← all publishers

omkar-ukirde

@omkar-ukirde source repo

15 published skills

  1. Web · omkar-ukirde
    Web application security testing skills organized by OWASP Top 10 2021 categories.
    0 installs
  2. Network · omkar-ukirde
    Network penetration testing skills for service exploitation and protocol attacks.
    0 installs
  3. Web2 Recon · omkar-ukirde
    Web2 recon pipeline — subdomain enumeration (subfinder, Chaos API, assetfinder), live host discovery (dnsx, httpx), URL crawling (katana, waybackurls, gau), directory fuzzing (ffuf), JS analysis (LinkFinder, SecretFinder), continuous monitoring (new subdomain alerts, JS change detection, GitHub commit watch). Use when starting recon on any web2 target or when asked about asset discovery, subdomain enum, or attack surface mapping.
    0 installs
  4. Web3 Audit · omkar-ukirde
    Smart contract security audit — 10 DeFi bug classes (accounting desync, access control, incomplete path, off-by-one, oracle, ERC4626, reentrancy, flash loan, signature replay, proxy), pre-dive kill signals (TVL < $500K etc), Foundry PoC template, grep patterns for each class, and real Immunefi paid examples. Use for any Solidity/Rust contract audit or when deciding whether a DeFi target is worth hunting.
    2 installs
  5. Cve Hunting · omkar-ukirde
    Fetch and analyze the latest CVEs for web application components, frameworks, and servers.
    0 installs
  6. Databases · omkar-ukirde bundle
    Skills for attacking database services including SQL, NoSQL, and in-memory databases.
    0 installs
  7. A03 Injection · omkar-ukirde bundle
    Skills for identifying and exploiting injection vulnerabilities including SQL, NoSQL, command, template, and other injection attacks per OWASP A03:2021.
    0 installs
  8. Auth Services · omkar-ukirde bundle
    Skills for attacking authentication and remote access services including SSH, RDP, Kerberos, and LDAP.
    0 installs
  9. File Services · omkar-ukirde bundle
    Skills for attacking file sharing services including FTP, SMB, NFS, and version control.
    0 installs
  10. A07 Auth Failures · omkar-ukirde bundle
    Skills for exploiting authentication and session management vulnerabilities including JWT, OAuth, and 2FA bypass per OWASP A07:2021.
    0 installs
  11. Layer2 Attacks · omkar-ukirde bundle
    Skills for Layer 2 network attacks including ARP spoofing, DHCP attacks, and VLAN hopping.
    0 installs
  12. Report Writing · omkar-ukirde
    Bug bounty report writing for H1/Bugcrowd/Intigriti/Immunefi — report templates, human tone guidelines, impact-first writing, CVSS 3.1 scoring, title formula, impact statement formula, severity decision guide, downgrade counters, pre-submit checklist. Use after validating a finding and before submitting. Never use "could potentially" — prove it or don't report.
    0 installs
  13. Triage Validation · omkar-ukirde
    Finding validation before writing any report — 7-Question Gate (all 7 questions), 4 pre-submission gates, always-rejected list, conditionally valid with chain table, CVSS 3.1 quick reference, severity decision guide, report title formula, 60-second pre-submit checklist. Use BEFORE writing any report. One wrong answer = kill the finding and move on. Saves N/A ratio.
    0 installs
  14. A01 Broken Access Control · omkar-ukirde bundle
    Skills for testing broken access control vulnerabilities including IDOR, CSRF, CORS misconfigurations, and open redirects per OWASP A01:2021.
    0 installs
  15. A05 Security Misconfiguration · omkar-ukirde bundle
    Skills for exploiting security misconfigurations including XXE, file upload, subdomain takeover, and cache issues per OWASP A05:2021.
    0 installs