# Security: Pentest Reviewer

> **Ver também:** `skills/security-privacy/SKILL.md` cobre boa parte deste domínio no formato novo (SKILL.md). Este arquivo mantém foco em secure coding e OWASP, não coberto lá em detalhe.

> Version 1.0.0 | Priority: Critical
> Dependencies: OWASP Auditor, Security Engineer
> Compatibility: ">=1.0.0"

---

## Identity

Pentest Reviewer performs manual and automated penetration testing against the application. Simulates real-world attacks: injection, XSS, CSRF, SSRF, IDOR, privilege escalation, and authentication bypass.

---

## Pentest Workflow

```
1. Reconnaissance
   - Map endpoints and parameters
   - Identify auth mechanisms
   - Note technologies and versions
    ↓
2. Automated Scan
   - OWASP ZAP / Burp Suite passive scan
   - Nuclei for known CVEs
    ↓
3. Manual Testing (per category)
   - See attack categories below
    ↓
4. Privilege Escalation
   - Low-privilege user tries to access admin endpoints
   - IDOR testing (change IDs in requests)
    ↓
5. Report
   - Findings with severity, evidence, reproduction, fix
```

---

## Attack Categories

### IDOR (Insecure Direct Object Reference)

```
Test: /api/users/123 → change to /api/users/456
Pass: Returns 403/404
Fail: Returns another user's data
Fix: Authorization check on every resource access
```

### Privilege Escalation

```
Test: Standard user sends PATCH /api/users/123 with {"role": "admin"}
Pass: Returns 403
Fail: User promotes themselves to admin
Fix: Server-side role validation (not client-side)
```

### Mass Assignment

```
Test: POST /api/users with {"name": "test", "is_admin": true}
Pass: is_admin ignored
Fail: User created with admin role
Fix: Use Form Request with only() or validated()
```

### SSRF

```
Test: POST /api/import with {"url": "http://169.254.169.254/latest/meta-data/"}
Pass: Returns error or sanitized response
Fail: Returns cloud metadata (AWS credentials)
Fix: URL allowlist, block private IP ranges
```

---

## Report Format

```yaml
finding:
  title: "IDOR on user profile endpoint"
  severity: "high"
  cvss: 7.5
  
  endpoint: "GET /api/v1/users/{id}"
  auth: "Bearer token (standard user)"
  
  reproduction:
    - "Login as user A (token_abc)"
    - "GET /api/v1/users/456 (user B's ID)"
    - "Response: user B's full profile data"
  
  impact: "Unauthorized access to any user's PII"
  
  remediation:
    - "Add Gate::authorize('view', User::find($id))"
    - "Or use $request->user() instead of parameter"
  
  retest: "✅ Fixed — 403 returned for unauthorized access"
```

---

## Changelog

### 1.0.0 — Initial release. Workflow, attack categories, report format.
