| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
1 parent 4beef09 commit a711c9e
7 files changed
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -2768,7 +2768,7 @@ def maskSensitiveData(msg): | |||
| 2768 | 2768 | ||
| 2769 | 2769 | retVal = msg | |
| 2770 | 2770 | ||
| 2771 | - for item in filter(None, map(lambda x: conf.get(x), ("hostname", "googleDork", "aCred", "pCred", "tbl", "db", "col", "user", "cookie", "proxy"))): | ||
| 2771 | + for item in filter(None, map(lambda x: conf.get(x), ("hostname", "googleDork", "authCred", "proxyCred", "tbl", "db", "col", "user", "cookie", "proxy"))): | ||
| 2772 | 2772 | regex = SENSITIVE_DATA_REGEX % re.sub("(\W)", r"\\\1", item) | |
| 2773 | 2773 | while extractRegexResult(regex, retVal): | |
| 2774 | 2774 | value = extractRegexResult(regex, retVal) | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -180,7 +180,7 @@ def _urllib2Opener(): | |||
| 180 | 180 | if conf.proxy: | |
| 181 | 181 | warnMsg += "with HTTP(s) proxy" | |
| 182 | 182 | logger.warn(warnMsg) | |
| 183 | - elif conf.aType: | ||
| 183 | + elif conf.authType: | ||
| 184 | 184 | warnMsg += "with authentication methods" | |
| 185 | 185 | logger.warn(warnMsg) | |
| 186 | 186 | else: | |
@@ -1011,8 +1011,8 @@ def _setHTTPProxy(): | |||
| 1011 | 1011 | errMsg = "proxy value must be in format '(%s)://url:port'" % "|".join(_[0].lower() for _ in getPublicTypeMembers(PROXY_TYPE)) | |
| 1012 | 1012 | raise SqlmapSyntaxException(errMsg) | |
| 1013 | 1013 | ||
| 1014 | - if conf.pCred: | ||
| 1015 | - _ = re.search("^(.*?):(.*?)$", conf.pCred) | ||
| 1014 | + if conf.proxyCred: | ||
| 1015 | + _ = re.search("^(.*?):(.*?)$", conf.proxyCred) | ||
| 1016 | 1016 | if not _: | |
| 1017 | 1017 | errMsg = "Proxy authentication credentials " | |
| 1018 | 1018 | errMsg += "value must be in format username:password" | |
@@ -1025,9 +1025,9 @@ def _setHTTPProxy(): | |||
| 1025 | 1025 | socks.setdefaultproxy(socks.PROXY_TYPE_SOCKS5 if scheme == PROXY_TYPE.SOCKS5 else socks.PROXY_TYPE_SOCKS4, hostname, port, username=username, password=password) | |
| 1026 | 1026 | socks.wrapmodule(urllib2) | |
| 1027 | 1027 | else: | |
| 1028 | - if conf.pCred: | ||
| 1028 | + if conf.proxyCred: | ||
| 1029 | 1029 | # Reference: http://stackoverflow.com/questions/34079/how-to-specify-an-authenticated-proxy-for-a-python-http-connection | |
| 1030 | - proxyString = "%s@" % conf.pCred | ||
| 1030 | + proxyString = "%s@" % conf.proxyCred | ||
| 1031 | 1031 | else: | |
| 1032 | 1032 | proxyString = "" | |
| 1033 | 1033 | ||
@@ -1097,24 +1097,24 @@ def _setHTTPAuthentication(): | |||
| 1097 | 1097 | ||
| 1098 | 1098 | global authHandler | |
| 1099 | 1099 | ||
| 1100 | - if not conf.aType and not conf.aCred and not conf.aCert: | ||
| 1100 | + if not conf.authType and not conf.authCred and not conf.authCert: | ||
| 1101 | 1101 | return | |
| 1102 | 1102 | ||
| 1103 | - elif conf.aType and not conf.aCred and not conf.aCert: | ||
| 1103 | + elif conf.authType and not conf.authCred and not conf.authCert: | ||
| 1104 | 1104 | errMsg = "you specified the HTTP authentication type, but " | |
| 1105 | 1105 | errMsg += "did not provide the credentials" | |
| 1106 | 1106 | raise SqlmapSyntaxException(errMsg) | |
| 1107 | 1107 | ||
| 1108 | - elif not conf.aType and conf.aCred: | ||
| 1108 | + elif not conf.authType and conf.authCred: | ||
| 1109 | 1109 | errMsg = "you specified the HTTP authentication credentials, " | |
| 1110 | 1110 | errMsg += "but did not provide the type" | |
| 1111 | 1111 | raise SqlmapSyntaxException(errMsg) | |
| 1112 | 1112 | ||
| 1113 | - if not conf.aCert: | ||
| 1113 | + if not conf.authCert: | ||
| 1114 | 1114 | debugMsg = "setting the HTTP authentication type and credentials" | |
| 1115 | 1115 | logger.debug(debugMsg) | |
| 1116 | 1116 | ||
| 1117 | - aTypeLower = conf.aType.lower() | ||
| 1117 | + aTypeLower = conf.authType.lower() | ||
| 1118 | 1118 | ||
| 1119 | 1119 | if aTypeLower not in (AUTH_TYPE.BASIC, AUTH_TYPE.DIGEST, AUTH_TYPE.NTLM, AUTH_TYPE.CERT): | |
| 1120 | 1120 | errMsg = "HTTP authentication type value must be " | |
@@ -1133,7 +1133,7 @@ def _setHTTPAuthentication(): | |||
| 1133 | 1133 | errMsg += "usage of option `--auth-cert`" | |
| 1134 | 1134 | raise SqlmapSyntaxException(errMsg) | |
| 1135 | 1135 | ||
| 1136 | - aCredRegExp = re.search(regExp, conf.aCred) | ||
| 1136 | + aCredRegExp = re.search(regExp, conf.authCred) | ||
| 1137 | 1137 | ||
| 1138 | 1138 | if not aCredRegExp: | |
| 1139 | 1139 | raise SqlmapSyntaxException(errMsg) | |
@@ -1165,7 +1165,7 @@ def _setHTTPAuthentication(): | |||
| 1165 | 1165 | debugMsg = "setting the HTTP(s) authentication certificate" | |
| 1166 | 1166 | logger.debug(debugMsg) | |
| 1167 | 1167 | ||
| 1168 | - aCertRegExp = re.search("^(.+?),\s*(.+?)$", conf.aCert) | ||
| 1168 | + aCertRegExp = re.search("^(.+?),\s*(.+?)$", conf.authCert) | ||
| 1169 | 1169 | ||
| 1170 | 1170 | if not aCertRegExp: | |
| 1171 | 1171 | errMsg = "HTTP authentication certificate option " | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -33,11 +33,12 @@ | |||
| 33 | 33 | "host": "string", | |
| 34 | 34 | "referer": "string", | |
| 35 | 35 | "headers": "string", | |
| 36 | - "aType": "string", | ||
| 37 | - "aCred": "string", | ||
| 38 | - "aCert": "string", | ||
| 36 | + "authType": "string", | ||
| 37 | + "authCred": "string", | ||
| 38 | + "authCert": "string", | ||
| 39 | 39 | "proxy": "string", | |
| 40 | - "pCred": "string", | ||
| 40 | + "proxyCred": "string", | ||
| 41 | + "proxyFile": "string", | ||
| 41 | 42 | "ignoreProxy": "boolean", | |
| 42 | 43 | "tor": "boolean", | |
| 43 | 44 | "torPort": "integer", | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -108,25 +108,28 @@ def cmdLineParser(): | |||
| 108 | 108 | request.add_option("--headers", dest="headers", | |
| 109 | 109 | help="Extra headers (e.g. \"Accept-Language: fr\\nETag: 123\")") | |
| 110 | 110 | ||
| 111 | - request.add_option("--auth-type", dest="aType", | ||
| 111 | + request.add_option("--auth-type", dest="authType", | ||
| 112 | 112 | help="HTTP authentication type " | |
| 113 | 113 | "(Basic, Digest, NTLM or Cert)") | |
| 114 | 114 | ||
| 115 | - request.add_option("--auth-cred", dest="aCred", | ||
| 115 | + request.add_option("--auth-cred", dest="authCred", | ||
| 116 | 116 | help="HTTP authentication credentials " | |
| 117 | 117 | "(name:password)") | |
| 118 | 118 | ||
| 119 | - request.add_option("--auth-cert", dest="aCert", | ||
| 119 | + request.add_option("--auth-cert", dest="authCert", | ||
| 120 | 120 | help="HTTP authentication certificate (" | |
| 121 | 121 | "key_file,cert_file)") | |
| 122 | 122 | ||
| 123 | 123 | request.add_option("--proxy", dest="proxy", | |
| 124 | 124 | help="Use a proxy to connect to the target URL") | |
| 125 | 125 | ||
| 126 | - request.add_option("--proxy-cred", dest="pCred", | ||
| 126 | + request.add_option("--proxy-cred", dest="proxyCred", | ||
| 127 | 127 | help="Proxy authentication credentials " | |
| 128 | 128 | "(name:password)") | |
| 129 | 129 | ||
| 130 | + request.add_option("--proxy-file", dest="proxyFile", | ||
| 131 | + help="Load proxy list from a file") | ||
| 132 | + | ||
| 130 | 133 | request.add_option("--ignore-proxy", dest="ignoreProxy", action="store_true", | |
| 131 | 134 | help="Ignore system default proxy settings") | |
