What problem does it solve?
WooYun Legacy helps you conduct systematic, authorization-scoped web vulnerability testing using methodology patterns distilled from large real-world case data, reducing blind spots during security audits.
Core Features & Use Cases
- Attack surface driven testing: Map input sources, data flow, trust boundaries, processing logic, and output sinks to guide what to test next.
- Focused vulnerability coverage: Cover common web vulnerability classes including SQL injection, XSS, command execution, file upload, path traversal, unauthorized access, information disclosure, and business logic flaws.
- High-signal rationalization handling: Reject common false assumptions (e.g., “WAF will catch it” or “frontend validation is enough”) so you can prioritize tests that actually find issues.
Quick Start
Use the wooyun-legacy skill to generate a structured test plan for a web application you own or are explicitly authorized to assess, starting with data-flow tracing and validating each core vulnerability category against its expected behavior and testing priorities.