sqlmap/lib/parse/headers.py

41 lines
1.7 KiB
Python

#!/usr/bin/env python
"""
Copyright (c) 2006-2026 sqlmap developers (https://sqlmap.org)
See the file 'LICENSE' for copying permission
"""
import os
from lib.core.common import parseXmlFile
from lib.core.common import singleTimeWarnMessage
from lib.core.data import kb
from lib.core.data import paths
from lib.parse.handler import FingerprintHandler
def headersParser(headers):
"""
This function calls a class that parses the input HTTP headers to
fingerprint the back-end database management system operating system
and the web application technology
"""
if not kb.headerPaths:
kb.headerPaths = {
"microsoftsharepointteamservices": os.path.join(paths.SQLMAP_XML_BANNER_PATH, "sharepoint.xml"),
"server": os.path.join(paths.SQLMAP_XML_BANNER_PATH, "server.xml"),
"servlet-engine": os.path.join(paths.SQLMAP_XML_BANNER_PATH, "servlet-engine.xml"),
"set-cookie": os.path.join(paths.SQLMAP_XML_BANNER_PATH, "set-cookie.xml"),
"x-aspnet-version": os.path.join(paths.SQLMAP_XML_BANNER_PATH, "x-aspnet-version.xml"),
"x-powered-by": os.path.join(paths.SQLMAP_XML_BANNER_PATH, "x-powered-by.xml"),
}
for header, xmlfile in kb.headerPaths.items():
if header in headers:
handler = FingerprintHandler(headers[header], kb.headersFp)
try:
parseXmlFile(xmlfile, handler)
parseXmlFile(paths.GENERIC_XML, handler)
except Exception:
# best-effort header fingerprinting - a broken/patched xml.sax must not abort the scan (see #6086)
singleTimeWarnMessage("unable to parse the response headers for technology fingerprinting")