SQL Injection
yaklang.io ProjectGuides SQL injection testing across MySQL, MSSQL, Oracle and PostgreSQL, covering detection, blind inference, extraction and escalation paths.
By author · 10 skills
Every skill by yaklang.io Project in the directory. Each page has a summary, the install command and a link to the source.
Guides SQL injection testing across MySQL, MSSQL, Oracle and PostgreSQL, covering detection, blind inference, extraction and escalation paths.
Tests JWT and OAuth 2.0 token security for signing flaws, claim abuse, bearer-token leakage and account-binding weaknesses.
Tests API authentication boundaries for JWTs, bearer tokens and API keys, including claim trust, header spoofing and rate-limit bypasses.
Guides security testing of Java expression evaluators across Spring, Struts2, Confluence and JSP/JSF applications.
Detects and verifies dangling DNS records that point to claimable cloud or SaaS resources, covering CNAME, NS, MX and wildcard risks.
Guides authorised security testing and CTF hash attacks, including length extension, collision generation, timing leaks and proof-of-work solving.
Exfiltrates page content through HTML injection when JavaScript is blocked, using dangling tags, form actions and other browser requests.
Analyses encoded and classical-cipher text in CTFs, identifying formats and applying frequency, Kasiski, substitution, Vigenere, transposition and XOR attacks.
Analyses RSA parameters with SageMath and RsaCtfTool to select attacks for weak keys, small exponents, shared factors and padding oracles.
Guides authorised red-team assessments of macOS protections, covering TCC, Gatekeeper, SIP, sandboxing, code signing, entitlements and persistence.