Skip to content

Instantly share code, notes, and snippets.

[root@matrix /]# du -xshc /; df -h .; lsof | grep eleted
1.7G /
1.7G total
Filesystem Size Used Avail Use% Mounted on
/dev/mapper/fedora--server-root 26G 18G 6.7G 74% /
monitor 1099 root 7u REG 0,37 141 13516 /tmp/tmpfOSiUzF (deleted)
ovsdb-ser 1100 root 7u REG 0,37 141 13516 /tmp/tmpfOSiUzF (deleted)
[root@matrix /]#
user-agent=Mozilla/5.0 compatable (All your base are belong to us!!; Macintosh %d%sUnix NT Netscape Linux Internet Explorer; I U; en-US;" Happy parsing! <script><!--
# -SSH- warewolf@xabean:~/bin/srp$ cat email
#!/usr/bin/perl
use strict;
use warnings;
use MIME::Base64;
use POSIX qw(strftime);
my ($email) = @ARGV;
@warewolf
warewolf / soup.txt
Created August 17, 2016 15:07
chicken noodle soup
Note: this makes a lot of food. It's got a lot of veggies in it, with so much solid stuff in there, it doesn't leave much room for the liquid. Adjust your veggies down to 1 cup each if you like a more liquidy soup.
This recipe is loosely based on http://www.cooks.com/rec/doc/0,1639,156182-243203,00.html and I have to admit that I took bits and pieces from other recipes on the site and took what sounded tasty and threw it all in the pot. Yes, one of the recipes called for bacon :) Yum.
THE MEAT & JUICES:
1 whole fryer chicken (I did not use the giblets)
4 cups chicken broth
THE FLAVOR:
1/4 tsp pepper
@warewolf
warewolf / foscam_initrd_strings.txt
Created September 24, 2016 05:26
foscam initrd strings (I totally did not dump this correctly)
blar: 85898 echo "${GREEN}You are welcomed by FOSCAM R&D.${NORMAL}"
blar: 85956 070701000002E1000081FF000003E8000003E80000000153AABED00000003B000000030000000100000000000000000000000B00000000etc/passwd
blar: 86080 root:$1$uYfJBoag$N8ofdlVBVcfzOY7utbTfo0:0:0::/root:/bin/sh
blar: 86140 070701000002E2000081FF000003E8000003E8000000015330D62300000026000000030000000100000000000000000000000C00000000etc/passwd-
blar: 86264 root:ab8nBoH3mb8.g:0:0::/root:/bin/sh
blar: 86304 070701000002E3000041FF000003E8000003E80000000256680ABA00000000000000030000000100000000000000000000000B00000000etc/init.d
blar: 86428 070701000002E4000081FF000003E8000003E8000000015330D62300000087000000030000000100000000000000000000001300000000etc/init.d/S90init
@warewolf
warewolf / initrd.txt
Created September 24, 2016 05:52
foscam c1 initrd listing
491765 4 drwx--S--- 20 warewolf warewolf 4096 Sep 24 01:50 .
499825 4 drwxrwxrwx 2 warewolf warewolf 4096 Sep 24 01:50 ./sys
499866 4 drwxrwxrwx 2 warewolf warewolf 4096 Sep 24 01:50 ./home
499828 4 drwxrwxrwx 4 warewolf warewolf 4096 Sep 24 01:50 ./etc
420858 4 -rwxrwxrwx 1 warewolf warewolf 2478 Sep 24 01:50 ./etc/protocols
420860 4 -rwxrwxrwx 1 warewolf warewolf 3399 Sep 24 01:50 ./etc/inittab
420859 4 -rwxrwxrwx 1 warewolf warewolf 101 Sep 24 01:50 ./etc/mtab
420839 4 -rwxrwxrwx 1 warewolf warewolf 30 Sep 24 01:50 ./etc/fs-version
420857 16 -rwxrwxrwx 1 warewolf warewolf 15958 Sep 24 01:50 ./etc/services
420838 4 -rwxrwxrwx 1 warewolf warewolf 9 Sep 24 01:50 ./etc/group
@warewolf
warewolf / core_debug_logs-different_call.txt
Last active February 28, 2017 05:20
Weird asterisk SRTP problem
[Feb 28 00:12:10] DEBUG[30298][C-0000000c] sdp_srtp.c: local_key64 W2rZR1yHSV+hefz2Haeu5L3F7U0nuW4OOtMgXRba len 40
[Feb 28 00:12:10] DEBUG[30298][C-0000000c] res_srtp.c: Adding new policy for SSRC 1571565691
[Feb 28 00:12:10] DEBUG[30298][C-0000000c] sdp_srtp.c: SRTP policy activated
[Feb 28 00:12:10] DEBUG[30298][C-0000000c] sdp_srtp.c: Crypto line: a=crypto:1 AES_CM_128_HMAC_SHA1_80 inline:W2rZR1yHSV+hefz2Haeu5L3F7U0nuW4OOtMgXRba
[Feb 28 00:12:10] DEBUG[30298][C-0000000c] chan_sip.c: Processing media-level (audio) SDP a=crypto:1 AES_CM_128_HMAC_SHA1_80 inline:ODc0MjU5AABmZWU0ZWMzADJkNWRlMmRkNjA2NDhm... OK.
[Feb 28 00:12:10] DEBUG[30298][C-0000000c] chan_sip.c: Processing media-level (audio) SDP a=crypto:2 AES_CM_128_HMAC_SHA1_32 inline:NTRlM2Y2NmIzNDhhMmM5NTY4NzU3ZTQAMzYxNjNj... UNSUPPORTED OR FAILED.
[Feb 28 00:12:10] DEBUG[30298][C-0000000c] chan_sip.c: Processing media-level (audio) SDP a=crypto:3 F8_128_HMAC_SHA1_80 inline:MjUzYTdkYTY0ZTY0NGQ0YjJiMWUzMzM2NDVjYzEz... UNSUPPORTED OR FAILED.
[Feb 28 00:12:
@warewolf
warewolf / ifcfg-gremonitor0
Created July 1, 2017 22:13
Fedora/Red Hat Open vSwitch malware analysis segment "mirror" tunnel config
# set remote_ip below to your cuckoo VM's management IP
# set local_ip below to your VM server's management IP
TYPE="OVSTunnel"
OVS_TUNNEL_TYPE="gre"
OVS_BRIDGE="malwarebr0"
DEVICE="gremonitor0"
OVS_TUNNEL_OPTIONS="options:remote_ip=192.168.2.100 options:local_ip=192.168.2.70"
OVS_EXTRA="\
-- --id=@p get port gremonitor0 \
@warewolf
warewolf / diff.patch
Created July 5, 2017 04:04
registry diff of the same win7 VM booting 2x
--- /tmp/left-bA3uU/left-system-reg-l5GJd.tmp 2017-07-04 23:48:10.086963908 -0400
+++ /tmp/right-3nTJO/right-system-reg-ydUqH.tmp 2017-07-04 23:48:10.086963908 -0400
@@ -101,20 +101,20 @@
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CMF\SqmData]
"AvgCountDiff"=dword:000001f6
"AvgFileCount"=dword:000001f6
-"CMFLastStartTime"=hex(b):05,ff,f9,48,41,04,ca,01
-"CMFStartTime"=hex(b):c0,b2,bb,72,d6,f4,d2,01
+"CMFLastStartTime"=hex(b):c0,b2,bb,72,d6,f4,d2,01