Skip to content

Instantly share code, notes, and snippets.

🐢
I may be slow to respond.

Cody Zacharias haccer

🐢
I may be slow to respond.
Block or report user

Report or block haccer

Hide content and notifications from this user.

Learn more about blocking users

Contact Support about this user’s behavior.

Learn more about reporting abuse

Report abuse
View GitHub Profile
View ggroup.py
#!/usr/bin/env python3
# Google Groups v1
# python3 ggroup.py domains.txt
import requests
import re
import sys
with open(sys.argv[1]) as f:
sites = f.read().splitlines()
@haccer
haccer / chromeExtDL.sh
Created Sep 8, 2018
Download Chrome Extension Source Code
View chromeExtDL.sh
#!/bin/bash
# ./chromeExtDL.sh <extension id> <path to save location>
curl -s -L -o "/tmp/$1.zip" "https://clients2.google.com/service/update2/crx?response=redirect&os=mac&arch=x86-64&nacl_arch=x86-64&prod=chromecrx&prodchannel=stable&prodversion=44.0.2403.130&x=id%3D$1%26uc"
unzip -d $2 /tmp/$1.zip
rm /tmp/$1.zip
@haccer
haccer / encode.py
Created Sep 8, 2018
An overkill directory traversal fuzzing-wordlist generator.
View encode.py
#!/usr/bin/env python3
# An overkill directory traversal fuzzing wordlist generator.
# Creates approx. 931 items.
import base64
import sys
import urllib.parse
string = sys.argv[1]
# Encodings taken dotdotpwn
@haccer
haccer / install_go.sh
Created Aug 29, 2018
Bash script to install the latest version of Go (For linux)
View install_go.sh
#!/bin/bash
# Bash script to install the latest version of Go (For linux)
# Get current version of Go for 64-bit Linux
CUR=$(curl -s https://golang.org/dl/ | grep linux-amd64 | grep 'download downloadBox' | cut -d'"' -f4)
# Download Go
wget $CUR
# Get filename
View URI Schemes
aaa
aaas
about
acap
acct
acr
adiumxtra
afp
afs
aim
@haccer
haccer / keybase.py
Created Jul 13, 2018
Extract emails from PGP keys
View keybase.py
#!/usr/bin/env python
import requests, base64, re, sys
r = requests.get("https://keybase.io/" + sys.argv[1] + "/key.asc")
body = r.text.split("\n\n")
key = body[1].split("-----")
for email in re.findall(r' <(.*?)>', str(base64.b64decode(key[0]))):
print(email)
View keybase.md

Keybase proof

I hereby claim:

  • I am haccer on github.
  • I am htp (https://keybase.io/htp) on keybase.
  • I have a public key whose fingerprint is BA63 0D64 4F88 A8C5 93EE F1F8 1D38 581F FA90 9452

To claim this, I am signing this object:

@haccer
haccer / alexa.sh
Created Apr 18, 2018
Gather domains in the Alexa top 1 million
View alexa.sh
#!/bin/bash
# This script will fetch the Alexa top 1 million domains and prepare them how I like it.
# Check if unzip is installed
[ -f /usr/bin/unzip ] || sudo apt-get install unzip
# Get Alexa Top 1 mil
wget -q --show-progress http://s3.amazonaws.com/alexa-static/top-1m.csv.zip
# Unzip
@haccer
haccer / all.txt
Last active Jun 29, 2018 — forked from jhaddix/all.txt
all wordlists for every dns enumeration tool... ever.
View all.txt
This file has been truncated, but you can view the full file.
0
00
0-0
000
0000
00000
000000
000005
00001
@haccer
haccer / scanio.sh
Last active Sep 14, 2019
PoC script to mass-locate vulnerable subdomains using results from Rapid7's Project Sonar
View scanio.sh
#!/bin/bash
# Usage : ./scanio.sh <save file>
# Example: ./scanio.sh cname_list.txt
# Premium
function ech() {
spinner=( "|" "/" "-" "\\" )
while true; do
for i in ${spinner[@]}; do
echo -ne "\r[$i] $1"
You can’t perform that action at this time.