Skip to content

Releases: akha-security/akca

v0.2.5

Choose a tag to compare

@github-actions github-actions released this 28 Sep 19:44

Highlights

  • Expand injection coverage with blind boolean LDAP and XPath checks, Velocity/Smarty/Razor SSTI probes, string-transform template evaluation, dynamic MSSQL timing payloads, Windows PowerShell/cmd variants, and stronger SQL boolean/arithmetic oracles.
  • Add heuristic IDOR testing for single-profile scans while preserving strict multi-role BOLA ownership and anonymous-control proofs.
  • Add route authorization-bypass coverage for encoded slashes, case normalization, method overrides, and safe-read fallback for non-GET endpoints.
  • Extend SSRF coverage with IPv6, IPv4-mapped IPv6, hexadecimal/octal, zero-address, gopher and dict payloads.
  • Add directory-listing discovery, broader cloud-takeover fingerprints, and cache parameter-cloaking verification.

Discovery and replay

  • Preserve browser-captured XHR request templates ahead of synthetic forms, including original methods, bodies, headers, cookies, CSRF context and duplicate parameters.
  • Add XML, multipart, raw GraphQL, WebSocket JSON, observed-header, cookie and positional path-identifier mutation surfaces.
  • Discover common content roots and inferred parent directories from observed static assets, with structural Apache, nginx, Python and IIS directory-index detection.
  • Auto-admit exact passive CDN dependencies learned from successful in-scope HTML/CSP without expanding active scan scope or forwarding credentials.
  • Infer authorization role profiles from distinct configured authentication profiles and publish browser/OAST/identity/workflow/runtime readiness.

Verification and false-positive control

  • Introduce SQL boolean-pair and numeric arithmetic-oracle proof types with alternating replay, clean controls and padding-aware semantic comparison.
  • Publish per-target request, response, authentication/rate/gateway block, timeout, transport, proof-role and suppression diagnostics.
  • Require current proof-policy evidence before a candidate can become a finding; unproven candidates fail closed and remain visible in coverage diagnostics.
  • Distinguish browser-confirmed reflected XSS from true DOM-based XSS in terminal labels and stored evidence.
  • Add end-to-end OAST self-testing, exact scan-scoped correlation and hidden health callbacks.
  • Expand TLS, CSP, deserialization, LLM, sensitive-data and CVE validation while keeping evidence typed and replayable.

Reporting and operation

  • Stream HTML, JSON, CSV, Markdown and SARIF findings with context cancellation instead of building large reports entirely in memory.
  • Generate a bounded fast-partial report after Ctrl+C and allow a second interrupt to cancel reporting immediately.
  • Preserve full Burp-style request/response evidence, add coverage diagnostics, and embed scanner version, commit and build date.
  • Add machine-readable assurance profiles and a fail-closed complete-corpus release gate for module/capability omissions.
  • Embed release build provenance and publish signed GitHub attestations in addition to SHA-256 checksums.

Validation

  • Full Go package tests pass with go test ./... -count=1.
  • Static analysis passes with go vet ./....
  • Strict observed-corpus benchmark quality retains 1.0 precision and an F1 score above 0.96.
  • Regression coverage includes the six Burp Bounty SQLi surfaces, reflected-vs-DOM XSS classification, browser request replay, directory listing, OAST correlation, report streaming and interrupt behavior.

Install with Go

go install github.com/akha-security/akca/engine/cmd/akca@v0.2.5

After the module proxy refreshes, @latest resolves to v0.2.5 as well:

go install github.com/akha-security/akca/engine/cmd/akca@latest

Downloads

  • akca-windows-amd64.exe — Windows x64
  • akca-linux-amd64 — Linux x64
  • akca-linux-arm64 — Linux ARM64
  • akca-darwin-amd64 — macOS Intel
  • akca-darwin-arm64 — macOS Apple Silicon
  • SHA256SUMS.txt — SHA-256 verification manifest

Release binaries include GitHub build-provenance attestations and can be verified with gh attestation verify <binary> -R akha-security/akca.

Browser-backed checks require Chrome, Chromium, or Edge. Use AKCA only against systems you own or are explicitly authorized to test.

Full changelog: v0.2.4...v0.2.5

v0.2.4

Choose a tag to compare

@github-actions github-actions released this 26 Sep 13:58

Highlights

  • Preserve complete captured HTTP requests and responses in findings and reports instead of shortening or rebuilding available raw evidence.
  • Render structured-only evidence in a conventional Burp-style request/response format with standard headers, content length, and HTTP reason phrases.
  • Ship a self-contained AKCA-branded HTML report with clearer vulnerability statistics, detailed finding sections, Request/Response/Both views, full-content controls, and print-safe evidence.
  • Introduce a Lipgloss-based Scan Session panel with target emphasis, active status, request policy, engine, authentication, transport, OAST, and RAM information.
  • Replace ETA with an elapsed timer and show readable vulnerability-module names with in-place Running-to-Completed updates.
  • Make -h concise and --help exhaustive, with usage examples limited to supported command forms.
  • Reduce normal terminal noise by aggregating browser dependency blocks and moving repetitive coverage diagnostics to verbose output without discarding coverage metadata.

Reliability fixes

  • Preserve long response bodies, repeated headers, and trailing whitespace in generated evidence.
  • Label transport-truncated and missing request/response evidence explicitly.
  • Distinguish incomplete module coverage from execution failure so coverage gaps do not become misleading scanner errors.
  • Improve browser dependency summaries and adaptive module accounting for failed, budget-limited, and unfinished targets.

Documentation

  • Explain AKCA's context-aware, evidence-oriented scanning model and its relationship to established commercial DAST tools.
  • Add an English workflow and security-testing capability catalog.
  • Add Turkish and international community-support guidance. AKCA does not accept personal donations or sponsorships.
  • Replace the previous README image with reproducible output captured from AKCA's local integration lab.

Validation

  • Full Go package tests pass with go test ./... -count=1.
  • Static analysis passes with go vet ./....
  • Report regressions cover raw transaction preservation, long bodies, escaping, missing and truncated evidence, tabs, full-content controls, print behavior, and clipboard paths.
  • The Windows executable reports AKCA ADVANCED WEB SECURITY SCANNER v0.2.4.

Downloads

  • akca-windows-amd64.exe — Windows x64
  • akca-linux-amd64 — Linux x64
  • akca-linux-arm64 — Linux ARM64
  • akca-darwin-amd64 — macOS Intel
  • akca-darwin-arm64 — macOS Apple Silicon
  • SHA256SUMS.txt — SHA-256 verification manifest

Browser-backed checks require Chrome, Chromium, or Edge. Use AKCA only against systems you own or are explicitly authorized to test.

Full changelog: v0.2.3...v0.2.4

v0.2.3

Choose a tag to compare

@github-actions github-actions released this 25 Sep 10:15

Fixed

  • Present partial coverage prominently so an incomplete scan cannot be mistaken for complete assurance.
  • Remove the standalone Coverage & Readiness section from HTML and Markdown reports while retaining machine-readable coverage metadata and the partial-scan warning.
  • Replace raw CLI budget values and repetitive unlimited labels with concise coverage and traffic descriptions.
  • Remove meaningless 0.0 req/s output from the live progress row and format URL counts, memory values and status text consistently.

Added

  • Add an executive HTML report overview with risk level, severity distribution, vulnerability statistics and detailed scan metadata.
  • Organize findings into affected endpoint, description, impact, classification, recommendation and evidence sections.
  • Add a transaction-focused request and response viewer with outbound/inbound context, method or status details, proof highlighting and copy controls.
  • Rebuild the startup summary as a focused Scan Control dashboard for target, profile, discovery, verification and traffic policy.
  • Document why Full Scan prioritizes application coverage and verified evidence over minimum completion time, including guidance for bounded scans.

Validation

  • Full Go package tests pass with go test ./... -count=1.
  • Static analysis passes with go vet ./cmd/akca ./internal/report.
  • GitHub quality checks, race detection and the strict observed benchmark complete successfully.
  • Windows executable was launched and verified to report AKCA ADVANCED WEB SECURITY SCANNER v0.2.3.

Downloads

  • akca-windows-amd64.exe — Windows x64
  • akca-linux-amd64 — Linux x64
  • akca-linux-arm64 — Linux ARM64
  • akca-darwin-amd64 — macOS Intel
  • akca-darwin-arm64 — macOS Apple Silicon
  • SHA256SUMS.txt — SHA-256 verification manifest

Browser-backed checks require Chrome, Chromium or Edge. Use AKCA only against systems you own or are explicitly authorized to test.

Full changelog: v0.2.2...v0.2.3

v0.2.2

Choose a tag to compare

@akha-security akha-security released this 24 Sep 23:10

Fixed

  • Recursively analyze lazy-loaded JavaScript chunks and retain script dependencies independently from the API-finding confidence threshold.
  • Preserve extra login fields, multi-stage authentication requests, cookies and response bearer tokens during automatic login and reauthentication.
  • Require typed, replayable evidence for GraphQL, WebSocket, API exposure, JWT and authorization findings instead of promoting generic response differences.
  • Reject SQL injection findings based on HTTP 400/422 responses or arithmetic behavior without replay and negative-control proof.
  • Redact JavaScript secret values, nested login credentials, tokens and sensitive report fields by default.

Added

  • Add browser-assisted crawling when direct HTTP requests are blocked, empty or receive browser-solvable responses such as HTTP 403.
  • Add schema-derived, bounded GraphQL probes and typed disclosure checks without treating introspection or generic validation errors as vulnerabilities.
  • Add authenticated multi-step login and bearer-token session support with refreshed credentials propagated into active scan profiles.
  • Add coverage and module-readiness diagnostics to JSON, HTML and Markdown reports, including explicit partial-scan warnings.
  • Add regression coverage for recursive SPA discovery, authenticated sessions, typed verification and report coverage behavior.

Validation

  • Full Go package tests pass with go test ./... -count=1 -timeout=180s.
  • Static analysis passes with go vet ./....
  • Controlled local testlab scan passes.
  • Strict observed benchmark passes with precision, recall and specificity of 1.0 and a false-positive rate of 0 on the available corpus.
  • Windows executable was launched and verified to report AKCA ADVANCED WEB SECURITY SCANNER v0.2.2.

Downloads

  • akca-windows-amd64.exe — Windows x64
  • akca-linux-amd64 — Linux x64
  • akca-linux-arm64 — Linux ARM64
  • akca-darwin-amd64 — macOS Intel
  • akca-darwin-arm64 — macOS Apple Silicon
  • SHA256SUMS.txt — SHA-256 verification manifest

Use AKCA only against systems you own or are explicitly authorized to test.

Full changelog: v0.2.1...v0.2.2

v0.2.1

Choose a tag to compare

@akha-security akha-security released this 23 Sep 12:12

Fixed

  • Reject SQL injection evidence when baseline or payload responses return HTTP 4xx, preventing bad-request boolean probes such as 1 AND 20909=20909 from being reported as confirmed injection.
  • Continue crawler discovery through browser-assisted rendering when initial HTTP requests are blocked or empty, including 403 responses that still load in a normal browser.
  • Remove crawler route-saturation caps from unbounded full scans and fix queue-drain accounting so discovery does not end while requests are still being scheduled.
  • Initialize adaptive module budgets from the module catalog so every registered full-scan module receives a request plan and usage counter.

Added

  • Coverage-gap reporting for blocked or contentless crawl starts, making 0 crawler requests style failures visible instead of silently completing.
  • Regression tests for blocked-browser crawling, redirect discovery, SQLi 4xx false-positive rejection and catalog-wide module budget initialization.

Validation

  • Full Go package tests pass with go test ./... -count=1.
  • Static analysis passes with go vet ./....

v0.2.0

Choose a tag to compare

@github-actions github-actions released this 12 Sep 13:22

Full Changelog: v0.1.9...v0.2.0

v0.1.9

Choose a tag to compare

@github-actions github-actions released this 11 Sep 09:14

v0.1.9

Fixed

  • Reduce false positives in CORS, open redirects, CSTI, JSONP, WebSocket, prototype pollution, parser differential and route authentication checks by requiring evidence of the claimed security effect.
  • Validate actual redirect destinations instead of attacker URLs embedded in nested query parameters.
  • Repair stored-XSS tracking and raw HTTP smuggling verification; preserve raw request and response evidence.
  • Include response status and security-relevant headers in finding replay comparisons.
  • Correct coverage accounting, persistent learning outcome counts, response similarity and cache-hit detection.
  • Share request budgets across HTTP, browser HTTP and raw protocol probe paths.
  • Restore Copy Response, Copy Request and Copy cURL in HTML reports, including a clipboard fallback.
  • Isolate the CLI integration test from the user's data directory.

Added

  • Private-canary proof policies and browser cross-origin read observations.
  • Regression tests for the reported false positives, raw protocol replay, clipboard behavior and shared budgets.
  • Audit and validation reports documenting remaining verification limits.

Validation

  • The preceding changes passed tests in 80 Go packages and go vet.
  • The strict observed benchmark passed for the existing corpus.
  • Live third-party/browser coverage is not inferred from fixture tests; local race testing required an unavailable GCC toolchain.

v0.1.8

Choose a tag to compare

@github-actions github-actions released this 08 Sep 16:02

v0.1.8

Added

  • Physical wire transport interception with strict request budgets across redirects, retries and per-host pacing.
  • Timing-based blind NoSQL verification with baseline calibration, zero-delay controls and delayed confirmation.
  • Native multipart and XML request mutation, including boundary management and crawler form encoding support.
  • Live health metrics, improved scan comparison streaming and collision-resistant scan IDs.

Fixed

  • Expand SQL error detection and tolerate valid timing findings with expected server error responses.
  • Bound crawler route saturation and restrict automatic redirect scope adoption to canonical host pairs by default.
  • Correct reflection sentinel probes and dynamic payload assembly.
  • Harden report-builder error handling and persist scan records before session start.

v0.1.7

Choose a tag to compare

@github-actions github-actions released this 07 Sep 08:37

v0.1.7

Added

  • GET-to-POST method pivoting with dual query/body hidden-parameter discovery.
  • Automatic promotion of confirmed hidden POST parameters into scanner targets.
  • Surface-adaptive module budgeting with per-category probe quotas and starvation isolation.
  • Expanded high-impact parameter wordlists with context-aware prioritization for admin, cloud, upload and proxy routes.

Fixed

  • Preserve final scan status and avoid health-metrics nil pointer panics.
  • Count request budgets outside retry loops and preserve HTTP 429 evidence with Retry-After handling.
  • Use cryptographic randomness for WAF bypass headers and correct rate-limiter jitter.
  • Tighten preflight, scope expansion, non-standard port handling, proxy port allocation and UTF-8 truncation behavior.

Optimized

  • Scope TLS misconfiguration checks to root hosts.
  • Reduce noisy coverage notices in normal CLI output.
  • Run api_versioning once per host on root or base API endpoints.

v0.1.6

Choose a tag to compare

@github-actions github-actions released this 06 Sep 13:01

v0.1.6

Added

  • Type-aware probing across SQL injection, command injection, NoSQL injection, IDOR/BOLA and path traversal modules.
  • Numeric-safe SQL and command probes for parameters that reject free-form payload prefixes.
  • Nested dotted-path support for MongoDB operator queries and authentication bypass bodies.
  • Category-weighted request budgets with rollover from completed modules and groups.
  • Coverage-gap metrics when configured budgets prevent full target coverage.

Fixed

  • Support bracket, dot and unindexed array JSON mutations without overwriting container values.
  • Target only scalar JSON leaf values to avoid schema-validation rejections.
  • Balance Windows and Linux traversal testing to avoid premature fast-fail behavior.