πŸ”₯ Sn1per SE v11.0 Now Available – Major Refactor, New Tools, Faster Recon, Smarter Resumes

We’re excited to announce the release of Sn1per SE v11.0, a major update that delivers a fully refactored codebase, new reconnaissance and vulnerability scanning tools, and powerful scan resume and debugging capabilities.

This release focuses on stability, performance, and visibility, making large-scale penetration testing, red teaming, and continuous security assessments faster and easier than ever.

(more…)

Sn1per SE v10.8 Now Available – New Features, Tools & Enhancements!

We’re excited to announce the release of Sn1per SE (Scan Engine) v10.8, bringing a host of new features, tools, templates, and improvements. This update is part of the Sn1per SE development branch, exclusively available to Sn1per Professional and Sn1per Enterprise customers. If you’re a previous customer or using the Community Edition on GitHub, you’ll need to purchase a Sn1per Professional or Enterprise license to access this latest update.

(more…)

Sn1per Scan Engine v10.7 Released!

Sn1per SE (Scan Engine) v10.7 is now available with a ton of new features and improvements. This update is part of the Sn1per SE development branch which is available to Sn1per Professional and Sn1per Enterprise customers. If you are a previous customer or if you use the Community Edition available on Github, you will need to purchase a Sn1per Professional or Sn1per Enterprise license to download and receive updates.

(more…)

Sn1per SE Update

Sn1per Scan Engine v10.6 Released!

Sn1per SE (Scan Engine) v10.6 is now available with a ton of new features and improvements. This update is part of the Sn1per SE development branch which is available to Sn1per Professional and Sn1per Enterprise customers. If you are a previous customer (ie. Sn1per Professional v9.0 or less) or if you use the Community Edition available on Github, you will need to purchase a Sn1per Professional or Sn1per Enterprise license to download and receive updates.

(more…)

CVE-2024-21733 Apache Tomcat HTTP Request Smuggling

CVE-2024-21733 Apache Tomcat HTTP Request Smuggling

Our security research team recently discovered a critical “0day” vulnerability which was assigned CVE-2024-21733. The vulnerability was discovered by xer0dayz from Sn1perSecurity LLC and allows attackers to force a victim’s browser to de-synchronize its connection with websites hosted on top of Apache Tomcat, causing sensitive data to be smuggled from the server and/or client connections. In some cases, this can leak sensitive data such as clear-text credentials.

Severity: CRITICAL | Exploit Available: Yes | Exploitability: Easy | Remotely Exploitable: Yes

(more…)