Web高级安全测试 — 注入攻击族、协议安全、认证与逻辑漏洞、文件与部署安全、现代Web攻击面,含完整Playbook
日本語の概要は準備中です。原文の説明を表示しています。
28 件 ・ 関連度順
概要と使いどころ
Web高级安全测试 — 注入攻击族、协议安全、认证与逻辑漏洞、文件与部署安全、现代Web攻击面,含完整Playbook
日本語の概要は準備中です。原文の説明を表示しています。
OWASP Top 10 testing, injection vulnerability detection, API security assessment, authentication testing, and web vulnerability reporting for authorized assessments
日本語の概要は準備中です。原文の説明を表示しています。
Test web application security with Burp Suite. Use when a user asks to intercept HTTP traffic, test for web vulnerabilities, fuzz API endpoints, analyze authentication flows, or perform manual web application pentesting.
日本語の概要は準備中です。原文の説明を表示しています。
Security review and implementation guidance for Odoo website, portal, public controllers, JSON routes, QWeb output, and browser-facing assets. Use when exposing Odoo data over HTTP, adding portal/public pages or forms, using sudo, handling tokens, rendering HTML, or reviewing web attack surfaces.
日本語の概要は準備中です。原文の説明を表示しています。
Identifying and validating cross-site scripting vulnerabilities using Burp Suite's scanner, intruder, and repeater tools during authorized security assessments.
日本語の概要は準備中です。原文の説明を表示しています。
Identify and exploit Server-Side Request Forgery (SSRF) vulnerabilities in Next.js applications, specifically focusing on insecure server actions or API routes fetching user-controlled URLs on the server-side.
日本語の概要は準備中です。原文の説明を表示しています。
Identify and exploit misconfigured Spring Boot Actuator endpoints. This skill covers how to extract sensitive configuration details, heap dumps, environment variables, and ultimately escalating to Remote Code Execution (RCE) via `spring-cloud-starter` vulnerabilities.
日本語の概要は準備中です。原文の説明を表示しています。
Identify and exploit Prototype Pollution vulnerabilities in JavaScript/Node.js applications. This skill covers the progression from polluting `Object.prototype` to identifying functional gadgets (like `child_process.spawn`) to achieve Remote Code Execution (RCE).
日本語の概要は準備中です。原文の説明を表示しています。
Identify and exploit logic flaws in OAuth implementations, focusing specifically on the absence or improper validation of the `state` parameter, which leads to Cross-Site Request Forgery (CSRF) and account takeover (ATO).
日本語の概要は準備中です。原文の説明を表示しています。
Identify and exploit Prototype Pollution vulnerabilities in JavaScript applications to achieve client-side Cross-Site Scripting (XSS), bypass authentication, or execute Remote Code Execution (RCE) on Node.js servers by manipulating the core Object prototype.
日本語の概要は準備中です。原文の説明を表示しています。
Exploit advanced HTTP Request Smuggling combining Transfer-Encoding vulnerabilities (TE.TE). By obscuring the Transfer-Encoding header, an attacker forces desynchronization between a frontend proxy (which processes the request one way) and the backend server (which processes it another way), allowing the smuggling of malicious requests to bypass security controls or poison caches.
日本語の概要は準備中です。原文の説明を表示しています。
Identify and exploit SQL Injection vulnerabilities in Django applications, specifically focusing on edge cases involving raw querysets (`RawSQL`), improper use of `.extra()`, and poorly sanitized filters where Django's typical ORM protections are bypassed.
日本語の概要は準備中です。原文の説明を表示しています。
Exploit Document Object Model (DOM) Based Cross-Site Scripting (XSS) vulnerabilities. Unlike Reflected or Stored XSS, the attack payload is executed purely on the client-side as a result of modifying the DOM environment, often without the payload ever reaching the backend server.
日本語の概要は準備中です。原文の説明を表示しています。
Master Burp Suite Professional for comprehensive web application security testing. Use this skill when performing manual web application assessments with Burp Suite including proxy interception, Scanner automation, Intruder attacks, Repeater analysis, and extension integration. Covers advanced techniques like match-and-replace rules, macro authentication, Collaborator for OOB testing, and Turbo Intruder for high-speed fuzzing.
日本語の概要は準備中です。原文の説明を表示しています。
Exploit pervasive logical flaws in Multi-Factor Authentication (MFA/2FA) implementations to bypass the secondary authentication challenge entirely. Techniques include response manipulation, referal spoofing, token reuse, and predictable backup codes.
日本語の概要は準備中です。原文の説明を表示しています。
Aggregate SAST, SCA, DAST, secrets, API, frontend, and backend security checks into one report.
日本語の概要は準備中です。原文の説明を表示しています。
Run user-authorized black-box web security tests and evidence-based reports. Use for 黑盒安全测试、渗透测试、数据泄露、未授权访问、公开 JS/API、登录爆破防护、CORS 或安全响应头检查。
日本語の概要は準備中です。原文の説明を表示しています。
Develop Burp Suite extensions in Java (Montoya API) or Python (Jython). Supports creating HTTP listeners, scanner checks, intruder payloads, UI tabs, and context menus. Includes project templates, multi-platform setup guides, and best practices.
日本語の概要は準備中です。原文の説明を表示しています。
Identifying and exploiting OAuth 2.0 and OpenID Connect misconfigurations including redirect URI manipulation, token leakage, and authorization code theft during security assessments.
日本語の概要は準備中です。原文の説明を表示しています。
Detect and exploit NoSQL injection vulnerabilities in MongoDB, CouchDB, and other NoSQL databases to demonstrate authentication bypass, data extraction, and unauthorized access risks.
日本語の概要は準備中です。原文の説明を表示しています。
Identifying and exploiting insecure deserialization vulnerabilities in Java, PHP, Python, and .NET applications to achieve remote code execution during authorized penetration tests.
日本語の概要は準備中です。原文の説明を表示しています。
Exploit PHP type juggling vulnerabilities caused by loose comparison operators to bypass authentication, circumvent hash verification, and manipulate application logic through type coercion attacks.
日本語の概要は準備中です。原文の説明を表示しています。
Detecting and exploiting HTTP request smuggling vulnerabilities caused by Content-Length and Transfer-Encoding parsing discrepancies between front-end and back-end servers.
日本語の概要は準備中です。原文の説明を表示しています。
Testing WebSocket implementations for authentication bypass, cross-site hijacking, injection attacks, and insecure message handling during authorized security assessments.
日本語の概要は準備中です。原文の説明を表示しています。