mirror of
https://github.com/sqlmapproject/sqlmap.git
synced 2025-01-24 08:14:24 +03:00
fixed test cases now that MySQL test db has two more tables and removed old test cases, soon to be replaced with new ones for other DBMSes
This commit is contained in:
parent
9149d77cc8
commit
5ceadf02ae
|
@ -44,7 +44,7 @@
|
|||
<item value="r'database management system users privileges:.+debian-sys-maint.+\(administrator\).+root.+\(administrator\).+privilege: SUPER'"/>
|
||||
<item value="r'database management system users roles:.+debian-sys-maint.+\[.+root.+\[.+role: SUPER'"/>
|
||||
<item value="r'available databases \[.+information_schema.+mysql.+owasp10.+testdb'"/>
|
||||
<item value="r'Database: testdb.+1 table.+users'"/>
|
||||
<item value="r'Database: testdb.+3 tables.+users'"/>
|
||||
<item value="r'Database: testdb.+Table: users.+3 columns.+surname.+varchar\(1000\)'"/>
|
||||
<item value="r'Database: testdb.+Table.+Entries.+users.+5'"/>
|
||||
<item value="r'Database: testdb.+Table: users.+5 entries.+luther.+nameisnull.+'"/>
|
||||
|
@ -87,7 +87,7 @@
|
|||
<item value="r'database management system users privileges:.+debian-sys-maint.+\(administrator\).+root.+\(administrator\).+privilege: SUPER'"/>
|
||||
<item value="r'database management system users roles:.+debian-sys-maint.+\[.+root.+\[.+role: SUPER'"/>
|
||||
<item value="r'available databases \[.+information_schema.+mysql.+owasp10.+testdb'"/>
|
||||
<item value="r'Database: testdb.+1 table.+users'"/>
|
||||
<item value="r'Database: testdb.+3 tables.+users'"/>
|
||||
<item value="r'Database: testdb.+Table: users.+3 columns.+surname.+varchar\(1000\)'"/>
|
||||
<item value="r'Database: testdb.+Table.+Entries.+users.+5'"/>
|
||||
<item value="r'Database: testdb.+Table: users.+5 entries.+luther.+nameisnull.+'"/>
|
||||
|
@ -130,7 +130,7 @@
|
|||
<item value="r'database management system users privileges:.+debian-sys-maint.+\(administrator\).+root.+\(administrator\).+privilege: SUPER'"/>
|
||||
<item value="r'database management system users roles:.+debian-sys-maint.+\[.+root.+\[.+role: SUPER'"/>
|
||||
<item value="r'available databases \[.+information_schema.+mysql.+owasp10.+testdb'"/>
|
||||
<item value="r'Database: testdb.+1 table.+users'"/>
|
||||
<item value="r'Database: testdb.+3 tables.+users'"/>
|
||||
<item value="r'Database: testdb.+Table: users.+3 columns.+surname.+varchar\(1000\)'"/>
|
||||
<item value="r'Database: testdb.+Table.+Entries.+users.+5'"/>
|
||||
<item value="r'Database: testdb.+Table: users.+5 entries.+luther.+nameisnull.+'"/>
|
||||
|
@ -173,7 +173,7 @@
|
|||
<item value="r'database management system users privileges:.+debian-sys-maint.+\(administrator\).+root.+\(administrator\).+privilege: SUPER'"/>
|
||||
<item value="r'database management system users roles:.+debian-sys-maint.+\[.+root.+\[.+role: SUPER'"/>
|
||||
<item value="r'available databases \[.+information_schema.+mysql.+owasp10.+testdb'"/>
|
||||
<item value="r'Database: testdb.+1 table.+users'"/>
|
||||
