Skip to content

Instantly share code, notes, and snippets.

View aels's full-sized avatar
💭
No business. Everyone will die.

0xbadad aels

💭
No business. Everyone will die.
View GitHub Profile
@aels
aels / port2service.csv
Created December 18, 2021 14:29
port2service database
We can't make this file beautiful and searchable because it's too large.
Service Name: unknown,Port No: 0,Protocol: tcp,Description: Reserved,Source: IANA
Service Name: unknown,Port No: 0,Protocol: udp,Description: Reserved,Source: IANA
Service Name: tcpmux,Port No: 1,Protocol: tcp,Description: TCP Port Service Multiplexer,Source: IANA
Service Name: tcpmux,Port No: 1,Protocol: udp,Description: TCP Port Service Multiplexer,Source: IANA
Service Name: compressnet,Port No: 2,Protocol: tcp,Description: Management Utility,Source: IANA
Service Name: compressnet,Port No: 2,Protocol: udp,Description: Management Utility,Source: IANA
Service Name: compressnet,Port No: 3,Protocol: tcp,Description: Compression Process,Source: IANA
Service Name: compressnet,Port No: 3,Protocol: udp,Description: Compression Process,Source: IANA
Service Name: unknown,Port No: 4,Protocol: tcp,Description: Unassigned,Source: IANA
Service Name: unknown,Port No: 4,Protocol: udp,Description: Unassigned,Source: IANA
@aels
aels / wsoExGently.php
Last active December 20, 2021 06:46
PHP 7.0-8.0 disable_functions bypass PoC (*nix only)
# PHP 7.0-8.0 disable_functions bypass PoC (*nix only)
#
# Bug: https://bugs.php.net/bug.php?id=54350
#
# This exploit should work on all PHP 7.0-8.0 versions
# released as of 2021-10-06
#
# Author: https://github.com/mm0r1
@aels
aels / fpm.py
Created December 21, 2021 05:14 — forked from phith0n/fpm.py
Fastcgi PHP-FPM Client && Code Execution
import socket
import random
import argparse
import sys
from io import BytesIO
# Referrer: https://github.com/wuyunfeng/Python-FastCGI-Client
PY2 = True if sys.version_info.major == 2 else False
@aels
aels / mysql-login-pass.txt
Created December 30, 2021 00:50
list of vulnerable websites
url, mysql login:password
https://constative.com#,constative2:ya6YxVIclFxzu3agLHSJ
https://myhealthgazette.com#,healthgazette:V12_aHZsJgccQLErH7BP
https://thewoksoflife.com#,thewoksoflife:wBbmROPl8VyTW0REpdgj
https://hugosway.com#,prodhugosway:LSmjbU2GWYaipUYRi6kb
https://eclincher.com#,eclinchersite:wBUmB76IP9cOLcdUXX1E
https://nicekicks.com#,matthalfhill:PaJTcyqBuH6-U0rxhIRT
https://gottabemobile.com#,gottabemobile:U2SQTokTusXXug0m
https://sidehusl.com#,sidehusl:ZlucjfZb08f4pOp2xyKH
https://nuvei.com#,nuvei:MCku7HiNeCuyhLO3euib
@aels
aels / gist:e4f15e9d3e239fd74d1fc497d287e9c2
Created December 30, 2021 02:54
curl dnslytics.com reverse-ip request
-s 'https://dnslytics.com/reverse-ip' -H 'authority: dnslytics.com' -H 'pragma: no-cache' -H 'cache-control: no-cache' -H 'sec-ch-ua: " Not A;Brand";v="99", "Chromium";v="96", "Google Chrome";v="96"' -H 'sec-ch-ua-mobile: ?0' -H 'sec-ch-ua-platform: "macOS"' -H 'upgrade-insecure-requests: 1' -H 'user-agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.93 Safari/537.36' -H 'origin: https://dnslytics.com' -H 'content-type: application/x-www-form-urlencoded' -H 'accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9' -H 'sec-fetch-site: same-origin' -H 'sec-fetch-mode: navigate' -H 'sec-fetch-user: ?1' -H 'sec-fetch-dest: document' -H 'referer: https://dnslytics.com/reverse-ip' -H 'accept-language: en,ru;q=0.9,pt;q=0.8' -H 'cookie: cf_clearance=tbIasx23acyrOjQMNu0QPZn71HlFAzFxrsKNQML2CDw-1638918329-0-150' --compressed
root:
root:password
root:mysql
root:root
root:chippc
admin:admin
root:
root:nagiosxi
root:usbw
cloudera:cloudera
/**@license
* __ _____ ________ __
* / // _ /__ __ _____ ___ __ _/__ ___/__ ___ ______ __ __ __ ___ / /
* __ / // // // // // _ // _// // / / // _ // _// // // \/ // _ \/ /
* / / // // // // // ___// / / // / / // ___// / / / / // // /\ // // / /__
* \___//____ \\___//____//_/ _\_ / /_//____//_/ /_/ /_//_//_/ /_/ \__\_\___/
* \/ /____/
* http://terminal.jcubic.pl
*
* This is example of how to create custom formatter for jQuery Terminal
@amorki.pl
@antimir.net
@aol.be
@aol.ca
@aol.com
@aol.de
@aol.net
@atlantmail.com
@atlaskit.com
@autopressinternet.com
luukku.com
mail2lauren.com
bikeracers.net
mail333.com
mail2maurice.com
mail.pt
mail2newmexico.com
mail2mom.com
mail2hip.com
the-police.com
Product/Vendor Username Password
2Wire,Inc. http <blank>
2wire (ssh) admin admin
360 Systems factory factory
3COM 3comcso RIP000
3COM adm <blank>
3COM admin 1234admin
3COM admin admin
3COM Admin Admin
3COM admin <blank>