Major bug fix: --os-shell web backdoor functionality is now fixed (was broken since changeset r859).

This commit is contained in:
Bernardo Damele 2010-01-04 10:47:09 +00:00
parent 96a033b51d
commit 236ca9b952

View File

@ -169,7 +169,7 @@ class Takeover(Abstraction, Metasploit, Registry):
requestDir = os.path.normpath(directory.replace(kb.docRoot, "/").replace("\\", "/"))
baseUrl = "%s://%s:%d%s" % (conf.scheme, conf.hostname, conf.port, requestDir)
uploaderUrl = "%s/%s" % (baseUrl, uploaderName)
uploaderUrl = uploaderUrl.replace("./", "/").replace("\\", "/").replace("//", "/")
uploaderUrl = uploaderUrl.replace("./", "/").replace("\\", "/")
uplPage, _ = Request.getPage(url=uploaderUrl, direct=True)
if "sqlmap backdoor uploader" not in uplPage: