Summary
任意文件上传的检测、绕过和利用。当目标有上传功能(头像、附件、导入)、multipart表单、文件管理接口时使用。包含扩展名/Content-Type/Magic Bytes三层绕过、.htaccess覆盖、.user.ini+auto_prepend_file、图片马二次渲染绕过、ZIP解压利用、上传路径猜解方法
wgpsec/aboutsecurity
npx skills add https://github.com/wgpsec/aboutsecurity
任意文件上传的检测、绕过和利用。当目标有上传功能(头像、附件、导入)、multipart表单、文件管理接口时使用。包含扩展名/Content-Type/Magic Bytes三层绕过、.htaccess覆盖、.user.ini+auto_prepend_file、图片马二次渲染绕过、ZIP解压利用、上传路径猜解方法
Related neighbors and high-traction skills in the same topics — useful to compare before installing.
PluginEval quality methodology — dimensions, rubrics, statistical methods, and scoring formulas…
5.9K installsAudit websites and landing pages for conversion issues and design evidence-based A/B tests. Use…
4.9K installs>- Reconnaissance and methodology playbook. Use when mapping assets, discovering endpoints, fin…
3.2K installs>- Use after competitive-platform-analysis has produced a tiered competitor set. Scores each co…
2.9K installsSPARC (Specification, Pseudocode, Architecture, Refinement, Completion) comprehensive developme…
1.2K installsMaster the complete penetration testing lifecycle from reconnaissance through reporting. This s…
711 installsOther skills from wgpsec/aboutsecurity · top by installs.
npx skills add https://github.com/wgpsec/aboutsecurity
Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.
master