
uphiago
Showing 1–60 of 81 skills · Page 1 of 2
uphiago / cors-chain-automation
1.3kUse when a bounded list of authorized API endpoints needs consistent CORS triage before browser validation.
uphiago / deep-invade
1.3kDeep pentest WP: SSRF, plugin CVE, JS mine, port scan chain.
uphiago / firebase-supabase-attack
1.3kExploit Firebase/Supabase for data via JS config leak probe.
uphiago / xmlrpc-exploitation
1.3kExploit XMLRPC multicall, pingback for brute force and SSRF.
uphiago / api-noauth-hunt
1.3kUse when an API may expose data or privileged operations without authentication.
uphiago / asn-infrastructure-mapping
1.3kMap organization IP infrastructure via ASN, CIDR, TLD expansion, and reverse DNS.
uphiago / cache-attack
1.3kPoison CDN cache or deceive when X-Cache header is detected.
uphiago / cloud-iam-deep
1.3kGCP/AWS/Azure cloud exploitation -- Cloud Functions, Firestore, Cloud Run, S3, MinIO, Blob Storage, SA keys
uphiago / cms-detection
1.3kIdentify CMS, frameworks, and server technology stacks on live hosts.
uphiago / exchange-owa-attack
1.3kExchange/OWA NTLM AD leak, spray attack when mail subdomain.
uphiago / flask-werkzeug-attack
1.3kExploit Flask/Werkzeug debugger exposure for traceback and SECRET leaks.
uphiago / github-secret-hunting
1.3kFind leaked API keys, tokens, and credentials in public GitHub repositories.
uphiago / hardcoded-credential-hunt
1.3kDetect hardcoded passwords in HTML forms, JavaScript, and API responses.
uphiago / http2-header-impersonation
1.3kSpoof HTTP/2 SETTINGS frames and pseudo-header order per browser profile.
uphiago / humanize-automation
1.3kHuman-like mouse, keyboard and scroll behavior for behavioral bot bypass.
uphiago / hunt-broken-function-level-auth
1.3kHunt broken function-level authorization via verb drift, route shadowing, and transport gaps.
uphiago / hunt-fastapi
1.3kHunt FastAPI-specific vulnerabilities: dependency injection gaps, Pydantic coercion, and OpenAPI mining.
uphiago / hunt-information-disclosure
1.3kHunt error leakage, DVCS exposure, source maps, config files, and differential oracles.
uphiago / hunt-mass-assignment
1.3kHunt mass assignment via sensitive field injection and ORM framework exploitation.
uphiago / hunt-mcp-security
1.3kHunt Model Context Protocol (MCP) vulnerabilities in AI-tool integration systems.
uphiago / hunt-nestjs
1.3kHunt NestJS-specific vulnerabilities: guard bypass, decorator gaps, and microservice auth drift.
uphiago / hunt-prototype-pollution
1.3kHunt client-side and server-side prototype pollution for XSS, auth bypass, and RCE.
uphiago / hunt-wordpress
1.3kUse when an authorized target exposes WordPress core, plugin, theme, REST, or XML-RPC behavior.
uphiago / js-secrets-extraction
1.3kAnalyze JS bundles and source maps for hardcoded secrets, API keys, JWTs, and internal endpoints
uphiago / origin-ip-discovery
1.3kDiscover origin IPs behind CDN/WAF via favicon hash, DNS history, and SSL certs.
uphiago / port-service-discovery
1.3kNmap scan for MySQL, Redis, FTP, SSH, internal API services.
uphiago / recon-playbook
1.3kUse when starting or restructuring an authorized external web and API assessment.
uphiago / s3-minio-content-type-xss
1.3kExploit public bucket Content-Type override for stored XSS on target origin.
uphiago / scada-hikvision-isapi
1.3kEnumerate Hikvision ISAPI endpoints on SCADA and IoT web interfaces.
uphiago / stealth-browser-launch
1.3kLaunch stealth Chromium with C++ fingerprint patches for anti-bot bypass.
uphiago / tls-fingerprint-impersonation
1.3kSpoof TLS ClientHello and JA4 fingerprints for browser impersonation.
uphiago / unauth-api-flow-hijack
1.3kExploit unauthenticated multi-step API flows without credentials.
uphiago / visual-recon
1.3kScreenshot all live hosts for rapid visual triage and technology fingerprinting.
uphiago / web-enumeration
1.3kSensitive file scanning, path traversal bypass, vHost enum, .env extract, log mining, Varnish detect
uphiago / pentest-playbook
1.3k7-phase pentest pipeline from passive recon to exploitation.
uphiago / google-dorks-catalog
1.3kHigh-precision Google dorks for exposed configs, secrets, and credentials -- real-world validated
uphiago / hunt-django
1.3kHunt Django-specific vulnerabilities: DRF permission gaps, ORM injection, and admin exploitation.
uphiago / subdomain-takeover-hunt
1.3kDetect and verify subdomain takeover via dangling CNAME to unclaimed services.
uphiago / vhost-enumeration
1.3kDiscover hidden virtual hosts via Host header fuzzing and SSL certificate parsing.
