// OPTIONAL UPGRADE · OUT-OF-BAND DETECTION · NEWSCAN PRO

NewScan Pro — catch the bugs that only prove themselves out-of-band.

A whole class of vulnerabilities — blind and reflection-based — never appear in any response your scanner can see. Confirming them means making the target reach back out to a listener you control and watching for the callback. NewScan Pro is the hosted listener NewNormal Security runs for you, so NewScan can trigger and verify those findings end to end.

Everything NewScan verifies in-band stays fully local and free. Pro is strictly opt-in: only the out-of-band callback interactions touch the hosted listener — your target traffic, findings, and AI keys still never leave your machine.

What NewScan Pro adds

// out-of-band classes the listener unlocks

// WHEN A FINDING NEEDS A TARGET TO POINT BACK AT

One hosted endpoint. Every blind vulnerability class, verified.

NewScan Pro provides the HTTP(S) and DNS endpoint the target calls back to. NewScan plants a unique canary in its payloads, the hosted listener records any callback, and the scanner correlates it to the exact request that triggered it — recording a verified, reproduced finding, never a guess.

The listener is the one capability that needs a Pro license and an account. The scanner itself never does — and every out-of-band check keeps an in-band arm, so a scan without Pro still reports the vulnerability class and loses only the blind confirmation.

// OUT-OF-BAND DETECTIONS PRO UNLOCKS

Detection How the callback confirms it
Blind SSRFThe target fetches the canary over HTTP or DNS — proof the server made the request. Separate arms prove an allow-list bypass too (redirect-follow, DNS rebinding, credential and encoding tricks), each with the remediation for how it got through.
SSRF where scanners don’t lookGraphQL arguments found by introspection, image/URL proxies that carry the origin in the path (/unsafe/http://… — Thumbor, imgproxy, /_next/image), and webhook/upstream fetches (OWASP API10). Same canary, surfaces a parameter sweep never reaches.
OAuth / OIDC URI SSRFThe URI params an authorization server is supposed to dereference — request_uri, jwks_uri, sector_identifier_uri, logo_uri — pointed at the listener. A callback proves the server fetches attacker URLs pre-auth.
Prompt-injection SSRF (LLM & MCP)A canary URL planted in the prompt instructs the model’s browsing/fetch tool to retrieve it; the callback proves the injection actually drove a server-side request. Same arm confirms a poisoned MCP tool reaching out.
Blind XSSA stored payload fires later — when an admin views it — and loads its script from the listener. Nothing in the response you got ever showed it.
OOB XXEAn external entity resolves against the listener — in a JSON/XML API, a SOAP operation, or an uploaded SVG — confirming the parser is vulnerable when no file content reflects.
Insecure deserialization → RCEA language gadget (Python pickle, Java URLDNS — JDK-only, no extra library needed) makes the target call out as it deserializes — proving execution before any response is rendered.
CVE RCE callbacksLog4Shell (CVE-2021-44228), Text4Shell (CVE-2022-42889), Fastjson autotype and Langflow’s unauthenticated /api/v1/validate/code — a lookup reaching the listener proves the version present actually executes, instead of guessing from a version string.
JWT jku / x5uA forged token points at a JWKS on the listener; the fetch proves the verifier trusts attacker-supplied keys — token forgery and SSRF at once.
Reset poisoning & email header injectionThe app’s own mail lands in the hosted SMTP sink — proving it sent mail out, and revealing a host-header-poisoned reset link (account takeover) or an attacker-injected recipient.
Remote include & XSLT fetchAn include/template parameter (RFI) or an XSLT document() pulls the listener’s URL server-side — the recorded pull is the confirmation when nothing renders.
Open DNS resolver & SMTP relayNetwork mode: a recursive query for a canary host, and one external→external test message. A DNS callback or a delivery into the sink is the only way to prove the abuse actually works from outside.

These are the highest-impact ones — the hosted listener arms every out-of-band check in NewScan, and new ones land with the daily detection releases. Each callback is correlated to the request that triggered it and recorded as a verified, reproduced finding.

The listener answers DNS under its domain and serves a valid jwks.json, so multi-step callbacks (DNS → HTTP, jku fetch) complete and correlate to one session.