<item value="r'Database: testdb.+3 tables.+users'"/>
|
||||
<item value="r'Database: testdb.+Table: users.+3 columns.+surname.+varchar\(1000\)'"/>
|
||||
<item value="r'Database: testdb.+Table.+Entries.+users.+5'"/>
|
||||
<item value="r'Database: testdb.+Table: users.+5 entries.+luther.+nameisnull.+'"/>
|
||||
|
@ -216,7 +216,7 @@
|
|||
<item value="r'database management system users privileges:.+debian-sys-maint.+\(administrator\).+root.+\(administrator\).+privilege: SUPER'"/>
|
||||
<item value="r'database management system users roles:.+debian-sys-maint.+\[.+root.+\[.+role: SUPER'"/>
|
||||
<item value="r'available databases \[.+information_schema.+mysql.+owasp10.+testdb'"/>
|
||||
<item value="r'Database: testdb.+1 table.+users'"/>
|
||||
<item value="r'Database: testdb.+3 tables.+users'"/>
|
||||
<item value="r'Database: testdb.+Table: users.+3 columns.+surname.+varchar\(1000\)'"/>
|
||||
<item value="r'Database: testdb.+Table.+Entries.+users.+5'"/>
|
||||
<item value="r'Database: testdb.+Table: users.+5 entries.+luther.+nameisnull.+'"/>
|
||||
|
@ -259,7 +259,7 @@
|
|||
<item value="r'database management system users privileges:.+debian-sys-maint.+\(administrator\).+root.+\(administrator\).+privilege: SUPER'"/>
|
||||
<item value="r'database management system users roles:.+debian-sys-maint.+\[.+root.+\[.+role: SUPER'"/>
|
||||
<item value="r'available databases \[.+information_schema.+mysql.+owasp10.+testdb'"/>
|
||||
<item value="r'Database: testdb.+1 table.+users'"/>
|
||||
<item value="r'Database: testdb.+3 tables.+users'"/>
|
||||
<item value="r'Database: testdb.+Table: users.+3 columns.+surname.+varchar\(1000\)'"/>
|
||||
<item value="r'Database: testdb.+Table.+Entries.+users.+5'"/>
|
||||
<item value="r'Database: testdb.+Table: users.+5 entries.+luther.+nameisnull.+'"/>
|
||||
|
@ -369,7 +369,7 @@
|
|||
<tbl value="a,e,i"/>
|
||||
</switches>
|
||||
<parse>
|
||||
<item value="r'Database: testdb.+1 table.+users'"/>
|
||||
<item value="r'Database: testdb.+3 tables.+users'"/>
|
||||
<item value="r'.+5 entries.+wu.+nameisnull'"/>
|
||||
</parse>
|
||||
</case>
|
||||
|
@ -383,7 +383,7 @@
|
|||
<tbl value="a,e,i"/>
|
||||
</switches>
|
||||
<parse>
|
||||
<item value="r'Database: testdb.+1 table.+users'"/>
|
||||
<item value="r'Database: testdb.+3 tables.+users'"/>
|
||||
<item value="r'.+5 entries.+wu.+nameisnull'"/>
|
||||
</parse>
|
||||
</case>
|
||||
|
@ -397,7 +397,7 @@
|
|||
<tbl value="a,e,i"/>
|
||||
</switches>
|
||||
<parse>
|
||||
<item value="r'Database: testdb.+1 table.+users'"/>
|
||||
<item value="r'Database: testdb.+3 tables.+users'"/>
|
||||
<item value="r'.+5 entries.+wu.+nameisnull'"/>
|
||||
</parse>
|
||||
</case>
|
||||
|
@ -411,7 +411,7 @@
|
|||
<answers value="do you want to dump=N"/>
|
||||
</switches>
|
||||
<parse>
|
||||
<item value="r'Database: testdb.+1 table.+users.+Database: mysql.+1 table.+user '"/>
|
||||
<item value="r'Database: testdb.+3 tables.+users.+Database: mysql.+1 table.+user '"/>
|
||||
</parse>
|
||||
</case>
|
||||
