LevelBlue Named Official Cybersecurity Advisor of the PGA of America. Learn more
Access immediate incident response support, available 24/7
Access immediate incident response support, available 24/7
LevelBlue Named Official Cybersecurity Advisor of the PGA of America. Learn more
While some of the team is already out in Vegas for Black Hat, the rest of us have been in the office, slaving away to bring you an update to the TrustKeeper scan engine before we head out there for DEF CON.
This update includes more than a dozen new vulnerability tests, as well as seven new fingerprints for web applications, including several for various applications from the Horde Project. The new vulnerability tests include ones for several recent vulns in Microsoft SharePoint, WordPress and PHP. We also added detection for web-server log files, which some people and some misconfigurations make publically accessible.
This release also marks the introduction of our next-generation web-application scanning module, which will initially be undergoing testing alongside our existing web app scanner. Our internal testing has shown it to be a significant improvement over the existing scanner (phew!), but we're going to put it through broader external testing before we remove the legacy scanning module.
That's it for now. If you're in Las Vegas this week, come find us and chat us up. We'll be the ones in spider shirts.
Some of the more interesting vulnerability tests we added recently are as follows:
Apache
Generic
Microsoft
PHP
Samba
WordPress
All Trustwave customers using the TrustKeeper Scan Engine receive the updates "auto-magically" as soon as an update is available. No action is required.