Справочник веб-уязвимостей для bug bounty
★ 8.1 · research
web2-vuln-classes is a Claude Code skill that provides a complete reference for 26 web2 vulnerability classes, covering root causes, detection patterns, bypass tables, exploit techniques, and real paid bug bounty examples. It spans IDOR, auth bypass, XSS, SSRF (11 IP bypass techniques), SQLi, business logic flaws, race conditions, OAuth/OIDC, file upload (10 bypass techniques), GraphQL, LLM/AI agentic framework (ASI01–ASI10), HTTP smuggling (CL.TE/TE.CL/H2.CL), cache poisoning, MFA bypass (7 patterns), SAML attacks, SSTI across Jinja2/Twig/Freemarker/ERB/Spring, LFI→RCE chains, insecure deserialization for PHP/Java/Python/Node, and dependency confusion. Each class includes vulnerable-vs-secure code samples, testing checklists, and chaining escalation paths from Medium to Critical. Built for penetration testers and bug bounty hunters studying a specific vuln class or identifying what makes bugs pay.
- #web2-vulnerabilities
- #idor
- #xss
- #ssrf
- #sqli
- #api-security
- #auth-bypass