injection

Original🇺🇸 English
Translated

Injection vulnerability testing - SQL, NoSQL, OS Command, SSTI, XXE, and LDAP/XPath injection techniques.

9installs
Added on

NPX Install

npx skill4agent add transilienceai/communitytools injection

Tags

Translated version includes tags in frontmatter

Injection

Test for injection vulnerabilities across all input vectors. Covers SQL, NoSQL, Command, SSTI, XXE, and LDAP injection.

Techniques

TypeKey Vectors
SQL InjectionIn-band (union, error), Blind (boolean, time), Out-of-band
NoSQL InjectionOperator injection, JavaScript injection, aggregation pipeline
Command InjectionOS command separators, blind techniques, out-of-band
SSTITemplate engine detection, sandbox escape, RCE chains
XXEEntity expansion, SSRF via XXE, blind XXE, parameter entities
LDAP/XPathFilter manipulation, authentication bypass

Workflow

  1. Identify injection points (parameters, headers, cookies, JSON fields)
  2. Detect injection type with minimal probes
  3. Exploit with context-appropriate payloads
  4. Escalate (data extraction, RCE, file read)
  5. Capture evidence and write PoC

Reference

  • reference/sql-injection*.md
    - SQL injection techniques
  • reference/nosql-injection*.md
    - NoSQL injection techniques
  • reference/os-command-injection*.md
    - OS command injection
  • reference/ssti*.md
    - Server-side template injection
  • reference/xxe*.md
    - XML external entity injection