<case name="MySQL error-based multi-threaded search enumeration - tables without given database">
|
||||
|
@ -424,7 +424,7 @@
|
|||
<answers value="do you want to dump=N"/>
|
||||
</switches>
|
||||
<parse>
|
||||
<item value="r'Database: testdb.+1 table.+users.+Database: mysql.+1 table.+user '"/>
|
||||
<item value="r'Database: testdb.+3 tables.+users.+Database: mysql.+1 table.+user '"/>
|
||||
</parse>
|
||||
</case>
|
||||
<case name="MySQL UNION query multi-threaded search enumeration - tables without given database">
|
||||
|
@ -437,7 +437,7 @@
|
|||
<answers value="do you want to dump=N"/>
|
||||
</switches>
|
||||
<parse>
|
||||
<item value="r'Database: testdb.+1 table.+users.+Database: mysql.+1 table.+user '"/>
|
||||
<item value="r'Database: testdb.+3 tables.+users.+Database: mysql.+1 table.+user '"/>
|
||||
</parse>
|
||||
</case>
|
||||
<case name="MySQL boolean-based multi-threaded search enumeration - column without given db or table">
|
||||
|
@ -654,399 +654,4 @@
|
|||
</parse>
|
||||
</case>
|
||||
<!-- End of user's provided statement enumeration switches -->
|
||||
|
||||
<!-- Old test cases -->
|
||||
<case name="MySQL (--technique=E --is-dba --banner --current-user --current-db --dbs --tables -D testdb -T users --columns --dump)">
|
||||
<switches>
|
||||
<url value="http://debiandev/sqlmap/mysql/get_int.php?id=1"/>
|
||||
<isDba value="True"/>
|
||||
<tech value="E"/>
|
||||
<getBanner value="True"/>
|
||||
<getCurrentUser value="True"/>
|
||||
<getCurrentDb value="True"/>
|
||||
<getDbs value="True"/>
|
||||
<getTables value="True"/>
|
||||
<db value="testdb"/>
|
||||
<tbl value="users"/>
|
||||
<getColumns value="True"/>
|
||||
<dumpTable value="True"/>
|
||||
</switches>
|
||||
<parse>
|
||||
<item value="current user is DBA: True"/>
|
||||
<item value="banner: '5.1.63-0+squeeze2'"/>
|
||||
<item value="current user: 'root@localhost'"/>
|
||||
<item value="current database: 'testdb'"/>
|
||||
<item value="r'information_schema.+mysql.+owasp10.+testdb'"/>
|
||||
<item value="r'1 table.+users'"/>
|
||||
<item value="r'3 columns.+surname.+varchar\(1000\)'"/>
|
||||
<item value="r'5 entries.+nameisnull.+'"/>
|
||||
</parse>
|
||||
</case>
|
||||
<case name="MySQL (--technique=U --is-dba --banner --current-user --current-db --dbs --tables -D testdb -T users --columns --dump)">
|
||||
<switches>
|
||||
<url value="http://debiandev/sqlmap/mysql/get_int.php?id=1"/>
|
||||
<isDba value="True"/>
|
||||
<tech value="U"/>
|
||||
<getBanner value="True"/>
|
||||
<getCurrentUser value="True"/>
|
||||
<getCurrentDb value="True"/>
|
||||
<getDbs value="True"/>
|
||||
<getTables value="True"/>
|
||||
<db value="testdb"/>
|
||||
<tbl value="users"/>
|
||||
<getColumns value="True"/>
|
||||
<dumpTable value="True"/>
|
||||
</switches>
|
||||
<parse>
|
||||
<item value="current user is DBA: True"/>
|
||||
<item value="banner: '5.1.63-0+squeeze1'"/>
|
||||
<item value="current user: 'root@localhost'"/>
|
||||
<item value="current database: 'testdb'"/>
|
||||
