Agent skill

Hunt Aspnet

by sickn33 in sickn33/agentic-awesome-skills

“Hunt ASP.NET-specific surface”

— description from SKILL.md by sickn33
MITAuto-check passedSecurity

Install Hunt Aspnet

skills CLI
$ npx skills add sickn33/agentic-awesome-skills --skill hunt-aspnet -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sickn33/agentic-awesome-skills hunt-aspnet --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/hunt-aspnet .claude/skills/hunt-aspnet && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
hunt-aspnet
GitHub stars
47k
Used in
1 other repo
Token cost
~5.5k tokens
SKILL.md length
1,953 words
Files
1
Skills in repo
1,493
Repo updated
First seen
Licence
MIT

At a glance

  • Works in 12 steps: Fingerprint the framework version.… → Locate every form with __VIEWSTATE.… → Check __VIEWSTATEENCRYPTED value. Empty… → …
  • SKILL.md covers Crown Jewel Targets, Attack Surface Signals, Step-by-Step Hunting Methodology and Payload & Detection Patterns, plus 7 more sections
  • Calls curl; reaches x.com

About this skill

Hunt Aspnet is a skill in sickn33/agentic-awesome-skills (47k stars). Its SKILL.md is about 5.5k tokens, and copies of it appear in 1 other owners' repositories. Licence: MIT.

Requirements

  • Compatibility (from SKILL.md): Requires explicit written authorization for a target scope plus the relevant testing tools for this technique. Docs-only; helper scripts and commands not bundled.

Workflow steps

12 steps, taken from the first numbered list in SKILL.md.

  1. Fingerprint the framework version. Trigger any 500 error (stale ViewState POST is a reliable way) and look for Version Information…
  2. Locate every form with __VIEWSTATE. Spider the target and grep for name="__VIEWSTATE". Each is a candidate sink for deserialization…
  3. Check __VIEWSTATEENCRYPTED value. Empty (value="") means ViewState is signed-only via but NOT encrypted. Recovery of the validation key →…
  4. Test the ViewState parser-error differential (the dual-parser anti-pattern). Send 7+ ViewState shapes and classify responses
  5. Look for load-balanced cross-node ViewState MAC failures. If POST gets a 500 with "Validation of viewstate MAC failed. If this application…
  6. Probe trace.axd and elmah.axd. If either returns 200 anonymously, it's a Critical finding (trace leaks every request + headers + form…
  7. Enumerate WCF services (.svc). For each, fetch ?wsdl and ?mex (metadata exchange). MEX endpoints sometimes return full service contracts…
  8. Test request-validator bypass. ASP.NET's request validator blocks < in query strings by default. Bypass categories that may still get…
  9. Check customErrors mode. If 500s expose full stack traces, framework versions, file paths, internal method names → customErrors mode="Off"…
  10. Look for Telerik components. Telerik.Web.UI.WebResource.axd?type=rau is the historic upload-to-RCE chain (CVE-2017-11317). The…
  11. SharePoint-specific deserialization paths — see hunt-sharepoint skill for the ToolPane.aspx + anonymous FormDigest + unencrypted ViewState…
  12. SafeControl enumeration via reflection. SharePoint's Picker.aspx?PickerDialogType= (and DNN-equivalent endpoints) accept class names and…

What it can do on your machine

Read from SKILL.md and the folder at commit 680176d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • x.com

    Also links to:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires explicit written authorization for a target scope plus the relevant testing tools for this technique. Docs-only; helper scripts and commands not bundled.

    From compatibility in the SKILL.md frontmatter.

Context cost

Hunt Aspnet loads about 5.5k tokens when it runs. Until then it costs about 10 tokens; SKILL.md has 1,953 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~10
When it runs · the whole SKILL.md, loaded when a task matches
~5.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sickn33/agentic-awesome-skills at commit 680176d, republished under its MIT licence (© sickn33). 1,953 words, ~5,465 tokens.

