Web Attack

HTTP/Web exploitation until a server shell or equivalent OS execution. Use after /web-recon has mapped the application. Covers injection, upload, LFI, SSRF/XXE, SSTI, deserialization, JWT/SAML, API logic, desync/cache/parser, and Web-controlled backend abuse. WAF stays here. Endpoint blocks after OS execution hand off to /edr-bypass then return. Direct non-HTTP service ports belong to /recon or /service-attack.

pale-knight 1e652eb 25 files · 123.9 KB Updated

File contents

pale-knight/redteam-skill/tree/main/skills/web-attack commit 1e652ebff4

Frequently asked questions

npx skillmds@latest add pale-knight/web-attack