| 132 | 135 | ||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -372,7 +372,7 @@ def getPage(**kwargs): | |||
| 372 | 372 | ||
| 373 | 373 | conn = urllib2.urlopen(req) | |
| 374 | 374 | ||
| 375 | - if not kb.authHeader and getRequestHeader(req, HTTP_HEADER.AUTHORIZATION) and conf.aType == AUTH_TYPE.BASIC: | ||
| 375 | + if not kb.authHeader and getRequestHeader(req, HTTP_HEADER.AUTHORIZATION) and conf.authType == AUTH_TYPE.BASIC: | ||
| 376 | 376 | kb.authHeader = getRequestHeader(req, HTTP_HEADER.AUTHORIZATION) | |
| 377 | 377 | ||
| 378 | 378 | if not kb.proxyAuthHeader and getRequestHeader(req, HTTP_HEADER.PROXY_AUTHORIZATION): | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -18,6 +18,9 @@ url = | |||
| 18 | 18 | # 'conversations/' folder path | |
| 19 | 19 | logFile = | |
| 20 | 20 | ||
| 21 | + # Scan multiple targets enlisted in a given textual file | ||
| 22 | + bulkFile = | ||
| 23 | + | ||
| 21 | 24 | # Load HTTP request from a file | |
| 22 | 25 | # Example (file content): POST /login.jsp HTTP/1.1\nHost: example.com\nUser-Agent: Mozilla/4.0\n\nuserid=joe&password=guessme | |
| 23 | 26 | requestFile = | |
@@ -76,17 +79,17 @@ headers = Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9 | |||
| 76 | 79 | # HTTP Authentication type. Useful only if the target URL requires | |
| 77 | 80 | # HTTP Basic, Digest or NTLM authentication and you have such data. | |
| 78 | 81 | # Valid: Basic, Digest, NTLM or Cert | |
| 79 | - aType = | ||
| 82 | + authType = | ||
| 80 | 83 | ||
| 81 | 84 | # HTTP authentication credentials. Useful only if the target URL requires | |
| 82 | 85 | # HTTP Basic, Digest or NTLM authentication and you have such data. | |
| 83 | 86 | # Syntax: username:password | |
| 84 | - aCred = | ||
| 87 | + authCred = | ||
| 85 | 88 | ||
| 86 | 89 | # HTTP Authentication certificate. Useful only if the target URL requires | |
| 87 | 90 | # logon certificate and you have such data. | |
| 88 | 91 | # Syntax: key_file,cert_file | |
| 89 | - aCert = | ||
| 92 | + authCert = | ||
| 90 | 93 | ||
| 91 | 94 | # Use a proxy to connect to the target URL. | |
| 92 | 95 | # Syntax: http://address:port | |
@@ -95,7 +98,10 @@ proxy = | |||
| 95 | 98 | # Proxy authentication credentials. Useful only if the proxy requires | |
| 96 | 99 | # Basic or Digest authentication and you have such data. | |
| 97 | 100 | # Syntax: username:password | |
| 98 | - pCred = | ||
| 101 | + proxyCred = | ||
| 102 | + | ||
| 103 | + # Load proxy list from a file | ||
| 104 | + proxyFile = | ||
| 99 | 105 | ||
| 100 | 106 | # Ignore system default proxy settings. | |
| 101 | 107 | # Valid: True or False | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -3423,8 +3423,8 @@ | |||
| 3423 | 3423 | <switches> | |
| 3424 | 3424 | <url value="http://debiandev/sqlmap/mysql/basic/get_int.php?id=1"/> | |
| 3425 | 3425 | <tech value="E"/> | |
| 3426 | - <aType value="Basic"/> | ||
| 3427 | - <aCred value="testuser:testpass"/> | ||
| 3426 | + <authType value="Basic"/> | ||
| 3427 | + <authCred value="testuser:testpass"/> | ||
| 3428 | 3428 | <getBanner value="True"/> | |
| 3429 | 3429 | </switches> | |
| 3430 | 3430 | <parse> | |
@@ -3435,8 +3435,8 @@ | |||
| 3435 | 3435 | <switches> | |
| 3436 | 3436 | <url value="http://debiandev/sqlmap/mysql/digest/get_int.php?id=1"/> | |
| 3437 | 3437 | <tech value="E"/> | |
| 3438 | - <aType value="Digest"/> | ||
| 3439 | - <aCred value="testuser:testpass"/> | ||
| 3438 | + <authType value="Digest"/> | ||
| 3439 | + <authCred value="testuser:testpass"/> | ||
| 3440 | 3440 | <getBanner value="True"/> | |
| 3441 | 3441 | </switches> | |
| 3442 | 3442 | <parse> | |
| Back | FazBrowse Home | New Git URL |
0 commit comments