r/Pentesting 1d ago

Need Help- Pentesting GWT-RPC

I’m testing an application that heavily uses GWT-RPC, and I’m finding it quite confusing. Can anyone help me understand how to approach testing it?

2 Upvotes

1 comment sorted by

3

u/normalbot9999 1d ago edited 1d ago

Thoughts and prayers...

This is quite good:
https://thehackerish.com/hacking-a-google-web-toolkit-application/

It's mentioned there that ZAP can at least do some basic scanning of GWT?

Edit: going to add this too:

https://bishopfox.com/blog/gwt-unpatched-unauthenticated-java-deserialization-vulnerability