claude-red is a curated library of offensive security skills designed for the Claude skills system. Each skill is a structured SKILL.md file that primes Claude with expert-level methodology for a specific attack surface — from SQLi to shellcode, EDR evasion to exploit development.
Self-hosted, 100% client-side PKI toolbox: X.509/CSR/chain/CRL/PKCS#7/PKCS#12 decoders, ASN.1 viewer, format converter and self-signed certificate generator.
From “Won’t Fix” to $$$$: How I Bypassed Google’s SSRF Filters Using an IPv6-Mapped Address
Hello everyone, I’m Nitin Attri! I spend my time hunting bugs, bypassing filters, and helping organizations secure their infrastructure.Continue reading on Medium »
Read more...
Hello everyone, I’m Nitin Attri! I spend my time hunting bugs, bypassing filters, and helping organizations secure their infrastructure.Continue reading on Medium »
Read more...
Medium
From “Won’t Fix” to $$$$: How I Bypassed Google’s SSRF Filters Using an IPv6-Mapped Address
Hello everyone, I’m Nitin Attri! I spend my time hunting bugs, bypassing filters, and helping organizations secure their infrastructure.
How a Race Condition Turned a Simple Feedback Form Into a $700 Bounty
When we hear race condition, most security researchers probably think about the usual suspects.Continue reading on Medium »
Read more...
When we hear race condition, most security researchers probably think about the usual suspects.Continue reading on Medium »
Read more...
Medium
How a Race Condition Turned a Simple Feedback Form Into a $700 Bounty
When we hear race condition, most security researchers probably think about the usual suspects.
From “Won’t Fix” to $$$$: How I Bypassed Google’s SSRF Filters Using an IPv6-Mapped Address
https://medium.com/@technicalattri/from-wont-fix-to-how-i-bypassed-google-s-ssrf-filters-using-an-ipv6-mapped-address-a64ca42a039d?source=rss------bug_bounty-5
https://medium.com/@technicalattri/from-wont-fix-to-how-i-bypassed-google-s-ssrf-filters-using-an-ipv6-mapped-address-a64ca42a039d?source=rss------bug_bounty-5
Hello everyone, I’m Nitin Attri! I spend my time hunting bugs, bypassing filters, and helping organizations secure their infrastructure.Continue reading on Medium » (https://medium.com/@technicalattri/from-wont-fix-to-how-i-bypassed-google-s-ssrf-filters-using-an-ipv6-mapped-address-a64ca42a039d?source=rss------bug_bounty-5)
How a Race Condition Turned a Simple Feedback Form Into a $700 Bounty
https://medium.com/@ekanshchoudhary.96/how-a-race-condition-turned-a-simple-feedback-form-into-a-700-bounty-d0594b1e7c78?source=rss------bug_bounty-5
https://medium.com/@ekanshchoudhary.96/how-a-race-condition-turned-a-simple-feedback-form-into-a-700-bounty-d0594b1e7c78?source=rss------bug_bounty-5
When we hear race condition, most security researchers probably think about the usual suspects.Continue reading on Medium » (https://medium.com/@ekanshchoudhary.96/how-a-race-condition-turned-a-simple-feedback-form-into-a-700-bounty-d0594b1e7c78?source=rss------bug_bounty-5)
Leaked account lead to RCE
Hello guys welcome to my new writeup, today i will explain how did i got from leaked accounts lead to RCE.Continue reading on Medium »
Read more...
Hello guys welcome to my new writeup, today i will explain how did i got from leaked accounts lead to RCE.Continue reading on Medium »
Read more...
Medium
Leaked account lead to RCE
Hello guys welcome to my new writeup, today i will explain how did i got from leaked accounts lead to RCE.
Google Cloud DLP: Universal Detection Bypass in Google’s Own Sandboxes
What happened: Google Cloud DLP returns zero findings when sensitive data is obfuscated with U+200B (Category Cf).Continue reading on Medium »
Read more...
What happened: Google Cloud DLP returns zero findings when sensitive data is obfuscated with U+200B (Category Cf).Continue reading on Medium »
Read more...
Medium
Google Cloud DLP: Universal Detection Bypass in Google’s Own Sandboxes
What happened: Google Cloud DLP returns zero findings when sensitive data is obfuscated with U+200B (Category Cf).
Best use of the regex for the Bug Bounty, No fluff [Do not skip this article]
How to Turn GitHub, JavaScript, Archived URLs, and Broken Validation Into High-Signal Bug Bounty ReconContinue reading on MeetCyber »
Read more...
How to Turn GitHub, JavaScript, Archived URLs, and Broken Validation Into High-Signal Bug Bounty ReconContinue reading on MeetCyber »
Read more...
Medium
Best use of the regex for the Bug Bounty, No fluff [Do not skip this article]
How to Turn GitHub, JavaScript, Archived URLs, and Broken Validation Into High-Signal Bug Bounty Recon
Native HTTP/HTTPS interception proxy for penetration testers and bug bounty hunters with live request tampering, request replay, high-speed fuzzing, and HTTPQL filtering.