sqlmap/plugins/dbms/mssqlserver/connector.py

82 lines
2.5 KiB
Python
Raw Normal View History

2019-03-21 16:00:09 +03:00
#!/usr/bin/env python2
"""
2019-01-05 23:38:52 +03:00
Copyright (c) 2006-2019 sqlmap developers (http://sqlmap.org/)
2017-10-11 15:50:46 +03:00
See the file 'LICENSE' for copying permission
"""
try:
import _mssql
import pymssql
2017-09-04 18:05:48 +03:00
except:
pass
2012-10-23 17:34:59 +04:00
import logging
from lib.core.common import getSafeExString
2019-05-03 14:20:15 +03:00
from lib.core.convert import getBytes
from lib.core.data import conf
from lib.core.data import logger
from lib.core.exception import SqlmapConnectionException
from plugins.generic.connector import Connector as GenericConnector
class Connector(GenericConnector):
"""
2018-05-08 15:06:34 +03:00
Homepage: http://www.pymssql.org/en/stable/
User guide: http://www.pymssql.org/en/stable/pymssql_examples.html
API: http://www.pymssql.org/en/stable/ref/pymssql.html
Debian package: python-pymssql
License: LGPL
Possible connectors: http://wiki.python.org/moin/SQL%20Server
2010-03-31 19:31:11 +04:00
Important note: pymssql library on your system MUST be version 1.0.2
to work, get it from http://sourceforge.net/projects/pymssql/files/pymssql/1.0.2/
"""
def connect(self):
self.initConnection()
try:
self.connector = pymssql.connect(host="%s:%d" % (self.hostname, self.port), user=self.user, password=self.password, database=self.db, login_timeout=conf.timeout, timeout=conf.timeout)
except (pymssql.Error, _mssql.MssqlDatabaseException) as ex:
raise SqlmapConnectionException(getSafeExString(ex))
2018-04-09 12:34:50 +03:00
except ValueError:
raise SqlmapConnectionException
2013-01-18 14:21:23 +04:00
self.initCursor()
2013-04-15 16:31:27 +04:00
self.printConnected()
def fetchall(self):
2010-04-06 19:12:52 +04:00
try:
return self.cursor.fetchall()
except (pymssql.Error, _mssql.MssqlDatabaseException) as ex:
logger.log(logging.WARN if conf.dbmsHandler else logging.DEBUG, "(remote) '%s'" % getSafeExString(ex).replace("\n", " "))
2010-04-06 19:12:52 +04:00
return None
def execute(self, query):
2012-01-13 18:10:53 +04:00
retVal = False
try:
2019-05-03 14:20:15 +03:00
self.cursor.execute(getBytes(query))
2012-01-13 18:10:53 +04:00
retVal = True
except (pymssql.OperationalError, pymssql.ProgrammingError) as ex:
logger.log(logging.WARN if conf.dbmsHandler else logging.DEBUG, "(remote) '%s'" % getSafeExString(ex).replace("\n", " "))
except pymssql.InternalError as ex:
raise SqlmapConnectionException(getSafeExString(ex))
2012-01-13 18:10:53 +04:00
return retVal
def select(self, query):
2012-01-13 18:10:53 +04:00
retVal = None
2010-03-31 19:31:11 +04:00
2012-01-13 18:10:53 +04:00
if self.execute(query):
retVal = self.fetchall()
try:
self.connector.commit()
except pymssql.OperationalError:
pass
2012-01-13 18:10:53 +04:00
return retVal