Auth Bypass

Bypass authentication via forced browsing to protected URLs, parameter tampering (authenticated=yes, debug=true, fromtrustIP=true), session ID prediction from linear/incremental cookies, SQL injection on login forms, PHP unserialize() boolean type juggling (b:1 payload), and credential transport over HTTP. Detectable with Burp Suite, OWASP ZAP, WebGoat.

ShulkwiSEC Updated 21 repo stars

File contents

ShulkwiSEC/bb-huge/tree/main/skills/curated/auth-bypass commit 401c5e5fec

Frequently asked questions

npx skillmds@latest add shulkwisec/auth-bypass