Skip to content

Instantly share code, notes, and snippets.

View inC3ASE's full-sized avatar

Gabriel Sawyer inC3ASE

  • Aptos, California
View GitHub Profile
@inC3ASE
inC3ASE / usr-x11.txt
Created October 14, 2016 08:12
//usr/X11
total 0
0 drwxr-xr-x 128 0 0 4352 Aug 27 17:18 bin
0 drwxr-xr-x 4 0 0 136 May 5 01:17 etc
0 drwxr-xr-x 19 0 0 646 Aug 27 17:18 include
0 drwxr-xr-x 207 0 0 7038 Aug 27 17:18 lib
0 drwxr-xr-x 14 0 0 476 May 5 01:27 share
0 drwxr-xr-x 5 0 0 170 May 5 01:31 var
./bin:
total 56176
@inC3ASE
inC3ASE / dev.txt
Created October 14, 2016 08:13
//dev
ArchCelsum:dev ArchCelsum$ ls -lsnR
total 0
0 crw------- 1 0 0 17, 1 Sep 23 00:54 afsc_type5
0 crw------- 1 0 0 10, 0 Sep 23 00:54 auditpipe
0 crw-r--r-- 1 0 0 9, 3 Sep 23 00:54 auditsessions
0 crw------- 1 0 0 19, 0 Sep 23 00:54 autofs
0 crw------- 1 0 0 31, 0 Sep 23 00:54 autofs_control
0 crw-rw-rw- 1 0 0 22, 0 Sep 23 00:54 autofs_homedirmounter
0 crw-rw-rw- 1 0 0 21, 0 Sep 23 00:54 autofs_notrigger
0 crw-rw-rw- 1 0 0 20, 72 Sep 23 00:54 autofs_nowait
@inC3ASE
inC3ASE / applications.txt
Created October 14, 2016 08:16
//Applications
This file has been truncated, but you can view the full file.
ArchCelsum:Applications ArchCelsum$ ls -lsnR
total 8
0 drwxr-xr-x@ 5 0 80 170 Oct 5 13:18 Adobe Creative Cloud
0 drwxr-xr-x@ 3 501 80 102 Sep 22 02:27 Affinity Designer Trial.app
0 drwxr-xr-x 3 501 20 102 Sep 23 17:34 Airtable.app
0 drwxr-xr-x@ 3 501 80 102 Aug 18 05:09 Aldryn Desktop.app
0 drwxr-xr-x@ 3 0 0 102 Jun 24 15:36 App Store.app
0 drwxr-xr-x 4 0 80 136 Oct 12 22:26 Aruba Networks
0 drwxr-xr-x@ 3 501 20 102 Aug 30 10:59 Atom.app
0 drwxr-xr-x@ 3 0 0 102 May 4 18:47 Automator.app
@inC3ASE
inC3ASE / Library.txt
Created October 14, 2016 08:25
//Library 190728 lines
This file has been truncated, but you can view the full file.
ArchCelsum:Library ArchCelsum$ ls -lsnR
total 0
0 drwxr-xr-x 20 0 80 680 Oct 12 22:26 Application Support
0 drwxr-xr-x 8 0 0 272 Sep 13 17:37 Audio
0 drwxrwxrwt 6 0 80 204 Oct 5 13:26 Caches
0 drwxr-xr-x 2 0 0 68 Jul 30 13:48 ColorPickers
0 drwxr-xr-x 4 0 0 136 Sep 23 00:46 ColorSync
0 drwxr-xr-x 2 0 0 68 Jul 30 14:59 Components
0 drwxr-xr-x 3 0 0 102 Jul 30 18:32 Compositions
0 drwxr-xr-x 2 0 0 68 Jul 30 14:59 Contextual Menu Items
@inC3ASE
inC3ASE / SystemLibrary
Created October 14, 2016 08:28
//System/Library 532859 lines
This file has been truncated, but you can view the full file.
ArchCelsum:System ArchCelsum$ ls -lsnR
total 0
0 drwxr-xr-x 91 0 0 3094 Sep 23 00:49 Library
./Library:
total 0
0 drwxr-xr-x 3 0 0 102 Aug 4 17:54 AWD
0 drwxr-xr-x 4 0 0 136 Sep 13 17:40 Accessibility
0 drwxr-xr-x 3 0 0 102 Jul 30 14:50 AccessoryUpdaterBundles
0 drwxr-xr-x 7 0 0 238 Sep 13 17:34 Accounts
@inC3ASE
inC3ASE / osXBaseSystemDMGPoser.txt
Created October 14, 2016 08:33