Download SKILL.mdSave it as .claude/skills/hunt-aspnet/SKILL.md (or your agent's skills folder).
name
hunt-aspnet
description
Hunt ASP.NET-specific surface
compatibility
Requires explicit written authorization for a target scope plus the relevant testing tools for this technique. Docs-only; helper scripts and commands not bundled.
category
security
risk
offensive
source
https://github.com/elementalsouls/Claude-BugHunter
source_repo
elementalsouls/Claude-BugHunter
source_type
community
date_added
2026-09-20
license
MIT
license_source
https://github.com/elementalsouls/Claude-BugHunter/blob/main/LICENSE
sources
github, authorized-engagement
report_count
1

⚠️ AUTHORIZED USE ONLY This skill is for educational purposes or authorized security assessments only. You must have explicit, written permission from the system owner before using this tool. Misuse of this tool is illegal and strictly prohibited.

Mandatory confirmation gate Before running any command that probes, exploits, changes, persists on, extracts data from, or attempts credential access against a target:

  1. Ask the user to state the exact target URL, IP, account, or resource.
  2. Ask the user to confirm written authorization and the permitted scope.
  3. Show the exact command(s) and explain their expected effect.
  4. Wait for explicit confirmation in the current conversation.

Without that confirmation, remain read-only and provide defensive guidance only. Prefer a sandbox, disposable VM, or controlled lab.

Crown Jewel Targets

ASP.NET deserialization bugs pay among the highest amounts in bug bounty when they reach RCE. Even when patched, the disclosure-tier findings (signed-only ViewState, dual-parser differential, request-validator quirks) reliably pay Low-Medium.

Highest-value targets:

  • SharePoint farms (any version — 2013/2016/2019/SE) — sign-only ViewState + permissive ToolPane.aspx + anonymous FormDigest creates the CVE-2025-53770 ToolShell precondition chain
  • Telerik UI for ASP.NET AJAX — Telerik.Web.UI.WebResource.axd is a documented RCE sink when keys leak (CVE-2017-11317, CVE-2017-11357, CVE-2019-18935)
  • Classic ASP.NET Webforms enterprise apps — banking portals, dealer portals, HR systems left on .NET Framework 4.x
  • WCF services (*.svc?WSDL) — often forgotten admin endpoints with looser auth than the main app
  • Sitecore CMS — ViewState + Sitecore-specific deserialization chains (CVE-2021-42237)
  • DotNetNuke (DNN) — historic ViewState RCE chains
  • Umbraco CMS — ViewState + custom deserialization sinks

Asset types that pay most: internet-reachable ASP.NET Webforms apps > WCF admin services > Telerik-integrated sites > Classic ASP.NET MVC with VSF (very rare)


Attack Surface Signals

Response headers indicating ASP.NET:

X-AspNet-Version: 4.0.30319          (classic — disclosure on its own)
X-Powered-By: ASP.NET
X-AspNetMvc-Version: 5.2
Server: Microsoft-IIS/10.0
Set-Cookie: ASP.NET_SessionId=...
Set-Cookie: .ASPXAUTH=...            (Forms auth cookie)
Set-Cookie: .ASPXFORMSAUTH=...
Set-Cookie: ASP.NET_SessionId=...; SameSite=None  (suggests cross-origin embedding)

Body signals (in form HTML):

<input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="..." />
<input type="hidden" name="__VIEWSTATEGENERATOR" id="__VIEWSTATEGENERATOR" value="..." />
<input type="hidden" name="__VIEWSTATEENCRYPTED" id="__VIEWSTATEENCRYPTED" value="" />
                                        ↑ EMPTY = signed-only, not encrypted = exploitable if key leaks
<input type="hidden" name="__EVENTVALIDATION" id="__EVENTVALIDATION" value="..." />
<input type="hidden" name="__REQUESTDIGEST" id="__REQUESTDIGEST" value="0x...,...">
                                        ↑ SharePoint CSRF token; if anon-issued, see hunt-sharepoint

URL patterns to probe:

/trace.axd                            (per-app trace viewer; sometimes anon-accessible)
/elmah.axd                            (ELMAH error log viewer)
/elmah.axd/?id=...                    (ELMAH RCE / stack-trace leak)
/*.svc                                (WCF services)
/*.svc?wsdl                           (WCF WSDL)
/*.svc/mex                            (Metadata Exchange)
/*.asmx                               (legacy SOAP)
/*.asmx?WSDL                          (legacy SOAP description)
/*.asmx?disco                         (legacy discovery)
/Telerik.Web.UI.WebResource.axd       (Telerik AJAX components)
/ChartImg.axd                         (DataVisualization controls; historic deserialization)
/ScriptResource.axd                   (script resource handler; sometimes leaks paths)
/WebResource.axd                      (web resource handler)
/_vti_bin/*                           (SharePoint Web Service Forwarder)
/api/                                 (Web API 2.x is ASP.NET on classic framework)
/signin                               (often FedAuth / WS-Federation)

Tech-stack signals:

  • Server: Microsoft-IIS/10.0 (or /8.5, /7.5) — confirmed Windows + IIS
  • X-AspNet-Version header — classic .NET Framework (4.x); .NET Core/5+ does NOT emit this
  • Cookies with ASP.NET_SessionId, .ASPXAUTH, FedAuth — Forms or claims auth
  • __VIEWSTATE in form bodies — Webforms (NOT MVC, NOT Razor Pages, NOT Blazor)
  • MicrosoftSharePointTeamServices header (sometimes stripped by ELB but leaks in start.aspx body) — SharePoint

Step-by-Step Hunting Methodology

  1. Fingerprint the framework version. Trigger any 500 error (stale ViewState POST is a reliable way) and look for Version Information: Microsoft .NET Framework Version:X.X.XXXXX; ASP.NET Version:X.X.XXXX.X in the error body. This banner discloses both the runtime and ASP.NET-version-specific patch level. .NET 4.0.30319 + ASP.NET 4.8.x is the most common modern combination.

  2. Locate every form with __VIEWSTATE. Spider the target and grep for name="__VIEWSTATE". Each is a candidate sink for deserialization attacks if MAC / encryption is bypassable.

  3. Check __VIEWSTATEENCRYPTED value. Empty (value="") means ViewState is signed-only via <machineKey> but NOT encrypted. Recovery of the validation key → arbitrary deserialization. Non-empty (value="something") means ViewState is BOTH signed and encrypted; both keys needed to forge.

  4. Test the ViewState parser-error differential (the dual-parser anti-pattern). Send 7+ ViewState shapes and classify responses:

    • Trivial garbage (AAAA) → "Validation of viewstate MAC failed"
    • Real prefix from current page → "Validation of viewstate MAC failed"
    • Flipped-bit real ViewState → "Validation of viewstate MAC failed"
    • Oversize (A * 100000) → "Validation of viewstate MAC failed"
    • XML-shaped (<xss/>) → "The state information is invalid for this page and might be corrupted" ← different parser path
    • LosFormatter-style prefix (/wEPDwUKMTcxNzgyOTQwMmRkkz9p4lzA...) → "The state information is invalid for this page and might be corrupted"

    The differential proves there are two distinct deserialization entry points, one of which dispatches BEFORE the MAC check on some payload shapes. Historically this enables MAC-before-parse-bypass exploits.

  5. Look for load-balanced cross-node ViewState MAC failures. If POST gets a 500 with "Validation of viewstate MAC failed. If this application is hosted by a Web Farm or cluster, ensure that <machineKey> configuration specifies the same validationKey...", the farm has multiple WFEs WITHOUT machineKey sync, or without sticky-session affinity. Operationally this breaks legit users; security-wise it confirms farm topology.

  6. Probe trace.axd and elmah.axd. If either returns 200 anonymously, it's a Critical finding (trace leaks every request + headers + form data; ELMAH leaks every server error including stack traces).

  7. Enumerate WCF services (.svc). For each, fetch ?wsdl and ?mex (metadata exchange). MEX endpoints sometimes return full service contracts including admin operations.

