Skip to main content
Manus에서 모든 스킬 실행
원클릭으로
$pwd:

ghost-bits-cast-attack

// Java "Ghost Bits" / Cast Attack playbook (Black Hat Asia 2026). Use when attacking Java services where 16-bit char is silently narrowed to 8-bit byte to bypass WAF/IDS for SQL injection, deserialization RCE, file upload (Webshell), path traversal, CRLF injection, request smuggling, and SMTP injection. Affects Tomcat, Spring, Jetty, Undertow, Vert.x, Jackson, Fastjson, Apache Commons BCEL, Apache HttpClient, Angus Mail, JDK HttpServer, Lettuce, Jodd, XMLWriter and re-enables many "patched" CVEs through WAF bypass.

$ git log --oneline --stat
stars:840
forks:132
updated:2026년 4월 30일 03:51
파일 탐색기
2 개 파일
SKILL.md
readonly