FazBrowse GitHub Viewer
|
Trending
|
URL:
|
Home
Tools:
[Download Repo ZIP]
[View Raw Code]
[Original HTTPS Page]
sqlmap/sqlmap.py at master · sql9/sqlmap · GitHub
sql9
/
sqlmap
Public
forked from
sqlmapproject/sqlmap
Notifications
You must be signed in to change notification settings
Fork
0
Star
0
Code
Pull requests
0
Actions
Projects
Wiki
Security and quality
0
Insights
Additional navigation options
Code
Pull requests
Actions
Projects
Wiki
Security and quality
Insights
Expand file tree
Breadcrumbs
sqlmap
/
sqlmap.py
Copy path
More file actions
More file actions
Latest commit
History
History
History
executable file
·
188 lines (152 loc) · 5.33 KB
Breadcrumbs
sqlmap
/
sqlmap.py
Copy path
File metadata and controls
executable file
·
188 lines (152 loc) · 5.33 KB
Raw
Copy raw file
Download raw file
Open symbols panel
Edit and raw actions
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
#!/usr/bin/env python
"""
Copyright (c) 2006-2015 sqlmap developers (http://sqlmap.org/)
See the file 'doc/COPYING' for copying permission
"""
import
bdb
import
inspect
import
logging
import
os
import
re
import
shutil
import
sys
import
tempfile
import
time
import
traceback
import
warnings
warnings
.
filterwarnings
(
action
=
"ignore"
,
message
=
".*was already imported"
,
category
=
UserWarning
)
warnings
.
filterwarnings
(
action
=
"ignore"
,
category
=
DeprecationWarning
)
from
lib
.
utils
import
versioncheck
# this has to be the first non-standard import
from
lib
.
controller
.
controller
import
start
from
lib
.
core
.
common
import
banner
from
lib
.
core
.
common
import
createGithubIssue
from
lib
.
core
.
common
import
dataToStdout
from
lib
.
core
.
common
import
getUnicode
from
lib
.
core
.
common
import
maskSensitiveData
from
lib
.
core
.
common
import
setColor
from
lib
.
core
.
common
import
setPaths
from
lib
.
core
.
common
import
weAreFrozen
from
lib
.
core
.
data
import
cmdLineOptions
from
lib
.
core
.
data
import
conf
from
lib
.
core
.
data
import
kb
from
lib
.
core
.
data
import
logger
from
lib
.
core
.
data
import
paths
from
lib
.
core
.
common
import
unhandledExceptionMessage
from
lib
.
core
.
exception
import
SqlmapBaseException
from
lib
.
core
.
exception
import
SqlmapShellQuitException
from
lib
.
core
.
exception
import
SqlmapSilentQuitException
from
lib
.
core
.
exception
import
SqlmapUserQuitException
from
lib
.
core
.
option
import
initOptions
from
lib
.
core
.
option
import
init
from
lib
.
core
.
profiling
import
profile
from
lib
.
core
.
settings
import
LEGAL_DISCLAIMER
from
lib
.
core
.
testing
import
smokeTest
from
lib
.
core
.
testing
import
liveTest
from
lib
.
parse
.
cmdline
import
cmdLineParser
from
lib
.
utils
.
api
import
setRestAPILog
from
lib
.
utils
.
api
import
StdDbOut
def
modulePath
():
"""
This will get us the program's directory, even if we are frozen
using py2exe
"""
try
:
_
=
sys
.
executable
if
weAreFrozen
()
else
__file__
except
NameError
:
_
=
inspect
.
getsourcefile
(
modulePath
)
return
getUnicode
(
os
.
path
.
dirname
(
os
.
path
.
realpath
(
_
)),
sys
.
getfilesystemencoding
())
def
main
():
"""
Main function of sqlmap when running from command line.
"""
try
:
paths
.
SQLMAP_ROOT_PATH
=
modulePath
()
setPaths
()
# Store original command line options for possible later restoration
cmdLineOptions
.
update
(
cmdLineParser
().
