Skip to main content

Skills neste repositório

uphiago/recon-skills - Página 4

O SkillsMP coletou 145 skills de uphiago/recon-skills. Abra uma skill para revisar a origem e os detalhes.

uphiago/recon-skills

Mostrando 25 de 145 skills coletadas.

ocupação
Analistas de segurança da informação
descrição

Hunt Host Header Injection — password reset poisoning → ATO, web cache poisoning via unkeyed Host/X-Forwarded-Host, routing-based SSRF (Host picks upstream → cloud metadata/internal services), path-override SSRF/ACL-bypass (X-Original-URL/X-Rewrite-URL),…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Hunting skill for idor vulnerabilities. Built from 26 public bug bounty reports. Use when hunting idor on any target.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Hunt Kubernetes & Docker — API anonymous access, kubelet 10250 exec (SPDY/WebSocket, NOT plain POST) and the simpler /run primitive, etcd 2379 unauth, dashboard skip-login, RBAC misconfig, secret/SA-token abuse, docker.sock host escape, runc/container-escape…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Hunt LDAP Injection and XPath Injection — authentication bypass, blind char-by-char attribute exfiltration, AD user/group enumeration, XML-store XPath bypass. Covers the LDAP special-character set (* ( ) \ NUL /), search-filter-context vs DN-injection,…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Hunt public /metrics, /health, and actuator endpoints leaking AI usage, DB pools, and operational intelligence.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Hunt MFA / 2FA bypass — 7 distinct patterns. (1) MFA not enforced on sensitive endpoints (password change, email change accept without MFA challenge), (2) MFA-step skip via direct navigation to post-login URL, (3) MFA-token replay (same code accepted twice),…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Hunt Next.js specific vulnerabilities — Server Actions arbitrary function execution, Middleware auth bypass via static asset paths, ISR cache poisoning, Image Optimization SSRF (/_next/image), RSC payload leakage, getServerSideProps injection, source map…

Idioma do texto original: inglês

atualizado
ocupação
Desenvolvedores de software
descrição

Hunt NoSQL Injection — MongoDB operator injection ($where, $regex, $gt, $ne), CouchDB, Redis command injection, auth bypass via NoSQLi, data dump. Use when target uses MongoDB/Mongoose, CouchDB, Redis, or shows NoSQL error messages.

Idioma do texto original: inglês

atualizado
ocupação
Desenvolvedores de software
descrição

Hunt NTLM/Negotiate information disclosure on internet-reachable IIS/SharePoint/Exchange. Anonymous NTLM Type-2 challenge capture leaks NetBIOS domain, internal DNS forest, computer name, AD timestamp via AV_PAIRS structure. Default Windows-installer…

Idioma do texto original: inglês

atualizado
ocupação
Desenvolvedores de software
descrição

Hunt Open Redirect — all types including low-impact, chained to OAuth token theft → ATO, phishing chains. URL parameter manipulation, JavaScript redirect, meta refresh, header injection. Use when hunting redirect bugs or building ATO chains.

Idioma do texto original: inglês

atualizado
ocupação
Desenvolvedores de software
descrição

Hunting skill for rce vulnerabilities. Built from 67 public bug bounty reports. Use when hunting rce on any target.

Idioma do texto original: inglês

atualizado
ocupação
Desenvolvedores de software
descrição

Hunt SAML / SSO attacks. Patterns: XML Signature Wrapping (XSW) — modify Assertion while keeping Signature valid by relocating signed element, comment injection in NameID (admin@target.com<!--evil-->@attacker.com → some parsers see admin@target.com),…

Idioma do texto original: inglês

atualizado
ocupação
Desenvolvedores de software
descrição

Enumerate hidden tables, fields, and endpoints via API error hints. Agnostic across PostgREST, Zod, FastAPI, GraphQL, and REST.

Idioma do texto original: inglês

atualizado
ocupação
Desenvolvedores de software
descrição

Hunt Session Management vulnerabilities — session fixation (no regeneration on login), insufficient invalidation on logout / password-change / email-change, predictable or low-entropy session IDs, JWT-as-session with no exp/revocation, refresh-token…

Idioma do texto original: inglês

atualizado
ocupação
Desenvolvedores de software
descrição

Hunt Microsoft SharePoint Server (2013/2016/2019/Subscription Edition) on-prem farms — anonymous endpoint enumeration, version disclosure, legacy SOAP login bypass (Authentication.asmx), ToolShell precondition chain (CVE-2025-53770), SafeControl reflection…

Idioma do texto original: inglês

atualizado
ocupação
Desenvolvedores de software
descrição

Hunt Spring Boot specific vulnerabilities — Actuator endpoints (heapdump, env, loggers, mappings, shutdown), Spring Expression Language (SpEL) injection → RCE, H2 console RCE, Jolokia JMX exposure, Spring4Shell (CVE-2022-22965), Spring Cloud Function SPEL…

Idioma do texto original: inglês

atualizado
ocupação
Desenvolvedores de software
descrição

Hunt server-side template injection (SSTI) across Jinja2 (Flask/Django), Twig (Symfony), Freemarker (Java), ERB (Rails), Spring, Velocity, Mako, Thymeleaf, Smarty. Detection probes use double-curly and dollar-curly math expressions evaluated server-side. Once…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Hunting skill for subdomain takeover vulnerabilities. Includes modern provider fingerprints — Microsoft Azure DevOps `cloudapp.azure.com` regional-pool re-issue (1-click OAuth ATO via wildcard `reply_to`, Binary Security), Zendesk help-desk takeover → email…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Hunt WebSocket vulnerabilities — Cross-Site WebSocket Hijacking (CSWSH), missing/weak Origin validation on the WS handshake, no per-message authentication, message tampering, socket.io namespace/room authorization bypass, and handshake-layer Upgrade…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Hunt read-protected write-gaping endpoints. PATCH/POST/DELETE without authorization while GET is protected. Agnostic: Supabase, Firebase, REST, GraphQL.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Hunting skill for xxe vulnerabilities. Built from 10 public bug bounty reports including SVG-upload XXE, Office-doc (PPTX/DOCX) XXE, SOAP XXE, SAML AssertionConsumer XXE, blind OOB XXE via DTD callback, parameter-entity XXE, XXE-to-LFI, XXE-to-SSRF, and…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Kernel-level proxy protection via proxy-ns — forces ALL traffic (TCP/UDP/DNS) through Tor using Linux network namespaces. Unlike proxychains, this works with Go/Rust/static binaries, prevents DNS leaks, and is impossible for applications to bypass. Includes…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

End-to-end password spray playbook. User enumeration, lockout detection, password pattern generation, spray execution across all protocols, error code differentials, and engagement discipline. Unifies M365/Entra, Okta, Exchange, Kerberos, SharePoint, XMLRPC,…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Red-team operator discipline — the mindset corrections that separate offensive testing from defensive WAPT. Built from authorized red-team work where conservative defaults caused multiple findings to be missed and one to be incorrectly retracted. Use at the…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

VMware vSphere / vCenter Server external attack matrix — version fingerprinting, the high-impact CVE chain (CVE-2021-21972 vRealize unauth file upload, CVE-2021-21985 vSAN plugin RCE, CVE-2022-22954 Workspace ONE SSTI, CVE-2023-20887 Aria RCE, CVE-2024-37085…

Idioma do texto original: inglês

atualizado
Mostrando 25 de 145 skills coletadas.