sqlmap-users Mailing List for sqlmap (Page 48)
Brought to you by:
inquisb
You can subscribe to this list here.
2008 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
(4) |
Oct
(11) |
Nov
(24) |
Dec
(13) |
---|---|---|---|---|---|---|---|---|---|---|---|---|
2009 |
Jan
(23) |
Feb
(17) |
Mar
(13) |
Apr
(48) |
May
(22) |
Jun
(18) |
Jul
(22) |
Aug
(13) |
Sep
(23) |
Oct
(6) |
Nov
(11) |
Dec
(25) |
2010 |
Jan
(21) |
Feb
(33) |
Mar
(61) |
Apr
(47) |
May
(48) |
Jun
(30) |
Jul
(24) |
Aug
(37) |
Sep
(52) |
Oct
(59) |
Nov
(32) |
Dec
(57) |
2011 |
Jan
(166) |
Feb
(93) |
Mar
(65) |
Apr
(117) |
May
(87) |
Jun
(124) |
Jul
(102) |
Aug
(78) |
Sep
(65) |
Oct
(22) |
Nov
(71) |
Dec
(79) |
2012 |
Jan
(93) |
Feb
(55) |
Mar
(45) |
Apr
(49) |
May
(56) |
Jun
(93) |
Jul
(95) |
Aug
(42) |
Sep
(26) |
Oct
(36) |
Nov
(32) |
Dec
(46) |
2013 |
Jan
(36) |
Feb
(78) |
Mar
(38) |
Apr
(57) |
May
(35) |
Jun
(39) |
Jul
(23) |
Aug
(33) |
Sep
(28) |
Oct
(38) |
Nov
(22) |
Dec
(16) |
2014 |
Jan
(33) |
Feb
(23) |
Mar
(41) |
Apr
(29) |
May
(12) |
Jun
(20) |
Jul
(21) |
Aug
(23) |
Sep
(18) |
Oct
(34) |
Nov
(12) |
Dec
(39) |
2015 |
Jan
(2) |
Feb
(51) |
Mar
(10) |
Apr
(28) |
May
(9) |
Jun
(22) |
Jul
(32) |
Aug
(35) |
Sep
(29) |
Oct
(50) |
Nov
(8) |
Dec
(2) |
2016 |
Jan
(8) |
Feb
(2) |
Mar
(3) |
Apr
(14) |
May
|
Jun
|
Jul
|
Aug
(12) |
Sep
|
Oct
|
Nov
(1) |
Dec
(19) |
2017 |
Jan
|
Feb
(18) |
Mar
|
Apr
(1) |
May
|
Jun
|
Jul
|
Aug
(4) |
Sep
|
Oct
|
Nov
(2) |
Dec
|
2018 |
Jan
|
Feb
|
Mar
(1) |
Apr
(1) |
May
(3) |
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
2019 |
Jan
|
Feb
|
Mar
|
Apr
(3) |
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
From: Bernardo D. A. G. <ber...@gm...> - 2012-11-09 13:54:17
|
yo broder, sup? this field not 4 all, g0 play with wii witch yo understand bettar plz On 9 November 2012 13:52, manupriya hasija <man...@gm...> wrote: > hey > m new to dis field,but have an urgency touse and understand this tool > so plz guide me from the start,i dnt even 9 hw to install it > i didnt get the exe file for it > plz guide me > > > ------------------------------------------------------------------------------ > Everyone hates slow websites. So do we. > Make your web apps faster with AppDynamics > Download AppDynamics Lite for free today: > http://p.sf.net/sfu/appdyn_d2d_nov > _______________________________________________ > sqlmap-users mailing list > sql...@li... > https://lists.sourceforge.net/lists/listinfo/sqlmap-users > > -- Bernardo Damele A. G. E-mail / Jabber: bernardo.damele (at) gmail.com Mobile: +447788962949 (UK 07788962949) |
From: manupriya h. <man...@gm...> - 2012-11-09 13:52:06
|
hey m new to dis field,but have an urgency touse and understand this tool so plz guide me from the start,i dnt even 9 hw to install it i didnt get the exe file for it plz guide me |
From: Luka P. <lu...@pu...> - 2012-11-08 05:28:08
|
Have you (or a program) modified sqlmap's files? Try to update it with git directly or just redownload the whole thing. On Thu, Nov 8, 2012 at 5:31 AM, root <ro...@cn...> wrote: > ** **** ************ > > hi,all > i don't konw this error why? > > sqlmap.py --update > > > [12:26:00] [INFO] updating sqlmap to the latest development version from the Git > Hub repository > [12:26:00] [INFO] update in progress .... > > [12:26:04] [ERROR] update could not be completed ('From git github com sqlmappro > > ject sqlmap branch HEAD FETCH_HEAD error Your local changes to the following fil > > es would be overwritten by merge _sqlmap py doc THANKS md lib controller checks > > py lib controller controller py lib core agent py lib core common py lib core co > > nvert py lib core enums py lib core option py lib core settings py lib core targ > > et py lib core wordlist py lib parse cmdline py lib request basic py lib request > > connect py lib request inject py lib takeover icmpsh py lib takeover metasploit > > py lib takeover udf py lib takeover web py lib takeover xp_cmdshell py lib tech > > niques blind inference py lib techniques union test py lib techniques union use > > py lib utils checkpayload py lib utils crawler py lib utils google py lib utils > > hash py lib utils pivotdumptable py plugins dbms access connector py plugins dbm > > s access enumeration py plugins dbms db2 connector py plugins dbms firebird conn > > ector py plugins dbms firebird enumeration py plugins dbms mssqlserver connector > > py plugins dbms mssqlserver enumeration py plugins dbms mssqlserver filesystem > > py plugins dbms mysql connector py plugins dbms oracle connector py plugins dbms > > oracle enumeration py plugins dbms postgresql enumeration py plugins dbms postg > > resql syntax py plugins dbms sqlite connector py plugins dbms sqlite enumeration > > py plugins dbms sybase connector py plugins generic databases py plugins generi > > c entries py plugins generic misc py plugins generic search py plugins generic u > > sers py procs mysql write_file_limit sql sqlmap conf tamper apostrophemask py ta > > mper apostrophenullencode py tamper appendnullbyte py tamper base64encode py tam > > per between py tamper chardoubleencode py tamper charencode py tamper charunicod > > eencode py tamper equaltolike py tamper halfversionedmorekeywords py tamper ifnu > > ll2ifisnull py tamper modsecurityversioned py tamper modsecurityzeroversioned py > > tamper multiplespaces py tamper nonrecursivereplacement py tamper percentage py > > tamper randomcase py tamper randomcomments py tamper securesphere py tamper sp_ > > password py tamper space2comment py tamper space2dash py tamper space2hash py ta > > mper space2morehash py tamper space2mssqlblank py tamper space2mssqlhash py tamp > > er space2mysqlblank py tamper space2mysqldash py tamper space2plus py tamper spa > > ce2randomblank py tamper unionalltounion py tamper unmagicquotes py tamper versi > > onedkeywords py tamper versionedmorekeywords py thirdparty multipart multipartpo > > st py xml queries xml Please commit your changes or stash them before you can me > rge Aborting') > > [12:26:04] [INFO] for Windows platform it's recommended to use a GitHub for Wind > ows client for updating purposes (http://windows.github.com/ > ) or just download t > he latest snapshot from https://github.com/sqlmapproject/sqlmap/downloads > > > > > thanks&Best > Regards > > > ------------------------------------------------------------------------------ > Everyone hates slow websites. So do we. > Make your web apps faster with AppDynamics > Download AppDynamics Lite for free today: > http://p.sf.net/sfu/appdyn_d2d_nov > _______________________________________________ > sqlmap-users mailing list > sql...@li... > https://lists.sourceforge.net/lists/listinfo/sqlmap-users > > |
From: root <ro...@cn...> - 2012-11-08 04:31:50
|
hi,all i don't konw this error why? sqlmap.py --update [12:26:00] [INFO] updating sqlmap to the latest development version from the Git Hub repository [12:26:00] [INFO] update in progress .... [12:26:04] [ERROR] update could not be completed ('From git github com sqlmappro ject sqlmap branch HEAD FETCH_HEAD error Your local changes to the following fil es would be overwritten by merge _sqlmap py doc THANKS md lib controller checks py lib controller controller py lib core agent py lib core common py lib core co nvert py lib core enums py lib core option py lib core settings py lib core targ et py lib core wordlist py lib parse cmdline py lib request basic py lib request connect py lib request inject py lib takeover icmpsh py lib takeover metasploit py lib takeover udf py lib takeover web py lib takeover xp_cmdshell py lib tech niques blind inference py lib techniques union test py lib techniques union use py lib utils checkpayload py lib utils crawler py lib utils google py lib utils hash py lib utils pivotdumptable py plugins dbms access connector py plugins dbm s access enumeration py plugins dbms db2 connector py plugins dbms firebird conn ector py plugins dbms firebird enumeration py plugins dbms mssqlserver connector py plugins dbms mssqlserver enumeration py plugins dbms mssqlserver filesystem py plugins dbms mysql connector py plugins dbms oracle connector py plugins dbms oracle enumeration py plugins dbms postgresql enumeration py plugins dbms postg resql syntax py plugins dbms sqlite connector py plugins dbms sqlite enumeration py plugins dbms sybase connector py plugins generic databases py plugins generi c entries py plugins generic misc py plugins generic search py plugins generic u sers py procs mysql write_file_limit sql sqlmap conf tamper apostrophemask py ta mper apostrophenullencode py tamper appendnullbyte py tamper base64encode py tam per between py tamper chardoubleencode py tamper charencode py tamper charunicod eencode py tamper equaltolike py tamper halfversionedmorekeywords py tamper ifnu ll2ifisnull py tamper modsecurityversioned py tamper modsecurityzeroversioned py tamper multiplespaces py tamper nonrecursivereplacement py tamper percentage py tamper randomcase py tamper randomcomments py tamper securesphere py tamper sp_ password py tamper space2comment py tamper space2dash py tamper space2hash py ta mper space2morehash py tamper space2mssqlblank py tamper space2mssqlhash py tamp er space2mysqlblank py tamper space2mysqldash py tamper space2plus py tamper spa ce2randomblank py tamper unionalltounion py tamper unmagicquotes py tamper versi onedkeywords py tamper versionedmorekeywords py thirdparty multipart multipartpo st py xml queries xml Please commit your changes or stash them before you can me rge Aborting') [12:26:04] [INFO] for Windows platform it's recommended to use a GitHub for Wind ows client for updating purposes (http://windows.github.com/) or just download t he latest snapshot from https://github.com/sqlmapproject/sqlmap/downloads thanks&Best Regards |
From: Miroslav S. <mir...@gm...> - 2012-10-28 21:31:12
|
Hi. You are using fairly outdated version. Please update to the latest revision and retry it again. You can visit our official homepage at http://sqlmap.org/ and read under "Download" section for more instructions. Kind regards, Miroslav Stampar On Sat, Oct 27, 2012 at 9:09 AM, Võ Hoàng Bảo Ngọc <tao...@gm...>wrote: > I have problem with sql-map when i try to use my wordlist to crack > password and this is the report: > > sqlmap version: 1.0-dev (r4766) > Python version: 2.6.5 > Operating system: posix > Command line: ./sqlmap.py -u > ************************************************* -D **** -T ********* > --dump > Technique: ERROR > Back-end DBMS: MySQL (fingerprinted) > Traceback (most recent call last): > File "/pentest/database/sqlmap/_sqlmap.py", line 83, in main > start() > File "/pentest/database/sqlmap/lib/controller/controller.py", line 565, > in start > action() > File "/pentest/database/sqlmap/lib/controller/action.py", line 109, in > action > conf.dbmsHandler.dumpTable() > File "/pentest/database/sqlmap/plugins/generic/enumeration.py", line > 1761, in dumpTable > attackDumpedTable() > File "/pentest/database/sqlmap/lib/utils/hash.py", line 375, in > attackDumpedTable > results = dictionaryAttack(attack_dict) > File "/pentest/database/sqlmap/lib/utils/hash.py", line 638, in > dictionaryAttack > dictPaths = getFileItems(listPath) > File "/pentest/database/sqlmap/lib/core/common.py", line 1753, in > getFileItems > with codecs.open(filename, 'r', UNICODE_ENCODING) if unicode_ else > open(filename, 'r') as f: > File "/usr/lib/python2.6/codecs.py", line 870, in open > file = __builtin__.open(filename, mode, buffering) > IOError: [Errno 21] Is a directory: '/wordlist' > > Please help me to resolve the problem > > > ------------------------------------------------------------------------------ > WINDOWS 8 is here. > Millions of people. Your app in 30 days. > Visit The Windows 8 Center at Sourceforge for all your go to resources. > http://windows8center.sourceforge.net/ > join-generation-app-and-make-money-coding-fast/ > _______________________________________________ > sqlmap-users mailing list > sql...@li... > https://lists.sourceforge.net/lists/listinfo/sqlmap-users > > -- Miroslav Stampar http://about.me/stamparm |
From: Võ H. B. N. <tao...@gm...> - 2012-10-27 07:09:35
|
I have problem with sql-map when i try to use my wordlist to crack password and this is the report: sqlmap version: 1.0-dev (r4766) Python version: 2.6.5 Operating system: posix Command line: ./sqlmap.py -u ************************************************* -D **** -T ********* --dump Technique: ERROR Back-end DBMS: MySQL (fingerprinted) Traceback (most recent call last): File "/pentest/database/sqlmap/_sqlmap.py", line 83, in main start() File "/pentest/database/sqlmap/lib/controller/controller.py", line 565, in start action() File "/pentest/database/sqlmap/lib/controller/action.py", line 109, in action conf.dbmsHandler.dumpTable() File "/pentest/database/sqlmap/plugins/generic/enumeration.py", line 1761, in dumpTable attackDumpedTable() File "/pentest/database/sqlmap/lib/utils/hash.py", line 375, in attackDumpedTable results = dictionaryAttack(attack_dict) File "/pentest/database/sqlmap/lib/utils/hash.py", line 638, in dictionaryAttack dictPaths = getFileItems(listPath) File "/pentest/database/sqlmap/lib/core/common.py", line 1753, in getFileItems with codecs.open(filename, 'r', UNICODE_ENCODING) if unicode_ else open(filename, 'r') as f: File "/usr/lib/python2.6/codecs.py", line 870, in open file = __builtin__.open(filename, mode, buffering) IOError: [Errno 21] Is a directory: '/wordlist' Please help me to resolve the problem |
From: Miroslav S. <mir...@gm...> - 2012-10-24 21:01:08
|
Hi Nico. Thank you for your report and find it fixed with the latest commit [1]. Kind regards, Miroslav Stampar [1] https://github.com/sqlmapproject/sqlmap/issues/216 On Wed, Oct 24, 2012 at 8:48 AM, Nico Montezco <ro...@ma...> wrote: > Hello friends, doing an analysis to a system based on JSP, Apache 2.4.1 and > Oracle 10g Enterprise Edition Release 10.2.0.4.0 64-bit; sqlmap gave me > the following error: > > > *[02:40:27] [CRITICAL] unhandled exception in sqlmap/1.0-dev-8b57e1f, > retry your run with the latest development version from the GitHub > repository. If the exception persists, please send by e-mail to ' > sql...@li...' or open a new issue at ' > https://github.com/sqlmapproject/sqlmap/issues/new' with the following > text and any information required to reproduce the bug. The developers will > try to reproduce the bug, fix it accordingly and get back to you. > sqlmap version: 1.0-dev-8b57e1f > Python version: 2.6.5 > Operating system: posix > Command line: ./sqlmap.py -u > ************************************************************* -a > --dbms=oracle > Technique: UNION > Back-end DBMS: Oracle (fingerprinted) > * > Traceback (most recent call last): > File "/pentest/database/sqlmap/_sqlmap.py", line 72, in main > start() > File "/pentest/database/sqlmap/lib/controller/controller.py", line 567, > in start > action() > File "/pentest/database/sqlmap/lib/controller/action.py", line 99, in > action > conf.dbmsHandler.getRoles(), "role") > File "/pentest/database/sqlmap/plugins/dbms/oracle/enumeration.py", line > 62, in getRoles > return self.getRoles(query2=True) > File "/pentest/database/sqlmap/plugins/dbms/oracle/enumeration.py", line > 81, in getRoles > if self.__isAdminFromPrivileges(roles): > AttributeError: OracleMap instance has no attribute > '_Enumeration__isAdminFromPrivileges' > > [*] shutting down at 02:40:27 > > > I wonder if I've done something wrong or is a program error ... Whatever > the problem I would love to explain it to me and tell me how to fix it. The > command I use is: > > *./sqlmap.py -u http://localhost/webserver/inicio.jsp?previo=2 -a > --dbms=oracle* > > > Excuse my English is very bad I hope I have understood.... > > I await your response grateful > > atte > > Nico Montezco. > > > > ------------------------------------------------------------------------------ > Everyone hates slow websites. So do we. > Make your web apps faster with AppDynamics > Download AppDynamics Lite for free today: > http://p.sf.net/sfu/appdyn_sfd2d_oct > _______________________________________________ > sqlmap-users mailing list > sql...@li... > https://lists.sourceforge.net/lists/listinfo/sqlmap-users > > -- Miroslav Stampar http://about.me/stamparm |
From: Miroslav S. <mir...@gm...> - 2012-10-24 20:50:24
|
Hi Joshua. This was fixed yesterday [1]. Please update to the latest revision and try it again. Kind regards, Miroslav Stampar [1] https://github.com/sqlmapproject/sqlmap/issues/214 On Wed, Oct 24, 2012 at 7:36 AM, Joshua Rogers <meg...@gm...> wrote: > [16:35:30] [CRITICAL] unhandled exception in sqlmap/1.0-dev-f11a640, > retry your run with the latest development version from the GitHub > repository. If the exception persists, please send by e-mail to > 'sql...@li...' or open a new issue at > 'https://github.com/sqlmapproject/sqlmap/issues/new' with the following > text and any information required to reproduce the bug. The developers > will try to reproduce the bug, fix it accordingly and get back to you. > sqlmap version: 1.0-dev-f11a640 > Python version: 2.6.5 > Operating system: posix > Command line: ./sqlmap.py --random-agent -u > **************************************************** > > --data=quantity[]=1&category_id=&product_id=347&prod_id[]=347&page=shop.cart&func=cartadd&Itemid=4&option=com_virtuemart&set_price[]=&adjust_price[]=&master_product[]= > --time-sec=1 --predict-output --hex --no-cast --dbs > Technique: TIME > Back-end DBMS: MySQL (fingerprinted) > Traceback (most recent call last): > File "/home/toil/sqlmap/_sqlmap.py", line 72, in main > start() > File "/home/toil/sqlmap/lib/controller/controller.py", line 568, in start > action() > File "/home/toil/sqlmap/lib/controller/action.py", line 106, in action > conf.dumper.dbs(conf.dbmsHandler.getDbs()) > File "/home/toil/sqlmap/plugins/generic/databases.py", line 135, in > getDbs > db = inject.getValue(query, inband=False, error=False) > File "/home/toil/sqlmap/lib/request/inject.py", line 437, in getValue > value = __goInferenceProxy(query, fromUser, batch, unpack, > charsetType, firstChar, lastChar, dump) > File "/home/toil/sqlmap/lib/request/inject.py", line 317, in > __goInferenceProxy > outputs = __goInferenceFields(expression, expressionFields, > expressionFieldsList, payload, charsetType=charsetType, > firstChar=firstChar, lastChar=lastChar, dump=dump) > File "/home/toil/sqlmap/lib/request/inject.py", line 116, in > __goInferenceFields > output = __goInference(payload, expressionReplaced, charsetType, > firstChar, lastChar, dump) > File "/home/toil/sqlmap/lib/request/inject.py", line 88, in __goInference > count, value = bisection(payload, expression, length, charsetType, > firstChar, lastChar, dump) > File "/home/toil/sqlmap/lib/techniques/blind/inference.py", line 538, > in bisection > infoMsg = "\r[%s] [INFO] retrieved: %s %s\n" % > (time.strftime("%X"), filterControlChars(finalValue), " " * > len(finalValue)) > TypeError: object of type 'NoneType' has no len() > > [*] shutting down at 16:35:30 > > > > > Error was: http://www.gametraders.com.au/online-store/index.php > > > > > ------------------------------------------------------------------------------ > Everyone hates slow websites. So do we. > Make your web apps faster with AppDynamics > Download AppDynamics Lite for free today: > http://p.sf.net/sfu/appdyn_sfd2d_oct > _______________________________________________ > sqlmap-users mailing list > sql...@li... > https://lists.sourceforge.net/lists/listinfo/sqlmap-users > -- Miroslav Stampar http://about.me/stamparm |
