| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -157,6 +157,9 @@ Krzysztof Kotowicz <kkotowicz@gmail.com> | |||
| 157 | 157 | Nicolas Krassas <krasn@ans.gr> | |
| 158 | 158 | for reporting a bug | |
| 159 | 159 | ||
| 160 | + Alex Landa <landa.alex86@gmail.com> | ||
| 161 | + for providing a patch adding support for XML output | ||
| 162 | + | ||
| 160 | 163 | Guido Landi <lists@keamera.org> | |
| 161 | 164 | for reporting a couple of bugs | |
| 162 | 165 | for the great technical discussions | |
@@ -193,7 +196,7 @@ Enrico Milanese <enricomilanese@gmail.com> | |||
| 193 | 196 | for reporting a bugs when using (-a) a single line User-Agent file | |
| 194 | 197 | for providing me with some ideas for the PHP backdoor | |
| 195 | 198 | ||
| 196 | - Alejo Murillo <alex@65535.com> | ||
| 199 | + Alejo Murillo Moya <alex@65535.com> | ||
| 197 | 200 | for suggesting a feature | |
| 198 | 201 | ||
| 199 | 202 | Roberto Nemirovsky <roberto.paes@gmail.com> | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -26,7 +26,6 @@ | |||
| 26 | 26 | from lib.core.common import getHtmlErrorFp | |
| 27 | 27 | from lib.core.data import conf | |
| 28 | 28 | from lib.core.data import kb | |
| 29 | - from lib.core.dump import dumper | ||
| 30 | 29 | from lib.core.exception import sqlmapUnsupportedDBMSException | |
| 31 | 30 | from lib.core.settings import SUPPORTED_DBMS | |
| 32 | 31 | from lib.techniques.blind.timebased import timeTest | |
@@ -69,53 +68,53 @@ def action(): | |||
| 69 | 68 | ||
| 70 | 69 | # Techniques options | |
| 71 | 70 | if conf.stackedTest: | |
| 72 | - dumper.string("stacked queries support", stackedTest()) | ||
| 71 | + conf.dumper.technic("stacked queries support", stackedTest()) | ||
| 73 | 72 | ||
| 74 | 73 | if conf.timeTest: | |
| 75 | - dumper.string("time based blind sql injection payload", timeTest()) | ||
| 74 | + conf.dumper.technic("time based blind sql injection payload", timeTest()) | ||
| 76 | 75 | ||
| 77 | 76 | if ( conf.unionUse or conf.unionTest ) and not kb.unionPosition: | |
| 78 | - dumper.string("valid union", unionTest()) | ||
| 77 | + conf.dumper.technic("valid union", unionTest()) | ||
| 79 | 78 | ||
| 80 | 79 | # Enumeration options | |
| 81 | 80 | if conf.getBanner: | |
| 82 | - dumper.string("banner", conf.dbmsHandler.getBanner()) | ||
| 81 | + conf.dumper.banner(conf.dbmsHandler.getBanner()) | ||
| 83 | 82 | ||
| 84 | 83 | if conf.getCurrentUser: | |
| 85 | - dumper.string("current user", conf.dbmsHandler.getCurrentUser()) | ||
| 84 | + conf.dumper.currentUser(conf.dbmsHandler.getCurrentUser()) | ||
| 86 | 85 | ||
| 87 | 86 | if conf.getCurrentDb: | |
| 88 | - dumper.string("current database", conf.dbmsHandler.getCurrentDb()) | ||
| 87 | + conf.dumper.currentDb(conf.dbmsHandler.getCurrentDb()) | ||
| 89 | 88 | ||
| 90 | 89 | if conf.isDba: | |
| 91 | - dumper.string("current user is DBA", conf.dbmsHandler.isDba()) | ||
| 90 | + conf.dumper.dba(conf.dbmsHandler.isDba()) | ||
