Skip to main content

このリポジトリの skills

abelrguezr/hacktricks-skills - 16ページ

SkillsMP は abelrguezr/hacktricks-skills から 908 件の skill を収集しています。skill を開くとソースと詳細を確認できます。

abelrguezr/hacktricks-skills

収集済み skill 908 件中 40 件を表示しています。

職業分類
情報セキュリティアナリスト
説明

Use this skill when pentesting Rocket.Chat installations and you have admin access. This skill helps you exploit the webhook JavaScript execution feature to achieve Remote Code Execution (RCE). Trigger this skill when the user mentions Rocket.Chat, Rocket…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Exploit Roundcube webmail vulnerabilities and recover credentials. Use this skill whenever you need to test Roundcube installations, exploit CVE-2025-49113 authenticated RCE, decrypt Roundcube session data, or recover IMAP passwords from compromised Roundcube…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Ruby on Rails and Ruby application security testing. Use this skill whenever you're pentesting Ruby applications, Rails apps, or need to check for Ruby-specific vulnerabilities like file upload RCE, Active Storage exploits, Rack middleware issues, ReDoS…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Security testing skill for Sitecore Experience Platform (XP) vulnerabilities including pre-auth HTML cache poisoning and post-auth RCE via BinaryFormatter deserialization. Use this skill whenever the user mentions Sitecore XP, Sitecore security testing, cache…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

How to test and exploit HTTP header vulnerabilities during web security assessments. Use this skill whenever you need to test HTTP headers for security issues, including header injection, cache poisoning, request smuggling, header bypass techniques, or…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Spring Boot Actuator exploitation for penetration testing. Use this skill whenever you need to assess Spring Boot applications for actuator misconfigurations, extract secrets from heapdumps, abuse logging endpoints for credential capture, or test for RCE via…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Pentest Symfony applications - fingerprint versions, test for known CVEs (CVE-2019-18889, CVE-2025-64500, CVE-2024-51736, CVE-2025-47946, CVE-2026-24739), exploit APP_SECRET disclosure via _fragment, test PATH_INFO bypass, check for exposed .env files, debug…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Exploit CVE-2025-3600 in Telerik UI for ASP.NET AJAX (versions 2011.2.712 through 2025.1.218) for pre-auth DoS and RCE via unsafe reflection in WebResource.axd. Use this skill whenever you need to test for Telerik vulnerabilities, assess .NET web applications…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Perform Apache Tomcat security assessments including enumeration, vulnerability scanning, and exploitation. Use this skill whenever the user mentions Tomcat, Apache Tomcat, port 8080, web application manager, WAR file upload, or needs to assess a Java web…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

How to uncover and bypass Cloudflare protection to find origin server IPs or scrape protected websites. Use this skill whenever the user mentions Cloudflare bypass, origin IP discovery, WAF bypass, scraping protected sites, or needs to find real server IPs…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Security audit and hardening guidance for VMware ESX/vCenter infrastructure. Use this skill when users need to assess VMware virtualization security, understand attack vectors for defensive purposes, enumerate ESXi hosts for authorized penetration testing,…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Security audit and vulnerability assessment for Vue.js applications. Use this skill whenever the user mentions Vue.js security, XSS vulnerabilities, Vue application hardening, frontend security review, or needs to identify security issues in Vue code. Trigger…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

How to perform comprehensive security testing on web APIs including REST, SOAP, GraphQL, and tRPC endpoints. Use this skill whenever the user needs to audit API security, test for authorization flaws, discover hidden endpoints, or assess API vulnerabilities.…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Exploit Werkzeug/Flask debug console vulnerabilities for RCE. Use this skill whenever you encounter a Flask/Werkzeug application with debug mode enabled, need to bypass the console PIN protection, or want to exploit the Unicode request smuggling…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Perform comprehensive WordPress security assessments including enumeration, vulnerability testing, and exploitation. Use this skill whenever the user needs to assess WordPress security, test for common WordPress vulnerabilities, enumerate WordPress sites,…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Use this skill for WSGI/uWSGI post-exploitation attacks including magic variable exploitation, SSRF-to-uWSGI pivots via gopher protocol, and backdoor deployment. Trigger when the user mentions WSGI, uWSGI, uwsgi protocol, magic variables, UWSGI_FILE, SSRF to…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Zabbix security assessment and exploitation. Use this skill whenever the user mentions Zabbix monitoring, CVE-2024-22120, Zabbix SQLi, Zabbix cookie forgery, Zabbix RCE, or any Zabbix-related security testing. Trigger for Zabbix web UI assessment, port…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Security testing skill for auditing 2FA/MFA/OTP implementations. Use this skill whenever you need to test two-factor authentication security, audit MFA implementations, check for OTP bypass vulnerabilities, or perform authorized penetration testing on…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Use this skill whenever testing web applications for HTTP header vulnerabilities, proxy misconfigurations, or when investigating hop-by-hop header handling issues. Trigger this skill for any pentesting task involving HTTP headers, X-Forwarded-For…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

