Browse Skills

11972 skills across 8 categories

All Skills (1897 found)

πŸ•΅οΈ
2026/08/12

HTTP Request Smuggling

HTTP Request Smuggling tests for CL.TE, TE.CL, TE.TE, and H2.CL desyncs between front-end and back-end servers. Use it to detect request boundary confusion, confirm impact, and demonstrate cache poisoning or auth bypass.
Quality
1.7K269
πŸ›‘οΈ
2026/08/12

IDOR Automated Testing

IDOR Automated Testing checks API endpoints for insecure direct object references using two accounts with different privilege levels. Use it to test horizontal and vertical access control bypasses and compare responses.
Quality
1.7K269
πŸ”
2026/08/12

JWT Token Attack

JWT Token Attack tests JWT implementations for alg=none bypass, key confusion, claim tampering, and kid injection. Use it when checking whether a service accepts forged or modified tokens.
Quality
1.7K269
πŸ”€
2026/08/12

Open Redirect Testing

Open Redirect Testing identifies redirect parameters and tests them for unsafe destination handling. Use it to verify redirect, OAuth, and login-flow weaknesses that can enable phishing or token theft.
Quality
1.7K269
πŸ›‘οΈ
2026/08/12

Prototype Pollution Attack

Prototype Pollution Attack outlines how to test JavaScript apps for __proto__ and constructor.prototype pollution. Use it when checking merge or parse endpoints for client-side XSS, privilege escalation, or server-side gadget chains.
Quality
1.7K269
βš”οΈ
2026/08/12

Race Condition Attack

Race Condition Attack sends concurrent requests to test time-of-check-to-time-of-use flaws. Use it to probe race-prone actions like coupon redemption, transfers, duplicate creation, and rate-limit bypasses.
Quality
1.7K269
πŸ›‘οΈ
2026/08/12

Rate Limit Bypass

Rate Limit Bypass tests endpoints for weak throttling and account lockout controls using header, URL, and method variations. Use it when checking login, reset, OTP, or other rate-limited flows.
Quality
1.7K269
πŸ›‘οΈ
2026/08/12

Server-Side Template Injection

Server-Side Template Injection detects SSTI, fingerprints template engines, and tests for code execution in server-rendered inputs. Use it when a web app may evaluate user-controlled template syntax.
Quality
1.7K269
πŸ•΅οΈ
2026/08/12

SSRF Testing

SSRF Testing checks URL-handling features for server-side request forgery. Use it to probe internal resources, cloud metadata endpoints, and common filter bypasses.
Quality
1.7K269
πŸ•΅οΈ
2026/08/12

Subdomain Takeover

Subdomain Takeover identifies dangling CNAME records and fingerprints the cloud services they point to. Use it to check for takeover conditions and verify cloud storage exposure.
Quality
1.7K269
πŸ§ͺ
2026/08/12

Web Cache Poisoning

Web Cache Poisoning helps test for unkeyed headers, parameters, and normalization issues that can poison cached responses. Use it when checking whether attackers can serve altered content to other users.
Quality
1.7K269
πŸ•ΈοΈ
2026/08/12

WebSocket Security Testing

WebSocket Security Testing checks WebSocket endpoints for CSWSH, message injection, and authentication bypass. Use it when validating origin checks, session handling, and message handling in a WebSocket app.
Quality
1.7K269
PreviousPage 51 of 159Next