Yasuo Logo

Yasuo

0
Free
Visit Website

Yasuo is a ruby script that scans for vulnerable 3rd-party web applications. While working on a network security assessment (internal, external, redteam gigs etc.), we often come across vulnerable 3rd-party web applications or web front-ends that allow us to compromise the remote server by exploiting publicly known vulnerabilities. Some of the common & favorite applications are Apache Tomcat administrative interface, JBoss jmx-console, Hudson Jenkins and so on. If you search through Exploit-db, there are over 10,000 remotely exploitable vulnerabilities that exist in tons of web applications/front-ends and could allow an attacker to completely compromise the back-end server. These vulnerabilities range from RCE to malicious file uploads to SQL injection to RFI/LFI etc. Yasuo is built to quickly scan the network for such vulnerable applications thus serving pwnable targets on a silver platter.

FEATURES

ALTERNATIVES

Automates SQL injection detection and exploitation

A virtual machine with numerous security vulnerabilities for testing exploits with Metasploit.

A tool that detects dangling DNS records in a multi-cloud environment to prevent subdomain takeovers.

Audits JavaScript projects for known vulnerabilities and outdated package versions using OSS Index v3 REST API.

Automate your reconnaissance process with AttackSurfaceMapper, a tool for mapping and analyzing network attack surfaces.

A presentation about the OWASP Top 10, a list of the most critical security risks to web applications.

A vulnerability and exposure management platform that unifies security tool data, automates workflows, and provides risk-based prioritization for enterprise vulnerability management programs.

Finds publicly known security vulnerabilities in a website's frontend JavaScript libraries.