From: Nico M. <ro...@ma...> - 2012-10-24 06:48:49
|
Hello friends, doing an analysis to a system based on JSP, Apache 2.4.1 and Oracle 10g Enterprise Edition Release 10.2.0.4.0 64-bit; sqlmap gave me the following error: [02:40:27] [CRITICAL] unhandled exception in sqlmap/1.0-dev-8b57e1f, retry your run with the latest development version from the GitHub repository. If the exception persists, please send by e-mail to 'sql...@li...' or open a new issue at 'https://github.com/sqlmapproject/sqlmap/issues/new' with the following text and any information required to reproduce the bug. The developers will try to reproduce the bug, fix it accordingly and get back to you. sqlmap version: 1.0-dev-8b57e1f Python version: 2.6.5 Operating system: posix Command line: ./sqlmap.py -u ************************************************************* -a --dbms=oracle Technique: UNION Back-end DBMS: Oracle (fingerprinted) Traceback (most recent call last): File "/pentest/database/sqlmap/_sqlmap.py", line 72, in main start() File "/pentest/database/sqlmap/lib/controller/controller.py", line 567, in start action() File "/pentest/database/sqlmap/lib/controller/action.py", line 99, in action conf.dbmsHandler.getRoles(), "role") File "/pentest/database/sqlmap/plugins/dbms/oracle/enumeration.py", line 62, in getRoles return self.getRoles(query2=True) File "/pentest/database/sqlmap/plugins/dbms/oracle/enumeration.py", line 81, in getRoles if self.__isAdminFromPrivileges(roles): AttributeError: OracleMap instance has no attribute '_Enumeration__isAdminFromPrivileges' [*] shutting down at 02:40:27 I wonder if I've done something wrong or is a program error ... Whatever the problem I would love to explain it to me and tell me how to fix it. The command I use is: ./sqlmap.py -u http://localhost/webserver/inicio.jsp?previo=2 -a --dbms=oracle Excuse my English is very bad I hope I have understood.... I await your response grateful atte Nico Montezco. |
From: Joshua R. <meg...@gm...> - 2012-10-24 05:37:07
|
[16:35:30] [CRITICAL] unhandled exception in sqlmap/1.0-dev-f11a640, retry your run with the latest development version from the GitHub repository. If the exception persists, please send by e-mail to 'sql...@li...' or open a new issue at 'https://github.com/sqlmapproject/sqlmap/issues/new' with the following text and any information required to reproduce the bug. The developers will try to reproduce the bug, fix it accordingly and get back to you. sqlmap version: 1.0-dev-f11a640 Python version: 2.6.5 Operating system: posix Command line: ./sqlmap.py --random-agent -u **************************************************** --data=quantity[]=1&category_id=&product_id=347&prod_id[]=347&page=shop.cart&func=cartadd&Itemid=4&option=com_virtuemart&set_price[]=&adjust_price[]=&master_product[]= --time-sec=1 --predict-output --hex --no-cast --dbs Technique: TIME Back-end DBMS: MySQL (fingerprinted) Traceback (most recent call last): File "/home/toil/sqlmap/_sqlmap.py", line 72, in main start() File "/home/toil/sqlmap/lib/controller/controller.py", line 568, in start action() File "/home/toil/sqlmap/lib/controller/action.py", line 106, in action conf.dumper.dbs(conf.dbmsHandler.getDbs()) File "/home/toil/sqlmap/plugins/generic/databases.py", line 135, in getDbs db = inject.getValue(query, inband=False, error=False) File "/home/toil/sqlmap/lib/request/inject.py", line 437, in getValue value = __goInferenceProxy(query, fromUser, batch, unpack, charsetType, firstChar, lastChar, dump) File "/home/toil/sqlmap/lib/request/inject.py", line 317, in __goInferenceProxy outputs = __goInferenceFields(expression, expressionFields, expressionFieldsList, payload, charsetType=charsetType, firstChar=firstChar, lastChar=lastChar, dump=dump) File "/home/toil/sqlmap/lib/request/inject.py", line 116, in __goInferenceFields output = __goInference(payload, expressionReplaced, charsetType, firstChar, lastChar, dump) File "/home/toil/sqlmap/lib/request/inject.py", line 88, in __goInference count, value = bisection(payload, expression, length, charsetType, firstChar, lastChar, dump) File "/home/toil/sqlmap/lib/techniques/blind/inference.py", line 538, in bisection infoMsg = "\r[%s] [INFO] retrieved: %s %s\n" % (time.strftime("%X"), filterControlChars(finalValue), " " * len(finalValue)) TypeError: object of type 'NoneType' has no len() [*] shutting down at 16:35:30 Error was: http://www.gametraders.com.au/online-store/index.php |
From: Miroslav S. <mir...@gm...> - 2012-10-23 07:46:48
|
Hi Iago. As Luka mentioned, there is not way how to bypass it. It's a irreversible conversion from one format to another. Kind regards, Miroslav Stampar On Sat, Oct 20, 2012 at 5:01 AM, Luka Pušić <lu...@pu...> wrote: > No. > > Best regards, > Luka > > On Fri, Oct 19, 2012 at 8:19 PM, Iago Sousa <146...@gm...> wrote: > >> Hello there, >> Is there a way to bypass cast to int in PHP? >> >> >> ------------------------------------------------------------------------------ >> Everyone hates slow websites. So do we. >> Make your web apps faster with AppDynamics >> Download AppDynamics Lite for free today: >> http://p.sf.net/sfu/appdyn_sfd2d_oct >> _______________________________________________ >> sqlmap-users mailing list >> sql...@li... >> https://lists.sourceforge.net/lists/listinfo/sqlmap-users >> >> > > > ------------------------------------------------------------------------------ > Everyone hates slow websites. So do we. > Make your web apps faster with AppDynamics > Download AppDynamics Lite for free today: > http://p.sf.net/sfu/appdyn_sfd2d_oct > _______________________________________________ > sqlmap-users mailing list > sql...@li... > https://lists.sourceforge.net/lists/listinfo/sqlmap-users > > -- Miroslav Stampar http://about.me/stamparm |
From: Miroslav S. <mir...@gm...> - 2012-10-23 07:45:48
|
Hi. In most of cases it's all about permissions or missing system tables containing desired information. Can't tell you anything specific without more information. Kind regards, Miroslav Stampar On Tue, Oct 23, 2012 at 6:17 AM, root <ro...@cn...> wrote: > ** ******** > why sqlmap always can not fetch the tables? > > like this > > i use the other tools,like havij,can fetch it,why this not? > > [12:13:58] [INFO] fetching number of tables for database 'test' > [12:13:58] [INFO] retrieving the length of query output > [12:13:58] [INFO] retrieved: > [12:13:59] [WARNING] reflective value(s) found and filtering out > > [12:14:02] [INFO] resumed: 0 > > [12:14:02] [WARNING] unable to retrieve the number of tables for database 'test' > [12:14:02] [ERROR] unable to retrieve the table names for any database > do you want to use common table existence check? [y/N/q] y > > [12:14:05] [WARNING] in case of continuous data retrieval problems you are advis > ed to try a switch '--no-cast' and/or switch '--hex' > > > > > thanks&Best > Regards > > > ------------------------------------------------------------------------------ > Everyone hates slow websites. So do we. > Make your web apps faster with AppDynamics > Download AppDynamics Lite for free today: > http://p.sf.net/sfu/appdyn_sfd2d_oct > _______________________________________________ > sqlmap-users mailing list > sql...@li... > https://lists.sourceforge.net/lists/listinfo/sqlmap-users > > -- Miroslav Stampar http://about.me/stamparm |
From: root <ro...@cn...> - 2012-10-23 06:04:13
|
why sqlmap always can not fetch the tables? like this i use the other tools,like havij,can fetch it,why this not? [12:13:58] [INFO] fetching number of tables for database 'test' [12:13:58] [INFO] retrieving the length of query output [12:13:58] [INFO] retrieved: [12:13:59] [WARNING] reflective value(s) found and filtering out [12:14:02] [INFO] resumed: 0 [12:14:02] [WARNING] unable to retrieve the number of tables for database 'test' [12:14:02] [ERROR] unable to retrieve the table names for any database do you want to use common table existence check? [y/N/q] y [12:14:05] [WARNING] in case of continuous data retrieval problems you are advis ed to try a switch '--no-cast' and/or switch '--hex' thanks&Best Regards |
From: Luka P. <lu...@pu...> - 2012-10-20 03:01:09
|
No. Best regards, Luka On Fri, Oct 19, 2012 at 8:19 PM, Iago Sousa <146...@gm...> wrote: > Hello there, > Is there a way to bypass cast to int in PHP? > > > ------------------------------------------------------------------------------ > Everyone hates slow websites. So do we. > Make your web apps faster with AppDynamics > Download AppDynamics Lite for free today: > http://p.sf.net/sfu/appdyn_sfd2d_oct > _______________________________________________ > sqlmap-users mailing list > sql...@li... > https://lists.sourceforge.net/lists/listinfo/sqlmap-users > > |
From: Iago S. <146...@gm...> - 2012-10-19 18:19:42
|
Hello there, Is there a way to bypass cast to int in PHP? |
From: Miroslav S. <mir...@gm...> - 2012-10-13 07:42:56
|