<item value="r'information_schema.+mysql.+owasp10.+testdb'"/>
|
||||
<item value="r'1 table.+users'"/>
|
||||
<item value="r'3 columns.+surname.+varchar\(1000\)'"/>
|
||||
<item value="r'5 entries.+nameisnull.+'"/>
|
||||
</parse>
|
||||
</case>
|
||||
<case name="MySQL partial union (--technique=U --is-dba --banner --current-user --current-db --dbs --tables -D testdb -T users --columns --dump)">
|
||||
<switches>
|
||||
<url value="http://debiandev/sqlmap/mysql/get_int_partialunion.php?id=1"/>
|
||||
<isDba value="True"/>
|
||||
<tech value="U"/>
|
||||
<getBanner value="True"/>
|
||||
<getCurrentUser value="True"/>
|
||||
<getCurrentDb value="True"/>
|
||||
<getDbs value="True"/>
|
||||
<getTables value="True"/>
|
||||
<db value="testdb"/>
|
||||
<tbl value="users"/>
|
||||
<getColumns value="True"/>
|
||||
<dumpTable value="True"/>
|
||||
</switches>
|
||||
<parse>
|
||||
<item value="current user is DBA: True"/>
|
||||
<item value="banner: '5.1.63-0+squeeze1'"/>
|
||||
<item value="current user: 'root@localhost'"/>
|
||||
<item value="current database: 'testdb'"/>
|
||||
<item value="r'information_schema.+mysql.+owasp10.+testdb'"/>
|
||||
<item value="r'1 table.+users'"/>
|
||||
<item value="r'3 columns.+surname.+varchar\(1000\)'"/>
|
||||
<item value="r'5 entries.+nameisnull.+'"/>
|
||||
</parse>
|
||||
</case>
|
||||
<case name="Postgres (--technique=B --is-dba --banner --current-user --current-db --dbs --tables -D testdb -T users --columns --dump --threads=4)">
|
||||
<switches>
|
||||
<url value="http://debiandev/sqlmap/pgsql/get_int.php?id=1"/>
|
||||
<isDba value="True"/>
|
||||
<tech value="B"/>
|
||||
<getBanner value="True"/>
|
||||
<getCurrentUser value="True"/>
|
||||
<getCurrentDb value="True"/>
|
||||
<getDbs value="True"/>
|
||||
<getTables value="True"/>
|
||||
<db value="testdb"/>
|
||||
<tbl value="users"/>
|
||||
<getColumns value="True"/>
|
||||
<dumpTable value="True"/>
|
||||
<threads value="4"/>
|
||||
</switches>
|
||||
<parse>
|
||||
<item value="current user is DBA: True"/>
|
||||
<item value="PostgreSQL 8.3.9 on i486-pc-linux-gnu, compiled by GCC gcc-4.3.real (Debian 4.3.2-1.1) 4.3.2"/>
|
||||
<item value="current user: 'testuser'"/>
|
||||
<item value="current database: 'testdb'"/>
|
||||
<item value="r'postgres.+template0.+template1.+testdb'"/>
|
||||
<item value="r'1 table.+users'"/>
|
||||
<item value="r'3 columns.+username.+bpchar'"/>
|
||||
<item value="r'4 entries.+nameisnull'"/>
|
||||
</parse>
|
||||
</case>
|
||||
<case name="Postgres (--technique=E --is-dba --banner --current-user --current-db --dbs --tables -D testdb -T users --columns --dump)">
|
||||
<switches>
|
||||
<url value="http://debiandev/sqlmap/pgsql/get_int.php?id=1"/>
|
||||
<isDba value="True"/>
|
||||
<tech value="E"/>
|
||||
<getBanner value="True"/>
|
||||
<getCurrentUser value="True"/>
|
||||
<getCurrentDb value="True"/>
|
||||
<getDbs value="True"/>
|
||||
<getTables value="True"/>
|
||||
<db value="testdb"/>
|
||||
<tbl value="users"/>
|
||||
<getColumns value="True"/>
