2008-10-15 19:38:22 +04:00
|
|
|
#!/usr/bin/env python
|
|
|
|
|
|
|
|
"""
|
2008-10-15 19:56:32 +04:00
|
|
|
$Id$
|
2008-10-15 19:38:22 +04:00
|
|
|
|
|
|
|
This file is part of the sqlmap project, http://sqlmap.sourceforge.net.
|
|
|
|
|
|
|
|
Copyright (c) 2006-2008 Bernardo Damele A. G. <bernardo.damele@gmail.com>
|
|
|
|
and Daniele Bellucci <daniele.bellucci@gmail.com>
|
|
|
|
|
|
|
|
sqlmap is free software; you can redistribute it and/or modify it under
|
|
|
|
the terms of the GNU General Public License as published by the Free
|
|
|
|
Software Foundation version 2 of the License.
|
|
|
|
|
|
|
|
sqlmap is distributed in the hope that it will be useful, but WITHOUT ANY
|
|
|
|
WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS
|
|
|
|
FOR A PARTICULAR PURPOSE. See the GNU General Public License for more
|
|
|
|
details.
|
|
|
|
|
|
|
|
You should have received a copy of the GNU General Public License along
|
|
|
|
with sqlmap; if not, write to the Free Software Foundation, Inc., 51
|
|
|
|
Franklin St, Fifth Floor, Boston, MA 02110-1301 USA
|
|
|
|
"""
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
import re
|
|
|
|
|
|
|
|
from xml.sax import parse
|
|
|
|
from xml.sax.handler import ContentHandler
|
|
|
|
|
|
|
|
from lib.core.common import checkFile
|
|
|
|
from lib.core.common import sanitizeStr
|
2008-11-16 02:41:31 +03:00
|
|
|
from lib.core.data import kb
|
|
|
|
from lib.core.data import paths
|
2008-10-15 19:38:22 +04:00
|
|
|
|
|
|
|
|
2008-11-16 02:41:31 +03:00
|
|
|
class BannerHandler(ContentHandler):
|
2008-10-15 19:38:22 +04:00
|
|
|
"""
|
|
|
|
This class defines methods to parse and extract information from
|
|
|
|
the given DBMS banner based upon the data in XML file
|
|
|
|
"""
|
|
|
|
|
2008-11-16 02:41:31 +03:00
|
|
|
def __init__(self, banner):
|
|
|
|
self.__banner = sanitizeStr(banner)
|
|
|
|
|
2008-11-17 20:41:02 +03:00
|
|
|
self.__regexp = None
|
|
|
|
self.__match = None
|
|
|
|
self.__version = None
|
2008-11-16 02:41:31 +03:00
|
|
|
|
2008-11-17 20:41:02 +03:00
|
|
|
|
|
|
|
def __feedInfo(self, key, value):
|
|
|
|
value = sanitizeStr(value)
|
|
|
|
|
|
|
|
if value in ( None, "None" ):
|
|
|
|
return
|
|
|
|
|
|
|
|
if key == "version":
|
|
|
|
kb.bannerFp[key] = value
|
|
|
|
else:
|
|
|
|
if key not in kb.bannerFp.keys():
|
|
|
|
kb.bannerFp[key] = set()
|
|
|
|
|
|
|
|
kb.bannerFp[key].add(value)
|
2008-11-16 02:41:31 +03:00
|
|
|
|
|
|
|
|
|
|
|
def startElement(self, name, attrs):
|
|
|
|
if name == "regexp":
|
|
|
|
self.__regexp = sanitizeStr(attrs.get("value"))
|
|
|
|
self.__match = re.search(self.__regexp, self.__banner, re.I | re.M)
|
|
|
|
|
|
|
|
if name == "info" and self.__match:
|
2008-11-17 20:41:02 +03:00
|
|
|
self.__feedInfo("type", attrs.get("type"))
|
|
|
|
self.__feedInfo("distrib", attrs.get("distrib"))
|
|
|
|
self.__feedInfo("release", attrs.get("release"))
|
|
|
|
self.__feedInfo("codename", attrs.get("codename"))
|
2008-11-16 02:41:31 +03:00
|
|
|
|
2008-11-17 20:41:02 +03:00
|
|
|
self.__version = sanitizeStr(attrs.get("version"))
|
|
|
|
self.__sp = sanitizeStr(attrs.get("sp"))
|
2008-11-16 02:41:31 +03:00
|
|
|
|
2008-11-17 20:41:02 +03:00
|
|
|
if self.__version.isdigit():
|
|
|
|
self.__feedInfo("version", self.__match.group(int(self.__version)))
|
2008-11-16 02:41:31 +03:00
|
|
|
|
|
|
|
if self.__sp.isdigit():
|
