sqlmap-users Mailing List for sqlmap (Page 79)
Brought to you by:
inquisb
You can subscribe to this list here.
2008 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
(4) |
Oct
(11) |
Nov
(24) |
Dec
(13) |
---|---|---|---|---|---|---|---|---|---|---|---|---|
2009 |
Jan
(23) |
Feb
(17) |
Mar
(13) |
Apr
(48) |
May
(22) |
Jun
(18) |
Jul
(22) |
Aug
(13) |
Sep
(23) |
Oct
(6) |
Nov
(11) |
Dec
(25) |
2010 |
Jan
(21) |
Feb
(33) |
Mar
(61) |
Apr
(47) |
May
(48) |
Jun
(30) |
Jul
(24) |
Aug
(37) |
Sep
(52) |
Oct
(59) |
Nov
(32) |
Dec
(57) |
2011 |
Jan
(166) |
Feb
(93) |
Mar
(65) |
Apr
(117) |
May
(87) |
Jun
(124) |
Jul
(102) |
Aug
(78) |
Sep
(65) |
Oct
(22) |
Nov
(71) |
Dec
(79) |
2012 |
Jan
(93) |
Feb
(55) |
Mar
(45) |
Apr
(49) |
May
(56) |
Jun
(93) |
Jul
(95) |
Aug
(42) |
Sep
(26) |
Oct
(36) |
Nov
(32) |
Dec
(46) |
2013 |
Jan
(36) |
Feb
(78) |
Mar
(38) |
Apr
(57) |
May
(35) |
Jun
(39) |
Jul
(23) |
Aug
(33) |
Sep
(28) |
Oct
(38) |
Nov
(22) |
Dec
(16) |
2014 |
Jan
(33) |
Feb
(23) |
Mar
(41) |
Apr
(29) |
May
(12) |
Jun
(20) |
Jul
(21) |
Aug
(23) |
Sep
(18) |
Oct
(34) |
Nov
(12) |
Dec
(39) |
2015 |
Jan
(2) |
Feb
(51) |
Mar
(10) |
Apr
(28) |
May
(9) |
Jun
(22) |
Jul
(32) |
Aug
(35) |
Sep
(29) |
Oct
(50) |
Nov
(8) |
Dec
(2) |
2016 |
Jan
(8) |
Feb
(2) |
Mar
(3) |
Apr
(14) |
May
|
Jun
|
Jul
|
Aug
(12) |
Sep
|
Oct
|
Nov
(1) |
Dec
(19) |
2017 |
Jan
|
Feb
(18) |
Mar
|
Apr
(1) |
May
|
Jun
|
Jul
|
Aug
(4) |
Sep
|
Oct
|
Nov
(2) |
Dec
|
2018 |
Jan
|
Feb
|
Mar
(1) |
Apr
(1) |
May
(3) |
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
2019 |
Jan
|
Feb
|
Mar
|
Apr
(3) |
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
From: anonymous a. <tm...@2c...> - 2011-09-12 20:01:16
|
<div>Or it starts from the beginning?</div> |
From: Miroslav S. <mir...@gm...> - 2011-09-12 19:08:25
|
Hi. It's happening no matter if it's Backtrack or not. From my observations it happens after addition of a new file into repository. As said, long time unresolved known issue. Kr On 12.9.2011. 21:04, "Sherif El-Deeb" <arc...@gm...> wrote: |
From: Avery R. <as...@ya...> - 2011-09-12 19:06:01
|
Your are correct, thanks for the explanation too. Sent from my iPhone On Sep 12, 2011, at 3:03 PM, Sherif El-Deeb <arc...@gm...> wrote: > I think this is happening because for some reason the sqlmap included > in BackTrack "you're using backtrack, right?" is getting its updates > from "https://svn.sqlmap.org/sqlmap/" whereas it should be from > "https://svn.sqlmap.org/sqlmap/trunk/sqlmap" > > > On Mon, Sep 12, 2011 at 9:56 PM, Avery Rozar <as...@ya...> wrote: >> Sweet, that worked.. Thanks very much! >> >> Sent from my iPhone >> >> On Sep 12, 2011, at 2:53 PM, Sherif El-Deeb <arc...@gm...> wrote: >> >>> remove the old directory, do a clean svn checkout will solve your problem >>> >>> # rm -rf sqlmap >>> # svn checkout https://svn.sqlmap.org/sqlmap/trunk/sqlmap sqlmap-dev >>> >>> On Mon, Sep 12, 2011 at 8:54 PM, Avery Rozar <as...@ya...> wrote: >>>> >>>> Hello all, >>>> I'm trying to run an update but keep getting a username and password request, where do I find this? I though it was simply the un and password I created to join this list, but that's not working... Thanks much!! >>>> ------------------------------------------------------------------------------ >>>> Doing More with Less: The Next Generation Virtual Desktop >>>> What are the key obstacles that have prevented many mid-market businesses >>>> from deploying virtual desktops? How do next-generation virtual desktops >>>> provide companies an easier-to-deploy, easier-to-manage and more affordable >>>> virtual desktop model.http://www.accelacomm.com/jaw/sfnl/114/51426474/ >>>> _______________________________________________ >>>> sqlmap-users mailing list >>>> sql...@li... >>>> https://lists.sourceforge.net/lists/listinfo/sqlmap-users >>>> >> |
From: Sherif El-D. <arc...@gm...> - 2011-09-12 19:03:59
|
