Quantcast
Viewing all articles
Browse latest Browse all 236

The newest Faraday version yet - all hail v2.6!

Let's give a warm welcome to Faraday v2.6 (Community, Pro & Corp)!

Faraday is the Integrated Multiuser Risk Environment you were looking for! It maps and leverages all the knowledge you generate in real time, letting you track and understand your audits. Our dashboard for CISOs and managers uncovers the impact and risk being assessed by the audit in real-time without the need for a single email. Developed with a specialized set of functionalities that helps users improve their own work, the main purpose is to re-use the available tools in the community taking advantage of them in a collaborative way! Check out the Faraday project in Github.



Improving the Data Analysis tools

As per your requests, we made some changes to the existing Data Analysis tools introduced in the last release. We added the possibility to change data configuration in order to customize charts, a new bar chart type to show most vulnerable services and a filter for undefined or null values.
Image may be NSFW.
Clik here to view.
Most vulnerable services

Image may be NSFW.
Clik here to view.
Modal to set chart properties

Image may be NSFW.
Clik here to view.
Charts customization




Executive Report clean up

Some users reported issues with the sorting of Hosts and Evidence in the reports. We fixed it so the hosts in grouped reports are sorted by IP and evidence is sorted by alphabetically by name.

Image may be NSFW.
Clik here to view.
Targets are sorted by IP
Image may be NSFW.
Clik here to view.
Evidence names sorted alphabetically

We know sometimes it is necessary to use special characters for evidence names. Some of our users

Web UI

Now you can manually create the same vulnerability in several hosts at once! Select as many targets as you want when creating your vulns.


Image may be NSFW.
Clik here to view.
Add vuln to multiple targets at once

 
Also, we made the vulnerability creation modal more consistent with the rest of the views by starting the pagination of the targets in page 1 instead of 0.

Corp changes and fixes

  • Improved Data analysis charts. Added more chart properties and data binding

Pro changes and fixes

  • Improved target ordering in grouped reports 
  • Fixed bug with new line character in reports DOCX 
  • Adds alphabetical sort for Evidence in the Executive Report 
  • Fix bug updating users with no roles 
  • Fixed report creation with evidence names containing special chars

Community changes and fixes

  • Added the ability to select more than one target when creating a vuln in the Web UI 
  • Merged PR #182 - problems with zonatransfer.me 
  • Fixed bug in Download CSV of Status report with old versions of Firefox
  • Fixed formula injection vulnerability in export to CSV feature 
  • Fixed DOM-based XSS in the Top Services widget of the dashboard 
  • Fix in AppScan plugin
  • Fix HTML injection in Vulnerability template
  • Add new plugin: Junit XML
  • Improved pagination in new vuln modal of status report 
  • Added "Policy Violations" field for Vulnerabilities
We hope you enjoy it, and let us know if you have any questions or comments.

https://www.faradaysec.com

https://github.com/infobyte/faraday
https://twitter.com/faradaysec

https://forum.faradaysec.com/


https://www.faradaysec.com/ideas

Viewing all articles
Browse latest Browse all 236

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>