Hi Geoff. Please try to connect with the openssl from the command line: openssl s_client www.site.com:443 Python SSL module uses OpenSSL bindings for connecting, so if it goes well, then something other could be a problem here. In that case sending us privately a site's url (you can strip all parameter values) could help us a lot in debugging this issue. Kind regards, Miroslav Stampar On Thu, Oct 11, 2012 at 5:48 PM, Geoff Jones <no...@0x...> wrote: > Hi, > > I'm having an issue connecting to one particular SSL enabled site. The > error being received is not related to SSL, though I have confirmed it is > not a UA/status code issue as the error suggests (tested via a connection > with curl - and it also works if going through a proxy): > > *[16:38:03] [CRITICAL] connection dropped or unknown HTTP status code > received. Try to force the HTTP User-Agent header with option > '--user-agent' or switch '--random-agent'. sqlmap is going to retry the > request* > > The only difference I can see between the sites, is the SSL ciphers that > they support. The supported ciphers are listed below (site2 is the one > causing problems - sqlmap works against site1): > > sslscan site1.local | grep -i accept > > Accepted SSLv3 128 bits AES128-SHA > Accepted SSLv3 128 bits RC4-SHA > Accepted SSLv3 128 bits RC4-MD5 > Accepted TLSv1 128 bits AES128-SHA > Accepted TLSv1 128 bits RC4-SHA > Accepted TLSv1 128 bits RC4-MD5 > sslscan site2.local | grep -i accept > Accepted SSLv3 168 bits EDH-RSA-DES-CBC3-SHA > Accepted SSLv3 168 bits DES-CBC3-SHA > Accepted SSLv3 128 bits RC4-SHA > Accepted TLSv1 256 bits AES256-SHA > Accepted TLSv1 168 bits EDH-RSA-DES-CBC3-SHA > Accepted TLSv1 168 bits DES-CBC3-SHA > Accepted TLSv1 128 bits RC4-SHA > > I have no idea where to start debugging this issue. Is it a Python issue, > an OpenSSL issue, sqlmap, or something else? > > Running Gentoo with Python 2.7 (have tried 2.6), and openssl-1.0.0j. I > very much suspect this is a problem with my build, though any pointers > would be most appreciated. > > Regards, > > Geoff > > > ------------------------------------------------------------------------------ > Don't let slow site performance ruin your business. Deploy New Relic APM > Deploy New Relic app performance management and know exactly > what is happening inside your Ruby, Python, PHP, Java, and .NET app > Try New Relic at no cost today and get our sweet Data Nerd shirt too! > http://p.sf.net/sfu/newrelic-dev2dev > _______________________________________________ > sqlmap-users mailing list > sql...@li... > https://lists.sourceforge.net/lists/listinfo/sqlmap-users > > -- Miroslav Stampar http://about.me/stamparm |
From: Geoff J. <no...@0x...> - 2012-10-11 16:18:52
|
Hi, I'm having an issue connecting to one particular SSL enabled site. The error being received is not related to SSL, though I have confirmed it is not a UA/status code issue as the error suggests (tested via a connection with curl - and it also works if going through a proxy): *[16:38:03] [CRITICAL] connection dropped or unknown HTTP status code received. Try to force the HTTP User-Agent header with option '--user-agent' or switch '--random-agent'. sqlmap is going to retry the request* The only difference I can see between the sites, is the SSL ciphers that they support. The supported ciphers are listed below (site2 is the one causing problems - sqlmap works against site1): sslscan site1.local | grep -i accept Accepted SSLv3 128 bits AES128-SHA Accepted SSLv3 128 bits RC4-SHA Accepted SSLv3 128 bits RC4-MD5 Accepted TLSv1 128 bits AES128-SHA Accepted TLSv1 128 bits RC4-SHA Accepted TLSv1 128 bits RC4-MD5 sslscan site2.local | grep -i accept Accepted SSLv3 168 bits EDH-RSA-DES-CBC3-SHA Accepted SSLv3 168 bits DES-CBC3-SHA Accepted SSLv3 128 bits RC4-SHA Accepted TLSv1 256 bits AES256-SHA Accepted TLSv1 168 bits EDH-RSA-DES-CBC3-SHA Accepted TLSv1 168 bits DES-CBC3-SHA Accepted TLSv1 128 bits RC4-SHA I have no idea where to start debugging this issue. Is it a Python issue, an OpenSSL issue, sqlmap, or something else? Running Gentoo with Python 2.7 (have tried 2.6), and openssl-1.0.0j. I very much suspect this is a problem with my build, though any pointers would be most appreciated. Regards, Geoff |
From: Miroslav S. <mir...@gm...> - 2012-10-11 12:37:13
|
Hi Daniel. If sqlmap is not able to detect stacked queries (like in your case), then it won't be able to use/exploit those commands from --sql-shell. Pretty simple. Just take a look into your list of "sqlmap identified the following injection points..." for that same target and if there are things like "boolean"/"time-based blind"... and no "stacked" then you have no luck. As you've said "stacked queries could be executed". If you want to be sure you can try to re-test the target with higher --time-sec. For example, python sqlmap.py -u .... --flush-session --time-sec=20. If that fails then you won't be able to use stacked queries as you've expected. Kind regards, Miroslav Stampar On Wed, Oct 10, 2012 at 4:52 PM, Daniel Calvo Castro < dan...@ke...> wrote: > Hi Miroslav, Bernardo, list members, > > As far I know ( please correct if i´m wrong ) reading a couple of > times Bernardo´s Damele Advanced SQL Injection whitepaper , Stacked > queries could be executed via Blind and MySQL with ASP.NET,but sqlmap > show me via sql-shell: > > web server operating system: Windows 2008 > web application technology: ASP.NET, Microsoft IIS 7.5, ASP > back-end DBMS: MySQL 5 > sql-shell> create database test2;create database test3;drop table test; > [16:10:32] [WARNING] execution of custom SQL queries is only available > when stacked queries are supported > > current-user of mysql is root with full privileges, the goal is to > create a temporary table via stacked queries also well described in > that great document, could someone point me in the right way? > > Thanks in advance > > > ------------------------------------------------------------------------------ > Don't let slow site performance ruin your business. Deploy New Relic APM > Deploy New Relic app performance management and know exactly > what is happening inside your Ruby, Python, PHP, Java, and .NET app > Try New Relic at no cost today and get our sweet Data Nerd shirt too! > http://p.sf.net/sfu/newrelic-dev2dev > _______________________________________________ > sqlmap-users mailing list > sql...@li... > https://lists.sourceforge.net/lists/listinfo/sqlmap-users > -- Miroslav Stampar http://about.me/stamparm |
From: Karel M. <rez...@se...> - 2012-10-10 18:15:24
|
Thank you, Miro, for patching. Regards Karel Marhoul On 9.10.2012 11:36, Miroslav Stampar wrote: > Hi Karel. > > This should be fixed now [1]. > > Kind regards, > Miroslav Stampar > > [1] https://github.com/sqlmapproject/sqlmap/issues/198 > > On Tue, Oct 9, 2012 at 11:04 AM, Karel Marhoul <rez...@se... > <mailto:rez...@se...>> wrote: > > I could confirm this behavior with these versions of burp: > > Burp Suite Proffesional 1.4.12 > Burp Suite Proffesional 1.5rc3 > > Patch would be appreciated. > > Regards > > Karel > > > On 9.10.2012 10:49, Miroslav Stampar wrote: > > Hi again. > > It's a preamble, but the request itself is down below. We process > requests, not preambles. As we need to support generic LOG > files, we are > "hunting" for requests itself. > > If somebody could confirm that Burp really strips any HTTPS > "tips" from > the requests and just puts those in preambles (like in your > case), I'll > gladly do the "patching". > > Kind regards, > Miroslav Stampar > > On Tue, Oct 9, 2012 at 10:44 AM, Karel Marhoul > <rez...@se... <mailto:rez...@se...> > <mailto:rez...@se... <mailto:rez...@se...>>> wrote: > > Hello Miroslav, there is a mention of port 443 in the request > "preamble", see: > > > > ==============================____======================== > > > 12:40:22 https://www.xxx.cz:443 [81.91.80.92] > > > ==============================____======================== > > > That specific request came from HTTPS page and landed > toward HTTP, > I'm sure of that. > > I suggest sqlmap log parser should first look at the port > in the > request preamble and then send the request to this port - > is that > possible to implement? > > Regards > > Karel > > On 9.10.2012 10:30, Miroslav Stampar wrote: > > Hi Karel. > > Strictly speaking there is no bug here. If you take a > look carefully > into the HTTP request inside you'll see that there is > no mention of > either HTTPS nor 443 inside the request itself. It > seems like the > request came from the https page (referer header), but > landed > toward the > HTTP land. > > I would suggest you to just try to append the :443 to > the Host > header > value (Host: www.xxx.cz <http://www.xxx.cz> > <http://www.xxx.cz> <http://www.xxx.cz> > > -> Host: www.xxx.cz:443 <http://www.xxx.cz:443> > <http://www.xxx.cz:443> > <http://www.xxx.cz:443>) > > Kind regards, > Miroslav Stampar > > On Sun, Oct 7, 2012 at 1:37 PM, Karel Marhoul > <rez...@se... <mailto:rez...@se...> > <mailto:rez...@se... <mailto:rez...@se...>> > <mailto:rez...@se... > <mailto:rez...@se...> <mailto:rez...@se... > <mailto:rez...@se...>>>__> wrote: > > Hello, I came across a bug while using sqlmap with -l > parameter. I have > burp log file with following content (only one > request to > https port): > > > ==============================____======================== > > 12:40:22 https://www.xxx.cz:443 [81.91.80.92] > > ==============================____======================== > GET > > > /index.php?option=com_thumber&____view=thumb&format=image&__path=__images/cups/web-xxx-__klub___ikona-spion.jpg&newX=__160&newY=__120 > HTTP/1.1 > Host: www.xxx.cz <http://www.xxx.cz> > <http://www.xxx.cz> <http://www.xxx.cz> > > User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; > rv:15.0) > Gecko/20100101 > Firefox/15.0.1 > Accept: image/png,image/*;q=0.8,*/*;q=____0.5 > > Accept-Language: en-us,en;q=0.5 > Accept-Encoding: gzip, deflate > Connection: keep-alive > Referer: https://www.xxx.cz/ > Cookie: > > __utma=148540003.1998141124.____1349164485.1349423437.____1349599213.20; > > > __utmz=148540003.1349164485.1.____1.utmcsr=(direct)|utmccn=(____direct)|utmcmd=(none); > theme_cookie=life; > > e6da1f1e61cfd387eff8fb21161379____6e=__3c29965kggoo45p49dhrs1npq0; > __utmc=148540003 > Cache-Control: max-age=0 > > > ==============================____======================== > > Then I start sqlmap this way: > > ./sqlmap.py -l /root/burp.log --batch --threads=10 > --scope=www.xxx.cz <http://www.xxx.cz> > <http://www.xxx.cz> <http://www.xxx.cz> > > > And sqlmap instead of sending request to https > (443) port > it will use > http (80) port instead: > > > ------------------------------____--------------------------- > > [13:21:55] [INFO] using regular expression > 'www.xxx.cz <http://www.xxx.cz> > <http://www.xxx.cz> > <http://www.xxx.cz>' for filtering > targets > [13:21:55] [INFO] sqlmap parsed 1 testable > requests from > the targets > list > [13:21:55] [INFO] url 1: > GET > http://www.xxx.cz:80/index.