Detectify security updates for 4 April
For continuous coverage, we push out major Detectify security updates every two weeks, keeping our tool up-to-date with new findings, features and improvements sourced from …

For continuous coverage, we push out major Detectify security updates every two weeks, keeping our tool up-to-date with new findings, features and improvements sourced from …

To bring you the most up-to-date security service and help you stay on top of threats, we update Detectify on a regular basis. Here are some of the latest security tests added to the tool.

Security never stands still, which is why we update our service on a regular basis to help you keep up with the latest vulnerabilities. We are constantly working on updating and improving our modules, but you can find some highlights from this week’s update below.

Security never stands still, which is why we update our service on a regular basis to help you keep up with the latest vulnerabilities. Here are a few of the modules included in this week’s release.

The first one on the list is Injection. This type of finding is more like a category, and includes all kinds of vulnerabilities where an application sends untrusted data to an interpreter. It is often found in database queries, but other examples are OS commands, XML parsers or when user input is sent as program arguments.

SQL injection flaws are very critical. A remote attacker will gain access to the underlying database. In the worst case scenario it allows the attacker to read, write and delete content in the database. This blog post explain what it is and how you fix it.

During the past month, a great deal has happened in the web security landscape, and we have added a ton of new findings to the service. Some of these findings come from other security companies’ public disclosures, whilst others are the results of internal audits of responsible disclosure programs.

A clever attacker can with ease gather all the intelligence he/she needs in order to conduct a full fledged exploit to reveal all the usernames (emails) and passwords of your website.