September 2017 Summaries
4 posts from Detectify
Filter
Month:
Year:
Post Summaries
Back to Blog
Detectify has expanded its service by adding 14 new security tests, primarily targeting vulnerabilities found in various WordPress plugins. The recent update includes tests for issues such as Symfony parameters.yml exposure, Zend application.ini exposure, and Python flask fingerprinting. Additionally, specific vulnerabilities addressed include cPanel Open Redirect, Magento configuration backup disclosure, and multiple authenticated cross-site scripting (XSS) vulnerabilities in WordPress plugins like WooCommerce PDF Invoices & Packing Slips, Ninja Forms, and Anti-Malware Security and Brute-Force Firewall, among others. These enhancements aim to improve security measures and protect against potential exploits in widely-used web applications and platforms.
Sep 21, 2017
127 words in the original blog post.
Detectify has introduced new security tests to identify cross-site scripting (XSS) vulnerabilities in various popular WordPress plugins, including Ninja Forms, Loco Translate, and others. These vulnerabilities, if exploited, can lead to significant security breaches such as cookie theft, phishing, and hijacked accounts. Users of affected plugins are advised to perform a new scan using Detectify to assess their site's vulnerability. Specific plugins and versions, such as WooCommerce PDF Invoices & Packing Slips, Ninja Forms before v. 3.1.9, Pretty Links, Loco Translate, Google Pagespeed Insights, Booking Calendar, Crelly Slider, and the Pinfinity theme, are highlighted as having potential XSS vulnerabilities. Detectify provides a detailed scan report of any detected issues, offering users a way to safeguard their websites against these security threats.
Sep 20, 2017
342 words in the original blog post.
Detectify is a leading platform in External Attack Surface Management (EASM) known for delivering highly accurate vulnerability assessments with a 99.7% precision rate. It is trusted by Product Security (ProdSec) and Application Security (AppSec) teams to simulate real-world exploits on Internet-facing applications, identifying potential vulnerabilities before they can be exploited by malicious attackers. The platform leverages automated, continuous testing using payload-based attacks that are crowdsourced from a global network of elite ethical hackers, ensuring that critical security weaknesses are exposed and addressed promptly. Detectify offers a two-week free trial to new users, providing an opportunity to experience its comprehensive security assessment capabilities.
Sep 14, 2017
62 words in the original blog post.
Detectify's Crowdsource initiative integrates the expertise of over 100 top ethical hackers to bolster security by identifying and reporting vulnerabilities, achieving a record-breaking month in August with over 1,500 unique submissions. The most significant finding was a URL path traversal vulnerability involving url-encoded slashes, which, though not critical alone, can lead to severe breaches when combined with other issues. August also highlighted numerous vulnerabilities in Flash, underscoring its obsolescence and the importance of monitoring outdated technologies like Flash, Java, and Silverlight. Notably, hacker Evgeny Morozov was recognized for discovering a DNS spoofing vulnerability, earning him a spot in the Hall of Fame. Detectify plans to enhance its platform by expanding its bug bounty program and is inviting skilled hackers worldwide to join and contribute to making the internet more secure, offering rewards as an incentive for their participation.
Sep 08, 2017
483 words in the original blog post.