Skip to content

Instantly share code, notes, and snippets.

View ehsahil's full-sized avatar

Sahil Ahamad ehsahil

View GitHub Profile
. - matches any single charactors
? - The preceding item is not optional and will be matched, at most ], once
* - The preceding item will be matched zero or more times.
+ - the preceding item will be matched one or more times.
{N} - The preceding item will be matched exectly N times
{N,} - the preceding item will be matched exactly N or more times.
{N.M} - the preceding item will be mached at least N, but not more then M times.
- represents the range if it't not first or last in a list or the endpoint point of a range in a list.
^ - match the empty string at the beginning of line.
$ - match the empty string at the end of a word.
# Defines Git aliases.
#
# Authors:
# Sorin Ionescu <sorin.ionescu@gmail.com>
_git_status_ignore_submodules='all'
# Git
alias g='git'
#Personal alias
#.bashrc file
alias adbf="adb forward tcp:31415 tcp:31415"
alias pt="source ./venv/bin/activate"
alias aa="work/src/github.com/aquatone"
alias convert="/opt/tools/convert.sh"
alias shot="python /Users/sahil/opt/recon/webscreenshot/webscreenshot.py"
alias mobsf="docker run -it -p 8000:8000 opensecurity/mobile-security-framework-mobsf:latest"
alias th="trufflehog"
alias goaltdns="goaltdns -w /work/src/github.com/subfinder/goaltdns/words.txt"
1. Listing AWS bucket content. (Testing for list permission)
Sahils-MacBook-Pro:~ sahil$ aws s3 ls s3://bucket
2. Writing on AWS Bucket. (Testing for write Permission)
Sahils-MacBook-Pro:~ sahil$ aws s3 cp test.txt s3://bucket (Copying test.txt into the bucket with no public file read permission)
Sahils-MacBook-Pro:~ sahil$ aws s3 mv test.txt s3://bucket (Moving test.txt into the bucket with no public file read permission)
Copy test.txt file into the aws s3 bucket with public file read permission.
@ehsahil
ehsahil / List of API endpoints & objects
Created November 4, 2019 06:18 — forked from yassineaboukir/List of API endpoints & objects
A list of 3203 common API endpoints and objects designed for fuzzing.
0
00
01
02
03
1
1.0
10
100
1000
@ehsahil
ehsahil / .bash_profile
Created January 22, 2020 06:03 — forked from natelandau/.bash_profile
Mac OSX Bash Profile
# ---------------------------------------------------------------------------
#
# Description: This file holds all my BASH configurations and aliases
#
# Sections:
# 1. Environment Configuration
# 2. Make Terminal Better (remapping defaults and adding functionality)
# 3. File and Folder Management
# 4. Searching
# 5. Process Management
@ehsahil
ehsahil / list.txt
Created May 13, 2019 15:46 — forked from shortjared/list.txt
List of AWS Service Principals
acm.amazonaws.com
alexa-appkit.amazon.com
apigateway.amazonaws.com
application-autoscaling.amazonaws.com
appstream.application-autoscaling.amazonaws.com
appsync.amazonaws.com
athena.amazonaws.com
autoscaling.amazonaws.com
batch.amazonaws.com
channels.lex.amazonaws.com
@ehsahil
ehsahil / recon-points.txt
Last active May 1, 2020 20:07
recon-points.txt
Tips from @jobertabma, co-founder of HackerOne -- https://twitter.com/jobertabma/status/998769037445230592
0x00: I visit the product and marketing pages and read up what the products do. I identify how the product it exposed to the end user. This will give me an idea what the initial attack surface looks like, what data they're protecting, how users interact with each other, and what the learning curve looks like. I sign up for any number of accounts that is required to test the features. This will give me insight into the individual features. I do some light fingerprinting of the frameworks they use.I've even talked to engineers, product managers, and executives before even looking at something.
0x01: I prioritize based on features and then weakness type. I generally set a goal for myself to go after particular information, e.g. for an email provider I might ask myself: "I want to get access to someone's emails." Because I know what their features do, I can make an educated guess which features process ema
Basics Filters:
1. City
Example City:New Delhi.
2. Country
Example: Country:INDIA
3. Port
Example:Ports: 8443, 8080, 8180 etc
@ehsahil
ehsahil / content_discovery_nullenc0de.txt
Created August 29, 2019 04:39 — forked from nullenc0de/content_discovery_nullenc0de.txt
content_discovery_nullenc0de.txt
This file has been truncated, but you can view the full file.
/
$$$lang-translate.service.js.aspx
$367-Million-Merger-Blocked.html
$defaultnav
${idfwbonavigation}.xml
$_news.php
$search2
£º
.0