  8. Test request-validator bypass. ASP.NET's request validator blocks < in query strings by default. Bypass categories that may still get through:

    • HTML-entity-encoded payloads (&lt;script&gt; — but these don't execute)
    • Encoded inside JSON / XML POST bodies (different content-type ≠ same validator)
    • In path segments (not query) — validator scope depends on framework version
    • In Cookie / Referer headers (varies)
    • Inside <%@ ... %> ASP directives if reached via WebDAV PUT (rare)
  9. Check customErrors mode. If 500s expose full stack traces, framework versions, file paths, internal method names → customErrors mode="Off" is set. Should be RemoteOnly for production.

  10. Look for Telerik components. Telerik.Web.UI.WebResource.axd?type=rau is the historic upload-to-RCE chain (CVE-2017-11317). The dialogParametersHolder parameter chain (CVE-2019-18935) requires the encryption key but is otherwise RCE.

  11. SharePoint-specific deserialization paths — see hunt-sharepoint skill for the ToolPane.aspx + anonymous FormDigest + unencrypted ViewState chain.

  12. SafeControl enumeration via reflection. SharePoint's Picker.aspx?PickerDialogType=<TypeName> (and DNN-equivalent endpoints) accept class names and return DIFFERENT error messages for "type exists but not whitelisted" vs "type does not exist." Feed a wordlist of Microsoft.SharePoint.*.WebControls.* types to enumerate the SafeControl list — useful for CVE-2019-0604-family hunting.


Payload & Detection Patterns

Stack-trace fingerprint (trigger via stale ViewState POST):

bash
curl -sk -X POST "https://target.example/page.aspx" \
  --data "__VIEWSTATE=AAAA&__VIEWSTATEGENERATOR=AAAA"
# Inspect body for:
#  - "Validation of viewstate MAC failed" → confirms signed ViewState
#  - "The state information is invalid for this page" → confirms ALTERNATE parser path
#  - "Version Information: Microsoft .NET Framework Version:X.X.XXXXX" → exact patch level
#  - "Microsoft.SharePoint.Client.ServerStub..." → SharePoint farm

ViewState parser-error differential probe (Python):

python
import requests, re, json
S = requests.Session(); S.verify = False
# Get fresh form
r = S.get("https://target.example/path/page.aspx")
real_vs = re.search(r'__VIEWSTATE" id="__VIEWSTATE" value="([^"]+)', r.text).group(1)
real_vsg = re.search(r'__VIEWSTATEGENERATOR" id="__VIEWSTATEGENERATOR" value="([^"]+)', r.text).group(1)

# Test 7 payload shapes
for label, vs in [
    ("trivial",      "AAAA"),
    ("real",         real_vs),
    ("flipped-bit",  real_vs[:50] + "X" + real_vs[51:]),
    ("oversize",     "A" * 100000),
    ("base64",       "VGVzdE1hcmtlcjY3OFhZWg=="),
    ("xml-shaped",   "<xss/>"),
    ("losformatter", "/wEPDwUKMTcxNzgyOTQwMmRkkz9p4lzA" + "A"*50),
]:
    r = S.post("https://target.example/path/page.aspx",
               data={"__VIEWSTATE": vs, "__VIEWSTATEGENERATOR": real_vsg})
    title = re.search(r'<title>([^<]+)</title>', r.text)
    title = title.group(1)[:100] if title else "—"
    print(f"  [{label:14s}] {r.status_code}  {title}")

trace.axd anonymous check:

bash
curl -sk -o /dev/null -w "%{http_code}\n" "https://target.example/trace.axd"
# 200 = full trace dump exposed → Critical
# 403 = mod set to localhost-only → check via X-Forwarded-For: 127.0.0.1

WCF service enumeration:

bash
# Find all .svc files
curl -sk "https://target.example/" -o body.html
grep -oE '/[a-zA-Z0-9/_-]+\.svc' body.html | sort -u
# For each found:
curl -sk "https://target.example/Service.svc?wsdl" | xmllint --format - | head -60

