hunt-aspnet
Hunt ASP.NET-specific surface — ViewState deserialization (signed-only vs encrypted), machineKey recovery, dual-parser MAC-bypass anti-pattern, request-validator bypass, trace.axd/elmah.axd disclosure, load-balanced ViewState cross-node failures, SafeControl enumeration via reflection, customErrors…
Install / Use
npx skills add elementalsouls/Claude-BugHunter --skill hunt-aspnetInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
Development & EngineeringSupported Platforms
Our assessment of hunt-aspnet
hunt-aspnet scores 96/100 on our quality scale, 197th of 3,055 Development & Engineering skills we index (top 7%).
Its SKILL.md is 19 KB long, well organised into 28 sections with 9 code examples: a thorough specification that gives an agent plenty to work with.
With 4,669 GitHub stars, it is one of the more widely adopted skills in the catalogue.
Maintenance, license and trust
- The repository was last updated 2 days ago, so hunt-aspnet is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
hunt-aspnet compared with similar skills
All 4 of these similar skills score higher than hunt-aspnet; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| hunt-aspnet (this skill)by elementalsouls | 96 | 4.7k | 2d ago | SKILL.md |
| Agent-Reachby Panniantong | 100 | 85.9k | 12d ago | CLAUDE.md |
| ai-job-searchby MadsLorentzen | 100 | 44.3k | today | CLAUDE.md |
| claude-howtoby luongnv89 | 100 | 41.7k | 2d ago | CLAUDE.md |
| algorithmic-artby anthropics | 100 | 177.9k | 5d ago | SKILL.md |
Frequently asked questions
- How do I install hunt-aspnet?
- Run
npx skills add elementalsouls/Claude-BugHunter --skill hunt-aspnet. The install tabs above show the steps for each supported agent. - Which AI agents does hunt-aspnet work with?
- It is written for Zed, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is hunt-aspnet safe to use?
- It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is hunt-aspnet still maintained?
- The repository was last updated 2 days ago, so hunt-aspnet is actively maintained.
Skill content
View source on GitHubname: hunt-aspnet description: Hunt ASP.NET-specific surface — ViewState deserialization (signed-only vs encrypted), machineKey recovery, dual-parser MAC-bypass anti-pattern, request-validator bypass, trace.axd/elmah.axd disclosure, load-balanced ViewState cross-node failures, SafeControl enumeration via reflection, customErrors mode=Off stack-trace leaks, classic Webforms .aspx/.asmx/.svc surface. Built for ASP.NET Webforms + WCF + SharePoint farms. sources: github, authorized-engagement report_count: 1
Crown Jewel Targets
ASP.NET deserialization bugs pay among the highest amounts in bug bounty when they reach RCE. Even when patched, the disclosure-tier findings (signed-only ViewState, dual-parser differential, request-validator quirks) reliably pay Low-Medium.
Highest-value targets:
- SharePoint farms (any version — 2013/2016/2019/SE) — sign-only ViewState + permissive ToolPane.aspx + anonymous FormDigest creates the CVE-2025-53770 ToolShell precondition chain
- Telerik UI for ASP.NET AJAX —
Telerik.Web.UI.WebResource.axdis a documented RCE sink when keys leak (CVE-2017-11317, CVE-2017-11357, CVE-2019-18935) - Classic ASP.NET Webforms enterprise apps — banking portals, dealer portals, HR systems left on .NET Framework 4.x
- WCF services (
*.svc?WSDL) — often forgotten admin endpoints with looser auth than the main app - Sitecore CMS — ViewState + Sitecore-specific deserialization chains (CVE-2021-42237)
- DotNetNuke (DNN) — historic ViewState RCE chains
- Umbraco CMS — ViewState + custom deserialization sinks
Asset types that pay most: internet-reachable ASP.NET Webforms apps > WCF admin services > Telerik-integrated sites > Classic ASP.NET MVC with VSF (very rare)
Attack Surface Signals
Response headers indicating ASP.NET:
X-AspNet-Version: 4.0.30319 (classic — disclosure on its own)
X-Powered-By: ASP.NET
X-AspNetMvc-Version: 5.2
Server: Microsoft-IIS/10.0
Set-Cookie: ASP.NET_SessionId=...
Set-Cookie: .ASPXAUTH=... (Forms auth cookie)
Set-Cookie: .ASPXFORMSAUTH=...
