trust me, i know what i am doing :)

This commit is contained in:
Miroslav Stampar 2010-11-07 20:33:33 +00:00
parent 73e85bfc75
commit 620fa1c8fb
2 changed files with 8 additions and 6 deletions

View File

@ -217,6 +217,8 @@ def start():
testSqlInj = True
paramKey = (conf.hostname, conf.path, place, parameter)
conf.matchRatio = None
if paramKey in kb.testedParams:
testSqlInj = False
@ -242,14 +244,14 @@ def start():
if testSqlInj:
heuristicCheckSqlInjection(place, parameter, value)
conf.matchRatio = None
for parenthesis in range(0, 4):
logMsg = "testing sql injection on %s " % place
logMsg += "parameter '%s' with " % parameter
logMsg += "%d parenthesis" % parenthesis
logger.info(logMsg)
conf.matchRatio = None
injType = checkSqlInjection(place, parameter, value, parenthesis)
if injType:

View File

@ -20,6 +20,10 @@ def comparison(page, headers=None, getSeqMatcher=False, pageLength=None):
if page is None and pageLength is None:
return None
# In case of an DBMS error page return None
if wasLastRequestError():
return None
regExpResults = None
if page:
@ -105,10 +109,6 @@ def comparison(page, headers=None, getSeqMatcher=False, pageLength=None):
if getSeqMatcher:
return ratio
# In case of an DBMS error page return None
elif wasLastRequestError():
return None
elif ratio == 1:
return True