____php?option=com_thumber&view=____thumb&format=image&path=____images/cups/web-xxx-klub_____ikona-spion.jpg&newX=160&newY=____120 > <http://www.xxx.cz:80/index.__php?option=com_thumber&view=__thumb&format=image&path=__images/cups/web-xxx-klub___ikona-spion.jpg&newX=160&newY=__120> > > <http://www.xxx.cz:80/index.__php?option=com_thumber&view=__thumb&format=image&path=__images/cups/web-xxx-klub___ikona-spion.jpg&newX=160&newY=__120 > <http://www.xxx.cz:80/index.php?option=com_thumber&view=thumb&format=image&path=images/cups/web-xxx-klub_ikona-spion.jpg&newX=160&newY=120>> > Cookie: > > __utma=148540003.1998141124.____1349164485.1349423437.____1349599213.20; > > > __utmz=148540003.1349164485.1.____1.utmcsr=(direct)|utmccn=(____direct)|utmcmd=(none); > theme_cookie=life; > > e6da1f1e61cfd387eff8fb21161379____6e=__3c29965kggoo45p49dhrs1npq0; > __utmc=148540003 > do you want to test this url? [Y/n/q] > > Y > [snip] > > ------------------------------____--------------------------- > > > Could you please fix this? > > Regards > > Karel Marhoul > > > > ------------------------------____----------------------------__--__------------------ > > Don't let slow site performance ruin your > business. Deploy > New Relic APM > Deploy New Relic app performance management and > know exactly > what is happening inside your Ruby, Python, PHP, > Java, and > .NET app > Try New Relic at no cost today and get our sweet > Data Nerd > shirt too! > http://p.sf.net/sfu/newrelic-____dev2dev > <http://p.sf.net/sfu/newrelic-__dev2dev> > <http://p.sf.net/sfu/newrelic-__dev2dev > <http://p.sf.net/sfu/newrelic-dev2dev>> > ___________________________________________________ > sqlmap-users mailing list > sqlmap-users@lists.__sourcefor__ge.net > <http://sourceforge.net> > <mailto:sqlmap-users@lists.__sourceforge.net > <mailto:sql...@li...>> > <mailto:sqlmap-users@lists. > <mailto:sqlmap-users@lists.>__s__ourceforge.net > <http://sourceforge.net> > <mailto:sqlmap-users@lists.__sourceforge.net > <mailto:sql...@li...>>> > https://lists.sourceforge.net/____lists/listinfo/sqlmap-users > <https://lists.sourceforge.net/__lists/listinfo/sqlmap-users> > > <https://lists.sourceforge.__net/lists/listinfo/sqlmap-__users > <https://lists.sourceforge.net/lists/listinfo/sqlmap-users>> > > > > > -- > Miroslav Stampar > http://about.me/stamparm > > > > > > -- > Miroslav Stampar > http://about.me/stamparm > > > > > > -- > Miroslav Stampar > http://about.me/stamparm |
From: Daniel C. C. <dan...@ke...> - 2012-10-10 16:07:01
|
Hi Miroslav, Bernardo, list members, As far I know ( please correct if i´m wrong ) reading a couple of times Bernardo´s Damele Advanced SQL Injection whitepaper , Stacked queries could be executed via Blind and MySQL with ASP.NET,but sqlmap show me via sql-shell: web server operating system: Windows 2008 web application technology: ASP.NET, Microsoft IIS 7.5, ASP back-end DBMS: MySQL 5 sql-shell> create database test2;create database test3;drop table test; [16:10:32] [WARNING] execution of custom SQL queries is only available when stacked queries are supported current-user of mysql is root with full privileges, the goal is to create a temporary table via stacked queries also well described in that great document, could someone point me in the right way? Thanks in advance |
From: Dennis <kor...@ya...> - 2012-10-09 11:05:02
|
Cool, thanks for the patch! Cheers Am 09.10.2012 12:32, schrieb Miroslav Stampar: > Hi Dennis. > > From now on sqlmap should take into the consideration the preamble too > - It takes it as a first choice for scheme::port values (e.g. > https::443). In case that there are different values inside the > request body itself, specifically Host header, then those values have > higher priority. > > Kind regards, > Miroslav Stampar > > On Tue, Oct 9, 2012 at 11:41 AM, Dennis <kor...@ya... > <mailto:kor...@ya...>> wrote: > > Hey Miroslav, > > how did you fix this? Does sqlmap take the preamble into account? > Or how do you figure out, what is https and what's not? > > Regards, > Dennis > > > Am 09.10.2012 11:36, schrieb Miroslav Stampar: >> Hi Karel. >> >> This should be fixed now [1]. >> >> Kind regards, >> Miroslav Stampar >> >> [1] https://github.com/sqlmapproject/sqlmap/issues/198 >> >> On Tue, Oct 9, 2012 at 11:04 AM, Karel Marhoul >> <rez...@se... <mailto:rez...@se...>> wrote: >> >> I could confirm this behavior with these versions of burp: >> >> Burp Suite Proffesional 1.4.12 >> Burp Suite Proffesional 1.5rc3 >> >> Patch would be appreciated. >> >> Regards >> >> Karel >> >> >> On 9.10.2012 10:49, Miroslav Stampar wrote: >> >> Hi again. >> >> It's a preamble, but the request itself is down below. We >> process >> requests, not preambles. As we need to support generic >> LOG files, we are >> "hunting" for requests itself. >> >> If somebody could confirm that Burp really strips any >> HTTPS "tips" from >> the requests and just puts those in preambles (like in >> your case), I'll >> gladly do the "patching". >> >> Kind regards, >> Miroslav Stampar >> >> On Tue, Oct 9, 2012 at 10:44 AM, Karel Marhoul >> <rez...@se... <mailto:rez...@se...> >> <mailto:rez...@se... >> <mailto:rez...@se...>>> wrote: >> >> Hello Miroslav, there is a mention of port 443 in the >> request >> "preamble", see: >> >> > >> ==============================__======================== >> >> > 12:40:22 https://www.xxx.cz:443 [81.91.80.92] >> > >> ==============================__======================== >> >> >> That specific request came from HTTPS page and landed >> toward HTTP, >> I'm sure of that. >> >> I suggest sqlmap log parser should first look at the >> port in the >> request preamble and then send the request to this >> port - is that >> possible to implement? >> >> Regards >> >> Karel >> >> On 9.10.2012 10:30, Miroslav Stampar wrote: >> >> Hi Karel. >> >> Strictly speaking there is no bug here. If you >> take a look carefully >> into the HTTP request inside you'll see that >> there is no mention of >> either HTTPS nor 443 inside the request itself. >> It seems like the >> request came from the https page (referer >> header), but landed >> toward the >> HTTP land. >> >> I would suggest you to just try to append the >> :443 to the Host >> header >> value (Host: www.xxx.cz <http://www.xxx.cz> >> <http://www.xxx.cz> <http://www.xxx.cz> >> >> -> Host: www.xxx.cz:443 <http://www.xxx.cz:443> >> <http://www.xxx.cz:443> >> <http://www.xxx.cz:443>) >> >> Kind regards, >> Miroslav Stampar >> >> On Sun, Oct 7, 2012 at 1:37 PM, Karel Marhoul >> <rez...@se... >> <mailto:rez...@se...> >> <mailto:rez...@se... <mailto:rez...@se...>> >> <mailto:rez...@se... >> <mailto:rez...@se...> >> <mailto:rez...@se... >> <mailto:rez...@se...>>>> wrote: >> >> Hello, I came across a bug while using >> sqlmap with -l >> parameter. I have >> burp log file with following content (only >> one request to >> https port): >> >> >> ==============================__======================== >> >> 12:40:22 https://www.xxx.cz:443 [81.91.80.92] >> >> ==============================__======================== >> GET >> >> >> /index.php?option=com_thumber&__view=thumb&format=image&path=__images/cups/web-xxx-klub___ikona-spion.jpg&newX=160&newY=__120 >> HTTP/1.1 >> Host: www.xxx.cz <http://www.xxx.cz> >> <http://www.xxx.cz> <http://www.xxx.cz> >> >> User-Agent: Mozilla/5.0 (Windows NT 6.1; >> WOW64; rv:15.0) >> Gecko/20100101 >> Firefox/15.0.1 >> Accept: image/png,image/*;q=0.8,*/*;q=__0.5 >> >> Accept-Language: en-us,en;q=0.5 >> Accept-Encoding: gzip, deflate >> Connection: keep-alive >> Referer: https://www.xxx.cz/ >> Cookie: >> >> __utma=148540003.1998141124.__1349164485.1349423437.__1349599213.20; >> >> >> __utmz=148540003.1349164485.1.__1.utmcsr=(direct)|utmccn=(__direct)|utmcmd=(none); >> theme_cookie=life; >> >> e6da1f1e61cfd387eff8fb21161379__6e=3c29965kggoo45p49dhrs1npq0; >> __utmc=148540003 >> Cache-Control: max-age=0 >> >> >> ==============================__======================== >> >> Then I start sqlmap this way: >> >> ./sqlmap.py -l /root/burp.log --batch >> --threads=10 >> --scope=www.xxx.cz <http://www.xxx.cz> >> <http://www.xxx.cz> <http://www.xxx.cz> >> >> >> And sqlmap instead of sending request to >> https (443) port >> it will use >> http (80) port instead: >> >> >> ------------------------------__--------------------------- >> >> [13:21:55] [INFO] using regular expression >> 'www.xxx.cz <http://www.xxx.cz> >> <http://www.xxx.cz> >> <http://www.xxx.cz>' for filtering >> targets >> [13:21:55] [INFO] sqlmap parsed 1 testable >> requests from >> the targets >> list >> [13:21:55] [INFO] url 1: >> GET >> >> http://www.xxx.cz:80/index.__php?option=com_thumber&view=__thumb&format=image&path=__images/cups/web-xxx-klub___ikona-spion.jpg&newX=160&newY=__120 >> >> <http://www.xxx.cz:80/index.php?option=com_thumber&view=thumb&format=image&path=images/cups/web-xxx-klub_ikona-spion.jpg&newX=160&newY=120> >> Cookie: >> >> __utma=148540003.1998141124.__1349164485.1349423437.__1349599213.20; >> >> >> __utmz=148540003.1349164485.1.__1.utmcsr=(direct)|utmccn=(__direct)|utmcmd=(none); >> theme_cookie=life; >> >> e6da1f1e61cfd387eff8fb21161379__6e=3c29965kggoo45p49dhrs1npq0; >> __utmc=148540003 >> do you want to test this url? [Y/n/q] >> > Y >> [snip] >> >> ------------------------------__--------------------------- >> >> >> Could you please fix this? >> >> Regards >> >> Karel Marhoul >> >> >> >> ------------------------------__------------------------------__------------------ >> >> >> Don't let slow site performance ruin your >> business. Deploy >> New Relic APM >> Deploy New Relic app performance management >> and know exactly >> what is happening inside your Ruby, Python, >> PHP, Java, and >> .NET app >> Try New Relic at no cost today and get our >> sweet Data Nerd >> shirt too! >> http://p.sf.net/sfu/newrelic-__dev2dev >> <http://p.sf.net/sfu/newrelic-dev2dev> >> >> _________________________________________________ >> sqlmap-users mailing list >> sqlmap-users@lists.