Skip to main content

这个仓库中的 skills

abelrguezr/hacktricks-skills - 第 17 页

SkillsMP 已收集 abelrguezr/hacktricks-skills 中的 908 个 Skill。打开任一 Skill 可查看来源和详情。

abelrguezr/hacktricks-skills

已展示 40 / 908 个已收集 Skill。

职业分类
信息安全分析师
描述

Detect and analyze Server-Side Leaks (SS-Leaks) vulnerabilities in web applications. Use this skill whenever the user mentions server-side leaks, information disclosure, error message analysis, stack trace exposure, or wants to audit web applications for…

原文语言:英语

更新
职业分类
信息安全分析师
描述

How to pentest decentralized applications (DApps). Use this skill whenever the user mentions DApps, Web3 applications, blockchain applications, smart contracts, or wants to audit/penetrate test any decentralized application. This includes NFT platforms, DeFi…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Audit and remediate dependency confusion vulnerabilities in package management configurations. Use this skill whenever the user mentions package managers (npm, pip, Maven, Gradle, NuGet, Go modules, Cargo, Bundler), CI/CD security, supply chain attacks,…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Java deserialization vulnerability assessment and exploitation. Use this skill whenever the user mentions Java deserialization, ObjectInputStream, readObject, gadget chains, ysoserial, or any Java serialization security testing. Trigger for pentesting Java…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Use this skill for .NET deserialization vulnerability assessment and exploitation. Trigger when investigating BinaryFormatter, SoapFormatter, Json.Net, XAML, or any .NET serialization sinks. Covers ObjectDataProvider gadgets, YSoNet/ysoserial.net payloads,…

原文语言:英语

更新
职业分类
信息安全分析师
描述

How to identify and exploit insecure deserialization vulnerabilities across PHP, Python, NodeJS, Java, .NET, and Ruby. Use this skill whenever the user mentions deserialization, serialization, object injection, gadget chains, ysoserial, pickle, unserialize,…

原文语言:英语

更新
职业分类
信息安全分析师
描述

How to exploit ASP.NET ViewState deserialization attacks when the secret key is known. Use this skill whenever you need to test ASP.NET applications for ViewState vulnerabilities, analyze ViewState tokens, perform deserialization attacks on .NET applications,…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Exploit ASP.NET ViewState deserialization vulnerabilities. Use this skill whenever you need to assess, enumerate, or exploit __VIEWSTATE parameters in ASP.NET applications. This includes discovering MachineKeys, generating payloads with YSoSerial.Net, and…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Detect and exploit Java deserialization vulnerabilities using DNS-based payloads, GadgetProbe, and Java Deserialization Scanner. Use this skill whenever the user mentions Java deserialization, gadget chains, ysoserial, Burp extensions for deserialization…

原文语言:英语

更新
职业分类
信息安全分析师
描述

How to identify and exploit Java JSF ViewState deserialization vulnerabilities in web applications. Use this skill whenever the user mentions JSF, ViewState, Java web applications, deserialization attacks, .faces files, or wants to test for RCE through…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Identify and analyze Java SignedObject-gated deserialization vulnerabilities, including pre-auth reachability via error handlers. Use this skill whenever investigating Java deserialization issues, analyzing stack traces with SignedObject.getObject() calls,…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Generate and explain Java deserialization payloads using Apache Commons Collections gadget chains. Use this skill whenever the user mentions Java deserialization, Apache Commons Collections, gadget chains, ysoserial, CommonsCollections1, or needs to create…

原文语言:英语

更新
职业分类
信息安全分析师
描述

How to discover, verify, and exploit JNDI/Log4Shell vulnerabilities in Java applications. Use this skill whenever the user mentions Log4j, JNDI, LDAP injection, CVE-2021-44228, Java deserialization, or needs to test for remote code execution through logging…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Exploit Laravel Livewire v3 deserialization vulnerabilities for RCE. Use this skill whenever the user mentions Livewire, Laravel, deserialization attacks, CVE-2025-54068, Livewire snapshots, hydration abuse, or any web application using Livewire v3. Trigger…

原文语言:英语

更新
职业分类
信息安全分析师
描述

How to discover, debug, and exploit client-side prototype pollution vulnerabilities in JavaScript applications. Use this skill whenever the user mentions prototype pollution, __proto__, constructor.prototype, Object.prototype, or wants to find XSS via…

原文语言:英语

更新
职业分类
信息安全分析师
描述

How to test for and exploit prototype pollution vulnerabilities in Express.js applications. Use this skill whenever you're pentesting Node.js/Express applications, analyzing JSON parsing vulnerabilities, or investigating server-side prototype pollution. Make…

原文语言:英语

更新
职业分类
信息安全分析师
描述

How to identify and exploit prototype pollution vulnerabilities in Node.js applications. Use this skill whenever the user mentions prototype pollution, __proto__, Object.prototype, JavaScript prototype attacks, Node.js deserialization vulnerabilities, or…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Generate and test Node.js prototype pollution to RCE payloads. Use this skill whenever the user mentions prototype pollution, Node.js security testing, child_process exploitation, PP2RCE, or needs to convert prototype pollution into remote code execution.…

原文语言:英语

更新
职业分类
信息安全分析师
描述

PHP deserialization exploitation for pentesting. Use this skill whenever you need to exploit PHP deserialization vulnerabilities, including spl_autoload_register abuse, phpggc gadget chains, PHPUnit PHPT coverage attacks, TCPDF POP chains, html2pdf phar://…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Security skill for understanding, testing, and mitigating Python YAML deserialization vulnerabilities. Use this skill whenever the user mentions YAML deserialization, PyYAML security, Python RCE through YAML, deserialization attacks, or needs to audit code…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Ruby class pollution vulnerability analysis and exploitation. Use this skill whenever the user needs to understand, identify, or test Ruby class pollution vulnerabilities in applications. This includes merge-on-attributes attacks, privilege escalation through…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Use this skill whenever you're testing Ruby on Rails applications for deserialization vulnerabilities, JSON parsing issues, or authorization bypasses involving the _json parameter. Trigger this when you see JSON endpoints, Rails controllers, or need to test…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Detect and analyze domain/subdomain takeover vulnerabilities. Use this skill whenever the user mentions subdomain takeover, domain takeover, dangling DNS records, CNAME vulnerabilities, orphaned cloud resources, or wants to audit DNS records for security…

原文语言:英语

更新
职业分类
信息安全分析师
描述

How to identify and test email injection vulnerabilities in web applications. Use this skill whenever the user mentions email injection, header injection, PHP mail exploitation, email bypass techniques, SSO email attacks, or any email-related security…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Security testing skill for identifying and exploiting Local File Inclusion (LFI) and Remote File Inclusion (RFI) vulnerabilities. Use this skill whenever you need to test for path traversal vulnerabilities, file inclusion attacks, PHP wrapper exploitation, or…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Exploit LFI to RCE using compress.zlib:// protocol with PHP_STREAM_PREFER_STDIO race condition. Use this skill whenever you need to escalate a Local File Inclusion vulnerability to Remote Code Execution, especially when the target has security checks that…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Exploit Local File Inclusion (LFI) vulnerabilities to achieve Remote Code Execution (RCE) using the Eternal Waiting technique. Use this skill when you have an LFI vulnerability, can upload files to the target, and need to escalate to code execution by…

原文语言:英语

更新
职业分类
信息安全分析师
描述

How to exploit LFI vulnerabilities to achieve RCE by leveraging Nginx temporary file descriptors. Use this skill whenever you encounter LFI vulnerabilities, need to escalate from file inclusion to code execution, or are investigating nginx reverse proxy…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Exploit Local File Inclusion (LFI) vulnerabilities in PHP applications using filter chains to achieve Remote Code Execution (RCE). Use this skill whenever the user mentions LFI, file inclusion, PHP filters, php://filter, or wants to exploit PHP…

原文语言:英语

更新
职业分类
信息安全分析师
描述

How to exploit Local File Inclusion (LFI) to Remote Code Execution (RCE) using PHPInfo() output. Use this skill whenever you need to escalate LFI vulnerabilities to RCE, especially when phpinfo() pages are accessible, or when you're testing for file inclusion…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Exploit Local File Inclusion (LFI) vulnerabilities to achieve Remote Code Execution (RCE) by triggering PHP segmentation faults that leave temporary upload files undeleted. Use this skill whenever you find an LFI vulnerability in a PHP application and want to…

原文语言:英语

更新
职业分类
信息安全分析师
描述

How to test for and exploit Local File Inclusion (LFI) vulnerabilities that can lead to Remote Code Execution (RCE) through temporary file uploads. Use this skill whenever you're testing web applications for file inclusion vulnerabilities, analyzing PHP file…

原文语言:英语

更新
职业分类
信息安全分析师
描述

How to exploit PHP PHAR deserialization vulnerabilities. Use this skill whenever you need to test for or exploit deserialization vulnerabilities in PHP applications, especially when dealing with file inclusion via phar:// protocol, file operations like…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Exploit Local File Inclusion (LFI) vulnerabilities using PHP session upload progress to achieve Remote Code Execution (RCE). Use this skill whenever the user mentions LFI, file inclusion vulnerabilities, PHP sessions, session upload progress, or needs to…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Test file upload vulnerabilities and bypass protections. Use this skill whenever the user needs to assess file upload security, test extension bypasses, create polyglot files, or exploit upload handlers. Trigger on requests about file upload testing, webshell…

原文语言:英语

更新
职业分类
信息安全分析师
描述

How to test PDF upload endpoints for XXE (XML External Entity) injection and CORS bypass vulnerabilities. Use this skill whenever you're pentesting file upload functionality, especially PDF uploads, or when investigating XXE injection vectors through file…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Security testing skill for Formula/CSV Injection, LaTeX Injection, and GhostScript Injection vulnerabilities. Use this skill whenever you need to test for spreadsheet formula injection (CSV/Excel), LaTeX document injection, or GhostScript PDF processing…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Pentest gRPC-Web services and endpoints. Use this skill whenever the user mentions gRPC-Web, gRPC over HTTP, protobuf services, Envoy proxies, or wants to test/audit gRPC-Web APIs. Trigger for any gRPC-Web reconnaissance, payload manipulation, CORS testing,…

原文语言:英语

更新
职业分类
信息安全分析师
描述

How to perform H2C (HTTP/2 over cleartext) and WebSocket smuggling attacks to bypass reverse proxy protections. Use this skill whenever you need to test for upgrade header smuggling vulnerabilities, bypass WAF/proxy rules, access internal endpoints behind a…

原文语言:英语

更新
职业分类
信息安全分析师
描述

How to assess JWT (JSON Web Token) security vulnerabilities in web applications. Use this skill whenever the user mentions JWT tokens, JSON Web Tokens, token security, authentication bypass, session hijacking, or needs to test JWT implementations for…

原文语言:英语

更新
已展示 40 / 908 个已收集 Skill。