mirror of
				https://github.com/sqlmapproject/sqlmap.git
				synced 2025-10-31 07:57:47 +03:00 
			
		
		
		
	Adding some tamper scripts
This commit is contained in:
		
							parent
							
								
									c47061f25d
								
							
						
					
					
						commit
						1280abc25c
					
				|  | @ -18,7 +18,7 @@ from lib.core.enums import OS | |||
| from thirdparty.six import unichr as _unichr | ||||
| 
 | ||||
| # sqlmap version (<major>.<minor>.<month>.<monthly commit>) | ||||
| VERSION = "1.4.7.18" | ||||
| VERSION = "1.4.7.19" | ||||
| TYPE = "dev" if VERSION.count('.') > 2 and VERSION.split('.')[-1] != '0' else "stable" | ||||
| TYPE_COLORS = {"dev": 33, "stable": 90, "pip": 34} | ||||
| VERSION_STRING = "sqlmap/%s#%s" % ('.'.join(VERSION.split('.')[:-1]) if VERSION.count('.') > 2 and VERSION.split('.')[-1] == '0' else VERSION, TYPE) | ||||
|  |  | |||
							
								
								
									
										32
									
								
								tamper/0eunion.py
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										32
									
								
								tamper/0eunion.py
									
									
									
									
									
										Normal file
									
								
							|  | @ -0,0 +1,32 @@ | |||
| #!/usr/bin/env python | ||||
| 
 | ||||
| """ | ||||
| Copyright (c) 2006-2020 sqlmap developers (http://sqlmap.org/) | ||||
| See the file 'LICENSE' for copying permission | ||||
| """ | ||||
| 
 | ||||
| import re | ||||
| 
 | ||||
| from lib.core.enums import PRIORITY | ||||
| 
 | ||||
| __priority__ = PRIORITY.HIGHEST | ||||
| 
 | ||||
| def dependencies(): | ||||
|     pass | ||||
| 
 | ||||
| def tamper(payload, **kwargs): | ||||
|     """ | ||||
|     Replaces instances of <int> UNION with <int>e0UNION | ||||
| 
 | ||||
|     Requirement: | ||||
|         * MySQL | ||||
|         * MsSQL | ||||
| 
 | ||||
|     Notes: | ||||
|         * Reference: https://media.blackhat.com/us-13/US-13-Salgado-SQLi-Optimization-and-Obfuscation-Techniques-Slides.pdf | ||||
| 
 | ||||
|     >>> tamper('1 UNION ALL SELECT') | ||||
|     '1e0UNION ALL SELECT' | ||||
|     """ | ||||
| 
 | ||||
|     return re.sub("(\d+)\s+(UNION )", r"\g<1>e0\g<2>", payload, re.I) if payload else payload | ||||
							
								
								
									
										31
									
								
								tamper/dunion.py
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										31
									
								
								tamper/dunion.py
									
									
									
									
									
										Normal file
									
								
							|  | @ -0,0 +1,31 @@ | |||
| #!/usr/bin/env python | ||||
| 
 | ||||
| """ | ||||
| Copyright (c) 2006-2020 sqlmap developers (http://sqlmap.org/) | ||||
| See the file 'LICENSE' for copying permission | ||||
| """ | ||||
| 
 | ||||
| import re | ||||
| 
 | ||||
| from lib.core.enums import PRIORITY | ||||
| 
 | ||||
| __priority__ = PRIORITY.HIGHEST | ||||
| 
 | ||||
| def dependencies(): | ||||
|     pass | ||||
| 
 | ||||
| def tamper(payload, **kwargs): | ||||
|     """ | ||||
|     Replaces instances of <int> UNION with <int>DUNION | ||||
| 
 | ||||
|     Requirement: | ||||
|         * Oracle | ||||
| 
 | ||||
|     Notes: | ||||
|         * Reference: https://media.blackhat.com/us-13/US-13-Salgado-SQLi-Optimization-and-Obfuscation-Techniques-Slides.pdf | ||||
| 
 | ||||
|     >>> tamper('1 UNION ALL SELECT') | ||||
|     '1DUNION ALL SELECT' | ||||
|     """ | ||||
| 
 | ||||
|     return re.sub("(\d+)\s+(UNION )", r"\g<1>D\g<2>", payload, re.I) if payload else payload | ||||
							
								
								
									
										31
									
								
								tamper/schemasplit.py
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										31
									
								
								tamper/schemasplit.py
									
									
									
									
									
										Normal file
									
								
							|  | @ -0,0 +1,31 @@ | |||
| #!/usr/bin/env python | ||||
| 
 | ||||
| """ | ||||
| Copyright (c) 2006-2020 sqlmap developers (http://sqlmap.org/) | ||||
| See the file 'LICENSE' for copying permission | ||||
| """ | ||||
| 
 | ||||
| import re | ||||
| 
 | ||||
| from lib.core.enums import PRIORITY | ||||
| 
 | ||||
| __priority__ = PRIORITY.HIGHEST | ||||
| 
 | ||||
| def dependencies(): | ||||
|     pass | ||||
| 
 | ||||
| def tamper(payload, **kwargs): | ||||
|     """ | ||||
|     Replaces instances of <int> UNION with <int>e0UNION | ||||
| 
 | ||||
|     Requirement: | ||||
|         * MySQL | ||||
| 
 | ||||
|     Notes: | ||||
|         * Reference: https://media.blackhat.com/us-13/US-13-Salgado-SQLi-Optimization-and-Obfuscation-Techniques-Slides.pdf | ||||
| 
 | ||||
|     >>> tamper('SELECT id FROM testdb.users') | ||||
|     'SELECT id FROM testdb 9.e.users' | ||||
|     """ | ||||
| 
 | ||||
|     return re.sub("( FROM \w+)\.(\w+)", r"\g<1> 9.e.\g<2>", payload, re.I) if payload else payload | ||||
		Loading…
	
		Reference in New Issue
	
	Block a user