Skip to content

Commit aebae6e

Browse files
committed
Added (heuristic) support for sqlmapproject#1679
1 parent 0a3e771 commit aebae6e

File tree

3 files changed

+20
-11
lines changed

3 files changed

+20
-11
lines changed

lib/core/settings.py

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@
1919
from lib.core.enums import OS
2020

2121
# sqlmap version (<major>.<minor>.<month>.<monthly commit>)
22-
VERSION = "1.1.3.14"
22+
VERSION = "1.1.3.15"
2323
TYPE = "dev" if VERSION.count('.') > 2 and VERSION.split('.')[-1] != '0' else "stable"
2424
TYPE_COLORS = {"dev": 33, "stable": 90, "pip": 34}
2525
VERSION_STRING = "sqlmap/%s#%s" % ('.'.join(VERSION.split('.')[:-1]) if VERSION.count('.') > 2 and VERSION.split('.')[-1] == '0' else VERSION, TYPE)

lib/request/connect.py

Lines changed: 17 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -1045,19 +1045,28 @@ def _randomizeParameter(paramString, randomParameter):
10451045
found = False
10461046
value = getUnicode(value)
10471047

1048-
regex = r"\b(%s)\b([^\w]+)(\w+)" % re.escape(name)
1049-
if kb.postHint and re.search(regex, (post or "")):
1050-
found = True
1051-
post = re.sub(regex, "\g<1>\g<2>%s" % value, post)
1048+
if kb.postHint and re.search(r"\b%s\b" % re.escape(name), post or ""):
1049+
if kb.postHint in (POST_HINT.XML, POST_HINT.SOAP):
1050+
if re.search(r"<%s\b" % re.escape(name), post):
1051+
found = True
1052+
post = re.sub(r"(?s)(<%s\b[^>]*>)(.*?)(</%s)" % (re.escape(name), re.escape(name)), "\g<1>%s\g<3>" % value, post)
1053+
elif re.search(r"\b%s>" % re.escape(name), post):
1054+
found = True
1055+
post = re.sub(r"(?s)(\b%s>)(.*?)(</[^<]*\b%s>)" % (re.escape(name), re.escape(name)), "\g<1>%s\g<3>" % value, post)
1056+
1057+
regex = r"\b(%s)\b([^\w]+)(\w+)" % re.escape(name)
1058+
if not found and re.search(regex, (post or "")):
1059+
found = True
1060+
post = re.sub(regex, "\g<1>\g<2>%s" % value, post)
10521061

10531062
regex = r"((\A|%s)%s=).+?(%s|\Z)" % (re.escape(delimiter), re.escape(name), re.escape(delimiter))
1054-
if re.search(regex, (get or "")):
1063+
if not found and re.search(regex, (post or "")):
10551064
found = True
1056-
get = re.sub(regex, "\g<1>%s\g<3>" % value, get)
1065+
post = re.sub(regex, "\g<1>%s\g<3>" % value, post)
10571066

1058-
if re.search(regex, (post or "")):
1067+
if re.search(regex, (get or "")):
10591068
found = True
1060-
post = re.sub(regex, "\g<1>%s\g<3>" % value, post)
1069+
get = re.sub(regex, "\g<1>%s\g<3>" % value, get)
10611070

10621071
if re.search(regex, (query or "")):
10631072
found = True

txt/checksum.md5

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -45,7 +45,7 @@ a8143dab9d3a27490f7d49b6b29ea530 lib/core/data.py
4545
d8e9250f3775119df07e9070eddccd16 lib/core/replication.py
4646
785f86e3f963fa3798f84286a4e83ff2 lib/core/revision.py
4747
40c80b28b3a5819b737a5a17d4565ae9 lib/core/session.py
48-
c33fe4941f9d344d9100104b0a0e4abb lib/core/settings.py
48+
3d8c01162174b351f890ceb122fd9052 lib/core/settings.py
4949
d91291997d2bd2f6028aaf371bf1d3b6 lib/core/shell.py
5050
2ad85c130cc5f2b3701ea85c2f6bbf20 lib/core/subprocessng.py
5151
afd0636d2e93c23f4f0a5c9b6023ea17 lib/core/target.py
@@ -67,7 +67,7 @@ a0444cc351cd6d29015ad16d9eb46ff4 lib/parse/sitemap.py
6767
403d873f1d2fd0c7f73d83f104e41850 lib/request/basicauthhandler.py
6868
0035612a620934d7ebe6d18426cfb065 lib/request/basic.py
6969
ef48de622b0a6b4a71df64b0d2785ef8 lib/request/comparison.py
70-
a4e3e939d059bb604309f5089c78c1dc lib/request/connect.py
70+
46fe0392776e18fcc37bf08d2c3ce5e3 lib/request/connect.py
7171
fb6b788d0016ab4ec5e5f661f0f702ad lib/request/direct.py
7272
cc1163d38e9b7ee5db2adac6784c02bb lib/request/dns.py
7373
5dcdb37823a0b5eff65cd1018bcf09e4 lib/request/httpshandler.py

0 commit comments

Comments
 (0)