sqlmap-users Mailing List for sqlmap (Page 83)
Brought to you by:
inquisb
You can subscribe to this list here.
2008 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
(4) |
Oct
(11) |
Nov
(24) |
Dec
(13) |
---|---|---|---|---|---|---|---|---|---|---|---|---|
2009 |
Jan
(23) |
Feb
(17) |
Mar
(13) |
Apr
(48) |
May
(22) |
Jun
(18) |
Jul
(22) |
Aug
(13) |
Sep
(23) |
Oct
(6) |
Nov
(11) |
Dec
(25) |
2010 |
Jan
(21) |
Feb
(33) |
Mar
(61) |
Apr
(47) |
May
(48) |
Jun
(30) |
Jul
(24) |
Aug
(37) |
Sep
(52) |
Oct
(59) |
Nov
(32) |
Dec
(57) |
2011 |
Jan
(166) |
Feb
(93) |
Mar
(65) |
Apr
(117) |
May
(87) |
Jun
(124) |
Jul
(102) |
Aug
(78) |
Sep
(65) |
Oct
(22) |
Nov
(71) |
Dec
(79) |
2012 |
Jan
(93) |
Feb
(55) |
Mar
(45) |
Apr
(49) |
May
(56) |
Jun
(93) |
Jul
(95) |
Aug
(42) |
Sep
(26) |
Oct
(36) |
Nov
(32) |
Dec
(46) |
2013 |
Jan
(36) |
Feb
(78) |
Mar
(38) |
Apr
(57) |
May
(35) |
Jun
(39) |
Jul
(23) |
Aug
(33) |
Sep
(28) |
Oct
(38) |
Nov
(22) |
Dec
(16) |
2014 |
Jan
(33) |
Feb
(23) |
Mar
(41) |
Apr
(29) |
May
(12) |
Jun
(20) |
Jul
(21) |
Aug
(23) |
Sep
(18) |
Oct
(34) |
Nov
(12) |
Dec
(39) |
2015 |
Jan
(2) |
Feb
(51) |
Mar
(10) |
Apr
(28) |
May
(9) |
Jun
(22) |
Jul
(32) |
Aug
(35) |
Sep
(29) |
Oct
(50) |
Nov
(8) |
Dec
(2) |
2016 |
Jan
(8) |
Feb
(2) |
Mar
(3) |
Apr
(14) |
May
|
Jun
|
Jul
|
Aug
(12) |
Sep
|
Oct
|
Nov
(1) |
Dec
(19) |
2017 |
Jan
|
Feb
(18) |
Mar
|
Apr
(1) |
May
|
Jun
|
Jul
|
Aug
(4) |
Sep
|
Oct
|
Nov
(2) |
Dec
|
2018 |
Jan
|
Feb
|
Mar
(1) |
Apr
(1) |
May
(3) |
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
2019 |
Jan
|
Feb
|
Mar
|
Apr
(3) |
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
From: Robin W. <ro...@di...> - 2011-08-02 12:41:37
|
Hi I've got an application that is vulnerable to SQLi in one of two cookie parameters. The one that is injectable is the ASP.NET_SessionId which has to start with a valid session id but then if given an extra ' on the end it fails and dumps out a nice SQL error. So what I need to do is to tell sqlmap to inject onto the end of the one cookie but leave the other intact. Is this possible? Robin |
From: Ahmed S. <ah...@is...> - 2011-08-02 12:24:43
|
Thanks guys for the response. Miroslav Stampar, I'm gonna send you the link :) On Tue, Aug 2, 2011 at 10:40 AM, Bernardo Damele A. G. < ber...@gm...> wrote: > Hi Ahmed, > > On 2 August 2011 06:09, Ahmed Shawky <ah...@is...> wrote: > > guys is there an option to provide --union-char argument with a range of > > integers something like --union-char range(1,30) as in some cases NULL > > character isn't valid and providing a single character doesn't do the job > > No, it's not possible and I do not have plans at the moment to implement > this. > > > and is it possible to change that end of the payload to be /* instead of > -- > > ? > > Yes, you can use --suffix "/*". Remember to provide also --prefix > accordingly (e.g. "" or "'"). > > > -- > Bernardo Damele A. G. > > E-mail / Jabber: bernardo.damele (at) gmail.com > Mobile: +447788962949 (UK 07788962949) > PGP Key ID: Unavailable > -- - Ahmed Shawky El-Antry - Pen-tester, Programmer and System administrator - lnxg33k owner "http://lnxg33k.wordpress.com" - Isecur1ty team member"http://www.isecur1ty.org" - Twitter @lnxg33k |
From: Bernardo D. A. G. <ber...@gm...> - 2011-08-02 08:40:27
|
Hi Ahmed, On 2 August 2011 06:09, Ahmed Shawky <ah...@is...> wrote: > guys is there an option to provide --union-char argument with a range of > integers something like --union-char range(1,30) as in some cases NULL > character isn't valid and providing a single character doesn't do the job No, it's not possible and I do not have plans at the moment to implement this. > and is it possible to change that end of the payload to be /* instead of -- > ? Yes, you can use --suffix "/*". Remember to provide also --prefix accordingly (e.g. "" or "'"). -- Bernardo Damele A. G. E-mail / Jabber: bernardo.damele (at) gmail.com Mobile: +447788962949 (UK 07788962949) PGP Key ID: Unavailable |
From: Bernardo D. A. G. <ber...@gm...> - 2011-08-02 08:28:18
|
Hi Brad, Please find it fixed now. Thanks for reporting. Bernardo On 2 August 2011 04:11, Brad Merrell <bra...@gm...> wrote: > [WARNING] unknown charset 'th'. Please report by e-mail to > sql...@li.... > > Website: http://www.dutchiefanclub.com/newsdetail.php?id=66 > ------------------------------------------------------------------------------ > BlackBerry® DevCon Americas, Oct. 18-20, San Francisco, CA > The must-attend event for mobile developers. Connect with experts. > Get tools for creating Super Apps. See the latest technologies. > Sessions, hands-on labs, demos & much more. Register early & save! > http://p.sf.net/sfu/rim-blackberry-1 > _______________________________________________ > sqlmap-users mailing list > sql...@li... > https://lists.sourceforge.net/lists/listinfo/sqlmap-users > > -- Bernardo Damele A. G. E-mail / Jabber: bernardo.damele (at) gmail.com Mobile: +447788962949 (UK 07788962949) PGP Key ID: Unavailable |
From: Miroslav S. <mir...@gm...> - 2011-08-02 06:32:29
|
Hi. Well no this moment. Idea was to provide basic hash attack functionality and to let user manually do the others uncracked. If there would be more than one user request than yours we could try to implement this too in some near/far future. Kr On 2.8.2011. 07:53, "Liran Mimoni" <rea...@gm...> wrote: > > > Sent from my iPhone > > ------------------------------------------------------------------------------ > BlackBerry® DevCon Americas, Oct. 18-20, San Francisco, CA > The must-attend event for mobile developers. Connect with experts. > Get tools for creating Super Apps. See the latest technologies. > Sessions, hands-on labs, demos & much more. Register early & save! > http://p.sf.net/sfu/rim-blackberry-1 > _______________________________________________ > sqlmap-users mailing list > sql...@li... > https://lists.sourceforge.net/lists/listinfo/sqlmap-users |
From: Liran M. <rea...@gm...> - 2011-08-02 05:53:35
|
Sent from my iPhone |
From: Ahmed S. <ah...@is...> - 2011-08-02 05:14:26
|
guys is there an option to provide --union-char argument with a range of integers something like --union-char range(1,30) as in some cases NULL character isn't valid and providing a single character doesn't do the job and is it possible to change that end of the payload to be /* instead of -- ? -- - Ahmed Shawky El-Antry - Pen-tester, Programmer and System administrator - lnxg33k owner "http://lnxg33k.wordpress.com" - Isecur1ty team member"http://www.isecur1ty.org" - Twitter @lnxg33k |
From: Brad M. <bra...@gm...> - 2011-08-02 03:11:40
|
[WARNING] unknown charset 'th'. Please report by e-mail to sql...@li.... Website: http://www.dutchiefanclub.com/newsdetail.php?id=66 |
From: Miroslav S. <mir...@gm...> - 2011-08-01 23:43:06
|
hi Olu proper fix should be r4318. please update to have it fixed. kr On Tue, Aug 2, 2011 at 1:18 AM, Bernardo Damele A. G. <ber...@gm...> wrote: > Hi Olu, > > I committed a possible fix. Can you please svn update and retry? > > Bernardo > > > On 1 August 2011 19:29, Olu Akindeinde <sey...@gm...> wrote: >> Hi, >> I have started receiving this error when I Ctrl+C and it tries to crack the >> hashes. It wasn't like that before. >> Thanks >> [19:23:41] [WARNING] Ctrl+C detected in dumping phase >> >> >> [19:23:41] [CRITICAL] unhandled exception in sqlmap/1.0-dev (r4314), retry >> your run with the latest development version from the Subversion repository. >> If the exception persists, please send by e-mail to >> sql...@li... the following text and any information >> required to reproduce the bug. The developers will try to reproduce the bug, >> fix it accordingly and get back to you. >> sqlmap version: 1.0-dev (r4314) >> Python version: 2.6.1 >> Operating system: posix >> Command line: ./sqlmap.py -u >> ******************************************************** --data=ln=&passwd2= >> -v 2 -U ** -D *** -T ************ -C ************************ --dump >> --replicate >> Technique: BOOLEAN >> Back-end DBMS: MySQL (fingerprinted) >> Traceback (most recent call last): >> File "./sqlmap.py", line 86, in main >> start() >> File "/Users/fx/sqlmap/lib/controller/controller.py", line 554, in start >> action() >> File "/Users/fx/sqlmap/lib/controller/action.py", line 109, in action >> conf.dbmsHandler.dumpTable() >> File "/Users/fx/sqlmap/plugins/generic/enumeration.py", line 1754, in >> dumpTable >> attackDumpedTable() >> File "/Users/fx/sqlmap/lib/utils/hash.py", line 282, in attackDumpedTable >> if table[colUser]['values'][i] not in attack_dict: >> File "/Users/fx/sqlmap/lib/core/common.py", line 258, in __getitem__ >> return chunk[offset] >> IndexError: list index out of range >> [*] shutting down at 19:23:41 >> >> Thanks >> >> ------------------------------------------------------------------------------ >> BlackBerry® DevCon Americas, Oct. 18-20, San Francisco, CA >> The must-attend event for mobile developers. Connect with experts. >> Get tools for creating Super Apps. See the latest technologies. >> Sessions, hands-on labs, demos & much more. Register early & save! >> http://p.sf.net/sfu/rim-blackberry-1 >> _______________________________________________ >> sqlmap-users mailing list >> sql...@li... >> https://lists.sourceforge.net/lists/listinfo/sqlmap-users >> >> > > > > -- > Bernardo Damele A. G. > > E-mail / Jabber: bernardo.damele (at) gmail.com > Mobile: +447788962949 (UK 07788962949) > PGP Key ID: Unavailable > > ------------------------------------------------------------------------------ > BlackBerry® DevCon Americas, Oct. 18-20, San Francisco, CA > The must-attend event for mobile developers. Connect with experts. > Get tools for creating Super Apps. See the latest technologies. > Sessions, hands-on labs, demos & much more. Register early & save! > http://p.sf.net/sfu/rim-blackberry-1 > _______________________________________________ > sqlmap-users mailing list > sql...@li... > https://lists.sourceforge.net/lists/listinfo/sqlmap-users > -- Miroslav Stampar (@stamparm) E-mail: miroslav.stampar (at) gmail.com PGP Key ID: 0xB5397B1B |
From: Bernardo D. A. G. <ber...@gm...> - 2011-08-01 23:35:06
|
Hi Alessio, This should be fixed now. Thanks for reporting. Bernardo On 1 August 2011 14:03, Alessio Dalla Piazza <ale...@gm...> wrote: > Hi :) > Thanks for adding my name in doc/THANKS :) > > The latest error is correct but in dump db i have another error: > > [14:59:06] [INFO] fetching entries for table '***********' on database > 'Microsoft_Access_masterdb' > [14:59:06] [WARNING] HTTP error codes detected during testing: > 500 (Internal Server Error) - 277 times, 999 (?) - 1 times > > [14:59:06] [CRITICAL] unhandled exception in sqlmap/1.0-dev (r4314), retry > your run with the latest development version from the Subversion repository. > If the exception persists, please send by e-mail to > sql...@li... the following text and any information > required to reproduce the bug. The developers will try to reproduce the bug, > fix it accordingly and get back to you. > sqlmap version: 1.0-dev (r4314) > Python version: 2.7.1+ > Operating system: posix > Command line: ./sqlmap.py -u > ************************************************************************************** > --dump-all > Technique: UNION > Back-end DBMS: Microsoft Access (fingerprinted) > Traceback (most recent call last): > File "./sqlmap.py", line 86, in main > start() > File "/home/clshack/sqlmap-dev/lib/controller/controller.py", line 554, in > start > action() > File "/home/clshack/sqlmap-dev/lib/controller/action.py", line 112, in > action > conf.dbmsHandler.dumpAll() > File "/home/clshack/sqlmap-dev/plugins/generic/enumeration.py", line 1800, > in dumpAll > self.dumpTable() > File "/home/clshack/sqlmap-dev/plugins/generic/enumeration.py", line 1609, > in dumpTable > query = rootQuery.inband.query % (colString, conf.db, tbl) > TypeError: not all arguments converted during string formatting > > [*] shutting down at 14:59:06 > > -- > Alessio Dalla Piazza > http://www.clshack.it > > DownloadMb > http://www.downloadmb.it > > Contributor at BackBox Linux > http://www.backbox.org > > ------------------------------------------------------------------------------ > Got Input? Slashdot Needs You. > Take our quick survey online. Come on, we don't ask for help often. > Plus, you'll get a chance to win $100 to spend on ThinkGeek. > http://p.sf.net/sfu/slashdot-survey > > _______________________________________________ > sqlmap-users mailing list > sql...@li... > https://lists.sourceforge.net/lists/listinfo/sqlmap-users > > -- Bernardo Damele A. G. E-mail / Jabber: bernardo.damele (at) gmail.com Mobile: +447788962949 (UK 07788962949) PGP Key ID: Unavailable |
From: Bernardo D. A. G. <ber...@gm...> - 2011-08-01 23:34:20
|
Hi, This should be fixed now. Thanks for reporting. Bernardo 2011/8/1 anonymous anonymous <tm...@2c...>: > [21:20:51] [INFO] fetching entries for table 'admin' on database > 'Microsoft_Access_masterdb' > [21:20:51] [CRITICAL] unhandled exception in sqlmap/1.0-dev (r4314), retry > your run with the latest development version from the Subversion repository. > If the exception persists, please send by e-mail to > sql...@li... the following text and any information > required to reproduce the bug. The developers will try to reproduce the bug, > fix it accordingly and get back to you. > sqlmap version: 1.0-dev (r4314) > Python version: 2.6.6 > Operating system: posix > Command line: ./sqlmap.py -u > *************************************************** -p id -T ***** --dump > Technique: UNION > Back-end DBMS: Microsoft Access (fingerprinted) > Traceback (most recent call last): > File "./sqlmap.py", line 86, in main > start() > File "/root/sqlmap/lib/controller/controller.py", line 554, in start > action() > File "/root/sqlmap/lib/controller/action.py", line 109, in action > conf.dbmsHandler.dumpTable() > File "/root/sqlmap/plugins/generic/enumeration.py", line 1609, in > dumpTable > query = rootQuery.inband.query % (colString, conf.db, tbl) > TypeError: not all arguments converted during string formatting > [*] shutting down at 21:20:51 > ------------------------------------------------------------------------------ > BlackBerry® DevCon Americas, Oct. 18-20, San Francisco, CA > The must-attend event for mobile developers. Connect with experts. > Get tools for creating Super Apps. See the latest technologies. > Sessions, hands-on labs, demos & much more. Register early & save! > http://p.sf.net/sfu/rim-blackberry-1 > _______________________________________________ > sqlmap-users mailing list > sql...@li... > https://lists.sourceforge.net/lists/listinfo/sqlmap-users > > -- Bernardo Damele A. G. E-mail / Jabber: bernardo.damele (at) gmail.com Mobile: +447788962949 (UK 07788962949) PGP Key ID: Unavailable |
From: Bernardo D. A. G. <ber...@gm...> - 2011-08-01 23:18:39
|
Hi Olu, I committed a possible fix. Can you please svn update and retry? Bernardo On 1 August 2011 19:29, Olu Akindeinde <sey...@gm...> wrote: > Hi, > I have started receiving this error when I Ctrl+C and it tries to crack the > hashes. It wasn't like that before. > Thanks > [19:23:41] [WARNING] Ctrl+C detected in dumping phase > > > [19:23:41] [CRITICAL] unhandled exception in sqlmap/1.0-dev (r4314), retry > your run with the latest development version from the Subversion repository. > If the exception persists, please send by e-mail to > sql...@li... the following text and any information > required to reproduce the bug. The developers will try to reproduce the bug, > fix it accordingly and get back to you. > sqlmap version: 1.0-dev (r4314) > Python version: 2.6.1 > Operating system: posix > Command line: ./sqlmap.py -u > ******************************************************** --data=ln=&passwd2= > -v 2 -U ** -D *** -T ************ -C ************************ --dump > --replicate > Technique: BOOLEAN > Back-end DBMS: MySQL (fingerprinted) > Traceback (most recent call last): > File "./sqlmap.py", line 86, in main > start() > File "/Users/fx/sqlmap/lib/controller/controller.py", line 554, in start > action() > File "/Users/fx/sqlmap/lib/controller/action.py", line 109, in action > conf.dbmsHandler.dumpTable() > File "/Users/fx/sqlmap/plugins/generic/enumeration.py", line 1754, in > dumpTable > attackDumpedTable() > File "/Users/fx/sqlmap/lib/utils/hash.py", line 282, in attackDumpedTable > if table[colUser]['values'][i] not in attack_dict: > File "/Users/fx/sqlmap/lib/core/common.py", line 258, in __getitem__ > return chunk[offset] > IndexError: list index out of range > [*] shutting down at 19:23:41 > > Thanks > > ------------------------------------------------------------------------------ > BlackBerry® DevCon Americas, Oct. 18-20, San Francisco, CA > The must-attend event for mobile developers. Connect with experts. > Get tools for creating Super Apps. See the latest technologies. > Sessions, hands-on labs, demos & much more. Register early & save! > http://p.sf.net/sfu/rim-blackberry-1 > _______________________________________________ > sqlmap-users mailing list > sql...@li... > https://lists.sourceforge.net/lists/listinfo/sqlmap-users > > -- Bernardo Damele A. G. E-mail / Jabber: bernardo.damele (at) gmail.com Mobile: +447788962949 (UK 07788962949) PGP Key ID: Unavailable |
From: Liran M. <rea...@gm...> - 2011-08-01 21:33:50
|
MSSQL - there is a chance that sqlmap will manage to fetch all DB's but wont be able to get the tables? there is a way to bypass it? thanks web server operating system: Windows web application technology: ASP.NET, PHP 5.2.14 back-end DBMS: Microsoft SQL Server 2008 [00:31:15] [INFO] fetching tables for database: ******************** [00:31:15] [INFO] read from file '/root/stuff/sqlmap9/output/********************/session': None [00:31:16] [WARNING] it was not possible to count the number of entries for the used SQL query. sqlmap will assume that it returns only one entry [00:31:17] [INFO] read from file '/root/stuff/sqlmap9/output/********************/session': None [00:31:18] [WARNING] it was not possible to count the number of entries for the used SQL query. sqlmap will assume that it returns only one entry [00:31:18] [INFO] read from file '/root/stuff/sqlmap9/output/********************/session': None [00:31:18] [INFO] fetching number of tables for database '********************' [00:31:18] [INFO] read from file '/root/stuff/sqlmap9/output/********************/session': [00:31:18] [INFO] read from file '/root/stuff/sqlmap9/output/********************/session': [00:31:18] [INFO] retrieved: [00:31:21] [WARNING] unable to retrieve the number of tables for database '********************' [00:31:21] [CRITICAL] unable to retrieve the tables for any database [00:31:21] [WARNING] HTTP error codes detected during testing: 404 (Not Found) - 3 times [*] shutting down at 00:31:21 |
From: anonymous a. <tm...@2c...> - 2011-08-01 19:25:51
|
<div><div>[21:20:51] [INFO] fetching entries for table 'admin' on database 'Microsoft_Access_masterdb'</div><div>[21:20:51] [CRITICAL] unhandled exception in sqlmap/1.0-dev (r4314), retry your run with the latest development version from the Subversion repository. If the exception persists, please send by e-mail to sql...@li... the following text and any information required to reproduce the bug. The developers will try to reproduce the bug, fix it accordingly and get back to you.</div><div>sqlmap version: 1.0-dev (r4314)</div><div>Python version: 2.6.6</div><div>Operating system: posix</div><div>Command line: ./sqlmap.py -u *************************************************** -p id -T ***** --dump</div><div>Technique: UNION</div><div>Back-end DBMS: Microsoft Access (fingerprinted)</div><div>Traceback (most recent call last):</div><div> File "./sqlmap.py", line 86, in main</div><div> start()</div><div> File "/root/sqlmap/lib/controller/controller.py", line 554, in start</div><div> action()</div><div> File "/root/sqlmap/lib/controller/action.py", line 109, in action</div><div> conf.dbmsHandler.dumpTable()</div><div> File "/root/sqlmap/plugins/generic/enumeration.py", line 1609, in dumpTable</div><div> query = rootQuery.inband.query % (colString, conf.db, tbl)</div><div>TypeError: not all arguments converted during string formatting</div><div>[*] shutting down at 21:20:51</div></div> |
From: Olu A. <sey...@gm...> - 2011-08-01 18:29:37
|
