tag

web-security

30 indexed skills · max 10 per page

skills (30)

testing-for-xxe-injection-vulnerabilities

mukul975/Anthropic-Cybersecurity-Skills · testing-for-xxe-injection-vulnerabilities

1

Discovering and exploiting XML External Entity injection vulnerabilities to read server files, perform SSRF, and exfiltrate data during authorized penetration tests.

performing-graphql-security-assessment

mukul975/Anthropic-Cybersecurity-Skills · performing-graphql-security-assessment

0

Assessing GraphQL API endpoints for introspection leaks, injection attacks, authorization flaws, and denial-of-service vulnerabilities during authorized security tests.

performing-jwt-none-algorithm-attack

mukul975/Anthropic-Cybersecurity-Skills · performing-jwt-none-algorithm-attack

0

Execute and test the JWT none algorithm attack to bypass signature verification by manipulating the alg header field in JSON Web Tokens.

exploiting-template-injection-vulnerabilities

mukul975/Anthropic-Cybersecurity-Skills · exploiting-template-injection-vulnerabilities

0

Detecting and exploiting Server-Side Template Injection (SSTI) vulnerabilities across Jinja2, Twig, Freemarker, and other template engines to achieve remote code execution.

performing-security-headers-audit

mukul975/Anthropic-Cybersecurity-Skills · performing-security-headers-audit

0

Auditing HTTP security headers including CSP, HSTS, X-Frame-Options, and cookie attributes to identify missing or misconfigured browser-level protections.

exploiting-http-request-smuggling

mukul975/Anthropic-Cybersecurity-Skills · exploiting-http-request-smuggling

0

Detecting and exploiting HTTP request smuggling vulnerabilities caused by Content-Length and Transfer-Encoding parsing discrepancies between front-end and back-end servers.

implementing-web-application-logging-with-modsecurity

mukul975/Anthropic-Cybersecurity-Skills · implementing-web-application-logging-with-modsecurity

0

Configure ModSecurity WAF with OWASP Core Rule Set (CRS) for web application logging, tune rules to reduce false positives, analyze audit logs for attack detection, and implement custom SecRules for application-specific threats. The analyst configures SecRuleEngine, SecAuditEngine, and CRS paranoia levels to balance security coverage with operational stability. Activates for requests involving WAF configuration, ModSecurity rule tuning, web application audit logging, or CRS deployment.

testing-jwt-token-security

mukul975/Anthropic-Cybersecurity-Skills · testing-jwt-token-security

0

Assessing JSON Web Token implementations for cryptographic weaknesses, algorithm confusion attacks, and authorization bypass vulnerabilities during security engagements.

testing-for-host-header-injection

mukul975/Anthropic-Cybersecurity-Skills · testing-for-host-header-injection

0

Test web applications for HTTP Host header injection vulnerabilities to identify password reset poisoning, web cache poisoning, SSRF, and virtual host routing manipulation risks.

testing-for-xml-injection-vulnerabilities

mukul975/Anthropic-Cybersecurity-Skills · testing-for-xml-injection-vulnerabilities

0

Test web applications for XML injection vulnerabilities including XXE, XPath injection, and XML entity attacks to identify data exposure and server-side request forgery risks.

prevpage 1 / 3next