Skip to main content

anshumanbh/vulnvibes

SkillsMP는 anshumanbh/vulnvibes에서 10개의 skill을 수집했습니다. skill을 열어 소스와 세부 정보를 확인하세요.

최근 기록된 소스 활동
SkillsMP 카탈로그 업데이트
수집된 skills
10
GitHub 스타
19
GitHub 포크
6

이 저장소의 skills

직업 카테고리 1개 · 100% 분류됨

수집된 skill 10개 중 10개를 표시합니다.

직업 분류
정보 보안 분석가
설명

Investigate authentication vulnerabilities in source code including missing authentication, weak authentication, and session management issues. Use when threat model identifies CWE-287 (Improper Authentication), CWE-384 (Session Fixation), CWE-306 (Missing…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Investigate authorization vulnerabilities in source code including IDOR, privilege escalation, and missing access controls. Use when threat model identifies CWE-639 (IDOR), CWE-862 (Missing Authorization), CWE-863 (Incorrect Authorization), CWE-269 (Privilege…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Investigate browser security vulnerabilities including CORS misconfiguration, CSRF, clickjacking, and cookie security. Use when threat model identifies CWE-346 (Origin Validation), CWE-942 (Permissive CORS), CWE-352 (CSRF), CWE-1021 (Clickjacking), or browser…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Investigate cryptographic vulnerabilities in source code including weak algorithms, hardcoded secrets, and improper key management. Use when threat model identifies CWE-327 (Use of Broken Crypto), CWE-798 (Hardcoded Credentials), CWE-326 (Inadequate…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Investigate data exposure vulnerabilities in source code including PII leakage, sensitive data logging, and information disclosure. Use when threat model identifies CWE-200 (Information Exposure), CWE-532 (Sensitive Data in Logs), CWE-359 (Privacy Violation),…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Investigate insecure deserialization vulnerabilities that can lead to RCE or data manipulation. Use when threat model identifies CWE-502 (Deserialization of Untrusted Data), CWE-915 (Mass Assignment), or object deserialization concerns.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Investigate file operation vulnerabilities including unrestricted file upload, path traversal in file operations, and insecure file handling. Use when threat model identifies CWE-434 (Unrestricted Upload), CWE-73 (External Control of File Path), CWE-427…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Investigate injection vulnerabilities in source code including SQL injection, XSS, and command injection. Use when threat model identifies CWE-89 (SQL Injection), CWE-79 (XSS), CWE-78 (OS Command Injection), or injection concerns.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Investigate security misconfiguration vulnerabilities including debug modes, default credentials, overly permissive settings, and insecure defaults. Use when threat model identifies CWE-16 (Configuration), CWE-1188 (Insecure Default Initialization), CWE-276…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Investigate Server-Side Request Forgery (SSRF) vulnerabilities where user input controls server-initiated requests. Use when threat model identifies CWE-918 (SSRF), CWE-441 (Unintended Proxy), or server-side request concerns.

원문 언어: 영어

업데이트
수집된 skill 10개 중 10개를 표시합니다.