
Tips on how to write exploit scripts (faster!)
This repository contains a list of useful snippets and tips that pertain to the writing of exploit scripts in the OSWE labs and certification exam.
Some examples here may go against certain coding practices, but our end goal is to write the exploit script fast and correct.
The Code Snippets section is a great place to start if you are not experienced in using the
requestslibrary or are new to Python. Otherwise, feel free to skip to the Reusable Code section or the Tips section.
requests library
params argument)data argument)json argument)files argument)headers argument)cookies argument)3XX redirects (Using allow_redirects argument)verify argument)proxies argument)SessionassertSession object so it does not need to be explictly passed to each function callBASE_URL string and construct the required URLs from itproxies argument , set the HTTP_PROXY / HTTPS_PROXY environment variable when running""" to create the payload string if it contains both single (') and double quotes (")f"") or str.format if the payload contains too many curly braces ({})import requests
def main():
print("Hello World!")
if __name__ == __main__:
main()
# For sending HTTP requests
import requests
# For Base64 encoding/decoding
from base64 import b64encode, b64decode, urlsafe_b64encode, urlsafe_b64decode
# For getting current time or for calculating time delays
from time import time
# For regular expressions
import re
# For running shell commands
import subprocess
# For multithreading
from concurrent.futures import ThreadPoolExecutor
# For running a HTTP server in the background
import threading
from http.server import HTTPServer, BaseHTTPRequestHandler
# For parsing HTTP cookies
from http import cookies
# For getting command-line arguments
import sys
requests libraryresp_obj = requests.get("https://github.com")
# GET method
requests.get("https://github.com")
# POST method
requests.post("https://github.com")
# PUT method
requests.put("https://github.com")
# PATCH method
requests.patch("https://github.com")
# DELETE method
requests.delete("https://github.com")
resp_obj = requests.get("https://github.com")
# HTTP status code (e.g 404, 500, 301)
resp_obj.status_code
# HTTP response headers (e.g Location, Content-Disposition)
resp_obj.headers["Location"]
# Body as bytes
resp_obj.content
# Body as a string
resp_obj.text
# Body as a dictionary (if body is a JSON)
resp_obj.json()
params argument)params = {
"foo": "bar"
}
requests.get("https://github.com", params=params)