mirror of
https://github.com/sqlmapproject/sqlmap.git
synced 2026-08-04 14:55:40 +00:00
second step toward negative logic support (ported to detection phase too) - works well with --string, --regexp and --code now
This commit is contained in:
parent
0013b0970f
commit
4520744b4d
2 changed files with 6 additions and 1 deletions
|
|
@ -322,6 +322,9 @@ def checkSqlInjection(place, parameter, value):
|
|||
boundPayload = agent.suffixQuery(boundPayload, comment, suffix, where)
|
||||
cmpPayload = agent.payload(place, parameter, newValue=boundPayload, where=where)
|
||||
|
||||
pushValue(kb.negativeLogic)
|
||||
kb.negativeLogic = "OR NOT" in cmpPayload
|
||||
|
||||
return cmpPayload
|
||||
|
||||
# Useful to set kb.matchRatio at first based on
|
||||
|
|
@ -347,6 +350,8 @@ def checkSqlInjection(place, parameter, value):
|
|||
|
||||
injectable = True
|
||||
|
||||
kb.negativeLogic = popValue()
|
||||
|
||||
# In case of error-based SQL injection
|
||||
elif method == PAYLOAD.METHOD.GREP:
|
||||
# Perform the test's request and grep the response
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue