Skip to main content
Ejecuta cualquier Skill en Manus
con un clic
withcrux
Perfil de creador de GitHub

withcrux

Vista por repositorio de 20 skills recopiladas en 1 repositorios de GitHub.

skills recopiladas
20
repositorios
1
actualizado
2026-04-05
mapa de repositorios

Dónde viven las skills

Repositorios principales por número de skills recopiladas, con su participación en este catálogo del creador y su variedad ocupacional.

explorador de repositorios

Repositorios y skills representativas

analyzing-cron-job-privesc-vectors
Analistas de seguridad de la información

Identify and exploit Linux cron job misconfigurations to escalate privileges from a low-privilege user to root. Covers writable cron scripts, world-writable PATH entries, wildcard injection, and cron-based reverse shells in isolated lab environments.

2026-04-05
exploiting-command-injection-vulnerabilities
Analistas de seguridad de la información

Identify and exploit OS command injection vulnerabilities in web applications where user-supplied input is passed unsanitized to a shell command. Covers in-band, blind, and out-of-band command injection techniques against deliberately vulnerable targets in isolated lab environments.

2026-04-05
performing-arp-spoofing-in-lab
Analistas de seguridad de la información

Perform ARP spoofing and man-in-the-middle (MITM) attacks within isolated LAN environments using arpspoof and ettercap to intercept traffic between two hosts. Covers ARP cache poisoning, traffic forwarding, and credential sniffing in a controlled Docker lab network.

2026-04-05
performing-dns-zone-transfer-attacks
Analistas de seguridad de la información

Enumerate DNS infrastructure by requesting full zone transfers (AXFR) from misconfigured authoritative DNS servers using dig, nslookup, and fierce. Covers zone transfer mechanics, subdomain harvesting, and identifying exposed internal hostnames in isolated lab environments.

2026-04-05
performing-smb-enumeration-in-lab
Analistas de seguridad de la información

Enumerate SMB shares, users, and sessions on Windows and Linux targets using smbclient and enum4linux within isolated lab environments. Covers null session attacks, share listing, file retrieval, and user enumeration against misconfigured Samba and Windows SMB services.

2026-04-05
analyzing-jwt-token-security
Analistas de seguridad de la información

Analyze JSON Web Tokens (JWTs) for common security vulnerabilities including algorithm confusion attacks (RS256 to HS256), none algorithm bypass, weak secret brute-forcing, and claim manipulation. Practice in isolated lab environments to understand authentication bypass and privilege escalation via token forgery.

2026-04-05
analyzing-network-packet-captures
Analistas de seguridad de la información

Analyze PCAP files and live network captures using Wireshark and tshark to extract credentials, reconstruct HTTP sessions, identify malicious traffic patterns, and detect protocol anomalies in isolated lab environments. Core network forensics and traffic analysis skill for security professionals.

2026-04-05
analyzing-sudo-rules-for-privesc-vectors
Analistas de seguridad de la información

Enumerate and exploit sudo misconfigurations on Linux systems to escalate privileges. Covers NOPASSWD entries, wildcard abuse, sudo -l enumeration, LD_PRELOAD injection, and GTFOBins lookup for allowed commands in isolated lab environments. Core skill for Linux privilege escalation phases.

2026-04-05
Mostrando las 8 principales de 20 skills recopiladas en este repositorio.
Mostrando 1 de 1 repositorios
Todos los repositorios cargados