__ >> <mailto:sqlmap-users@lists.__>sourceforge.net >> <http://sourceforge.net> >> <mailto:sql...@li... >> <mailto:sql...@li...>> >> <mailto:sqlmap-users@lists. >> <mailto:sqlmap-users@lists.>__sourceforge.net >> <http://sourceforge.net> >> <mailto:sql...@li... >> <mailto:sql...@li...>>> >> >> https://lists.sourceforge.net/__lists/listinfo/sqlmap-users >> >> <https://lists.sourceforge.net/lists/listinfo/sqlmap-users> >> >> >> >> >> -- >> Miroslav Stampar >> http://about.me/stamparm >> >> >> >> >> >> -- >> Miroslav Stampar >> http://about.me/stamparm >> >> >> >> >> >> -- >> Miroslav Stampar >> http://about.me/stamparm >> >> >> ------------------------------------------------------------------------------ >> Don't let slow site performance ruin your business. Deploy New Relic APM >> Deploy New Relic app performance management and know exactly >> what is happening inside your Ruby, Python, PHP, Java, and .NET app >> Try New Relic at no cost today and get our sweet Data Nerd shirt too! >> http://p.sf.net/sfu/newrelic-dev2dev >> >> >> _______________________________________________ >> sqlmap-users mailing list >> sql...@li... <mailto:sql...@li...> >> https://lists.sourceforge.net/lists/listinfo/sqlmap-users > > > > > -- > Miroslav Stampar > http://about.me/stamparm |
From: Miroslav S. <mir...@gm...> - 2012-10-09 10:32:51
|
Hi Dennis. >From now on sqlmap should take into the consideration the preamble too - It takes it as a first choice for scheme::port values (e.g. https::443). In case that there are different values inside the request body itself, specifically Host header, then those values have higher priority. Kind regards, Miroslav Stampar On Tue, Oct 9, 2012 at 11:41 AM, Dennis <kor...@ya...> wrote: > Hey Miroslav, > > how did you fix this? Does sqlmap take the preamble into account? Or how > do you figure out, what is https and what's not? > > Regards, > Dennis > > > Am 09.10.2012 11:36, schrieb Miroslav Stampar: > > Hi Karel. > > This should be fixed now [1]. > > Kind regards, > Miroslav Stampar > > [1] https://github.com/sqlmapproject/sqlmap/issues/198 > > On Tue, Oct 9, 2012 at 11:04 AM, Karel Marhoul <rez...@se...>wrote: > >> I could confirm this behavior with these versions of burp: >> >> Burp Suite Proffesional 1.4.12 >> Burp Suite Proffesional 1.5rc3 >> >> Patch would be appreciated. >> >> Regards >> >> Karel >> >> >> On 9.10.2012 10:49, Miroslav Stampar wrote: >> >>> Hi again. >>> >>> It's a preamble, but the request itself is down below. We process >>> requests, not preambles. As we need to support generic LOG files, we are >>> "hunting" for requests itself. >>> >>> If somebody could confirm that Burp really strips any HTTPS "tips" from >>> the requests and just puts those in preambles (like in your case), I'll >>> gladly do the "patching". >>> >>> Kind regards, >>> Miroslav Stampar >>> >>> On Tue, Oct 9, 2012 at 10:44 AM, Karel Marhoul <rez...@se... >>> <mailto:rez...@se...>> wrote: >>> >>> Hello Miroslav, there is a mention of port 443 in the request >>> "preamble", see: >>> >>> > ==============================__======================== >>> >>> > 12:40:22 https://www.xxx.cz:443 [81.91.80.92] >>> > ==============================__======================== >>> >>> >>> That specific request came from HTTPS page and landed toward HTTP, >>> I'm sure of that. >>> >>> I suggest sqlmap log parser should first look at the port in the >>> request preamble and then send the request to this port - is that >>> possible to implement? >>> >>> Regards >>> >>> Karel >>> >>> On 9.10.2012 10:30, Miroslav Stampar wrote: >>> >>> Hi Karel. >>> >>> Strictly speaking there is no bug here. If you take a look >>> carefully >>> into the HTTP request inside you'll see that there is no mention >>> of >>> either HTTPS nor 443 inside the request itself. It seems like the >>> request came from the https page (referer header), but landed >>> toward the >>> HTTP land. >>> >>> I would suggest you to just try to append the :443 to the Host >>> header >>> value (Host: www.xxx.cz <http://www.xxx.cz> <http://www.xxx.cz> >>> >>> >>> -> Host: www.xxx.cz:443 <http://www.xxx.cz:443> >>> <http://www.xxx.cz:443>) >>> >>> Kind regards, >>> Miroslav Stampar >>> >>> On Sun, Oct 7, 2012 at 1:37 PM, Karel Marhoul >>> <rez...@se... <mailto:rez...@se...> >>> <mailto:rez...@se... <mailto:rez...@se...>>> >>> wrote: >>> >>> Hello, I came across a bug while using sqlmap with -l >>> parameter. I have >>> burp log file with following content (only one request to >>> https port): >>> >>> ==============================__======================== >>> >>> 12:40:22 https://www.xxx.cz:443 [81.91.80.92] >>> ==============================__======================== >>> GET >>> >>> >>> /index.php?option=com_thumber&__view=thumb&format=image&path=__images/cups/web-xxx-klub___ikona-spion.jpg&newX=160&newY=__120 >>> HTTP/1.1 >>> Host: www.xxx.cz <http://www.xxx.cz> <http://www.xxx.cz> >>> >>> User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:15.0) >>> Gecko/20100101 >>> Firefox/15.0.1 >>> Accept: image/png,image/*;q=0.8,*/*;q=__0.5 >>> >>> Accept-Language: en-us,en;q=0.5 >>> Accept-Encoding: gzip, deflate >>> Connection: keep-alive >>> Referer: https://www.xxx.cz/ >>> Cookie: >>> >>> __utma=148540003.1998141124.__1349164485.1349423437.__1349599213.20; >>> >>> >>> __utmz=148540003.1349164485.1.__1.utmcsr=(direct)|utmccn=(__direct)|utmcmd=(none); >>> theme_cookie=life; >>> >>> e6da1f1e61cfd387eff8fb21161379__6e=3c29965kggoo45p49dhrs1npq0; >>> __utmc=148540003 >>> Cache-Control: max-age=0 >>> >>> ==============================__======================== >>> >>> Then I start sqlmap this way: >>> >>> ./sqlmap.py -l /root/burp.log --batch --threads=10 >>> --scope=www.xxx.cz <http://www.xxx.cz> <http://www.xxx.cz> >>> >>> >>> >>> And sqlmap instead of sending request to https (443) port >>> it will use >>> http (80) port instead: >>> >>> >>> ------------------------------__--------------------------- >>> >>> [13:21:55] [INFO] using regular expression 'www.xxx.cz >>> <http://www.xxx.cz> >>> <http://www.xxx.cz>' for filtering >>> targets >>> [13:21:55] [INFO] sqlmap parsed 1 testable requests from >>> the targets >>> list >>> [13:21:55] [INFO] url 1: >>> GET >>> >>> http://www.xxx.cz:80/index.__php?option=com_thumber&view=__thumb&format=image&path=__images/cups/web-xxx-klub___ikona-spion.jpg&newX=160&newY=__120 >>> < >>> http://www.xxx.cz:80/index.php?option=com_thumber&view=thumb&format=image&path=images/cups/web-xxx-klub_ikona-spion.jpg&newX=160&newY=120 >>> > >>> Cookie: >>> >>> __utma=148540003.1998141124.__1349164485.1349423437.__1349599213.20; >>> >>> >>> __utmz=148540003.1349164485.1.__1.utmcsr=(direct)|utmccn=(__direct)|utmcmd=(none); >>> theme_cookie=life; >>> >>> e6da1f1e61cfd387eff8fb21161379__6e=3c29965kggoo45p49dhrs1npq0; >>> __utmc=148540003 >>> do you want to test this url? [Y/n/q] >>> > Y >>> [snip] >>> >>> ------------------------------__--------------------------- >>> >>> >>> Could you please fix this? >>> >>> Regards >>> >>> Karel Marhoul >>> >>> >>> >>> ------------------------------__------------------------------__------------------ >>> >>> >>> Don't let slow site performance ruin your business. Deploy >>> New Relic APM >>> Deploy New Relic app performance management and know exactly >>> what is happening inside your Ruby, Python, PHP, Java, and >>> .NET app >>> Try New Relic at no cost today and get our sweet Data Nerd >>> shirt too! >>> http://p.sf.net/sfu/newrelic-__dev2dev >>> <http://p.sf.net/sfu/newrelic-dev2dev> >>> _________________________________________________ >>> sqlmap-users mailing list >>> sqlmap-users@lists.__sourceforge.net >>> <mailto:sql...@li...> >>> <mailto:sqlmap-users@lists.__sourceforge.net >>> <mailto:sql...@li...>> >>> https://lists.sourceforge.net/__lists/listinfo/sqlmap-users >>> <https://lists.sourceforge.net/lists/listinfo/sqlmap-users> >>> >>> >>> >>> >>> -- >>> Miroslav Stampar >>> http://about.me/stamparm >>> >>> >>> >>> >>> >>> -- >>> Miroslav Stampar >>> http://about.me/stamparm >>> >> >> > > > -- > Miroslav Stampar > http://about.me/stamparm > > > ------------------------------------------------------------------------------ > Don't let slow site performance ruin your business. Deploy New Relic APM > Deploy New Relic app performance management and know exactly > what is happening inside your Ruby, Python, PHP, Java, and .NET app > Try New Relic at no cost today and get our sweet Data Nerd shirt too!http://p.sf.net/sfu/newrelic-dev2dev > > > > _______________________________________________ > sqlmap-users mailing lis...@li...https://lists.sourceforge.net/lists/listinfo/sqlmap-users > > > -- Miroslav Stampar http://about.me/stamparm |
From: Dennis <kor...@ya...> - 2012-10-09 09:41:42
|
