Skip to content
KitploitKITPLOIT
उपकरणब्लॉग
जमा करें
उपकरणब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

··फ़ीड·संपर्क·गोपनीयता·© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
pytm — खतरे के मॉडलिंग के लिए एक पायथोनिक ढांचा | Kitploit
उपकरण/GitHubGitHub/izar/pytm
भेद्यता विश्लेषणDevSecOpsखतरा खुफियालर्निंग और शिक्षा
GitHubizar/pytm

pytm

खतरे के मॉडलिंग के लिए एक पायथोनिक ढांचा

रिपॉजिटरी देखें
2216 दिन पहलेKitploit द्वारा समीक्षित

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें

build+test OpenSSF Best Practices

pytm: धमकी मॉडलिंग के लिए एक पायथनिक ढांचा

pytm logo

परिचय

पारंपरिक धमकी मॉडलिंग अक्सर बहुत देर से आती है, या कभी-कभी बिल्कुल नहीं आती। इसके अलावा, मैन्युअल डेटा फ्लो और रिपोर्ट बनाना बेहद समय लेने वाला हो सकता है। pytm का लक्ष्य धमकी मॉडलिंग को बाईं ओर स्थानांतरित करना है, जिससे धमकी मॉडलिंग अधिक स्वचालित और डेवलपर-केंद्रित हो जाए।

विशेषताएँ

आपके इनपुट और आर्किटेक्चरल डिज़ाइन की परिभाषा के आधार पर, pytm स्वचालित रूप से निम्नलिखित आइटम उत्पन्न कर सकता है:

  • Data Flow Diagram (DFD)
  • Sequence Diagram
  • आपके सिस्टम से संबंधित खतरे

आवश्यकताएँ

  • Linux/MacOS
  • Python 3.11+
  • Graphviz package
  • Java (OpenJDK 10 or 11)
  • plantuml.jar

आरंभ करना

tm.py एक उदाहरण मॉडल है। आप इसे चलाकर उन रिपोर्ट और डायग्राम इमेज फ़ाइलों को उत्पन्न कर सकते हैं जिनका यह संदर्भ देता है:``` mkdir -p tm ./tm.py --report docs/basic_template.md | pandoc -f markdown -t html > tm/report.html ./tm.py --dfd | dot -Tpng -o tm/dfd.png ./tm.py --seq | java -Djava.awt.headless=true -jar $PLANTUML_PATH -tpng -pipe > tm/seq.png

