FazBrowse GitHub Viewer
|
Trending
|
URL:
|
Home
Tools:
[Download Repo ZIP]
[View Raw Code]
[Original HTTPS Page]
sqlmap/plugins/generic/custom.py at master · PowerCod/sqlmap · GitHub
PowerCod
/
sqlmap
Public
forked from
sqlmapproject/sqlmap
Notifications
You must be signed in to change notification settings
Fork
0
Star
0
Code
Pull requests
0
Actions
Projects
Wiki
Security and quality
0
Insights
Additional navigation options
Code
Pull requests
Actions
Projects
Wiki
Security and quality
Insights
Expand file tree
Breadcrumbs
sqlmap
/
plugins
/
generic
/
custom.py
Copy path
More file actions
More file actions
Latest commit
History
History
History
128 lines (97 loc) · 3.75 KB
Breadcrumbs
sqlmap
/
plugins
/
generic
/
custom.py
Copy path
File metadata and controls
128 lines (97 loc) · 3.75 KB
Raw
Copy raw file
Download raw file
Open symbols panel
Edit and raw actions
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
#!/usr/bin/env python
"""
Copyright (c) 2006-2015 sqlmap developers (http://sqlmap.org/)
See the file 'doc/COPYING' for copying permission
"""
import
re
import
sys
from
lib
.
core
.
common
import
Backend
from
lib
.
core
.
common
import
dataToStdout
from
lib
.
core
.
common
import
getSQLSnippet
from
lib
.
core
.
common
import
getUnicode
from
lib
.
core
.
common
import
isStackingAvailable
from
lib
.
core
.
data
import
conf
from
lib
.
core
.
data
import
logger
from
lib
.
core
.
dicts
import
SQL_STATEMENTS
from
lib
.
core
.
enums
import
AUTOCOMPLETE_TYPE
from
lib
.
core
.
settings
import
NULL
from
lib
.
core
.
settings
import
PARAMETER_SPLITTING_REGEX
from
lib
.
core
.
shell
import
autoCompletion
from
lib
.
request
import
inject
class
Custom
:
"""
This class defines custom enumeration functionalities for plugins.
"""
def
__init__
(
self
):
pass
def
sqlQuery
(
self
,
query
):
output
=
None
sqlType
=
None
query
=
query
.
rstrip
(
';'
)
for
sqlTitle
,
sqlStatements
in
SQL_STATEMENTS
.
items
():
for
sqlStatement
in
sqlStatements
:
if
query
.
lower
().
startswith
(
sqlStatement
):
sqlType
=
sqlTitle
break
if
not
any
(
_
in
query
.
upper
()
for
_
in
(
"OPENROWSET"
,
"INTO"
))
and
(
not
sqlType
or
"SELECT"
in
sqlType
):
infoMsg
=
"fetching %s query output: '%s'"
%
(
sqlType
if
sqlType
is
not
None
else
"SQL"
,
query
)
logger
.
info
(
infoMsg
)
output
=
inject
.
getValue
(
query
,
fromUser
=
True
)
return
output
elif
not
isStackingAvailable
()
and
not
conf
.
direct
:
warnMsg
=
"execution of custom SQL queries is only "
warnMsg
+=
"available when stacked queries are supported"
logger
.
warn
(
warnMsg
)
return
None
else
:
if
sqlType
:
debugMsg
=
"executing %s query: '%s'"
%
(
sqlType
if
sqlType
is
not
None
else
"SQL"
,
query
)
else
:
debugMsg
=
"executing unknown SQL type query: '%s'"
%
query
logger
.
debug
(
debugMsg
)
inject
.
goStacked
(
query
)
debugMsg
=
"done"
logger
.
debug
(
debugMsg
)
output
=
NULL
return
output
def
sqlShell
(
self
):
infoMsg
=
"calling %s shell. To quit type "
%
Backend
.
getIdentifiedDbms
()
infoMsg
+=
"'x' or 'q' and press ENTER"
logger
.
info
(
infoMsg
)
autoCompletion
(
AUTOCOMPLETE_TYPE
.
SQL
)
while
True
:
query
=
None
try
:
query
=
raw_input
(
"sql-shell> "
)
query
=
getUnicode
(
query
,
encoding
=
sys
.
stdin
.
encoding
)
except
KeyboardInterrupt
:
print
errMsg
=
"user aborted"
logger
.
error
(
errMsg
)
except
EOFError
:
print
errMsg
=
"exit"
logger
.
error
(
errMsg
)
break
if
not
query
:
continue
if
query
.
lower
()
in
(
"x"
,
"q"
,
"exit"
,
"quit"
):
break
output
=
self
.
sqlQuery
(
query
)
if
output
and
output
!=
"Quit"
:
conf
.
dumper
.
query
(
query
,
output
)
elif
not
output
:
pass
elif
output
!=
"Quit"
:
dataToStdout
(
"No output
\n
"
)
def
sqlFile
(
self
):
infoMsg
=
"executing SQL statements from given file(s)"
logger
.
info
(
infoMsg
)
for
sfile
in
re
.
split
(
PARAMETER_SPLITTING_REGEX
,
conf
.
sqlFile
):
sfile
=
sfile
.
strip
()
if
not
sfile
:
continue
query
=
getSQLSnippet
(
Backend
.
getDbms
(),
sfile
)
infoMsg
=
"executing SQL statement%s from file '%s'"
%
(
"s"
if
";"
in
query
else
""
,
sfile
)
logger
.
info
(
infoMsg
)
conf
.
dumper
.
query
(
query
,
self
.
sqlQuery
(
query
))
Back
|
FazBrowse Home
|
New Git URL