| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
1 parent b4139f5 commit 6863436
8 files changed
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -127,6 +127,7 @@ | |||
| 127 | 127 | "db": "string", | |
| 128 | 128 | "tbl": "string", | |
| 129 | 129 | "col": "string", | |
| 130 | + "excludeCol": "string", | ||
| 130 | 131 | "user": "string", | |
| 131 | 132 | "excludeSysDbs": "boolean", | |
| 132 | 133 | "limitStart": "integer", | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -404,10 +404,13 @@ def cmdLineParser(): | |||
| 404 | 404 | help="DBMS database to enumerate") | |
| 405 | 405 | ||
| 406 | 406 | enumeration.add_option("-T", dest="tbl", | |
| 407 | - help="DBMS database table to enumerate") | ||
| 407 | + help="DBMS database table(s) to enumerate") | ||
| 408 | 408 | ||
| 409 | 409 | enumeration.add_option("-C", dest="col", | |
| 410 | - help="DBMS database table column to enumerate") | ||
| 410 | + help="DBMS database table column(s) to enumerate") | ||
| 411 | + | ||
| 412 | + enumeration.add_option("-X", dest="excludeCol", | ||
| 413 | + help="DBMS database table column(s) to not enumerate") | ||
| 411 | 414 | ||
| 412 | 415 | enumeration.add_option("-U", dest="user", | |
| 413 | 416 | help="DBMS user to enumerate") | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -263,6 +263,10 @@ def searchColumn(self): | |||
| 263 | 263 | infoMsgTbl = "" | |
| 264 | 264 | infoMsgDb = "" | |
| 265 | 265 | colList = conf.col.split(",") | |
| 266 | + | ||
| 267 | + if conf.excludeCol: | ||
| 268 | + colList = [_ for _ in colList if _ not in conf.excludeCol.split(',')] | ||
| 269 | + | ||
| 266 | 270 | origTbl = conf.tbl | |
| 267 | 271 | origDb = conf.db | |
| 268 | 272 | colCond = rootQuery.inband.condition | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -181,6 +181,9 @@ def getColumns(self, onlyColNames=False): | |||
| 181 | 181 | else: | |
| 182 | 182 | colList = [] | |
| 183 | 183 | ||
| 184 | + if conf.excludeCol: | ||
| 185 | + colList = [_ for _ in colList if _ not in conf.excludeCol.split(',')] | ||
| 186 | + | ||
| 184 | 187 | for col in colList: | |
| 185 | 188 | colList[colList.index(col)] = safeSQLIdentificatorNaming(col) | |
| 186 | 189 | ||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -399,10 +399,13 @@ def getColumns(self, onlyColNames=False, colTuple=None, bruteForce=None): | |||
| 399 | 399 | if Backend.getIdentifiedDbms() in (DBMS.ORACLE, DBMS.DB2): | |
| 400 | 400 | conf.col = conf.col.upper() | |
| 401 | 401 | ||
| 402 | - colList = conf.col.split(",") | ||
| 402 | + colList = conf.col.split(',') | ||
| 403 | 403 | else: | |
| 404 | 404 | colList = [] | |
| 405 | 405 | ||
| 406 | + if conf.excludeCol: | ||
| 407 | + colList = [_ for _ in colList if _ not in conf.excludeCol.split(',')] | ||
| 408 | + | ||
| 406 | 409 | for col in colList: | |
| 407 | 410 | colList[colList.index(col)] = safeSQLIdentificatorNaming(col) | |
| 408 | 411 | ||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -122,6 +122,17 @@ def dumpTable(self, foundData=None): | |||
| 122 | 122 | ||
| 123 | 123 | columns = kb.data.cachedColumns[safeSQLIdentificatorNaming(conf.db)][safeSQLIdentificatorNaming(tbl, True)] | |
