Skip to main content

Skills neste repositório

EntroVyx/hermes-agent-offsec - Página 3

O SkillsMP coletou 146 skills de EntroVyx/hermes-agent-offsec. Abra uma skill para revisar a origem e os detalhes.

EntroVyx/hermes-agent-offsec

Mostrando 40 de 146 skills coletadas.

ocupação
Analistas de segurança da informação
descrição

Hunt HTTP request smuggling (CL.TE, TE.CL, H2.CL, H2.TE). Cause: front-end proxy and back-end server disagree on where one request ends and the next begins (Content-Length vs Transfer-Encoding header parsing inconsistency). CL.TE: front-end uses CL, back uses…

Idioma do texto original: inglês

atualizado
ocupação
Desenvolvedores de software
descrição

Hunting skill for idor vulnerabilities. Built from 26 public bug bounty reports. Use when hunting idor on any target.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Hunt Local File Inclusion (LFI), Remote File Inclusion (RFI), and Path Traversal — /etc/passwd read, log poisoning → RCE, PHP filter-chain RCE (no upload needed), php:// / data:// / zip:// / phar:// wrappers, RFI via allow_url_include, directory traversal…

Idioma do texto original: inglês

atualizado
ocupação
Desenvolvedores de software
descrição

Hunt LLM/AI feature bugs — prompt injection, indirect injection, exfiltration via tool-use/markdown, ASCII smuggling, agentic AI security (OWASP Agentic Apps 2026, ASI01-ASI10). Patterns: direct injection ('ignore previous instructions'), indirect injection…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Hunt public /metrics, /health, and actuator endpoints leaking AI usage, DB pools, and operational intelligence.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Hunt MFA / 2FA bypass — 7 distinct patterns. (1) MFA not enforced on sensitive endpoints (password change, email change accept without MFA challenge), (2) MFA-step skip via direct navigation to post-login URL, (3) MFA-token replay (same code accepted twice),…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Hunt Node.js specific vulnerabilities — Prototype Pollution → RCE chains (lodash/merge/assign), Express trust proxy misconfiguration, child_process/eval injection, template engine SSTI (EJS/Pug/Handlebars), path traversal in file servers, require() injection,…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Hunt NoSQL Injection — MongoDB operator injection ($where, $regex, $gt, $ne), CouchDB, Redis command injection, auth bypass via NoSQLi, data dump. Use when target uses MongoDB/Mongoose, CouchDB, Redis, or shows NoSQL error messages.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Hunting skill for oauth vulnerabilities. Built from 19 public bug bounty reports. Use when hunting oauth on any target.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Hunt Open Redirect — all types including low-impact, chained to OAuth token theft → ATO, phishing chains. URL parameter manipulation, JavaScript redirect, meta refresh, header injection. Use when hunting redirect bugs or building ATO chains.

Idioma do texto original: inglês

atualizado
ocupação
Desenvolvedores de software
descrição

Hunting skill for race condition vulnerabilities. Built from 12 public bug bounty reports including modern HTTP/2 single-packet attack cases (James Kettle DEF CON 2023 "Smashing the State Machine"; RyotaK / Flatt Security 10,000-request first-sequence-sync…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Hunting skill for rce vulnerabilities. Built from 67 public bug bounty reports. Use when hunting rce on any target.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Hunt SAML / SSO attacks. Patterns: XML Signature Wrapping (XSW) — modify Assertion while keeping Signature valid by relocating signed element, comment injection in NameID (admin@target.com<!--evil-->@attacker.com → some parsers see admin@target.com),…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Enumerate hidden tables, fields, and endpoints via API error hints. Agnostic across PostgREST, Zod, FastAPI, GraphQL, and REST.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Hunt Session Management vulnerabilities — session fixation (no regeneration on login), insufficient invalidation on logout / password-change / email-change, predictable or low-entropy session IDs, JWT-as-session with no exp/revocation, refresh-token…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Hunt source code and build artifact leakage — JavaScript source maps (.js.map) reconstructing TypeScript/ES6 source, Swagger/OpenAPI JSON endpoint discovery, .env/.git exposure, webpack chunks with hardcoded secrets, robots.txt/security.txt recon, build-info…