Hi, I have started receiving this error when I Ctrl+C and it tries to crack the hashes. It wasn't like that before. Thanks [19:23:41] [WARNING] Ctrl+C detected in dumping phase [19:23:41] [CRITICAL] unhandled exception in sqlmap/1.0-dev (r4314), retry your run with the latest development version from the Subversion repository. If the exception persists, please send by e-mail to sql...@li... the following text and any information required to reproduce the bug. The developers will try to reproduce the bug, fix it accordingly and get back to you. sqlmap version: 1.0-dev (r4314) Python version: 2.6.1 Operating system: posix Command line: ./sqlmap.py -u ******************************************************** --data=ln=&passwd2= -v 2 -U ** -D *** -T ************ -C ************************ --dump --replicate Technique: BOOLEAN Back-end DBMS: MySQL (fingerprinted) Traceback (most recent call last): File "./sqlmap.py", line 86, in main start() File "/Users/fx/sqlmap/lib/controller/controller.py", line 554, in start action() File "/Users/fx/sqlmap/lib/controller/action.py", line 109, in action conf.dbmsHandler.dumpTable() File "/Users/fx/sqlmap/plugins/generic/enumeration.py", line 1754, in dumpTable attackDumpedTable() File "/Users/fx/sqlmap/lib/utils/hash.py", line 282, in attackDumpedTable if table[colUser]['values'][i] not in attack_dict: File "/Users/fx/sqlmap/lib/core/common.py", line 258, in __getitem__ return chunk[offset] IndexError: list index out of range [*] shutting down at 19:23:41 Thanks |
From: Alessio D. P. <ale...@gm...> - 2011-08-01 13:04:16
|
Hi :) Thanks for adding my name in doc/THANKS :) The latest error is correct but in dump db i have another error: [14:59:06] [INFO] fetching entries for table '***********' on database 'Microsoft_Access_masterdb' [14:59:06] [WARNING] HTTP error codes detected during testing: 500 (Internal Server Error) - 277 times, 999 (?) - 1 times [14:59:06] [CRITICAL] unhandled exception in sqlmap/1.0-dev (r4314), retry your run with the latest development version from the Subversion repository. If the exception persists, please send by e-mail to sql...@li... the following text and any information required to reproduce the bug. The developers will try to reproduce the bug, fix it accordingly and get back to you. sqlmap version: 1.0-dev (r4314) Python version: 2.7.1+ Operating system: posix Command line: ./sqlmap.py -u ************************************************************************************** --dump-all Technique: UNION Back-end DBMS: Microsoft Access (fingerprinted) Traceback (most recent call last): File "./sqlmap.py", line 86, in main start() File "/home/clshack/sqlmap-dev/lib/controller/controller.py", line 554, in start action() File "/home/clshack/sqlmap-dev/lib/controller/action.py", line 112, in action conf.dbmsHandler.dumpAll() File "/home/clshack/sqlmap-dev/plugins/generic/enumeration.py", line 1800, in dumpAll self.dumpTable() File "/home/clshack/sqlmap-dev/plugins/generic/enumeration.py", line 1609, in dumpTable query = rootQuery.inband.query % (colString, conf.db, tbl) TypeError: not all arguments converted during string formatting [*] shutting down at 14:59:06 -- Alessio Dalla Piazza *http://www.clshack.it* <http://www.clshack.it> *DownloadMb* http://www.downloadmb.it Contributor at *BackBox* Linux *http://www.backbox.org* |
From: alex a. <ale...@gm...> - 2011-08-01 11:47:58
|
i want toost |
From: Miroslav S. <mir...@gm...> - 2011-08-01 10:11:33
|
hi Alessio. it should be fixed with the latest commit. thank you for your report. kr On Mon, Aug 1, 2011 at 11:57 AM, Alessio Dalla Piazza <ale...@gm...> wrote: > > Hello :D > I have latest svn revision of sqlmap but i have an error: > > [11:55:51] [INFO] the back-end DBMS is Microsoft Access > web server operating system: Windows 2003 > web application technology: ASP.NET, Microsoft IIS 6.0, ASP > back-end DBMS: Microsoft Access > [11:55:51] [INFO] fetching tables for database: Microsoft_Access_masterdb > [11:55:51] [WARNING] HTTP error codes detected during testing: > 999 (?) - 1 times > > [11:55:51] [CRITICAL] unhandled exception in sqlmap/1.0-dev (r4312), retry > your run with the latest development version from the Subversion repository. > If the exception persists, please send by e-mail to > sql...@li... the following text and any information > required to reproduce the bug. The developers will try to reproduce the bug, > fix it accordingly and get back to you. > sqlmap version: 1.0-dev (r4312) > Python version: 2.7.1+ > Operating system: posix > Command line: ./sqlmap.py -u > ************************************************************************************** > --tables > Technique: UNION > Back-end DBMS: Microsoft Access (fingerprinted) > Traceback (most recent call last): > File "./sqlmap.py", line 86, in main > start() > File "/home/clshack/sqlmap-dev/lib/controller/controller.py", line 554, in > start > action() > File "/home/clshack/sqlmap-dev/lib/controller/action.py", line 91, in > action > conf.dumper.dbTables(conf.dbmsHandler.getTables()) > File "/home/clshack/sqlmap-dev/plugins/generic/enumeration.py", line 810, > in getTables > tables = self.getTables(False) > File "/home/clshack/sqlmap-dev/plugins/generic/enumeration.py", line 890, > in getTables > value = arrayizeValue(filter(None, value)) > TypeError: 'NoneType' object is not iterable > > [*] shutting down at 11:55:51 > > -- > Alessio Dalla Piazza > http://www.clshack.it > > DownloadMb > http://www.downloadmb.it > > Contributor at BackBox Linux > http://www.backbox.org > > ------------------------------------------------------------------------------ > Got Input? Slashdot Needs You. > Take our quick survey online. Come on, we don't ask for help often. > Plus, you'll get a chance to win $100 to spend on ThinkGeek. > http://p.sf.net/sfu/slashdot-survey > > _______________________________________________ > sqlmap-users mailing list > sql...@li... > https://lists.sourceforge.net/lists/listinfo/sqlmap-users > > -- Miroslav Stampar (@stamparm) E-mail: miroslav.stampar (at) gmail.com PGP Key ID: 0xB5397B1B |
