FazBrowse GitHub Viewer
|
Trending
|
URL:
|
Home
Tools:
[Download Repo ZIP]
[View Raw Code]
[Original HTTPS Page]
sqlmap/lib/utils/google.py at master · sql9/sqlmap · GitHub
sql9
/
sqlmap
Public
forked from
sqlmapproject/sqlmap
Notifications
You must be signed in to change notification settings
Fork
0
Star
0
Code
Pull requests
0
Actions
Projects
Wiki
Security and quality
0
Insights
Additional navigation options
Code
Pull requests
Actions
Projects
Wiki
Security and quality
Insights
Expand file tree
Breadcrumbs
sqlmap
/
lib
/
utils
/
google.py
Copy path
More file actions
More file actions
Latest commit
History
History
History
161 lines (129 loc) · 6.31 KB
Breadcrumbs
sqlmap
/
lib
/
utils
/
google.py
Copy path
File metadata and controls
161 lines (129 loc) · 6.31 KB
Raw
Copy raw file
Download raw file
Open symbols panel
Edit and raw actions
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
#!/usr/bin/env python
"""
Copyright (c) 2006-2015 sqlmap developers (http://sqlmap.org/)
See the file 'doc/COPYING' for copying permission
"""
import
cookielib
import
httplib
import
re
import
socket
import
urllib
import
urllib2
from
lib
.
core
.
common
import
getUnicode
from
lib
.
core
.
common
import
readInput
from
lib
.
core
.
common
import
urlencode
from
lib
.
core
.
data
import
conf
from
lib
.
core
.
data
import
logger
from
lib
.
core
.
enums
import
CUSTOM_LOGGING
from
lib
.
core
.
enums
import
HTTP_HEADER
from
lib
.
core
.
exception
import
SqlmapConnectionException
from
lib
.
core
.
exception
import
SqlmapGenericException
from
lib
.
core
.
settings
import
GOOGLE_REGEX
from
lib
.
core
.
settings
import
DUCKDUCKGO_REGEX
from
lib
.
core
.
settings
import
HTTP_ACCEPT_ENCODING_HEADER_VALUE
from
lib
.
core
.
settings
import
UNICODE_ENCODING
from
lib
.
request
.
basic
import
decodePage
from
lib
.
request
.
httpshandler
import
HTTPSHandler
class
Google
(
object
):
"""
This class defines methods used to perform Google dorking (command
line option '-g <google dork>'
"""
def
__init__
(
self
,
handlers
):
self
.
_cj
=
cookielib
.
CookieJar
()
handlers
.
append
(
urllib2
.
HTTPCookieProcessor
(
self
.
_cj
))
handlers
.
append
(
HTTPSHandler
())
self
.
opener
=
urllib2
.
build_opener
(
*
handlers
)
self
.
opener
.
addheaders
=
conf
.
httpHeaders
try
:
conn
=
self
.
opener
.
open
(
"http://www.google.com/ncr"
)
conn
.
info
()
# retrieve session cookie
except
Exception
,
ex
:
errMsg
=
"unable to connect to Google ('%s')"
%
ex
raise
SqlmapConnectionException
(
errMsg
)
def
search
(
self
,
dork
):
"""
This method performs the effective search on Google providing
the google dork and the Google session cookie
"""
gpage
=
conf
.
googlePage
if
conf
.
googlePage
>
1
else
1
logger
.
info
(
"using Google result page #%d"
%
gpage
)
if
not
dork
:
return
None
url
=
"http://www.google.com/search?"
url
+=
"q=%s&"
%
urlencode
(
dork
,
convall
=
True
)
url
+=
"num=100&hl=en&complete=0&safe=off&filter=0&btnG=Search"
url
+=
"&start=%d"
%
((
gpage
-
1
)
*
100
)
try
:
conn
=
self
.
opener
.
open
(
url
)
requestMsg
=
"HTTP request:
\n
GET %s"
%
url
requestMsg
+=
" %s"
%
httplib
.
HTTPConnection
.
_http_vsn_str
logger
.
log
(
CUSTOM_LOGGING
.
TRAFFIC_OUT
,
requestMsg
)
page
=
conn
.
read
()
code
=
conn
.
code
status
=
conn
.
msg
responseHeaders
=
conn
.
info
()
page
=
decodePage
(
page
,
responseHeaders
.
get
(
"Content-Encoding"
),
responseHeaders
.
get
(
"Content-Type"
))
responseMsg
=
"HTTP response (%s - %d):
\n
"
%
(
status
,
code
)
if
conf
.
verbose
<=
4
:
responseMsg
+=
getUnicode
(
responseHeaders
,
UNICODE_ENCODING
)
elif
conf
.
verbose
>
4
:
responseMsg
+=
"%s
\n
%s
\n
"
%
(
responseHeaders
,
page
)
logger
.
log
(
CUSTOM_LOGGING
.
