Loading...
Loading...
Use when classifying a verified web or WordPress behavior and selecting a related validation skill.
npx skill4agent add uphiago/recon-skills attack-patterns-reference| Pattern | Initial signal | Owning skill |
|---|---|---|
| WordPress user exposure | REST or author route returns user metadata | |
| Credentialed CORS | Untrusted origin reflected with credentials | |
| XML-RPC methods | Protocol-valid | |
| XML-RPC SSRF | | |
| Public registration | Registration is enabled | |
| Plugin surface | REST namespace, asset, or version marker | |
| Staging difference | Non-production host has weaker controls | |
| Exposed error log | Response contains real application errors | |
| PHPInfo exposure | PHP configuration page is reachable | |
| Source or backup leak | Response contains repository, configuration, or database content | |
| JavaScript secret candidate | Bundle contains a credential-shaped value | |
| Public service | Non-HTTP or administrative service is internet reachable | |
references/p-patterns.md| Variant | Initial signal | Required validation |
|---|---|---|
| Origin reflection with credentials | Untrusted origin plus | Credentialed browser reads non-public data |
| Null-origin trust | | Sandboxed browser reads non-public data |
| Wildcard without credentials | | Determine whether the response is already public |
| Credentialed preflight | OPTIONS accepts origin, method, and headers | Actual request succeeds and browser exposes response |
| Auth-route CORS | CORS headers appear on a protected route | Approved session returns readable protected data |
| Plugin-specific CORS | Only one plugin namespace accepts the origin | Response contains protected data or performs an authorized test action |
| Environment-specific CORS | Staging and production policies differ | Demonstrate impact in the authorized environment |
| Third-party allowlist | One external service origin is trusted | Establish control of that origin and protected-data access |
| Path | Preconditions that must be verified |
|---|---|
| CORS to protected-data read | Approved session, untrusted origin, browser-readable non-public response |
| XML-RPC SSRF to cloud metadata | Controlled callback, reachable metadata service, usable secondary impact |
| Open registration to upload | Approved synthetic account, upload-capable role, executable file path |
| Exposed log to account access | Current credential material, approved identity, valid authentication control |
| Staging exposure to production impact | Shared trust boundary, reusable secret or deployment path, explicit scope |
cross-attack-chains