I think this is happening because for some reason the sqlmap included in BackTrack "you're using backtrack, right?" is getting its updates from "https://svn.sqlmap.org/sqlmap/" whereas it should be from "https://svn.sqlmap.org/sqlmap/trunk/sqlmap" On Mon, Sep 12, 2011 at 9:56 PM, Avery Rozar <as...@ya...> wrote: > Sweet, that worked.. Thanks very much! > > Sent from my iPhone > > On Sep 12, 2011, at 2:53 PM, Sherif El-Deeb <arc...@gm...> wrote: > >> remove the old directory, do a clean svn checkout will solve your problem >> >> # rm -rf sqlmap >> # svn checkout https://svn.sqlmap.org/sqlmap/trunk/sqlmap sqlmap-dev >> >> On Mon, Sep 12, 2011 at 8:54 PM, Avery Rozar <as...@ya...> wrote: >>> >>> Hello all, >>> I'm trying to run an update but keep getting a username and password request, where do I find this? I though it was simply the un and password I created to join this list, but that's not working... Thanks much!! >>> ------------------------------------------------------------------------------ >>> Doing More with Less: The Next Generation Virtual Desktop >>> What are the key obstacles that have prevented many mid-market businesses >>> from deploying virtual desktops? How do next-generation virtual desktops >>> provide companies an easier-to-deploy, easier-to-manage and more affordable >>> virtual desktop model.http://www.accelacomm.com/jaw/sfnl/114/51426474/ >>> _______________________________________________ >>> sqlmap-users mailing list >>> sql...@li... >>> https://lists.sourceforge.net/lists/listinfo/sqlmap-users >>> > |
From: Miroslav S. <mir...@gm...> - 2011-09-12 19:01:14
|
Thx for this :) Known issue Kind regards On 12.9.2011. 20:57, "Avery Rozar" <as...@ya...> wrote: > Sweet, that worked.. Thanks very much! > > Sent from my iPhone > > On Sep 12, 2011, at 2:53 PM, Sherif El-Deeb <arc...@gm...> wrote: > >> remove the old directory, do a clean svn checkout will solve your problem >> >> # rm -rf sqlmap >> # svn checkout https://svn.sqlmap.org/sqlmap/trunk/sqlmap sqlmap-dev >> >> On Mon, Sep 12, 2011 at 8:54 PM, Avery Rozar <as...@ya...> wrote: >>> >>> Hello all, >>> I'm trying to run an update but keep getting a username and password request, where do I find this? I though it was simply the un and password I created to join this list, but that's not working... Thanks much!! >>> ------------------------------------------------------------------------------ >>> Doing More with Less: The Next Generation Virtual Desktop >>> What are the key obstacles that have prevented many mid-market businesses >>> from deploying virtual desktops? How do next-generation virtual desktops >>> provide companies an easier-to-deploy, easier-to-manage and more affordable >>> virtual desktop model.http://www.accelacomm.com/jaw/sfnl/114/51426474/ >>> _______________________________________________ >>> sqlmap-users mailing list >>> sql...@li... >>> https://lists.sourceforge.net/lists/listinfo/sqlmap-users >>> > > ------------------------------------------------------------------------------ > Doing More with Less: The Next Generation Virtual Desktop > What are the key obstacles that have prevented many mid-market businesses > from deploying virtual desktops? How do next-generation virtual desktops > provide companies an easier-to-deploy, easier-to-manage and more affordable > virtual desktop model.http://www.accelacomm.com/jaw/sfnl/114/51426474/ > _______________________________________________ > sqlmap-users mailing list > sql...@li... > https://lists.sourceforge.net/lists/listinfo/sqlmap-users |
From: Avery R. <as...@ya...> - 2011-09-12 18:56:51
|
Sweet, that worked.. Thanks very much! Sent from my iPhone On Sep 12, 2011, at 2:53 PM, Sherif El-Deeb <arc...@gm...> wrote: > remove the old directory, do a clean svn checkout will solve your problem > > # rm -rf sqlmap > # svn checkout https://svn.sqlmap.org/sqlmap/trunk/sqlmap sqlmap-dev > > On Mon, Sep 12, 2011 at 8:54 PM, Avery Rozar <as...@ya...> wrote: >> >> Hello all, >> I'm trying to run an update but keep getting a username and password request, where do I find this? I though it was simply the un and password I created to join this list, but that's not working... Thanks much!! >> ------------------------------------------------------------------------------ >> Doing More with Less: The Next Generation Virtual Desktop >> What are the key obstacles that have prevented many mid-market businesses >> from deploying virtual desktops? How do next-generation virtual desktops >> provide companies an easier-to-deploy, easier-to-manage and more affordable >> virtual desktop model.http://www.accelacomm.com/jaw/sfnl/114/51426474/ >> _______________________________________________ >> sqlmap-users mailing list >> sql...@li... >> https://lists.sourceforge.net/lists/listinfo/sqlmap-users >> |