From: Alessio D. P. <ale...@gm...> - 2011-08-01 09:58:17
|
Hello :D I have latest svn revision of sqlmap but i have an error: [11:55:51] [INFO] the back-end DBMS is Microsoft Access web server operating system: Windows 2003 web application technology: ASP.NET, Microsoft IIS 6.0, ASP back-end DBMS: Microsoft Access [11:55:51] [INFO] fetching tables for database: Microsoft_Access_masterdb [11:55:51] [WARNING] HTTP error codes detected during testing: 999 (?) - 1 times [11:55:51] [CRITICAL] unhandled exception in sqlmap/1.0-dev (r4312), retry your run with the latest development version from the Subversion repository. If the exception persists, please send by e-mail to sql...@li... the following text and any information required to reproduce the bug. The developers will try to reproduce the bug, fix it accordingly and get back to you. sqlmap version: 1.0-dev (r4312) Python version: 2.7.1+ Operating system: posix Command line: ./sqlmap.py -u ************************************************************************************** --tables Technique: UNION Back-end DBMS: Microsoft Access (fingerprinted) Traceback (most recent call last): File "./sqlmap.py", line 86, in main start() File "/home/clshack/sqlmap-dev/lib/controller/controller.py", line 554, in start action() File "/home/clshack/sqlmap-dev/lib/controller/action.py", line 91, in action conf.dumper.dbTables(conf.dbmsHandler.getTables()) File "/home/clshack/sqlmap-dev/plugins/generic/enumeration.py", line 810, in getTables tables = self.getTables(False) File "/home/clshack/sqlmap-dev/plugins/generic/enumeration.py", line 890, in getTables value = arrayizeValue(filter(None, value)) TypeError: 'NoneType' object is not iterable [*] shutting down at 11:55:51 -- Alessio Dalla Piazza *http://www.clshack.it* <http://www.clshack.it> *DownloadMb* http://www.downloadmb.it Contributor at *BackBox* Linux *http://www.backbox.org* |
From: Mohd Z. S. <zam...@gm...> - 2011-08-01 09:41:46
|
No problem. Thank you. Zamiri Sent from my iPhone On 1 Aug 2011, at 17:30, "Bernardo Damele A. G." <ber...@gm...> wrote: > Find it fixed now. > Thanks for reporting. > > Bernardo > > > On 31 July 2011 06:02, Mohd Zamiri Sanin <zam...@gm...> wrote: >> updated to the latest revision 4308 >> OS : Ubuntu 10.10 >> >> ./sqlmap.py --update >> Traceback (most recent call last): >> File "./sqlmap.py", line 27, in <module> >> from lib.controller.controller import start >> File "/root/sqlmap/lib/controller/controller.py", line 13, in <module> >> from lib.controller.action import action >> File "/root/sqlmap/lib/controller/action.py", line 10, in <module> >> from lib.controller.handler import setHandler >> File "/root/sqlmap/lib/controller/handler.py", line 28, in <module> >> from plugins.dbms.mssqlserver import MSSQLServerMap >> File "/root/sqlmap/plugins/dbms/mssqlserver/__init__.py", line 14, in <module> >> from plugins.dbms.mssqlserver.enumeration import Enumeration >> File "/root/sqlmap/plugins/dbms/mssqlserver/enumeration.py", line >> 28, in <module> >> from plugins.generic.enumeration import Enumeration as GenericEnumeration >> File "/root/sqlmap/plugins/generic/enumeration.py", line 73, in <module> >> from lib.utils.hash import attackDumpedTable >> File "/root/sqlmap/lib/utils/hash.py", line 20, in <module> >> _ = multiprocessing.Queue() >> File "/usr/lib/python2.6/multiprocessing/__init__.py", line 213, in Queue >> return Queue(maxsize) >> File "/usr/lib/python2.6/multiprocessing/queues.py", line 37, in __init__ >> self._rlock = Lock() >> File "/usr/lib/python2.6/multiprocessing/synchronize.py", line 117, >> in __init__ >> SemLock.__init__(self, SEMAPHORE, 1, 1) >> File "/usr/lib/python2.6/multiprocessing/synchronize.py", line 49, in __init__ >> sl = self._semlock = _multiprocessing.SemLock(kind, value, maxvalue) >> OSError: [Errno 38] Function not implemented >> >> ------------------------------------------------------------------------------ >> Got Input? Slashdot Needs You. >> Take our quick survey online. Come on, we don't ask for help often. >> Plus, you'll get a chance to win $100 to spend on ThinkGeek. >> http://p.sf.net/sfu/slashdot-survey >> _______________________________________________ >> sqlmap-users mailing list >> sql...@li... >> https://lists.sourceforge.net/lists/listinfo/sqlmap-users >> > > > > -- > Bernardo Damele A. G. > > E-mail / Jabber: bernardo.damele (at) gmail.com > Mobile: +447788962949 (UK 07788962949) > PGP Key ID: Unavailable |
From: Bernardo D. A. G. <ber...@gm...> - 2011-08-01 09:30:36
|
Find it fixed now. Thanks for reporting. Bernardo On 31 July 2011 06:02, Mohd Zamiri Sanin <zam...@gm...> wrote: > updated to the latest revision 4308 > OS : Ubuntu 10.10 > > ./sqlmap.py --update > Traceback (most recent call last): > File "./sqlmap.py", line 27, in <module> > from lib.controller.controller import start > File "/root/sqlmap/lib/controller/controller.py", line 13, in <module> > from lib.controller.action import action > File "/root/sqlmap/lib/controller/action.py", line 10, in <module> > from lib.controller.handler import setHandler > File "/root/sqlmap/lib/controller/handler.py", line 28, in <module> > from plugins.dbms.mssqlserver import MSSQLServerMap > File "/root/sqlmap/plugins/dbms/mssqlserver/__init__.py", line 14, in <module> > from plugins.dbms.mssqlserver.enumeration import Enumeration > File "/root/sqlmap/plugins/dbms/mssqlserver/enumeration.py", line > 28, in <module> > from plugins.generic.enumeration import Enumeration as GenericEnumeration > File "/root/sqlmap/plugins/generic/enumeration.py", line 73, in <module> > from lib.utils.hash import attackDumpedTable > File "/root/sqlmap/lib/utils/hash.py", line 20, in <module> > _ = multiprocessing.Queue() > File "/usr/lib/python2.6/multiprocessing/__init__.py", line 213, in Queue > return Queue(maxsize) > File "/usr/lib/python2.6/multiprocessing/queues.py", line 37, in __init__ > self._rlock = Lock() > File "/usr/lib/python2.6/multiprocessing/synchronize.py", line 117, > in __init__ > SemLock.__init__(self, SEMAPHORE, 1, 1) > File "/usr/lib/python2.6/multiprocessing/synchronize.py", line 49, in __init__ > sl = self._semlock = _multiprocessing.SemLock(kind, value, maxvalue) > OSError: [Errno 38] Function not implemented > > ------------------------------------------------------------------------------ > Got Input? Slashdot Needs You. > Take our quick survey online. Come on, we don't ask for help often. > Plus, you'll get a chance to win $100 to spend on ThinkGeek. > http://p.sf.net/sfu/slashdot-survey > _______________________________________________ > sqlmap-users mailing list > sql...@li... > https://lists.sourceforge.net/lists/listinfo/sqlmap-users > -- Bernardo Damele A. G. E-mail / Jabber: bernardo.damele (at) gmail.com Mobile: +447788962949 (UK 07788962949) PGP Key ID: Unavailable |
From: Bernardo D. A. G. <ber...@gm...> - 2011-07-31 10:28:51
|
Hi Liran, 1.0 stable will be released within a year or so. Thanks for the compliments. Bernardo On 31 July 2011 00:52, Liran Mimoni <rea...@gm...> wrote: > Thanks Miroslav > When this build will be available for download? > and you 2 made an amazing app, Tomorrow i'm going to donate to your project, > your program is a real pro for me! > what's the paypal address for it ? > > On Sun, Jul 31, 2011 at 12:42 AM, Miroslav Stampar > <mir...@gm...> wrote: >> >> hi. >> >> here was a problem in programs logic that needed to be changed. >> >> with the last commit there won't be anymore questions like "do you >> want to retrieve..." for --sql-shell/--sql-query. this was causing >> problems (program did nothing) for non-compatible answers (N for >> queries and Y for non-queries). >> >> to make things short, there was a program logic bug that should be >> fixed now with r4307. >> >> kr >> >> On Sat, Jul 30, 2011 at 6:52 PM, Liran Mimoni <rea...@gm...> >> wrote: >> > sql-shell> update news set title = "dasdasd"; >> > do you want to retrieve the SQL statement output? [y/N/a] y >> > [19:50:14] [INFO] fetching SQL data manipulation query output: 'update >> > news >> > set title = "dasdasd";' >> > [19:50:14] [PAYLOAD] -1868 UNION ALL SELECT NULL, NULL, NULL, >> > CONCAT(CHAR(58,111,100,99,58),IFNULL(UPDATE news set title = >> > "dasdasd";,CHAR(32)),CHAR(58,100,117,121,58)), NULL, NULL# >> > [19:50:15] [WARNING] if the problem persists with 'None' values please >> > try >> > to use hidden switch --no-cast (fixing problems with some collation >> > issues) >> > [19:50:15] [DEBUG] performed 1 queries in 0 seconds >> > [19:50:15] [PAYLOAD] -3449 >> > [19:50:16] [INFO] retrieving the length of query output >> > [19:50:16] [PAYLOAD] -1492 OR NOT (ORD(MID((IFNULL(LENGTH(UPDATE news >> > set >> > title = "dasdasd";),CHAR(32))),1,1)) > 51) >> > [19:50:16] [PAYLOAD] -1492 OR NOT (ORD(MID((IFNULL(LENGTH(UPDATE news >> > set >> > title = "dasdasd";),CHAR(32))),1,1)) > 48) >> > [19:50:16] [PAYLOAD] -1492 OR NOT (ORD(MID((IFNULL(LENGTH(UPDATE news >> > set >> > title = "dasdasd";),CHAR(32))),1,1)) > 1) >> > [19:50:17] [INFO] retrieved: >> > [19:50:17] [DEBUG] performed 3 queries in 1 seconds >> > [19:50:17] [DEBUG] starting 50 threads >> > [19:50:17] [PAYLOAD] -1492 OR NOT (ORD(MID((IFNULL(UPDATE news set title >> > = >> > "dasdasd";,CHAR(32))),1,1)) > 64) >> > [19:50:17] [PAYLOAD] -1492 OR NOT (ORD(MID((IFNULL(UPDATE news set title >> > = >> > "dasdasd";,CHAR(32))),1,1)) > 32) >> > [19:50:17] [PAYLOAD] -1492 OR NOT (ORD(MID((IFNULL(UPDATE news set title >> > = >> > "dasdasd";,CHAR(32))),1,1)) > 16) >> > [19:50:18] [PAYLOAD] -1492 OR NOT (ORD(MID((IFNULL(UPDATE news set title >> > = >> > "dasdasd";,CHAR(32))),1,1)) > 8) >> > [19:50:18] [PAYLOAD] -1492 OR NOT (ORD(MID((IFNULL(UPDATE news set title >> > = >> > "dasdasd";,CHAR(32))),1,1)) > 4) >> > [19:50:18] [PAYLOAD] -1492 OR NOT (ORD(MID((IFNULL(UPDATE news set title >> > = >> > "dasdasd";,CHAR(32))),1,1)) > 2) >> > [19:50:18] [PAYLOAD] -1492 OR NOT (ORD(MID((IFNULL(UPDATE news set title >> > = >> > "dasdasd";,CHAR(32))),1,1)) > 1) >> > [19:50:19] [INFO] retrieved: >> > [19:50:19] [DEBUG] performed 7 queries in 3 seconds >> > >> > the update command didnt work, it didnt updated the requested column >> > Please help me thanks >> > >> > ------------------------------------------------------------------------------ >> > Got Input? Slashdot Needs You. >> > Take our quick survey online. Come on, we don't ask for help often. >> > Plus, you'll get a chance to win $100 to spend on ThinkGeek. >> > http://p.sf.net/sfu/slashdot-survey >> > _______________________________________________ >> > sqlmap-users mailing list >> > sql...