Full WSTG-aligned web application pentest — 12-phase methodology from information gathering through reporting, with concrete commands, expected outputs, pitfalls, and verification per phase.
Idioma del texto original: inglés
Menú
SkillsMP ha recopilado 145 skills de uphiago/recon-skills. Abre una skill para revisar su origen y sus detalles.
Mostrando 40 de 145 skills recopiladas.
Full WSTG-aligned web application pentest — 12-phase methodology from information gathering through reporting, with concrete commands, expected outputs, pitfalls, and verification per phase.
Idioma del texto original: inglés
Attack SAML SSO via XSW, signature strip, metadata extract.
Idioma del texto original: inglés
Use when two or more verified findings may combine into a higher-impact authorized attack path.
Idioma del texto original: inglés
Use when verified WordPress findings may combine into an authorized path to administrative or server control.
Idioma del texto original: inglés
Escape Docker containers to host root via 5 techniques.
Idioma del texto original: inglés
Use when classifying a verified web or WordPress behavior and selecting a related validation skill.
Idioma del texto original: inglés
Compare recon waves to find NEW, REGRESSED, PERSISTENT findings.
Idioma del texto original: inglés
Use when starting or restructuring an authorized external web and API assessment.
Idioma del texto original: inglés
Use when an API may expose data or privileged operations without authentication.
Idioma del texto original: inglés
Deep pentest WP: SSRF, plugin CVE, JS mine, port scan chain.
Idioma del texto original: inglés
Mine error_log for creds, paths, SQL when leak hunt finds.
Idioma del texto original: inglés
Exchange/OWA NTLM AD leak, spray attack when mail subdomain.
Idioma del texto original: inglés
Exploit Firebase/Supabase for data via JS config leak probe.
Idioma del texto original: inglés
Exploit Flask/Werkzeug debugger exposure for traceback and SECRET leaks.
Idioma del texto original: inglés
Mine GitLab for secrets, CI tokens when subdomain found.
Idioma del texto original: inglés
Attack cameras via RTSP, ONVIF, Axis config when 554 open.
Idioma del texto original: inglés
Analyze JS bundles and source maps for hardcoded secrets, API keys, JWTs, and internal endpoints
Idioma del texto original: inglés
Decode, forge, brute JWTs when Bearer auth header is seen.
Idioma del texto original: inglés
Chain phpinfo to RCE via exec check when info.php exposed.
Idioma del texto original: inglés
Port scan /8-/24 with Masscan+RustScan and nmap banners.
Idioma del texto original: inglés
Nmap scan for MySQL, Redis, FTP, SSH, internal API services.
Idioma del texto original: inglés
Hunt staging via crt.sh when production is WAF-hardened.
Idioma del texto original: inglés
Sensitive file scanning, path traversal bypass, vHost enum, .env extract, log mining, Varnish detect
Idioma del texto original: inglés
Hunt WP plugins via REST, exploit CVEs when version known.
Idioma del texto original: inglés
Batch WP recon: users, CORS, XMLRPC, leaks across domains.
Idioma del texto original: inglés
Scan WordPress REST API plugin endpoints for unauthenticated state-changing operations — discover write endpoints (POST/PUT/PATCH/DELETE) exposed without auth, enumerate all plugin routes, and test for unauthorized content publishing, settings modification,…
Idioma del texto original: inglés
Exploit XMLRPC multicall, pingback for brute force and SSRF.
Idioma del texto original: inglés
Zimbra SOAP user enum, CVE-2022-37042, SSRF when webmail.
Idioma del texto original: inglés
Use when a bounded list of authorized API endpoints needs consistent CORS triage before browser validation.
Idioma del texto original: inglés
Evidence-capture and PoC-redaction discipline for bug-bounty submissions: cookie redaction protocol (which fields to mask, Preview annotation / Burp panel hiding / DevTools workflow), PII black-bar discipline (what to mask in other-user data — names, emails,…
Idioma del texto original: inglés
Hunt CORS Misconfiguration — origin-reflection with credentials, null-origin trust, subdomain-regex bypass (unanchored vs unescaped-dot vs prefix-only), pre-flight (OPTIONS) gating bypass, postMessage origin checks. High only when an attacker-controlled…
Idioma del texto original: inglés
Use when an authorized target exposes WordPress core, plugin, theme, REST, or XML-RPC behavior.
Idioma del texto original: inglés
Use when testing an authorized LLM application for prompt injection, system-prompt exposure, unsafe tool use, or RAG data-boundary failures.
Idioma del texto original: inglés
Multi-sector batch domain expansion — identify untested/under-tested sectors, generate candidate company domains (national chains, franchises, regionals), filter against existing test coverage, probe alive domains, and run the full testing pipeline across 20+…
Idioma del texto original: inglés
Parameterized sector recon using sector database.
Idioma del texto original: inglés
Bug bounty report writing for H1/Bugcrowd/Intigriti/Immunefi — report templates, human tone guidelines, impact-first writing, CVSS 3.1 scoring, title formula, impact statement formula, severity decision guide, downgrade counters, pre-submit checklist. Use…
Idioma del texto original: inglés
Web2 recon pipeline — subdomain enumeration (subfinder, Chaos API, assetfinder), live host discovery (dnsx, httpx), URL crawling (katana, waybackurls, gau), directory fuzzing (ffuf), JS analysis (LinkFinder, SecretFinder), continuous monitoring (new subdomain…
Idioma del texto original: inglés
Use when verified WordPress CORS, XML-RPC, role, upload, and execution behaviors may form one authorized attack path.
Idioma del texto original: inglés
Systematic approach to finding and testing CVEs for identified WordPress plugins. Covers plugin discovery, version extraction from multiple sources (readme.txt, assets, inline JS), CVE database cross-referencing with WPScan/Patchstack/NVD/NVD API,…
Idioma del texto original: inglés
Hunt LLM/AI feature bugs — prompt injection, indirect injection, exfiltration viatool-use/markdown, ASCII smuggling, agentic AI security (OWASP Agentic Apps 2026, ASI01-ASI10). Patterns: direct injection ('ignore previous instructions'), indirect injection…
Idioma del texto original: inglés