Accept [RANDNUM] as <char> in payloads.xml and handle it accordingly

This commit is contained in:
Bernardo Damele
2011-04-07 11:10:35 +00:00
parent ca009e9fe2
commit c6b9d89d31
2 changed files with 4 additions and 1 deletions

View File

@@ -94,6 +94,9 @@ def checkSqlInjection(place, parameter, value):
if "[CHAR]" in title:
title = title.replace("[CHAR]", conf.uChar)
if "[RANDNUM]" in title:
title = title.replace("[RANDNUM]", "random number")
# Skip test if the user's wants to test only for a specific
# technique
if conf.tech and isinstance(conf.tech, list) and stype not in conf.tech: