Full WSTG-aligned web application pentest — 12-phase methodology from information gathering through reporting, with concrete commands, expected outputs, pitfalls, and verification per phase.
Idioma do texto original: inglês
Menu
O SkillsMP coletou 145 skills de uphiago/recon-skills. Abra uma skill para revisar a origem e os detalhes.
Mostrando 40 de 145 skills coletadas.
Full WSTG-aligned web application pentest — 12-phase methodology from information gathering through reporting, with concrete commands, expected outputs, pitfalls, and verification per phase.
Idioma do texto original: inglês
Attack SAML SSO via XSW, signature strip, metadata extract.
Idioma do texto original: inglês
Use when two or more verified findings may combine into a higher-impact authorized attack path.
Idioma do texto original: inglês
Use when verified WordPress findings may combine into an authorized path to administrative or server control.
Idioma do texto original: inglês
Escape Docker containers to host root via 5 techniques.
Idioma do texto original: inglês
Use when classifying a verified web or WordPress behavior and selecting a related validation skill.
Idioma do texto original: inglês
Compare recon waves to find NEW, REGRESSED, PERSISTENT findings.
Idioma do texto original: inglês
Use when starting or restructuring an authorized external web and API assessment.
Idioma do texto original: inglês
Use when an API may expose data or privileged operations without authentication.
Idioma do texto original: inglês
Deep pentest WP: SSRF, plugin CVE, JS mine, port scan chain.
Idioma do texto original: inglês
Mine error_log for creds, paths, SQL when leak hunt finds.
Idioma do texto original: inglês
Exchange/OWA NTLM AD leak, spray attack when mail subdomain.
Idioma do texto original: inglês
Exploit Firebase/Supabase for data via JS config leak probe.
Idioma do texto original: inglês
Exploit Flask/Werkzeug debugger exposure for traceback and SECRET leaks.
Idioma do texto original: inglês
Mine GitLab for secrets, CI tokens when subdomain found.
Idioma do texto original: inglês
Attack cameras via RTSP, ONVIF, Axis config when 554 open.
Idioma do texto original: inglês
Analyze JS bundles and source maps for hardcoded secrets, API keys, JWTs, and internal endpoints
Idioma do texto original: inglês
Decode, forge, brute JWTs when Bearer auth header is seen.
Idioma do texto original: inglês
Chain phpinfo to RCE via exec check when info.php exposed.
Idioma do texto original: inglês
Port scan /8-/24 with Masscan+RustScan and nmap banners.
Idioma do texto original: inglês
Nmap scan for MySQL, Redis, FTP, SSH, internal API services.
Idioma do texto original: inglês
Hunt staging via crt.sh when production is WAF-hardened.
Idioma do texto original: inglês
Sensitive file scanning, path traversal bypass, vHost enum, .env extract, log mining, Varnish detect
Idioma do texto original: inglês
Hunt WP plugins via REST, exploit CVEs when version known.
Idioma do texto original: inglês
Batch WP recon: users, CORS, XMLRPC, leaks across domains.
Idioma do texto original: inglês
Scan WordPress REST API plugin endpoints for unauthenticated state-changing operations — discover write endpoints (POST/PUT/PATCH/DELETE) exposed without auth, enumerate all plugin routes, and test for unauthorized content publishing, settings modification,…
Idioma do texto original: inglês
Exploit XMLRPC multicall, pingback for brute force and SSRF.
Idioma do texto original: inglês
Zimbra SOAP user enum, CVE-2022-37042, SSRF when webmail.
Idioma do texto original: inglês
Use when a bounded list of authorized API endpoints needs consistent CORS triage before browser validation.
Idioma do texto original: inglês
Evidence-capture and PoC-redaction discipline for bug-bounty submissions: cookie redaction protocol (which fields to mask, Preview annotation / Burp panel hiding / DevTools workflow), PII black-bar discipline (what to mask in other-user data — names, emails,…
Idioma do texto original: inglês
Hunt CORS Misconfiguration — origin-reflection with credentials, null-origin trust, subdomain-regex bypass (unanchored vs unescaped-dot vs prefix-only), pre-flight (OPTIONS) gating bypass, postMessage origin checks. High only when an attacker-controlled…
Idioma do texto original: inglês
Use when an authorized target exposes WordPress core, plugin, theme, REST, or XML-RPC behavior.
Idioma do texto original: inglês
Use when testing an authorized LLM application for prompt injection, system-prompt exposure, unsafe tool use, or RAG data-boundary failures.
Idioma do texto original: inglês
Multi-sector batch domain expansion — identify untested/under-tested sectors, generate candidate company domains (national chains, franchises, regionals), filter against existing test coverage, probe alive domains, and run the full testing pipeline across 20+…
Idioma do texto original: inglês
Parameterized sector recon using sector database.
Idioma do texto original: inglês
Bug bounty report writing for H1/Bugcrowd/Intigriti/Immunefi — report templates, human tone guidelines, impact-first writing, CVSS 3.1 scoring, title formula, impact statement formula, severity decision guide, downgrade counters, pre-submit checklist. Use…
Idioma do texto original: inglês
Web2 recon pipeline — subdomain enumeration (subfinder, Chaos API, assetfinder), live host discovery (dnsx, httpx), URL crawling (katana, waybackurls, gau), directory fuzzing (ffuf), JS analysis (LinkFinder, SecretFinder), continuous monitoring (new subdomain…
Idioma do texto original: inglês
Use when verified WordPress CORS, XML-RPC, role, upload, and execution behaviors may form one authorized attack path.
Idioma do texto original: inglês
Systematic approach to finding and testing CVEs for identified WordPress plugins. Covers plugin discovery, version extraction from multiple sources (readme.txt, assets, inline JS), CVE database cross-referencing with WPScan/Patchstack/NVD/NVD API,…
Idioma do texto original: inglês
Hunt LLM/AI feature bugs — prompt injection, indirect injection, exfiltration viatool-use/markdown, ASCII smuggling, agentic AI security (OWASP Agentic Apps 2026, ASI01-ASI10). Patterns: direct injection ('ignore previous instructions'), indirect injection…
Idioma do texto original: inglês