(by @_ashish_tiwari)
Version : 6.2
Heap size : 30 GB
core : 24
Memory : 128 GB
Client : PHP - 6.0
var rand1 = Math.floor(Math.random()*410);quotes = new Array | |
quotes[0]='若隐若现才是艺术! ——「问题儿童来自异世界」' | |
quotes[1]='下一次重逢,将是何年何月?天空必将见证。 ——「SOLA」' | |
quotes[2]='如果你都不知道自己想去哪里,那去哪里都是一样的。 ——「柴郡猫」' | |
quotes[3]='一定没有问题的! ——「魔卡少女樱」' | |
quotes[4]='这是眼泪吗?原来眼泪是这么的温暖,我一直以为,哀伤的东西都是冰冷的。 ——「风色幻想」' | |
quotes[5]='桑丘,让他们管我叫疯子吧,我还疯得不够,所以得不到他们的赞许。 ——「堂吉诃德」' | |
quotes[6]='美好的人眼裡映出的世界也是美好的。 ——「ARIA」' | |
quotes[7]='如果不能忠于自己的心,胜负又有什么价值呢? ——「塔希里亚故事集」' | |
quotes[8]='天空本是一种风景,可是遇见你之后,它变成了一种心情。 ——「九ちのセカィ」' |
<?php | |
/** | |
* http://ucren.com/blog/archives/549 | |
* 利用零宽字符“隐藏”信息 | |
* 每个字符都有一个唯一的编码,将编码以 2 进制表示得到 01.. 的字串,把 1 替换成 U+200C,把 0 替换成 U+200D 就得到一个全零宽空白的字符串 | |
* 在 unicode 里,至少有 U+200B, U+200C, U+200D 和 U+FEFF 四个零宽字符 | |
*/ | |
(by @_ashish_tiwari)
Version : 6.2
Heap size : 30 GB
core : 24
Memory : 128 GB
Client : PHP - 6.0
#!/bin/bash | |
# https://null-byte.com/turn-forums-into-c-c-servers-0196708/ | |
while true; do | |
forumUser="tokyoneon"; | |
username="tokyoneon@email.com"; | |
password="treHGFd76547^%$"; | |
cookies='/tmp/forum_cookies'; | |
function urlencode () |
#!/bin/sh | |
GIST_USER=sbp | |
function usage() { | |
echo Usage: $0 [command], where command is one of: | |
echo update - Gets any new gists for user | |
echo pull - Keep existing gists synced with server | |
echo sync - Do an update then a pull | |
} |
#ifndef WIN32_LEAN_AND_MEAN | |
# define WIN32_LEAN_AND_MEAN | |
#endif | |
#pragma warning (push) | |
/* 4820: '<struct-name>' : 'n' bytes padding added after data member '<member-name>'*/ | |
# pragma warning (disable : 4820) | |
# include <windows.h> | |
# include <stdio.h> |
from json import loads as jsload | |
from os import system | |
from random import random | |
from time import time | |
from requests import get as request | |
def resolve(sMid): | |
filename = 'C400' + sMid + '.m4a' |
""" | |
got_tmilk.py - Go Type Milking | |
Written by Ivan Kwiatkowski @ Kaspersky GReAT | |
Shared under the terms of the GPLv3 license | |
""" | |
C_HEADER = """ | |
enum golang_kind : __int8 | |
{ | |
INVALID = 0x0, |
This is a quick trick to build a ropchain :)
First, you need to find certain gadgets for needed operations:
a. pop
gadget for each of the registers ebx
, ecx
, edx
(for setting them up as arguments for syscall)
b. xor
and inc
gadgets for eax
(for setting up the syscall number)
When creating your rules for YARA keep in mind the following guidelines in order to get the best performance from them. This guide is based on ideas and recommendations by Victor M. Alvarez and WXS.
Global rules are evaluated first. Only if they are satisfied non-global rules are evaluated. This may be useful if all samples exhibit the same characteristics. Use them combined with the "private" statement to suppress a match notification on the global rules.