Set-Cookie: ASP.NET_SessionId=...; SameSite=None (suggests cross-origin embedding)
Body signals (in form HTML):
<input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="..." />
<input type="hidden" name="__VIEWSTATEGENERATOR" id="__VIEWSTATEGENERATOR" value="..." />
<input type="hidden" name="__VIEWSTATEENCRYPTED" id="__VIEWSTATEENCRYPTED" value="" />
↑ EMPTY = signed-only, not encrypted = exploitable if key leaks
<input type="hidden" name="__EVENTVALIDATION" id="__EVENTVALIDATION" value="..." />
<input type="hidden" name="__REQUESTDIGEST" id="__REQUESTDIGEST" value="0x...,...">
↑ SharePoint CSRF token; if anon-issued, see hunt-sharepoint
URL patterns to probe:
/trace.axd (per-app trace viewer; sometimes anon-accessible)
/elmah.axd (ELMAH error log viewer)
/elmah.axd/?id=... (ELMAH RCE / stack-trace leak)
/*.svc (WCF services)
/*.svc?wsdl (WCF WSDL)
/*.svc/mex (Metadata Exchange)
/*.asmx (legacy SOAP)
/*.asmx?WSDL (legacy SOAP description)
/*.asmx?disco (legacy discovery)
/Telerik.Web.UI.WebResource.axd (Telerik AJAX components)
/ChartImg.axd (DataVisualization controls; historic deserialization)
/ScriptResource.axd (script resource handler; sometimes leaks paths)
/WebResource.axd (web resource handler)
/_vti_bin/* (SharePoint Web Service Forwarder)
/api/ (Web API 2.x is ASP.NET on classic framework)
/signin (often FedAuth / WS-Federation)
Tech-stack signals:
Server: Microsoft-IIS/10.0(or/8.5,/7.5) — confirmed Windows + IISX-AspNet-Versionheader — classic .NET Framework (4.x); .NET Core/5+ does NOT emit this- Cookies with
ASP.NET_SessionId,.ASPXAUTH,FedAuth— Forms or claims auth __VIEWSTATEin form bodies — Webforms (NOT MVC, NOT Razor Pages, NOT Blazor)MicrosoftSharePointTeamServicesheader (sometimes stripped by ELB but leaks instart.aspxbody) — SharePoint
Step-by-Step Hunting Methodology
-
Fingerprint the framework version. Trigger any 500 error (stale ViewState POST is a reliable way) and look for
Version Information: Microsoft .NET Framework Version:X.X.XXXXX; ASP.NET Version:X.X.XXXX.Xin the error body. This banner discloses both the runtime and ASP.NET-version-specific patch level. .NET 4.0.30319 + ASP.NET 4.8.x is the most common modern combination. -
Locate every form with
__VIEWSTATE. Spider the target and grep forname="__VIEWSTATE". Each is a candidate sink for deserialization attacks if MAC / encryption is bypassable. -
Check
__VIEWSTATEENCRYPTEDvalue. Empty (value="") means ViewState is signed-only via<machineKey>but NOT encrypted. Recovery of the validation key → arbitrary deserialization. Non-empty (value="something") means ViewState is BOTH signed and encrypted; both keys needed to forge. -
Test the ViewState parser-error differential (the dual-parser anti-pattern). Send 7+ ViewState shapes and classify responses:
- Trivial garbage (
AAAA) →"Validation of viewstate MAC failed" - Real prefix from current page →
"Validation of viewstate MAC failed" - Flipped-bit real ViewState →
"Validation of viewstate MAC failed" - Oversize (
A * 100000) →"Validation of viewstate MAC failed" - XML-shaped (
<xss/>) → "The state information is invalid for this page and might be corrupted" ← different parser path - LosFormatter-style prefix (
/wEPDwUKMTcxNzgyOTQwMmRkkz9p4lzA...) → "The state information is invalid for this page and might be corrupted"
The differential proves there are two distinct deserialization entry points, one of which dispatches BEFORE the MAC check on some payload shapes. Historically this enables MAC-before-parse-bypass exploits.
- Trivial garbage (
-
Look for load-balanced cross-node ViewState MAC failures. If POST gets a 500 with
"Validation of viewstate MAC failed. If this application is hosted by a Web Farm or cluster, ensure that <machineKey> configuration specifies the same validationKey...", the farm has multiple WFEs WITHOUT machineKey sync, or without sticky-session affinity. Operationally this breaks legit users; security-wise it confirms farm topology. -
Probe
trace.axdandelmah.axd. If either returns 200 anonymously, it's a Critical finding (trace leaks every request + headers + form data; ELMAH leaks every server error including stack traces). -
Enumerate WCF services (
.svc). For each, fetch?wsdland?mex(metadata exchange). MEX endpoints sometimes return full service contracts including admin operations. -
Test request-validator bypass. ASP.NET's request validator blocks
<in query strings by default. Bypass categories that may still get through:- HTML-entity-encoded payloads (
<script>— but these don't execute) - Encoded inside JSON / XML POST bodies (different content-type ≠ same validator)
- In path segments (not query) — validator scope depends on framework version
- In Cookie / Referer headers (varies)
- Inside
<%@ ... %>ASP directives if reached via WebDAV PUT (rare)
- HTML-entity-encoded payloads (
-
Check
customErrorsmode. If 500s expose full stack traces, framework versions, file paths, internal method names →customErrors mode="Off"is set. Should beRemoteOnlyfor production. -
Look for Telerik components.
