用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/CyberStrikeus/CyberStrike --skill wstg-clnt-08命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
macOS post-exploitation for credential harvesting, DTrace monitoring, TCC bypass, and stealth operations via native tools
Windows userland post-exploitation for credential harvesting, monitoring, AMSI/ETW bypass, and stealth operations
Kubernetes post-exploitation for container escape, secret extraction, RBAC abuse, and cluster persistence
基于 SOC 职业分类
正在显示 SKILL.md
| name | wstg-clnt-08 |
| description | Testing for Cross-Site Flashing |
| category | client-side |
| owasp_id | WSTG-CLNT-08 |
| version | 1.0.0 |
| author | cyberstrike-official |
| tags | ["client-side","javascript","dom","cors","wstg","clnt"] |
| tech_stack | ["html","javascript"] |
| cwe_ids | ["CWE-1021"] |
| chains_with | [] |
| prerequisites | [] |
| severity_boost | {} |
WSTG-CLNT-08
Testing for Cross-Site Flashing
Cross-Site Flashing (XSF) vulnerabilities occur in Flash/SWF applications when user input is improperly handled. Although Flash is deprecated, legacy applications may still use it. Similar vulnerabilities can exist in other rich media technologies.
#!/bin/bash
TARGET="target.com"
# Find SWF files
curl -s "https://$TARGET" | grep -oP '[^"]+\.swf'
# Check crossdomain.xml
curl -s "https://$TARGET/crossdomain.xml"
# Common paths
paths=("/crossdomain.xml" "/clientaccesspolicy.xml" "/flash/crossdomain.xml")
for path in "${paths[@]}"; do
curl -s "https://$TARGET$path"
done
<!-- Vulnerable configuration -->
<?xml version="1.0"?>
<cross-domain-policy>
<allow-access-from domain="*"/>
<!-- Restrict cross-domain access -->
<?xml version="1.0"?>
<!DOCTYPE cross-domain-policy SYSTEM "http://www.adobe.com/xml/dtds/cross-domain-policy.dtd">
<cross-domain-policy>
<site-control permitted-cross-domain-policies="master-only"/>
<allow-access-from domain="www.trusted.com" secure="true"/>
</cross-domain-policy>
| Finding | CVSS | Severity |
|---|---|---|
| Wildcard crossdomain.xml | 5.3 | Medium |
| XSF vulnerability | 6.1 | Medium |
[ ] Flash files identified
[ ] crossdomain.xml analyzed
[ ] SWF parameters tested
[ ] clientaccesspolicy.xml checked
[ ] Findings documented