Skip to main content

这个仓库中的 skills

uphiago/recon-skills - 第 2 页

SkillsMP 已收集 uphiago/recon-skills 中的 145 个 Skill。打开任一 Skill 可查看来源和详情。

uphiago/recon-skills

已展示 40 / 145 个已收集 Skill。

职业分类
信息安全分析师
描述

Pick sectors, compile targets, batch recon for campaigns.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Map subdomains via crt.sh and subfinder at recon kickoff.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Use at the START of any bug bounty hunting session, when switching targets, or when feeling lost about what to do next. Master orchestrator that combines the 5-phase non-linear hunting workflow with the critical thinking framework (developer psychology,…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Master bug bounty orchestrator — full pipeline: recon, pre-hunt learning, vulnerability hunting (30+ classes), A-to-B chaining, AI/LLM testing (ASI01-ASI10), language-specific grep, bypass tables, and reporting (7-question gate, CVSS 3.1, human-tone…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Hunt HTTP request smuggling (CL.TE, TE.CL, H2.CL, H2.TE). Cause: front-end proxy and back-end server disagree on where one request ends and the next begins (Content-Length vs Transfer-Encoding header parsing inconsistency). CL.TE: front-end uses CL, back uses…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Meme coin and token security audit — rug pull detection (honeypot, hidden mint, fee manipulation, LP lock bypass), Solana SPL token analysis (freeze authority, mint authority, metadata mutability), Token-2022 extension risks (transfer hooks, permanent…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Security payloads, bypass tables, wordlists, gf pattern names, always-rejected bug list, and conditionally-valid-with-chain table. Use when you need specific payloads for XSS/SSRF/SQLi/XXE/NoSQLi/command injection/SSTI/IDOR/path-traversal/HTTP…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Finding validation before writing any report — 7-Question Gate (all 7 questions), 4 pre-submission gates, always-rejected list, conditionally valid with chain table, CVSS 3.1 quick reference, severity decision guide, report title formula, 60-second pre-submit…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Smart contract security audit — 10 DeFi bug classes (accounting desync, access control, incomplete path, off-by-one, oracle, ERC4626, reentrancy, flash loan, signature replay, proxy), pre-dive kill signals (TVL < $500K etc), Foundry PoC template, grep…

原文语言:英语

更新
职业分类
软件开发工程师
描述

Screenshot all live hosts for rapid visual triage and technology fingerprinting.

原文语言:英语

更新
职业分类
软件开发工程师
描述

Complete bug bounty workflow — recon (subdomain enumeration, asset discovery, fingerprinting, HackerOne scope, source code audit), pre-hunt learning, vuln hunting (30+ classes), A-to-B chaining, AI/LLM testing, bypass tables, language-specific grep,…

原文语言:英语

更新
职业分类
其他计算机职业
描述

Skill-set loader for /hunt orchestrator. Fingerprints the target, picks the right platform attack skills, and loads the Red Team or WAPT skill set. Use when /hunt has just received a mode answer (redteam or wapt + blackbox|greybox) and needs to load the…

原文语言:英语

更新
职业分类
软件开发工程师
描述

Hunt error leakage, DVCS exposure, source maps, config files, and differential oracles.

原文语言:英语

更新
职业分类
软件开发工程师
描述

Hunt Laravel specific vulnerabilities — Debug mode leakage (APP_DEBUG=true exposes full stack trace + env vars), Laravel Telescope/Horizon dashboard unauthorized access, Ignition RCE (CVE-2021-3129), Signed URL manipulation, Queue Worker abuse, mass…

原文语言:英语

更新
职业分类
软件开发工程师
描述

Hunting skill for misc vulnerabilities. Built from 225 public bug bounty reports. Use when hunting misc on any target.

原文语言:英语

更新
职业分类
软件开发工程师
描述

Hunt source code and build artifact leakage — JavaScript source maps (.js.map) reconstructing TypeScript/ES6 source, Swagger/OpenAPI JSON endpoint discovery, .env/.git exposure, webpack chunks with hardcoded secrets, robots.txt/security.txt recon, build-info…

原文语言:英语

更新
职业分类
软件开发工程师
描述

Hunting skill for sqli vulnerabilities. Built from 12 public bug bounty reports including modern NoSQL injection (Rocket.Chat CVE-2021-22911 MongoDB $regex, Mongoose ORM CVE-2024-53900 $where bypass), modern ORM raw-fragment SQLi (Django CVE-2024-42005,…

原文语言:英语

更新
职业分类
软件开发工程师
描述

Hunt TLS/SSL and DNS misconfigurations — missing HSTS (downgrade attack), weak cipher suites, expired/invalid certificates, mTLS bypass, missing SPF/DKIM/DMARC (email spoofing), DNS Zone Transfer (AXFR), dangling CNAME subdomain takeover, CAA records. Most of…

原文语言:英语

更新
职业分类
软件开发工程师
描述

Hunting skill for xss vulnerabilities. Built from 174 public bug bounty reports. Use when hunting xss on any target.

