web-security▌
30 indexed skills · max 10 per page
exploiting-sql-injection-with-sqlmap
mukul975/Anthropic-Cybersecurity-Skills · exploiting-sql-injection-with-sqlmap
Detecting and exploiting SQL injection vulnerabilities using sqlmap to extract database contents during authorized penetration tests.
performing-http-parameter-pollution-attack
mukul975/Anthropic-Cybersecurity-Skills · performing-http-parameter-pollution-attack
Execute HTTP Parameter Pollution attacks to bypass input validation, WAF rules, and security controls by injecting duplicate parameters that are processed differently by front-end and back-end systems.
testing-for-xss-vulnerabilities-with-burpsuite
mukul975/Anthropic-Cybersecurity-Skills · testing-for-xss-vulnerabilities-with-burpsuite
Identifying and validating cross-site scripting vulnerabilities using Burp Suite's scanner, intruder, and repeater tools during authorized security assessments.
exploiting-server-side-request-forgery
mukul975/Anthropic-Cybersecurity-Skills · exploiting-server-side-request-forgery
Identifying and exploiting SSRF vulnerabilities to access internal services, cloud metadata, and restricted network resources during authorized penetration tests.
performing-web-cache-poisoning-attack
mukul975/Anthropic-Cybersecurity-Skills · performing-web-cache-poisoning-attack
Exploiting web cache mechanisms to serve malicious content to other users by poisoning cached responses through unkeyed headers and parameters during authorized security tests.
testing-for-business-logic-vulnerabilities
mukul975/Anthropic-Cybersecurity-Skills · testing-for-business-logic-vulnerabilities
Identifying flaws in application business logic that allow price manipulation, workflow bypass, and privilege escalation beyond what technical vulnerability scanners can detect.
exploiting-insecure-deserialization
mukul975/Anthropic-Cybersecurity-Skills · exploiting-insecure-deserialization
Identifying and exploiting insecure deserialization vulnerabilities in Java, PHP, Python, and .NET applications to achieve remote code execution during authorized penetration tests.
exploiting-nosql-injection-vulnerabilities
mukul975/Anthropic-Cybersecurity-Skills · exploiting-nosql-injection-vulnerabilities
Detect and exploit NoSQL injection vulnerabilities in MongoDB, CouchDB, and other NoSQL databases to demonstrate authentication bypass, data extraction, and unauthorized access risks.
exploiting-websocket-vulnerabilities
mukul975/Anthropic-Cybersecurity-Skills · exploiting-websocket-vulnerabilities
Testing WebSocket implementations for authentication bypass, cross-site hijacking, injection attacks, and insecure message handling during authorized security assessments.
testing-for-broken-access-control
mukul975/Anthropic-Cybersecurity-Skills · testing-for-broken-access-control
Systematically testing web applications for broken access control vulnerabilities including privilege escalation, missing function-level checks, and insecure direct object references.