Skip to content

Instantly share code, notes, and snippets.

View securitygab's full-sized avatar
🎯
Creating new updates for securitygab/Home-Sec

SH'Kuroi securitygab

🎯
Creating new updates for securitygab/Home-Sec
View GitHub Profile
using System;
using System.Text;
using sNasa.text;
using nasaspacesec;
using System.Security.Cryptography;
namespace PasswordSecurity
{
class InvalidHashException : Exception
{
╭━╮╱╭┳━━━┳━━━┳━━━╮╭╮╱╱╱╱╱╱╱╱╱╭╮╱╱╱╱╱╱╱╱╭╮╭╮
┃┃╰╮┃┃╭━╮┃╭━╮┃╭━╮┃┃┃╱╱╱╱╱╱╱╱╱┃┃╱╱╱╱╱╱╱╱┃┃┃┃
┃╭╮╰╯┃┃╱┃┃╰━━┫┃╱┃┃┃┃╱╭━━╮╭━━╮┃┃╭╮╭━━╮╭━╯┃┃┃
┃┃╰╮┃┃╰━╯┣━━╮┃╰━╯┃┃┃╱┃┃━┫┃╭╮┃┃╰╯╯┃┃━┫┃╭╮┃╰╯
┃┃╱┃┃┃╭━╮┃╰━╯┃╭━╮┃┃╰╮┃┃━┫┃╭╮┃┃╭╮╮┃┃━┫┃╰╯┃╭╮
╰╯╱╰━┻╯╱╰┻━━━┻╯╱╰╯╰━╯╰━━╯╰╯╰╯╰╯╰╯╰━━╯╰━━╯╰╯
$~> timothy.o.johnson@nasa.gov:toj122163
$~> shanna.e.ohara@nasa.gov:mark05
$~> sherry.r.johnson@nasa.gov:pma65srj
@securitygab
securitygab / gist:948e45fe466685846085b717259ed04d
Created April 2, 2023 06:15
Secure Snippet (PHP) against injections and protecting you're header
// Securing against Header Injection
// CC: SecurityGab/Dengisan.nl
foreach($_POST as $key => $value){
$_POST[$key] = _cleaninjections(trim($value));
}
@securitygab
securitygab / ptt2cef4e3d - ODIDO
Created February 24, 2026 23:46
Injected the string ptt2cef4e3d in the usernames body parameter and we have found reflected in the response kek
Input Reflected Request&Response
< POST /Core/Security/Login?ptt7600efbd= HTTP/1.1
< Host: beheervastmobiel-acc.odido.nl
< User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36
< Content-Type: application/x-www-form-urlencoded
< Cookie: .AspNetCore.Antiforgery.Rl6OMZz-eJ8=CfDJ8CAQSoEe-i9LgXoOjiei_gSONg-LkAGG62CElNKLwP4R-ROFTrCGsAjTL2YZHyqK5igBnS5y7JpmJw0L5wnurzK6UnUS2isIrea-By3NTkzUYiaY9aQBW9BDfoEz-sOoMga7xC1KExC8oT-XxOJF92o
< Content-Length: 245
<
< __RequestVerificationToken=CfDJ8CAQSoEe-i9LgXoOjiei_gQM4tqEbyn5BVc7zGnHTtWbTDCS45peJ60Xsh0pmeJYaBQt5D6qpGA6rYut8oquz4ZSpvG7GRhBzDQHgY7NzNQUmwb0AP9MmvkdVdMFU945IoHv5zD9s_IdSLlD8F0wAQs&Password=Secure123456%24&Username=1d3d2d231d2dd4ptt2cef4e3d%60