Пример #1
0
def cookiepre(session, web, pay, req):
    success = []
    for i in pay:
        print(B+" [*] Trying Payload : "+C+''+ i)
        time.sleep(0.7)
        for cookie in session.cookies:
            cookie.value += i
            print(O+' [+] Using '+R+'!nfected'+O+' cookie : '+GR+cookie.value)
            r = session.get(web)
            if len(r.content) != len(req.content):
                poc = C+" [+] PoC : " +O+ cookie.name + " : " +GR+ cookie.value
                print(G+" [+] Blind Based SQli (Cookie Based) Detected! ")
                print(poc)
                print(P+' [+] Code : '+W+str(r.text)+'\n')
                success.append(i)
    return success
Пример #2
0
def cookiepre(pay,session,check, web):
    success = []
    for i in pay:
        print(B+" [*] Trying Payload : "+C+''+ i)
        time.sleep(0.7)
        for cookie in session.cookies:
            cookie.value += i
            print(O+' [+] Using '+R+'!nfected'+O+' cookie : '+GR+cookie.value)
            r = session.get(web)
            for j in range(0, len(check)):
                if check[j] in r.text:
                    poc = C+" [+] PoC : " +O+ cookie.name + " : " +GR+ cookie.value
                    print(G+" [+] Error Based SQli (Cookie Based) Detected! ")
                    print(poc)
                    print(P+' [+] Code : '+W+str(r.text)+'\n')
                    success.append(i)
    return success
Пример #3
0
def cookieatck(pays, session, web):
    success = []
    for j in pays:
        i = '%s' % j
        print(B+" [*] Trying Payload : "+C+ i)
        time.sleep(0.7)
        for cookie in session.cookies:
            cookie.value += i
            print(O+' [+] Using '+R+'!nfected'+O+' cookie : '+GR+cookie.value)
            r = session.get(web)
            if str(i) in str(r.text):
                poc = C+" [+] PoC : " +O+ cookie.name + " : " +GR+ cookie.value
                print(G+" [+] Cookie Based XSS Detected! ")
                print(poc)
                print(P+' [+] Code : '+W+str(r.text)+'\n')
                success.append(i)
    return success