How to identify and test for account takeover vulnerabilities in web applications. Use this skill whenever the user mentions account takeover, authentication bypass, password reset attacks, email verification bypass, session hijacking, or any technique to…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Analyze browser extensions for clickjacking vulnerabilities. Use this skill whenever you need to audit browser extensions (Chrome, Firefox, Edge) for security issues, review manifest.json files, test web_accessible_resources configurations, or investigate…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Audit browser extension permissions and host_permissions for security vulnerabilities. Use this skill whenever analyzing Chrome/Firefox extensions, reviewing manifest.json files, investigating extension security, or pentesting browser extensions. Trigger on…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

How to test browser extensions for XSS vulnerabilities including iframe-based XSS, DOM-based XSS, and clickjacking attacks. Use this skill whenever the user mentions browser extension security testing, Chrome extension vulnerabilities, XSS in extensions,…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Security testing methodology for browser extensions (Chrome, Firefox, Chromium). Use this skill whenever you need to audit, analyze, or pentest a browser extension for vulnerabilities. Trigger this skill for extension security reviews, manifest.json analysis,…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Force-load arbitrary browser extensions in Chromium-based browsers (Chrome, Edge, Brave) on Windows by forging valid HMACs in Preferences/Secure Preferences files. Use this skill whenever you need to persist a browser extension silently, bypass extension…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

How to assess payment process security during authorized penetration testing. Use this skill whenever the user mentions payment security testing, transaction flow analysis, payment gateway assessment, or needs to evaluate payment system vulnerabilities in an…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Web cache poisoning and cache deception testing for security assessments. Use this skill whenever the user mentions cache vulnerabilities, CDN security, web cache poisoning, cache deception, HTTP caching issues, or wants to test for cache-related…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

How to test for web cache poisoning vulnerabilities that can lead to denial of service. Use this skill whenever the user mentions cache servers, CDNs, DoS attacks, web server vulnerabilities, HTTP headers, Cloudflare, or any scenario where they want to test…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

How to perform cache poisoning attacks by exploiting URL parsing discrepancies between cache proxies and web servers. Use this skill whenever the user mentions cache poisoning, CDN vulnerabilities, URL parsing issues, proxy discrepancies, or wants to test for…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Techniques for bypassing captchas during authorized security testing and penetration testing. Use this skill whenever you're testing web applications and encounter captcha challenges that need to be automated or bypassed for testing purposes. This includes…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

How to test for clickjacking vulnerabilities in web applications. Use this skill whenever the user mentions clickjacking, UI redressing, iframe attacks, frame-busting, X-Frame-Options, CSP frame-ancestors, or wants to test if a web page can be embedded in…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

How to find and exploit Client Side Path Traversal (CSPT) vulnerabilities in web applications. Use this skill whenever the user mentions path traversal, URL manipulation, OSRF, on-site request forgery, frontend security testing, SPA vulnerabilities, or wants…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

How to detect and exploit Client Side Template Injection (CSTI) vulnerabilities in web applications. Use this skill whenever the user mentions template injection, AngularJS, VueJS, Mavo, or wants to test for client-side code execution vulnerabilities. Also…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

How to identify, test, and exploit command injection vulnerabilities in web applications. Use this skill whenever the user mentions command injection, OS command injection, RCE through user input, shell metacharacters, or wants to test for arbitrary command…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Content Security Policy (CSP) bypass research and testing for security assessments. Use this skill when analyzing CSP configurations, testing bypass techniques for authorized security assessments, or researching CSP vulnerabilities. Trigger when users mention…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

How to bypass Content Security Policy (CSP) when configured with 'self' and 'unsafe-inline'. Use this skill whenever you're doing web security testing, penetration testing, or analyzing CSP configurations that include 'unsafe-inline'. Trigger this skill for…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Test for Cross-Origin Resource Sharing (CORS) misconfigurations and bypass vulnerabilities. Use this skill whenever you need to audit web applications for CORS security issues, test Origin header validation, check for credential leakage, or explore DNS…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

How to test for CRLF (Carriage Return Line Feed) injection vulnerabilities in web applications. Use this skill whenever you need to assess HTTP header injection, response splitting, or newline-based bypasses during web security testing. Trigger this skill…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Cross-Site Request Forgery (CSRF) vulnerability testing and exploitation. Use this skill whenever the user mentions CSRF, cross-site request forgery, form submission attacks, session hijacking, web security testing, or needs to test web applications for CSRF…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

How to exploit HTML injection vulnerabilities using dangling markup techniques to exfiltrate data, steal forms, bypass CSP, and manipulate page behavior without JavaScript execution. Use this skill whenever the user mentions HTML injection, scriptless…

原文の言語: 英語

更新
収集済み skill 908 件中 40 件を表示しています。