Skip to main content

anshumanbh/vulnvibes

SkillsMP は anshumanbh/vulnvibes から 10 件の skill を収集しています。skill を開くとソースと詳細を確認できます。

記録された最新のソース活動
SkillsMP カタログ更新
収集済み skills
10
GitHub スター
19
GitHub フォーク
6

このリポジトリの skills

1 件の職業カテゴリ · 100% 分類済み

収集済み skill 10 件中 10 件を表示しています。

職業分類
情報セキュリティアナリスト
説明

Investigate authentication vulnerabilities in source code including missing authentication, weak authentication, and session management issues. Use when threat model identifies CWE-287 (Improper Authentication), CWE-384 (Session Fixation), CWE-306 (Missing…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Investigate authorization vulnerabilities in source code including IDOR, privilege escalation, and missing access controls. Use when threat model identifies CWE-639 (IDOR), CWE-862 (Missing Authorization), CWE-863 (Incorrect Authorization), CWE-269 (Privilege…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Investigate browser security vulnerabilities including CORS misconfiguration, CSRF, clickjacking, and cookie security. Use when threat model identifies CWE-346 (Origin Validation), CWE-942 (Permissive CORS), CWE-352 (CSRF), CWE-1021 (Clickjacking), or browser…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Investigate cryptographic vulnerabilities in source code including weak algorithms, hardcoded secrets, and improper key management. Use when threat model identifies CWE-327 (Use of Broken Crypto), CWE-798 (Hardcoded Credentials), CWE-326 (Inadequate…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Investigate data exposure vulnerabilities in source code including PII leakage, sensitive data logging, and information disclosure. Use when threat model identifies CWE-200 (Information Exposure), CWE-532 (Sensitive Data in Logs), CWE-359 (Privacy Violation),…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Investigate insecure deserialization vulnerabilities that can lead to RCE or data manipulation. Use when threat model identifies CWE-502 (Deserialization of Untrusted Data), CWE-915 (Mass Assignment), or object deserialization concerns.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Investigate file operation vulnerabilities including unrestricted file upload, path traversal in file operations, and insecure file handling. Use when threat model identifies CWE-434 (Unrestricted Upload), CWE-73 (External Control of File Path), CWE-427…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Investigate injection vulnerabilities in source code including SQL injection, XSS, and command injection. Use when threat model identifies CWE-89 (SQL Injection), CWE-79 (XSS), CWE-78 (OS Command Injection), or injection concerns.

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Investigate security misconfiguration vulnerabilities including debug modes, default credentials, overly permissive settings, and insecure defaults. Use when threat model identifies CWE-16 (Configuration), CWE-1188 (Insecure Default Initialization), CWE-276…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Investigate Server-Side Request Forgery (SSRF) vulnerabilities where user input controls server-initiated requests. Use when threat model identifies CWE-918 (SSRF), CWE-441 (Unintended Proxy), or server-side request concerns.

原文の言語: 英語

更新
収集済み skill 10 件中 10 件を表示しています。