Skip to content

Instantly share code, notes, and snippets.

View inC3ASE's full-sized avatar

Gabriel Sawyer inC3ASE

  • Aptos, California
View GitHub Profile
@inC3ASE
inC3ASE / gist:0ffb5764734c31f8881a6548d32834e0
Created October 14, 2016 08:53
//private/etc/rpc + ../rpc~orig
ArchCelsum:etc ArchCelsum$ cat rpc
#
# $FreeBSD$
# rpc 88/08/01 4.0 RPCSRC; from 1.12 99/07/25 SMI
#
rpcbind 100000 portmap sunrpc rpcbind
rstatd 100001 rstat rstat_svc rup perfmeter
rusersd 100002 rusers
nfs 100003 nfsprog
ypserv 100004 ypprog
@inC3ASE
inC3ASE / pf.os
Created October 14, 2016 08:54
//private/etc/pf.os "Passive OS Fingerprinting"
ArchCelsum:~ ArchCelsum$ cat //private/etc/pf.os
#
# $OpenBSD: pf.os,v 1.21 2006/07/28 21:51:12 david Exp $
# passive OS fingerprinting
# -------------------------
#
# SYN signatures. Those signatures work for SYN packets only (duh!).
#
# (C) Copyright 2000-2003 by Michal Zalewski <[email protected]>
# (C) Copyright 2003 by Mike Frantzen <[email protected]>
@inC3ASE
inC3ASE / securityA
Created October 14, 2016 08:56
//private/etc/security/* file contents including audit_class audit_control audit_event audit_user audit_warn
ArchCelsum:etc ArchCelsum$ cat security/*
#
# $P4: //depot/projects/trustedbsd/openbsm/etc/audit_class#6 $
#
0x00000000:no:invalid class
0x00000001:fr:file read
0x00000002:fw:file write
0x00000004:fa:file attribute access
0x00000008:fm:file attribute modify
0x00000010:fc:file create
@inC3ASE
inC3ASE / rcCommonNetboot
Created October 14, 2016 08:59
private-etc rc.common + rc.netboot
ArchCelsum:etc ArchCelsum$ cat rc.common
##
# Common setup for startup scripts.
##
# Copyright 1998-2002 Apple Computer, Inc.
##
#######################
# Configure the shell #
#######################
@inC3ASE
inC3ASE / gettytab
Created October 14, 2016 09:01
private/etc/gettytab + gettytab~orig
ArchCelsum:~ ArchCelsum$ cat //private/etc/gettytab
# from: @(#)gettytab 5.14 (Berkeley) 3/27/91
#
# Most of the table entries here are just copies of the old getty table,
# it is by no means certain, or even likely, that any of them are optimal
# for any purpose whatever. Nor is it likely that more than a couple are
# even correct.
#
# The default gettytab entry, used to set defaults for all other
# entries, and in cases where getty is called with no table name.
@inC3ASE
inC3ASE / sudoAll
Created October 14, 2016 09:04
private/etc sudo* files : sudo_lecture sudoers sudoers.d sudoers~orig
ArchCelsum:etc ArchCelsum$ sudo cat sudo*
Password:
Sorry, try again.
Password:
WARNING: Improper use of the sudo command could lead to data loss
or the deletion of important system files. Please double-check your
typing when using sudo. Type "man sudo" for more information.
To proceed, enter your password, or type Ctrl-C to abort.
@inC3ASE
inC3ASE / pf.conf
Created October 14, 2016 09:05
//private/etc/pf.conf * Abnormally important only because this is one of the ways things are bypassed
#
# Default PF configuration file.
#
# This file contains the main ruleset, which gets automatically loaded
# at startup. PF will not be automatically enabled, however. Instead,
# each component which utilizes PF is responsible for enabling and disabling
# PF via -E and -X as documented in pfctl(8). That will ensure that PF
# is disabled only when the last enable reference is released.
#
# Care must be taken to ensure that the main ruleset does not get flushed,
@inC3ASE
inC3ASE / periodic.conf
Created October 14, 2016 09:05
//private/etc/defaults/periodic.conf
#!/bin/sh
#
# This is defaults/periodic.conf - a file full of useful variables that
# you can set to change the default behaviour of periodic jobs on your
# system. You should not edit this file! Put any overrides into one of the
# $periodic_conf_files instead and you will be able to update these defaults
# later without spamming your local configuration information.
#
# The $periodic_conf_files files should only contain values which override
# values set in this file. This eases the upgrade path when defaults
@inC3ASE
inC3ASE / afpovertcp.cfg
Created October 14, 2016 09:07
QUANTUM .. One of the rarementions of quantum anything ina computer file. This is also a good example of how far some of these files dateback and clearly not ones that would come with a standard operating system
ArchCelsum:etc ArchCelsum$ cat afpovertcp.cfg
#
# /etc/afpovertcp.cfg is used to set the system-wide AFP defaults
# for the LibcAT AppleTalk library.
#
# Copyright 1998 Apple Computer, Inc.
#
# If this file exists, TCP/IP will be used as the default transport
# protocol for AFP. Otherwise ATP will be used.
#
@inC3ASE
inC3ASE / com.apple.screensharing.agent.launchd
Created October 14, 2016 09:09
//private/etccom.apple.screensharing.agent.launchd may be useful but Id have no idea what to do with it
416c6c20776f726b20616e64206e6f20706c6179206d616b65204a61636b20612064756c6c20626f79