From: Sherif El-D. <arc...@gm...> - 2011-09-12 18:53:09
|
remove the old directory, do a clean svn checkout will solve your problem # rm -rf sqlmap # svn checkout https://svn.sqlmap.org/sqlmap/trunk/sqlmap sqlmap-dev On Mon, Sep 12, 2011 at 8:54 PM, Avery Rozar <as...@ya...> wrote: > > Hello all, > I'm trying to run an update but keep getting a username and password request, where do I find this? I though it was simply the un and password I created to join this list, but that's not working... Thanks much!! > ------------------------------------------------------------------------------ > Doing More with Less: The Next Generation Virtual Desktop > What are the key obstacles that have prevented many mid-market businesses > from deploying virtual desktops? How do next-generation virtual desktops > provide companies an easier-to-deploy, easier-to-manage and more affordable > virtual desktop model.http://www.accelacomm.com/jaw/sfnl/114/51426474/ > _______________________________________________ > sqlmap-users mailing list > sql...@li... > https://lists.sourceforge.net/lists/listinfo/sqlmap-users > |
From: Wil R. <wil...@gm...> - 2011-09-12 18:36:45
|
Check your options. I've only been asked to supply username and password when I entered the wrong thing. For "Update" you shouldn't need anything. Sent from my iPhone On Sep 12, 2011, at 10:54 AM, Avery Rozar <as...@ya...> wrote: > Hello all, > I'm trying to run an update but keep getting a username and password request, where do I find this? I though it was simply the un and password I created to join this list, but that's not working... Thanks much!! > ------------------------------------------------------------------------------ > Doing More with Less: The Next Generation Virtual Desktop > What are the key obstacles that have prevented many mid-market businesses > from deploying virtual desktops? How do next-generation virtual desktops > provide companies an easier-to-deploy, easier-to-manage and more affordable > virtual desktop model.http://www.accelacomm.com/jaw/sfnl/114/51426474/ > _______________________________________________ > sqlmap-users mailing list > sql...@li... > https://lists.sourceforge.net/lists/listinfo/sqlmap-users |
From: Avery R. <as...@ya...> - 2011-09-12 17:54:18
|
Hello all, I'm trying to run an update but keep getting a username and password request, where do I find this? I though it was simply the un and password I created to join this list, but that's not working... Thanks much!! |
From: Martin D. <mar...@ho...> - 2011-09-12 16:39:28
|
error code attached as an png image critical unhandled exception error http://skydrive.live.com/redir.aspx?cid=1adf7a7447782df4&page=browse&resid=1ADF7A7447782DF4!231&type=5&Bpub=SDX.Photos&Bsrc=Photomail&authkey=ScvJMudQ0cg%24 |
From: Bernardo D. A. G. <ber...@gm...> - 2011-09-12 14:21:14
|
This has been fixed some time ago. Bernardo On 29 August 2011 19:13, <ks...@so...> wrote: > hello kids! > recently got this bug > > ------------- > [19:58:45] [CRITICAL] unhandled exception in sqlmap/1.0-dev (r4358), retry > your run with the latest development version from the Subversion > repository. If the exception persists, please send by e-mail to > sql...@li... the following text and any information > required to reproduce the bug. The developers will try to reproduce the > bug, fix it accordingly and get back to you. > sqlmap version: 1.0-dev (r4358) > Python version: 2.6.6 > Operating system: posix > Command line: sqlmap.py -m urls.txt --batch --privileges --random-agent > Technique: UNION > Back-end DBMS: Microsoft SQL Server (identified) > Traceback (most recent call last): > File "sqlmap.py", line 86, in main > start() > File "/mnt/1/sqlmap/sqlmap-dev/lib/controller/controller.py", line 460, > in start > injection = checkSqlInjection(place, parameter, value) > File "/mnt/1/sqlmap/sqlmap-dev/lib/controller/checks.py", line 408, in > checkSqlInjection > reqPayload, vector = unionTest(comment, place, parameter, value, > prefix, suffix) > File "/mnt/1/sqlmap/sqlmap-dev/lib/techniques/union/test.py", line 290, > in unionTest > validPayload, vector = __unionTestByCharBruteforce(comment, place, > parameter, value, prefix, suffix) > File "/mnt/1/sqlmap/sqlmap-dev/lib/techniques/union/test.py", line 257, > in __unionTestByCharBruteforce > count = __findUnionCharCount(comment, place, parameter, value, prefix, > suffix) > File "/mnt/1/sqlmap/sqlmap-dev/lib/techniques/union/test.py", line 150, > in __findUnionCharCount > if not re.search(r'>\s*%s\s*<' % kb.uChar, page): > File "/usr/lib/python2.6/re.py", line 142, in search > return _compile(pattern, flags).search(string) > TypeError: expected string or buffer > > --------------- > > > system - debian. > > Use proxychain to divert sqlmap traffic to socks. > (http://proxychains.sourceforge.net/) > > when socks die i got this exeption. > > cheers. > > > > ------------------------------------------------------------------------------ > Doing More with Less: The Next Generation Virtual Desktop > What are the key obstacles that have prevented many mid-market businesses > from deploying virtual desktops? How do next-generation virtual desktops > provide companies an easier-to-deploy, easier-to-manage and more affordable > virtual desktop model.http://www.accelacomm.com/jaw/sfnl/114/51426474/ > _______________________________________________ > sqlmap-users mailing list > sql...@li... > https://lists.sourceforge.net/lists/listinfo/sqlmap-users > -- Bernardo Damele A. G. E-mail / Jabber: bernardo.damele (at) gmail.com Mobile: +447788962949 (UK 07788962949) PGP Key ID: Unavailable |
From: Bernardo D. A. G. <ber...@gm...> - 2011-09-12 14:17:56
|
You can also follow twitter.com/sqlmap and svn log. Bernardo On 11 September 2011 17:10, Miroslav Stampar <mir...@gm...> wrote: > hi Derick. > > you can take a look at CHANGELOG for some quick info on new things: > https://svn.sqlmap.org/sqlmap/trunk/sqlmap/doc/ChangeLog > > kind regards > > On Sat, Sep 10, 2011 at 9:24 AM, Derick Nyarko <nya...@ya...> wrote: >> Okay cool. what's new in Sqlmap. can someone show me? >> ------------------------------------------------------------------------------ >> Malware Security Report: Protecting Your Business, Customers, and the >> Bottom Line. Protect your business and customers by understanding the >> threat from malware and how it can impact your online business. >> http://www.accelacomm.com/jaw/sfnl/114/51427462/ >> _______________________________________________ >> sqlmap-users mailing list >> sql...@li... >> https://lists.sourceforge.net/lists/listinfo/sqlmap-users >> >> > > > > -- > Miroslav Stampar > http://about.me/stamparm > > ------------------------------------------------------------------------------ > Using storage to extend the benefits of virtualization and iSCSI > Virtualization increases hardware utilization and delivers a new level of > agility. Learn what those decisions are and how to modernize your storage > and backup environments for virtualization. > http://www.accelacomm.com/jaw/sfnl/114/51434361/ > _______________________________________________ > sqlmap-users mailing list > sql...@li... > https://lists.sourceforge.net/lists/listinfo/sqlmap-users > -- Bernardo Damele A. G. E-mail / Jabber: bernardo.damele (at) gmail.com Mobile: +447788962949 (UK 07788962949) PGP Key ID: Unavailable |
From: Miroslav S. <mir...@gm...> - 2011-09-12 14:08:21
|
hi Christian. there was a "silent" bug inside which caused buggy waiting for console input without any warning in cases like yours (no warning waiting after "[INFO] confirming Microsoft SQL Server"). i've fixed that one in the latest commit, so it would be great if you could retest and see if that was the same bug you've encountered. kind regards On Wed, Aug 24, 2011 at 5:58 PM, Christian Rothländer <Chr...@cr...