|
||||
<dumpTable value="True"/>
|
||||
</switches>
|
||||
<parse>
|
||||
<item value="current user is DBA: True"/>
|
||||
<item value="PostgreSQL 8.3.9 on i486-pc-linux-gnu, compiled by GCC gcc-4.3.real (Debian 4.3.2-1.1) 4.3.2"/>
|
||||
<item value="current user: 'testuser'"/>
|
||||
<item value="current database: 'testdb'"/>
|
||||
<item value="r'postgres.+template0.+template1.+testdb'"/>
|
||||
<item value="r'1 table.+users'"/>
|
||||
<item value="r'3 columns.+username.+bpchar'"/>
|
||||
<item value="r'4 entries.+nameisnull'"/>
|
||||
</parse>
|
||||
</case>
|
||||
<case name="Postgres (--technique=U --is-dba --banner --current-user --current-db --dbs --tables -D testdb -T users --columns --dump)">
|
||||
<switches>
|
||||
<url value="http://debiandev/sqlmap/pgsql/get_int.php?id=1"/>
|
||||
<isDba value="True"/>
|
||||
<tech value="U"/>
|
||||
<getBanner value="True"/>
|
||||
<getCurrentUser value="True"/>
|
||||
<getCurrentDb value="True"/>
|
||||
<getDbs value="True"/>
|
||||
<getTables value="True"/>
|
||||
<db value="testdb"/>
|
||||
<tbl value="users"/>
|
||||
<getColumns value="True"/>
|
||||
<dumpTable value="True"/>
|
||||
</switches>
|
||||
<parse>
|
||||
<item value="current user is DBA: True"/>
|
||||
<item value="PostgreSQL 8.3.9 on i486-pc-linux-gnu, compiled by GCC gcc-4.3.real (Debian 4.3.2-1.1) 4.3.2"/>
|
||||
<item value="current user: 'testuser'"/>
|
||||
<item value="current database: 'testdb'"/>
|
||||
<item value="r'postgres.+template0.+template1.+testdb'"/>
|
||||
<item value="r'1 table.+users'"/>
|
||||
<item value="r'3 columns.+username.+bpchar'"/>
|
||||
<item value="r'4 entries.+nameisnull'"/>
|
||||
</parse>
|
||||
</case>
|
||||
<case name="Postgres partial union (--technique=U --is-dba --banner --current-user --current-db --dbs --tables -D testdb -T users --columns --dump)">
|
||||
<switches>
|
||||
<url value="http://debiandev/sqlmap/pgsql/get_int_partialunion.php?id=1"/>
|
||||
<isDba value="True"/>
|
||||
<tech value="U"/>
|
||||
<getBanner value="True"/>
|
||||
<getCurrentUser value="True"/>
|
||||
<getCurrentDb value="True"/>
|
||||
<getDbs value="True"/>
|
||||
<getTables value="True"/>
|
||||
<db value="testdb"/>
|
||||
<tbl value="users"/>
|
||||
<getColumns value="True"/>
|
||||
<dumpTable value="True"/>
|
||||
</switches>
|
||||
<parse>
|
||||
<item value="current user is DBA: True"/>
|
||||
<item value="PostgreSQL 8.3.9 on i486-pc-linux-gnu, compiled by GCC gcc-4.3.real (Debian 4.3.2-1.1) 4.3.2"/>
|
||||
<item value="current user: 'testuser'"/>
|
||||
<item value="current database: 'testdb'"/>
|
||||
<item value="r'postgres.+template0.+template1.+testdb'"/>
|
||||
<item value="r'1 table.+users'"/>
|
||||
<item value="r'3 columns.+username.+bpchar'"/>
|
||||
<item value="r'4 entries.+nameisnull'"/>
|
||||
</parse>
|
||||
</case>
|
||||
<case name="Oracle (--technique=B --is-dba --banner --current-user --current-db --dbs --tables -D SCOTT -T users --columns --dump --threads=4)">
|
||||
<switches>
|
||||
