mirror of
				https://github.com/sqlmapproject/sqlmap.git
				synced 2025-10-30 23:47:45 +03:00 
			
		
		
		
	New tamper script
This commit is contained in:
		
							parent
							
								
									537f39edd8
								
							
						
					
					
						commit
						2642e453b5
					
				
							
								
								
									
										37
									
								
								tamper/commalessmid.py
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										37
									
								
								tamper/commalessmid.py
									
									
									
									
									
										Normal file
									
								
							|  | @ -0,0 +1,37 @@ | |||
| #!/usr/bin/env python | ||||
| 
 | ||||
| """ | ||||
| Copyright (c) 2006-2015 sqlmap developers (http://sqlmap.org/) | ||||
| See the file 'doc/COPYING' for copying permission | ||||
| """ | ||||
| 
 | ||||
| import re | ||||
| 
 | ||||
| from lib.core.enums import PRIORITY | ||||
| 
 | ||||
| __priority__ = PRIORITY.HIGH | ||||
| 
 | ||||
| def dependencies(): | ||||
|     pass | ||||
| 
 | ||||
| def tamper(payload, **kwargs): | ||||
|     """ | ||||
|     Replaces instances like 'MID(A, B, C)' with 'MID(A FROM B FOR C)' | ||||
| 
 | ||||
|     Requirement: | ||||
|         * MySQL | ||||
| 
 | ||||
|     Tested against: | ||||
|         * MySQL 5.0 and 5.5 | ||||
| 
 | ||||
|     >>> tamper('MID(VERSION(), 1, 1)') | ||||
|     'MID(VERSION() FROM 1 FOR 1)' | ||||
|     """ | ||||
| 
 | ||||
|     retVal = payload | ||||
| 
 | ||||
|     match = re.search(r"(?i)MID\(([^,]+?)\s*,\s*(\d+)\s*\,\s*(\d+)\s*\)", payload or "") | ||||
|     if match: | ||||
|         retVal = retVal.replace(match.group(0), "MID(%s FROM %s FOR %s)" % (match.group(1), match.group(2), match.group(3))) | ||||
| 
 | ||||
|     return retVal | ||||
		Loading…
	
		Reference in New Issue
	
	Block a user