From c5197b99a07abdc3d3569976b9bf08c2cf7e346b Mon Sep 17 00:00:00 2001 From: Miroslav Stampar Date: Fri, 3 Jun 2016 13:59:32 +0200 Subject: [PATCH] Minor patch and minor improvement --- lib/controller/checks.py | 4 ++-- lib/core/settings.py | 2 +- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/lib/controller/checks.py b/lib/controller/checks.py index 0b19df9ec..43ab316d2 100644 --- a/lib/controller/checks.py +++ b/lib/controller/checks.py @@ -476,7 +476,7 @@ def checkSqlInjection(place, parameter, value): injectable = True - if not injectable and not any((conf.string, conf.notString, conf.regexp)) and kb.pageStable: + if not any((conf.string, conf.notString, conf.regexp)) and kb.pageStable: trueSet = set(extractTextTagContent(truePage)) trueSet = trueSet.union(__ for _ in trueSet for __ in _.split()) @@ -488,7 +488,7 @@ def checkSqlInjection(place, parameter, value): if candidates: candidates = sorted(candidates, key=lambda _: len(_)) for candidate in candidates: - if re.match(r"\A\w+\Z", candidate): + if re.match(r"\A\w+\Z", candidate) and candidate in truePage and candidate not in falsePage: break conf.string = candidate diff --git a/lib/core/settings.py b/lib/core/settings.py index 264a18a0c..efe33262d 100644 --- a/lib/core/settings.py +++ b/lib/core/settings.py @@ -19,7 +19,7 @@ from lib.core.enums import OS from lib.core.revision import getRevisionNumber # sqlmap version (...) -VERSION = "1.0.6.19" +VERSION = "1.0.6.20" REVISION = getRevisionNumber() STABLE = VERSION.count('.') <= 2 VERSION_STRING = "sqlmap/%s#%s" % (VERSION, "stable" if STABLE else "dev")