Browse Skills
Testing For Host Header Injection
v1.0.0Test web applications for HTTP Host header injection vulnerabilities to identify password reset poisoning, web cache poisoning, SSRF, and virtual host routing manipulation risks.
Testing For Json Web Token Vulnerabilities
v1.0.0Test JWT implementations for critical vulnerabilities including algorithm confusion, none algorithm bypass, kid parameter injection, and weak secret exploitation to achieve authentication bypass and privilege escalation.
Testing For Open Redirect Vulnerabilities
v1.0.0Identify and test open redirect vulnerabilities in web applications by analyzing URL redirection parameters, bypass techniques, and exploitation chains for phishing and token theft.
Testing For Sensitive Data Exposure
v1.0.0Identifying sensitive data exposure vulnerabilities including API key leakage, PII in responses, insecure storage, and unprotected data transmission during security assessments.
Testing For Xml Injection Vulnerabilities
v1.0.0Test web applications for XML injection vulnerabilities including XXE, XPath injection, and XML entity attacks to identify data exposure and server-side request forgery risks.
Testing For Xss Vulnerabilities
v1.0.0>
Testing For Xss Vulnerabilities With Burpsuite
v1.0.0Identifying and validating cross-site scripting vulnerabilities using Burp Suite's scanner, intruder, and repeater tools during authorized security assessments.
Testing For Xxe Injection Vulnerabilities
v1.0.0Discovering and exploiting XML External Entity injection vulnerabilities to read server files, perform SSRF, and exfiltrate data during authorized penetration tests.
Testing Jwt Token Security
v1.0.0Assessing JSON Web Token implementations for cryptographic weaknesses, algorithm confusion attacks, and authorization bypass vulnerabilities during security engagements.
Testing Mobile Api Authentication
v1.0.0>
Testing Oauth2 Implementation Flaws
v1.0.0>
Testing Websocket Api Security
v1.0.0>