
yaklang
Showing 1–60 of 103 skills · Page 1 of 2
yaklang / dependency-confusion
2.3kSupply-chain testing via package-manager dependency confusion: when internal package names resolve to attacker-controlled public registries, leading to malicious install and script execution. Use for npm/pip/gem/Maven/Composer/Docker manifest review and authorized red-team supply-chain exercises.
yaklang / http-parameter-pollution
2.3kHTTP Parameter Pollution (HPP): duplicate query/body keys parsed differently by servers, proxies, WAFs, and app frameworks
yaklang / linux-lateral-movement
2.3kLinux lateral movement playbook. Use after gaining initial access to pivot across Linux hosts via SSH hijacking, credential harvesting, internal pivoting, D-Bus exploitation, sudo token reuse, and shared filesystem abuse.
yaklang / prototype-pollution-advanced
2.3kAdvanced prototype pollution playbook — server-side RCE, client-side gadgets, filter bypasses, and detection techniques. Companion to ../prototype-pollution/ for basics
yaklang / ssrf-server-side-request-forgery
2.3kAlso load SCENARIOS.md when you need: - WebLogic SSRF (CVE-2014-4210) — `uddiexplorer/SearchPublicRegistries.jsp` + `operator` parameter + `%0D%0A` CRLF to inject Redis commands - SSRF → internal Redis → write crontab reverse shell complete payload chain - DNS Rebinding deep dive — TTL=0 trick, init…
yaklang / xslt-injection
2.3kXSLT injection testing: processor fingerprinting, XXE and document() SSRF, EXSLT write primitives, PHP/Java/.NET extension RCE surfaces
yaklang / xss-cross-site-scripting
2.3kAlso load SCENARIOS.md when you need: - Django debug page XSS (CVE-2017-12794) — duplicate key error → unescaped exception → XSS - UTF-7 XSS for legacy IE environments (`+ADw-script+AD4-`) - HttpOnly bypass methodology — proxy-the-browser, session riding, CSRF-via-XSS - XS-Leaks side channel attacks…
yaklang / xxe-xml-external-entity
2.3kAlso load SCENARIOS.md when you need: - Apache Solr XXE + RCE chain (CVE-2017-12629) — XXE to read config, then VelocityResponseWriter for RCE - Office docx XXE step-by-step — unzip → inject DOCTYPE into `word/document.xml` or `[Content_Types].xml` → repackage → upload - DOCTYPE-based blind SSRF — `…
yaklang / attack-surface-mapping
2.3kDraw a testable attack surface from one authorized target URL or one application
yaklang / auth-sec
2.3kEntry P1 category router for authentication and authorization
yaklang / csv-formula-injection
2.3kCSV/spreadsheet formula injection (DDE, Excel/LibreOffice, Google Sheets IMPORT*)
yaklang / file-access-vuln
2.3kEntry P1 category router for file access and upload workflows
yaklang / ghost-bits-cast-attack
2.3kJava "Ghost Bits" / Cast Attack playbook (Black Hat Asia 2026)
yaklang / hack
2.3kEntry P0 primary router and operating doctrine for HackSkills
yaklang / insecure-source-code-management
2.3kSource control and artifact exposure (.git, .svn, .hg, backups, .env)
yaklang / ssti-server-side-template-injection
2.3kBefore using full engine-specific exploitation, you can first load:
yaklang / websocket-security
2.3kWebSocket handshake, CSWSH, tooling (wsrepl, ws-harness, Burp), and common flaws
yaklang / active-directory-acl-abuse
2.3kActive Directory ACL abuse playbook
yaklang / active-directory-certificate-services
2.3kAD Certificate Services attack playbook
yaklang / active-directory-kerberos-attacks
2.3kKerberos attack playbook for Active Directory
yaklang / anti-debugging-techniques
2.3kAnti-debugging detection and bypass playbook
yaklang / api-auth-and-jwt-abuse
2.3kAPI authentication and JWT abuse playbook
yaklang / api-authorization-and-bola
2.3kAPI authorization and BOLA testing playbook
yaklang / api-recon-and-docs
2.3kAPI reconnaissance and documentation review playbook
yaklang / api-sec
2.3kEntry P1 category router for API security
yaklang / arbitrary-write-to-rce
2.3kArbitrary write to RCE playbook
yaklang / authbypass-authentication-flaws
2.3kAuthentication bypass testing playbook
yaklang / binary-protection-bypass
2.3kBinary protection bypass playbook
yaklang / browser-exploitation-v8
2.3kBrowser and V8 exploitation playbook
yaklang / business-logic-vuln
2.3kEntry P1 category router for business logic testing
yaklang / business-logic-vulnerabilities
2.3kBusiness logic vulnerability playbook
yaklang / classical-cipher-analysis
2.3kClassical cipher analysis playbook
yaklang / code-obfuscation-deobfuscation
2.3kCode obfuscation analysis and deobfuscation playbook
yaklang / cors-cross-origin-misconfiguration
2.3kCORS misconfiguration testing playbook
yaklang / csp-bypass-advanced
2.3kAdvanced Content Security Policy bypass techniques
yaklang / dangling-markup-injection
2.3kDangling markup injection playbook
yaklang / deserialization-insecure
2.3kInsecure deserialization playbook
yaklang / email-header-injection
2.3kEmail header injection and spoofing playbook
yaklang / expression-language-injection
2.3kExpression Language injection playbook
yaklang / format-string-exploitation
2.3kFormat string exploitation playbook
yaklang / graphql-and-hidden-parameters
2.3kGraphQL and hidden parameter testing playbook
yaklang / http-host-header-attacks
2.3kHTTP Host header injection and routing abuse playbook
yaklang / http2-specific-attacks
2.3kHTTP/2 protocol-specific attack playbook
yaklang / idor-broken-object-authorization
2.3kIDOR and broken object authorization testing playbook
yaklang / injection-checking
2.3kEntry P1 category router for injection testing
yaklang / jwt-oauth-token-attacks
2.3kJWT and OAuth token attack playbook
yaklang / kernel-exploitation
2.3kLinux kernel exploitation playbook
yaklang / kubernetes-pentesting
2.3kKubernetes penetration testing playbook
yaklang / lattice-crypto-attacks
2.3kLattice-based cryptanalysis playbook
yaklang / linux-privilege-escalation
2.3kLinux privilege escalation playbook
yaklang / linux-security-bypass
2.3kLinux security mechanism bypass playbook
yaklang / macos-process-injection
2.3kmacOS process injection playbook
yaklang / macos-security-bypass
2.3kmacOS security bypass playbook
yaklang / memory-forensics-volatility
2.3kMemory forensics playbook using Volatility 2/3
yaklang / mobile-ssl-pinning-bypass
2.3kMobile SSL pinning bypass playbook
yaklang / network-protocol-attacks
2.3kNetwork protocol attack playbook
yaklang / ntlm-relay-coercion
2.3kNTLM relay and authentication coercion playbook
yaklang / oauth-oidc-misconfiguration
2.3kOAuth and OIDC misconfiguration testing playbook
yaklang / path-traversal-lfi
2.3kPath traversal and LFI playbook
yaklang / prototype-pollution
2.3kPrototype pollution testing for JavaScript stacks