This month we have already released two updates for Netsparker Desktop web application security scanner. Below is an overview of what is new and improved.
Netsparker Desktop will automatically check if the target is vulnerable to the DROWN vulnerability. We released the update just two days after the vulnerability was made public, in version 220.127.116.1105. DROWN is another SSL/TLS vulnerability with which attackers can force people to use insecure algorithms, thus allowing them to read the communication between the user and the server. You can read more about the DROWN vulnerability from the vulnerability website.
In version 4.5.8 of Netsparker Desktop we also included a number of new security checks for the HTTP Strict Transport Security (HSTS) mechanism.
In this March update of Netsparker Desktop web application security scanner we have also:
For more detailed information on what is new, improved and also fixed in version 18.104.22.16829 of Netsparker Desktop please refer to the Netsparker Desktop changelog.