Yasuo Logo

Yasuo

0
Free
Visit Website

Yasuo is a ruby script that scans for vulnerable 3rd-party web applications. While working on a network security assessment (internal, external, redteam gigs etc.), we often come across vulnerable 3rd-party web applications or web front-ends that allow us to compromise the remote server by exploiting publicly known vulnerabilities. Some of the common & favorite applications are Apache Tomcat administrative interface, JBoss jmx-console, Hudson Jenkins and so on. If you search through Exploit-db, there are over 10,000 remotely exploitable vulnerabilities that exist in tons of web applications/front-ends and could allow an attacker to completely compromise the back-end server. These vulnerabilities range from RCE to malicious file uploads to SQL injection to RFI/LFI etc. Yasuo is built to quickly scan the network for such vulnerable applications thus serving pwnable targets on a silver platter.

FEATURES

ALTERNATIVES

OCaml bindings to the YARA scanning engine for integrating YARA scanning capabilities into OCaml projects

An Open Source supply chain security and auditing tool that tracks projects and dependencies, monitoring for vulnerabilities and issues.

A tool that showcases the attack surface of a given Android device, highlighting potential vulnerabilities and security risks.

Automates SQL injection detection and exploitation

A tool for validating and repairing Yara rules

A JavaScript scanner built in PHP for scraping URLs and other information.

A free and open-source deliberately insecure web application for security enthusiasts, developers, and students to discover and prevent web vulnerabilities.

Web-application vulnerability scanner with extensive coverage of security testing modules.

PINNED