
एक्सप्लॉइट स्क्रिप्ट लिखने के टिप्स (तेज़ी से!)
इस रिपॉज़िटरी में OSWE लैब्स और सर्टिफिकेशन परीक्षा में एक्सप्लॉइट स्क्रिप्ट लिखने से संबंधित उपयोगी स्निपेट्स और टिप्स की एक सूची है।
यहां कुछ उदाहरण कुछ कोडिंग प्रथाओं के विरुद्ध जा सकते हैं, लेकिन हमारा अंतिम लक्ष्य एक्सप्लॉइट स्क्रिप्ट को तेज़ और सही तरीके से लिखना है।
कोड स्निपेट्स अनुभाग शुरुआत करने के लिए एक अच्छी जगह है यदि आपको
requestsलाइब्रेरी का उपयोग करने का अनुभव नहीं है या आप Python में नए हैं। अन्यथा, बेझिझक पुनः प्रयोग योग्य कोड अनुभाग या टिप्स अनुभाग पर जाएं।
requests लाइब्रेरी का उपयोग करना
params argument का उपयोग करके)data argument का उपयोग करके)json argument का उपयोग करके)files argument का उपयोग करके)headers argument का उपयोग करके)cookies argument का उपयोग करके)3XX रीडायरेक्ट का अनुसरण अक्षम करना (allow_redirects argument का उपयोग करके)verify argument का उपयोग करके)proxies argument का उपयोग करके)Session बनानाassert का उपयोग करके एक सैनिटी चेक करेंSession ऑब्जेक्ट बनाएं ताकि इसे हर फ़ंक्शन कॉल में स्पष्ट रूप से पास न करना पड़ेBASE_URL स्ट्रिंग बनाएं और उससे आवश्यक URLs बनाएंproxies argument का उपयोग किए बिना, चलाते समय HTTP_PROXY / HTTPS_PROXY environment variable सेट करें') और डबल दोनों quotes (") हों, तो उसे बनाने के लिए """ का उपयोग करें{}) हों, तो f-strings (f"") या str.format का उपयोग करने से बचेंimport requests
def main():
print("Hello World!")
if __name__ == __main__:
main()
# For sending HTTP requests
import requests
# For Base64 encoding/decoding
from base64 import b64encode, b64decode, urlsafe_b64encode, urlsafe_b64decode
# For getting current time or for calculating time delays
from time import time
# For regular expressions
import re
# For running shell commands
import subprocess
# For multithreading
from concurrent.futures import ThreadPoolExecutor
# For running a HTTP server in the background
import threading
from http.server import HTTPServer, BaseHTTPRequestHandler
# For parsing HTTP cookies
from http import cookies
# For getting command-line arguments
import sys
requests लाइब्रेरी का उपयोग करनाresp_obj = requests.get("https://github.com")
# GET method
requests.get("https://github.com")
# POST method
requests.post("https://github.com")
# PUT method
requests.put("https://github.com")
# PATCH method
requests.patch("https://github.com")
# DELETE method
requests.delete("https://github.com")
resp_obj = requests.get("https://github.com")
# HTTP status code (e.g 404, 500, 301)
resp_obj.status_code
# HTTP response headers (e.g Location, Content-Disposition)
resp_obj.headers["Location"]
# Body as bytes
resp_obj.content
# Body as a string
resp_obj.text
# Body as a dictionary (if body is a JSON)
resp_obj.json()
params argument का उपयोग करके)