minor update

This commit is contained in:
Miroslav Stampar 2010-11-16 10:52:49 +00:00
parent 6ef3846400
commit 6232397129
2 changed files with 8 additions and 7 deletions

View File

@ -130,14 +130,14 @@ def heuristicCheckSqlInjection(place, parameter, value):
Request.queryPage(payload, place, raise404=False) Request.queryPage(payload, place, raise404=False)
result = wasLastRequestDBMSError() result = wasLastRequestDBMSError()
infoMsg = "(error based) heuristics shows that %s " % place infoMsg = "heuristics shows that %s " % place
infoMsg += "parameter '%s' is " % parameter infoMsg += "parameter '%s' might " % parameter
if result: if result:
infoMsg += "injectable (possible DBMS: %s)" % (kb.htmlFp[-1] if kb.htmlFp else 'Unknown') infoMsg += "be injectable (possible DBMS: %s)" % (kb.htmlFp[-1] if kb.htmlFp else 'Unknown')
logger.info(infoMsg) logger.info(infoMsg)
else: else:
infoMsg += "not injectable" infoMsg += "not be injectable"
logger.warning(infoMsg) logger.warning(infoMsg)
def checkDynParam(place, parameter, value): def checkDynParam(place, parameter, value):

View File

@ -220,9 +220,10 @@ class Connect:
responseHeaders = conn.info() responseHeaders = conn.info()
page = decodePage(page, responseHeaders.get("Content-Encoding"), responseHeaders.get("Content-Type")) page = decodePage(page, responseHeaders.get("Content-Encoding"), responseHeaders.get("Content-Type"))
msg = extractErrorMessage(page) if conf.parseErrors:
if msg and conf.parseErrors: msg = extractErrorMessage(page)
logger.error("error message: '%s'" % msg) if msg:
logger.info("parsed error message: '%s'" % msg)
except urllib2.HTTPError, e: except urllib2.HTTPError, e:
code = e.code code = e.code