Request-validator bypass categories:

# Default: <script>alert(1)</script> in ?q= → "Potentially dangerous Request.QueryString value detected"
# Bypasses that sometimes work:
?q=%3cscript%3e            (URL-encoded — depends on validator config)
?q=<svg/onload=alert(1)>  (depends on validator version)
?q=<%00script>             (NUL-byte; older validators)
?q=javascript:alert(1)     (no < at all — passes validator)
Cookie: foo=<script>       (cookie body not validated by default)
Referer: http://x.com/<script>  (referer not validated in classic ASP.NET)

Telerik exploit gate (CVE-2019-18935 — requires encryption keys):

bash
# Fingerprint Telerik
curl -sk "https://target.example/Telerik.Web.UI.WebResource.axd?type=rau" -X POST
# If response is RadAsyncUploadHandler-style → Telerik present; try keys
# Public exploits require leaked machineKey AND telerikEncryptionKey

Common Root Causes

  1. viewStateEncryption="Auto" defaults to signed-only on pages without sensitive ViewState data. Many SharePoint pages are configured this way. When __VIEWSTATEENCRYPTED is empty, ViewState is signed-only — recovery of validationKey alone enables forgery.

  2. <machineKey> AutoGenerate in a Web Farm. Each WFE generates a different key on first boot; ViewState issued by one WFE fails MAC validation on another. Operationally produces 500s; security-wise broadcasts the topology (the error message names the cluster).

  3. <customErrors mode="Off"> left from development. Stack traces with full method names, file paths, version banners exposed to anonymous internet users.

  4. trace.axd / elmah.axd left enabled in production. Often forgotten in <system.web><trace enabled="true"> blocks.

  5. Forgotten WCF .svc admin endpoints. Built for internal admin tooling, never disabled when the main app went to internet exposure.

  6. Dual-parser anti-pattern: ObjectStateFormatter (legacy) vs LosFormatter (modern) deserialize in different orders relative to MAC validation. Some payload shapes hit the legacy parser BEFORE MAC check.

  7. Request validator only applies to URL-encoded body and querystring. Headers, cookies, XML/JSON bodies, and multipart fields are NOT validated by default. Developers assume validator is universal; it is not.

  8. <machineKey> checked into source repos. Configuration check-ins to GitHub frequently leak validation/decryption keys. Combine with hunt-misc source-recon for Telerik / SharePoint / DNN keys.

  9. SafeControls web.config entries trusted to gate deserialization. SharePoint's <SafeControl> list determines which classes Picker.aspx can instantiate. Bypasses exist when the inheritance check is the only gate (CVE-2019-0604 family).


Show full SKILL.md (844 more words)Show less

Bypass Techniques

DefenseBypass
__VIEWSTATEENCRYPTED non-empty (encrypted)Recover both decryption + validation keys from any source-code leak / config-disclosure / VS forge primitive; without keys, deserialization cannot be triggered
Request validator blocks < in querystringMove payload to Cookie / Referer / JSON body / multipart filename — validator doesn't reach those contexts in classic ASP.NET
EnableViewStateMac="true" enforcedRecover validationKey from web.config disclosure or <machineKey> AutoGenerate fingerprinting (ysoserial.net --minify --islegacy mode generates ViewState that passes some MAC-validation gaps)
trace.axd localhost-onlySet X-Forwarded-For: 127.0.0.1 if the trace mode is localOnly and the validation uses Request.UserHostAddress (some apps use Forwarded-For instead)
WCF .svc 401 on anonymousTry ?wsdl and ?mex first; metadata is sometimes anonymously enumerable even when service ops require auth
Telerik upload patchedCheck the Telerik version: anything pre-2017Q1 (build 2017.1.118 or earlier) is the original RAU RCE. Check 2017Q3 - 2019Q3 for CVE-2019-18935
SafeControl whitelist enforcedInheritance gate (instanceof PickerDialog) IS the gate on patched SP — bypass requires finding a SafeControl subclass with a deserialization sink; enumerate via Picker.aspx
customErrors mode="On" (no stack traces)Force a different error path: invalid Content-Length, malformed ViewState that triggers a parser-level exception below the customErrors handler