// ALSO IN PRO

Shipped

Daily detection signature updates ✓

new detections every day, delivered over the air as signed signature packs — a Pro install picks them up at startup, no new image

Jira integration ✓

push findings straight to Jira tickets — re-filing updates instead of duplicating

GitHub Issues integration ✓

open GitHub Issues from findings; connect the repo on your account page

Security-framework reports ✓

reports scoped to PCI DSS, SOC 2, ISO 27001, HITRUST, HIPAA & NIST 800-53

How it works

// opt-in, correlated, privacy-preserving

01

Open a session

Your licensed scanner opens a session and gets a unique canary host: <token>.<session>.<domain>. Payloads carry that host so any callback is yours alone.

02

Target calls back

A vulnerable target reaches the hosted HTTP or DNS endpoint. The interaction is recorded and matched to your session by the canary subdomain — no shared state to untangle.

03

Verify & record

NewScan polls the interactions back, ties the callback to the request that caused it, and records a confirmed finding — real, with evidence attached.

PRIVACY BY DESIGN

Only the out-of-band callbacks ever touch the hosted listener. Your scan traffic, findings, credentials, and AI keys stay on your machine — the hosted listener receives a callback, not your data.

NEVER A DEAD END

Local in-band detection is free, forever — and every out-of-band check keeps an in-band arm, so a scan without Pro still reports the vulnerability class. What you lose is the blind confirmation: a finding that can only be proved by a callback is reported honestly as unconfirmed, never guessed at and never silently dropped.

Pricing

// NewScan Pro, hosted & maintained by NewNormal Security

1 MONTH

$495

NewScan Pro, billed month to month. Cancel anytime — ideal for a single engagement or a short assessment window.

  • Hosted HTTP(S) + DNS OOB listener
  • Every out-of-band detection class, including new ones as they ship
  • Individually licensed — one Pro activation per install
  • Upgrade to annual anytime — pay only the difference

ANNUAL

BEST VALUE
$1,985 / year

A full year of hosted out-of-band detection at the lowest effective rate. For testers and teams who run engagements all year.

  • Everything in monthly
  • 12 months for the price of ~4
  • Individually licensed — one Pro activation per install
  • Priority support on the hosted listener

1 MONTH → YEAR UPGRADE

$1,690

Already on Pro monthly and want the year? Convert your active month straight into a full annual term — no re-activation.

  • One-time payment — not a new subscription
  • Converts to a 12-month annual term
  • Same license & install — no re-activation

// ENTERPRISE SALES

Bigger rollout? Let's do a deal.

Multi-seat, organization-wide, or procurement that needs a PO and invoice? Enterprise gets custom pricing and invoicing that bypasses the standard plans above — sized to your deployment, billed how your finance team needs it. Tell us what you're after and we'll come back with terms.

Contact Enterprise sales →

HOW ACTIVATION WORKS

Buying here registers the license to your account: the buttons above open checkout (signing you in first if you aren't), and the new license appears in your account the moment payment clears. Activate an install by signing in from the NewScan app, or copy the license token from your account and paste it in.

You can also start from inside the NewScan app: hit Upgrade to Pro →, complete checkout in your browser, and the app polls for the signed license and installs it on its own — nothing ever connects back to your machine. Either way the license is registered to your email and bound to one install — one Pro activation per install.

QUESTIONS?

Volume, multi-seat, or invoicing needs? That's a conversation, not a sales call.

Talk to us →

All prices in USD. The free, self-hosted NewScan scanner can be installed and run on as many machines as you like — local in-band scanning never requires a license. NewScan Pro is the only licensed part: it is individually licensed per install (one activation per NewScan instance). Pro includes the out-of-band collaborator either way — use the listener we operate, or run your own if callbacks must not leave your infrastructure (air-gapped, sovereign cloud, data residency). Ask us about a self-hosted collaborator and we will help you stand it up.

Verify the findings other scanners can't see.

Keep your scans local and free. Add NewScan Pro only when you need the out-of-band callback — and confirm blind SSRF, OOB SQLi, blind XSS, XXE, jku, and DNS-exfil end to end.