From 0a620bf322dfa0e6964457a025ef02a3333c5247 Mon Sep 17 00:00:00 2001 From: Miroslav Stampar Date: Fri, 3 Jun 2011 15:43:50 +0000 Subject: [PATCH] more info to the user --- lib/controller/checks.py | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/lib/controller/checks.py b/lib/controller/checks.py index 267a903f5..b36c2b3f5 100644 --- a/lib/controller/checks.py +++ b/lib/controller/checks.py @@ -501,6 +501,12 @@ def checkSqlInjection(place, parameter, value): # Return the injection object if injection.place is not None and injection.parameter is not None: + if not conf.dropSetCookie and PAYLOAD.TECHNIQUE.BOOLEAN in injection.data and injection.data[PAYLOAD.TECHNIQUE.BOOLEAN].vector.startswith('OR'): + warnMsg = "in cases like this (OR boolean) please consider usage " + warnMsg += "of switch --drop-set-cookie if you experience any " + warnMsg += "problems during data retrieval" + logger.warn(warnMsg) + injection = checkFalsePositives(injection) return injection else: