server-side

Installation
SKILL.md

Server-Side

Test for server-side vulnerabilities that allow unauthorized access, RCE, or data exfiltration.

Techniques

Type Key Vectors
SSRF Internal service access, cloud metadata, protocol smuggling
HTTP Smuggling CL.TE, TE.CL, TE.TE, CL.0, H2.CL, h2c, multi-layer proxy chains, connection pooling desync
Path Traversal Directory traversal, null bytes, encoding bypass
File Upload Extension bypass, content-type manipulation, polyglot files
Deserialization Java, PHP, Python, .NET gadget chains
Host Header Password reset poisoning, cache poisoning, routing-based SSRF

Workflow

  1. Identify server-side processing points
  2. Test for vulnerability class indicators
Related skills
Installs
36
GitHub Stars
258
First Seen
Mar 21, 2026