Skip to main content

이 저장소의 skills

Wyl-cmd/kxns-cli - 2페이지

SkillsMP는 Wyl-cmd/kxns-cli에서 97개의 skill을 수집했습니다. skill을 열어 소스와 세부 정보를 확인하세요.

Wyl-cmd/kxns-cli

수집된 skill 97개 중 40개를 표시합니다.

직업 분류
정보 보안 분석가
설명

Hunt LDAP Injection and XPath Injection — authentication bypass, blind char-by-char attribute exfiltration, AD user/group enumeration, XML-store XPath bypass. Covers the LDAP special-character set (* ( ) \ NUL /), search-filter-context vs DN-injection,…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Hunt Local File Inclusion (LFI), Remote File Inclusion (RFI), and Path Traversal — /etc/passwd read, log poisoning → RCE, PHP filter-chain RCE (no upload needed), php:// / data:// / zip:// / phar:// wrappers, RFI via allow_url_include, directory traversal…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Hunt LLM/AI feature bugs — prompt injection, indirect injection, exfiltration via tool-use/markdown, ASCII smuggling, agentic AI security (OWASP Agentic Apps 2026, ASI01-ASI10). Patterns: direct injection ('ignore previous instructions'), indirect injection…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Hunt mass assignment via sensitive field injection and ORM framework exploitation.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Hunt Model Context Protocol (MCP) vulnerabilities in AI-tool integration systems.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Hunt NestJS-specific vulnerabilities: guard bypass, decorator gaps, and microservice auth drift.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Hunt NTLM/Negotiate information disclosure on internet-reachable IIS/SharePoint/Exchange. Anonymous NTLM Type-2 challenge capture leaks NetBIOS domain, internal DNS forest, computer name, AD timestamp via AV_PAIRS structure. Default Windows-installer…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Hunting skill for oauth vulnerabilities. Built from 19 public bug bounty reports. Use when hunting oauth on any target.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Hunt Open Redirect — all types including low-impact, chained to OAuth token theft → ATO, phishing chains. URL parameter manipulation, JavaScript redirect, meta refresh, header injection. Use when hunting redirect bugs or building ATO chains.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Hunt client-side and server-side prototype pollution for XSS, auth bypass, and RCE.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Hunting skill for race condition vulnerabilities. Built from 12 public bug bounty reports including modern HTTP/2 single-packet attack cases (James Kettle DEF CON 2023 "Smashing the State Machine"; RyotaK / Flatt Security 10,000-request first-sequence-sync…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Hunt SAML / SSO attacks. Patterns: XML Signature Wrapping (XSW) — modify Assertion while keeping Signature valid by relocating signed element, comment injection in NameID (admin@target.com<!--evil-->@attacker.com → some parsers see admin@target.com),…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Hunt Microsoft SharePoint Server (2013/2016/2019/Subscription Edition) on-prem farms — anonymous endpoint enumeration, version disclosure, legacy SOAP login bypass (Authentication.asmx), ToolShell precondition chain (CVE-2025-53770), SafeControl reflection…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Hunt source code and build artifact leakage — JavaScript source maps (.js.map) reconstructing TypeScript/ES6 source, Swagger/OpenAPI JSON endpoint discovery, .env/.git exposure, webpack chunks with hardcoded secrets, robots.txt/security.txt recon, build-info…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Hunting skill for sqli vulnerabilities. Built from 12 public bug bounty reports including modern NoSQL injection (Rocket.Chat CVE-2021-22911 MongoDB $regex, Mongoose ORM CVE-2024-53900 $where bypass), modern ORM raw-fragment SQLi (Django CVE-2024-42005,…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Hunting skill for ssrf vulnerabilities. Built from 15 public bug bounty reports including AWS metadata SSRF (HackerOne $25k Analytics PDF, Shopify Exchange $25k, Capital One 106M-record breach, Dropbox/HelloSign $4,913), GCP metadata SSRF (Snapchat $4k),…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Hunt server-side template injection (SSTI) across Jinja2 (Flask/Django), Twig (Symfony), Freemarker (Java), ERB (Rails), Spring, Velocity, Mako, Thymeleaf, Smarty. Detection probes use double-curly and dollar-curly math expressions evaluated server-side. Once…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Complete subdomain hunting — enumeration (crt.sh, subfinder, DNS brute force, permutation, TLD expansion, CT monitoring), staging/dev discovery (WordPress install takeover, security gap analysis, internal subdomain leaks via crt.sh), and takeover exploitation…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Hunt WebSocket vulnerabilities — Cross-Site WebSocket Hijacking (CSWSH), missing/weak Origin validation on the WS handshake, no per-message authentication, message tampering, socket.io namespace/room authorization bypass, and handshake-layer Upgrade…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Hunt WordPress-specific vulnerabilities — REST API user enumeration, XMLRPC brute force + SSRF + upload, CORS credential reflect on WP REST API, open registration, cross-subdirectory plugin discovery, Yoast sitemap email disclosure, Application Passwords…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Hunting skill for xss vulnerabilities. Built from 174 public bug bounty reports. Use when hunting xss on any target.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Hunting skill for xxe vulnerabilities. Built from 10 public bug bounty reports including SVG-upload XXE, Office-doc (PPTX/DOCX) XXE, SOAP XXE, SAML AssertionConsumer XXE, blind OOB XXE via DTD callback, parameter-entity XXE, XXE-to-LFI, XXE-to-SSRF, and…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Entry P1 category router + expert playbook for injection testing. Covers command injection (OS shell metacharacters, blind/OOB, filter bypass, WAF bypass, reverse shells, PHP disable_functions bypass, component-level sinks), expression language injection…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Attack cameras via RTSP, ONVIF, Axis config when 554 open.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Analyze JS bundles and source maps for hardcoded secrets, API keys, JWTs, and internal endpoints

