mirror of
https://github.com/sqlmapproject/sqlmap.git
synced 2025-12-09 06:01:29 +00:00
Another update for an Issue #352 and couple of fixes
This commit is contained in:
@@ -19,14 +19,13 @@ def tamper(payload, **kwargs):
|
||||
Double url-encodes all characters in a given payload (not processing
|
||||
already encoded)
|
||||
|
||||
Example:
|
||||
* Input: SELECT FIELD FROM%20TABLE
|
||||
* Output: %2553%2545%254c%2545%2543%2554%2520%2546%2549%2545%254c%2544%2520%2546%2552%254f%254d%2520%2554%2541%2542%254c%2545
|
||||
|
||||
Notes:
|
||||
* Useful to bypass some weak web application firewalls that do not
|
||||
double url-decode the request before processing it through their
|
||||
ruleset
|
||||
|
||||
>>> tamper('SELECT FIELD FROM%20TABLE')
|
||||
'%2553%2545%254C%2545%2543%2554%2520%2546%2549%2545%254C%2544%2520%2546%2552%254F%254D%2520%2554%2541%2542%254C%2545'
|
||||
"""
|
||||
|
||||
retVal = payload
|
||||
@@ -37,7 +36,7 @@ def tamper(payload, **kwargs):
|
||||
|
||||
while i < len(payload):
|
||||
if payload[i] == '%' and (i < len(payload) - 2) and payload[i + 1:i + 2] in string.hexdigits and payload[i + 2:i + 3] in string.hexdigits:
|
||||
retVal += payload[i:i + 3]
|
||||
retVal += '%%25%s' % payload[i + 1:i + 3]
|
||||
i += 3
|
||||
else:
|
||||
retVal += '%%25%.2X' % ord(payload[i])
|
||||
|
||||
Reference in New Issue
Block a user