Skip to main content

mitm-find-checksum

Find checksum and signature vulnerabilities. Use when user asks about hash validation, signature bypass, checksum manipulation, or cryptographic weaknesses.

跳到安装

来源信息

仓库
instavm/security-skills
最近来源活动
2026年3月23日 05:24
检测到的 SKILL.md 语言
英语
星标
86
分支
11

安装方式

默认使用会先检查来源的 Prompt;你也可以切换为直接命令,或下载本地副本。

检查来源文件

决定是否安装前,请先阅读 SKILL.md,以及 SkillsMP 当前展示的配套文件。

正在显示 SKILL.md

SKILL.md
来源说明 · 只读预览
name
mitm-find-checksum
description
Find checksum and signature vulnerabilities. Use when user asks about hash validation, signature bypass, checksum manipulation, or cryptographic weaknesses.
# Find Checksum/Signature Vulnerabilities Analyze the mitmproxy dump (log.txt) for checksum issues for: $ARGUMENTS > **Requires**: `log.txt` in the current directory. If it's missing, capture traffic first: > ```bash > mitmdump --set flow_detail=3 2>&1 | tee log.txt > ``` ## Vulnerability Types ### 1. Checksum Generation Exposed - API returns hash even on error - Can generate arbitrary checksums - Checksum endpoint accessible without auth ### 2. Weak Algorithms - MD5 without salt - SHA1 (deprecated) - Simple concatenation ### 3. Signature Collision - Same signature for different operations - Payment and refund use same algorithm - Parameter reordering gives same hash ### 4. Missing Fields in Checksum - Amount not in checksum calculation - Status not included - Critical fields missing ### 5. Checksum Not Validated - Hash parameter present but ignored - Backend accepts any hash value - Validation only on specific endpoints ## Patterns to Find ``` # Look for hash/checksum parameters hash=, checksum=, signature=, sign=, hmac= # Look for checksum generation APIs /generateHash, /getChecksum, /createSignature # Error responses with valid checksums "error": "...", "checksum": "valid_hash" ``` ## Testing Approach ```bash # Test if checksum is validated curl -X POST "https://target.com/callback" \ -d "amount=100&status=success&hash=invalid" # Test checksum generation curl "https://target.com/api/generateChecksum" \ -d "amount=1&status=success" ``` ## Output Format For each finding: - **Endpoint**: Where checksum is used - **Issue**: Type of vulnerability - **Algorithm**: If identifiable - **Fields Included**: What's in the hash - **Exploit**: How to bypass/generate - **Impact**: Payment fraud, data tampering - **Fix**: Strong HMAC, include all fields
在 GitHub 查看