| 92 | 91 | ||
| 93 | 92 | if conf.getUsers: | |
| 94 | - dumper.lister("database management system users", conf.dbmsHandler.getUsers()) | ||
| 93 | + conf.dumper.users(conf.dbmsHandler.getUsers()) | ||
| 95 | 94 | ||
| 96 | 95 | if conf.getPasswordHashes: | |
| 97 | - dumper.userSettings("database management system users password hashes", | ||
| 98 | - conf.dbmsHandler.getPasswordHashes(), "password hash") | ||
| 96 | + conf.dumper.userSettings("database management system users password hashes", | ||
| 97 | + conf.dbmsHandler.getPasswordHashes(), "password hash") | ||
| 99 | 98 | ||
| 100 | 99 | if conf.getPrivileges: | |
| 101 | - dumper.userSettings("database management system users privileges", | ||
| 102 | - conf.dbmsHandler.getPrivileges(), "privilege") | ||
| 100 | + conf.dumper.userSettings("database management system users privileges", | ||
| 101 | + conf.dbmsHandler.getPrivileges(), "privilege") | ||
| 103 | 102 | ||
| 104 | 103 | if conf.getRoles: | |
| 105 | - dumper.userSettings("database management system users roles", | ||
| 106 | - conf.dbmsHandler.getRoles(), "role") | ||
| 104 | + conf.dumper.userSettings("database management system users roles", | ||
| 105 | + conf.dbmsHandler.getRoles(), "role") | ||
| 107 | 106 | ||
| 108 | 107 | if conf.getDbs: | |
| 109 | - dumper.lister("available databases", conf.dbmsHandler.getDbs()) | ||
| 108 | + conf.dumper.dbs(conf.dbmsHandler.getDbs()) | ||
| 110 | 109 | ||
| 111 | 110 | if conf.getTables: | |
| 112 | - dumper.dbTables(conf.dbmsHandler.getTables()) | ||
| 111 | + conf.dumper.dbTables(conf.dbmsHandler.getTables()) | ||
| 113 | 112 | ||
| 114 | 113 | if conf.getColumns: | |
| 115 | - dumper.dbTableColumns(conf.dbmsHandler.getColumns()) | ||
| 114 | + conf.dumper.dbTableColumns(conf.dbmsHandler.getColumns()) | ||
| 116 | 115 | ||
| 117 | 116 | if conf.dumpTable: | |
| 118 | - dumper.dbTableValues(conf.dbmsHandler.dumpTable()) | ||
| 117 | + conf.dumper.dbTableValues(conf.dbmsHandler.dumpTable()) | ||
| 119 | 118 | ||
| 120 | 119 | if conf.dumpAll: | |
| 121 | 120 | conf.dbmsHandler.dumpAll() | |
@@ -124,7 +123,7 @@ def action(): | |||
| 124 | 123 | conf.dbmsHandler.search() | |
| 125 | 124 | ||
| 126 | 125 | if conf.query: | |
| 127 | - dumper.string(conf.query, conf.dbmsHandler.sqlQuery(conf.query)) | ||
| 126 | + conf.dumper.query(conf.query, conf.dbmsHandler.sqlQuery(conf.query)) | ||
| 128 | 127 | ||
| 129 | 128 | if conf.sqlShell: | |
| 130 | 129 | conf.dbmsHandler.sqlShell() | |
@@ -135,7 +134,7 @@ def action(): | |||
| 135 | 134 | ||
| 136 | 135 | # File system options | |
| 137 | 136 | if conf.rFile: | |
| 138 | - dumper.string("%s file saved to" % conf.rFile, conf.dbmsHandler.readFile(conf.rFile), sort=False) | ||
| 137 | + conf.dumper.rFile(conf.rFile, conf.dbmsHandler.readFile(conf.rFile)) | ||
| 139 | 138 | ||
| 140 | 139 | if conf.wFile: | |
| 141 | 140 | conf.dbmsHandler.writeFile(conf.wFile, conf.dFile, conf.wFileType) | |
@@ -158,7 +157,7 @@ def action(): | |||
| 158 | 157 | ||
| 159 | 158 | # Windows registry options | |
| 160 | 159 | if conf.regRead: | |
| 161 | - dumper.string("Registry key value data", conf.dbmsHandler.regRead()) | ||
| 160 | + conf.dumper.registerValue(conf.dbmsHandler.regRead()) | ||
| 162 | 161 | ||
| 163 | 162 | if conf.regAdd: | |
| 164 | 163 | conf.dbmsHandler.regAdd() | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -40,7 +40,7 @@ class Dump: | |||
| 40 | 40 | def __init__(self): | |
| 41 | 41 | self.__outputFile = None | |
| 42 | 42 | self.__outputFP = None | |
| 43 | - | ||
| 43 | + | ||
| 44 | 44 | def __write(self, data, n=True): | |
| 45 | 45 | if n: | |
| 46 | 46 | print data | |
@@ -52,11 +52,19 @@ def __write(self, data, n=True): | |||
| 52 | 52 | self.__outputFP.flush() | |
| 53 | 53 | ||
| 54 | 54 | conf.loggedToOut = True | |
| 55 | - | ||
| 55 | + | ||
| 56 | + def __formatString(self, string): | ||
| 57 | + string = unicode(string) | ||
| 58 | + string = string.replace("__NEWLINE__", "\n").replace("__TAB__", "\t") | ||
| 59 | + string = string.replace("__START__", "").replace("__STOP__", "") | ||
| 60 | + string = string.replace("__DEL__", ", ") | ||
| 61 | + | ||
| 62 | + return string | ||
| 63 | + | ||
| 56 | 64 | def setOutputFile(self): | |
| 57 | 65 | self.__outputFile = "%s%slog" % (conf.outputPath, os.sep) | |
| 58 | - self.__outputFP = codecs.open(self.__outputFile, "a", conf.dataEncoding) | ||
| 59 | - | ||
| 66 | + self.__outputFP = codecs.open(self.__outputFile, "ab", conf.dataEncoding) | ||
| 67 | + | ||
| 60 | 68 | def string(self, header, data, sort=True): | |
| 61 | 69 | if isinstance(data, (list, tuple, set)): | |
| 62 | 70 | self.lister(header, data, sort) | |
@@ -66,9 +74,7 @@ def string(self, header, data, sort=True): | |||
| 66 | 74 | data = unicode(data) | |
| 67 | 75 | ||
| 68 | 76 | if data: | |
| 69 | - data = data.replace("__NEWLINE__", "\n").replace("__TAB__", "\t") | ||
| 70 | - data = data.replace("__START__", "").replace("__STOP__", "") | ||
| 71 | - data = data.replace("__DEL__", ", ") | ||
| 77 | + data = self.__formatString(data) | ||
| 72 | 78 | ||
| 73 | 79 | if "\n" in data: | |
| 74 | 80 | self.__write("%s:\n---\n%s\n---\n" % (header, data)) | |
@@ -97,7 +103,25 @@ def lister(self, header, elements, sort=True): | |||
| 97 | 103 | ||
| 98 | 104 | if elements: | |
| 99 | 105 | self.__write("") | |
| 100 | - | ||
| 106 | + | ||
| 107 | + def technic(self,header,data): | ||
| 108 | + self.string(header, data) | ||
| 109 | + | ||
| 110 | + def banner(self,data): | ||
| 111 | + self.string("banner", data) | ||
| 112 | + | ||
| 113 | + def currentUser(self,data): | ||
| 114 | + self.string("current user", data) | ||
| 115 | + | ||
| 116 | + def currentDb(self,data): | ||
| 117 | + self.string("current database", data) | ||
| 118 | + | ||
| 119 | + def dba(self,data): | ||
| 120 | + self.string("current user is DBA", data) | ||
| 121 | + | ||
