From 33d987805d6d84f08c45ed285b6dcdab24213d9c Mon Sep 17 00:00:00 2001 From: Miroslav Stampar Date: Mon, 4 Apr 2011 08:11:11 +0000 Subject: [PATCH] minor revisit of encoding tampering scripts --- tamper/charencode.py | 4 ++-- tamper/charunicodeencode.py | 4 ++-- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/tamper/charencode.py b/tamper/charencode.py index 8f1390a60..ebf449fc1 100644 --- a/tamper/charencode.py +++ b/tamper/charencode.py @@ -16,8 +16,8 @@ __priority__ = PRIORITY.LOWEST def tamper(value): """ - Replaces value with urlencode of non-encoded chars in value - Example: 'SELECT%20FIELD%20FROM%20TABLE' becomes '%53%45%4c%45%43%54%20%46%49%45%4c%44%20%46%52%4f%4d%20%54%41%42%4c%45' + Urlencodes all characters in a given value (not processing already encoded) + Example: 'SELECT FIELD FROM%20TABLE' becomes '%53%45%4c%45%43%54%20%46%49%45%4c%44%20%46%52%4f%4d%20%54%41%42%4c%45' """ retVal = value diff --git a/tamper/charunicodeencode.py b/tamper/charunicodeencode.py index 9d3c11b2d..5c1d19662 100644 --- a/tamper/charunicodeencode.py +++ b/tamper/charunicodeencode.py @@ -16,8 +16,8 @@ __priority__ = PRIORITY.LOWEST def tamper(value): """ - Replaces value with unicode-urlencode of non-encoded chars in value - Example: 'SELECT%20FIELD%20FROM%20TABLE' becomes '%u0053%u0045%u004c%u0045%u0043%u0054%u0020%u0046%u0049%u0045%u004c%u0044%u0020%u0046%u0052%u004f%u004d%u0020%u0054%u0041%u0042%u004c%u0045' + Replaces value with unicode-urlencode of non-encoded chars in value (not processing already encoded) + Example: 'SELECT FIELD%20FROM TABLE' becomes '%u0053%u0045%u004c%u0045%u0043%u0054%u0020%u0046%u0049%u0045%u004c%u0044%u0020%u0046%u0052%u004f%u004d%u0020%u0054%u0041%u0042%u004c%u0045' """ retVal = value