Skip to main content

이 저장소의 skills

abelrguezr/hacktricks-skills - 16페이지

SkillsMP는 abelrguezr/hacktricks-skills에서 908개의 skill을 수집했습니다. skill을 열어 소스와 세부 정보를 확인하세요.

abelrguezr/hacktricks-skills

수집된 skill 908개 중 40개를 표시합니다.

직업 분류
정보 보안 분석가
설명

Use this skill when pentesting Rocket.Chat installations and you have admin access. This skill helps you exploit the webhook JavaScript execution feature to achieve Remote Code Execution (RCE). Trigger this skill when the user mentions Rocket.Chat, Rocket…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Exploit Roundcube webmail vulnerabilities and recover credentials. Use this skill whenever you need to test Roundcube installations, exploit CVE-2025-49113 authenticated RCE, decrypt Roundcube session data, or recover IMAP passwords from compromised Roundcube…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Ruby on Rails and Ruby application security testing. Use this skill whenever you're pentesting Ruby applications, Rails apps, or need to check for Ruby-specific vulnerabilities like file upload RCE, Active Storage exploits, Rack middleware issues, ReDoS…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Security testing skill for Sitecore Experience Platform (XP) vulnerabilities including pre-auth HTML cache poisoning and post-auth RCE via BinaryFormatter deserialization. Use this skill whenever the user mentions Sitecore XP, Sitecore security testing, cache…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

How to test and exploit HTTP header vulnerabilities during web security assessments. Use this skill whenever you need to test HTTP headers for security issues, including header injection, cache poisoning, request smuggling, header bypass techniques, or…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Spring Boot Actuator exploitation for penetration testing. Use this skill whenever you need to assess Spring Boot applications for actuator misconfigurations, extract secrets from heapdumps, abuse logging endpoints for credential capture, or test for RCE via…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Pentest Symfony applications - fingerprint versions, test for known CVEs (CVE-2019-18889, CVE-2025-64500, CVE-2024-51736, CVE-2025-47946, CVE-2026-24739), exploit APP_SECRET disclosure via _fragment, test PATH_INFO bypass, check for exposed .env files, debug…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Exploit CVE-2025-3600 in Telerik UI for ASP.NET AJAX (versions 2011.2.712 through 2025.1.218) for pre-auth DoS and RCE via unsafe reflection in WebResource.axd. Use this skill whenever you need to test for Telerik vulnerabilities, assess .NET web applications…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Perform Apache Tomcat security assessments including enumeration, vulnerability scanning, and exploitation. Use this skill whenever the user mentions Tomcat, Apache Tomcat, port 8080, web application manager, WAR file upload, or needs to assess a Java web…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

How to uncover and bypass Cloudflare protection to find origin server IPs or scrape protected websites. Use this skill whenever the user mentions Cloudflare bypass, origin IP discovery, WAF bypass, scraping protected sites, or needs to find real server IPs…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Security audit and hardening guidance for VMware ESX/vCenter infrastructure. Use this skill when users need to assess VMware virtualization security, understand attack vectors for defensive purposes, enumerate ESXi hosts for authorized penetration testing,…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Security audit and vulnerability assessment for Vue.js applications. Use this skill whenever the user mentions Vue.js security, XSS vulnerabilities, Vue application hardening, frontend security review, or needs to identify security issues in Vue code. Trigger…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

How to perform comprehensive security testing on web APIs including REST, SOAP, GraphQL, and tRPC endpoints. Use this skill whenever the user needs to audit API security, test for authorization flaws, discover hidden endpoints, or assess API vulnerabilities.…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Exploit Werkzeug/Flask debug console vulnerabilities for RCE. Use this skill whenever you encounter a Flask/Werkzeug application with debug mode enabled, need to bypass the console PIN protection, or want to exploit the Unicode request smuggling…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Perform comprehensive WordPress security assessments including enumeration, vulnerability testing, and exploitation. Use this skill whenever the user needs to assess WordPress security, test for common WordPress vulnerabilities, enumerate WordPress sites,…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Use this skill for WSGI/uWSGI post-exploitation attacks including magic variable exploitation, SSRF-to-uWSGI pivots via gopher protocol, and backdoor deployment. Trigger when the user mentions WSGI, uWSGI, uwsgi protocol, magic variables, UWSGI_FILE, SSRF to…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Zabbix security assessment and exploitation. Use this skill whenever the user mentions Zabbix monitoring, CVE-2024-22120, Zabbix SQLi, Zabbix cookie forgery, Zabbix RCE, or any Zabbix-related security testing. Trigger for Zabbix web UI assessment, port…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Security testing skill for auditing 2FA/MFA/OTP implementations. Use this skill whenever you need to test two-factor authentication security, audit MFA implementations, check for OTP bypass vulnerabilities, or perform authorized penetration testing on…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Use this skill whenever testing web applications for HTTP header vulnerabilities, proxy misconfigurations, or when investigating hop-by-hop header handling issues. Trigger this skill for any pentesting task involving HTTP headers, X-Forwarded-For…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

