Skip to content

Instantly share code, notes, and snippets.

View berkgoksel's full-sized avatar
🎯
Open to new ideas.

Berk Cem Göksel berkgoksel

🎯
Open to new ideas.
View GitHub Profile
@berkgoksel
berkgoksel / gist:4ba0bd48b0daf01b4481f7ef32afab96
Created September 12, 2026 11:56
Lenovo X1 - 5G WWAN fix on Ubuntu 26.04.
# Foxconn T99W696 (SDX61) 5G WWAN on Linux: FCC unlock, firmware crash workaround, suspend hook
## 0. FCC unlock
Lenovo ships the modem FCC locked. It enumerates and ModemManager sees it, but it never
registers until an unlock command is sent. The unlock script for this PCI ID lives in the
libdir, not in the shared available.d directory, and is not enabled by default.
```sh
ls -l /usr/lib/x86_64-linux-gnu/ModemManager/fcc-unlock.d/17cb:0308
@berkgoksel
berkgoksel / berk-linux-kernel-usb-cves.md
Last active September 12, 2026 12:07
Linux kernel USB Device Driver CVES - Berk Cem Goksel
from pip._internal import main
import sys
inst = {'y','yes'}
try:
import numpy as np
print("Everything seems OK. No need for setup.")
except ImportError:
@berkgoksel
berkgoksel / Ericsson LG IPECS NMS Cleartext Credential Dump
Created January 25, 2019 13:38
Dump postgresql database credentials, NMS login credentials and domain user credentials
# -*- coding: utf-8 -*-
# Exploit Title: Ericsson-LG iPECS NMS - Cleartext Cred. Dump
# Vendor Notification: 03-03-2018 - No response
# Initial CVE: 04-04-2018
# Disclosure: 21-04-2018
# Exploit Author: Berk Cem Göksel
# Contact: twitter.com/berkcgoksel || bgoksel.com
# Vendor Homepage: http://www.ipecs.com/
#!/usr/bin/env python
# coding: utf-8
############ Description: ##########
# The vulnerability was discovered during a vulnerability research lecture.
# This is meant to be a PoC.
####################################
# Exploit Title: Core FTP LE v2.2 Build 1921 (Client) - Buffer Overflow PoC
# Date: 12 Jun 2018
@berkgoksel
berkgoksel / Core FTP LE - Remote Buffer Overflow - (CVE-2018-12113).md
Last active June 22, 2018 06:44
Core FTP LE version 2.2 Build 1921 is prone to a buffer overflow vulnerability that may result in a DoS or remote code execution

Suggested description

Core FTP LE version 2.2 Build 1921 is prone to a buffer overflow vulnerability that may result in a DoS or remote code execution via a PASV response.


Vulnerability Type

Buffer Overflow

@berkgoksel
berkgoksel / PaleMoon_PoC.html
Created June 13, 2018 15:12
Pale Moon Browser < 27.9.3 - Use After Free - Proof of Concept.html
<!-- PaleMoon Browser - Proof of Concept -->
<!-- Exploit Title: Pale Moon Browser < 27.9.3 - Use After Free - Proof of Concept -->
<!-- Date: 13 Jun 2018 -->
<!-- Author - Berk Cem Goksel -->
<!-- Contact: twitter.com/berkcgoksel || bgoksel.com -->
<!-- Vendor Homepage: https://www.palemoon.org/ -->
<!-- Software Link: https://www.palemoon.org/palemoon-win32.shtml -->
<!-- Version: Versions prior to 27.9.3 (Tested versions: 27.9.0, 27.9.1, 27.9.2) -->
<!-- Tested on: Windows 10 -->
@berkgoksel
berkgoksel / Pale Moon Browser Use-after-free (CVE 2018-12292).md
Last active June 13, 2018 15:13
Use after free vulnerability on Pale Moon Browser. Multiple versions affected.

Suggested description

A use-after-free vulnerability exists in DOMProxyHandler::EnsureExpandoObject on Pale Moon Browser versions before 27.9.3.


Additional Information

The vulnerability has been confirmed and patched by the vendor.

from sys import argv
import sys
import os
import time
import requests
import re
if len(argv) != 3:
Test
123