Skip to content

Active scanner rules (beta) version 40

Choose a tag to compare

@zapbot zapbot released this 15 Mar 15:33
· 7612 commits to main since this release
0bb7735

Changed

  • Hidden File Finder scan rule, content checking has been added for .svn/entries as well as detection for wc.db.
  • Use Network add-on to detect/serve HttPoxy scan rule requests.
  • Maintenance changes.
  • The CSRF Token scan rule will now raise alerts as Medium risk (Issue 7021).

Fixed

  • Adapted Cloud Metadata Attack scan rule to use Custom Pages and active scan analyzer to help reduce false positives in certain cases (Issue 7033).
  • Generic Padding Oracle scan rule will no longer raise an alert for validation fields when the error response contains expected error patterns (Issue 6183).
  • Hidden File Finder no longer follows redirects when sending requests for potential hidden files which should make it less false positive prone (Issue 7036).