Blackbox Web Audit

Authorized black-box web/API audit WITHOUT test accounts — unauth probing discipline, unauth-IDOR rounds using leaked IDs, JS-bundle-first attack surface mapping, non-destructive gates, and local report delivery conventions (no zip, follow sibling example folder). Use when asked to audit/pentest a target where you hold no credentials, and when writing the local report deliverable afterwards.

zyrexnn 57e54a6 5 files · 33.5 KB Updated

File contents

zyrexnn/cybermes/tree/main/skills/security/blackbox-web-audit commit 57e54a6eb5

Frequently asked questions

npx skillmds@latest add zyrexnn/blackbox-web-audit