CLAUDE CODE MARKETPLACES
SkillsMarketplacesMCPDigestLearnAdvertise

This week in Claude

Every Monday: Claude Code, Agent SDK, MCP, and the Anthropic platform moves worth your time.

Skills by Category
Frontend DevelopmentBackend & APIsTesting & QASecurityDevOps & CI/CDGit & Pull RequestsDocumentationCode Review & QualityAI & Agent BuildingSkill Development
MCP Servers by Category
Web & Browser AutomationDatabasesAI & LLM ToolsCloud & InfrastructureCommunication & MessagingDeveloper ToolsDesign & CreativeDocuments & KnowledgeSearch & Web CrawlingAutomation & Workflows
Marketplaces by Category
AI Agents & OrchestrationLLM IntegrationDevelopment ToolsFrontend & UIBackend & APIsDatabasesTesting & Code QualityDevOps & CloudSecurity & ComplianceGit & Version Control

Claude Code Marketplaces

Discover Claude Code plugins, extensions, and tools. Automatically updated directory of Anthropic Claude AI marketplaces with development tools, productivity plugins, and integrations.

Resources

  • Browse Skills
  • Browse MCP Servers
  • Browse Marketplaces
  • Plugins Reference

Community

  • About
  • Learn
  • Feedback
  • Privacy Policy
  • Advertise

Built for the Claude Code community with Claude Code by @mertduzgun

Independent project, not affiliated with Anthropic
  1. Skills
  2. /
  3. yaklang
  4. /
  5. hack-skills
  6. /
  7. Unauthorized Access Common Services

Unauthorized Access Common Services

Editor's Note

This is your playbook for exploiting exposed infrastructure services that should never face the internet but often do. It walks through unauthenticated Redis (write SSH keys, cron jobs, or webshells), Rsync data exfiltration, PHP-FPM FastCGI RCE, Ghostcat AJP file reads, Hadoop YARN job submission for shells, and H2 Console JNDI injection. Each section gives you detection commands, exploitation steps with actual tooling, and the hardening config that would have stopped you. The port matrix alone is worth having loaded when you're triaging nmap output. These are infrastructure wins, not web app bugs, so you're often root or equivalent once you land the exploit.

Install

npx skills add https://github.com/yaklang/hack-skills --skill unauthorized-access-common-services
Votes
0
Installs855
GitHub Stars862
First SeenJun 3, 2026
View on GitHub

Comments

Login to comment