Telerik.Web.UI.WebResource.axd?type=rauis the historic upload-to-RCE chain (CVE-2017-11317). ThedialogParametersHolderparameter chain (CVE-2019-18935) requires the encryption key but is otherwise RCE. -
SharePoint-specific deserialization paths — see
hunt-sharepointskill for the ToolPane.aspx + anonymous FormDigest + unencrypted ViewState chain. -
SafeControl enumeration via reflection. SharePoint's
Picker.aspx?PickerDialogType=<TypeName>(and DNN-equivalent endpoints) accept class names and return DIFFERENT error messages for "type exists but not whitelisted" vs "type does not exist." Feed a wordlist ofMicrosoft.SharePoint.*.WebControls.*types to enumerate the SafeControl list — useful for CVE-2019-0604-family hunting.
Payload & Detection Patterns
Stack-trace fingerprint (trigger via stale ViewState POST):
curl -sk -X POST "https://target.example/page.aspx" \
--data "__VIEWSTATE=AAAA&__VIEWSTATEGENERATOR=AAAA"
# Inspect body for:
# - "Validation of viewstate MAC failed" → confirms signed ViewState
# - "The state information is invalid for this page" → confirms ALTERNATE parser path
# - "Version Information: Microsoft .NET Framework Version:X.X.XXXXX" → exact patch level
# - "Microsoft.SharePoint.Client.ServerStub..." → SharePoint farm
ViewState parser-error differential probe (Python):
import requests, re, json
S = requests.Session(); S.verify = False
# Get fresh form
r = S.get("https://target.example/path/page.aspx")
real_vs = re.search(r'__VIEWSTATE" id="__VIEWSTATE" value="([^"]+)', r.text).group(1)
real_vsg = re.search(r'__VIEWSTATEGENERATOR" id="__VIEWSTATEGENERATOR" value="([^"]+)', r.text).group(1)
# Test 7 payload shapes
for label, vs in [
("trivial", "AAAA"),
("real", real_vs),
("flipped-bit", real_vs[:50] + "X" + real_vs[51:]),
("oversize", "A" * 100000),
("base64", "VGVzdE1hcmtlcjY3OFhZWg=="),
("xml-shaped", "<xss/>"),
("losformatter", "/wEPDwUKMTcxNzgyOTQwMmRkkz9p4lzA" + "A"*50),
]:
r = S.post("https://target.example/path/page.aspx",
data={"__VIEWSTATE": vs, "__VIEWSTATEGENERATOR": real_vsg})
title = re.search(r'<title>([^<]+)</title>', r.text)
title = title.group(1)[:100] if title else "—"
print(f" [{label:14s}] {r.status_code} {title}")
trace.axd anonymous check:
curl -sk -o /dev/null -w "%{http_code}\n" "https://target.example/trace.axd"
# 200 = full trace dump exposed → Critical
# 403 = mod set to localhost-only → check via X-Forwarded-For: 127.0.0.1
WCF service enumeration:
# Find all .svc files
curl -sk "https://target.example/" -o body.html
grep -oE '/[a-zA-Z0-9/_-]+\.svc' body.html | sort -u
# For each found:
curl -sk "https://target.example/Service.svc?wsdl" | xmllint --format - | head -60
Request-validator bypass categories:
# Default: <script>alert(1)</script> in ?q= → "Potentially dangerous Request.QueryString value detected"
# Bypasses that sometimes work:
?q=%3cscript%3e (URL-encoded — depends on validator config)
?q=<svg/onload=alert(1)> (depends on validator version)
?q=<%00script> (NUL-byte; older validators)
?q=javascript:alert(1) (no < at all — passes validator)
Cookie: foo=<script> (cookie body not validated by default)
Referer: http://x.com/<script> (referer not validated in classic ASP.NET)
Telerik exploit gate (CVE-2019-18935 — requires encryption keys):
# Fingerprint Telerik
curl -sk "https://target.example/Telerik.Web.UI.WebResource.axd?type=rau" -X POST
# If response is RadAsyncUploadHandler-style → Telerik present; try keys
# Public exploits require leaked machineKey AND telerikEncryptionKey
Common Root Causes
-
viewStateEncryption="Auto"defaults to signed-only on pages without sensitive ViewState data. Many SharePoint pages are configured this way. When__VIEWSTATEENCRYPTEDis empty, ViewState is signed-only — recovery ofvalidationKeyalone enables forgery. -
<machineKey>AutoGenerate in a Web Farm. Each WFE generates a different key on first boot; ViewSt
Truncated for display — read the full file on GitHub.
Related Skills
Agent-Reach
85.9kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
ai-job-search
44.3kThe job search that runs on your machine. AI job application framework built on Claude Code: evaluate postings, tailor CVs, write cover letters, prep interviews. Fork it and own it.
claude-howto
41.7kA visual, example-driven guide to Claude Code — from basic concepts to advanced agents, with copy-paste templates that bring immediate value.
algorithmic-art
177.9kCreating algorithmic art using p5.js with seeded randomness and interactive parameter exploration. Use this when users request creating art using code, generative art, algorithmic art, flow fields, or particle systems.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
