Skip to main content
ankitsingh015
ملف منشئ GitHub

ankitsingh015

عرض على مستوى المستودعات لـ ٤٧ skills مجمعة عبر ١ مستودعات GitHub.

skills مجمعة
٤٧
مستودعات
١
محدث
٢٦ أغسطس ٢٠٢٦
خريطة المستودعات

أين توجد skills

أهم المستودعات حسب عدد skills المجمعة، مع حصتها من كتالوج هذا المنشئ وانتشارها المهني.

مستكشف المستودعات

المستودعات و skills الممثلة

access-control-and-idor
غير مصنف

Access-control technique list (IDOR, mass assignment, horizontal/vertical privilege escalation, GraphQL abuse, business-logic/money manipulation, race conditions) plus the explicit two-account IDOR testing procedure. Converted from master-pentest-prompt.md…

٢٦ أغسطس ٢٠٢٦
csrf-cors-origin
غير مصنف

CSRF token-bypass techniques, CORS misconfiguration patterns, postMessage origin issues, clickjacking, and WebSocket cross-origin hijacking. Converted from master-pentest-prompt.md Phase 10. Use on any state-changing request, any endpoint with CORS headers,…

٢٦ أغسطس ٢٠٢٦
injection-and-rce
غير مصنف

Full injection-class technique list (SQLi, command injection, LDAP/XPath/XSLT/EL, SSTI, CRLF, HPP, prototype pollution) and remote-code-execution technique list (deserialization, file-upload webshells, LFI/RFI, framework-specific RCE, dependency CVEs), plus…

٢٦ أغسطس ٢٠٢٦
ssrf
غير مصنف

SSRF technique list covering IP-bypass encodings, cloud metadata endpoints (AWS/GCP/Azure/Alibaba/DigitalOcean), protocol smuggling, and common SSRF injection points (URL fetchers, image proxies, PDF generators, webhooks). Converted from…

٢٦ أغسطس ٢٠٢٦
xss
غير مصنف

XSS technique list covering reflected/stored/DOM/blind/mutation XSS, injection contexts, CSP bypass classes, postMessage leakage, and storage-based XSS via uploaded file formats. Converted from master-pentest-prompt.md Phase 9. Use when a parameter reflects…

٢٦ أغسطس ٢٠٢٦
curl-decision-tree-and-persistence
غير مصنف

A diagnostic decision tree for common curl/HTTP errors (connection failures, TLS, 400/401/403/429/500), a URL-parameter-to-test-priority lookup table, and persistence rules for how long to keep pushing on a target before moving on. Converted from…

٢٥ أغسطس ٢٠٢٦
engagement-setup
غير مصنف

How to start a HuntMCP engagement -- assessment mode selection, /goal focus mode, target fingerprinting, and the ROI-based testing order. Converted from master-pentest-prompt.md Phases 0.1/0.2/0.5/0.9. Use at the very start of an engagement, before any live…

٢٥ أغسطس ٢٠٢٦
low-hanging-fruit
غير مصنف

The never-skip checklist of cheap, high-yield checks -- default credentials, installer leftovers, HTTP verb tampering, TRACE/XST, MIME-sniffing XSS, integer/type-confusion bypasses, unicode normalization tricks, cache deception/poisoning, and rate-limit gaps…

٢٥ أغسطس ٢٠٢٦
عرض 8 من أصل ٤٧ skills مجمعة.
عرض ١ من أصل ١ مستودعات
تم تحميل كل المستودعات