Source

yaklang/hack-skills

103 skills · 303.3K combined installs

Skills from this source

#
Skill
Source
8W Activity
Installs
4418
crlf-injection >- CRLF injection playbook. Use when user input reaches HTTP response headers, Location redirects, Set-Cookie values,…
yaklang/hack-skills
2.9K
4421
web-cache-deception >- Web cache deception and poisoning playbook. Use when CDN, reverse proxy, or application caching may serve sensitiv…
yaklang/hack-skills
2.9K
4425
dependency-confusion >- Supply-chain testing via package-manager dependency confusion: when internal package names resolve to attacker-con…
yaklang/hack-skills
2.9K
4432
mobile-ssl-pinning-bypass >- Mobile SSL pinning bypass playbook. Use when intercepting HTTPS traffic from mobile applications that implement ce…
yaklang/hack-skills
2.9K
4439
expression-language-injection >- Expression Language injection playbook. Use when Java EL, SpEL, OGNL, or MVEL expressions may evaluate attacker-co…
yaklang/hack-skills
2.9K
4440
http-host-header-attacks >- HTTP Host header injection and routing abuse playbook. Use when the application trusts the Host header for generat…
yaklang/hack-skills
2.9K
4452
csv-formula-injection >- CSV/spreadsheet formula injection (DDE, Excel/LibreOffice, Google Sheets IMPORT*). Use when exports, imports, or u…
yaklang/hack-skills
2.9K
4453
jndi-injection >- JNDI injection playbook. Use when Java applications perform JNDI lookups with attacker-controlled names, especiall…
yaklang/hack-skills
2.9K
4451
subdomain-takeover >- Subdomain takeover detection and exploitation playbook. Use when targets have dangling CNAME/NS/MX records pointin…
yaklang/hack-skills
2.9K
4457
active-directory-acl-abuse >- Active Directory ACL abuse playbook. Use when exploiting misconfigured AD permissions including GenericAll, WriteD…
yaklang/hack-skills
2.9K
4456
clickjacking >- Clickjacking playbook. Use when testing whether target pages can be framed, whether X-Frame-Options or CSP frame-a…
yaklang/hack-skills
2.9K
4462
saml-sso-assertion-attacks >- SAML SSO assertion attack playbook. Use when testing signature validation, assertion wrapping, audience restrictio…
yaklang/hack-skills
2.9K
4463
active-directory-kerberos-attacks >- Kerberos attack playbook for Active Directory. Use when targeting AD authentication via AS-REP roasting, Kerberoas…
yaklang/hack-skills
2.9K
4466
hash-attack-techniques >- Hash attack playbook. Use when exploiting length extension, MD5/SHA1 collisions, HMAC timing leaks, birthday attac…
yaklang/hack-skills
2.9K
4467
active-directory-certificate-services >- AD Certificate Services attack playbook. Use when targeting misconfigured AD CS for privilege escalation via ESC1-…
yaklang/hack-skills
2.9K
4470
http2-specific-attacks >- HTTP/2 protocol-specific attack playbook. Use when the target supports HTTP/2 and you need to exploit binary frami…
yaklang/hack-skills
2.9K
4471
arbitrary-write-to-rce >- Arbitrary write to RCE playbook. Use when you have an arbitrary write primitive (from heap exploitation, format st…
yaklang/hack-skills
2.9K
4478
ai-ml-security >- AI/ML security playbook. Use when assessing model supply chain attacks (pickle RCE, poisoned weights), adversarial…
yaklang/hack-skills
2.9K
4509
classical-cipher-analysis >- Classical cipher analysis playbook. Use when encountering substitution ciphers, Vigenere, transposition, XOR, or e…
yaklang/hack-skills
2.9K
4501
container-escape-techniques >- Container escape playbook. Use when operating inside a Docker container, LXC, or Kubernetes pod and need to escape…
yaklang/hack-skills
2.9K
4483
dangling-markup-injection >- Dangling markup injection playbook. Use when HTML injection is possible but JavaScript execution is blocked (CSP, …
yaklang/hack-skills
2.9K
4480
defi-attack-patterns >- DeFi attack pattern playbook. Use when analyzing flash loan attacks, price oracle manipulation, MEV sandwich attac…
yaklang/hack-skills
2.9K
4486
dns-rebinding-attacks >- DNS rebinding attack playbook. Use when testing applications that trust DNS resolution for origin checks, interact…
yaklang/hack-skills
2.9K
4503
email-header-injection >- Email header injection and spoofing playbook. Use when testing contact forms, email APIs, password reset flows, or…
yaklang/hack-skills
2.9K
4550
lattice-crypto-attacks >- Lattice-based cryptanalysis playbook. Use when attacking RSA via Coppersmith small roots, recovering DSA/ECDSA non…
