Skip to content

Instantly share code, notes, and snippets.

View mqu's full-sized avatar
🏠
Working from home

Marc Quinton mqu

🏠
Working from home
  • DGAC / DSNA / DTI
  • Toulouse / France
View GitHub Profile
@mqu
mqu / gist:be4e4fcd858d1bd7c6b15f87d6d6921a
Created September 12, 2026 08:46
gitlab/CVE-2026-85706/IOCS
root@gitlab:/var/log/gitlab/gitlab-rails# cat api_json.log | grep "repository/commits" | grep -E '"status":4[0-9]{2}|"status":5[0-9]{2}' | jq 'select(.path | test("repository/commits")) | select(.method=="POST")' | jq .remote_ip | sort | uniq -c | sort -rn
30 "138.199.15.172, 138.199.15.172"
30 "138.199.15.172"
6 "159.26.96.85, 159.26.96.85"
3 "194.163.163.146"
2 "68.178.160.183"
1 "5.196.56.134, 5.196.56.134"
1 "5.135.209.134, 5.135.209.134"
@mqu
mqu / gist:b5829f90f3315d04d9d3f2f91c073f00
Last active July 3, 2025 09:44
Wekan / mongosh / filter users with last connexion < 6 months
# - query mongodb database with services.resume.loginTokens having date greater than 6 months
# - display in json format username, email, loginToken as lastLogin
# - sort by date in reverse-order
# - inject query in mongodb container with docker-compose
# tags: mongo, wekan, users, mongosh, mongodb, jq, users dump.
# FAQ : https://chatgpt.com/share/686650cf-2c00-8011-ad3a-745dd635ba44
docker-compose exec -T mongo mongosh wekan --quiet --eval '
console.log(JSON.stringify(
db.users.find({
@mqu
mqu / pid2c.bash
Last active June 27, 2024 12:50 — forked from jsidhu/gist:2ff16fe4ee734fdf358471ded60c99f4
Prints the name of the container inside which the process with a PID on the host is
#!/bin/bash -e
# given a process ID (PID), give me container name
# url: https://gist.github.com/mqu/8e204f61712be418ad8458da282d33f9
# forked from : https://gist.github.com/jsidhu/2ff16fe4ee734fdf358471ded60c99f4
# https://stackoverflow.com/questions/24406743/coreos-get-docker-container-name-by-pid
# Prints the name of the container inside which the process with a PID on the host is.
function getName {
local pid="$1"
@mqu
mqu / gist:074e2ee64aa73ea66ab221c7abc86f92
Created May 17, 2024 06:39
ebury detection commands
# doc: https://web-assets.esetstatic.com/wls/en/papers/white-papers/ebury-is-alive-but-unseen.pdf
# repo git: https://github.com/eset/malware-research/tree/master/ebury
url=https://raw.githubusercontent.com/eset/malware-research/master/ebury/detect_ebury.sh
curl -s $url > /tmp/detect_ebury.sh
chmod +x /tmp/detect_ebury.sh
# disable ebury (environnement variable) or login with console (not SSH)
# Ebury, can mask it presence with login with SSH.
export LD_PRELOAD=
fff
@mqu
mqu / README.md
Created August 18, 2023 09:09
passhport-admin / {user,target} create
@mqu
mqu / docker_svn-server.md
Created July 20, 2023 14:10 — forked from dpmex4527/docker_svn-server.md
Set up SVN server on docker
@mqu
mqu / echo.rb
Created August 10, 2022 14:39 — forked from dtchepak/echo.rb
Simple Ruby HTTP server to echo whatever GET or POST requests come through. Largely based on https://www.igvita.com/2007/02/13/building-dynamic-webrick-servers-in-ruby/.
# Reference: https://www.igvita.com/2007/02/13/building-dynamic-webrick-servers-in-ruby/
require 'webrick'
class Echo < WEBrick::HTTPServlet::AbstractServlet
def do_GET(request, response)
puts request
response.status = 200
end
def do_POST(request, response)
puts request
@mqu
mqu / README.md
Created May 16, 2022 14:19
excalidraw / multi-user mode

This is Excalidraw + Excalidraw-room (web-socket server) behind an apache reverse-proxy using docker-compose.

usage :

  • clone this projet
  • clone Excalidraw source code in build/src :
mkdir -p build/src ; git clone https://github.com/excalidraw/excalidraw.git build/src/excalidraw
  • build docker-compose stack
@mqu
mqu / README.md
Last active March 2, 2022 16:29
déchiffrement des fichiers envoyés par ENEDIS/pro chiffrés en AES/CBC-256

tags: ENEDIS, ENEDIS-pro, AES/CBC-265, java