
from claude-bughunter2,450
Guided hunting methodology for server-side request forgery (SSRF): detection, OOB validation, payloads, bypass techniques, and escalation chains.
Provides a structured, field-tested methodology for discovering and validating SSRF vulnerabilities. Includes target prioritization (cloud metadata, Kubernetes, link-preview endpoints), out-of-band confirmation (Burp Collaborator / interactsh), payloads for cloud metadata and internal services, and bypass techniques for common filters. Also offers triage guidance to confirm impact and reproduceability.
Use this skill during web application security testing, bug-bounty hunts, and red-team engagements when you need to systematically find SSRF sinks, confirm blind SSRF via OOB callbacks, and escalate findings to cloud credential exfiltration or internal service access. Ideal for endpoints that accept URLs, file imports, link previews, and headless-renderer features.
Inferable: agents with security-testing and network fetch tools (Claude Code, Hermes-like security assistants, LLM agents that can run curl/requests).
SSRF hunting methodology skill with no bundled scripts — purely a reference document. Covers OOB validation, cloud metadata exploitation, bypass techniques, and real bug bounty citations ($6k-$25k). Well-structured and thorough for its niche. No security concerns beyond expected offensive security content appropriate to the domain.
No scripts to test. SKILL.md is a comprehensive SSRF hunting guide sourced from 15+ public bug bounty reports. Content is offensive security methodology, which is the stated purpose — not flagged. Would benefit from a references/ directory for supplementary material.
Bug Bounty Methodology
A five-phase bug-hunting workflow and critical-thinking playbook that orients security hunting sessions, maps steps from recon to report, and enforces quality g
Hunt SharePoint
Enumerate and assess on-prem Microsoft SharePoint servers for version disclosure, anonymous endpoints, legacy SOAP login abuse, ToolShell preconditions (CVE-202