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Decode, forge, brute JWTs when Bearer auth header is seen.

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Answer KXNS CLI usage, configuration, and troubleshooting questions. Use when user asks about KXNS CLI installation, setup, configuration, slash commands, keyboard shortcuts, MCP integration, providers, environment variables, how something works internally,…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

LLM prompt injection / system prompt extraction — 40+ technique catalog against hardened GPT-4o-class deployments. Covers direct/indirect/agentic attacks, encoding bypasses, delimiter smuggling, boolean extraction, positional enumeration, RAG poisoning,…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Microsoft 365 / Entra ID red-team attack chain — current 2026 reality. AADSTS code reference, user enumeration vectors (with hardening status), Smart Lockout math, Conditional Access bypass options, ROPC + SAML SSO browser flow, Burp/Playwright templates.…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Methodology for detecting client SOC patches, attacker activity, and security-state changes that occur DURING a red-team engagement — and converting those observations into deliverable findings. Built from authorized red-team work where the client patched a…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Operational arsenal for authorized external red-team and bug-bounty recon. Concrete probes, wordlists, regexes, dorks, curl one-liners for: subdomain enum, GraphQL/Swagger/REST discovery, identity fabric (Entra/Okta/ADFS/Google/SAML/M365 deep —…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Okta-as-IdP red-team attack chain — tenant discovery, user enumeration (multiple vectors), authentication flow analysis (factors enumeration, push-notification fatigue, SMS bypass), password spray with lockout discipline, Okta-specific phishing primitives…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Discover origin IPs behind CDN/WAF via favicon hash, DNS history, and SSL certs.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

7-phase pentest pipeline from passive recon to exploitation.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Chain phpinfo to RCE via exec check when info.php exposed.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Port scan /8-/24 with Masscan+RustScan and nmap banners.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Nmap scan for MySQL, Redis, FTP, SSH, internal API services.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Entry P1 category router for reconnaissance and methodology. Use when mapping scope, discovering assets, fingerprinting technology, building endpoint inventory, choosing the first high-value security testing path, and planning industry-sector recon campaigns.

원문 언어: 다국어 혼합

업데이트
직업 분류
정보 보안 분석가
설명

Sector-specific recon for small business service provider websites — plumbers, HVAC, electricians, landscapers, roofers, painters, cleaners, contractors. Typically WordPress, Wix, Squarespace, or custom PHP on shared hosting with minimal security. These sites…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Red-team operator discipline — the mindset corrections that separate offensive testing from defensive WAPT. Built from authorized red-team work where conservative defaults caused multiple findings to be missed and one to be incorrectly retracted. Use at the…

원문 언어: 영어

업데이트
수집된 skill 97개 중 40개를 표시합니다.