Idioma do texto original: inglês

atualizado
ocupação
Desenvolvedores de software
descrição

Hunting skill for sqli vulnerabilities. Built from 12 public bug bounty reports including modern NoSQL injection (Rocket.Chat CVE-2021-22911 MongoDB $regex, Mongoose ORM CVE-2024-53900 $where bypass), modern ORM raw-fragment SQLi (Django CVE-2024-42005,…

Idioma do texto original: inglês

atualizado
ocupação
Desenvolvedores de software
descrição

Hunting skill for ssrf vulnerabilities. Built from 15 public bug bounty reports including AWS metadata SSRF (HackerOne $25k Analytics PDF, Shopify Exchange $25k, Capital One 106M-record breach, Dropbox/HelloSign $4,913), GCP metadata SSRF (Snapchat $4k),…

Idioma do texto original: inglês

atualizado
ocupação
Desenvolvedores de software
descrição

Hunt server-side template injection (SSTI) across Jinja2 (Flask/Django), Twig (Symfony), Freemarker (Java), ERB (Rails), Spring, Velocity, Mako, Thymeleaf, Smarty. Detection probes use double-curly and dollar-curly math expressions evaluated server-side. Once…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Hunting skill for subdomain takeover vulnerabilities. Includes modern provider fingerprints — Microsoft Azure DevOps `cloudapp.azure.com` regional-pool re-issue (1-click OAuth ATO via wildcard `reply_to`, Binary Security), Zendesk help-desk takeover → email…

Idioma do texto original: inglês

atualizado
ocupação
Desenvolvedores de software
descrição

Hunt Supabase exploitation — Supabase anon key discovery in JS bundles, REST API table enumeration with anon key, Row Level Security (RLS) bypass via missing organization_id check, RPC function abuse returning cross-organization data, Storage bucket listing,…

Idioma do texto original: inglês

atualizado
ocupação
Desenvolvedores de software
descrição

Hunt TLS/SSL and DNS misconfigurations — missing HSTS (downgrade attack), weak cipher suites, expired/invalid certificates, mTLS bypass, missing SPF/DKIM/DMARC (email spoofing), DNS Zone Transfer (AXFR), dangling CNAME subdomain takeover, CAA records. Most of…

Idioma do texto original: inglês

atualizado
ocupação
Desenvolvedores de software
descrição

Hunt WebSocket vulnerabilities — Cross-Site WebSocket Hijacking (CSWSH), missing/weak Origin validation on the WS handshake, no per-message authentication, message tampering, socket.io namespace/room authorization bypass, and handshake-layer Upgrade…

Idioma do texto original: inglês

atualizado
ocupação
Desenvolvedores de software
descrição

Hunt WordPress-specific vulnerabilities — REST API user enumeration, XMLRPC brute force + SSRF + upload, CORS credential reflect on WP REST API, open registration, cross-subdirectory plugin discovery, Yoast sitemap email disclosure, Application Passwords…

Idioma do texto original: inglês

atualizado
ocupação
Desenvolvedores de software
descrição

Hunt read-protected write-gaping endpoints. PATCH/POST/DELETE without authorization while GET is protected. Agnostic: Supabase, Firebase, REST, GraphQL.

Idioma do texto original: inglês

atualizado
ocupação
Desenvolvedores de software
descrição

Hunting skill for xss vulnerabilities. Built from 174 public bug bounty reports. Use when hunting xss on any target.

Idioma do texto original: inglês

atualizado
ocupação
Desenvolvedores de software
descrição

Hunting skill for xxe vulnerabilities. Built from 10 public bug bounty reports including SVG-upload XXE, Office-doc (PPTX/DOCX) XXE, SOAP XXE, SAML AssertionConsumer XXE, blind OOB XXE via DTD callback, parameter-entity XXE, XXE-to-LFI, XXE-to-SSRF, and…

Idioma do texto original: inglês

atualizado
ocupação
Desenvolvedores de software
descrição

Manual-first bug bounty and pentest methodology built from a top-paid disclosed HackerOne sample. Use when testing real application behavior beyond scanner output: business logic, authorization drift, workflow abuse, state-machine flaws, onboarding abuse,…