root@kitploit:~
एक उदाहरण `Makefile` भी है जो इन सभी को लक्ष्यों में लपेटता है जिन्हें कई मॉडलों के लिए आसानी से साझा किया जा सकता है। यदि आपके पास [GNU make](https://www.gnu.org/software/make/) स्थापित है (लिनक्स वितरणों पर डिफ़ॉल्ट रूप से उपलब्ध, पर OSX पर नहीं), तो बस चलाएँ:

```bash
make help

make MODEL=the_name_of_your_model_minus_.py

root@kitploit:~
आपके पास या तो अपने मॉडल के समान निर्देशिका में plantuml.jar होना चाहिए, या PLANTUML_PATH सेट करना चाहिए। सभी निर्भरताओं, जैसे `pandoc` या `Java` को स्थापित करने से बचने के लिए, स्क्रिप्ट को एक कंटेनर के अंदर चलाया जा सकता है:```
# do this only once
export USE_DOCKER=true
make image

# call this after every change in your model
make

आरंभ करना - Devbox वेरिएंट

pytm के उपयोग को सरल बनाने के लिए, होस्ट निर्भरताओं को Devbox का उपयोग करके पूरी तरह से अलग किया जा सकता है। यह आमतौर पर OCI कंटेनर दृष्टिकोण की तुलना में कम ओवरहेड और अधिक सुविधाजनक विकल्प है।

  • Linux/MacOS पर Devbox स्थापित करें: curl -fsSL https://get.jetify.com/devbox | bash
  • Windows/WSL पर Devbox स्थापित करें
  • Devbox को नवीनतम संस्करण में अपडेट करें: devbox version update
  • अपना GitHub एक्सेस टोकन ~/.config/nix/nix.conf फ़ाइल फ़ाइल में सेट करें: access-tokens = github.com=YOUR_TOKEN_HERE
  • प्रोजेक्ट की devbox.json फ़ाइल में निर्दिष्ट सभी टूल्स और पैकेजों को शामिल करते हुए एक नया, पृथक शेल वातावरण बनाएं: devbox shell
  • जब आप अपने टर्मिनल में केवल python टाइप करते हैं तो उपयोग किए जाने वाले Python निष्पादन योग्य का पूर्ण पथ प्रदर्शित करने के लिए which python कमांड का उपयोग करें। आउटपुट निम्न पथ होना चाहिए: .devbox/nix/profile/default/bin/python
  • निम्न कमांड चलाकर परीक्षण करें, जिसे sample.png नामक PNG फ़ाइल के रूप में DFD उत्पन्न करना चाहिए: ./tm.py --dfd | dot -Tpng -o sample.png

उपयोग

सभी उपलब्ध तर्क:```text usage: tm.py [-h] [--debug] [--dfd] [--report REPORT] [--exclude EXCLUDE] [--seq] [--list] [--describe DESCRIBE] [--list-elements] [--json JSON] [--levels LEVELS [LEVELS ...]] [--stale_days STALE_DAYS]

optional arguments: -h, --help show this help message and exit --debug print debug messages --dfd output DFD --report REPORT output report using the named template file (sample template file is under docs/template.md) --exclude EXCLUDE specify threat IDs to be ignored --seq output sequential diagram --list list all available threats --colormap color the risk in the diagram --describe DESCRIBE describe the properties available for a given element --list-elements list all elements which can be part of a threat model --json JSON output a JSON file --levels LEVELS [LEVELS ...] Select levels to be drawn in the threat model (int separated by comma). --stale_days STALE_DAYS checks if the delta between the TM script and the code described by it is bigger than the specified value in days

root@kitploit:~