<url value="http://debiandev/sqlmap/oracle/get_int.php?id=1"/>
|
||||
<isDba value="True"/>
|
||||
<tech value="B"/>
|
||||
<getBanner value="True"/>
|
||||
<getCurrentUser value="True"/>
|
||||
<getCurrentDb value="True"/>
|
||||
<getDbs value="True"/>
|
||||
<getTables value="True"/>
|
||||
<db value="SCOTT"/>
|
||||
<tbl value="users"/>
|
||||
<getColumns value="True"/>
|
||||
<dumpTable value="True"/>
|
||||
<threads value="4"/>
|
||||
</switches>
|
||||
<parse>
|
||||
<item value="current user is DBA: True"/>
|
||||
<item value="banner: 'Oracle Database 10g Enterprise Edition Release 10.2.0.1.0 - Prod'"/>
|
||||
<item value="current user: 'SYS'"/>
|
||||
<item value="'TESTDB.REGRESS.RDBMS.DEV.US.ORACLE.COM'"/>
|
||||
<item value="r'available databases.+15.+CTXSYS.+DBSNMP.+SCOTT.+SYS.+SYSMAN'"/>
|
||||
<item value="r'5 tables.+BONUS.+DEPT.+EMP.+SALGRADE.+USERS'"/>
|
||||
<item value="r'3 columns.+SURNAME.+VARCHAR'"/>
|
||||
<item value="r'4 entries.+nameisnull'"/>
|
||||
</parse>
|
||||
</case>
|
||||
<case name="Oracle (--technique=E --is-dba --banner --current-user --current-db --dbs --tables -D SCOTT -T users --columns --dump)">
|
||||
<switches>
|
||||
<url value="http://debiandev/sqlmap/oracle/get_int.php?id=1"/>
|
||||
<isDba value="True"/>
|
||||
<tech value="E"/>
|
||||
<getBanner value="True"/>
|
||||
<getCurrentUser value="True"/>
|
||||
<getCurrentDb value="True"/>
|
||||
<getDbs value="True"/>
|
||||
<getTables value="True"/>
|
||||
<db value="SCOTT"/>
|
||||
<tbl value="users"/>
|
||||
<getColumns value="True"/>
|
||||
<dumpTable value="True"/>
|
||||
</switches>
|
||||
<parse>
|
||||
<item value="current user is DBA: True"/>
|
||||
<item value="banner: 'Oracle Database 10g Enterprise Edition Release 10.2.0.1.0 - Prod'"/>
|
||||
<item value="current user: 'SYS'"/>
|
||||
<item value="'TESTDB.REGRESS.RDBMS.DEV.US.ORACLE.COM'"/>
|
||||
<item value="r'available databases.+15.+CTXSYS.+DBSNMP.+SCOTT.+SYS.+SYSMAN'"/>
|
||||
<item value="r'5 tables.+BONUS.+DEPT.+EMP.+SALGRADE.+USERS'"/>
|
||||
<item value="r'3 columns.+SURNAME.+VARCHAR'"/>
|
||||
<item value="r'4 entries.+nameisnull'"/>
|
||||
</parse>
|
||||
</case>
|
||||
<case name="Oracle (--technique=U --is-dba --banner --current-user --current-db --dbs --tables -D SCOTT -T users --columns --dump)">
|
||||
<switches>
|
||||
<url value="http://debiandev/sqlmap/oracle/get_int.php?id=1"/>
|
||||
<isDba value="True"/>
|
||||
<tech value="U"/>
|
||||
<getBanner value="True"/>
|
||||
<getCurrentUser value="True"/>
|
||||
<getCurrentDb value="True"/>
|
||||
<getDbs value="True"/>
|
||||
<getTables value="True"/>
|
||||
<db value="SCOTT"/>
|
||||
<tbl value="users"/>
|
||||
<getColumns value="True"/>
|
||||
<dumpTable value="True"/>
|
||||
</switches>
|
||||
<parse>
|
||||
<item value="current user is DBA: True"/>
|
||||
<item value="banner: 'Oracle Database 10g Enterprise Edition Release 10.2.0.1.0 - Prod'"/>
|
||||
<item value="current user: 'SYS'"/>
|
||||
<item value="'TESTDB.REGRESS.RDBMS.DEV.US.ORACLE.COM'"/>
