Skip to content

Instantly share code, notes, and snippets.

View seadog007's full-sized avatar
:octocat:

尤理衡 (Li-Heng Yu) seadog007

:octocat:
View GitHub Profile
@seadog007
seadog007 / hash.txt
Created August 24, 2024 15:59
HITCON 2024 Badge Hash
0,0,1,112,168,0,0,0,5=28
0,0,110,107,210,1,0,0,4=28
0,0,162,95,77,2,0,0,17=28
0,1,19,7,202,1,0,0,25=28
0,10,105,112,197,1,0,0,5=28
0,10,2,71,71,2,0,0,7=28
0,10,60,6,156,0,0,0,27=28
0,10,78,137,182,0,0,0,5=28
0,100,11,111,9,0,0,0,27=28
0,100,204,223,228,0,0,0,15=28
@seadog007
seadog007 / brute.cpp
Last active August 25, 2024 16:18
HITCON 2024 Badge Hash Bruteforcer
#include <stddef.h>
#include <stdint.h>
#include <stdio.h>
#include <string.h>
#include <atomic>
#include <iostream>
#include <thread>
#include <vector>
@seadog007
seadog007 / phpipam.sh
Created January 4, 2021 05:44
Shell Defined Network - Syncing the IP lease setting from phpIPAM to RouterOS
#!/bin/bash
#
# Author: seadog007
# Date: 2021/01/03
# Description: Adding DHCP Lease & Static ARP & IP Whitelist from phpIPAM
# which makes phpIPAM actually managed IPs
#
ipam='192.168.1.5'
#!/bin/bash
# Kong Public Exposed & Unauthorized API Exploit
# Using the API to RCE (even the kong is highly possible in container)
#
# Author: Li-Heng Yu (Jasper Yu) <[email protected]>
# Thu April 30, 2020
# MIT License
[ $# -ne 3 ] && echo 'Usage: '$0' <Kong API> <Kong Proxy Entry> <Command>' && echo 'Example: ./kong_exploit.sh "192.168.1.2:8001" "192.168.1.2:8000" "whoami"' && exit
@seadog007
seadog007 / readme.txt
Created April 19, 2020 12:06
A Plaid Puzzle (PuzzleScript Script)
Play this game by pasting the script in http://www.puzzlescript.net/editor.html
@seadog007
seadog007 / googlelive_extract.py
Last active April 21, 2018 09:21
Google Live Photo extractor - Extracts static photo and video from the live photo taken by Google Camera.
#!/usr/bin/env python3
#
# Google Live Photo extractor
# Extracts static photo and video from the live photo taken by Google Camera
#
# Usage:
# $ googlelive_extract.py <image.jpg>
#
# Creates two new files - image_static.jpg and image_video.mp4
#
@seadog007
seadog007 / export.js
Created January 26, 2018 06:05
For http://moves-export.herokuapp.com/ when you have too many days. Run it in your console
function save() {
var textToWrite = out;
var textFileAsBlob = new Blob([textToWrite], {
type: 'text/json'
});
var fileNameToSaveAs = "moves-export.json";
var downloadLink = document.getElementById("download");
downloadLink.download = fileNameToSaveAs;
downloadLink.innerHTML = "";
@seadog007
seadog007 / run.js
Last active October 12, 2017 15:34
Plurk changing nick name event script
var re = /alt="\(dice20\)"\ rndnum="2"\ \/><[^>]alt="\(dice20\)"\ rndnum="20"\ \/><[^>]*alt="\(bzzz\)"\ rndnum="4"/;
var plurk_id = 1358061688;
var plurk_owner_id = 9194929;
var timer = setInterval(function(){
var rnd = (new Date().getTime());
var content = rnd + '\n(dice20)(dice20)(bzzz)'.repeat(10);
jQuery.post("/Responses/add", {qualifier: ':', content: content, p_uid: plurk_owner_id, plurk_id: plurk_id, lang: 'tr_ch', uid: SiteState.getSessionUser().id}, function(data){
m = re.exec(data.object.content);
if(m !== null){
console.log('Got it');
@seadog007
seadog007 / hitcon_zeroday_publish_channel_notification.sh
Last active July 21, 2017 06:16
HITCON ZeroDay publish notification to Telegram channel
#!/bin/bash
token='token_only'
disable_preview='True'
for i in `seq 1 10`
do
curl -s https://zeroday.hitcon.org/vulnerability/disclosed/page/$i | grep vu-l-data-titl | tr -d $'\t' | \
while read line
do
link=`echo $line | grep -oP '<a\ href="\K.*(?=")'`
title=`echo $line | grep -oP '<a.*">\K.*(?=</a)'`
@seadog007
seadog007 / fiddler.js
Last active January 31, 2019 06:53
Fiddler extension for cracking Taiwan McDonald Coupon app which is available for both Android and iOS version (´・ω・`)
/*
======================
Author: 海豹
Date: 2017/1/22
Version: 1.0.0.0
Description: Fiddler extension for cracking Taiwan MacDonald Coupon app which is available for both Android and iOS version (´・ω・`)
僅供學術使用 請勿用作非法用途
======================
*/
import System;