Latest News
August 3, 2008Immunity CANVAS Professional 6.37
Miami Beach, FL - (August 3, 2008) - CANVAS Professional 6.37 delivers new Windows rootkitting capabilities, a variety of new exploits, and improved engine stability and robustness. On the feature front CANVAS Professional 6.37 includes new modules to investigate DNS Caches and remote memory dumps. Available now!
July 2, 2008
Immunity CANVAS Professional 6.36
Miami Beach, FL - (July 2, 2008) - CANVAS Professional 6.36 brings an array of new engine features to the table, including MOSDEF OS X Intel support, new Solaris and Windows exploits and improved Linux payload generation. CANVAS Professional 6.36 also includes an updated SPIKE Proxy with much improved support libraries for convenient RFI exploitation. Available now!
June 2, 2008
Immunity CANVAS Professional 6.35
Miami Beach, FL - (June 2, 2008) - CANVAS Professional 6.35 delivers on the feature front by including full MOSDEFSock support for PHP ScriptNodes. CANVAS users can now bounce CANVAS exploits and recon modules through hosts compromised via PHP bugs without touching disk. CANVAS Professional 6.35 also includes several new exploits and features including the i2omgmt Driver Impersonation attack, and a SSH key checker for the Debian/Ubuntu OpenSSL PRNG weakness. Available now!
May 1, 2008
Immunity CANVAS Professional 6.34
Miami Beach, FL - (May 1, 2008) - Immunity is proud to present: CANVAS Professional 6.34 CANVAS Professional 6.34 offers an exciting new collection of exploits and drastic improvements in the client side arena. CANVAS Professional 6.34 includes the first public exploit for the much discussed Flash 9e vulnerability. Other new features include a slew of new web exploits, MSRPC fuzzing, and full SSL support for MOSDEF HTTP tunneling. Available now!
April 1, 2008
Immunity CANVAS Professional 6.33
Miami Beach, FL - (April 1, 2008) - Immunity is proud to present: CANVAS Professional 6.33. CANVAS Professional 6.33 is loaded with Kernel goodies for both Windows and Linux. On the Windows side of things we've included the first public exploit for the MS07_066 Vista Local Privilege Escalation bug, and on the Linux side of things we've included a full MOSDEF exploit for the vmsplice(2) Kernel bug. Other exploits include a full MOSDEF socket recycling remote root exploit for the ASUS Eee PC SAMBA 3.24 and five new web app exploits. Available now!
March 3, 2008
Immunity CANVAS Professional 6.32
Miami Beach, FL - (March 3, 2008) - Immunity is proud to present: Immunity CANVAS Professional 6.32. CANVAS Professional 6.32 includes Immunity's MS08-001 Windows IGMPv3 exploit, 20 new web application exploits, and the client side Adobe Acrobat Reader Javascript stack overflow. Exploits for the Novell Netware Print Spooler bug, updated Solaris XFS and MS06-040 for Windows Server 2003 SP0 round out the exploit updates for the month.
February 1, 2008
Immunity CANVAS Professional 6.31
Miami Beach, FL - (February 1, 2008) - Immunity CANVAS Professional 6.31 is now available. CANVAS 6.31 includes support for Windows kernel backdooring, contains improved OS Detection features and offers full MOSDEF support for Java and Script nodes.
January 2nd, 2008
Immunity CANVAS Professional 6.30
Immunity's award winning CANVAS product now includes exploits for MS07_065, the punbb web forum, and OpenOffice.org's arbitrary Java execution vulnerability.
December 3, 2007
Immunity CANVAS Professional 6.29
This release of CANVAS Professional provides new clientside exploits, fingerprinting and reconnaisance tools, as well as numerous reliability and usability improvements.
November 1, 2007
Immunity CANVAS Professional 6.28
Immunity CANVAS Professional 6.28 is now available. It includes many exciting new exploits and features. Exploit highlights include the Solaris XFS module, the MacroVision Driver module for XP SP2, and various clientside exploits including the RealPlayer Import ActiveX module and Microsoft IE7 url-handling module. New features include full geolocation support and SPIKE Proxy now supports automatic Remote File Inclusion exploitation.
October 19, 2007
Immunity Dojo and Talks at Pacsec 2007
Immunity's very own Kostya Kortchinsky and Nicolas Waisman will be teaching and presenting at PacSec 2007. Kostya will be presenting a talk on improved Windows Localization detection and Nico will be discussing the future of Heap Overflows on Windows. Together they will be teaching a PacSec Dojo on the art of finding 0day vulnerabilities. This Dojo will be a useful introduction to Immunity's February class, also to be held in Tokyo.
