编写Python 2暴力破解脚本破解0-1000范围Bash程序数字密码
Python 2 Brute-force Script for Password-Protected Bash Program
Here's a working implementation based on your pseudocode, with proper handling of subprocess input and process status checks:
import subprocess from subprocess import PIPE import time def find_password(): for password in range(0, 1001): # Start the bash program, redirect stdin to send input proc = subprocess.Popen( ['./program'], stdin=PIPE, stdout=PIPE, stderr=subprocess.STDOUT, shell=False ) # Send the current password guess (add newline to simulate enter key) proc.stdin.write(str(password) + '\n') proc.stdin.flush() # Give the program a moment to process the input time.sleep(0.1) # Check if the process is still running (None means alive) if proc.poll() is None: print("Success! Found password:", password) # Optional: If you want to interact with the running program, you can do so here # For example, read output: print(proc.stdout.read()) return password else: # Clean up resources for failed attempts proc.stdin.close() proc.stdout.close() print("Password not found in 0-1000 range") return None if __name__ == "__main__": find_password()
Key Details Explained:
- Subprocess Setup: We use
subprocess.Popenwithstdin=PIPEto send input to the bash program.stdout=PIPEandstderr=STDOUTcapture output (useful for debugging if needed). - Sending Input: We convert the number to a string and add a newline (
\n) because the program expects you to press Enter after typing the password.flush()ensures the input is sent immediately instead of being buffered. - Checking Process Status:
proc.poll()returnsNoneif the process is still running (meaning the password was correct), or an exit code if it exited (wrong password). - Small Delay:
time.sleep(0.1)gives the bash program enough time to process the input and either exit or continue running. Adjust this if your program is slower to respond. - Resource Cleanup: We close stdin and stdout for failed attempts to avoid resource leaks.
Notes:
- Make sure the
./programfile has executable permissions (chmod +x programif needed). - Run this script from the same directory where
programis located, or provide the full path to the program (e.g.,'/home/user/Downloads/program'). - If your program outputs specific messages on correct/incorrect passwords, you could also read the stdout to verify instead of relying on process status—this might be more reliable for some programs.
内容的提问来源于stack exchange,提问作者adam
相关产品推荐
相关产品推荐

