Skip to main content

这个仓库中的 skills

abelrguezr/hacktricks-skills - 第 19 页

SkillsMP 已收集 abelrguezr/hacktricks-skills 中的 908 个 Skill。打开任一 Skill 可查看来源和详情。

abelrguezr/hacktricks-skills

已展示 40 / 908 个已收集 Skill。

职业分类
信息安全分析师
描述

Detect and exploit Server Side Inclusion (SSI) and Edge Side Inclusion (ESI) injection vulnerabilities in web applications. Use this skill whenever you're doing web pentesting, testing for file inclusion vulnerabilities, cache poisoning attacks, or when you…

原文语言:英语

更新
职业分类
信息安全分析师
描述

How to identify and exploit SOAP/JAX-WS ThreadLocal authentication bypass vulnerabilities in Java web services. Use this skill whenever the user mentions SOAP endpoints, JAX-WS handlers, authentication bypass, ThreadLocal, WebLogic, JBoss, GlassFish, or any…

原文语言:英语

更新
职业分类
信息安全分析师
描述

How to identify, test for, and exploit Cypher injection vulnerabilities in Neo4j graph databases. Use this skill whenever the user mentions Neo4j, graph databases, Cypher queries, database injection testing, or needs to assess graph database security. This…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Use this skill whenever testing for SQL injection vulnerabilities in MS Access databases, including Jet/ACE database engines. Trigger on any mention of MS Access, .mdb files, Access database, or SQL injection testing against legacy ASP applications. This…

原文语言:英语

更新
职业分类
信息安全分析师
描述

MSSQL SQL injection exploitation techniques including Active Directory enumeration, SSRF via MSSQL functions, WAF bypass methods, and data exfiltration. Use this skill whenever the user mentions MSSQL, Microsoft SQL Server, SQL injection against MSSQL…

原文语言:英语

更新
职业分类
信息安全分析师
描述

MySQL SQL injection testing and exploitation. Use this skill whenever the user mentions SQL injection, MySQL database testing, database enumeration, WAF bypass, blind injection, union-based injection, error-based injection, or any database security testing…

原文语言:英语

更新
职业分类
信息安全分析师
描述

MySQL/MariaDB SSRF and RCE exploitation techniques via SQL injection. Use this skill when you have SQL injection access to a MySQL/MariaDB database and want to explore server-side request forgery (SSRF) or remote code execution (RCE) through database…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Oracle SQL injection exploitation techniques for SSRF, OOB exfiltration, and internal reconnaissance. Use this skill whenever the user mentions Oracle databases, SQL injection against Oracle, DBMS packages, UTL_HTTP, UTL_TCP, DBMS_CLOUD, or needs to perform…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Upload binary files to PostgreSQL using large objects (pg_largeobject). Use this skill whenever you need to store files in PostgreSQL, exfiltrate data via SQL injection, upload malware payloads, or work with pg_largeobject, lo_creat, lo_import, lo_export…

原文语言:英语

更新
职业分类
信息安全分析师
描述

PostgreSQL data exfiltration using dblink and lo_import functions. Use this skill whenever the user needs to extract data from a PostgreSQL database through SQL injection, mentions dblink, lo_import, file exfiltration, database data extraction, CTF challenges…

原文语言:英语

更新
职业分类
信息安全分析师
描述

PostgreSQL injection attack techniques for authorized security testing. Use this skill whenever the user mentions PostgreSQL, SQL injection, database security testing, privilege escalation through databases, port scanning from SQL, NTLM hash extraction, or…

原文语言:英语

更新
职业分类
信息安全分析师
描述

PostgreSQL PL/pgSQL password bruteforce attack for security testing. Use this skill when you have SQL injection access to a PostgreSQL database and want to test password security. Trigger when the user mentions PostgreSQL brute force, password cracking, SQL…

原文语言:英语

更新
职业分类
信息安全分析师
描述

How to test for and exploit PostgreSQL SQL injection vulnerabilities. Use this skill whenever the user mentions PostgreSQL injection, SQL injection against PostgreSQL databases, WAF bypass for PostgreSQL, or needs to enumerate/exfiltrate data from PostgreSQL…

原文语言:英语

更新
职业分类
信息安全分析师
描述

PostgreSQL Remote Code Execution via Extensions - Use this skill when testing PostgreSQL databases for extension loading vulnerabilities, analyzing RCE attack vectors through shared library injection, or understanding how to exploit CREATE FUNCTION to load…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Exploit PostgreSQL scripting languages (plpythonu, plperlu, plrubyu, etc.) to achieve remote code execution from a compromised database. Use this skill whenever you have SQL access to a PostgreSQL database and want to enumerate available languages, trust…

原文语言:英语

更新
职业分类
信息安全分析师
描述

SQL injection vulnerability testing and exploitation guide. Use this skill whenever the user mentions SQL injection, SQLi, database injection, SQL vulnerability testing, penetration testing of web applications, authentication bypass, WAF bypass, or any…

原文语言:英语

更新
职业分类
信息安全分析师
描述

How to exploit Second Order SQL Injection vulnerabilities using SQLMap. Use this skill whenever the user mentions second-order SQLi, stored SQL injection, SQLMap with --second-url or --second-req, or needs to chain multiple requests to exploit a SQL injection…

原文语言:英语

更新
职业分类
信息安全分析师
描述

SQL injection testing with sqlmap. Use this skill whenever the user needs to test for SQL injection vulnerabilities, enumerate databases, extract data from vulnerable applications, or bypass WAFs with sqlmap. Trigger on any mention of SQL injection testing,…