The *stale_days* तर्क यह निर्धारित करने का प्रयास करता है कि मॉडल स्क्रिप्ट (जिसे आप लिख रहे हैं) और उस कोड के बीच दिनों में कितना अंतर है, जो मॉडल किए जा रहे सिस्टम को लागू करता है। आदर्श रूप से, सक्रिय रूप से विकसित सिस्टम के अधिकांश मामलों में वे काफी करीब होने चाहिए। आप अपने प्रोजेक्ट की धड़कन और अपने थ्रेट मॉडल की 'ताजगी' को मापने के लिए इसे समय-समय पर चला सकते हैं।

वर्तमान में उपलब्ध तत्व हैं: TM, Element, Server, ExternalEntity, Datastore, Actor, Process, SetOfProcesses, Dataflow, Boundary, Lambda, LLM और Agent।

एक तत्व के उपलब्ध गुणों को तत्व के नाम के बाद `--describe` का उपयोग करके सूचीबद्ध किया जा सकता है:```text

(pytm) ➜  pytm git:(master) ✗ ./tm.py --describe Element
Element class attributes:
  OS
  definesConnectionTimeout        default: False
  description
  handlesResources                default: False
  implementsAuthenticationScheme  default: False
  implementsNonce                 default: False
  inBoundary
  inScope                         Is the element in scope of the threat model, default: True
  isAdmin                         default: False
  isHardened                      default: False
  name                            required
  onAWS                           default: False

The colormap तर्क, dfd के साथ उपयोग किया जाता है, एक रंग-कोडित DFD आउटपुट करता है जहां तत्वों को उनके जोखिम स्तर (नियमों को चलाकर पहचाने गए) के आधार पर लाल, पीले या हरे रंग में चित्रित किया जाता है।

उपयोग - Devbox Variant

  • devbox shell
  • pytm का उपयोग हमेशा की तरह करें
  • exit

एक Threat Model बनाना

निम्नलिखित एक नमूना tm.py फ़ाइल है जो एक सरल एप्लिकेशन का वर्णन करती है जहां एक उपयोगकर्ता एप्लिकेशन में लॉग इन करता है और ऐप पर टिप्पणियाँ पोस्ट करता है। ऐप सर्वर उन टिप्पणियों को डेटाबेस में संग्रहीत करता है। एक AWS Lambda है जो समय-समय पर डेटाबेस को साफ करता है।```python

#!/usr/bin/env python3

from pytm import TM, Server, Datastore, Dataflow, Boundary, Actor, Lambda, LLM, Data, Classification

tm = TM("my test tm") tm.description = "another test tm" tm.isOrdered = True

User_Web = Boundary("User/Web") Web_DB = Boundary("Web/DB")

user = Actor("User") user.inBoundary = User_Web

web = Server("Web Server") web.OS = "CloudOS" web.isHardened = True web.sourceCode = "server/web.cc"

db = Datastore("SQL Database (*)") db.OS = "CentOS" db.isHardened = False db.inBoundary = Web_DB db.isSql = True db.inScope = False db.sourceCode = "model/schema.sql"

comments = Data( name="Comments", description="Comments in HTML or Markdown",
classification=Classification.PUBLIC,
isPII=False, isCredentials=False,
# credentialsLife=Lifetime.LONG,
isStored=True, isSourceEncryptedAtRest=False, isDestEncryptedAtRest=True )

results = Data( name="results", description="Results of insert op",
classification=Classification.SENSITIVE,
isPII=False, isCredentials=False,
# credentialsLife=Lifetime.LONG,
isStored=True, isSourceEncryptedAtRest=False, isDestEncryptedAtRest=True )

my_lambda = Lambda("cleanDBevery6hours") my_lambda.hasAccessControl = True my_lambda.inBoundary = Web_DB

llm_api = LLM("AI Writing Assistant") llm_api.isThirdParty = True llm_api.processesPersonalData = True llm_api.hasContentFiltering = False llm_api.hasSystemPrompt = True llm_api.processesUntrustedInput = True

my_lambda_to_db = Dataflow(my_lambda, db, "(λ)Periodically cleans DB") my_lambda_to_db.protocol = "SQL" my_lambda_to_db.dstPort = 3306

user_to_web = Dataflow(user, web, "User enters comments (*)") user_to_web.protocol = "HTTP" user_to_web.dstPort = 80 user_to_web.data = comments

web_to_user = Dataflow(web, user, "Comments saved (*)") web_to_user.protocol = "HTTP"

web_to_db = Dataflow(web, db, "Insert query with comments") web_to_db.protocol = "MySQL" web_to_db.dstPort = 3306

db_to_web = Dataflow(db, web, "Comments contents") db_to_web.protocol = "MySQL" db_to_web.data = results

web_to_llm = Dataflow(web, llm_api, "Chat completion request") web_to_llm.protocol = "HTTPS" web_to_llm.dstPort = 443

tm.process()

root@kitploit:~
आपके पास [pytmGPT](https://chat.openai.com/g/g-soISG24ix-pytmgpt) का उपयोग करके गद्य से अपने मॉडल बनाने का विकल्प भी है!

### आरेख उत्पन्न करना

आरेख [Dot](https://graphviz.gitlab.io/) और [PlantUML](https://plantuml.com/) के रूप में आउटपुट होते हैं।

जब `--dfd` तर्क उपरोक्त `tm.py` फ़ाइल को दिया जाता है तो यह stdout पर आउटपुट उत्पन्न करता है, जिसे Data Flow Diagram उत्पन्न करने के लिए Graphviz के dot में भेजा जाता है:```bash

tm.py --dfd | dot -Tpng -o sample.png

यह आरेख उत्पन्न करता है:

dfd.png

एक तत्व में ".levels = [1,2]" विशेषताएँ जोड़ने से यह (और इससे जुड़े Dataflows, यदि दोनों प्रवाह अंत एक ही DFD स्तर में हों) कमांड आर्गुमेंट "--levels 1 2" के आधार पर प्रदर्शित होगा (या नहीं होगा)।

निम्नलिखित कमांड एक Sequence diagram उत्पन्न करता है।```bash

tm.py --seq | java -Djava.awt.headless=true -jar plantuml.jar -tpng -pipe > seq.png

root@kitploit:~
यह आरेख उत्पन्न करता है:

seq.png

### रिपोर्ट बनाना

आरेखों और निष्कर्षों को टेम्पलेट में शामिल करके एक अंतिम रिपोर्ट तैयार की जा सकती है:```bash

tm.py --report docs/basic_template.md | pandoc -f markdown -t html > report.html

रिपोर्ट टेम्पलेट में उपयोग किया जाने वाला टेम्पलेटिंग प्रारूप बहुत सरल है:```text

Threat Model Sample


System Description

{tm.description}

Dataflow Diagram

Level 0 DFD

Dataflows

NameFromToDataProtocolPort
{dataflows🔁{{item.name}}{{item.source.name}}{{item.sink.name}}{{item.data}}

Findings

{findings🔁* {{item.description}} on element "{{item.target}}" }

root@kitploit:~
तत्वों के अनुसार परिणामों को समूहबद्ध करने के लिए, एक अधिक उन्नत, नेस्टेड लूप का उपयोग करें:```text
## Findings

{elements:repeat:{{item.findings:if:
### {{item.name}}

{{item.findings:repeat:
**Threat**: {{{{item.id}}}} - {{{{item.description}}}}

**Severity**: {{{{item.severity}}}}

**Mitigations**: {{{{item.mitigations}}}}

**References**: {{{{item.references}}}}

}}}}}

लूप के अंदर सभी आइटम्स को एस्केप किया जाना चाहिए, ब्रेसेज़ को दोगुना करते हुए, इसलिए {item.name} {{item.name}} बन जाता है। उपरोक्त उदाहरण दो नेस्टेड लूप का उपयोग करता है, इसलिए आंतरिक लूप में आइटम्स को दो बार एस्केप किया जाना चाहिए, यही कारण है कि वे चार ब्रेसेज़ का उपयोग कर रहे हैं।

ओवरराइड्स

आप फाइंडिंग्स (मॉडल एसेट्स और/या डेटाफ्लो से मेल खाने वाले खतरे) की विशेषताओं को ओवरराइड कर सकते हैं, उदाहरण के लिए एक कस्टम CVSS स्कोर और/या प्रतिक्रिया टेक्स्ट सेट करने के लिए:```python user_to_web = Dataflow(user, web, "User enters comments (*)", protocol="HTTP", dstPort="80") user_to_web.overrides = [ Finding( # Overflow Buffers threat_id="INP02", cvss="9.3", response="""To Mitigate: run a memory sanitizer to validate the binary""", severity="Very High", ) ]

root@kitploit:~
यदि आप एक Finding जोड़ रहे हैं, तो सुनिश्चित करें कि आप एक गंभीरता जोड़ें: "Very High", "High", "Medium", "Low", "Very Low".

## खतरे का डेटाबेस

सुरक्षा व्यवसायी के लिए, आप `TM.threatsFile` सेट करके अपनी स्वयं की खतरों की फ़ाइल प्रदान कर सकते हैं। इसमें इस प्रकार की प्रविष्टियाँ होनी चाहिए:```json
{
   "SID":"INP01",
   "target": ["Lambda","Process"],
   "description": "Buffer Overflow via Environment Variables",
   "details": "This attack pattern involves causing a buffer overflow through manipulation of environment variables. Once the attacker finds that they can modify an environment variable, they may try to overflow associated buffers. This attack leverages implicit trust often placed in environment variables.",
   "Likelihood Of Attack": "High",
   "severity": "High",
   "condition": "target.usesEnvironmentVariables is True and target.controls.sanitizesInput is False and target.controls.checksInputBounds is False",
   "prerequisites": "The application uses environment variables.An environment variable exposed to the user is vulnerable to a buffer overflow.The vulnerable environment variable uses untrusted data.Tainted data used in the environment variables is not properly validated. For instance boundary checking is not done before copying the input data to a buffer.",
   "mitigations": "Do not expose environment variable to the user.Do not use untrusted data in your environment variables. Use a language or compiler that performs automatic bounds checking. There are tools such as Sharefuzz [R.10.3] which is an environment variable fuzzer for Unix that support loading a shared library. You can use Sharefuzz to determine if you are exposing an environment variable vulnerable to buffer overflow.",
   "example": "Attack Example: Buffer Overflow in $HOME A buffer overflow in sccw allows local users to gain root access via the $HOME environmental variable. Attack Example: Buffer Overflow in TERM A buffer overflow in the rlogin program involves its consumption of the TERM environmental variable.",
   "references": "https://capec.mitre.org/data/definitions/10.html, CVE-1999-0906, CVE-1999-0046, http://cwe.mitre.org/data/definitions/120.html, http://cwe.mitre.org/data/definitions/119.html, http://cwe.mitre.org/data/definitions/680.html"
 }

target फ़ील्ड मॉडल तत्वों के वर्गों को सूचीबद्ध करता है जिनसे इस खतरे का मिलान किया जाना है। ये परिसंपत्तियाँ हो सकती हैं, जैसे: Actor, Datastore, Server, Process, SetOfProcesses, ExternalEntity, Lambda, LLM, Agent या Element, जो आधार वर्ग है और किसी भी चीज़ से मेल खाता है। यह एक Dataflow भी हो सकता है जो दो परिसंपत्तियों को जोड़ता है।

अन्य सभी फ़ील्ड (condition को छोड़कर) प्रदर्शन के लिए उपलब्ध हैं और अंतिम रिपोर्ट में निष्कर्षों को सूचीबद्ध करने के लिए टेम्पलेट में उपयोग की जा सकती हैं।

चेतावनी

threats.json फ़ाइल में स्ट्रिंग्स होती हैं जो eval() से चलती हैं। सुनिश्चित करें कि फ़ाइल में सही अनुमतियाँ हैं अन्यथा हमलावर स्ट्रिंग्स को बदल सकता है और आपको उनकी ओर से कोड चलाने के लिए मजबूर कर सकता है।

तर्क condition में रहता है, जहाँ target के सदस्यों का तार्किक मूल्यांकन किया जा सकता है। true लौटाने का मतलब है कि नियम एक निष्कर्ष उत्पन्न करता है, अन्यथा, यह निष्कर्ष नहीं है। Condition target के गुणों और/या target.control के नियंत्रण गुणों की तुलना कर सकता है और इन विधियों में से किसी एक को भी कॉल कर सकता है:

  • target.oneOf(class, ...) जहाँ class एक या अधिक है: Actor, Datastore, Server, Process, SetOfProcesses, ExternalEntity, Lambda, LLM, Agent या Dataflow,
  • target.crosses(Boundary),
  • target.enters(Boundary),
  • target.exits(Boundary),
  • target.inside(Boundary).

यदि target एक Dataflow है, तो याद रखें कि आप अन्य गुणों के साथ target.source और/या target.sink तक पहुँच सकते हैं।

परिसंपत्तियों पर शर्तें target.input और target.output गुणों का निरीक्षण करके सभी आने वाले और बाहर जाने वाले Dataflows का विश्लेषण कर सकती हैं। उदाहरण के लिए, केवल इनकमिंग ट्रैफ़िक वाले सर्वरों के विरुद्ध खतरे का मिलान करने के लिए, any(target.inputs) का उपयोग करें। एक अधिक उन्नत उदाहरण, SQL डेटास्टोर से जुड़ने वाले तत्वों का मिलान, होगा any(f.sink.oneOf(Datastore) and f.sink.isSQL for f in target.outputs)।

JSON से आयात करना

थोड़े से Python कोड के साथ JSON से एक खतरा मॉडल आयात करना संभव है (tests/input.json में पाए गए उदाहरण में विशेष प्रारूप पर ध्यान दें)। निम्नलिखित उदाहरण परीक्षणों में पाए गए input.json उदाहरण को आयात करता है। निम्नलिखित कोड को tm2.py के रूप में सहेजें।

root@kitploit:~

#!/usr/bin/env python3
# Example tm2.py contents
# Run: python tm2.py --dfd | dot -Tpng -o sample_json.png

from pytm import (
    TM,
    Actor,
    Boundary,
    Classification,
    Data,
    Dataflow,
    Datastore,
    Lambda,
    Server,
    DatastoreType,
    Assumption,
    load,
)

json_file_string = './tests/input.json'
with open(json_file_string) as input_json:
    TM.reset()
    tm = load(input_json)
    tm.process()