原文语言:英语

更新
职业分类
软件开发工程师
描述

Operational arsenal for authorized external red-team and bug-bounty recon. Concrete probes, wordlists, regexes, dorks, curl one-liners for: subdomain enum, GraphQL/Swagger/REST discovery, identity fabric (Entra/Okta/ADFS/Google/SAML/M365 deep —…

原文语言:英语

更新
职业分类
软件开发工程师
描述

External recon for software supply-chain attack surface — package-namespace squatting candidates, dependency-confusion vulnerabilities, GitHub Actions injection openings, container image registry exposure, SBOM mining, internal-package-name leakage, and CI/CD…

原文语言:英语

更新
职业分类
软件开发工程师
描述

Scripts and workflows to batch-test popular WordPress plugin CVEs across hundreds of domains. Covers automated plugin detection, version extraction from readme.txt, CVE matching against a curated matrix of high-impact plugin vulnerabilities (ElementsKit,…

原文语言:英语

更新
职业分类
软件开发工程师
描述

Hunt cloud / infrastructure misconfigurations. AWS: public S3 buckets (s3:GetObject anonymous), permissive bucket policies (PutObjectAcl public-write), exposed CloudFront origin, public Lambda function URL, public RDS snapshot, IAM credentials in JS bundles,…

原文语言:英语

更新
职业分类
软件开发工程师
描述

Hunting skill for ssrf vulnerabilities. Built from 15 public bug bounty reports including AWS metadata SSRF (HackerOne $25k Analytics PDF, Shopify Exchange $25k, Capital One 106M-record breach, Dropbox/HelloSign $4,913), GCP metadata SSRF (Snapchat $4k),…

原文语言:英语

更新
职业分类
软件开发工程师
描述

Map organization IP infrastructure via ASN, CIDR, TLD expansion, and reverse DNS.

原文语言:英语

更新
职业分类
软件开发工程师
描述

Hunt broken function-level authorization via verb drift, route shadowing, and transport gaps.

原文语言:英语

更新
职业分类
软件开发工程师
描述

Hunt Django-specific vulnerabilities: DRF permission gaps, ORM injection, and admin exploitation.

原文语言:英语

更新
职业分类
软件开发工程师
描述

Hunt FastAPI-specific vulnerabilities: dependency injection gaps, Pydantic coercion, and OpenAPI mining.

原文语言:英语

更新
职业分类
软件开发工程师
描述

Hunt Firebase / Firestore / GCP exploitation — Firebase API key discovery in JS bundles, anonymous auth via signUp endpoint, Firestore collection enumeration with anon key, Realtime Database read/write without auth, Firebase Storage bucket listing, Firebase…

原文语言:英语

更新
职业分类
软件开发工程师
描述

Hunt Local File Inclusion (LFI), Remote File Inclusion (RFI), and Path Traversal — /etc/passwd read, log poisoning → RCE, PHP filter-chain RCE (no upload needed), php:// / data:// / zip:// / phar:// wrappers, RFI via allow_url_include, directory traversal…

原文语言:英语

更新
职业分类
软件开发工程师
描述

Hunt mass assignment via sensitive field injection and ORM framework exploitation.

原文语言:英语

更新
职业分类
软件开发工程师
描述

Hunt Model Context Protocol (MCP) vulnerabilities in AI-tool integration systems.

原文语言:英语

更新
职业分类
软件开发工程师
描述

Hunt NestJS-specific vulnerabilities: guard bypass, decorator gaps, and microservice auth drift.

原文语言:英语

更新
职业分类
软件开发工程师
描述

Hunt Node.js specific vulnerabilities — Prototype Pollution → RCE chains (lodash/merge/assign), Express trust proxy misconfiguration, child_process/eval injection, template engine SSTI (EJS/Pug/Handlebars), path traversal in file servers, require() injection,…

原文语言:英语

更新
职业分类
软件开发工程师
描述

Hunting skill for oauth vulnerabilities. Built from 19 public bug bounty reports. Use when hunting oauth on any target.

原文语言:英语

更新
职业分类
软件开发工程师
描述

Hunt client-side and server-side prototype pollution for XSS, auth bypass, and RCE.

原文语言:英语

更新
职业分类
软件开发工程师
描述

Hunting skill for race condition vulnerabilities. Built from 12 public bug bounty reports including modern HTTP/2 single-packet attack cases (James Kettle DEF CON 2023 "Smashing the State Machine"; RyotaK / Flatt Security 10,000-request first-sequence-sync…

原文语言:英语

更新
职业分类
软件开发工程师
描述

Hunt Supabase exploitation — Supabase anon key discovery in JS bundles, REST API table enumeration with anon key, Row Level Security (RLS) bypass via missing organization_id check, RPC function abuse returning cross-organization data, Storage bucket listing,…

原文语言:英语

更新
职业分类
软件开发工程师
描述

Microsoft 365 / Entra ID red-team attack chain — current 2026 reality. AADSTS code reference, user enumeration vectors (with hardening status), Smart Lockout math, Conditional Access bypass options, ROPC + SAML SSO browser flow, Burp/Playwright templates.…

原文语言:英语

更新
职业分类
软件开发工程师
描述

Methodology for detecting client SOC patches, attacker activity, and security-state changes that occur DURING a red-team engagement — and converting those observations into deliverable findings. Built from authorized red-team work where the client patched a…

原文语言:英语

更新
已展示 40 / 145 个已收集 Skill。