Hunt Grpc

"Hunt gRPC vulnerabilities — server reflection enabled (enumerate all services/methods), missing authentication / metadata-stripping on internal endpoints, plaintext gRPC over HTTP/2, internal endpoint disclosure, proto file leakage, gRPC-Web/grpc-gateway transcoding injection, and HTTP/2 Rapid Reset DoS (CVE-2023-44487). Use when target exposes port 50051 / 443 / 8443 / 9090 with HTTP/2, when grp

wufufu770 Updated

File contents

wufufu770/skills/tree/main/ext/2-web-vulns/039-hunt-grpc commit 63af2196fe

Frequently asked questions

npx skillmds@latest add wufufu770/hunt-grpc