Summary
Redis 未授权访问与利用。当发现目标开放 6379 端口、Redis 服务无认证或弱密码、需要从 Redis 获取敏感数据或实现远程命令执行时使用。覆盖未授权访问、数据窃取、crontab 写入 RCE、主从复制 RCE、模块加载 RCE、webshell 写入、SSH 公钥注入、Lua 脚本注入、Pub/Sub…
wgpsec/aboutsecurity
npx skills add https://github.com/wgpsec/aboutsecurity
Redis 未授权访问与利用。当发现目标开放 6379 端口、Redis 服务无认证或弱密码、需要从 Redis 获取敏感数据或实现远程命令执行时使用。覆盖未授权访问、数据窃取、crontab 写入 RCE、主从复制 RCE、模块加载 RCE、webshell 写入、SSH 公钥注入、Lua 脚本注入、Pub/Sub…
Related neighbors and high-traction skills in the same topics — useful to compare before installing.
Use when Codex is already in the attack-path-analysis phase of a security scan or the user expl…
287 installsBuild comprehensive attack trees to visualize threat paths. Use when mapping attack scenarios, …
11.9K installs>- JWT and OAuth token attack playbook. Use when validating token trust, signing algorithms, ke…
3.1K installs>- HTTP Host header injection and routing abuse playbook. Use when the application trusts the H…
2.9K installs>- SAML SSO assertion attack playbook. Use when testing signature validation, assertion wrappin…
2.9K installs>- Kerberos attack playbook for Active Directory. Use when targeting AD authentication via AS-R…
2.9K installsOther skills from wgpsec/aboutsecurity · top by installs.
npx skills add https://github.com/wgpsec/aboutsecurity
Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.
master