|
||||
<item value="r'available databases.+15.+CTXSYS.+DBSNMP.+SCOTT.+SYS.+SYSMAN'"/>
|
||||
<item value="r'5 tables.+BONUS.+DEPT.+EMP.+SALGRADE.+USERS'"/>
|
||||
<item value="r'3 columns.+SURNAME.+VARCHAR'"/>
|
||||
<item value="r'4 entries.+nameisnull'"/>
|
||||
</parse>
|
||||
</case>
|
||||
<case name="Oracle partial union (--technique=U --is-dba --banner --current-user --current-db --dbs --tables -D SCOTT -T users --columns --dump)">
|
||||
<switches>
|
||||
<url value="http://debiandev/sqlmap/oracle/get_int_partialunion.php?id=1"/>
|
||||
<isDba value="True"/>
|
||||
<tech value="U"/>
|
||||
<getBanner value="True"/>
|
||||
<getCurrentUser value="True"/>
|
||||
<getCurrentDb value="True"/>
|
||||
<getDbs value="True"/>
|
||||
<getTables value="True"/>
|
||||
<db value="SCOTT"/>
|
||||
<tbl value="users"/>
|
||||
<getColumns value="True"/>
|
||||
<dumpTable value="True"/>
|
||||
</switches>
|
||||
<parse>
|
||||
<item value="current user is DBA: True"/>
|
||||
<item value="banner: 'Oracle Database 10g Enterprise Edition Release 10.2.0.1.0 - Prod'"/>
|
||||
<item value="current user: 'SYS'"/>
|
||||
<item value="'TESTDB.REGRESS.RDBMS.DEV.US.ORACLE.COM'"/>
|
||||
<item value="r'available databases.+15.+CTXSYS.+DBSNMP.+SCOTT.+SYS.+SYSMAN'"/>
|
||||
<item value="r'5 tables.+BONUS.+DEPT.+EMP.+SALGRADE.+USERS'"/>
|
||||
<item value="r'3 columns.+SURNAME.+VARCHAR'"/>
|
||||
<item value="r'4 entries.+nameisnull'"/>
|
||||
</parse>
|
||||
</case>
|
||||
<case name="MSSQL (--technique=B --is-dba --banner --current-user --current-db --dbs --tables -D testdb -T users --columns --dump --threads=4)">
|
||||
<switches>
|
||||
<url value="http://windowsdev/sqlmap/mssql/iis/get_int.asp?id=1"/>
|
||||
<isDba value="True"/>
|
||||
<tech value="B"/>
|
||||
<getBanner value="True"/>
|
||||
<getCurrentUser value="True"/>
|
||||
<getCurrentDb value="True"/>
|
||||
<getDbs value="True"/>
|
||||
<getTables value="True"/>
|
||||
<db value="testdb"/>
|
||||
<tbl value="users"/>
|
||||
<getColumns value="True"/>
|
||||
<dumpTable value="True"/>
|
||||
<threads value="4"/>
|
||||
</switches>
|
||||
<parse>
|
||||
<item value="current user is DBA: True"/>
|
||||
<item value="r'Microsoft SQL Server 2005.+Oct 14 2005 00:33:37'"/>
|
||||
<item value="current user: 'sa'"/>
|
||||
<item value="current database: 'testdb'"/>
|
||||
<item value="r'available databases.+5.+master.+model.+msdb.+tempdb.+testdb'"/>
|
||||
<item value="r'dbo\.sysdiagrams.+dbo\.users'"/>
|
||||
<item value="r'3 columns.+surname.+varchar'"/>
|
||||
<item value="r'5 entries.+nameisnull.+'"/>
|
||||
</parse>
|
||||
</case>
|
||||
<case name="MSSQL (--technique=E --is-dba --banner --current-user --current-db --dbs --tables -D testdb -T users --columns --dump)">
|
||||
<switches>
|
||||
<url value="http://windowsdev/sqlmap/mssql/iis/get_int.asp?id=1"/>
|
||||
<isDba value="True"/>
|
||||
<tech value="E"/>
|
||||
<getBanner value="True"/>
|
||||
<getCurrentUser value="True"/>
|
||||
<getCurrentDb value="True"/>
|
