mirror of
https://github.com/sqlmapproject/sqlmap.git
synced 2025-12-07 13:11:29 +00:00
Major enhancement to the engine to parse XML files and matches on DBMS banner
and HTTP response headers. Initial web application technology fingerprint (for the moment based only on X-Powered-By HTTP response header and not shown yet to the user). Minor layout adjustments.
This commit is contained in:
@@ -44,11 +44,24 @@ class BannerHandler(ContentHandler):
|
||||
def __init__(self, banner):
|
||||
self.__banner = sanitizeStr(banner)
|
||||
|
||||
self.__regexp = None
|
||||
self.__match = None
|
||||
self.__position = None
|
||||
self.__regexp = None
|
||||
self.__match = None
|
||||
self.__version = None
|
||||
|
||||
self.info = {}
|
||||
|
||||
def __feedInfo(self, key, value):
|
||||
value = sanitizeStr(value)
|
||||
|
||||
if value in ( None, "None" ):
|
||||
return
|
||||
|
||||
if key == "version":
|
||||
kb.bannerFp[key] = value
|
||||
else:
|
||||
if key not in kb.bannerFp.keys():
|
||||
kb.bannerFp[key] = set()
|
||||
|
||||
kb.bannerFp[key].add(value)
|
||||
|
||||
|
||||
def startElement(self, name, attrs):
|
||||
@@ -57,22 +70,23 @@ class BannerHandler(ContentHandler):
|
||||
self.__match = re.search(self.__regexp, self.__banner, re.I | re.M)
|
||||
|
||||
if name == "info" and self.__match:
|
||||
self.__position = sanitizeStr(attrs.get("version"))
|
||||
self.__feedInfo("type", attrs.get("type"))
|
||||
self.__feedInfo("distrib", attrs.get("distrib"))
|
||||
self.__feedInfo("release", attrs.get("release"))
|
||||
self.__feedInfo("codename", attrs.get("codename"))
|
||||
|
||||
self.__version = sanitizeStr(attrs.get("version"))
|
||||
self.__sp = sanitizeStr(attrs.get("sp"))
|
||||
|
||||
self.info['type'] = sanitizeStr(attrs.get("type"))
|
||||
self.info['distrib'] = sanitizeStr(attrs.get("distrib"))
|
||||
self.info['release'] = sanitizeStr(attrs.get("release"))
|
||||
self.info['codename'] = sanitizeStr(attrs.get("codename"))
|
||||
|
||||
if self.__position.isdigit():
|
||||
self.info['version'] = self.__match.group(int(self.__position))
|
||||
if self.__version.isdigit():
|
||||
self.__feedInfo("version", self.__match.group(int(self.__version)))
|
||||
|
||||
if self.__sp.isdigit():
|
||||
self.info['sp'] = "Service Pack %s" % self.__match.group(int(self.__sp))
|
||||
self.__feedInfo("sp", "Service Pack %s" % self.__match.group(int(self.__sp)))
|
||||
|
||||
self.__match = None
|
||||
self.__position = None
|
||||
self.__regexp = None
|
||||
self.__match = None
|
||||
self.__version = None
|
||||
|
||||
|
||||
class MSSQLBannerHandler(ContentHandler):
|
||||
@@ -90,7 +104,14 @@ class MSSQLBannerHandler(ContentHandler):
|
||||
self.__version = ""
|
||||
self.__servicePack = ""
|
||||
|
||||
self.info = {}
|
||||
|
||||
def __feedInfo(self, key, value):
|
||||
value = sanitizeStr(value)
|
||||
|
||||
if value in ( None, "None" ):
|
||||
return
|
||||
|
||||
kb.bannerFp[key] = value
|
||||
|
||||
|
||||
def startElement(self, name, attrs):
|
||||
@@ -114,9 +135,9 @@ class MSSQLBannerHandler(ContentHandler):
|
||||
def endElement(self, name):
|
||||
if name == "signature":
|
||||
if re.search(" %s[\.\ ]+" % self.__version, self.__banner):
|
||||
self.info['dbmsRelease'] = self.__release
|
||||
self.info['dbmsVersion'] = self.__version
|
||||
self.info['dbmsServicePack'] = self.__servicePack
|
||||
self.__feedInfo("dbmsRelease", self.__release)
|
||||
self.__feedInfo("dbmsVersion", self.__version)
|
||||
self.__feedInfo("dbmsServicePack", self.__servicePack)
|
||||
|
||||
self.__version = ""
|
||||
self.__servicePack = ""
|
||||
@@ -137,9 +158,6 @@ def bannerParser(banner):
|
||||
DBMS banner based upon the data in XML file
|
||||
"""
|
||||
|
||||
banner = sanitizeStr(banner)
|
||||
info = {}
|
||||
|
||||
if kb.dbms == "Microsoft SQL Server":
|
||||
xmlfile = paths.MSSQL_XML
|
||||
elif kb.dbms == "MySQL":
|
||||
@@ -154,24 +172,9 @@ def bannerParser(banner):
|
||||
if kb.dbms == "Microsoft SQL Server":
|
||||
handler = MSSQLBannerHandler(banner)
|
||||
parse(xmlfile, handler)
|
||||
info = handler.info
|
||||
|
||||
handler = BannerHandler(banner)
|
||||
parse(paths.GENERIC_XML, handler)
|
||||
|
||||
for title, value in handler.info.items():
|
||||
info[title] = value
|
||||
else:
|
||||
handler = BannerHandler(banner)
|
||||
parse(xmlfile, handler)
|
||||
info = handler.info
|
||||
|
||||
if "type" not in info or info["type"] == "None":
|
||||
parse(paths.GENERIC_XML, handler)
|
||||
info["type"] = handler.info["type"]
|
||||
|
||||
if "distrib" not in info or info["distrib"] == "None":
|
||||
parse(paths.GENERIC_XML, handler)
|
||||
info["distrib"] = handler.info["distrib"]
|
||||
|
||||
return info
|
||||
parse(paths.GENERIC_XML, handler)
|
||||
|
||||
@@ -26,10 +26,68 @@ Franklin St, Fifth Floor, Boston, MA 02110-1301 USA
|
||||
|
||||
import re
|
||||
|
||||
from xml.sax import parse
|
||||
from xml.sax.handler import ContentHandler
|
||||
|
||||
from lib.core.common import checkFile
|
||||
from lib.core.common import sanitizeStr
|
||||
from lib.core.data import kb
|
||||
from lib.core.data import paths
|
||||
from lib.parse.banner import BannerHandler
|
||||
|
||||
|
||||
class HeadersHandler(ContentHandler):
|
||||
"""
|
||||
This class defines methods to parse and extract information from
|
||||
the given HTTP header based upon the data in XML file
|
||||
"""
|
||||
|
||||
def __init__(self, header):
|
||||
self.__header = sanitizeStr(header)
|
||||
|
||||
self.__regexp = None
|
||||
self.__match = None
|
||||
self.__techVersion = None
|
||||
|
||||
|
||||
def __feedInfo(self, key, value):
|
||||
value = sanitizeStr(value)
|
||||
|
||||
if value in ( None, "None" ):
|
||||
return
|
||||
|
||||
if key == "techVersion":
|
||||
kb.headersFp[key] = value
|
||||
else:
|
||||
if key not in kb.headersFp.keys():
|
||||
kb.headersFp[key] = set()
|
||||
|
||||
kb.headersFp[key].add(value)
|
||||
|
||||
|
||||
def startElement(self, name, attrs):
|
||||
if name == "regexp":
|
||||
self.__regexp = sanitizeStr(attrs.get("value"))
|
||||
self.__match = re.search(self.__regexp, self.__header, re.I | re.M)
|
||||
|
||||
if name == "info" and self.__match:
|
||||
self.__feedInfo("type", attrs.get("type"))
|
||||
self.__feedInfo("distrib", attrs.get("distrib"))
|
||||
self.__feedInfo("release", attrs.get("release"))
|
||||
self.__feedInfo("codename", attrs.get("codename"))
|
||||
self.__feedInfo("technology", attrs.get("codename"))
|
||||
|
||||
self.__techVersion = sanitizeStr(attrs.get("tech_version"))
|
||||
self.__sp = sanitizeStr(attrs.get("sp"))
|
||||
|
||||
if self.__techVersion.isdigit():
|
||||
self.__feedInfo("techVersion", self.__match.group(int(self.__techVersion)))
|
||||
|
||||
if self.__sp.isdigit():
|
||||
self.__feedInfo("sp", "Service Pack %s" % self.__match.group(int(self.__sp)))
|
||||
|
||||
self.__regexp = None
|
||||
self.__match = None
|
||||
self.__techVersion = None
|
||||
|
||||
|
||||
def headersParser(headers):
|
||||
@@ -39,17 +97,23 @@ def headersParser(headers):
|
||||
and the web application technology
|
||||
"""
|
||||
|
||||
topHeaders = (
|
||||
"cookie",
|
||||
"microsoftsharepointteamservices",
|
||||
"server",
|
||||
"servlet-engine",
|
||||
"www-authenticate",
|
||||
"x-aspnet-version",
|
||||
"x-powered-by",
|
||||
)
|
||||
# TODO: ahead here
|
||||
topHeaders = {
|
||||
#"cookie": "%s/cookie.xml" % paths.SQLMAP_XML_BANNER_PATH,
|
||||
#"microsoftsharepointteamservices": "%s/microsoftsharepointteamservices.xml" % paths.SQLMAP_XML_BANNER_PATH,
|
||||
#"server": "%s/server.xml" % paths.SQLMAP_XML_BANNER_PATH,
|
||||
#"servlet-engine": "%s/servlet-engine.xml" % paths.SQLMAP_XML_BANNER_PATH,
|
||||
#"set-cookie": "%s/cookie.xml" % paths.SQLMAP_XML_BANNER_PATH,
|
||||
#"www-authenticate": "%s/www-authenticate.xml" % paths.SQLMAP_XML_BANNER_PATH,
|
||||
#"x-aspnet-version": "%s/x-aspnet-version.xml" % paths.SQLMAP_XML_BANNER_PATH,
|
||||
"x-powered-by": "%s/x-powered-by.xml" % paths.SQLMAP_XML_BANNER_PATH,
|
||||
}
|
||||
|
||||
for header in headers:
|
||||
if header in topHeaders:
|
||||
# TODO: fill me
|
||||
pass
|
||||
if header in topHeaders.keys():
|
||||
value = headers[header]
|
||||
xmlfile = topHeaders[header]
|
||||
checkFile(xmlfile)
|
||||
handler = HeadersHandler(value)
|
||||
parse(xmlfile, handler)
|
||||
parse(paths.GENERIC_XML, handler)
|
||||
|
||||
Reference in New Issue
Block a user