Skip to main content

mitm-find-checksum

Find checksum and signature vulnerabilities. Use when user asks about hash validation, signature bypass, checksum manipulation, or cryptographic weaknesses.

الانتقال إلى التثبيت

معلومات المصدر

المستودع
instavm/security-skills
آخر نشاط في المصدر
٢٣ مارس ٢٠٢٦ في ٠٥:٢٤
لغة SKILL.md المكتشفة
الإنجليزية
النجوم
٨٦
التفرعات
١١

خيارات التثبيت

يُحدَّد Prompt الذي يراجع المصدر أولًا بشكل افتراضي. يمكنك التبديل إلى أمر مباشر أو تنزيل نسخة محلية.

مراجعة ملفات المصدر

اقرأ SKILL.md وأي ملفات مرافقة يعرضها SkillsMP قبل أن تقرر التثبيت.

عرض SKILL.md

SKILL.md
تعليمات المصدر · معاينة للقراءة فقط
name
mitm-find-checksum
description
Find checksum and signature vulnerabilities. Use when user asks about hash validation, signature bypass, checksum manipulation, or cryptographic weaknesses.
# Find Checksum/Signature Vulnerabilities Analyze the mitmproxy dump (log.txt) for checksum issues for: $ARGUMENTS > **Requires**: `log.txt` in the current directory. If it's missing, capture traffic first: > ```bash > mitmdump --set flow_detail=3 2>&1 | tee log.txt > ``` ## Vulnerability Types ### 1. Checksum Generation Exposed - API returns hash even on error - Can generate arbitrary checksums - Checksum endpoint accessible without auth ### 2. Weak Algorithms - MD5 without salt - SHA1 (deprecated) - Simple concatenation ### 3. Signature Collision - Same signature for different operations - Payment and refund use same algorithm - Parameter reordering gives same hash ### 4. Missing Fields in Checksum - Amount not in checksum calculation - Status not included - Critical fields missing ### 5. Checksum Not Validated - Hash parameter present but ignored - Backend accepts any hash value - Validation only on specific endpoints ## Patterns to Find ``` # Look for hash/checksum parameters hash=, checksum=, signature=, sign=, hmac= # Look for checksum generation APIs /generateHash, /getChecksum, /createSignature # Error responses with valid checksums "error": "...", "checksum": "valid_hash" ``` ## Testing Approach ```bash # Test if checksum is validated curl -X POST "https://target.com/callback" \ -d "amount=100&status=success&hash=invalid" # Test checksum generation curl "https://target.com/api/generateChecksum" \ -d "amount=1&status=success" ``` ## Output Format For each finding: - **Endpoint**: Where checksum is used - **Issue**: Type of vulnerability - **Algorithm**: If identifiable - **Fields Included**: What's in the hash - **Exploit**: How to bypass/generate - **Impact**: Payment fraud, data tampering - **Fix**: Strong HMAC, include all fields
عرض على GitHub