| 124 | 124 | colList = sorted(filter(None, columns.keys())) | |
| 125 | + | ||
| 126 | + if conf.excludeCol: | ||
| 127 | + colList = [_ for _ in colList if _ not in conf.excludeCol.split(',')] | ||
| 128 | + | ||
| 129 | + if not colList: | ||
| 130 | + warnMsg = "skipping table '%s'" % unsafeSQLIdentificatorNaming(tbl) | ||
| 131 | + warnMsg += " in database '%s'" % unsafeSQLIdentificatorNaming(conf.db) | ||
| 132 | + warnMsg += " (no usable column names)" | ||
| 133 | + logger.warn(warnMsg) | ||
| 134 | + continue | ||
| 135 | + | ||
| 125 | 136 | colNames = colString = ", ".join(column for column in colList) | |
| 126 | 137 | rootQuery = queries[Backend.getIdentifiedDbms()].dump_table | |
| 127 | 138 | ||
@@ -420,7 +431,12 @@ def dumpFoundColumn(self, dbs, foundCols, colConsider): | |||
| 420 | 431 | continue | |
| 421 | 432 | ||
| 422 | 433 | conf.tbl = table | |
| 423 | - conf.col = ",".join(column for column in filter(None, sorted(columns))) | ||
| 434 | + colList = filter(None, sorted(columns)) | ||
| 435 | + | ||
| 436 | + if conf.excludeCol: | ||
| 437 | + colList = [_ for _ in colList if _ not in conf.excludeCol.split(',')] | ||
| 438 | + | ||
| 439 | + conf.col = ",".join(colList) | ||
| 424 | 440 | kb.data.cachedColumns = {} | |
| 425 | 441 | kb.data.dumpedTable = {} | |
| 426 | 442 | ||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -349,7 +349,7 @@ def searchColumn(self): | |||
| 349 | 349 | elif test[0] in ("q", "Q"): | |
| 350 | 350 | raise SqlmapUserQuitException | |
| 351 | 351 | else: | |
| 352 | - regex = "|".join(conf.col.split(",")) | ||
| 352 | + regex = '|'.join(conf.col.split(',')) | ||
| 353 | 353 | conf.dumper.dbTableColumns(columnExists(paths.COMMON_COLUMNS, regex)) | |
| 354 | 354 | ||
| 355 | 355 | message = "do you want to dump entries? [Y/n] " | |
@@ -368,6 +368,10 @@ def searchColumn(self): | |||
| 368 | 368 | infoMsgTbl = "" | |
| 369 | 369 | infoMsgDb = "" | |
| 370 | 370 | colList = conf.col.split(",") | |
| 371 | + | ||
| 372 | + if conf.excludeCol: | ||
| 373 | + colList = [_ for _ in colList if _ not in conf.excludeCol.split(',')] | ||
| 374 | + | ||
| 371 | 375 | origTbl = conf.tbl | |
| 372 | 376 | origDb = conf.db | |
| 373 | 377 | colCond = rootQuery.inband.condition | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -445,12 +445,15 @@ getComments = False | |||
| 445 | 445 | # Back-end database management system database to enumerate. | |
| 446 | 446 | db = | |
| 447 | 447 | ||
| 448 | - # Back-end database management system database table to enumerate. | ||
| 448 | + # Back-end database management system database table(s) to enumerate. | ||
| 449 | 449 | tbl = | |
| 450 | 450 | ||
| 451 | - # Back-end database management system database table column to enumerate. | ||
| 451 | + # Back-end database management system database table column(s) to enumerate. | ||
| 452 | 452 | col = | |
| 453 | 453 | ||
| 454 | + # Back-end database management system database table column(s) to not enumerate. | ||
| 455 | + excludeCol = | ||
| 456 | + | ||
| 454 | 457 | # Back-end database management system database user to enumerate. | |
| 455 | 458 | user = | |
| 456 | 459 | ||
| Back | FazBrowse Home | New Git URL |
0 commit comments