mirror of
				https://github.com/sqlmapproject/sqlmap.git
				synced 2025-10-25 13:11:00 +03:00 
			
		
		
		
	Disabling ORDER BY tests in heavily dynamic environment
This commit is contained in:
		
							parent
							
								
									f0677d88b7
								
							
						
					
					
						commit
						cdb1e79370
					
				|  | @ -1168,6 +1168,8 @@ def checkDynamicContent(firstPage, secondPage): | |||
|             warnMsg += "sqlmap is going to retry the request(s)" | ||||
|             singleTimeLogMessage(warnMsg, logging.CRITICAL) | ||||
| 
 | ||||
|             kb.heavyDynamic = True | ||||
| 
 | ||||
|             secondPage, _, _ = Request.queryPage(content=True) | ||||
|             findDynamicContent(firstPage, secondPage) | ||||
| 
 | ||||
|  |  | |||
|  | @ -1945,6 +1945,7 @@ def _setKnowledgeBaseAttributes(flushAll=True): | |||
|     kb.forcePartialUnion = False | ||||
|     kb.forceWhere = None | ||||
|     kb.futileUnion = None | ||||
|     kb.heavyDynamic = False | ||||
|     kb.headersFp = {} | ||||
|     kb.heuristicDbms = None | ||||
|     kb.heuristicExtendedDbms = None | ||||
|  |  | |||
|  | @ -19,7 +19,7 @@ from lib.core.enums import DBMS_DIRECTORY_NAME | |||
| from lib.core.enums import OS | ||||
| 
 | ||||
| # sqlmap version (<major>.<minor>.<month>.<monthly commit>) | ||||
| VERSION = "1.2.3.48" | ||||
| VERSION = "1.2.3.49" | ||||
| TYPE = "dev" if VERSION.count('.') > 2 and VERSION.split('.')[-1] != '0' else "stable" | ||||
| TYPE_COLORS = {"dev": 33, "stable": 90, "pip": 34} | ||||
| VERSION_STRING = "sqlmap/%s#%s" % ('.'.join(VERSION.split('.')[:-1]) if VERSION.count('.') > 2 and VERSION.split('.')[-1] == '0' else VERSION, TYPE) | ||||
|  |  | |||
|  | @ -54,7 +54,7 @@ def _findUnionCharCount(comment, place, parameter, value, prefix, suffix, where= | |||
|             query = agent.suffixQuery(query, suffix=suffix, comment=comment) | ||||
|             payload = agent.payload(newValue=query, place=place, parameter=parameter, where=where) | ||||
|             page, headers, code = Request.queryPage(payload, place=place, content=True, raise404=False) | ||||
|             return not any(re.search(_, page or "", re.I) and not re.search(_, kb.pageTemplate or "", re.I) for _ in ("(warning|error):", "order by", "unknown column", "failed")) and comparison(page, headers, code) or re.search(r"data types cannot be compared or sorted", page or "", re.I) is not None | ||||
|             return not any(re.search(_, page or "", re.I) and not re.search(_, kb.pageTemplate or "", re.I) for _ in ("(warning|error):", "order by", "unknown column", "failed")) and not kb.heavyDynamic and comparison(page, headers, code) or re.search(r"data types cannot be compared or sorted", page or "", re.I) is not None | ||||
| 
 | ||||
|         if _orderByTest(1 if lowerCount is None else lowerCount) and not _orderByTest(randomInt() if upperCount is None else upperCount + 1): | ||||
|             infoMsg = "'ORDER BY' technique appears to be usable. " | ||||
|  |  | |||
|  | @ -21,7 +21,7 @@ c88d66597f4aab719bde4542b0a1a6e0  extra/shutils/regressiontest.py | |||
| 1e5532ede194ac9c083891c2f02bca93  extra/sqlharvest/__init__.py | ||||
| b3e60ea4e18a65c48515d04aab28ff68  extra/sqlharvest/sqlharvest.py | ||||
| 0f581182871148b0456a691ae85b04c0  lib/controller/action.py | ||||
| 0ee74789b09bb40e8f48baddefe21724  lib/controller/checks.py | ||||
| ebc0d5d4e3981c9c57197fa09e37aa91  lib/controller/checks.py | ||||
| 33689bb1b064d4eebc216934795a595f  lib/controller/controller.py | ||||
| c7443613a0a2505b1faec931cee2a6ef  lib/controller/handler.py | ||||
| 1e5532ede194ac9c083891c2f02bca93  lib/controller/__init__.py | ||||
|  | @ -40,13 +40,13 @@ cada93357a7321655927fc9625b3bfec  lib/core/exception.py | |||
| 1e5532ede194ac9c083891c2f02bca93  lib/core/__init__.py | ||||
| 458a194764805cd8312c14ecd4be4d1e  lib/core/log.py | ||||
| c9a56e58984420a5abb7a3f7aadc196d  lib/core/optiondict.py | ||||
| b7c3e98e5400d73e9ce5c1a30145f7c6  lib/core/option.py | ||||
| 8484e95c616b7a5220157c13e24fa1d6  lib/core/option.py | ||||
| 7cfd04e583cca782b843f6f6d973981a  lib/core/profiling.py | ||||
| ffa5f01f39b17c8d73423acca6cfe86a  lib/core/readlineng.py | ||||
| 0c3eef46bdbf87e29a3f95f90240d192  lib/core/replication.py | ||||
| a7db43859b61569b601b97f187dd31c5  lib/core/revision.py | ||||
| fcb74fcc9577523524659ec49e2e964b  lib/core/session.py | ||||
| f4f6c7e5f8265293270273b6415450eb  lib/core/settings.py | ||||
| b7dd1e5592efbbfd550047b53014543e  lib/core/settings.py | ||||
| 0dfc2ed40adf72e302291f6ecd4406f6  lib/core/shell.py | ||||
| a7edc9250d13af36ac0108f259859c19  lib/core/subprocessng.py | ||||
| a35efa7bec9f1e6cedf17c9830a79241  lib/core/target.py | ||||
|  | @ -96,7 +96,7 @@ fb9e34d558293b5d6b9727f440712886  lib/takeover/registry.py | |||
| f999f2e88dea9ac8831eb2f468478b5f  lib/techniques/error/use.py | ||||
| 1e5532ede194ac9c083891c2f02bca93  lib/techniques/__init__.py | ||||
| 1e5532ede194ac9c083891c2f02bca93  lib/techniques/union/__init__.py | ||||
| d35a42c4144b822debd82c2e66c1dd4d  lib/techniques/union/test.py | ||||
| 07882f244fc73e130ab1a17caa6f5fb0  lib/techniques/union/test.py | ||||
| 11ecf2effbe9f40b361843d546c3c521  lib/techniques/union/use.py | ||||
| c552f8d924d962a26f2ded250bcea3b8  lib/utils/api.py | ||||
| 37dfb641358669f62c2acedff241348b  lib/utils/brute.py | ||||
|  |  | |||
		Loading…
	
		Reference in New Issue
	
	Block a user