> wrote: > Hi there, > > I just updated to the last revision (4365) and tried to attack a Microsoft SQL Server 2005 via AND/OR time-based blind or MS stacked queries. > > The module which analysed which dba is there gets stuck with MSSQL (if I force --dbms=mssql). Otherwise it finds a Postgres-DB (which obviously can't be because of the attack vector). I think there > might be something broken. > > I reverted to #4233 which is working and correctly detects MSSQL. > > Greetings, > Christian > > > ----snip---- > > GET parameter 'meetingKey' is vulnerable. Do you want to keep testing the others? [y/N] > sqlmap identified the following injection points with a total of 47 HTTP(s) requests: > --- > Place: GET > Parameter: meetingKey > Type: stacked queries > Title: Microsoft SQL Server/Sybase stacked queries > Payload: passcode=&meetingKey='; WAITFOR DELAY '0:0:5';-- AND 'yUTW'='yUTW > > Type: AND/OR time-based blind > Title: Microsoft SQL Server/Sybase time-based blind > Payload: passcode=&meetingKey=' WAITFOR DELAY '0:0:5'-- AND 'PowX'='PowX > --- > > [17:33:51] [INFO] testing Microsoft SQL Server > [17:33:51] [WARNING] it is very important not to stress the network adapter's bandwidth during usage of time-based queries > [17:34:12] [INFO] confirming Microsoft SQL Server > <stuck here, Wireshark shows useless attack vectors (just the Waitfor Delay)> > > ----snip---- > > > ------------------------------------------------------------------------------ > Doing More with Less: The Next Generation Virtual Desktop > What are the key obstacles that have prevented many mid-market businesses > from deploying virtual desktops? How do next-generation virtual desktops > provide companies an easier-to-deploy, easier-to-manage and more affordable > virtual desktop model.http://www.accelacomm.com/jaw/sfnl/114/51426474/ > _______________________________________________ > sqlmap-users mailing list > sql...@li... > https://lists.sourceforge.net/lists/listinfo/sqlmap-users > -- Miroslav Stampar http://about.me/stamparm |
From: Bernardo D. A. G. <ber...@gm...> - 2011-09-12 13:45:56
|
Hi, You are likely using Python 2.5. Install Python 2.7 and rerun. Regards, Bernardo On 12 September 2011 14:32, anonymous anonymous <tm...@2c...> wrote: > Windows Server 2003, checked out from svn and "python sqlmap.py" prints: > > C:\Documents and Settings\PHIL\My Documents\sqlmap-dev>python sqlmap.py > File "sqlmap.py", line 96 > except exceptionsTuple, e: > ^ > SyntaxError: invalid syntax > ------------------------------------------------------------------------------ > Doing More with Less: The Next Generation Virtual Desktop > What are the key obstacles that have prevented many mid-market businesses > from deploying virtual desktops? How do next-generation virtual desktops > provide companies an easier-to-deploy, easier-to-manage and more affordable > virtual desktop model.http://www.accelacomm.com/jaw/sfnl/114/51426474/ > _______________________________________________ > sqlmap-users mailing list > sql...@li... > https://lists.sourceforge.net/lists/listinfo/sqlmap-users > > -- Bernardo Damele A. G. E-mail / Jabber: bernardo.damele (at) gmail.com Mobile: +447788962949 (UK 07788962949) PGP Key ID: Unavailable |
From: Bernardo D. A. G. <ber...@gm...> - 2011-09-12 13:44:52
|
Hi, Back-end database management system? Technique used to dump? An output of -v 3 --flush-session running with sqlmap updated from svn would be of help to debug this possible bug. Thank you. Bernardo On 27 August 2011 15:03, anonymous anonymous <tm...@2c...> wrote: > Subject. The latest revision. > ------------------------------------------------------------------------------ > EMC VNX: the world's simplest storage, starting under $10K > The only unified storage solution that offers unified management > Up to 160% more powerful than alternatives and 25% more efficient. > Guaranteed. http://p.sf.net/sfu/emc-vnx-dev2dev > _______________________________________________ > sqlmap-users mailing list > sql...@li... > https://lists.sourceforge.net/lists/listinfo/sqlmap-users > > -- Bernardo Damele A. G. E-mail / Jabber: bernardo.damele (at) gmail.com Mobile: +447788962949 (UK 07788962949) PGP Key ID: Unavailable |
From: anonymous a. <tm...@2c...> - 2011-09-12 13:32:25
|
<div>Windows Server 2003, checked out from svn and "python sqlmap.py" prints:</div><div> </div><div><div>C:\Documents and Settings\PHIL\My Documents\sqlmap-dev>python sqlmap.py</div><div> File "sqlmap.py", line 96</div><div> except exceptionsTuple, e:</div><div> ^</div><div>SyntaxError: invalid syntax</div></div> |
From: Bernardo D. A. G. <ber...@gm...> - 2011-09-12 13:25:18
|
