Skip to content

Instantly share code, notes, and snippets.

@lepz0r
Last active July 20, 2023 05:05
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save lepz0r/24837482e1dcc73995edea074f0aeed9 to your computer and use it in GitHub Desktop.
Save lepz0r/24837482e1dcc73995edea074f0aeed9 to your computer and use it in GitHub Desktop.
My personal geneva (genetic evasion, https://github.com/kkevsterrr/geneva) strategies
March 16 2023
ID
[TCP:options-sack:]-fragment{tcp:-1:False}(,fragment{tcp:-1:True:5})-|
[TCP:options-timestamp:]-fragment{tcp:5:True:2}-|
[TCP:options-sackok::4]-fragment{tcp:57:True}(,fragment{tcp:-1:True:5})-| [TCP:chksum:55606]-fragment{tcp:-1:False:16}-|
[TCP:reserved:0]-fragment{tcp:42:True}(,tamper{TCP:chksum:corrupt})-|
[TCP:options-timestamp:]-fragment{tcp:54:True:40}(tamper{TCP:options-nop:replace:},)-|
[TCP:options-nop::4]-fragment{tcp:54:True:40}(tamper{TCP:options-nop:corrupt},duplicate)-|
[TCP:options-nop::4]-fragment{tcp:54:True:40}-|
[TCP:options-timestamp:]-fragment{tcp:30:True}(,fragment{tcp:-1:True})-|
[TCP:reserved:0]-fragment{tcp:42:True}(,fragment{tcp:4:True}(,tamper{TCP:options-uto:replace:151}))-| [TCP:reserved:0]-duplicate-|
[TCP:options-nop:]-fragment{tcp:58:True}(duplicate,)-| [TCP:options-altchksumopt:]-fragment{tcp:-1:False}-| [TCP:load:%D2%BD%3D3x%13x%23%5DK%1A%20d%27%08%179D%2C_%7B%D0%AE_%10%D2%81~%06_%19G%7Dx%0D/K%19%13D%12%5Cz%12%7B%0Fu1%0A%3B%0Eb%01eDYV%C3%AB%17XN%3EMtH%0F%03%03Gqo%18b%3E%E2%8F%B1t%3D4ZwW%00Cmd%3D%21B6%14%27%7F%121%D6%A7W%DA%8E2%3D%10JBBsyP%60%12%290%059nQGOretql.%0D%7F%40%19%D4%A4lF-%16t%0A%26ts%DF%97Onr%D3%9D%7B%15P%10%0D%17%1F/%25Ri%1C%05%10%09DD%0DL%3F%7B%14%1F%29g5%185%0E%D0%85%0FOx%08%7B%0D%0750i%1DG.Y%10%25%1B%1B8d%5B%3En6%29%3B%5EX%3CU_%5DSlYV%C2%A4P%5C%14%0F5.6%29b%0F%C8%B8r7%0BfDkL%3BXgeD%0A%24%7F%14m%15k%3B%00%5BG%13y0%25E7%CA%9B9%03%5EBDon5AWek%00L%DE%97%14%253L%09fb%DA%81%09%605u%1FF%2Aa%C3%A8D%06iZf%03V%3Cj9%2CYV%0D%7C%10%1D%1F2T%0A4/A%3D%5EW%3CtJ3%13/%14MH%3Cw%20%04%03%09%04%00wG%24.a4%3Fio%13%DB%AF%7D%07%0C%16%16%2B%3Bf3%16%27E~X%26K%2CD%06U%1E%04%3A%DD%81%1EQQz7b%7F%00qT%0C%0C_%3Cy%23%C8%B8/%1448x%3FMcw%28%2B%C3%8D%14T%D4%99%D3%92%1ATD%1EC/%0F1%00%C4%B1%29w%2C77cTW%7C%3C%3AJNB%14K0%08%1A%1E%07~3v%19J%C7%B3%60a%19/4%0C%01%DC%93%CC%A6%7B4zJMgU%16%0FF_%5CW9%5EC%00%3Dc%D1%94%24cI.n%5B7%2C-%28d-yW%14%5E%40%7C%DA%82b%CD%AE%D0%A6y9Uvl%26%1FO%16%28%16%16.