__dict__
)
initOptions
(
cmdLineOptions
)
if
hasattr
(
conf
,
"api"
):
# Overwrite system standard output and standard error to write
# to an IPC database
sys
.
stdout
=
StdDbOut
(
conf
.
taskid
,
messagetype
=
"stdout"
)
sys
.
stderr
=
StdDbOut
(
conf
.
taskid
,
messagetype
=
"stderr"
)
setRestAPILog
()
banner
()
conf
.
showTime
=
True
dataToStdout
(
"[!] legal disclaimer: %s
\n
\n
"
%
LEGAL_DISCLAIMER
,
forceOutput
=
True
)
dataToStdout
(
"[*] starting at %s
\n
\n
"
%
time
.
strftime
(
"%X"
),
forceOutput
=
True
)
init
()
if
conf
.
profile
:
profile
()
elif
conf
.
smokeTest
:
smokeTest
()
elif
conf
.
liveTest
:
liveTest
()
else
:
start
()
except
SqlmapUserQuitException
:
errMsg
=
"user quit"
logger
.
error
(
errMsg
)
except
(
SqlmapSilentQuitException
,
bdb
.
BdbQuit
):
pass
except
SqlmapShellQuitException
:
cmdLineOptions
.
sqlmapShell
=
False
except
SqlmapBaseException
as
ex
:
errMsg
=
getUnicode
(
ex
.
message
)
logger
.
critical
(
errMsg
)
sys
.
exit
(
1
)
except
KeyboardInterrupt
:
print
errMsg
=
"user aborted"
logger
.
error
(
errMsg
)
except
EOFError
:
print
errMsg
=
"exit"
logger
.
error
(
errMsg
)
except
SystemExit
:
pass
except
:
print
errMsg
=
unhandledExceptionMessage
()
excMsg
=
traceback
.
format_exc
()
for
match
in
re
.
finditer
(
r'File "(.+?)", line'
,
excMsg
):
file_
=
match
.
group
(
1
)
file_
=
os
.
path
.
relpath
(
file_
,
os
.
path
.
dirname
(
__file__
))
file_
=
file_
.
replace
(
"
\\
"
,
'/'
)
file_
=
re
.
sub
(
r"\.\./"
,
'/'
,
file_
).
lstrip
(
'/'
)
excMsg
=
excMsg
.
replace
(
match
.
group
(
1
),
file_
)
errMsg
=
maskSensitiveData
(
errMsg
)
excMsg
=
maskSensitiveData
(
excMsg
)
logger
.
critical
(
errMsg
)
kb
.
stickyLevel
=
logging
.
CRITICAL
dataToStdout
(
excMsg
)
createGithubIssue
(
errMsg
,
excMsg
)
finally
:
if
conf
.
get
(
"showTime"
):
dataToStdout
(
"
\n
[*] shutting down at %s
\n
\n
"
%
time
.
strftime
(
"%X"
),
forceOutput
=
True
)
if
kb
.
get
(
"tempDir"
):
shutil
.
rmtree
(
kb
.
tempDir
,
ignore_errors
=
True
)
kb
.
threadContinue
=
False
kb
.
threadException
=
True
if
conf
.
get
(
"hashDB"
):
try
:
conf
.
hashDB
.
flush
(
True
)
except
KeyboardInterrupt
:
pass
if
cmdLineOptions
.
get
(
"sqlmapShell"
):
cmdLineOptions
.
clear
()
conf
.
clear
()
kb
.
clear
()
main
()
if
hasattr
(
conf
,
"api"
):
try
:
conf
.
database_cursor
.
disconnect
()
except
KeyboardInterrupt
:
pass
if
conf
.
get
(
"dumper"
):
conf
.
dumper
.
flush
()
# Reference: http://stackoverflow.com/questions/1635080/terminate-a-multi-thread-python-program
if
conf
.
get
(
"threads"
,
0
)
>
1
or
conf
.
get
(
"dnsServer"
):
os
.
_exit
(
0
)
if
__name__
==
"__main__"
:
main
()
Back
|
FazBrowse Home
|
New Git URL