Django Attack Probe

Authorized self-pentest probe targeting Django and DRF-specific weaknesses. Tests DEBUG-page leak, ALLOWED_HOSTS bypass via Host header, default admin path enumeration, ORM raw() injection, mass-assignment via ModelSerializer, and DRF AllowAny on mutating endpoints. Use when the user asks to "pentest" their own Django app.

Dolphinllc 1abc4c1 4.8 KB Updated

File contents

Dolphinllc/claude-security-skills/tree/main/skills/offensive/web/django-attack-probe commit 1abc4c1c95

Frequently asked questions

npx skillmds@latest add dolphinllc/django-attack-probe