Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
직접 명령은 검토 Prompt를 거치지 않습니다. 실행하기 전에 소스를 확인하세요.
npx skills add https://github.com/CyberStrikeus/CyberStrike --skill wstg-clnt-08명령은 한 줄로 유지됩니다. 복사하기 전에 가로로 스크롤해 전체 내용을 확인하세요.
로컬 사본을 원하시나요? SkillsMP에서 현재 제공할 수 있는 파일을 다운로드하세요.
SOC 직업 분류 기준
SKILL.md 표시 중
| name | wstg-clnt-08 |
| description | Testing for Cross-Site Flashing |
| category | client-side |
| owasp_id | WSTG-CLNT-08 |
| version | 1.0.0 |
| author | cyberstrike-official |
| tags | ["client-side","javascript","dom","cors","wstg","clnt"] |
| tech_stack | ["html","javascript"] |
| cwe_ids | ["CWE-1021"] |
| chains_with | [] |
| prerequisites | [] |
| severity_boost | {} |
WSTG-CLNT-08
Testing for Cross-Site Flashing
Cross-Site Flashing (XSF) vulnerabilities occur in Flash/SWF applications when user input is improperly handled. Although Flash is deprecated, legacy applications may still use it. Similar vulnerabilities can exist in other rich media technologies.
#!/bin/bash
TARGET="target.com"
# Find SWF files
curl -s "https://$TARGET" | grep -oP '[^"]+\.swf'
# Check crossdomain.xml
curl -s "https://$TARGET/crossdomain.xml"
# Common paths
paths=("/crossdomain.xml" "/clientaccesspolicy.xml" "/flash/crossdomain.xml")
for path in "${paths[@]}"; do
curl -s "https://$TARGET$path"
done
<!-- Vulnerable configuration -->
<?xml version="1.0"?>
<cross-domain-policy>
<allow-access-from domain="*"/>
<!-- Restrict cross-domain access -->
<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<site-control permitted-cross-domain-policies="master-only"/>
<allow-access-from domain="www.trusted.com" secure="true"/>
</cross-domain-policy>
| Finding | CVSS | Severity |
|---|---|---|
| Wildcard crossdomain.xml | 5.3 | Medium |
| XSF vulnerability | 6.1 | Medium |
[ ] Flash files identified
[ ] crossdomain.xml analyzed
[ ] SWF parameters tested
[ ] clientaccesspolicy.xml checked
[ ] Findings documented