Skip to main content

auth-bypass

Hunt authentication/authorization bypass in route guards, role checks, tenant boundaries, and state-machine transitions.

الانتقال إلى التثبيت

معلومات المصدر

المستودع
BitterSecurity/Decepticon
آخر نشاط في المصدر
٢ يونيو ٢٠٢٦ في ١٧:٤٢
لغة SKILL.md المكتشفة
الإنجليزية
النجوم
٥٬٥٦٥
التفرعات
١٬٠٥٣

خيارات التثبيت

يُحدَّد Prompt الذي يراجع المصدر أولًا بشكل افتراضي. يمكنك التبديل إلى أمر مباشر أو تنزيل نسخة محلية.

مراجعة ملفات المصدر

اقرأ SKILL.md وأي ملفات مرافقة يعرضها SkillsMP قبل أن تقرر التثبيت.

عرض SKILL.md

SKILL.md
تعليمات المصدر · معاينة للقراءة فقط
name
auth-bypass
description
Hunt authentication/authorization bypass in route guards, role checks, tenant boundaries, and state-machine transitions.
metadata
{"subdomain":"web-exploitation","when_to_use":"authentication authorization bypass route guard role check tenant boundary state machine transition session jwt"}
# Auth Bypass Playbook ## Targets - Endpoints with role-based access - Admin-only routes - Tenant-scoped resources - Multi-step auth flows (MFA, password reset) ## Common failure patterns - Missing middleware on one route variant - Trusting client-controlled role/tenant fields - TOCTOU between check and action - Alternate API versions lacking guard checks ## Validation - Positive: low-priv session performs high-priv action. - Negative: same request with expected guard path should deny.
عرض على GitHub