server-side

Identify and demonstrate server-side vulnerabilities in web applications.

3|1|Updated May 26, 2026
One-click install
npx skills add https://github.com/LeoWSY-hashblue/-communitytools-custom --skill server-side-leowsy-hashblue
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: server-side
Source: https://github.com/LeoWSY-hashblue/-communitytools-custom/tree/main/skills/server-side
Command: npx skills add https://github.com/LeoWSY-hashblue/-communitytools-custom --skill server-side-leowsy-hashblue

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Server-side vulnerability testing to detect and demonstrate SSRF, HTTP Request Smuggling, Path Traversal, File Upload abuse, Insecure Deserialization, and Host Header injection, helping teams prioritize remediation and harden defenses.

Core Features & Use Cases

  • Catalogs and demonstrates key server-side vulnerability classes across modern web apps.
  • Provides structured workflows and evidence-ready guidance for pentests, bug bounty scopes, and security training.
  • Supports practical scenarios for client-server applications, CI pipelines, and security-readiness assessments.

Quick Start

Run a comprehensive server-side vulnerability assessment against your target URL and review the generated findings to plan remediations.

Frequently Asked Questions about server-side

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I test for server-side vulnerabilities like SSRF and HTTP Request Smuggling?

You test for server-side vulnerabilities by applying techniques for SSRF, HTTP Request Smuggling, Path Traversal, File Upload abuse, Insecure Deserialization, and Host Header manipulation to generate evidence and remediation guidance.

What is HTTP Request Smuggling and how does it impact web application security?

HTTP Request Smuggling is a server-side vulnerability where malformed requests bypass security controls, and testing it helps security teams assess risk, collect evidence, and prioritize remediation in bug bounty scopes and pentests.

How do I demonstrate Insecure Deserialization vulnerabilities with reproducible steps?

You demonstrate Insecure Deserialization by applying practical exploitation scenarios to your target, collecting evidence-ready reproducible steps, and providing structured remediation guidance suitable for security assessments and CI pipelines.

Can I use this server-side vulnerability assessment for bug bounty scopes and secure SDLC?

Yes, you can use this server-side vulnerability assessment for bug bounty scopes, pentests, and secure SDLC, as it provides structured workflows and evidence-ready guidance for client-server applications and security-readiness assessments.

What is the best way to audit web applications for Host Header manipulation and Path Traversal?

The best way to audit web applications is running a comprehensive server-side vulnerability assessment that identifies and demonstrates Host Header manipulation and Path Traversal, generating actionable findings to plan remediations.

Does server-side vulnerability testing provide remediation guidance for File Upload abuse?

Yes, server-side vulnerability testing provides remediation guidance for File Upload abuse by identifying the vulnerability, demonstrating practical exploitation scenarios, and collecting evidence to help security teams harden defenses.