Hey Miroslav, how did you fix this? Does sqlmap take the preamble into account? Or how do you figure out, what is https and what's not? Regards, Dennis Am 09.10.2012 11:36, schrieb Miroslav Stampar: > Hi Karel. > > This should be fixed now [1]. > > Kind regards, > Miroslav Stampar > > [1] https://github.com/sqlmapproject/sqlmap/issues/198 > > On Tue, Oct 9, 2012 at 11:04 AM, Karel Marhoul <rez...@se... > <mailto:rez...@se...>> wrote: > > I could confirm this behavior with these versions of burp: > > Burp Suite Proffesional 1.4.12 > Burp Suite Proffesional 1.5rc3 > > Patch would be appreciated. > > Regards > > Karel > > > On 9.10.2012 10:49, Miroslav Stampar wrote: > > Hi again. > > It's a preamble, but the request itself is down below. We process > requests, not preambles. As we need to support generic LOG > files, we are > "hunting" for requests itself. > > If somebody could confirm that Burp really strips any HTTPS > "tips" from > the requests and just puts those in preambles (like in your > case), I'll > gladly do the "patching". > > Kind regards, > Miroslav Stampar > > On Tue, Oct 9, 2012 at 10:44 AM, Karel Marhoul > <rez...@se... <mailto:rez...@se...> > <mailto:rez...@se... <mailto:rez...@se...>>> > wrote: > > Hello Miroslav, there is a mention of port 443 in the request > "preamble", see: > > > > ==============================__======================== > > > 12:40:22 https://www.xxx.cz:443 [81.91.80.92] > > > ==============================__======================== > > > That specific request came from HTTPS page and landed > toward HTTP, > I'm sure of that. > > I suggest sqlmap log parser should first look at the port > in the > request preamble and then send the request to this port - > is that > possible to implement? > > Regards > > Karel > > On 9.10.2012 10:30, Miroslav Stampar wrote: > > Hi Karel. > > Strictly speaking there is no bug here. If you take a > look carefully > into the HTTP request inside you'll see that there is > no mention of > either HTTPS nor 443 inside the request itself. It > seems like the > request came from the https page (referer header), but > landed > toward the > HTTP land. > > I would suggest you to just try to append the :443 to > the Host > header > value (Host: www.xxx.cz <http://www.xxx.cz> > <http://www.xxx.cz> <http://www.xxx.cz> > > -> Host: www.xxx.cz:443 <http://www.xxx.cz:443> > <http://www.xxx.cz:443> > <http://www.xxx.cz:443>) > > Kind regards, > Miroslav Stampar > > On Sun, Oct 7, 2012 at 1:37 PM, Karel Marhoul > <rez...@se... <mailto:rez...@se...> > <mailto:rez...@se... <mailto:rez...@se...>> > <mailto:rez...@se... > <mailto:rez...@se...> <mailto:rez...@se... > <mailto:rez...@se...>>>> wrote: > > Hello, I came across a bug while using sqlmap with -l > parameter. I have > burp log file with following content (only one > request to > https port): > > > ==============================__======================== > > 12:40:22 https://www.xxx.cz:443 [81.91.80.92] > > ==============================__======================== > GET > > > /index.php?option=com_thumber&__view=thumb&format=image&path=__images/cups/web-xxx-klub___ikona-spion.jpg&newX=160&newY=__120 > HTTP/1.1 > Host: www.xxx.cz <http://www.xxx.cz> > <http://www.xxx.cz> <http://www.xxx.cz> > > User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; > rv:15.0) > Gecko/20100101 > Firefox/15.0.1 > Accept: image/png,image/*;q=0.8,*/*;q=__0.5 > > Accept-Language: en-us,en;q=0.5 > Accept-Encoding: gzip, deflate > Connection: keep-alive > Referer: https://www.xxx.cz/ > Cookie: > > __utma=148540003.1998141124.__1349164485.1349423437.__1349599213.20; > > > __utmz=148540003.1349164485.1.__1.utmcsr=(direct)|utmccn=(__direct)|utmcmd=(none); > theme_cookie=life; > > e6da1f1e61cfd387eff8fb21161379__6e=3c29965kggoo45p49dhrs1npq0; > __utmc=148540003 > Cache-Control: max-age=0 > > > ==============================__======================== > > Then I start sqlmap this way: > > ./sqlmap.py -l /root/burp.log --batch --threads=10 > --scope=www.xxx.cz <http://www.xxx.cz> > <http://www.xxx.cz> <http://www.xxx.cz> > > > And sqlmap instead of sending request to https > (443) port > it will use > http (80) port instead: > > > ------------------------------__--------------------------- > > [13:21:55] [INFO] using regular expression > 'www.xxx.cz <http://www.xxx.cz> > <http://www.xxx.cz> > <http://www.xxx.cz>' for filtering > targets > [13:21:55] [INFO] sqlmap parsed 1 testable > requests from > the targets > list > [13:21:55] [INFO] url 1: > GET > > http://www.xxx.cz:80/index.__php?option=com_thumber&view=__thumb&format=image&path=__images/cups/web-xxx-klub___ikona-spion.jpg&newX=160&newY=__120 > > <http://www.xxx.cz:80/index.php?option=com_thumber&view=thumb&format=image&path=images/cups/web-xxx-klub_ikona-spion.jpg&newX=160&newY=120> > Cookie: > > __utma=148540003.1998141124.__1349164485.1349423437.__1349599213.20; > > > __utmz=148540003.1349164485.1.__1.utmcsr=(direct)|utmccn=(__direct)|utmcmd=(none); > theme_cookie=life; > > e6da1f1e61cfd387eff8fb21161379__6e=3c29965kggoo45p49dhrs1npq0; > __utmc=148540003 > do you want to test this url? [Y/n/q] > > Y > [snip] > > ------------------------------__--------------------------- > > > Could you please fix this? > > Regards > > Karel Marhoul > > > > ------------------------------__------------------------------__------------------ > > > Don't let slow site performance ruin your > business. Deploy > New Relic APM > Deploy New Relic app performance management and > know exactly > what is happening inside your Ruby, Python, PHP, > Java, and > .NET app > Try New Relic at no cost today and get our sweet > Data Nerd > shirt too! > http://p.sf.net/sfu/newrelic-__dev2dev > <http://p.sf.net/sfu/newrelic-dev2dev> > _________________________________________________ > sqlmap-users mailing list > sqlmap-users@lists.__sourceforge.net > <http://sourceforge.net> > <mailto:sql...@li... > <mailto:sql...@li...>> > <mailto:sqlmap-users@lists. > <mailto:sqlmap-users@lists.>__sourceforge.net > <http://sourceforge.net> > <mailto:sql...@li... > <mailto:sql...@li...>>> > > https://lists.sourceforge.net/__lists/listinfo/sqlmap-users > > <https://lists.sourceforge.net/lists/listinfo/sqlmap-users> > > > > > -- > Miroslav Stampar > http://about.me/stamparm > > > > > > -- > Miroslav Stampar > http://about.me/stamparm > > > > > > -- > Miroslav Stampar > http://about.me/stamparm > > > ------------------------------------------------------------------------------ > Don't let slow site performance ruin your business. Deploy New Relic APM > Deploy New Relic app performance management and know exactly > what is happening inside your Ruby, Python, PHP, Java, and .NET app > Try New Relic at no cost today and get our sweet Data Nerd shirt too! > http://p.sf.net/sfu/newrelic-dev2dev > > > _______________________________________________ > sqlmap-users mailing list > sql...@li... > https://lists.sourceforge.net/lists/listinfo/sqlmap-users |
From: Miroslav S. <mir...@gm...> - 2012-10-09 09:37:06
|
Hi Karel. This should be fixed now [1]. Kind regards, Miroslav Stampar [1] https://github.com/sqlmapproject/sqlmap/issues/198 On Tue, Oct 9, 2012 at 11:04 AM, Karel Marhoul <rez...@se...> wrote: > I could confirm this behavior with these versions of burp: > > Burp Suite Proffesional 1.4.12 > Burp Suite Proffesional 1.5rc3 > > Patch would be appreciated. > > Regards > > Karel > > > On 9.10.2012 10:49, Miroslav Stampar wrote: > >> Hi again. >> >> It's a preamble, but the request itself is down below. We process >> requests, not preambles. As we need to support generic LOG files, we are >> "hunting" for requests itself. >> >> If somebody could confirm that Burp really strips any HTTPS "tips" from >> the requests and just puts those in preambles (like in your case), I'll >> gladly do the "patching". >> >> Kind regards, >> Miroslav Stampar >> >> On Tue, Oct 9, 2012 at 10:44 AM, Karel Marhoul <rez...@se... >> <mailto:rez...@se...>> wrote: >> >> Hello Miroslav, there is a mention of port 443 in the request >> "preamble", see: >> >> > ==============================**__======================== >> >> > 12:40:22 https://www.xxx.cz:443 [81.91.80.92] >> > ==============================**__======================== >> >> >> That specific request came from HTTPS page and landed toward HTTP, >> I'm sure of that. >> >> I suggest sqlmap log parser should first look at the port in the >> request preamble and then send the request to this port - is that >> possible to implement? >> >> Regards >> >> Karel >> >> On 9.10.2012 10:30, Miroslav Stampar wrote: >> >> Hi Karel. >> >> Strictly speaking there is no bug here. If you take a look >> carefully >> into the HTTP request inside you'll see that there is no mention >> of >> either HTTPS nor 443 inside the request itself. It seems like the >> request came from the https page (referer header), but landed >> toward the >> HTTP land. >> >> I would suggest you to just try to append the :443 to the Host >> header >> value (Host: www.xxx.cz <http://www.xxx.cz> <http://www.xxx.cz> >> >> -> Host: www.xxx.cz:443 <http://www.xxx.cz:443> >> <http://www.xxx.cz:443>) >> >> Kind regards, >> Miroslav Stampar >> >> On Sun, Oct 7, 2012 at 1:37 PM, Karel Marhoul >> <rez...@se... <mailto:rez...@se...> >> <mailto:rez...@se... <mailto:rez...@se...>>**> >> wrote: >> >> Hello, I came across a bug while using sqlmap with -l >> parameter. I have >> burp log file with following content (only one request to >> https port): >> >> ==============================**__======================== >> >> 12:40:22 https://www.xxx.cz:443 [81.91.80.92] >> ==============================**__======================== >> GET >> >> /index.php?option=com_thumber&**__view=thumb&format=image&** >> path=__images/cups/web-xxx-**klub___ikona-spion.jpg&newX=**160&newY=__120 >> HTTP/1.1 >> Host: www.xxx.cz <http://www.xxx.cz> <http://www.xxx.cz> >> >> User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:15.0) >> Gecko/20100101 >> Firefox/15.0.1 >> Accept: image/png,image/*;q=0.8,*/*;q=**__0.5 >> >> Accept-Language: en-us,en;q=0.5 >> Accept-Encoding: gzip, deflate >> Connection: keep-alive >> Referer: https://www.xxx.cz/ >> Cookie: >> __utma=148540003.1998141124.__**1349164485.1349423437.__** >> 1349599213.20; >> >> __utmz=148540003.1349164485.1.