2019-05-08 13:47:52 +03:00
|
|
|
#!/usr/bin/env python
|
2008-11-18 20:42:46 +03:00
|
|
|
|
|
|
|
"""
|
2020-01-01 15:25:15 +03:00
|
|
|
Copyright (c) 2006-2020 sqlmap developers (http://sqlmap.org/)
|
2017-10-11 15:50:46 +03:00
|
|
|
See the file 'LICENSE' for copying permission
|
2008-11-18 20:42:46 +03:00
|
|
|
"""
|
|
|
|
|
|
|
|
import re
|
2011-12-22 02:09:21 +04:00
|
|
|
|
2008-11-18 20:42:46 +03:00
|
|
|
from xml.sax.handler import ContentHandler
|
2019-06-04 15:44:06 +03:00
|
|
|
|
2008-11-18 20:42:46 +03:00
|
|
|
from lib.core.common import sanitizeStr
|
|
|
|
|
|
|
|
class FingerprintHandler(ContentHandler):
|
|
|
|
"""
|
|
|
|
This class defines methods to parse and extract information from
|
|
|
|
the given DBMS banner based upon the data in XML file
|
|
|
|
"""
|
|
|
|
|
|
|
|
def __init__(self, banner, info):
|
2011-01-15 15:53:40 +03:00
|
|
|
ContentHandler.__init__(self)
|
|
|
|
|
2012-02-16 17:46:01 +04:00
|
|
|
self._banner = sanitizeStr(banner)
|
|
|
|
self._regexp = None
|
|
|
|
self._match = None
|
|
|
|
self._dbmsVersion = None
|
|
|
|
self._techVersion = None
|
|
|
|
self._info = info
|
|
|
|
|
|
|
|
def _feedInfo(self, key, value):
|
2008-11-18 20:42:46 +03:00
|
|
|
value = sanitizeStr(value)
|
|
|
|
|
2013-01-09 18:38:41 +04:00
|
|
|
if value in (None, "None"):
|
2008-11-18 20:42:46 +03:00
|
|
|
return
|
|
|
|
|
2011-12-22 02:09:21 +04:00
|
|
|
if key == "dbmsVersion":
|
2012-02-16 17:46:01 +04:00
|
|
|
self._info[key] = value
|
2008-11-18 20:42:46 +03:00
|
|
|
else:
|
2019-01-22 05:00:44 +03:00
|
|
|
if key not in self._info:
|
2012-02-16 17:46:01 +04:00
|
|
|
self._info[key] = set()
|
2008-11-18 20:42:46 +03:00
|
|
|
|
2011-12-22 02:09:21 +04:00
|
|
|
for _ in value.split("|"):
|
2012-02-16 17:46:01 +04:00
|
|
|
self._info[key].add(_)
|
2008-11-18 20:42:46 +03:00
|
|
|
|
|
|
|
def startElement(self, name, attrs):
|
|
|
|
if name == "regexp":
|
2012-02-16 17:46:01 +04:00
|
|
|
self._regexp = sanitizeStr(attrs.get("value"))
|
2017-10-31 13:38:09 +03:00
|
|
|
_ = re.match(r"\A[A-Za-z0-9]+", self._regexp) # minor trick avoiding compiling of large amount of regexes
|
2011-12-22 02:09:21 +04:00
|
|
|
|
2012-02-16 17:46:01 +04:00
|
|
|
if _ and _.group(0).lower() in self._banner.lower() or not _:
|
|
|
|
self._match = re.search(self._regexp, self._banner, re.I | re.M)
|
2011-11-22 16:40:12 +04:00
|
|
|
else:
|
2012-02-16 17:46:01 +04:00
|
|
|
self._match = None
|
2008-11-18 20:42:46 +03:00
|
|
|
|
2012-02-16 17:46:01 +04:00
|
|
|
if name == "info" and self._match:
|
|
|
|
self._feedInfo("type", attrs.get("type"))
|
|
|
|
self._feedInfo("distrib", attrs.get("distrib"))
|
|
|
|
self._feedInfo("release", attrs.get("release"))
|
|
|
|
self._feedInfo("codename", attrs.get("codename"))
|
2008-11-18 20:42:46 +03:00
|
|
|
|
2012-02-16 17:46:01 +04:00
|
|
|
self._dbmsVersion = sanitizeStr(attrs.get("dbms_version"))
|
|
|
|
self._techVersion = sanitizeStr(attrs.get("tech_version"))
|
|
|
|
self._sp = sanitizeStr(attrs.get("sp"))
|
2008-11-18 20:42:46 +03:00
|
|
|
|
2012-02-16 17:46:01 +04:00
|
|
|
if self._dbmsVersion.isdigit():
|
|
|
|
self._feedInfo("dbmsVersion", self._match.group(int(self._dbmsVersion)))
|
2008-11-18 20:42:46 +03:00
|
|
|
|
2012-02-16 17:46:01 +04:00
|
|
|
if self._techVersion.isdigit():
|
|
|
|
self._feedInfo("technology", "%s %s" % (attrs.get("technology"), self._match.group(int(self._techVersion))))
|
2008-11-18 20:42:46 +03:00
|
|
|
else:
|
2012-02-16 17:46:01 +04:00
|
|
|
self._feedInfo("technology", attrs.get("technology"))
|
2008-11-18 20:42:46 +03:00
|
|
|
|
2012-02-16 17:46:01 +04:00
|
|
|
if self._sp.isdigit():
|
2013-12-02 01:25:12 +04:00
|
|
|
self._feedInfo("sp", "Service Pack %s" % int(self._sp))
|
2008-11-18 20:42:46 +03:00
|
|
|
|
2012-02-16 17:46:01 +04:00
|
|
|
self._regexp = None
|
|
|
|
self._match = None
|
|
|
|
self._dbmsVersion = None
|
|
|
|
self._techVersion = None
|