Giancarlo Pellegrino
gianko.bsky.social
Giancarlo Pellegrino
@gianko.bsky.social
Faculty at CISPA.
Want to see it first-hand?
Find the source code at github.com/pixelindigo/...
February 25, 2025 at 7:55 PM
YuraScanner can reach deep states of web applications that no scanner can. We tested on 20 web apps, manually validated its ability to discover and execute tasks, and discovered 12 zero-day XSS vulnerabilities.
February 25, 2025 at 7:55 PM
YuraScanner is one of the first task-driven web application scanners powered by LLM that can autonomously discover workflows and execute them. No user traces or input are needed!
February 25, 2025 at 7:55 PM
Don’t miss the YuraScanner presentation by Tim, today, session 2B “Web Security” at NDSS ‘25!

Our new scanner features LLM, XSS, and a pinch of 0-days. Read further to find out more!
February 25, 2025 at 7:55 PM
We are making the source code of YuraScanner public: github.com/pixelindigo/...

We initially restricted it to prevent misuse (fake accounts, scraping). We re-eval risk-benefits with live tests. Defenses (CAPTCHA, MFA, etc.) are sufficient, thus we pushed the code to GitHub.
February 13, 2025 at 10:54 AM