mirror of
https://github.com/Strategic-Automation/violin.git
synced 2026-08-14 12:33:37 +02:00
- redirects-unvalidated.md: systematic open-redirect probe loop (17 params, Location-header capture, external-redirect follow, allowlist-substring bypass) - auth-bypass.md: when to run default/weak creds (after user-enum finds admin; hand-testable set is not brute force) - xss.md: URL-valued fields (avatar/link) as stored/blind XSS vectors - business-logic.md: referral self-referral registration recipe (register A, refer B, check both sides for credit) - exhaustive-coverage.md: mandatory auth/registration-flow coverage step so the routing triggers no matter which playbook the agent reads first No benchmark names or session inventory; generic OWASP technique only.