Idioma do texto original: inglês

atualizado
ocupação
Desenvolvedores de software
descrição

Meme coin and token security audit — rug pull detection (honeypot, hidden mint, fee manipulation, LP lock bypass), Solana SPL token analysis (freeze authority, mint authority, metadata mutability), Token-2022 extension risks (transfer hooks, permanent…

Idioma do texto original: inglês

atualizado
ocupação
Desenvolvedores de software
descrição

Operational arsenal for authorized external red-team and bug-bounty recon. Concrete probes, wordlists, regexes, dorks, curl one-liners for: subdomain enum, GraphQL/Swagger/REST discovery, identity fabric (Entra/Okta/ADFS/Google/SAML/M365 deep —…

Idioma do texto original: inglês

atualizado
ocupação
Desenvolvedores de software
descrição

Kernel-level proxy protection via proxy-ns — forces ALL traffic (TCP/UDP/DNS) through Tor using Linux network namespaces. Unlike proxychains, this works with Go/Rust/static binaries, prevents DNS leaks, and is impossible for applications to bypass. Includes…

Idioma do texto original: inglês

atualizado
ocupação
Desenvolvedores de software
descrição

Set up and manage self-improving parallel reconnaissance agent triads — eternal overlapping waves of deep invasion, target expansion, and skill evolution. Covers the full lifecycle: spawning parallel subagents, cron orchestration, documentation structure,…

Idioma do texto original: inglês

atualizado
ocupação
Desenvolvedores de software
descrição

Sector-specific recon for car dealership and automotive retail websites — typically WordPress or custom PHP on shared hosting with inventory listings, financing applications, service booking, and OEM-branded portals. Built from a 20-target batch recon across…

Idioma do texto original: inglês

atualizado
ocupação
Desenvolvedores de software
descrição

Sector-specific recon for bakery, pastry shop, and cake shop websites — typically WordPress on shared hosting with e-commerce (WooCommerce, Shopify), online ordering for cakes/pastries, catering pages, and store locators. Common platforms include EatStreet,…

Idioma do texto original: inglês

atualizado
ocupação
Desenvolvedores de software
descrição

Sector-specific recon for craft brewery, brewpub, and distillery websites — common e-commerce platforms (Untappd, Shopify, WooCommerce), age-gate patterns, event calendars, beer menu APIs, and online ordering systems. Typically WordPress, Shopify, or custom…

Idioma do texto original: inglês

atualizado
ocupação
Desenvolvedores de software
descrição

Sector-specific recon for coffee shop, cafe, and tea house websites — typically WordPress on shared hosting with online ordering for pickup/delivery, loyalty/rewards programs, catering menus, and location/store finders. Common platforms include Toast POS,…

Idioma do texto original: inglês

atualizado
ocupação
Desenvolvedores de software
descrição

Sector-specific recon for car wash and auto detailing company websites — typically WordPress on shared hosting with membership plans, pricing menus, booking/scheduling tools, and customer account portals. Common platforms include EverWash, Washify, DRB…

Idioma do texto original: inglês

atualizado
ocupação
Desenvolvedores de software
descrição

Sector-specific recon for church/religious organization websites — WordPress on shared hosting with minimal security posture. Built from a 58-company mass recon dataset where church/religious org domains showed the highest rate of unpatched WordPress…

Idioma do texto original: inglês

atualizado
ocupação
Desenvolvedores de software
descrição

Sector-specific recon for daycare/childcare organization websites — typically WordPress or custom PHP on shared hosting with minimal security posture. Built from sector analysis showing daycare sites have high rates of unpatched CMS installs, exposed…

Idioma do texto original: inglês

atualizado
ocupação
Desenvolvedores de software
descrição

Sector-specific recon for dentist, orthodontist, and dental practice websites — typically WordPress on shared hosting with online booking, patient portal integrations, and insurance verification pages. Common platforms include Dentrix Ascend, Eaglesoft, Open…

Idioma do texto original: inglês

atualizado
Mostrando 40 de 146 skills coletadas.