Gate 0 Validation

Before writing the report, confirm:

  1. What can the attacker DO right now with the disclosed information?

    • trace.axd 200 with full request dump → Critical (PII / session cookies / Authorization headers exposed)
    • elmah.axd 200 with error log → High (stack traces + internal paths + sometimes credentials)
    • __VIEWSTATEENCRYPTED empty + recoverable machineKey via separate finding → Critical chain to RCE
    • __VIEWSTATEENCRYPTED empty without key recovery → Low-Medium (primitive present, not exploitable on its own)
    • Stack traces in 500s → Low unless they include credentials / connection strings
  2. Have you reproduced the full chain to attacker-attainable impact, or only the primitive?

    • Cross-reference triage-validation Pre-Severity Gate. "Primitive confirmed" is not Critical until the chain ends in impact.
  3. Can a triager reproduce in <10 min from your report?

    • Each step copy-pasteable curl / Python.
    • For RCE chains: link the public exploit tool (ysoserial.net, viewgen, telerik-revda) and the specific gadget chain.

Real Impact Examples

Scenario A — Signed-only ViewState + permissive ToolPane on EoL SharePoint 2013

https://target-portal.example/_layouts/15/ToolPane.aspx?DisplayMode=Edit returns 200 anonymously. The form contains __VIEWSTATE (signed only — __VIEWSTATEENCRYPTED=""), and __REQUESTDIGEST is anonymously issued via _api/contextinfo. Combined with SP2013 being end-of-life (no patch will ever ship), this is the canonical CVE-2025-53770 "ToolShell" precondition chain on a permanently-unpatched code path. Reported severity: Critical. The dual-parser test (Section 4 of Methodology) confirmed that XML-shaped payloads reach the legacy ObjectStateFormatter BEFORE MAC validation — additional evidence that the chain is reachable even without full machineKey recovery (though full RCE requires both).

Scenario B — Telerik RadAsyncUploadHandler exposed on legacy bank portal

/Telerik.Web.UI.WebResource.axd?type=rau returns the Telerik upload handler. Telerik version (visible in JS bundle metadata) is 2016.3.1027. CVE-2017-11317 applies — keys are baked into the public Telerik DLL of that version. Upload → write aspx to /app_data/ → request → RCE. Reported severity: Critical.

Scenario C — trace.axd + elmah.axd both exposed on enterprise HR portal

trace.axd 200 returns 50 most recent requests, including Authorization: Bearer eyJ... headers on API requests. elmah.axd 200 returns full error log with database connection-string in one of the exceptions. Reported severity: Critical (credentials in plaintext to anonymous internet).


  • hunt-rce — ViewState deserialization is the headline ASP.NET RCE path; signed-only ViewState + leaked machineKey = RCE every time. Chain primitive: ASP.NET ViewState dual-parser MAC-bypass anti-pattern detected (signed but not encrypted, <%@ Page enableViewStateMac="true" viewStateEncryptionMode="Never" %>) + machineKey recovered (from web.config disclosure, elmah.axd, source leak, or GitHub) → hunt-rce ysoserial.net TypeConfuseDelegate gadget → arbitrary command in w3wp.exe worker-process identity.
  • hunt-sharepoint — SharePoint farms inherit every ASP.NET anti-pattern plus their own surface. Chain primitive: ASP.NET fingerprint reveals SharePoint (X-SharePoint headers + /_layouts/ reachable) → pivot to hunt-sharepoint for SP-specific RCE paths (ToolShell, SafeControl reflection) before generic ViewState attack.
  • hunt-ntlm-info — IIS sites that advertise NTLM/Negotiate anonymously leak AD topology. Chain primitive: ASP.NET app behind IIS with WWW-Authenticate: NTLM → hunt-ntlm-info Type-2 challenge capture → internal forest name → cross-reference Entra tenant via m365-entra-attack discovery.
  • hunt-file-upload — Telerik RadAsyncUpload, Kentico, Umbraco, and DotNetNuke all have historical upload-handler RCE. Chain primitive: ASP.NET CMS fingerprinted → hunt-file-upload bypass matrix against the CMS upload handler → .aspx written into web-accessible path → request → RCE under app-pool identity.
  • triage-validation — trace.axd/elmah.axd disclosure is only Critical when it actually leaks live credentials/tokens; pure stack traces are usually Low. Chain primitive: pull every reported finding through triage-validation 7-Question Gate before submission — distinguish "verbose error" (informational) from "live bearer token in error log" (Critical) before writing the report (redteam-report-template).