||||
<getDbs value="True"/>
|
||||
<getTables value="True"/>
|
||||
<db value="testdb"/>
|
||||
<tbl value="users"/>
|
||||
<getColumns value="True"/>
|
||||
<dumpTable value="True"/>
|
||||
</switches>
|
||||
<parse>
|
||||
<item value="current user is DBA: True"/>
|
||||
<item value="r'Microsoft SQL Server 2005.+Oct 14 2005 00:33:37'"/>
|
||||
<item value="current user: 'sa'"/>
|
||||
<item value="current database: 'testdb'"/>
|
||||
<item value="r'available databases.+5.+master.+model.+msdb.+tempdb.+testdb'"/>
|
||||
<item value="r'dbo\.sysdiagrams.+dbo\.users'"/>
|
||||
<item value="r'3 columns.+surname.+varchar'"/>
|
||||
<item value="r'5 entries.+nameisnull.+'"/>
|
||||
</parse>
|
||||
</case>
|
||||
<case name="MSSQL (--technique=U --is-dba --banner --current-user --current-db --dbs --tables -D testdb -T users --columns --dump)">
|
||||
<switches>
|
||||
<url value="http://windowsdev/sqlmap/mssql/iis/get_int.asp?id=1"/>
|
||||
<isDba value="True"/>
|
||||
<tech value="U"/>
|
||||
<getBanner value="True"/>
|
||||
<getCurrentUser value="True"/>
|
||||
<getCurrentDb value="True"/>
|
||||
<getDbs value="True"/>
|
||||
<getTables value="True"/>
|
||||
<db value="testdb"/>
|
||||
<tbl value="users"/>
|
||||
<getColumns value="True"/>
|
||||
<dumpTable value="True"/>
|
||||
</switches>
|
||||
<parse>
|
||||
<item value="current user is DBA: True"/>
|
||||
<item value="r'Microsoft SQL Server 2005.+Oct 14 2005 00:33:37'"/>
|
||||
<item value="current user: 'sa'"/>
|
||||
<item value="current database: 'testdb'"/>
|
||||
<item value="r'available databases.+5.+master.+model.+msdb.+tempdb.+testdb'"/>
|
||||
<item value="r'dbo\.sysdiagrams.+dbo\.users'"/>
|
||||
<item value="r'3 columns.+surname.+varchar'"/>
|
||||
<item value="r'5 entries.+nameisnull.+'"/>
|
||||
</parse>
|
||||
</case>
|
||||
<case name="MSSQL partial union (--technique=U --is-dba --banner --current-user --current-db --dbs --tables -D testdb -T users --columns --dump)">
|
||||
<switches>
|
||||
<url value="http://windowsdev/sqlmap/mssql/iis/get_int_partialunion.asp?id=1"/>
|
||||
<isDba value="True"/>
|
||||
<tech value="U"/>
|
||||
<getBanner value="True"/>
|
||||
<getCurrentUser value="True"/>
|
||||
<getCurrentDb value="True"/>
|
||||
<getDbs value="True"/>
|
||||
<getTables value="True"/>
|
||||
<db value="testdb"/>
|
||||
<tbl value="users"/>
|
||||
<getColumns value="True"/>
|
||||
<dumpTable value="True"/>
|
||||
</switches>
|
||||
<parse>
|
||||
<item value="current user is DBA: True"/>
|
||||
<item value="r'Microsoft SQL Server 2005.+Oct 14 2005 00:33:37'"/>
|
||||
<item value="current user: 'sa'"/>
|
||||
<item value="current database: 'testdb'"/>
|
||||
<item value="r'available databases.+5.+master.+model.+msdb.+tempdb.+testdb'"/>
|
||||
<item value="r'dbo\.sysdiagrams.+dbo\.users'"/>
|
||||
<item value="r'3 columns.+surname.+varchar'"/>
|
||||
<item value="r'5 entries.+nameisnull.+'"/>
|
||||
</parse>
|
||||
</case>
|
||||
</root>
|
||||
|
|
Loading…
Reference in New Issue
Block a user