error message popup in scheduler “there is already a queue starting a that time when the queues were of different type”
  • Fixed: Crawler MaximumVariationCount was being ignored in the scanner settings.
  • Fixed: eval() security check moved from scanner to crawler.
  • Fixed: Aborting of analysis while executing events in CSA engine not always working.
  • Fixed: CSA engine “Worker already executing” exception.
  • Fixed: In XML or AVDL export CDATA content is no longer encoded.

v7.0.20101216 - 20 Dec 2010

Build v7.0.20101216- 20th December 2010

New features

  • DOM XSS will now report the filename in which the attack was executed
  • DOM XSS checks on document.open, window.open, window.navigate and more

Bug fixes

  • Fixed: Aborting analysis while executing events not always worked in CSA
  • Fixed: CSA engine crashing with “worker already executing” exception
  • Fixed: Crawler was not considering maximum number of variations in case of links from comments
  • Fixed: In some cases during a WSDL service scan, port address query params where not properly used
  • Fixed: False positive for ASP.NET padding oracle test
  • Bugfix: HTML parser; Fixed regex for extracting URLs from HTML comments

v7.0.20101206 - 06 Dec 2010

Build v7.0.20101206- 6th December 2010

New feature

  • Acunetix WVS automatically checks for

    DOM XSS vulnerabilities

Bug fixes

  • Fixed: Get First URL Only option not working correctly because it was still importing links from CSA engine
  • Fixed: “User credentials sent in clear text” was not being reported by crawler in certain circumstances
  • Fixed: Port was being specified in host header even if default ports were being used.

v7.0.20101123 - 23 Nov 2010

Build v7.0.20101123- 23th November 2010

Improvements

  • More updates to the Client Script Analyser (CSA) engine for better Web 2.0 support

Bug fixes

  • Fix: Added port in host header for https in manual browsing
  • Fixed: Crawler not serving pages to Client Script Analyzer engine on request if pages were already queued
  • Fixed: Compare results frame crashed if nodes are expanding while still comparing
  • Fixed: CanonicalizeLink was incorrectly interpreted “..” style links

v7.0.20101115 - 15 Nov 2010

Build v7.0.20101115- 15th November 2010

New features

  • Ability to stop individual running security scripts during a scan

Major Improvements

  • Introduced a good number of CSA engine improvements; better support of JQuery and Web 2.0 applications
  • Introduced a number of new XSS security checks

Bug fixes

  • Fixed: Memory leak in NTLM authentication
  • Fixed: Incorrect interpratation of links with leading “//”
  • Fixed: Access violation crashes in HTTP Sniffer for certain SSL websites

v7.0.20101028 - 28 Oct 2010

Build v7.0.20101028- 28th October 2010

Bug fixes

  • Fixed: Replay of recorded login sequences was not working properly in the free version
  • Fixed: NTML authentication was not working properly when using specific type of credentials
  • Fixed: Crash in Login Sequence Recorder while detecting invalid session on some particular websites
  • Bugfix: Fixed XSS tests to automatically follow redirects
  • Bugfix: Fixed script error in ASP.NET padding oracle test

v7.0.20101012 - 12 Oct 2010

Build v7.0.20101012 - 12th October 2010

Bug fixes

  • Fixed: Client Script Analyser engine was blocking if insertAdjacentHTML used on an element without parent
  • Fixed: “Accept” header was not sent by the advanced penetration testing tools

v7.0.20100921 - 22 Sep 2010

Build v7.0.20100921 - 22nd September 2010

New Security Check

  • Added a security check for the latest OpenX OFC file upload vulnerability
  • Added a ASP.NET security check for the ASP.NET padding Oracle vulnerability

Improvements

  • Reduced the number of false positives for Blind SQL injections security checks
  • Improved Blind SQL injection tests by adding a number of new tests to detect blind SQL injections in UPDATE/INSERT/…

Bug fixes

  • Fixed: Cookie encoding didn’t worked as expected in some cases
  • Fixed: Cookie were not always imported from AcuSensor data

v7.0.20100902 - 02 Sep 2010

Build v7.0.20100902 - 2nd September 2010

New Features

  • Added the option to mark a whole group or node alerts as false positive via right click

Bug fixes

  • Problems with proxy authentication didn’t allow proxy users to run scans
  • Mark Alert as false positive was not working properly in some cases

1 22 23 24 26