When: November 28-30, 2007
Where: Aoyama Diamond Hall, Tokyo, Japan
Info: PacSec Dojo Listing
October 15, 2007
Immunity welcomes Paul Starzetz
Immunity is proud to welcome Paul Starzetz to the Immunity team!
October 9, 2007
Immunity founder Dave Aitel profiled by DarkReading
Darkreading.com's profile of Immunity Founder and CTO Dave Aitel can be read here.
October 2, 2007
Immunity releases Immunity CANVAS Professional 6.27
Miami Beach, FL - (October 2, 2007) - CANVAS Professonial 6.27 delivers an array of exciting new features, such as: a much improved GUI, MOSDEF for Solaris X86, and a flurry of new exploits. New exploit modules include exploits for flaws in the VMWARE DHCPD, Tivoli Storage Manager, Xitami, Veritas Netback, and Brightstore Media Server. CANVAS Professional 6.27 also comes with 21 new Web App exploits. CANVAS Professional 6.27 is available now!
September 27, 2007
Immunity hires top notch Kiwi and Argentinian talent
Miami Beach, FL, Buenos Aires AR, Aukland NZ - (September 27, 2007) - Immunity is proud to announce the addition of Adam Boileau and Pablo Sole to the Immunity team.
September 4, 2007
Immunity releases Immunity CANVAS Professional 6.26
Miami Beach, FL - (September 4, 2007) - CANVAS 6.26 delivers 20 brand new exploit modules for the month of September. It now includes exploits for the Solaris 10 telnet/login vulnerability, the HP OpenView Trace buffer overflow, the Borland IB Server buffer overflow and the Novell Netware Printer Provider client overflow. The CANVAS Engine now has a UserAgent object for Python based web hacking and the OSdetect module has been much improved. CANVAS Professional 6.25 is available now!
August 18, 2007
Immunity now offers a forum for people to share scripts, ideas, screenshots, and other important information on.
August 1, 2007
Immunity releases Immunity CANVAS Professional 6.25
Miami Beach, FL - (August 1, 2007) - CANVAS Professonial 6.25 delivers an engine overhaul and a brand new paintjob. The GUI has been redesigned and CANVAS looks better than ever. Furthermore the x86 MOSDEF assembler is now twice as fast. This means dramatic MOSDEF and exploit speedups. Boasting fifteen new exploit and attack modules, CANVAS Professional 6.25 is available now!
July 2, 2007
Immunity releases Immunity CANVAS Professional 6.24
Miami Beach, FL - (July 2, 2007) - Immunity brings you full MOSDEF PPC and 64 bit Python support with CANVAS 6.24. Next to engine improvements CANVAS Professional 6.24 also includes 11 new web application exploits and a complete version of SPIKE 3.0 to fully satisfy your fuzzing needs.
June 4, 2007
Immunity releases Immunity CANVAS 6.23
Miami Beach, FL - (June 4, 2007) - Immunity brings you a flurry of exciting new exploits this June, including a reliable remote root exploit for OS X on both Intel and PPC platforms. Other updates include an exploit for the Samba LsaLookupSids heap overflow and no less than five new web application exploits. New features include a UNIXSHELL handler, non-executable stack support (SP2) in the ANI cursor exploit, and improved MOSDEF UNIX support.
May 2, 2007
Immunity releases Immunity CANVAS 6.22
Miami Beach, FL - (May 2, 2007) - Immunity brings you full clientside HTTP MOSDEF tunneling with CANVAS 6.22. Next to providing the technology needed to keep up with current exploitation trends, CANVAS 6.22 also includes eight new exploits. Including an exploit for the notorious MS DNS bug and four PHP injection vulnerabilities that work with the CANVAS PHP Node framework. New tools include a module to list services on Windows machines and a module that can use the Windows At service.
April 1, 2007
Immunity releases Immunity CANVAS 6.21
Miami Beach, FL - (April 1, 2007) - Immunity releases an exploit for the very current Windows ANI File Format Parser overflow in CANVAS 6.21. Next to keeping CANVAS customers on the cutting edge of security research, this month's release also includes twelve other exploit modules. Including the much discussed GDIWrite4 local exploit and an exploit for the Snort DCERPC bug. New features include multiple host targeting, callback interface matching, and binary exploit integration.