```
हम `tm2.py` को उसी तरह कॉल कर सकते हैं जैसे हमने पहले किया था, यहाँ `--dfd` के साथ और फिर आउटपुट को Graphviz (`dot`) पर रीडायरेक्ट करें:```bash

python tm2.py --dfd | dot -Tpng -o sample_json.png

```
## स्लाइड्स बनाना!

एक बार जब खतरा मॉडल पूरा और तैयार हो जाता है, तो भयावह प्रस्तुति चरण आता है - और अब pytm आपकी मदद भी कर सकता है, एक टेम्पलेट के साथ जो आपके खतरा मॉडल को स्लाइड्स में व्यक्त करता है, (RevealMD)[https://github.com/webpro/reveal-md] की शक्ति का उपयोग करके! बस docs/revealjs.md टेम्पलेट का उपयोग करें और आपको कुछ सुंदर स्लाइड्स मिलेंगी, पूरी तरह से अनुकूलन योग्य, जिन्हें आप अपने ब्राउज़र से प्रस्तुत और साझा कर सकते हैं।



https://github.com/izar/pytm/assets/368769/30218241-c7cc-4085-91e9-bbec2843f838



## वर्तमान में समर्थित खतरे```text
INP01 - Buffer Overflow via Environment Variables
INP02 - Overflow Buffers
INP03 - Server Side Include (SSI) Injection
CR01 - Session Sidejacking
INP04 - HTTP Request Splitting
CR02 - Cross Site Tracing
INP05 - Command Line Execution through SQL Injection
INP06 - SQL Injection through SOAP Parameter Tampering
SC01 - JSON Hijacking (aka JavaScript Hijacking)
LB01 - API Manipulation
AA01 - Authentication Abuse/ByPass
DS01 - Excavation
DE01 - Interception
DE02 - Double Encoding
API01 - Exploit Test APIs
AC01 - Privilege Abuse
INP07 - Buffer Manipulation
AC02 - Shared Data Manipulation
DO01 - Flooding
HA01 - Path Traversal
AC03 - Subverting Environment Variable Values
DO02 - Excessive Allocation
DS02 - Try All Common Switches
INP08 - Format String Injection
INP09 - LDAP Injection
INP10 - Parameter Injection
INP11 - Relative Path Traversal
INP12 - Client-side Injection-induced Buffer Overflow
AC04 - XML Schema Poisoning
DO03 - XML Ping of the Death
AC05 - Content Spoofing
INP13 - Command Delimiters
INP14 - Input Data Manipulation
DE03 - Sniffing Attacks
CR03 - Dictionary-based Password Attack
API02 - Exploit Script-Based APIs
HA02 - White Box Reverse Engineering
DS03 - Footprinting
AC06 - Using Malicious Files
HA03 - Web Application Fingerprinting
SC02 - XSS Targeting Non-Script Elements
AC07 - Exploiting Incorrectly Configured Access Control Security Levels
INP15 - IMAP/SMTP Command Injection
HA04 - Reverse Engineering
SC03 - Embedding Scripts within Scripts
INP16 - PHP Remote File Inclusion
AA02 - Principal Spoof
CR04 - Session Credential Falsification through Forging
DO04 - XML Entity Expansion
DS04 - XSS Targeting Error Pages
SC04 - XSS Using Alternate Syntax
CR05 - Encryption Brute Forcing
AC08 - Manipulate Registry Information
DS05 - Lifting Sensitive Data Embedded in Cache
SC05 - Removing Important Client Functionality
INP17 - XSS Using MIME Type Mismatch
AA03 - Exploitation of Trusted Credentials
AC09 - Functionality Misuse
INP18 - Fuzzing and observing application log data/errors for application mapping
CR06 - Communication Channel Manipulation
AC10 - Exploiting Incorrectly Configured SSL
CR07 - XML Routing Detour Attacks
AA04 - Exploiting Trust in Client
CR08 - Client-Server Protocol Manipulation
INP19 - XML External Entities Blowup
INP20 - iFrame Overlay
AC11 - Session Credential Falsification through Manipulation
INP21 - DTD Injection
INP22 - XML Attribute Blowup
INP23 - File Content Injection
DO05 - XML Nested Payloads
AC12 - Privilege Escalation
AC13 - Hijacking a privileged process
AC14 - Catching exception throw/signal from privileged block
INP24 - Filter Failure through Buffer Overflow
INP25 - Resource Injection
INP26 - Code Injection
INP27 - XSS Targeting HTML Attributes
INP28 - XSS Targeting URI Placeholders
INP29 - XSS Using Doubled Characters
INP30 - XSS Using Invalid Characters
INP31 - Command Injection
INP32 - XML Injection
INP33 - Remote Code Inclusion
INP34 - SOAP Array Overflow
INP35 - Leverage Alternate Encoding
DE04 - Audit Log Manipulation
AC15 - Schema Poisoning
INP36 - HTTP Response Smuggling
INP37 - HTTP Request Smuggling
INP38 - DOM-Based XSS
AC16 - Session Credential Falsification through Prediction
INP39 - Reflected XSS
INP40 - Stored XSS
AC17 - Session Hijacking - ServerSide
AC18 - Session Hijacking - ClientSide
INP41 - Argument Injection
AC19 - Reusing Session IDs (aka Session Replay) - ServerSide
AC20 - Reusing Session IDs (aka Session Replay) - ClientSide
AC21 - Cross Site Request Forgery
DS06 - Data Leak
DR01 - Unprotected Sensitive Data
AC22 - Credentials Aging (deprecated)
AC23 - Credentials Disclosure
AC24 - Use of hardcoded credentials
LLM01 - Direct Prompt Injection
LLM02 - Indirect Prompt Injection via Retrieved Content
LLM03 - Sensitive Data Leakage to Third-Party Provider
LLM04 - Training Data Poisoning
LLM05 - Excessive Agency via Unauthorized Tool Use
LLM06 - Arbitrary Code Execution via LLM Agent
LLM07 - Jailbreaking and Safety Bypass
LLM08 - Sensitive Information Disclosure Through Output
LLM09 - Untrusted Tool Launch Configuration


```
टूल डाउनलोड करें
  • Devbox शेल वातावरण से बाहर निकलें: exit
  • {{item.protocol}}
    {{item.dstPort}}
    }