2008-11-17 20:41:02 +03:00
|
|
|
self.__feedInfo("sp", "Service Pack %s" % self.__match.group(int(self.__sp)))
|
2008-11-16 02:41:31 +03:00
|
|
|
|
2008-11-17 20:41:02 +03:00
|
|
|
self.__regexp = None
|
|
|
|
self.__match = None
|
|
|
|
self.__version = None
|
2008-11-16 02:41:31 +03:00
|
|
|
|
|
|
|
|
|
|
|
class MSSQLBannerHandler(ContentHandler):
|
|
|
|
"""
|
|
|
|
This class defines methods to parse and extract information from the
|
|
|
|
given Microsoft SQL Server banner based upon the data in XML file
|
|
|
|
"""
|
|
|
|
|
2008-10-15 19:38:22 +04:00
|
|
|
def __init__(self, banner):
|
|
|
|
self.__banner = sanitizeStr(banner)
|
2008-11-16 02:41:31 +03:00
|
|
|
|
2008-10-15 19:38:22 +04:00
|
|
|
self.__inVersion = False
|
|
|
|
self.__inServicePack = False
|
|
|
|
self.__release = None
|
|
|
|
self.__version = ""
|
|
|
|
self.__servicePack = ""
|
|
|
|
|
2008-11-17 20:41:02 +03:00
|
|
|
|
|
|
|
def __feedInfo(self, key, value):
|
|
|
|
value = sanitizeStr(value)
|
|
|
|
|
|
|
|
if value in ( None, "None" ):
|
|
|
|
return
|
|
|
|
|
|
|
|
kb.bannerFp[key] = value
|
2008-11-16 02:41:31 +03:00
|
|
|
|
2008-10-15 19:38:22 +04:00
|
|
|
|
|
|
|
def startElement(self, name, attrs):
|
|
|
|
if name == "signatures":
|
|
|
|
self.__release = sanitizeStr(attrs.get("release"))
|
|
|
|
|
|
|
|
elif name == "version":
|
|
|
|
self.__inVersion = True
|
|
|
|
|
|
|
|
elif name == "servicepack":
|
|
|
|
self.__inServicePack = True
|
|
|
|
|
|
|
|
|
|
|
|
def characters(self, data):
|
|
|
|
if self.__inVersion:
|
|
|
|
self.__version += sanitizeStr(data)
|
|
|
|
elif self.__inServicePack:
|
|
|
|
self.__servicePack += sanitizeStr(data)
|
|
|
|
|
|
|
|
|
|
|
|
def endElement(self, name):
|
|
|
|
if name == "signature":
|
|
|
|
if re.search(" %s[\.\ ]+" % self.__version, self.__banner):
|
2008-11-17 20:41:02 +03:00
|
|
|
self.__feedInfo("dbmsRelease", self.__release)
|
|
|
|
self.__feedInfo("dbmsVersion", self.__version)
|
|
|
|
self.__feedInfo("dbmsServicePack", self.__servicePack)
|
2008-10-15 19:38:22 +04:00
|
|
|
|
|
|
|
self.__version = ""
|
|
|
|
self.__servicePack = ""
|
|
|
|
|
|
|
|
|
|
|
|
elif name == "version":
|
|
|
|
self.__inVersion = False
|
|
|
|
self.__version = self.__version.replace(" ", "")
|
|
|
|
|
|
|
|
elif name == "servicepack":
|
|
|
|
self.__inServicePack = False
|
|
|
|
self.__servicePack = self.__servicePack.replace(" ", "")
|
|
|
|
|
|
|
|
|
2008-11-16 02:41:31 +03:00
|
|
|
def bannerParser(banner):
|
2008-10-15 19:38:22 +04:00
|
|
|
"""
|
|
|
|
This function calls a class to extract information from the given
|
|
|
|
DBMS banner based upon the data in XML file
|
|
|
|
"""
|
|
|
|
|
2008-11-16 02:41:31 +03:00
|
|
|
if kb.dbms == "Microsoft SQL Server":
|
|
|
|
xmlfile = paths.MSSQL_XML
|
|
|
|
elif kb.dbms == "MySQL":
|
|
|
|
xmlfile = paths.MYSQL_XML
|
|
|
|
elif kb.dbms == "Oracle":
|
|
|
|
xmlfile = paths.ORACLE_XML
|
|
|
|
elif kb.dbms == "PostgreSQL":
|
|
|
|
xmlfile = paths.PGSQL_XML
|
|
|
|
|
|
|
|
checkFile(xmlfile)
|
|
|
|
|
|
|
|
if kb.dbms == "Microsoft SQL Server":
|
|
|
|
handler = MSSQLBannerHandler(banner)
|
|
|
|
parse(xmlfile, handler)
|
|
|
|
handler = BannerHandler(banner)
|
|
|
|
parse(paths.GENERIC_XML, handler)
|
|
|
|
else:
|
|
|
|
handler = BannerHandler(banner)
|
|
|
|
parse(xmlfile, handler)
|
2008-11-17 20:41:02 +03:00
|
|
|
parse(paths.GENERIC_XML, handler)
|