原文语言:英语

更新
职业分类
信息安全分析师
描述

SQLMap automation and SQL injection testing assistant. Use this skill whenever the user needs to test for SQL injection vulnerabilities, run SQLMap commands, extract database information, or perform web application security testing. Trigger on mentions of…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Exploit SSRF vulnerabilities to access cloud metadata services and extract credentials from AWS, GCP, Azure, and other cloud providers. Use this skill whenever the user mentions SSRF, server-side request forgery, cloud metadata, instance metadata,…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Server-Side Request Forgery (SSRF) vulnerability assessment and exploitation. Use this skill whenever the user mentions SSRF, server-side request forgery, internal network access, cloud metadata endpoints, blind SSRF, gopher protocol payloads, or any scenario…

原文语言:英语

更新
职业分类
信息安全分析师
描述

How to identify and test for Server-Side Request Forgery (SSRF) vulnerabilities in web applications. Use this skill whenever the user mentions SSRF, server-side request forgery, internal network access, cloud metadata endpoints, or wants to test if an…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Use this skill whenever testing for SSRF vulnerabilities, bypassing URL filters, or generating SSRF payloads. Trigger on any mention of SSRF, server-side request forgery, URL validation bypass, localhost access, internal network scanning, cloud metadata…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Expression Language (EL) injection exploitation for Java applications. Use this skill whenever you need to detect, test, or exploit EL injection vulnerabilities in JavaEE applications, Spring Framework, JSP, JSF, or any Java-based web application. Trigger…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Generate Jinja2 Server-Side Template Injection (SSTI) payloads and bypass techniques for web application security testing. Use this skill whenever you need to test for template injection vulnerabilities in Flask/Jinja2 applications, generate RCE payloads,…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Server-Side Template Injection (SSTI) detection and exploitation. Use this skill whenever the user mentions template injection, SSTI, Jinja, Twig, FreeMarker, Velocity, Thymeleaf, or any template engine vulnerability. Also trigger when users need to test web…

原文语言:英语

更新
职业分类
信息安全分析师
描述

How to perform timing attacks on web applications to discover hidden parameters, headers, and scoped SSRFs. Use this skill whenever the user mentions timing analysis, response time differences, hidden attack surface discovery, race conditions, or wants to…

原文语言:英语

更新
职业分类
信息安全分析师
描述

How to find and exploit Unicode injection vulnerabilities in web applications. Use this skill whenever you're testing for XSS, SQLi, or other injection vulnerabilities and want to try Unicode-based bypass techniques. Trigger this when you encounter input…

原文语言:英语

更新
职业分类
信息安全分析师
描述

How to identify and exploit Unicode normalization vulnerabilities in web applications. Use this skill whenever you're testing for SQL injection bypass, XSS, WAF evasion, or input validation issues that might be affected by Unicode normalization. Trigger this…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Audit web applications for UUID security vulnerabilities. Use this skill whenever you need to analyze UUID implementations, identify predictable UUID patterns, assess password reset token security, or perform security testing on any system using UUIDs.…

原文语言:英语

更新
职业分类
信息安全分析师
描述

How to use WFuzz for web application fuzzing and brute force testing. Use this skill whenever the user mentions web fuzzing, brute forcing login forms, directory enumeration, parameter discovery, header testing, cookie brute forcing, HTTP method testing, or…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Comprehensive web vulnerability assessment methodology and checklist. Use this skill whenever the user mentions web pentesting, vulnerability assessment, security testing, bug bounty hunting, web application security, OWASP testing, or any security audit of…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Perform WebSocket security testing including enumeration, fuzzing, CSWSH detection, and vulnerability assessment. Use this skill whenever the user mentions WebSocket testing, real-time communication security, wss/ws endpoints, cross-site WebSocket hijacking,…

原文语言:英语

更新
职业分类
信息安全分析师
描述

How to test for and exploit XPath injection vulnerabilities in web applications. Use this skill whenever the user mentions XPath injection, XML query vulnerabilities, authentication bypass via XPath, blind XPath attacks, OOB XPath exploitation, or needs to…

原文语言:英语

更新
职业分类
信息安全分析师
描述

How to perform timing-based XSS attacks exploiting browser connection pool limits. Use this skill whenever you need to leak data through timing side-channels, exploit Chrome's 6 concurrent connection limit per origin, perform blind XSS exfiltration, or…

原文语言:英语

更新
职业分类
信息安全分析师
描述

XS-Search connection pool timing attack for web pentesting. Use this skill whenever you need to exfiltrate data from a target page you cannot directly read, when you can control content that affects page load time, or when you have a CSRF/HTML injection…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Perform cross-origin search attacks using cookie bombing and error event oracles. Use this skill when you need to extract data from a cross-origin endpoint by detecting server errors (431/414/400) triggered by inflated request headers. Trigger this skill for…

原文语言:英语

更新
职业分类
信息安全分析师
描述

How to perform CSS injection attacks to exfiltrate data from input fields using CSS selectors and @import. Use this skill whenever the user mentions CSS injection, style injection, data exfiltration from forms, input field attacks, or wants to extract secrets…

原文语言:英语

更新
职业分类
信息安全分析师
描述

CSS injection attack techniques for web security testing. Use this skill whenever the user mentions CSS injection, style injection, attribute exfiltration, blind CSS attacks, @import exfiltration, unicode-range attacks, font-based data leakage, or any…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Exploit LESS code injection vulnerabilities to perform SSRF and local file read attacks. Use this skill whenever you need to test for CSS preprocessor injection, identify vulnerable endpoints that process user input through LESS compilers, or extract…

原文语言:英语

更新
已展示 40 / 908 个已收集 Skill。