When to Use

  • You have explicit, written authorization to assess the target in scope, and the task matches this skill's vulnerability class or technique within a bug-bounty or penetration-test engagement.
  • You need the recon, exploitation, or validation workflow described below — executed strictly inside the approved scope.

Limitations

  • Authorized scope only: the confirmation gate above is mandatory before any probing, exploitation, or credential-access command.
  • Docs-only import: upstream helper scripts, commands, engine, and research assets are not bundled; reinstall tooling from the source repo when needed.
  • Validate every finding (see triage-validation) before reporting; report via report-writing. Prefer a sandbox, disposable VM, or controlled lab.
Example
bash
# Read-only first step; confirm scope before anything active.
cat scope.txt  # target list from the authorized engagement brief

Adapted from elementalsouls/Claude-BugHunter (MIT); frontmatter, When to Use/Limitations, and safety boundaries added for upstream compliance. Docs-only import: executable helpers, commands, engine, and research assets not bundled.

© sickn33, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/hunt-aspnet of sickn33/agentic-awesome-skills.

Open the folder on GitHubat commit 680176d

Used in 1 other repository

We found 5 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in sickn33/agentic-awesome-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Hunt Aspnet next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Hunt Aspnet compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Hunt Aspnet this skillsickn33/agentic-awesome-skills47k1 repos~5.5kAutomated safety check: PassMIT
Migrate Dotnet9 To Dotnet10dotnet/skills5.6k2 repos~4.8kAutomated safety check: PassMIT
Winui AppLanceMcCarthy/DevOpsExamples1721 repos~2.8kAutomated safety check: PassApache-2.0
Event EndeavoursSapiensAnatis/Dawnshard151—~944Automated safety check: PassMIT
Configure Telerik NugetLanceMcCarthy/DevOpsExamples172—~976Automated safety check: PassMIT
GitHub Actions Failure DebuggingLanceMcCarthy/DevOpsExamples172—~312Automated safety check: PassMIT

Similar skills

  • Official

    Migrate a .NET 9 project or solution to .NET 10 and resolve all breaking changes.

    5.6k GitHub starsUsed in 2 repos~4.8k tokens
    DevOps & CloudAuto-check passed
  • Winui App

    LanceMcCarthy/DevOpsExamples

    Bootstrap, develop, and design modern WinUI 3 desktop applications with C and the Windows App SDK using official Microsoft guidance, WinUI Gallery patterns, Windows App SDK samples, and…

    172 GitHub starsUsed in 1 repo~2.8k tokens
    DevOps & CloudAuto-check passed
  • Event Endeavours

    SapiensAnatis/Dawnshard

    Implement event missions (endeavours) into the mission designer project.

    151 GitHub stars~944 tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • Configure Telerik Nuget

    LanceMcCarthy/DevOpsExamples

    Helps setup, configure and manage Telerik NuGet feeds in your repo's nuget.config file.

    172 GitHub stars~976 tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • GitHub Actions Failure Debugging

    LanceMcCarthy/DevOpsExamples

    Guide for debugging failing GitHub Actions workflows. An agent skill from LanceMcCarthy/DevOpsExamples.

    172 GitHub stars~312 tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Official

    Migrate a .NET 10 project or solution to .NET 11 and resolve all breaking changes.