March 1, 2007
Immunity releases Immunity CANVAS 6.20
Miami Beach, FL - (March 1, 2007) - Immunity puts the pedal to the metal with CANVAS 6.20. Caching improvements to the MOSDEF engine ensure a faster and more stable MOSDEF, whilst overall engine updates have upped the performance levels in many crucial areas. CANVAS 6.20 also brings with it improved language support and new targets for many of its exploits and offers exciting new features to the MassAttack module to make your penetration testing life easier.
February 14, 2007
Free Immunity CANVAS + VulnDisco Package, for limited time only!
VulnDisco, Gleg Ltd's set of 0day exploitation modules, are specially designed to be used with Immunity CANVAS. For a limited time only Immunity and Gleg are pleased to announce a free CANVAS offer to new customers purchasing any VulnDisco Professional license or to new customers purchasing the Unlimited User Standard VulnDisco license. Customers purchasing VulnDisco Standard for 10 users/installations can obtain CANVAS for just $500. This offer includes 3 months of CANVAS updates. CANVAS normally retails at $1244 per license. To take advantage of this offer please email sales@immunityinc.com!
February 1, 2007
Immunity releases Immunity CANVAS 6.19
Miami Beach, FL - (February 1, 2007) - Immunity shares the love in valentine February with CANVAS 6.19. This release includes support for IPv6, a Command Line Executer framework for web bugs and many exploit improvements. New modules include attacks against MS07-004 (VML), Citrix PrintProvider and 3Com TFTPD.
January 29, 2007
Immunity CANVAS runs on Windows Vista
See this screenshot for an example of the latest Immunity CANVAS Professional running a scan from Windows Vista Ultimate.
January 9, 2007
Immunity releases MS07_004 Exploit
Immunity, Inc. publishes working exploit for MS07_004 into Immunity Partners' program, less than three hours after it was announced.
January 1, 2007
Immunity releases Immunity CANVAS 6.18
Miami Beach, FL - (January 1, 2006) - Immunity is excited to ring in the new year with version 6.18 of Immunity CANVAS Professional. This release includes exploits for MS06_074 (SNMP), Symantec Remote Management, Novell Netware and Netmail, as well as many updates and stability improvements.
December 1, 2006
Immunity releases Immunity CANVAS 6.17
Miami Beach, FL - (December 1, 2006) - Immunity is proud to announce version 6.17 of Immunity CANVAS Professional. This release includes exploits for MS0_066, MS06_070, MS06_071, Novel eDirectory HttpStk.dlm, and Linux /proc a.out vulnerability.
November 1, 2006
Immunity releases Immunity CANVAS 6.16
Miami Beach, FL - (November 1, 2006) - Immunity, Inc. is proud to
announce version 6.16 of Immunity CANVAS Professional. This release
features a massively-threaded automated attack tool.
October 2, 2006
Immunity releases Immunity CANVAS 6.15
Miami beach, FL - (September 2, 2006) - Immunity, Inc. is proud to
announce the release of Immunity CANVAS Professional 6.15. This release
includes a built-in Windows keylogger, and several new exploits.
July 3, 2006
Immunity releases Immunity CANVAS 6.12
Miami Beach, FL - (July 3, 2006) - Immunity, Inc. has released
version 6.12 of Immunity CANVAS Professional. This release follows the successful integration of the latest Microsoft vulnerabilities
into the flagship Immunity product - vulnerabilities which had
previously only been available to Immunity Partner's customers. This month, as always, Immunity was the first company to offer its
customers the latest vulnerabilities within hours or days of the Microsoft Tuesday advisories.
June 1, 2006
Immunity releases Immunity CANVAS 6.11
Miami Beach, FL - (June 1, 2006) - Immunity, Inc. is proud to announce
the release of Immunity CANVAS Professional 6.11. This release
contains the first ever commercially available remote kernel-level
exploit. This exploit, for a vulnerability in Microsoft Windows
operating systems brings a new level of capability to penetation
testers using the CANVAS Professional product to test remote servers.
May 22, 2006
Immunity, Inc. launches groundbreaking VisualSploit product
Miami Beach, FL - (May 22, 2006) - Immunity, Inc. is proud to announce the public availability of VisualSploit, a plugin to Immunity's flagship product Immunity CANVAS which allows non-programmers to develop exploits for the Immunity CANVAS framework simply by dragging and dropping exploit components.
This provides a way for wide audience of people who previously would be unable to write their own exploits to utilize the advanced features of Immunity CANVAS to produce original modules they can then use to test their entire network with.
Immunity VisualSploit is available now at http://www.immunityinc.com/products-visualsploit.shtml
March 28, 2006
Immunity, Inc and SilverSEAL Corp. announce a strategic alliance to integrate services
New York, NY - (March 28, 2006) - SilverSEAL Corporation, a premier provider of investigative services, computer forensics, and physical security announced on Tuesday, a strategic alliance with Immunity Incorporated to integrate their specialized information security services to their product repertoire.
Immunity's extraordinary capabilities in discovering and implementing exploits for both operating systems and applications provided a natural fit for SilverSEAL, as they focus on expanding their computer forensic division.
"We're excited about our relationship with Immunity Inc.," commented John Silverman, president of SilverSEAL Inc., "we've been in the business of uncovering truths for our clients for 22 years. However, in the current world of information technology our clients are more vulnerable to having confidential information compromised due to the increasing threat of hackers, Trojans, viruses, and worms. Immunity is a perfect fit because they are one of the best in the trade and are honorable, a combination that is rare in this industry."
Justine Aitel, Immunity's CEO, is similarly positive about the complete layer of protection now available to SilverSEAL clients. "Immunity's specialist resources compliment those already available to SilverSEAL clients. Firms that collect and store sensitive information are worried about ensuring it is adequately protected, but usually do not have the expertise on staff to properly assess and manage the ever-evolving risks themselves. SilverSEAL, in partnering with Immunity, can now reassure its clients that their electronically stored data and networks are properly protected."
About Immunity, Inc:
Founded in 2002, Immunity Inc, comprising of world-class security researchers including CTO Dave Aitel, specializes in the realm of information security.
Developing the incredibly robust penetration platform named CANVAS, as well as being the co-authors of: The Hackers Handbook and the Shell Coders Handbook, make the Immunity team one of the best in their industry. With former government and extensive information security experience, the Immunity team brings to the table premier consulting services regarding the assessment of software and web-based applications.
About SilverSEAL:
SilverSeal is made up of two highly regarded firms: Silverman Associates which specializes in Investigative Services and SEAL Security which concentrates on providing comprehensive Security Solutions.
Founded in 1988, Silverman Associates has been providing discreet investigative services, earning the reputation
as resourceful problem solvers specializing in litigation support, corporate due diligence, investigative database rese
arch, and computer forensics. SEAL Security was formed in 1995 to fill the need for quality corporate and customized se
curity, providing high-end officers and crisis management teams to the corporate world.
March 1, 2006
Immunity CANVAS 6.8 release includes AIX attack capabilities. This allows Immunity CANVAS users to test large enterprises. Immunity CANVAS is unique in that it now supports AIX, Linux, Solaris, Windows, BSD, and OS X. Also included are expanded methods for downloading the entire memory contents of Windows processes. This can be used for forensics, simultanious intruder detection, and data access.
February 17, 2006
Protover test suites are now available for purchase directly from
Immunity. Protover can be used to test the security and stability of
various protocol implementations including SSL, IMAP and LDAP. Further
information including pricing is available at Gleg, Ltd's website:
http://www.gleg.net
December 21, 2005
Immunity's CANVAS Professional has been reviewed by the independent
technology analyst company, The 451 Group.
The full report is available here. The 451 Group calls CANVAS
Professional a "robust penetration platform" that is "10 times
less expensive than its nearest competitor". The report also
includes a description of CANVAS's main "technical differentiator",
MOSDEF.
October 6, 2005
Immunity is pleased to annouce itself as reseller of Sabre BinNavi - the
world's first debugging system based on directed graphs and graph
visualisation. More information available at: http://www.immunitysec.com/products-binnavi.shtml.
September 22, 2005
Immunity Theater of Owning
July 14, 2005
Immunity is pleased to announce the appointment of Justine Aitel to the
position of CEO, Immunity, Inc.
Dave Aitel will continue to drive the technical direction of Immunity allowing
Justine to focus on strategic initiatives.
January 14,2005
Immunity announces the addition of Justine Bone (Aitel) to the
Immunity team. Justine was previously responsible for global risk
management and information security at Bloomberg L.P, based in New
York City. Justine is a New Zealander who began her career with the
NZ's Government Communications Security Bureau, later moving to the
United States to join Internet Security Systems as researcher and
consultant. Justine can be reached at justine.aitel@immunitysec.com.
Oct 29, 2004
Immunity adds Hydrogen to its formidable product lineup.
March 22, 2004
Immunity employees Dave Aitel and Sinan Eren add
"The Shellcoder's Handbook" to their list of publications.















