Home / Companies / Detectify / Blog / November 2017

November 2017 Summaries

3 posts from Detectify

Filter
Month: Year:
Post Summaries Back to Blog
The OWASP Top 10 2017 list highlights the most common web vulnerabilities, serving as an international security standard aimed at raising awareness among developers. Despite changes since the 2013 list, many vulnerabilities remain, with Injection and Cross-site Scripting still prevalent due to their widespread nature. The 2017 update introduces three new vulnerabilities—XML External Entities (XXE), Insecure Deserialization, and Insufficient Logging and Monitoring—while removing CSRF and Unvalidated Redirects and Forwards due to their decreased prevalence. The list reflects evolving web technologies and emphasizes the importance of addressing security beyond these ten categories, as noted by security experts like Fredrik Nordberg Almroth and Linus Särud. Detectify offers scanning capabilities to identify these vulnerabilities, though some, like Insufficient Logging and Monitoring, present challenges for automated detection. The persistence of certain vulnerabilities underscores the complexity and ongoing challenges in web security, especially with the continuous emergence of new technologies and frameworks.
Nov 23, 2017 822 words in the original blog post.
A recent update has introduced a new set of vulnerabilities affecting various platforms, including Sitecore, HashiCorp Consul, and WordPress. The vulnerabilities encompass a range of issues such as information exposure in .NET affecting Sitecore and Episerver, exposure of MySQL and PostgreSQL history files, and several WordPress-specific vulnerabilities like SQL injection, object injection, authentication bypass, cross-site scripting (XSS), and server-side request forgery (SSRF). Specific vulnerabilities include phpMyFAQ XSS, WordPress simple-login-log SQL injection, and authenticated open redirects in BuddyPress, among others. Users are advised to conduct scans to determine if they are susceptible to these vulnerabilities.
Nov 16, 2017 101 words in the original blog post.
Detectify Crowdsource, a crowdsourced security community launched a year ago, has successfully harnessed the expertise of over 100 ethical hackers worldwide to identify and automate the detection of web vulnerabilities, significantly enhancing website security for its customers. The platform, which combines bug bounties with automation, has received 345 submissions from 128 security researchers, with XSS being the most common vulnerability identified. By incorporating these submissions into the Detectify scanner, the platform maximizes the impact of individual findings, securing numerous sites and enriching the hackers' experience and financial rewards. Kristian Bremberg, the Community Manager, highlights the platform's unique approach and ongoing development based on community feedback, aiming to continue its growth and adaptation to the evolving bug bounty landscape. With a vision of a more secure internet, Detectify Crowdsource stands out by integrating white-hat knowledge with automation and fostering security awareness.
Nov 10, 2017 776 words in the original blog post.