TRAFFIC_IN
,
responseMsg
)
except
urllib2
.
HTTPError
,
e
:
try
:
page
=
e
.
read
()
except
socket
.
timeout
:
warnMsg
=
"connection timed out while trying "
warnMsg
+=
"to get error page information (%d)"
%
e
.
code
logger
.
critical
(
warnMsg
)
return
None
except
(
urllib2
.
URLError
,
socket
.
error
,
socket
.
timeout
):
errMsg
=
"unable to connect to Google"
raise
SqlmapConnectionException
(
errMsg
)
retVal
=
[
urllib
.
unquote
(
match
.
group
(
1
))
for
match
in
re
.
finditer
(
GOOGLE_REGEX
,
page
,
re
.
I
|
re
.
S
)]
if
not
retVal
and
"detected unusual traffic"
in
page
:
warnMsg
=
"Google has detected 'unusual' traffic from "
warnMsg
+=
"used IP address disabling further searches"
raise
SqlmapGenericException
(
warnMsg
)
if
not
retVal
:
message
=
"no usable links found. "
message
+=
"do you want to (re)try with DuckDuckGo? [Y/n] "
output
=
readInput
(
message
,
default
=
"Y"
)
if
output
.
strip
().
lower
()
!=
'n'
:
url
=
"https://duckduckgo.com/d.js?"
url
+=
"q=%s&p=%d&s=100"
%
(
urlencode
(
dork
,
convall
=
True
),
gpage
)
if
not
conf
.
randomAgent
:
self
.
opener
.
addheaders
=
[
_
for
_
in
self
.
opener
.
addheaders
if
_
[
0
].
lower
()
!=
HTTP_HEADER
.
USER_AGENT
.
lower
()]
self
.
opener
.
addheaders
.
append
((
HTTP_HEADER
.
USER_AGENT
,
"Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:24.0) Gecko/20100101 Firefox/24.0"
))
self
.
opener
.
addheaders
=
[
_
for
_
in
self
.
opener
.
addheaders
if
_
[
0
].
lower
()
!=
HTTP_HEADER
.
ACCEPT_ENCODING
.
lower
()]
self
.
opener
.
addheaders
.
append
((
HTTP_HEADER
.
ACCEPT_ENCODING
,
HTTP_ACCEPT_ENCODING_HEADER_VALUE
))
try
:
conn
=
self
.
opener
.
open
(
url
)
requestMsg
=
"HTTP request:
\n
GET %s"
%
url
requestMsg
+=
" %s"
%
httplib
.
HTTPConnection
.
_http_vsn_str
logger
.
log
(
CUSTOM_LOGGING
.
TRAFFIC_OUT
,
requestMsg
)
page
=
conn
.
read
()
code
=
conn
.
code
status
=
conn
.
msg
responseHeaders
=
conn
.
info
()
page
=
decodePage
(
page
,
responseHeaders
.
get
(
"Content-Encoding"
),
responseHeaders
.
get
(
"Content-Type"
))
responseMsg
=
"HTTP response (%s - %d):
\n
"
%
(
status
,
code
)
if
conf
.
verbose
<=
4
:
responseMsg
+=
getUnicode
(
responseHeaders
,
UNICODE_ENCODING
)
elif
conf
.
verbose
>
4
:
responseMsg
+=
"%s
\n
%s
\n
"
%
(
responseHeaders
,
page
)
logger
.
log
(
CUSTOM_LOGGING
.
TRAFFIC_IN
,
responseMsg
)
except
urllib2
.
HTTPError
,
e
:
try
:
page
=
e
.
read
()
except
socket
.
timeout
:
warnMsg
=
"connection timed out while trying "
warnMsg
+=
"to get error page information (%d)"
%
e
.
code
logger
.
critical
(
warnMsg
)
return
None
except
:
errMsg
=
"unable to connect to DuckDuckGo"
raise
SqlmapConnectionException
(
errMsg
)
retVal
=
[
urllib
.
unquote
(
match
.
group
(
1
))
for
match
in
re
.
finditer
(
DUCKDUCKGO_REGEX
,
page
,
re
.
I
|
re
.
S
)]
return
retVal
Back
|
FazBrowse Home
|
New Git URL