yaklang/hack-skills
2.9K
4494
linux-lateral-movement >- Linux lateral movement playbook. Use after gaining initial access to pivot across Linux hosts via SSH hijacking, c…
yaklang/hack-skills
2.9K
4477
linux-privilege-escalation >- Linux privilege escalation playbook. Use when you have low-privilege shell access and need to escalate to root via…
yaklang/hack-skills
2.9K
4518
linux-security-bypass >- Linux security mechanism bypass playbook. Use when facing restricted bash/rbash, read-only or noexec filesystems, …
yaklang/hack-skills
2.9K
4507
memory-forensics-volatility >- Memory forensics playbook using Volatility 2/3. Use when analyzing memory dumps for malware analysis, credential e…
yaklang/hack-skills
2.9K
4484
network-protocol-attacks >- Network protocol attack playbook. Use when exploiting layer 2/3 protocols including ARP spoofing, LLMNR/NBT-NS/mDN…
yaklang/hack-skills
2.9K
4479
prototype-pollution >- Prototype pollution testing for JavaScript stacks. Use when user input is merged into objects (query parsers, JSON…
yaklang/hack-skills
2.9K
4532
prototype-pollution-advanced >- Advanced prototype pollution playbook — server-side RCE, client-side gadgets, filter bypasses, and detection techn…
yaklang/hack-skills
2.9K
4562
rsa-attack-techniques >- RSA attack playbook for CTF and real-world cryptanalysis. Use when given RSA parameters (n, e, c) and need to reco…
yaklang/hack-skills
2.9K
4558
sandbox-escape-techniques >- Sandbox escape playbook. Use when breaking out of Python sandbox, Lua sandbox, seccomp filter, chroot jail, contai…
yaklang/hack-skills
2.9K
4537
smart-contract-vulnerabilities >- Smart contract vulnerability playbook. Use when auditing Solidity/EVM contracts for reentrancy, integer overflow, …
yaklang/hack-skills
2.9K
4528
stack-overflow-and-rop >- Stack overflow and ROP playbook. Use when exploiting buffer overflows to hijack control flow via return address ov…
yaklang/hack-skills
2.9K
4553
steganography-techniques >- Steganography detection and extraction playbook. Use when analyzing images (LSB, PNG chunks, JPEG DCT, EXIF), audi…
yaklang/hack-skills
2.9K
4559
symmetric-cipher-attacks >- Symmetric cipher attack playbook. Use when exploiting block cipher mode weaknesses (CBC padding oracle, ECB cut-an…
yaklang/hack-skills
2.9K
4513
tunneling-and-pivoting >- Tunneling and pivoting playbook. Use when establishing network tunnels through compromised hosts including SSH tun…
yaklang/hack-skills
2.9K
4497
type-juggling >- PHP type juggling and weak comparison (`==`) bypass. Use when authentication, HMAC/signature checks, or token vali…
yaklang/hack-skills
2.9K
4482
windows-av-evasion >- AV/EDR evasion playbook for Windows. Use when bypassing AMSI, ETW, .NET assembly detection, shellcode execution, p…
yaklang/hack-skills
2.9K
4570
windows-lateral-movement >- Windows lateral movement playbook. Use when pivoting between Windows hosts via PsExec, WMI, WinRM, DCOM, RDP, pass…
yaklang/hack-skills
2.9K
4506
windows-privilege-escalation >- Windows local privilege escalation playbook. Use when you have low-privilege shell access on Windows and need to e…
yaklang/hack-skills
2.9K
4491
xslt-injection >- XSLT injection testing: processor fingerprinting, XXE and document() SSRF, EXSLT write primitives, PHP/Java/.NET e…
yaklang/hack-skills
2.9K
4593
macos-security-bypass >- macOS security bypass playbook. Use when targeting macOS endpoints and need to bypass TCC, Gatekeeper, SIP, sandbo…
yaklang/hack-skills
2.8K
4622
ntlm-relay-coercion >- NTLM relay and authentication coercion playbook. Use when capturing and relaying NTLM authentication to escalate p…
yaklang/hack-skills
2.8K
4652
macos-process-injection >- macOS process injection playbook. Use when you need to inject code into running or launching macOS processes via d…
yaklang/hack-skills
2.8K
4669
nosql-injection NoSQL injection playbook. Use when MongoDB-style operators, JSON query objects, flexible search filters, or backend q…
yaklang/hack-skills
2.8K
4668
upload-insecure-files Insecure file upload playbook. Use when testing upload validation, storage paths, processing pipelines, preview behav…
yaklang/hack-skills
2.8K
4718
reverse-shell-techniques Reverse shell techniques playbook. Use when establishing remote shells including language one-liners, encrypted shell…
yaklang/hack-skills
2.8K
Page 2 · 103 total Previous Next