| 122 | + def users(self,users): | ||
| 123 | + self.lister("database management system users", users) | ||
| 124 | + | ||
| 101 | 125 | def userSettings(self, header, userSettings, subHeader): | |
| 102 | 126 | self.__areAdmins = set() | |
| 103 | 127 | ||
@@ -125,35 +149,8 @@ def userSettings(self, header, userSettings, subHeader): | |||
| 125 | 149 | self.__write(" %s: %s" % (subHeader, setting)) | |
| 126 | 150 | print | |
| 127 | 151 | ||
| 128 | - def dbColumns(self, dbColumns, colConsider, dbs): | ||
| 129 | - for column in dbColumns.keys(): | ||
| 130 | - if colConsider == "1": | ||
| 131 | - colConsiderStr = "s like '" + column + "' were" | ||
| 132 | - else: | ||
| 133 | - colConsiderStr = " '%s' was" % column | ||
| 134 | - | ||
| 135 | - msg = "Column%s found in the " % colConsiderStr | ||
| 136 | - msg += "following databases:" | ||
| 137 | - self.__write(msg) | ||
| 138 | - | ||
| 139 | - printDbs = {} | ||
| 140 | - | ||
| 141 | - for db, tblData in dbs.items(): | ||
| 142 | - for tbl, colData in tblData.items(): | ||
| 143 | - for col, dataType in colData.items(): | ||
| 144 | - if column.lower() in col.lower(): | ||
| 145 | - if db in printDbs: | ||
| 146 | - if tbl in printDbs[db]: | ||
| 147 | - printDbs[db][tbl][col] = dataType | ||
| 148 | - else: | ||
| 149 | - printDbs[db][tbl] = { col: dataType } | ||
| 150 | - else: | ||
| 151 | - printDbs[db] = {} | ||
| 152 | - printDbs[db][tbl] = { col: dataType } | ||
| 153 | - | ||
| 154 | - continue | ||
| 155 | - | ||
| 156 | - self.dbTableColumns(printDbs) | ||
| 152 | + def dbs(self,dbs): | ||
| 153 | + self.lister("available databases", dbs) | ||
| 157 | 154 | ||
| 158 | 155 | def dbTables(self, dbTables): | |
| 159 | 156 | if not isinstance(dbTables, dict): | |
@@ -268,7 +265,7 @@ def dbTableValues(self, tableValues): | |||
| 268 | 265 | os.makedirs(dumpDbPath, 0755) | |
| 269 | 266 | ||
| 270 | 267 | dumpFileName = "%s%s%s.csv" % (dumpDbPath, os.sep, table) | |
| 271 | - dumpFP = codecs.open(dumpFileName, "w", conf.dataEncoding) | ||
| 268 | + dumpFP = codecs.open(dumpFileName, "wb", conf.dataEncoding) | ||
| 272 | 269 | ||
| 273 | 270 | count = int(tableValues["__infos__"]["count"]) | |
| 274 | 271 | separator = "" | |
@@ -350,6 +347,45 @@ def dbTableValues(self, tableValues): | |||
| 350 | 347 | ||
| 351 | 348 | logger.info("Table '%s.%s' dumped to CSV file '%s'" % (db, table, dumpFileName)) | |
| 352 | 349 | ||
| 350 | + def dbColumns(self, dbColumns, colConsider, dbs): | ||
| 351 | + for column in dbColumns.keys(): | ||
| 352 | + if colConsider == "1": | ||
| 353 | + colConsiderStr = "s like '" + column + "' were" | ||
| 354 | + else: | ||
| 355 | + colConsiderStr = " '%s' was" % column | ||
| 356 | + | ||
| 357 | + msg = "Column%s found in the " % colConsiderStr | ||
| 358 | + msg += "following databases:" | ||
| 359 | + self.__write(msg) | ||
| 360 | + | ||
| 361 | + printDbs = {} | ||
| 362 | + | ||
