Active scanner rules (beta) version 40
·
7612 commits
to main
since this release
Changed
- Hidden File Finder scan rule, content checking has been added for .svn/entries as well as detection for wc.db.
- Use Network add-on to detect/serve HttPoxy scan rule requests.
- Maintenance changes.
- The CSRF Token scan rule will now raise alerts as Medium risk (Issue 7021).
Fixed
- Adapted Cloud Metadata Attack scan rule to use Custom Pages and active scan analyzer to help reduce false positives in certain cases (Issue 7033).
- Generic Padding Oracle scan rule will no longer raise an alert for validation fields when the error response contains expected error patterns (Issue 6183).
- Hidden File Finder no longer follows redirects when sending requests for potential hidden files which should make it less false positive prone (Issue 7036).