byyaklang· 59 skills
Java "Ghost Bits" / Cast Attack playbook (Black Hat Asia 2026). Use when attacking Java services where 16-bit char is silently narrowed to 8-bit byte to bypass WAF/IDS for SQL injection, deserialization RCE, file upload (Webshell), path traversal, CRLF injection, request smuggling, and SMTP injection. Affects Tomcat, Spring, Jetty, Undertow, Vert.x, Jackson, Fastjson, Apache Commons BCEL, Apache HttpClient, Angus Mail, JDK HttpServer, Lettuce, Jodd, XMLWriter and re-enables many "patched" CVEs through WAF bypass.
$npx -y skills add yaklang/hack-skills --skill ghost-bits-cast-attackInstalls into the current project.
Run `npx skills use "https://github.com/yaklang/hack-skills" --skill "yaklang/hack-skills/ghost-bits-cast-attack"` and follow the generated skill instructions now. Read its complete output, redirecting it to a temporary file first if necessary. Resolve relative paths from the supporting-files directory it provides.
Use the skills in "https://github.com/yaklang/hack-skills" that are relevant to the current task. Run `npx skills add "https://github.com/yaklang/hack-skills"` and select the relevant skills, then follow their instructions.