    5.6k GitHub starsUsed in 1 repo~3.6k tokens
    DevOps & CloudAuto-check passed

More from sickn33/agentic-awesome-skills

All 1,493 skills in this repo
  • Liuguang Banlan UI

    sickn33/agentic-awesome-skills

    Implements an interface in one of two named color modes, iridescent white or colorful black, from a parameterized starter that reports measured color intensity.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • User Thoughts Memory

    sickn33/agentic-awesome-skills

    Saves a user's project decisions, rules and preferences into a project-local mdbase so later sessions and other agents can recover the intent.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Using LWC Memory and Graphs

    sickn33/agentic-awesome-skills

    Keeps project decisions, research and verified results available across coding-agent sessions through LWC memory, a document Wiki graph and a CodeGraph code index.

    47k GitHub starsUsed in 1 repo~2k tokens
    Auto-check passed
  • Find Complementary Founders

    sickn33/agentic-awesome-skills

    Guides an agent through assessing its own owner for cofounder fit, publishing an approved profile, and ranking complementary profiles other agents published for their owners.

    47k GitHub starsUsed in 1 repo~4.8k tokens
    Auto-check passed
  • Whatsapp Cloud API

    sickn33/agentic-awesome-skills

    Integracao com WhatsApp Business Cloud API (Meta). An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~4.5k tokens
    Auto-check passed
  • Cline Pilot

    sickn33/agentic-awesome-skills

    Acts as a proxy for the Cline CLI, dispatching coding tasks one at a time, monitoring runs by hard evidence, relaying decisions to you and learning per-project preferences.

    47k GitHub starsUsed in 1 repo~4.6k tokens
    Auto-check passed

Works with

Categories

Questions about Hunt Aspnet

How do I install Hunt Aspnet in Claude Code?

Run `npx skills add sickn33/agentic-awesome-skills --skill hunt-aspnet -a claude-code`. Or copy the skill folder (skills/hunt-aspnet in sickn33/agentic-awesome-skills) into .claude/skills/hunt-aspnet in your project. Claude Code loads it when a task matches its description.

How do I install Hunt Aspnet in Codex?

Run `npx skills add sickn33/agentic-awesome-skills --skill hunt-aspnet -a codex`. Or copy the skill folder (skills/hunt-aspnet in sickn33/agentic-awesome-skills) into .agents/skills/hunt-aspnet in your project. Codex loads it when a task matches its description.

Can I use Hunt Aspnet in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sickn33/agentic-awesome-skills --skill hunt-aspnet -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hunt-aspnet, .gemini/skills/hunt-aspnet, .github/skills/hunt-aspnet and .opencode/skills/hunt-aspnet in your project.

What does Hunt Aspnet need to run?

Going by SKILL.md and its folder, Hunt Aspnet needs the command-line tools its instructions call (curl). Compatibility (from SKILL.md): Requires explicit written authorization for a target scope plus the relevant testing tools for this technique. Docs-only; helper scripts and commands not bundled..

Does Hunt Aspnet access the network?

SKILL.md names 2 domains. In commands or code: x.com; the agent is likely to contact it when it follows the instructions. As links in the text: github.com. This is read from the text; nothing was executed.

Is Hunt Aspnet safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Hunt Aspnet use?

Hunt Aspnet is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Hunt Aspnet use?

About 5.5k tokens (SKILL.md is roughly 22k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Hunt Aspnet?

Skills that share tags, products or a category with Hunt Aspnet: Migrate Dotnet9 To Dotnet10 (dotnet/skills, 5.6k stars), Winui App (LanceMcCarthy/DevOpsExamples, 172 stars), Event Endeavours (SapiensAnatis/Dawnshard, 151 stars) and Configure Telerik Nuget (LanceMcCarthy/DevOpsExamples, 172 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Hunt Aspnet?

sickn33 (a GitHub user) maintains it in sickn33/agentic-awesome-skills, which has 47,379 GitHub stars. The repository holds 1,493 skills in this directory. The repository was last updated on October 9, 2026.

Source: sickn33/agentic-awesome-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.