How to identify and test for account takeover vulnerabilities in web applications. Use this skill whenever the user mentions account takeover, authentication bypass, password reset attacks, email verification bypass, session hijacking, or any technique to…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Analyze browser extensions for clickjacking vulnerabilities. Use this skill whenever you need to audit browser extensions (Chrome, Firefox, Edge) for security issues, review manifest.json files, test web_accessible_resources configurations, or investigate…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Audit browser extension permissions and host_permissions for security vulnerabilities. Use this skill whenever analyzing Chrome/Firefox extensions, reviewing manifest.json files, investigating extension security, or pentesting browser extensions. Trigger on…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

How to test browser extensions for XSS vulnerabilities including iframe-based XSS, DOM-based XSS, and clickjacking attacks. Use this skill whenever the user mentions browser extension security testing, Chrome extension vulnerabilities, XSS in extensions,…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Security testing methodology for browser extensions (Chrome, Firefox, Chromium). Use this skill whenever you need to audit, analyze, or pentest a browser extension for vulnerabilities. Trigger this skill for extension security reviews, manifest.json analysis,…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Force-load arbitrary browser extensions in Chromium-based browsers (Chrome, Edge, Brave) on Windows by forging valid HMACs in Preferences/Secure Preferences files. Use this skill whenever you need to persist a browser extension silently, bypass extension…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

How to assess payment process security during authorized penetration testing. Use this skill whenever the user mentions payment security testing, transaction flow analysis, payment gateway assessment, or needs to evaluate payment system vulnerabilities in an…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Web cache poisoning and cache deception testing for security assessments. Use this skill whenever the user mentions cache vulnerabilities, CDN security, web cache poisoning, cache deception, HTTP caching issues, or wants to test for cache-related…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

How to test for web cache poisoning vulnerabilities that can lead to denial of service. Use this skill whenever the user mentions cache servers, CDNs, DoS attacks, web server vulnerabilities, HTTP headers, Cloudflare, or any scenario where they want to test…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

How to perform cache poisoning attacks by exploiting URL parsing discrepancies between cache proxies and web servers. Use this skill whenever the user mentions cache poisoning, CDN vulnerabilities, URL parsing issues, proxy discrepancies, or wants to test for…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Techniques for bypassing captchas during authorized security testing and penetration testing. Use this skill whenever you're testing web applications and encounter captcha challenges that need to be automated or bypassed for testing purposes. This includes…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

How to test for clickjacking vulnerabilities in web applications. Use this skill whenever the user mentions clickjacking, UI redressing, iframe attacks, frame-busting, X-Frame-Options, CSP frame-ancestors, or wants to test if a web page can be embedded in…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

How to find and exploit Client Side Path Traversal (CSPT) vulnerabilities in web applications. Use this skill whenever the user mentions path traversal, URL manipulation, OSRF, on-site request forgery, frontend security testing, SPA vulnerabilities, or wants…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

How to detect and exploit Client Side Template Injection (CSTI) vulnerabilities in web applications. Use this skill whenever the user mentions template injection, AngularJS, VueJS, Mavo, or wants to test for client-side code execution vulnerabilities. Also…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

How to identify, test, and exploit command injection vulnerabilities in web applications. Use this skill whenever the user mentions command injection, OS command injection, RCE through user input, shell metacharacters, or wants to test for arbitrary command…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Content Security Policy (CSP) bypass research and testing for security assessments. Use this skill when analyzing CSP configurations, testing bypass techniques for authorized security assessments, or researching CSP vulnerabilities. Trigger when users mention…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

How to bypass Content Security Policy (CSP) when configured with 'self' and 'unsafe-inline'. Use this skill whenever you're doing web security testing, penetration testing, or analyzing CSP configurations that include 'unsafe-inline'. Trigger this skill for…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Test for Cross-Origin Resource Sharing (CORS) misconfigurations and bypass vulnerabilities. Use this skill whenever you need to audit web applications for CORS security issues, test Origin header validation, check for credential leakage, or explore DNS…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

How to test for CRLF (Carriage Return Line Feed) injection vulnerabilities in web applications. Use this skill whenever you need to assess HTTP header injection, response splitting, or newline-based bypasses during web security testing. Trigger this skill…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Cross-Site Request Forgery (CSRF) vulnerability testing and exploitation. Use this skill whenever the user mentions CSRF, cross-site request forgery, form submission attacks, session hijacking, web security testing, or needs to test web applications for CSRF…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

How to exploit HTML injection vulnerabilities using dangling markup techniques to exfiltrate data, steal forms, bypass CSP, and manipulate page behavior without JavaScript execution. Use this skill whenever the user mentions HTML injection, scriptless…

원문 언어: 영어

업데이트
수집된 skill 908개 중 40개를 표시합니다.