2019-05-08 13:47:52 +03:00
|
|
|
#!/usr/bin/env python
|
2010-03-27 02:23:25 +03:00
|
|
|
|
|
|
|
"""
|
2024-01-04 01:11:52 +03:00
|
|
|
Copyright (c) 2006-2024 sqlmap developers (https://sqlmap.org/)
|
2017-10-11 15:50:46 +03:00
|
|
|
See the file 'LICENSE' for copying permission
|
2010-03-27 02:23:25 +03:00
|
|
|
"""
|
|
|
|
|
2010-03-28 00:50:19 +03:00
|
|
|
try:
|
|
|
|
import cx_Oracle
|
2017-09-04 18:05:48 +03:00
|
|
|
except:
|
2010-03-28 00:50:19 +03:00
|
|
|
pass
|
|
|
|
|
2012-10-23 17:34:59 +04:00
|
|
|
import logging
|
2012-02-22 14:40:11 +04:00
|
|
|
import os
|
2018-01-25 14:13:33 +03:00
|
|
|
import re
|
2010-05-29 16:14:51 +04:00
|
|
|
|
2019-01-22 04:08:02 +03:00
|
|
|
from lib.core.common import getSafeExString
|
2019-11-17 02:22:47 +03:00
|
|
|
from lib.core.convert import getText
|
2012-10-23 17:34:59 +04:00
|
|
|
from lib.core.data import conf
|
2010-03-28 00:50:19 +03:00
|
|
|
from lib.core.data import logger
|
2012-12-06 17:14:19 +04:00
|
|
|
from lib.core.exception import SqlmapConnectionException
|
2010-03-27 02:23:25 +03:00
|
|
|
from plugins.generic.connector import Connector as GenericConnector
|
|
|
|
|
2012-02-22 14:40:11 +04:00
|
|
|
os.environ["NLS_LANG"] = ".AL32UTF8"
|
2010-05-29 16:14:51 +04:00
|
|
|
|
2010-03-27 02:23:25 +03:00
|
|
|
class Connector(GenericConnector):
|
|
|
|
"""
|
2018-05-08 15:06:34 +03:00
|
|
|
Homepage: https://oracle.github.io/python-cx_Oracle/
|
|
|
|
User https://cx-oracle.readthedocs.io/en/latest/
|
|
|
|
API: https://wiki.python.org/moin/DatabaseProgramming
|
|
|
|
License: https://cx-oracle.readthedocs.io/en/latest/license.html#license
|
2010-03-27 02:23:25 +03:00
|
|
|
"""
|
|
|
|
|
2010-03-31 14:50:47 +04:00
|
|
|
def connect(self):
|
2010-03-28 00:50:19 +03:00
|
|
|
self.initConnection()
|
|
|
|
self.__dsn = cx_Oracle.makedsn(self.hostname, self.port, self.db)
|
2019-11-17 02:22:47 +03:00
|
|
|
self.__dsn = getText(self.__dsn)
|
|
|
|
self.user = getText(self.user)
|
|
|
|
self.password = getText(self.password)
|
2010-03-28 00:50:19 +03:00
|
|
|
|
|
|
|
try:
|
|
|
|
self.connector = cx_Oracle.connect(dsn=self.__dsn, user=self.user, password=self.password, mode=cx_Oracle.SYSDBA)
|
|
|
|
logger.info("successfully connected as SYSDBA")
|
2019-01-22 02:40:48 +03:00
|
|
|
except (cx_Oracle.OperationalError, cx_Oracle.DatabaseError, cx_Oracle.InterfaceError) as ex:
|
2019-01-22 04:08:02 +03:00
|
|
|
if "Oracle Client library" in getSafeExString(ex):
|
|
|
|
msg = re.sub(r"DPI-\d+:\s+", "", getSafeExString(ex))
|
2018-01-25 14:23:54 +03:00
|
|
|
msg = re.sub(r': ("[^"]+")', r" (\g<1>)", msg)
|
|
|
|
msg = re.sub(r". See (http[^ ]+)", r'. See "\g<1>"', msg)
|
2018-01-25 14:13:33 +03:00
|
|
|
raise SqlmapConnectionException(msg)
|
|
|
|
|
2010-03-28 00:50:19 +03:00
|
|
|
try:
|
|
|
|
self.connector = cx_Oracle.connect(dsn=self.__dsn, user=self.user, password=self.password)
|
2019-01-22 04:08:02 +03:00
|
|
|
except (cx_Oracle.OperationalError, cx_Oracle.DatabaseError, cx_Oracle.InterfaceError) as ex:
|
|
|
|
raise SqlmapConnectionException(ex)
|
2010-03-28 00:50:19 +03:00
|
|
|
|
2013-01-18 14:21:23 +04:00
|
|
|
self.initCursor()
|
2013-04-15 16:31:27 +04:00
|
|
|
self.printConnected()
|
2010-03-28 00:50:19 +03:00
|
|
|
|
|
|
|
def fetchall(self):
|
2010-04-06 19:12:52 +04:00
|
|
|
try:
|
|
|
|
return self.cursor.fetchall()
|
2019-01-22 04:08:02 +03:00
|
|
|
except cx_Oracle.InterfaceError as ex:
|
|
|
|
logger.log(logging.WARN if conf.dbmsHandler else logging.DEBUG, "(remote) '%s'" % getSafeExString(ex))
|
2010-04-06 19:12:52 +04:00
|
|
|
return None
|
2010-03-28 00:50:19 +03:00
|
|
|
|
|
|
|
def execute(self, query):
|
2012-01-13 18:10:53 +04:00
|
|
|
retVal = False
|
|
|
|
|
2010-03-28 00:50:19 +03:00
|
|
|
try:
|
2019-11-17 02:22:47 +03:00
|
|
|
self.cursor.execute(getText(query))
|
2012-01-13 18:10:53 +04:00
|
|
|
retVal = True
|
2019-01-22 04:08:02 +03:00
|
|
|
except cx_Oracle.DatabaseError as ex:
|
|
|
|
logger.log(logging.WARN if conf.dbmsHandler else logging.DEBUG, "(remote) '%s'" % getSafeExString(ex))
|
2010-03-28 00:50:19 +03:00
|
|
|
|
|
|
|
self.connector.commit()
|
|
|
|
|
2012-01-13 18:10:53 +04:00
|
|
|
return retVal
|
|
|
|
|
2010-03-28 00:50:19 +03:00
|
|
|
def select(self, query):
|
2012-01-13 18:10:53 +04:00
|
|
|
retVal = None
|
|
|
|
|
|
|
|
if self.execute(query):
|
|
|
|
retVal = self.fetchall()
|
|
|
|
|
|
|
|
return retVal
|