**__1.utmcsr=(direct)|utmccn=(__** >> direct)|utmcmd=(none); >> theme_cookie=life; >> e6da1f1e61cfd387eff8fb21161379**__6e=** >> 3c29965kggoo45p49dhrs1npq0; >> __utmc=148540003 >> Cache-Control: max-age=0 >> >> ==============================**__======================== >> >> Then I start sqlmap this way: >> >> ./sqlmap.py -l /root/burp.log --batch --threads=10 >> --scope=www.xxx.cz <http://www.xxx.cz> <http://www.xxx.cz> >> >> >> And sqlmap instead of sending request to https (443) port >> it will use >> http (80) port instead: >> >> ------------------------------** >> __--------------------------- >> >> [13:21:55] [INFO] using regular expression 'www.xxx.cz >> <http://www.xxx.cz> >> <http://www.xxx.cz>' for filtering >> targets >> [13:21:55] [INFO] sqlmap parsed 1 testable requests from >> the targets >> list >> [13:21:55] [INFO] url 1: >> GET >> http://www.xxx.cz:80/index.__**php?option=com_thumber&view=__** >> thumb&format=image&path=__**images/cups/web-xxx-klub___** >> ikona-spion.jpg&newX=160&newY=**__120<http://www.xxx.cz:80/index.__php?option=com_thumber&view=__thumb&format=image&path=__images/cups/web-xxx-klub___ikona-spion.jpg&newX=160&newY=__120> >> <http://www.xxx.cz:80/index.**php?option=com_thumber&view=** >> thumb&format=image&path=**images/cups/web-xxx-klub_** >> ikona-spion.jpg&newX=160&newY=**120<http://www.xxx.cz:80/index.php?option=com_thumber&view=thumb&format=image&path=images/cups/web-xxx-klub_ikona-spion.jpg&newX=160&newY=120> >> > >> Cookie: >> __utma=148540003.1998141124.__**1349164485.1349423437.__** >> 1349599213.20; >> >> __utmz=148540003.1349164485.1.**__1.utmcsr=(direct)|utmccn=(__** >> direct)|utmcmd=(none); >> theme_cookie=life; >> e6da1f1e61cfd387eff8fb21161379**__6e=** >> 3c29965kggoo45p49dhrs1npq0; >> __utmc=148540003 >> do you want to test this url? [Y/n/q] >> > Y >> [snip] >> ------------------------------** >> __--------------------------- >> >> >> Could you please fix this? >> >> Regards >> >> Karel Marhoul >> >> >> ------------------------------**__----------------------------** >> --__------------------ >> >> Don't let slow site performance ruin your business. Deploy >> New Relic APM >> Deploy New Relic app performance management and know exactly >> what is happening inside your Ruby, Python, PHP, Java, and >> .NET app >> Try New Relic at no cost today and get our sweet Data Nerd >> shirt too! >> http://p.sf.net/sfu/newrelic-_**_dev2dev<http://p.sf.net/sfu/newrelic-__dev2dev> >> <http://p.sf.net/sfu/newrelic-**dev2dev<http://p.sf.net/sfu/newrelic-dev2dev> >> > >> ______________________________**___________________ >> sqlmap-users mailing list >> sqlmap-users@lists.__sourcefor**ge.net <http://sourceforge.net> >> <mailto:sqlmap-users@lists.**sourceforge.net<sql...@li...> >> > >> <mailto:sqlmap-users@lists.__s**ourceforge.net<http://sourceforge.net> >> <mailto:sqlmap-users@lists.**sourceforge.net<sql...@li...> >> >> >> https://lists.sourceforge.net/**__lists/listinfo/sqlmap-users<https://lists.sourceforge.net/__lists/listinfo/sqlmap-users> >> <https://lists.sourceforge.**net/lists/listinfo/sqlmap-**users<https://lists.sourceforge.net/lists/listinfo/sqlmap-users> >> > >> >> >> >> >> -- >> Miroslav Stampar >> http://about.me/stamparm >> >> >> >> >> >> -- >> Miroslav Stampar >> http://about.me/stamparm >> > > -- Miroslav Stampar http://about.me/stamparm |
From: Miroslav S. <mir...@gm...> - 2012-10-09 09:13:34
|
Ok. I'll do the patching and let you know. Kind regards, Miroslav Stampar On Tue, Oct 9, 2012 at 11:12 AM, Dennis <kor...@ya...> wrote: > Hey, > > burp acts as you suspected. Here's an example of https://google.de logged > from a burp pro v1.4.12: > > ====================================================== > 11:05:56 https://www.google.de:443 [173.194.35.184] > ====================================================== > GET / HTTP/1.1 > Host: www.google.de > > User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:15.0) Gecko/20100101 > Firefox/15.0.1 > Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 > Accept-Language: de-de,de;q=0.8,en-us;q=0.5,en;q=0.3 > Accept-Encoding: gzip, deflate > DNT: 1 > Connection: keep-alive > Cookie: xxx > Pragma: no-cache > Cache-Control: no-cache > > > ====================================================== > > The same goes for burp's "Copy to File" feature. I usually use the > --force-ssl flag to circumvent this. > > Cheers, > Dennis > > > Am 09.10.2012 10:49, schrieb Miroslav Stampar: > > Hi again. > > It's a preamble, but the request itself is down below. We process > requests, not preambles. As we need to support generic LOG files, we are > "hunting" for requests itself. > > If somebody could confirm that Burp really strips any HTTPS "tips" from > the requests and just puts those in preambles (like in your case), I'll > gladly do the "patching". > > Kind regards, > Miroslav Stampar > > On Tue, Oct 9, 2012 at 10:44 AM, Karel Marhoul <rez...@se...>wrote: > >> Hello Miroslav, there is a mention of port 443 in the request "preamble", >> see: >> >> > ====================================================== >> > 12:40:22 https://www.xxx.cz:443 [81.91.80.92] >> > ====================================================== >> >> That specific request came from HTTPS page and landed toward HTTP, I'm >> sure of that. >> >> I suggest sqlmap log parser should first look at the port in the request >> preamble and then send the request to this port - is that possible to >> implement? >> >> Regards >> >> Karel >> >> On 9.10.2012 10:30, Miroslav Stampar wrote: >> >>> Hi Karel. >>> >>> Strictly speaking there is no bug here. If you take a look carefully >>> into the HTTP request inside you'll see that there is no mention of >>> either HTTPS nor 443 inside the request itself. It seems like the >>> request came from the https page (referer header), but landed toward the >>> HTTP land. >>> >>> I would suggest you to just try to append the :443 to the Host header >>> value (Host: www.xxx.cz <http://www.xxx.cz> -> Host: www.xxx.cz:443 >>> <http://www.xxx.cz:443>) >>> >>> Kind regards, >>> Miroslav Stampar >>> >>> On Sun, Oct 7, 2012 at 1:37 PM, Karel Marhoul <rez...@se... >>> <mailto:rez...@se...>> wrote: >>> >>> Hello, I came across a bug while using sqlmap with -l parameter. I >>> have >>> burp log file with following content (only one request to https >>> port): >>> >>> ====================================================== >>> 12:40:22 https://www.xxx.cz:443 [81.91.80.92] >>> ====================================================== >>> GET >>> >>> /index.php?option=com_thumber&view=thumb&format=image&path=images/cups/web-xxx-klub_ikona-spion.jpg&newX=160&newY=120 >>> HTTP/1.1 >>> Host: www.xxx.cz <http://www.xxx.cz> >>> User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:15.0) >>> Gecko/20100101 >>> Firefox/15.0.1 >>> Accept: image/png,image/*;q=0.8,*/*;q=0.5 >>> Accept-Language: en-us,en;q=0.5 >>> Accept-Encoding: gzip, deflate >>> Connection: keep-alive >>> Referer: https://www.xxx.cz/ >>> Cookie: >>> __utma=148540003.1998141124.1349164485.1349423437.1349599213.20; >>> >>> __utmz=148540003.1349164485.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); >>> theme_cookie=life; >>> e6da1f1e61cfd387eff8fb211613796e=3c29965kggoo45p49dhrs1npq0; >>> __utmc=148540003 >>> Cache-Control: max-age=0 >>> >>> ====================================================== >>> >>> Then I start sqlmap this way: >>> >>> ./sqlmap.py -l /root/burp.log --batch --threads=10 >>> --scope=www.xxx.cz <http://www.xxx.cz> >>> >>> And sqlmap instead of sending request to https (443) port it will use >>> http (80) port instead: >>> >>> --------------------------------------------------------- >>> [13:21:55] [INFO] using regular expression 'www.xxx.cz >>> <http://www.xxx.cz>' for filtering >>> targets >>> [13:21:55] [INFO] sqlmap parsed 1 testable requests from the targets >>> list >>> [13:21:55] [INFO] url 1: >>> GET >>> >>> http://www.xxx.cz:80/index.php?option=com_thumber&view=thumb&format=image&path=images/cups/web-xxx-klub_ikona-spion.jpg&newX=160&newY=120 >>> Cookie: >>> __utma=148540003.1998141124.1349164485.1349423437.1349599213.20; >>> >>> __utmz=148540003.1349164485.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); >>> theme_cookie=life; >>> e6da1f1e61cfd387eff8fb211613796e=3c29965kggoo45p49dhrs1npq0; >>> __utmc=148540003 >>> do you want to test this url? [Y/n/q] >>> > Y >>> [snip] >>> --------------------------------------------------------- >>> >>> Could you please fix this? >>> >>> Regards >>> >>> Karel Marhoul >>> >>> >>> ------------------------------------------------------------------------------ >>> Don't let slow site performance ruin your business. Deploy New Relic >>> APM >>> Deploy New Relic app performance management and know exactly >>> what is happening inside your Ruby, Python, PHP, Java, and .NET app >>> Try New Relic at no cost today and get our sweet Data Nerd shirt too! >>> http://p.sf.net/sfu/newrelic-dev2dev >>> _______________________________________________ >>> sqlmap-users mailing list >>> sql...@li... >>> <mailto:sql...@li...> >>> https://lists.sourceforge.net/lists/listinfo/sqlmap-users >>> >>> >>> >>> >>> -- >>> Miroslav Stampar >>> http://about.me/stamparm >>> >> >> > > > -- > Miroslav Stampar > http://about.me/stamparm > > > ------------------------------------------------------------------------------ > Don't let slow site performance ruin your business. Deploy New Relic APM > Deploy New Relic app performance management and know exactly > what is happening inside your Ruby, Python, PHP, Java, and .NET app > Try New Relic at no cost today and get our sweet Data Nerd shirt too!http://p.sf.net/sfu/newrelic-dev2dev > > > > _______________________________________________ > sqlmap-users mailing lis...@li... > https://lists.sourceforge.net/lists/listinfo/sqlmap-users > > > -- Miroslav Stampar http://about.me/stamparm |