Hi Christian, Can you please rerun with the latest development version from subversion with --flush-session -v3 -t traffic.log and provide us with traffic.log file privately in order to debug this possible bug? Thank you. Bernardo On 24 August 2011 16:58, Christian Rothländer <Chr...@cr...> wrote: > Hi there, > > I just updated to the last revision (4365) and tried to attack a Microsoft SQL Server 2005 via AND/OR time-based blind or MS stacked queries. > > The module which analysed which dba is there gets stuck with MSSQL (if I force --dbms=mssql). Otherwise it finds a Postgres-DB (which obviously can't be because of the attack vector). I think there > might be something broken. > > I reverted to #4233 which is working and correctly detects MSSQL. > > Greetings, > Christian > > > ----snip---- > > GET parameter 'meetingKey' is vulnerable. Do you want to keep testing the others? [y/N] > sqlmap identified the following injection points with a total of 47 HTTP(s) requests: > --- > Place: GET > Parameter: meetingKey > Type: stacked queries > Title: Microsoft SQL Server/Sybase stacked queries > Payload: passcode=&meetingKey='; WAITFOR DELAY '0:0:5';-- AND 'yUTW'='yUTW > > Type: AND/OR time-based blind > Title: Microsoft SQL Server/Sybase time-based blind > Payload: passcode=&meetingKey=' WAITFOR DELAY '0:0:5'-- AND 'PowX'='PowX > --- > > [17:33:51] [INFO] testing Microsoft SQL Server > [17:33:51] [WARNING] it is very important not to stress the network adapter's bandwidth during usage of time-based queries > [17:34:12] [INFO] confirming Microsoft SQL Server > <stuck here, Wireshark shows useless attack vectors (just the Waitfor Delay)> > > ----snip---- > > > ------------------------------------------------------------------------------ > Doing More with Less: The Next Generation Virtual Desktop > What are the key obstacles that have prevented many mid-market businesses > from deploying virtual desktops? How do next-generation virtual desktops > provide companies an easier-to-deploy, easier-to-manage and more affordable > virtual desktop model.http://www.accelacomm.com/jaw/sfnl/114/51426474/ > _______________________________________________ > sqlmap-users mailing list > sql...@li... > https://lists.sourceforge.net/lists/listinfo/sqlmap-users > -- Bernardo Damele A. G. E-mail / Jabber: bernardo.damele (at) gmail.com Mobile: +447788962949 (UK 07788962949) PGP Key ID: Unavailable |
From: Miroslav S. <mir...@gm...> - 2011-09-12 13:23:41
|
hi Preth. this should be fixed in v1.0-dev version from our repository. please check it out by issuing this: $ svn checkout https://svn.sqlmap.org/sqlmap/trunk/sqlmap sqlmap-dev kind regards On Wed, Aug 24, 2011 at 2:25 AM, Preth Hoonker <pre...@gm...> wrote: > Hi, i have some unexpected troubles with the latest version of SQLMap (0.9). > I hope this can help you to keep developing your t00l :) > > -------------------- error log -------------------------------- > [19:14:37] [CRITICAL] unhandled exception in sqlmap/0.9, retry your run with > the latest development version from the Subversion repository. If the > exception persists, please send by e-mail to > sql...@li... the following text and any information > required to reproduce the bug. The developers will try to reproduce the bug, > fix it accordingly and get back to you. > sqlmap version: 0.9 (r3630) > Python version: 2.7.1+ > Operating system: posix > Command line: ./sqlmap.py -u > ************************************************************************************** > --file-read=/etc/passwd > Technique: STACKED > Back-end DBMS: PostgreSQL (fingerprinted) > Traceback (most recent call last): > File "./sqlmap.py", line 82, in main > start() > File > "/home/preth00nker/Descargas/sqlmap-latest/sqlmap/lib/controller/controller.py", > line 447, in start > action() > File > "/home/preth00nker/Descargas/sqlmap-latest/sqlmap/lib/controller/action.py", > line 123, in action > conf.dumper.rFile(conf.rFile, conf.dbmsHandler.readFile(conf.rFile)) > File > "/home/preth00nker/Descargas/sqlmap-latest/sqlmap/plugins/generic/filesystem.py", > line 301, in readFile > fileContent = self.__unhexString(fileContent) > File > "/home/preth00nker/Descargas/sqlmap-latest/sqlmap/plugins/generic/filesystem.py", > line 43, in __unhexString > if len(hexStr) % 2 != 0: > TypeError: object of type 'NoneType' has no len() > > [*] shutting down at: 19:14:37 > > > -------------------- eof -------------------------------- > > greets > > ------------------------------------------------------------------------------ > Doing More with Less: The Next Generation Virtual Desktop > What are the key obstacles that have prevented many mid-market businesses > from deploying virtual desktops? How do next-generation virtual desktops > provide companies an easier-to-deploy, easier-to-manage and more affordable > virtual desktop model.http://www.accelacomm.com/jaw/sfnl/114/51426474/ > _______________________________________________ > sqlmap-users mailing list > sql...@li... > https://lists.sourceforge.net/lists/listinfo/sqlmap-users > > -- Miroslav Stampar http://about.me/stamparm |
From: Miroslav S. <mir...@gm...> - 2011-09-11 16:29:16
|
hi ryan. short answer is permissions (most often file write ones) long answer is: 1) --os-shell/--os-cmd/--os-pwn (STACKED INJECTION CASE) A) for MYSQL (rare in real life), PGSQL current DBMS user has to have UDF create/exec permissions B) MSSQL current DBMS user has to be able to run master.dbo.xp_cmdshell (EXEC permissions, function has to be enabled - sqlmap can try to enable it automatically, function has to exist) 2) --os-shell/--os-cmd/--os-pwn (NON-STACKED INJECTION CASE) A) for MYSQL current DBMS user has to have file write permissions to a reachable web directory kind regards On Sat, Sep 10, 2011 at 8:11 AM, ryan cartner <rya...@gm...> wrote: > what are the actual requirements for --os-cmd/shell/pwn ? I'm trying to > figure out how they work specifically. As far as I can tell you just need > write access to a folder in the web root. Is this true? Is there a way to > check your filesystem priviledges? > ------------------------------------------------------------------------------ > Malware Security Report: Protecting Your Business, Customers, and the > Bottom Line. Protect your business and customers by understanding the > threat from malware and how it can impact your online business. > http://www.accelacomm.com/jaw/sfnl/114/51427462/ > _______________________________________________ > sqlmap-users mailing list > sql...@li... > https://lists.sourceforge.net/lists/listinfo/sqlmap-users > > -- Miroslav Stampar http://about.me/stamparm |
From: Miroslav S. <mir...@gm...> - 2011-09-11 16:10:49
|
hi Derick. you can take a look at CHANGELOG for some quick info on new things: https://svn.sqlmap.org/sqlmap/trunk/sqlmap/doc/ChangeLog kind regards On Sat, Sep 10, 2011 at 9:24 AM, Derick Nyarko <nya...@ya...> wrote: > Okay cool. what's new in Sqlmap. can someone show me? > ------------------------------------------------------------------------------ > Malware Security Report: Protecting Your Business, Customers, and the > Bottom Line. Protect your business and customers by understanding the > threat from malware and how it can impact your online business. > http://www.accelacomm.com/jaw/sfnl/114/51427462/ > _______________________________________________ > sqlmap-users mailing list > sql...@li... > https://lists.sourceforge.net/lists/listinfo/sqlmap-users > > -- Miroslav Stampar http://about.me/stamparm |
From: Derick N. <nya...@ya...> - 2011-09-10 07:24:12
|
Okay cool. what's new in Sqlmap. can someone show me? |
From: ryan c. <rya...@gm...> - 2011-09-10 06:11:47
|
what are the actual requirements for --os-cmd/shell/pwn ? I'm trying to figure out how they work specifically. As far as I can tell you just need write access to a folder in the web root. Is this true? Is there a way to check your filesystem priviledges? |
From: Ahmed S. <ah...@is...> - 2011-09-09 18:14:27
|
AFAIK sqlmap uses into DUMPFILE and the speed of grabbing files within this function depends on the used technique it self during the injection On Fri, Sep 9, 2011 at 6:17 PM, ryan cartner <rya...@gm...> wrote: > Using --file-read on some injections can take a long time if the file must > be retrieved one character at a time. Currently there is no easy way to view > a partially downloaded file. This python script will do that. Simply run > sqlmap with --file-read and once you've read part of the file, run the > script like this: > > python ./partialfile.py -s ./output/www.something.com/session -f > global.asa > > it will grab the hex stream out of the sqlmap session file, convert it, and > spit it back out :) > Unfortunately this workaround is incompatible with --threads for two > reasons. First, sqlmap doesn't write out to the session file until either > it's finished or it receives sigint. second, in all my testing I haven't > been able to get it to take sigint (ctrl-c) when --threads is being used. > If anybody can figure out a fix for this i'm all ears :) > > #!/usr/bin/python > > import optparse, re, binascii > > parser = optparse.OptionParser() > parser.add_option('-s', help='sqlmap session file', dest='ses', nargs=1) > parser.add_option('-f', help='the filename of the file you are > downloading', dest=dl', nargs=1) > (opts, args) = parser.parse_args() > > if opts.ses is None or opts.dl is None: > print "Both a session file and the name of the file you are downloading are > required." > parser.print_help() > exit(-1) > print "Session file: " + opts.ses > pritn "Downloaded file: " + opts.dl > > f = open(opts.ses).read() > m = re.compile(opts.dl+"\'\)\)\]\[(.+?)$").search(f).group(1) > > if len(m) % 2 != 0 > m=m[0:-1] > > print binascii.unhexlify(m) > > > > ------------------------------------------------------------------------------ > Why Cloud-Based Security and Archiving Make Sense > Osterman Research conducted this study that outlines how and why cloud > computing security and archiving is rapidly being adopted across the IT > space for its ease of implementation, lower cost, and increased > reliability. Learn more. http://www.accelacomm.com/jaw/sfnl/114/51425301/ > _______________________________________________ > sqlmap-users mailing list > sql...@li... > https://lists.sourceforge.net/lists/listinfo/sqlmap-users > > -- - Ahmed Shawky El-Antry - lnxg33k owner "http://lnxg33k.wordpress.com" - Isecur1ty team member"http://www.isecur1ty.org" - Twitter @lnxg33k |
From: ryan c. <rya...@gm...> - 2011-09-09 16:17:07
|
Using --file-read on some injections can take a long time if the file must be retrieved one character at a time. Currently there is no easy way to view a partially downloaded file. This python script will do that. Simply run sqlmap with --file-read and once you've read part of the file, run the script like this: python ./partialfile.py -s ./output/www.something.com/session -f global.asa it will grab the hex stream out of the sqlmap session file, convert it, and spit it back out :) Unfortunately this workaround is incompatible with --threads for two reasons. First, sqlmap doesn't write out to the session file until either it's finished or it receives sigint. second, in all my testing I haven't been able to get it to take sigint (ctrl-c) when --threads is being used. If anybody can figure out a fix for this i'm all ears :) #!/usr/bin/python import optparse, re, binascii parser = optparse.OptionParser() parser.add_option('-s', help='sqlmap session file', dest='ses', nargs=1) parser.add_option('-f', help='the filename of the file you are downloading', dest=dl', nargs=1) (opts, args) = parser.parse_args() if opts.ses is None or opts.dl is None: print "Both a session file and the name of the file you are downloading are required." parser.print_help() exit(-1) print "Session file: " + opts.ses pritn "Downloaded file: " + opts.dl f = open(opts.ses).read() m = re.compile(opts.dl+"\'\)\)\]\[(.+?)$").search(f).group(1) if len(m) % 2 != 0 m=m[0:-1] print binascii.unhexlify(m) |
From: Miroslav S. <mir...@gm...> - 2011-09-09 13:07:28
|
hi ryan. it's because sqlmap doesn't know if it's ASCII or BINARY file at the other hand. hence, HEXing is the safest way to do it (especially for e.g. UNION based technique). kind regards On Fri, Sep 9, 2011 at 3:04 PM, ryan cartner <rya...@gm...> wrote: > why does --file-read retrieve a hex stream when downloading an ascii file? > > > ------------------------------------------------------------------------------ > Why Cloud-Based Security and Archiving Make Sense > Osterman Research conducted this study that outlines how and why cloud > computing security and archiving is rapidly being adopted across the IT > space for its ease of implementation, lower cost, and increased > reliability. Learn more. http://www.accelacomm.com/jaw/sfnl/114/51425301/ > _______________________________________________ > sqlmap-users mailing list > sql...@li... > https://lists.sourceforge.net/lists/listinfo/sqlmap-users > > -- Miroslav Stampar http://about.me/stamparm |