⚠️ AUTHORIZED USE ONLY This skill is for educational purposes or authorized security assessments only. You must have explicit, written permission from the system owner before using this tool. Misuse of this tool is illegal and strictly prohibited.
Mandatory confirmation gate Before running any command that probes, exploits, changes, persists on, extracts data from, or attempts credential access against a target:
- Ask the user to state the exact target URL, IP, account, or resource.
- Ask the user to confirm written authorization and the permitted scope.
- Show the exact command(s) and explain their expected effect.
- Wait for explicit confirmation in the current conversation.
Without that confirmation, remain read-only and provide defensive guidance only. Prefer a sandbox, disposable VM, or controlled lab.
关键词命中:
不应使用本 skill:
code-audit skill)输入:程序名 / SRC 入口 URL / 子域。
要做的事:
X-Bug-Bounty: <handle>)优先级判断(基于命中类型预估命中率,参考 references/methodology/05-srctimebox-priority.md):
→ 详见 references/methodology/00-index.md
不发包给目标的情报收集:
org:target + 关键词(password / api_key / SECRET)site:target.com inurl:/admin、filetype:env、intitle:Index of
资产枚举:
references/dictionaries/chinese-srcfingerprints.md 命中国产组件)按攻击类型走对应 playbook,每个 playbook 都包含:方法论 + 参数频率表 + 真实 H1 案例 + 结构化 payload + WAF 绕过变体。
优先级路径(按命中率 + 价值排序):
| Playbook | 入口提示 | 文件 |
|---|---|---|
| 未授权访问 | Actuator/Swagger/默认端口/弱密码 | references/playbooks/unauth-access.md |
| 信息泄露 | .git/.svn/.env/heapdump/路径列举 | references/playbooks/info-disclosure.md |
| 任意 X 越权 | 用户态 ID 可遍历/可修改 | references/playbooks/arbitrary-x-authz.md |
| 业务逻辑 | 密码重置/支付/订单/验证码 | references/playbooks/logic-flaws.md |
| OAuth/SAML/JWT | 认证流/redirect_uri/token | references/playbooks/oauth-saml-jwt.md |
| API REST | BOLA/Mass Assignment/速率 | references/playbooks/api-rest.md |
| SQLi | 任何用户输入进 DB | references/playbooks/sqli.md |
| RCE | 反序列化/SSTI/XXE/原型链/框架 | references/playbooks/rce.md |
| SSRF | URL 入参/缓存/Host 注入 | references/playbooks/ssrf-cache-host.md |
| 路径遍历 | 文件路径入参/LFI/RFI | references/playbooks/path-traversal.md |
| 文件上传 | 上传点 + 解析漏洞 | references/playbooks/file-upload.md |
| XSS | 任何用户输入进 HTML/JS | references/playbooks/xss.md |
| HTTP 走私 | 反代 + Content-Length | references/playbooks/http-smuggling.md |
| GraphQL | introspection/嵌套 | references/playbooks/graphql.md |
| 竞态 | 并发请求 / TOCTOU | references/playbooks/race-conditions.md |
| DoS | ReDoS / 资源不限速 / 算法爆炸 | references/playbooks/dos.md |
| 移动端 | Android / iOS APK | references/playbooks/mobile.md |
| LLM Agent | Prompt 注入 / 工具调用 | references/playbooks/llm-prompt-injection.md |
| 内网后渗透 | 凭据 / 横向 / 域 | references/playbooks/intranet-postexp.md |
通用方法论(不分攻击类型):
| 文档 | 关键内容 |
|---|---|
methodology/01-attack-priority.md |
RCE>文件写>认证绕过>注入>信息泄露 价值排序 |
methodology/02-bypass-toolkit.md |
通用绕过决策树 + 编码 / 混淆 / WAF |
methodology/03-evidence-discipline.md |
黑盒证据规则 + 反幻觉 + 合规 |
methodology/04-control-gap-hunting.md |
9 类敏感操作 → 应有控制 → 探测缺失 |
methodology/05-srctimebox-priority.md |
6h / 单日 / HVV / 月度 时间盒模板 |
行业垂直 playbook(资产相关时优先看):
| 行业 | 文档 | 何时用 |
|---|---|---|
| 银行 / 支付 / 金融 | industry/banking-finance.md |
目标含支付 / 网银 / 第三方支付聚合 |
| 电信 / ISP | industry/telecom-isp.md |
目标是运营商 / BOSS / 网管 / 物联网卡 |
字典 / 凭据:
| 文档 | 用途 |
|---|---|
dictionaries/default-credentials-cn.md |
致远 / 通达 / 万户 / 泛微 / 用友 / 金蝶 / 华为 / 中兴 / 海康等国产凭据 |
dictionaries/chinese-srcfingerprints.md |
国产 OA / 中间件指纹 + 高频参数 + 一键检测命令 |
→ 用模板 templates/report-submission.md
三段式骨架:
本 skill 支持调用本地 MCP 服务器作为工具层。主选 jshookmcp(134 工具精选 / 386 全集 / 36 域,内置 Burp Suite bridge / Frida / WASM / 反调试 / Android adb / sourcemap 重构)。完整索引与场景映射:
→ references/tools/mcp-jshook.md
默认推荐 search profile(上下文成本 ~3K token),通过 mcp__jshook__search_tools + mcp__jshook__activate_tools 按需激活,避免 full profile 一次性加载 40K+ token。
| 类别 | 量级 |
|---|---|
| 攻击类 playbook | 19 个 |
| 通用方法论文档 | 6 个 |
| 行业垂直 playbook | 2 个(银行 / 电信) |
| 字典 / 凭据 | 3 个 |
| 报告模板 | 1 个 |
| 结构化 payload | 305 条(177 web + 128 内网) |
| WAF / EDR 绕过变体 | 263 个步骤,覆盖 23 类 Web 攻击 |
| 工具命令速查 | 114 条(Nmap/SQLMap/Burp/MSF/...) |
| HackerOne 真实案例(已披露 High/Critical) | 2887 份,按 weakness 分到 141 个分类 MD |
| WooYun 历史案例统计(不可再生) | 88,636 条 |
H1 真实案例已直接嵌入对应 playbook 末尾(每个 playbook 末尾有"H1 真实案例" Top 12 表 + 摘要)。
每个 playbook 末段都有"不要做的事"。通用红线(任何 SRC 都遵守):
X-Bug-Bounty: <handle>)references/templates/report-submission.md 自查srchunter(如:srchunter scope set <program>、srchunter recon run、srchunter findings new <type>)。当前未实现 CLI,仅作命名约定。
src-hunter/
├── SKILL.md # 本文件 — skill 入口
├── README.md # 项目说明
└── references/
├── methodology/ 6 docs # 通用打法
├── playbooks/ 19 docs # 攻击类 playbook(每个含 H1 案例 + Payload 库)
├── industry/ 3 docs # 行业垂直
├── dictionaries/ 3 docs # 字典 / 凭据
├── templates/ 1 doc # 报告模板
├── h1-reports/ # 2887 份 H1 报告原始数据 + 141 类 MD
│ ├── raw/ # 原始 JSON(resume / 二次分析用)
│ └── by-weakness/ # 按 CWE 分类的 Markdown
└── payloader/ # 305 条结构化 payload 数据
├── raw/ # JSON(机读)
├── by-category/ # 按分类的 MD
├── tools/ # 工具命令
└── waf-bypass.md # 263 步骤 WAF 绕过集
tool-index 使用了真实工具路径?Adapted from zhaoxuya520/reverse-skill (MIT).