Skip to content

Instantly share code, notes, and snippets.

View penafieljlm's full-sized avatar

John Lawrence M. Peñafiel penafieljlm

View GitHub Profile
#
# creditcard.py
#
# Author:
# John Lawrence M. Penafiel (penafieljlm)
#
# Python source code attachment for the article at:
# https://penafieljlm.wordpress.com/2016/10/29/ekoparty-ctf-2016-write-ups/#web-150
#
/********************************************************************
 *   This C program was generated by spl2c, the Shakespeare to C    *
 *          converter by Jon Åslund and Karl Hasselström.           *
 ********************************************************************/

/* libspl definitions and function prototypes */
#include "spl.h"

int main(void)
@penafieljlm
penafieljlm / cissp_notes.md
Last active September 29, 2024 22:46
Personal CISSP Study Notes

CISSP Notes

CIA Triad

  • Confidentiality
    • Resources should be protected from unauthorized access
    • Prioritized by governments
    • Concepts
      • Sensitivity
        • How harmful is disclosure
  • Discretion
struct Template {
int64_t data_64;
int32_t data_32;
int16_t data_16;
char data_char;
} value {
// the x'es get instructions written onto them
// notice that those instructions are nops
//xxxxxx
  • Each user gets symmetric key, private key, and public key
  • Symmetric key = encrypts the data that only the user needs to see
  • Private key = decrypts the data shared to the user
  • Public key = encrypts the data shared to the user
  • Symmetric key is encrypted by user PBKDF2 of user's password
  • Private key is encrypted by user's symmetric key
  • Generate recovery codes for user and encrypt copies of symmetric key using these recovery codes
  • Encrypt user symmetric key using organization's public key for key backup mechanism
  • Stroe organization's private key in a password manager or something
<!DOCTYPE html>
<html>
<head>
<title></title>
<style type="text/css">
html {
height: 100%;
}
body {
height: 100%;
import re
import tld
# regex by @diegoperini
# taken from https://mathiasbynens.be/demo/url-regex
# modified by @penafieljlm
RE_DOMAIN = re.compile(
r'(?:'
r'\S+'
r'(?'
for %a in ("*.*") do "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" "%a" --sout=#transcode{acodec=mp3,vcodec=dummy}:standard{access=file,mux=raw,dst="%a.mp3"} --intf=dummy --verbose=2 --play-and-exit