Part of the "Internet Recovery" Loophole. Mounted Recursively, DMG within DMG and so on. Lucked into getting this to actually write as an active partitioned disk
This file has been truncated, but you can view the full file.
total 8
0 drwxrwxr-x+ 24 501 80 884 Oct 9 22:10 OS X Base System
8 lrwxr-xr-x 1 0 0 1 Sep 23 00:54 PooCah -> /
./OS X Base System:
total 24
0 drwxrwxr-x+ 5 501 80 170 Oct 9 22:17 Applications
0 drwxrwxr-x+ 3 501 80 102 May 17 21:14 Install OS X El Capitan.app
0 drwxrwxr-x+ 11 501 80 374 Jul 8 19:38 Library
0 drwxrwxr-x+ 4 501 80 136 Jul 8 19:37 System
@inC3ASE
inC3ASE / UsersGuest.txt
Created October 14, 2016 08:34
//Users/Guest I didn't set the user up and cant get rid of it. Files are pretty interesting, specifically what their actual content is
ArchCelsum:Guest ArchCelsum$ ls -lsnR
total 0
0 drwxr-xr-x+ 2 201 201 68 Oct 3 22:02 Desktop
0 drwxr-xr-x+ 2 201 201 68 Oct 3 22:02 Documents
0 drwxr-xr-x+ 2 201 201 68 Oct 3 22:02 Downloads
0 drwxr-xr-x@ 43 201 201 1462 Oct 10 22:25 Library
0 drwxr-xr-x+ 2 201 201 68 Oct 3 22:02 Movies
0 drwxr-xr-x+ 2 201 201 68 Oct 3 22:02 Music
0 drwxr-xr-x+ 2 201 201 68 Oct 3 22:02 Pictures
0 drwxr-xr-x+ 2 201 201 68 Oct 3 22:02 Public
@inC3ASE
inC3ASE / UsersShared.txt
Created October 14, 2016 08:35
//Users/Shared same case with this "user". Cant get rid of it, not much but maybe something
ArchCelsum:Shared ArchCelsum$ ls -lsnR
total 0
0 drwxr-xr-x 3 501 0 102 Oct 5 13:30 Adobe
0 drwxrwxrwx@ 2 501 0 68 Oct 5 19:06 SC Info
0 drwxrwxrwx@ 7 501 0 238 Oct 5 05:37 adi
./Adobe:
total 0
0 drwxr-xr-x 3 501 0 102 Oct 5 13:30 OOBE
@inC3ASE
inC3ASE / basepathdoublebackslash.txt
Created October 14, 2016 08:38
Basic from "//" Cant access anything from network, home, net, and various folders with really good stuff throughout, but... It's a start. This is the same type of system hack (gray hat, black hat) that's spreading at universities too. The file contents of each are whats the most important, but figured maybe somebody can start picking for me wher…
0 drwxrwxr-x+ 68 root admin 2312 Oct 13 17:52 Applications
0 drwxr-xr-x+ 61 root wheel 2074 Oct 3 22:02 Library
0 drwxr-xr-x@ 2 root wheel 68 Sep 23 00:48 Network
0 drwxr-xr-x@ 4 root wheel 136 Sep 23 00:15 System
0 drwxr-xr-x 6 root admin 204 Oct 3 22:02 Users
0 drwxr-xr-x@ 4 root wheel 136 Oct 13 17:55 Volumes
0 drwxr-xr-x@ 38 root wheel 1292 Sep 13 17:57 bin
0 drwxrwxr-t@ 2 root admin 68 Sep 23 00:48 cores
9 dr-xr-xr-x 3 root wheel 4280 Sep 23 00:54 dev
0 drwxrwxr-x 7 root admin 238 Aug 25 16:29 efi
@inC3ASE
inC3ASE / passwd
Created October 14, 2016 08:39
"//private/etc/passwd" contents
##
# User Database
#
# Note that this file is consulted directly only when the system is running
# in single-user mode. At other times this information is provided by
# Open Directory.
#
# See the opendirectoryd(8) man page for additional information about
# Open Directory.
##