What NewScan Pro adds
// out-of-band classes the listener unlocks// WHEN A FINDING NEEDS A TARGET TO POINT BACK AT
One hosted endpoint. Every blind vulnerability class, verified.
NewScan Pro provides the HTTP(S) and DNS endpoint the target calls back to. NewScan plants a unique canary in its payloads, the hosted listener records any callback, and the scanner correlates it to the exact request that triggered it — recording a verified, reproduced finding, never a guess.
The listener is the one capability that needs a Pro license and an account. The scanner itself never does — and every out-of-band check keeps an in-band arm, so a scan without Pro still reports the vulnerability class and loses only the blind confirmation.
// OUT-OF-BAND DETECTIONS PRO UNLOCKS
| Detection | How the callback confirms it |
|---|---|
| Blind SSRF | The target fetches the canary over HTTP or DNS — proof the server made the request. Separate arms prove an allow-list bypass too (redirect-follow, DNS rebinding, credential and encoding tricks), each with the remediation for how it got through. |
| SSRF where scanners don’t look | GraphQL arguments found by introspection, image/URL proxies that carry the origin in the path (/unsafe/http://… — Thumbor, imgproxy, /_next/image), and webhook/upstream fetches (OWASP API10). Same canary, surfaces a parameter sweep never reaches. |
| OAuth / OIDC URI SSRF | The URI params an authorization server is supposed to dereference — request_uri, jwks_uri, sector_identifier_uri, logo_uri — pointed at the listener. A callback proves the server fetches attacker URLs pre-auth. |
| Prompt-injection SSRF (LLM & MCP) | A canary URL planted in the prompt instructs the model’s browsing/fetch tool to retrieve it; the callback proves the injection actually drove a server-side request. Same arm confirms a poisoned MCP tool reaching out. |
| Blind XSS | A stored payload fires later — when an admin views it — and loads its script from the listener. Nothing in the response you got ever showed it. |
| OOB XXE | An external entity resolves against the listener — in a JSON/XML API, a SOAP operation, or an uploaded SVG — confirming the parser is vulnerable when no file content reflects. |
| Insecure deserialization → RCE | A language gadget (Python pickle, Java URLDNS — JDK-only, no extra library needed) makes the target call out as it deserializes — proving execution before any response is rendered. |
| CVE RCE callbacks | Log4Shell (CVE-2021-44228), Text4Shell (CVE-2022-42889), Fastjson autotype and Langflow’s unauthenticated /api/v1/validate/code — a lookup reaching the listener proves the version present actually executes, instead of guessing from a version string. |
| JWT jku / x5u | A forged token points at a JWKS on the listener; the fetch proves the verifier trusts attacker-supplied keys — token forgery and SSRF at once. |
| Reset poisoning & email header injection | The app’s own mail lands in the hosted SMTP sink — proving it sent mail out, and revealing a host-header-poisoned reset link (account takeover) or an attacker-injected recipient. |
| Remote include & XSLT fetch | An include/template parameter (RFI) or an XSLT document() pulls the listener’s URL server-side — the recorded pull is the confirmation when nothing renders. |
| Open DNS resolver & SMTP relay | Network mode: a recursive query for a canary host, and one external→external test message. A DNS callback or a delivery into the sink is the only way to prove the abuse actually works from outside. |
These are the highest-impact ones — the hosted listener arms every out-of-band check in NewScan, and new ones land with the daily detection releases. Each callback is correlated to the request that triggered it and recorded as a verified, reproduced finding.
The listener answers DNS under its domain and serves a valid jwks.json, so multi-step callbacks (DNS → HTTP, jku fetch) complete and correlate to one session.
// ALSO IN PRO
ShippedDaily detection signature updates ✓
new detections every day, delivered over the air as signed signature packs — a Pro install picks them up at startup, no new image
Jira integration ✓
push findings straight to Jira tickets — re-filing updates instead of duplicating
GitHub Issues integration ✓
open GitHub Issues from findings; connect the repo on your account page
Security-framework reports ✓
reports scoped to PCI DSS, SOC 2, ISO 27001, HITRUST, HIPAA & NIST 800-53
How it works
// opt-in, correlated, privacy-preserving01
Open a session
Your licensed scanner opens a session and gets a unique canary host: <token>.<session>.<domain>. Payloads carry that host so any callback is yours alone.
02
Target calls back
A vulnerable target reaches the hosted HTTP or DNS endpoint. The interaction is recorded and matched to your session by the canary subdomain — no shared state to untangle.
03
Verify & record
NewScan polls the interactions back, ties the callback to the request that caused it, and records a confirmed finding — real, with evidence attached.
PRIVACY BY DESIGN
Only the out-of-band callbacks ever touch the hosted listener. Your scan traffic, findings, credentials, and AI keys stay on your machine — the hosted listener receives a callback, not your data.
NEVER A DEAD END
Local in-band detection is free, forever — and every out-of-band check keeps an in-band arm, so a scan without Pro still reports the vulnerability class. What you lose is the blind confirmation: a finding that can only be proved by a callback is reported honestly as unconfirmed, never guessed at and never silently dropped.
Pricing
// NewScan Pro, hosted & maintained by NewNormal Security1 MONTH
NewScan Pro, billed month to month. Cancel anytime — ideal for a single engagement or a short assessment window.
- →Hosted HTTP(S) + DNS OOB listener
- →Every out-of-band detection class, including new ones as they ship
- →Individually licensed — one Pro activation per install
- →Upgrade to annual anytime — pay only the difference
ANNUAL
BEST VALUEA full year of hosted out-of-band detection at the lowest effective rate. For testers and teams who run engagements all year.
- →Everything in monthly
- →12 months for the price of ~4
- →Individually licensed — one Pro activation per install
- →Priority support on the hosted listener
1 MONTH → YEAR UPGRADE
Already on Pro monthly and want the year? Convert your active month straight into a full annual term — no re-activation.
- →One-time payment — not a new subscription
- →Converts to a 12-month annual term
- →Same license & install — no re-activation
// ENTERPRISE SALES
Bigger rollout? Let's do a deal.
Multi-seat, organization-wide, or procurement that needs a PO and invoice? Enterprise gets custom pricing and invoicing that bypasses the standard plans above — sized to your deployment, billed how your finance team needs it. Tell us what you're after and we'll come back with terms.
HOW ACTIVATION WORKS
Buying here registers the license to your account: the buttons above open checkout (signing you in first if you aren't), and the new license appears in your account the moment payment clears. Activate an install by signing in from the NewScan app, or copy the license token from your account and paste it in.
You can also start from inside the NewScan app: hit Upgrade to Pro →, complete checkout in your browser, and the app polls for the signed license and installs it on its own — nothing ever connects back to your machine. Either way the license is registered to your email and bound to one install — one Pro activation per install.
QUESTIONS?
Volume, multi-seat, or invoicing needs? That's a conversation, not a sales call.
Talk to us →All prices in USD. The free, self-hosted NewScan scanner can be installed and run on as many machines as you like — local in-band scanning never requires a license. NewScan Pro is the only licensed part: it is individually licensed per install (one activation per NewScan instance). Pro includes the out-of-band collaborator either way — use the listener we operate, or run your own if callbacks must not leave your infrastructure (air-gapped, sovereign cloud, data residency). Ask us about a self-hosted collaborator and we will help you stand it up.
Verify the findings other scanners can't see.
Keep your scans local and free. Add NewScan Pro only when you need the out-of-band callback — and confirm blind SSRF, OOB SQLi, blind XSS, XXE, jku, and DNS-exfil end to end.