@li... >> > https://lists.sourceforge.net/lists/listinfo/sqlmap-users >> > >> > >> >> >> >> -- >> Miroslav Stampar (@stamparm) >> >> E-mail: miroslav.stampar (at) gmail.com >> PGP Key ID: 0xB5397B1B > > > ------------------------------------------------------------------------------ > Got Input? Slashdot Needs You. > Take our quick survey online. Come on, we don't ask for help often. > Plus, you'll get a chance to win $100 to spend on ThinkGeek. > http://p.sf.net/sfu/slashdot-survey > _______________________________________________ > sqlmap-users mailing list > sql...@li... > https://lists.sourceforge.net/lists/listinfo/sqlmap-users > > -- Bernardo Damele A. G. E-mail / Jabber: bernardo.damele (at) gmail.com Mobile: +447788962949 (UK 07788962949) PGP Key ID: Unavailable |
From: Miroslav S. <mir...@gm...> - 2011-07-31 08:55:32
|
Hi. This is at least challenging, and maybe impossible to do in normal cases :) Problem is called encoding. You are using one encoding on your console, one encoding is used by the backend DBMS, one encoding is used by the server itself... Lots of interchanges is going on, and on some instances those interencoding changes are incompatible. The most usual problem is the incompatibility of the console encoding with the target itself. In your case you are most probably using some other encoding than the japanese one in your console and I wouldn't recommend changing of the console encoding just for doing this. I can only recommend you to "try" to --dump all the tables from the given db if the db name is something usable (e.g. shopdb). so, instead of using -T "japanese_table_name" you can try to dump all tables from that same database with -D "normal_dbname" --dump. If you are not able to do that either then please report back and we'll try to test it ourselves. KR On Sun, Jul 31, 2011 at 2:56 AM, anonymous anonymous <tm...@2c...> wrote: > Hello! > How can I access to japaneese table for example: > ./sqlmap.py -u "http://test/shop.asp?id=123" --technique=E --threads 50 -T > "注文履歴" --columns > If I use --dbs option this table enumareted in db tables list. > ------------------------------------------------------------------------------ > Got Input? Slashdot Needs You. > Take our quick survey online. Come on, we don't ask for help often. > Plus, you'll get a chance to win $100 to spend on ThinkGeek. > http://p.sf.net/sfu/slashdot-survey > _______________________________________________ > sqlmap-users mailing list > sql...@li... > https://lists.sourceforge.net/lists/listinfo/sqlmap-users > > -- Miroslav Stampar (@stamparm) E-mail: miroslav.stampar (at) gmail.com PGP Key ID: 0xB5397B1B |
From: Mohd Z. S. <zam...@gm...> - 2011-07-31 05:02:30
|
updated to the latest revision 4308 OS : Ubuntu 10.10 ./sqlmap.py --update Traceback (most recent call last): File "./sqlmap.py", line 27, in <module> from lib.controller.controller import start File "/root/sqlmap/lib/controller/controller.py", line 13, in <module> from lib.controller.action import action File "/root/sqlmap/lib/controller/action.py", line 10, in <module> from lib.controller.handler import setHandler File "/root/sqlmap/lib/controller/handler.py", line 28, in <module> from plugins.dbms.mssqlserver import MSSQLServerMap File "/root/sqlmap/plugins/dbms/mssqlserver/__init__.py", line 14, in <module> from plugins.dbms.mssqlserver.enumeration import Enumeration File "/root/sqlmap/plugins/dbms/mssqlserver/enumeration.py", line 28, in <module> from plugins.generic.enumeration import Enumeration as GenericEnumeration File "/root/sqlmap/plugins/generic/enumeration.py", line 73, in <module> from lib.utils.hash import attackDumpedTable File "/root/sqlmap/lib/utils/hash.py", line 20, in <module> _ = multiprocessing.Queue() File "/usr/lib/python2.6/multiprocessing/__init__.py", line 213, in Queue return Queue(maxsize) File "/usr/lib/python2.6/multiprocessing/queues.py", line 37, in __init__ self._rlock = Lock() File "/usr/lib/python2.6/multiprocessing/synchronize.py", line 117, in __init__ SemLock.__init__(self, SEMAPHORE, 1, 1) File "/usr/lib/python2.6/multiprocessing/synchronize.py", line 49, in __init__ sl = self._semlock = _multiprocessing.SemLock(kind, value, maxvalue) OSError: [Errno 38] Function not implemented |
From: anonymous a. <tm...@2c...> - 2011-07-31 01:14:19
|
<div>Hello!</div><div>How can I access to japaneese table for example:</div><div>./sqlmap.py -u "http://test/shop.asp?id=123" --technique=E --threads 50 -T "注文履歴" --columns</div><div>If I use --dbs option this table enumareted in db tables list.</div> |