| 363 | + for db, tblData in dbs.items(): | ||
| 364 | + for tbl, colData in tblData.items(): | ||
| 365 | + for col, dataType in colData.items(): | ||
| 366 | + if column.lower() in col.lower(): | ||
| 367 | + if db in printDbs: | ||
| 368 | + if tbl in printDbs[db]: | ||
| 369 | + printDbs[db][tbl][col] = dataType | ||
| 370 | + else: | ||
| 371 | + printDbs[db][tbl] = { col: dataType } | ||
| 372 | + else: | ||
| 373 | + printDbs[db] = {} | ||
| 374 | + printDbs[db][tbl] = { col: dataType } | ||
| 375 | + | ||
| 376 | + continue | ||
| 377 | + | ||
| 378 | + self.dbTableColumns(printDbs) | ||
| 379 | + | ||
| 380 | + def query(self, query, queryRes): | ||
| 381 | + self.string(query, queryRes) | ||
| 382 | + | ||
| 383 | + def rFile(self,filePath,fileData): | ||
| 384 | + self.string("%s file saved to" % filePath,fileData,sort=False) | ||
| 385 | + | ||
| 386 | + def registerValue(self,registerData): | ||
| 387 | + self.string("Registry key value data", registerData,sort=False) | ||
| 388 | + | ||
| 353 | 389 | # object to manage how to print the retrieved queries output to | |
| 354 | 390 | # standard output and sessions file | |
| 355 | 391 | dumper = Dump() | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -110,8 +110,6 @@ | |||
| 110 | 110 | "limitStop": "integer", | |
| 111 | 111 | "firstChar": "integer", | |
| 112 | 112 | "lastChar": "integer", | |
| 113 | - "getNumOfTables": "integer", | ||
| 114 | - "getNumOfDBs": "integer", | ||
| 115 | 113 | "query": "string", | |
| 116 | 114 | "sqlShell": "boolean" | |
| 117 | 115 | }, | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -37,6 +37,7 @@ | |||
| 37 | 37 | from lib.core.exception import sqlmapGenericException | |
| 38 | 38 | from lib.core.exception import sqlmapSyntaxException | |
| 39 | 39 | from lib.core.session import resumeConfKb | |
| 40 | + from lib.core.xmldump import dumper as xmldumper | ||
| 40 | 41 | ||
| 41 | 42 | def __setRequestParams(): | |
| 42 | 43 | """ | |
@@ -202,6 +203,14 @@ def __createDumpDir(): | |||
| 202 | 203 | if not os.path.isdir(conf.dumpPath): | |
| 203 | 204 | os.makedirs(conf.dumpPath, 0755) | |
| 204 | 205 | ||
| 206 | + def __configureDumper(): | ||
| 207 | + if conf.xmlFile: | ||
| 208 | + conf.dumper = xmldumper | ||
| 209 | + else: | ||
| 210 | + conf.dumper = dumper | ||
| 211 | + | ||
| 212 | + conf.dumper.setOutputFile() | ||
| 213 | + | ||
| 205 | 214 | def __createTargetDirs(): | |
| 206 | 215 | """ | |
| 207 | 216 | Create the output directory. | |
@@ -215,10 +224,9 @@ def __createTargetDirs(): | |||
| 215 | 224 | if not os.path.isdir(conf.outputPath): | |
| 216 | 225 | os.makedirs(conf.outputPath, 0755) | |
| 217 | 226 | ||
| 218 | - dumper.setOutputFile() | ||
| 219 | - | ||
| 220 | 227 | __createDumpDir() | |
| 221 | 228 | __createFilesDir() | |
| 229 | + __configureDumper() | ||
| 222 | 230 | ||
| 223 | 231 | def initTargetEnv(): | |
| 224 | 232 | """ | |
| Back | FazBrowse Home | New Git URL |
0 commit comments