Company
Date Published
Author
Detectify
Word count
334
Language
-
Hacker News points
None

Summary

Detectify regularly updates its security tool every two weeks with contributions from its security researchers and the Crowdsource ethical hacker community, although confidentiality agreements limit the disclosure of all updates. Recent improvements include added tests for vulnerabilities such as the Magento unauthenticated SQL injection, which now allows for more accurate testing and reporting by minimizing false positives. Also addressed is the WordPress wp-google-maps SQL injection, which saw a rapid response from the plugin vendor to patch the issue. Another highlighted vulnerability is the Google Maps unrestricted API key exposure, which can result in unauthorized usage and financial costs if not correctly configured. Additionally, Git Daemon exposure remains a concern, as it can lead to unauthorized access and downloading of source code from exposed configuration files.