Jump to content
YOUR-AD-HERE
HOSTING
TOOLS

Locked Netsparker Professional Edition v5.9.1.29030 - LifeTime Activated


itsMe

Recommended Posts

This is the hidden content, please

Netsparker Professional Edition Full Activated

Always on, always accurate
Netsparker is a fully integrated, scalable, multi-user web security solution
with built-in workflow and reporting tools.

Some of the basic security tests should include testing:

    SQL Injection
    XSS (Cross-site Scripting)
    DOM XSS
    Command Injection
    Blind Command Injection
    Local File Inclusions & Arbitrary File Reading
    Remote File Inclusions
    Remote Code Injection / Evaluation
    CRLF / HTTP Header Injection / Response Splitting
    Open Redirection
    Frame Injection
    Database User with Admin Privileges
    Vulnerability – Database (Inferred vulnerabilities)
    ViewState not Signed
    ViewState not Encrypted
    Web Backdoors
    TRACE / TRACK Method Support Enabled
    Disabled XSS Protection
    ASP.NET Debugging Enabled
    ASP.NET Trace Enabled
    Accessible Backup Files
    Accessible Apache Server-Status and Apache Server-Info pages
    Accessible Hidden Resources
    Vulnerable Crossdomain.xml File
    Vulnerable Robots.txt File
    Vulnerable Google Sitemap
    Application Source Code Disclosure

    Silverlight Client Access Policy File Vulnerable
    CVS, GIT, and SVN Information and Source Code Disclosure
    PHPInfo() Pages Accessible and PHPInfo() Disclosure in other Pages
    Sensitive Files Accessible
    Redirect Response BODY Is Too Large
    Redirect Response BODY Has Two Responses
    Insecure Authentication Scheme Used Over HTTP
    Password Transmitted over HTTP
    Password Form Served over HTTP
    Authentication Obtained by Brute Forcing
    Basic Authentication Obtained over HTTP
    Weak Credentials
    E-mail Address Disclosure
    Internal IP Disclosure
    Directory Listing
    Version Disclosure
    Internal Path Disclosure
    Access Denied Resources
    MS Office Information Disclosure
    AutoComplete Enabled
    MySQL Username Disclosure
    Default Page Security
    Cookies not marked as Secure
    Cookies not marked as HTTPOnly
    Stack Trace Disclosure
    Programming Error Message Disclosure
    Database Error Message Disclosure

Version 5.9.1.29030 – 6th of November 2020
NEW SECURITY CHECKS

    Added Oracle WebLogic Server Remote Code Execution (CVE-2020-14882)
    Added Oracle WebLogic Server Authentication Bypass (CVE-2020-14883)

This is the hidden content, please

This is the hidden content, please

 

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.