← Files Tahr SecurityARCHIVED FILE

skills/tahr-trace-dangerous-inputs/references/exploitability-proof-gates.md

3.29 KB · Sep 30, 2026 · 23:16 UTC

↓ Download file

# Exploitability Proof Gates

| Claim | Confirm only with | Keep as candidate when limited to |
|---|---|---|
| SQL injection | Database-derived version/user/database, schema/table/column, or bounded row data tied to the exact request | Error, boolean/size delta, timing, WAF signal |
| NoSQL/search injection | Unauthorized query-semantic change, protected record access, auth bypass, or bounded data extraction | Parser error, different empty response, timing |
| Command/code/RCE | Low-impact command output or controlled callback attributable to the exact input | Delay, error, reflected metacharacter |
| SSTI/expression injection | Server-side expression evaluation plus safe execution or protected data access appropriate to the claim | Reflected template syntax or template error |
| Unsafe deserialization | Controlled type/gadget behavior causing a safe callback, command effect, or unauthorized state/data result | Serialized format detection or parser exception |
| SSRF/webhook fetch | Controlled callback proving server origin, internal-service response, low-sensitivity metadata, redirect-chain, or safe file/protocol proof from the exact sink | Public fetch capability, DNS/timing only, accepted URL |
| XXE | Safe local file canary, parser-origin callback, or internal-resource proof | XML error or entity syntax acceptance |
| Path traversal/file read | Contents or fingerprint of a safe known file outside the intended namespace | Normalized path echo or error difference |
| XSS | Browser-generated dialog, console marker, outbound request, or DOM mutation from the real trigger context | Reflection, stored markup, source sink, accepted SVG/HTML |
| CORS | Foreign-origin browser reads sensitive authenticated data or performs a sensitive action | Reflected ACAO, null origin, missing Vary alone |
| postMessage | Controlled foreign sender causes sensitive DOM, navigation, data, or state effect | Listener presence or weak-looking origin check |
| Clickjacking | Sensitive action can be framed and safely demonstrated through the deceptive interaction | Missing frame headers on a nonsensitive page |
| Upload RCE | Uploaded artifact produces safe command output at the served/processed location | File acceptance, dangerous extension, guessed URL |
| Upload XSS | Browser runtime execution from the actual render/preview/download context | Script markup intact or inline content type alone |
| Document/upload SSRF | Callback, metadata, or internal response caused by document processing | Upload success or external reference in the file |
| Cache poisoning/deception | A separate follow-up request receives the poisoned or identity-specific cached response with stable cache evidence | Reflection, first response, cache headers alone |
| Request smuggling | Reproducible cross-request, queue, cache, or backend request impact from a concrete request pair | Timing or ambiguous connection hang |

## Evidence minimum

Preserve endpoint/action, method, field/carrier, actor/session context, exact safe mutation, baseline, response/proof, concrete impact, reproduction steps, and artifact references. Use raw secrets only transiently; store value class, length, fingerprint, and redacted context.

When a gate cannot be passed safely, retain the candidate, state the missing proof, and recommend a bounded validation in a disposable environment.

SHA-256: d6abbd3ba05e905ee168798ab99bdd75410bf5e928235519b141af386348e36a