Skip to content

Qualys Launches Periscope for Out-of-Band Web App Vulnerability Detection

Periscope targets blind XXE, SMTP header injection, and SSRF. It's now available on multiple Qualys platforms, proven to detect real-world vulnerabilities.

This picture shows a few buildings and trees and we see few vehicles moving on the road and we see...
This picture shows a few buildings and trees and we see few vehicles moving on the road and we see sign boards and traffic signal lights to the poles and a blue cloudy sky and we see few caution signs painted on the roads.

Qualys Launches Periscope for Out-of-Band Web App Vulnerability Detection

Qualys has introduced Periscope, a new vulnerability detection mechanism for web applications and REST APIs. It operates independently of traditional HTTP request-response interactions, focusing on out-of-band vulnerabilities that can target internal systems.

Periscope, available on several Qualys platforms, can detect vulnerabilities like Blind XXE injection, SMTP Header Injection, and Server-Side Request Forgery (SSRF). It works by fuzzing fields with crafted payloads, capturing DNS lookup requests, and verifying vulnerabilities.

Organizations can use Periscope to gain deeper insights into their web application vulnerabilities, driving remediation efforts and reducing risk. This method resembles other Out-of-Band Application Security Testing methods, avoiding disruption to the production environment.

Periscope's unique approach to vulnerability detection is now available on Qualys platforms, including EU1, EU2, US1, US2, US3, and IN1. Its effectiveness was demonstrated in a 2019 data breach against a U.S. bank, where it detected an SSRF vulnerability.

Read also:

Latest