From 7f4acaf6f9c839f820f30c04aaaa5f2f24ea9488 Mon Sep 17 00:00:00 2001 From: Miroslav Stampar Date: Thu, 30 Dec 2010 21:24:26 +0000 Subject: [PATCH] now comment injection fingerprint works with all techniques --- plugins/dbms/mysql/fingerprint.py | 5 +---- 1 file changed, 1 insertion(+), 4 deletions(-) diff --git a/plugins/dbms/mysql/fingerprint.py b/plugins/dbms/mysql/fingerprint.py index 3f1c118fa..f1ae9c2cd 100644 --- a/plugins/dbms/mysql/fingerprint.py +++ b/plugins/dbms/mysql/fingerprint.py @@ -66,10 +66,7 @@ class Fingerprint(GenericFingerprint): for version in range(element[0], element[1] + 1): randInt = randomInt() version = getUnicode(version) - query = agent.prefixQuery("/*!%s AND %d=%d*/" % (version, randInt, randInt + 1)) - query = agent.suffixQuery(query) - payload = agent.payload(newValue=query) - result = Request.queryPage(payload) + result = inject.checkBooleanExpression("%d=%d/*!%s AND %d=%d*/" % (randInt, randInt, version, randInt, randInt + 1)) if result: if not prevVer: