Browse Skills
11972 skills across 8 categories
π΅οΈ
2026/08/12
HTTP Request Smuggling
HTTP Request Smuggling tests for CL.TE, TE.CL, TE.TE, and H2.CL desyncs between front-end and back-end servers. Use it to detect request boundary confusion, confirm impact, and demonstrate cache poisoning or auth bypass.
Quality
1.7K269
π‘οΈ
2026/08/12
IDOR Automated Testing
IDOR Automated Testing checks API endpoints for insecure direct object references using two accounts with different privilege levels. Use it to test horizontal and vertical access control bypasses and compare responses.
Quality
1.7K269
π
2026/08/12
JWT Token Attack
JWT Token Attack tests JWT implementations for alg=none bypass, key confusion, claim tampering, and kid injection. Use it when checking whether a service accepts forged or modified tokens.
Quality
1.7K269
π
2026/08/12
Open Redirect Testing
Open Redirect Testing identifies redirect parameters and tests them for unsafe destination handling. Use it to verify redirect, OAuth, and login-flow weaknesses that can enable phishing or token theft.
Quality
1.7K269
π‘οΈ
2026/08/12
Prototype Pollution Attack
Prototype Pollution Attack outlines how to test JavaScript apps for __proto__ and constructor.prototype pollution. Use it when checking merge or parse endpoints for client-side XSS, privilege escalation, or server-side gadget chains.
Quality
1.7K269
βοΈ
2026/08/12
Race Condition Attack
Race Condition Attack sends concurrent requests to test time-of-check-to-time-of-use flaws. Use it to probe race-prone actions like coupon redemption, transfers, duplicate creation, and rate-limit bypasses.
Quality
1.7K269
π‘οΈ
2026/08/12
Rate Limit Bypass
Rate Limit Bypass tests endpoints for weak throttling and account lockout controls using header, URL, and method variations. Use it when checking login, reset, OTP, or other rate-limited flows.
Quality
1.7K269
π‘οΈ
2026/08/12
Server-Side Template Injection
Server-Side Template Injection detects SSTI, fingerprints template engines, and tests for code execution in server-rendered inputs. Use it when a web app may evaluate user-controlled template syntax.
Quality
1.7K269
π΅οΈ
2026/08/12
SSRF Testing
SSRF Testing checks URL-handling features for server-side request forgery. Use it to probe internal resources, cloud metadata endpoints, and common filter bypasses.
Quality
1.7K269
π΅οΈ
2026/08/12
Subdomain Takeover
Subdomain Takeover identifies dangling CNAME records and fingerprints the cloud services they point to. Use it to check for takeover conditions and verify cloud storage exposure.
Quality
1.7K269
π§ͺ
2026/08/12
Web Cache Poisoning
Web Cache Poisoning helps test for unkeyed headers, parameters, and normalization issues that can poison cached responses. Use it when checking whether attackers can serve altered content to other users.
Quality
1.7K269
πΈοΈ
2026/08/12
WebSocket Security Testing
WebSocket Security Testing checks WebSocket endpoints for CSWSH, message injection, and authentication bypass. Use it when validating origin checks, session handling, and message handling in a WebSocket app.
Quality
1.7K269