Skip to main content

yaklang/hack-skills

SkillsMP는 yaklang/hack-skills에서 102개의 skill을 수집했습니다. skill을 열어 소스와 세부 정보를 확인하세요.

최근 기록된 소스 활동
SkillsMP 카탈로그 업데이트
수집된 skills
102
GitHub 스타
1,792
GitHub 포크
237

이 저장소의 skills

직업 카테고리 2개 · 100% 분류됨

수집된 skill 102개 중 40개를 표시합니다.

직업 분류
정보 보안 분석가
설명

Business logic vulnerability playbook. Use when reasoning about workflows, race conditions, price manipulation, coupon abuse, state machines, and multi-step authorization gaps.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

LLM prompt injection playbook. Use when testing AI/LLM applications for direct injection, indirect injection via RAG/browsing, tool abuse, data exfiltration, MCP security risks, and defense bypass techniques.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Reconnaissance and methodology playbook. Use when mapping assets, discovering endpoints, fingerprinting technology, and building a structured testing plan for a new target.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

SQL injection playbook. Use when input reaches SQL queries, authentication logic, sorting, filtering, reporting, or DB-specific blind and out-of-band execution paths.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

SSRF playbook. Use when the server fetches URLs, resolves hostnames, imports remote content, or can be driven toward internal networks, cloud metadata, or secondary protocols.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Unauthorized access playbook for common exposed services. Use when Redis, Rsync, PHP-FPM, AJP/Ghostcat, Hadoop YARN, H2 Console, or similar management interfaces are exposed without authentication.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

CRLF injection playbook. Use when user input reaches HTTP response headers, Location redirects, Set-Cookie values, or log files where carriage-return/line-feed characters can split or inject content.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Insecure deserialization playbook. Use when Java, PHP, or Python applications deserialize untrusted data via ObjectInputStream, unserialize, pickle, or similar mechanisms that may lead to RCE, file access, or privilege escalation.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Java "Ghost Bits" / Cast Attack playbook (Black Hat Asia 2026). Use when attacking Java services where 16-bit char is silently narrowed to 8-bit byte to bypass WAF/IDS for SQL injection, deserialization RCE, file upload (Webshell), path traversal, CRLF…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Entry P0 primary router for HackSkills. Use when the task involves web application testing, API security assessment, recon, vulnerability triage, exploit path planning, or choosing the right next category skill before any deep topic skill.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Path traversal and LFI playbook. Use when file paths, download endpoints, include operations, archive extraction, or wrapper behavior may expose filesystem control.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

HTTP request smuggling and desynchronization testing. Use when front proxies, CDNs, or load balancers disagree with the origin on message framing (Content-Length vs Transfer-Encoding), on HTTP/2→HTTP/1 translation, or when exploring client-side desync via…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Insecure file upload playbook. Use when testing upload validation, storage paths, processing pipelines, preview behavior, overwrite risks, and upload-to-RCE chains.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

WAF bypass methodology and generic evasion techniques. Use when a web application firewall blocks injection payloads (SQLi, XSS, RCE) and you need to craft bypasses using encoding, protocol-level tricks, or WAF-specific weaknesses.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Entry P1 category router for API security. Use when choosing between API recon, authorization, token abuse, and hidden-parameter workflows before any deeper API topic skill.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Entry P1 category router for authentication and authorization. Use when testing login flows, sessions, object authorization, JWT, OAuth, CORS, CSRF, and enterprise SSO weaknesses before any deeper auth topic skill.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Authentication bypass testing playbook. Use when assessing login flows, password reset logic, account recovery, MFA bypass, token predictability, brute-force resistance, and session boundary flaws.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Entry P1 category router for business logic testing. Use when workflow abuse, race conditions, pricing flaws, or multi-step state attacks matter more than parser-level input injection.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

CSV/spreadsheet formula injection (DDE, Excel/LibreOffice, Google Sheets IMPORT*). Use when exports, imports, or user fields feed spreadsheets or reporting tools.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Supply-chain testing via package-manager dependency confusion: when internal package names resolve to attacker-controlled public registries, leading to malicious install and script execution. Use for npm/pip/gem/Maven/Composer/Docker manifest review and…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Entry P1 category router for file access and upload workflows. Use when testing download endpoints, file paths, local file inclusion, upload flows, preview pipelines, archive extraction, or storage and sharing boundaries.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

HTTP Parameter Pollution (HPP): duplicate query/body keys parsed differently by servers, proxies, WAFs, and app frameworks. Use when filters and application layers disagree on which value wins, enabling bypass, SSRF second URL, logic abuse, or CSRF token…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Entry P1 category router for injection testing. Use when routing between XSS, SQLi, SSRF, XXE, SSTI, command injection, and NoSQL injection workflows based on how attacker-controlled input is consumed.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Source control and artifact exposure (.git, .svn, .hg, backups, .env). Use when recon finds VCS paths, 403 on hidden dirs, or backup/config leaks during authorized testing.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Prototype pollution testing for JavaScript stacks. Use when user input is merged into objects (query parsers, JSON bodies, deep assign), when configuring libraries via untrusted keys, or when hunting RCE gadgets via polluted Object.prototype in Node or the…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Race condition and TOCTOU testing for web apps. Use when testing one-time operations, concurrent HTTP abuse, rate-limit bypass, Turbo Intruder gates, HTTP/2 single-packet attacks, and CWE-362-style synchronization gaps.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Entry P1 category router for reconnaissance and methodology. Use when mapping scope, discovering assets, fingerprinting technology, building endpoint inventory, and choosing the first high-value security testing path.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

SSTI playbook. Use when template expressions, server-side rendering, preview features, or templating engines may evaluate attacker-controlled content.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

PHP type juggling and weak comparison (`==`) bypass. Use when authentication, HMAC/signature checks, or token validation uses loose equality, numeric coercion, or hash comparisons without strict types — common in legacy PHP and CTF-style code paths.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

WebSocket handshake, CSWSH, tooling (wsrepl, ws-harness, Burp), and common flaws. Use when apps use real-time channels, chat, notifications, or WS-backed APIs.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

XSLT injection testing: processor fingerprinting, XXE and document() SSRF, EXSLT write primitives, PHP/Java/.NET extension RCE surfaces. Use when user-controlled XSLT/stylesheet input or transform endpoints are in scope.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

401/403 bypass playbook. Use when encountering access-denied responses on admin panels, API endpoints, or restricted paths. Covers path manipulation, HTTP method tampering, header injection, protocol downgrade, and automated bypass tools.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Active Directory ACL abuse playbook. Use when exploiting misconfigured AD permissions including GenericAll, WriteDACL, DCSync rights, shadow credentials, LAPS reading, GPO abuse, and BloodHound-guided attack paths.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

AD Certificate Services attack playbook. Use when targeting misconfigured AD CS for privilege escalation via ESC1-ESC13 template abuse, NTLM relay to enrollment, CA officer abuse, and certificate-based persistence.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Kerberos attack playbook for Active Directory. Use when targeting AD authentication via AS-REP roasting, Kerberoasting, golden/silver/diamond tickets, delegation abuse, or pass-the-ticket attacks.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

AI/ML security playbook. Use when assessing model supply chain attacks (pickle RCE, poisoned weights), adversarial examples, model poisoning, model stealing, data privacy attacks (membership inference, model inversion), and autonomous agent security risks.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Android pentesting playbook. Use when testing Android applications for SSL pinning bypass, exported component abuse, WebView vulnerabilities, intent redirection, root detection bypass, tapjacking, and backup extraction during authorized mobile security…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Anti-debugging detection and bypass playbook. Use when reversing protected binaries that detect debuggers via ptrace, PEB flags, timing checks, or signal/exception handlers on Linux and Windows.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Arbitrary write to RCE playbook. Use when you have an arbitrary write primitive (from heap exploitation, format string, or OOB write) and need to convert it into code execution by targeting GOT, hooks, _IO_FILE vtable, exit_funcs, TLS_dtor_list,…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Binary protection bypass playbook. Use when identifying and bypassing ASLR, PIE, NX/DEP, stack canary, RELRO, FORTIFY_SOURCE, CET, and MTE protections in ELF binaries to enable exploitation.

원문 언어: 영어

업데이트
수집된 skill 102개 중 40개를 표시합니다.