uphiago / bb-local-toolkit
1.3kComplete bug bounty workflow — recon (subdomain enumeration, asset discovery, fingerprinting, HackerOne scope, source code audit), pre-hunt learning, vuln hunting (30+ classes), A-to-B chaining, AI/LLM testing, bypass tables, language-specific grep, reporting. Use for ANY bug bounty task.
uphiago / bug-bounty
1.3kMaster bug bounty orchestrator — full pipeline: recon, pre-hunt learning, vulnerability hunting (30+ classes), A-to-B chaining, AI/LLM testing (ASI01-ASI10), language-specific grep, bypass tables, and reporting (7-question gate, CVSS 3.1, human-tone templates).
uphiago / hunt-api-misconfig
1.3kHunt API security misconfiguration — mass assignment, JWT attacks, prototype pollution, HTTP verb tampering. Mass assignment: send {is_admin:true, role:admin, verified:true} on profile/account/reset endpoints — server blindly applies.
uphiago / hunt-brute-force
1.3kHunt Missing/Weak Rate Limiting — login brute force, OTP/2FA brute force (10^6 keyspace), password-reset-token brute, credential stuffing, username/email enumeration via error-string / status-code / timing differences, weak password policy, missing CAPTCHA, IP-based rate-limit bypass via X-Forwarded…
uphiago / hunt-firebase
1.3kHunt Firebase / Firestore / GCP exploitation — Firebase API key discovery in JS bundles, anonymous auth via signUp endpoint, Firestore collection enumeration with anon key, Realtime Database read/write without auth, Firebase Storage bucket listing, Firebase Hosting detection, GCP service account JSO…
uphiago / hunt-llm-ai
1.3kHunt LLM/AI feature bugs — prompt injection, indirect injection, exfiltration viatool-use/markdown, ASCII smuggling, agentic AI security (OWASP Agentic Apps 2026, ASI01-ASI10).
uphiago / hunt-schema-enumeration
1.3kEnumerate hidden tables, fields, and endpoints via API error hints. Agnostic across PostgREST, Zod, FastAPI, GraphQL, and REST.
uphiago / hunt-supabase
1.3kHunt Supabase exploitation — Supabase anon key discovery in JS bundles, REST API table enumeration with anon key, Row Level Security (RLS) bypass via missing organization_id check, RPC function abuse returning cross-organization data, Storage bucket listing, Auth signUp/signIn with anon key, multi-t…
uphiago / hunt-write-gap
1.3kHunt read-protected write-gaping endpoints. PATCH/POST/DELETE without authorization while GET is protected. Agnostic: Supabase, Firebase, REST, GraphQL.
uphiago / llm-prompt-injection
1.3kUse when testing an authorized LLM application for prompt injection, system-prompt exposure, unsafe tool use, or RAG data-boundary failures.
uphiago / ops-proxyns
1.3kKernel-level proxy protection via proxy-ns — forces ALL traffic (TCP/UDP/DNS) through Tor using Linux network namespaces. Unlike proxychains, this works with Go/Rust/static binaries, prevents DNS leaks, and is impossible for applications to bypass.
uphiago / password-spray-methodology
1.3kEnd-to-end password spray playbook. User enumeration, lockout detection, password pattern generation, spray execution across all protocols, error code differentials, and engagement discipline.
uphiago / recon-sector-expansion
1.3kMulti-sector batch domain expansion — identify untested/under-tested sectors, generate candidate company domains (national chains, franchises, regionals), filter against existing test coverage, probe alive domains, and run the full testing pipeline across 20+ new targets in a single session.
uphiago / wp-plugin-automation
1.3kScripts and workflows to batch-test popular WordPress plugin CVEs across hundreds of domains. Covers automated plugin detection, version extraction from readme.txt, CVE matching against a curated matrix of high-impact plugin vulnerabilities (ElementsKit, Revslider, WPDM, Gravity Forms, Contact Form…
uphiago / wp-plugin-cve-hunt
1.3kSystematic approach to finding and testing CVEs for identified WordPress plugins. Covers plugin discovery, version extraction from multiple sources (readme.txt, assets, inline JS), CVE database cross-referencing with WPScan/Patchstack/NVD/NVD API, version-based vulnerability matching, exploitation P…
uphiago / wp-plugin-rest-auth-bypass
1.3kScan WordPress REST API plugin endpoints for unauthenticated state-changing operations — discover write endpoints (POST/PUT/PATCH/DELETE) exposed without auth, enumerate all plugin routes, and test for unauthorized content publishing, settings modification, and data leakage.
uphiago / wstg-web-pentest
1.3kFull WSTG-aligned web application pentest — 12-phase methodology from information gathering through reporting, with concrete commands, expected outputs, pitfalls, and verification per phase.
uphiago / cross-attack-chains
1.3kUse when two or more verified findings may combine into a higher-impact authorized attack path.
uphiago / cross-wave-delta-analysis
1.3kCompare recon waves to find NEW, REGRESSED, PERSISTENT findings.
uphiago / email-security
1.3kDMARC/SPF/DKIM check, email spoofing, SMTP test, and security header analysis
uphiago / hunt-metrics-exposure
1.3kHunt public /metrics, /health, and actuator endpoints leaking AI usage, DB pools, and operational intelligence.