PortSwigger SQLi Lab12脚本代理连接失败问题求助
我在PortSwigger的Web Security Academy学习SQL注入课程,卡在了Lab12,无法获取管理员密码。因为使用的是Burp社区版,所以用了一个Python脚本尝试自动注入获取密码,但持续遇到代理连接错误,错误信息如下:
python3 sqli-lab-12.py "https://0aaf00f503f92c0181a707140080003c.web-security-academy.net/" (+) Retreiving administrator password... Traceback (most recent call last): File "/usr/lib/python3/dist-packages/urllib3/connection.py", line 203, in _new_conn sock = connection.create_connection( ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ File "/usr/lib/python3/dist-packages/urllib3/util/connection.py", line 85, in create_connection raise err File "/usr/lib/python3/dist-packages/urllib3/util/connection.py", line 73, in create_connection sock.connect(sa) ConnectionRefusedError: [Errno 111] Connection refused The above exception was the direct cause of the following exception: Traceback (most recent call last): File "/usr/lib/python3/dist-packages/urllib3/connectionpool.py", line 777, in urlopen self._prepare_proxy(conn) File "/usr/lib/python3/dist-packages/urllib3/connectionpool.py", line 1046, in _prepare_proxy conn.connect() File "/usr/lib/python3/dist-packages/urllib3/connection.py", line 611, in connect self.sock = sock = self._new_conn() ^^^^^^^^^^^^^^^^ File "/usr/lib/python3/dist-packages/urllib3/connection.py", line 218, in _new_conn raise NewConnectionError( urllib3.exceptions.NewConnectionError: <urllib3.connection.HTTPSConnection object at 0x7fd62b7fead0>: Failed to establish a new connection: [Errno 111] Connection refused The above exception was the direct cause of the following exception: urllib3.exceptions.ProxyError: ('Unable to connect to proxy', NewConnectionError('<urllib3.connection.HTTPSConnection object at 0x7fd62b7fead0>: Failed to establish a new connection: [Errno 111] Connection refused')) The above exception was the direct cause of the following exception: Traceback (most recent call last): File "/usr/lib/python3/dist-packages/requests/adapters.py", line 667, in send resp = conn.urlopen( ^^^^^^^^^^^^^ File "/usr/lib/python3/dist-packages/urllib3/connectionpool.py", line 845, in urlopen retries = retries.increment( ^^^^^^^^^^^^^^^^^^ File "/usr/lib/python3/dist-packages/urllib3/util/retry.py", line 515, in increment raise MaxRetryError(_pool, url, reason) from reason # type: ignore[arg-type] ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ urllib3.exceptions.MaxRetryError: HTTPSConnectionPool(host='0aaf00f503f92c0181a707140080003c.web-security-academy.net', port=443): Max retries exceeded with url: / (Caused by ProxyError('Unable to connect to proxy', NewConnectionError('<urllib3.connection.HTTPSConnection object at 0x7fd62b7fead0>: Failed to establish a new connection: [Errno 111] Connection refused'))) During handling of the above exception, another exception occurred: Traceback (most recent call last): File "/home/acid/Downloads/sqli-lab-12.py", line 40, in <module> main() File "/home/acid/Downloads/sqli-lab-12.py", line 36, in main sqli_password(url) File "/home/acid/Downloads/sqli-lab-12.py", line 18, in sqli_password r = requests.get(url, cookies=cookies, verify=False, proxies=proxies) ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ File "/usr/lib/python3/dist-packages/requests/api.py", line 73, in get return request("get", url, params=params, **kwargs) ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ File "/usr/lib/python3/dist-packages/requests/api.py", line 59, in request return session.request(method=method, url=url, **kwargs) ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ File "/usr/lib/python3/dist-packages/requests/sessions.py", line 589, in request resp = self.send(prep, **send_kwargs) ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ File "/usr/lib/python3/dist-packages/requests/sessions.py", line 703, in send r = adapter.send(request, **kwargs) ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ File "/usr/lib/python3/dist-packages/requests/adapters.py", line 694, in send raise ProxyError(e, request=request) requests.exceptions.ProxyError: HTTPSConnectionPool(host='0aaf00f503f92c0181a707140080003c.web-security-academy.net', port=443): Max retries exceeded with url: / (Caused by ProxyError('Unable to connect to proxy', NewConnectionError('<urllib3.connection.HTTPSConnection object at 0x7fd62b7fead0>: Failed to establish a new connection: [Errno 111] Connection refused')))
我尝试切换代理协议(HTTP/HTTPS)但问题依旧,想请教问题出在哪里及解决办法。
排查与解决步骤
确认Burp代理处于运行状态
错误中的Connection refused明确表示脚本无法连接到代理端口。先检查Burp Suite是否已经启动,再用终端命令验证代理端口(默认8080)是否被占用:netstat -tulpn | grep 8080 # 或者用ss命令 ss -tulpn | grep 8080如果没有输出,说明Burp没在监听这个端口,需要在Burp的
Proxy->Options里启动监听。核对脚本的代理配置
打开你的sqli-lab-12.py脚本,找到proxies变量的定义,确保地址和端口与Burp的设置完全一致。Burp的代理是HTTP类型,HTTPS请求也需要走这个HTTP代理,正确配置应该是:proxies = { "http": "http://127.0.0.1:8080", "https": "http://127.0.0.1:8080" }不要把HTTPS代理写成
https://127.0.0.1:8080,这是常见错误。关闭系统全局代理
如果你的系统(或浏览器)开启了全局代理,可能会和脚本的代理配置冲突,导致请求被转发到错误的地址。先关闭全局代理,再重新运行脚本测试。检查Burp的监听绑定地址
在Burp的Proxy->Options页面,查看Proxy Listeners的绑定地址。如果设置为特定IP而非127.0.0.1或0.0.0.0,脚本可能无法连接。建议设置为127.0.0.1:8080,仅允许本地连接。临时跳过代理验证脚本可用性
若想快速确认脚本本身是否正常,可以暂时注释掉proxies参数,直接请求目标地址:# 修改前 # r = requests.get(url, cookies=cookies, verify=False, proxies=proxies) # 修改后 r = requests.get(url, cookies=cookies, verify=False)如果修改后能正常请求,说明问题确实出在代理连接环节,再回到前面的步骤排查。
内容的提问来源于stack exchange,提问作者dyeacid