%0D%7F%2CP2K9s8e%24%3E%D6%86%CC%BEv%0D5j2%03%0B7%5E%01nt%09%14Ec%26%05%18%3E%2ClYy%0D%2Ao%5E4B%1Df%3E%1Bb8%DD%8Ey1%26%0B%25B%05wORR1%17%16KV%0FD%18%0C6kE6%1A9Fi%5E%5C%0BS%05~CF%26uSV0l%04qN%07G%09d%0A%0EO%16%3A%00%15%7B%3A%14%05%27%1A%11eG%3Bg%10%01%5EQv%22%0B%2A%0D%5C%08V%07%21e%24%0A%1C%23%E2%BF%9D%01TVM%1EXF%5B%11F%D3%BC%CE%8EF%1E%5D%28P%0C1.1kH%0Bx3PIp-CP%2A3S9Vo%3As-%0C%11U7melb%C9%93%5E%0C%04%0Ec%20%5B%03%0Eb%15f%3FaQgJ%1BWB%2A%C4%8CiX%3FYZx%02Hirq%08%060Gp%2B%3D%13%3CZ%11%238%2B%1E%25qvhdDyv%7DH%D8%A8%3BRG%14b%3Bf%1D]-tamper{TCP:dport:corrupt}-|
April 3 2023
ID
[TCP:options-nop::4]-| \/ [TCP:options-md5header:]-tamper{TCP:window:corrupt}-|
[TCP:options-nop::4]-fragment{tcp:34:True:40}(tamper{TCP:options-uto:replace:77},)-| \/ [TCP:dataofs:5]-tamper{TCP:urgptr:corrupt}-|
[TCP:options-eol:]-tamper{TCP:window:replace:100}-|
[TCP:options-nop::4]-fragment{tcp:16:True:5}-| \/ [TCP:options-altchksumopt:]-tamper{TCP:options-sackok:replace:}-|
[TCP:options-altchksumopt:]-tamper{TCP:window:replace:70}-|
[TCP:options-sack:]-tamper{TCP:window:corrupt}-|
April 6 2023
KR
[TCP:dport:443]-fragment{tcp:41:False}-| \/ [TCP:flags:R]-drop-| \/ [TCP:flags:RA]-drop-|
[TCP:dport:443]-fragment{tcp:50:False}-| \/ [TCP:flags:R]-drop-| \/ [TCP:flags:RA]-drop-|
April 14 2023
RU
[TCP:window:502]-fragment{tcp:-1:False}-|
[TCP:window:502]-fragment{tcp:10:False:5}-|
[TCP:reserved:0]-fragment{tcp:21:False}(fragment{tcp:-1:False:13},)-|
May 10 2023
RU
[TCP:flags:PA]-fragment{tcp:1:True}(duplicate,duplicate)-|
[TCP:flags:PA]-fragment{tcp:3:False:1}-|
[TCP:flags:PA]-fragment{tcp:54:True:40}(fragment{tcp:1:True}(,duplicate),fragment{tcp:-1:True:5})-|
May 11 2023
IR
[IP:ihl:5:1]-tamper{TCP:options-timestamp:corrupt}(duplicate,)-|
[IP:ihl:5:1]-tamper{TCP:seq:corrupt}-|
July 20 2023
ID
[TCP:dport:443:4]-fragment{tcp:13:True:6}(,drop)-|
[TCP:dport:443:4]-fragment{tcp:2:True:14}(,drop)-|
[TCP:dport:443:4]-fragment{tcp:32:True:16}(,drop)-| \/ [TCP:options-md5header:]-drop-|
ID2
[TCP:dport:443]-fragment{tcp:-1:True:5}(fragment{tcp:11:True:5}(duplicate,),)-| [TCP:seq:1519154742]-tamper{TCP:options-uto:corrupt}-| [TCP:options-altchksumopt::3]-fragment{tcp:-1:True}(fragment{tcp:-1:True},)-| \/ [TCP:dport:443]-tamper{TCP:dataofs:replace:7}(tamper{TCP:options-eol:replace:},)-|
[TCP:dport:443:4]-fragment{tcp:-1:True:5}(fragment{tcp:6:True:37}(tamper{TCP:options-timestamp:replace:2848865731},),drop)-|
[TCP:dport:443:4]-fragment{tcp:-1:True:5}(fragment{tcp:-1:True:5},drop)-|
[TCP:dport:443:4]-fragment{tcp:-1:True:5}(fragment{tcp:6:True:37},drop)-|
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment