Skip to content

Instantly share code, notes, and snippets.

View 0xbug's full-sized avatar
🎯
Focusing

0xbug 0xbug

🎯
Focusing
View GitHub Profile
@0xbug
0xbug / domain_monitor.sh
Created September 9, 2022 06:16
domain_monitor.sh
apt-get update
apt-get install -y wget unzip
wget https://gist.githubusercontent.com/0xbug/b4c8128d2026f27a1e500b2ecc8bf099/raw/148592b73067260dfb5da1409a29c02b59567130/dnswordlist.txt -O dnswordlist.txt
wget https://github.com/0xbug/biu-cli/releases/download/v0.7/biu-cli_linux_amd64 -O /bin/biu-cli
wget https://github.com/projectdiscovery/subfinder/releases/download/v2.5.3/subfinder_2.5.3_linux_amd64.zip -O subfinder.zip
wget https://github.com/projectdiscovery/dnsx/releases/download/v1.1.0/dnsx_1.1.0_linux_amd64.zip -O dnsx.zip
chmod +x /bin/biu-cli
rm -rf subfinder
rm -rf dnsx
unzip -o subfinder.zip
@0xbug
0xbug / dnswordlist.txt
Created September 9, 2022 04:09
dnswordlist.txt
This file has been truncated, but you can view the full file.
perdue
134319qixn
58a6458
kymap
cgss
frimin
vodkgeyttp8
kmxcx
hdif-tz
gog-review
This file has been truncated, but you can view the full file.
www
mail
ftp
smtp
pop
m
webmail
pop3
imap
localhost
This file has been truncated, but you can view the full file.
www
mail
webmail
cpanel
webdisk
autodiscover
sni
cpcontacts
cpcalendars
com
@0xbug
0xbug / cloud_metadata.txt
Created May 29, 2019 07:34 — forked from jhaddix/cloud_metadata.txt
Cloud Metadata Dictionary useful for SSRF Testing
## AWS
# from http://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-instance-metadata.html#instancedata-data-categories
http://169.254.169.254/latest/user-data
http://169.254.169.254/latest/user-data/iam/security-credentials/[ROLE NAME]
http://169.254.169.254/latest/meta-data/iam/security-credentials/[ROLE NAME]
http://169.254.169.254/latest/meta-data/ami-id
http://169.254.169.254/latest/meta-data/reservation-id
http://169.254.169.254/latest/meta-data/hostname
http://169.254.169.254/latest/meta-data/public-keys/0/openssh-key
@0xbug
0xbug / gist:5bf08ff4e11dda6e2db359ac01a994bf
Created May 20, 2019 10:27
Hawkeye 部署(使用 docker 里面的 MongoDB)
docker network create hawkeye
docker run --network=hawkeye -v /var/lib/docker_mongo:/data/db --name=mongo --restart=always -d mongo
docker run -ti -p 80:80 --network=hawkeye -e MONGODB_URI=mongodb://mongo:27017 --restart=always -d daocloud.io/0xbug/hawkeye

宿主机

docker run -ti --name=awvs -v /tmp/awvs:/tmp/awvs ubuntu

acunetix_trial.shpatch_awvs 放到宿主机 /tmp/awvs 目录下

进入容器内

apt-get install sudo libxdamage1 libgtk-3-0 libasound2 libnss3 libxss1 libx11-xcb-dev -y
@0xbug
0xbug / fofa_rule.sql
Created August 11, 2017 03:05 — forked from Tr3jer/fofa_rule.sql
fofa_rule.sql
/*
Navicat Premium Data Transfer
Source Server : localhost
Source Server Type : MySQL
Source Server Version : 50542
Source Host : localhost
Source Database : rule
Target Server Type : MySQL
@0xbug
0xbug / sensitive_data_filter.conf
Last active June 27, 2017 09:18
elk日志脱敏-logstash 2.x
input {
stdin{}
}
filter {
ruby {
code => "
event['message']=event['message'].gsub(/[pP][aAWw][sSdD]\w{0,5}?[%'\"]{0,1}?[5]{0,1}?[D]{0,1}?[=:]['\"]{0,1}?.*?[\t&\"]/,'password=*&')
"
}
}
@0xbug
0xbug / sensitive_data_filter.conf
Last active December 24, 2021 06:54
elk日志脱敏-logstash 5.x
input {
stdin{}
}
filter {
ruby {
code => "
event.set('[messagea]',event.get('[message]').gsub(/[pP][aAWw][sSdD]\w{0,5}?[%'\"]{0,1}?[5]{0,1}?[D]{0,1}?[=:]['\"]{0,1}?.*?[\t&\"]/,'password=*&'))
"
}
}