Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Commit 7f4fa7c

Browse files
committed
Minor refactoring
1 parent b820975 commit 7f4fa7c

11 files changed

Lines changed: 23 additions & 23 deletions

tamper/apostrophemask.py

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -27,4 +27,4 @@ def tamper(payload):
2727
* http://lukasz.pilorz.net/testy/full_width_utf/index.phps
2828
"""
2929

30-
return payload.replace('\'', '%EF%BC%87') if payload else payload
30+
return payload.replace('\'', "%EF%BC%87") if payload else payload

tamper/apostrophenullencode.py

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -21,4 +21,4 @@ def tamper(payload):
2121
* Output: AND %00%271%00%27=%00%271%00%27
2222
"""
2323

24-
return payload.replace('\'', '%00%27') if payload else payload
24+
return payload.replace('\'', "%00%27") if payload else payload

tamper/chardoubleencode.py

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -40,7 +40,7 @@ def tamper(payload):
4040
retVal += payload[i:i+3]
4141
i += 3
4242
else:
43-
retVal += '%%25%X' % ord(payload[i])
43+
retVal += '%%25%.2X' % ord(payload[i])
4444
i += 1
4545

4646
return retVal

tamper/charencode.py

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -47,7 +47,7 @@ def tamper(payload):
4747
retVal += payload[i:i+3]
4848
i += 3
4949
else:
50-
retVal += '%%%X' % ord(payload[i])
50+
retVal += '%%%.2X' % ord(payload[i])
5151
i += 1
5252

5353
return retVal

tamper/charunicodeencode.py

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -52,7 +52,7 @@ def tamper(payload):
5252
retVal += "%%u00%s" % payload[i+1:i+3]
5353
i += 3
5454
else:
55-
retVal += '%%u00%X' % ord(payload[i])
55+
retVal += '%%u%.4X' % ord(payload[i])
5656
i += 1
5757

5858
return retVal

tamper/equaltolike.py

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -38,7 +38,7 @@ def tamper(payload):
3838

3939
def process(match):
4040
word = match.group()
41-
word = "%sLIKE%s" % (" " if word[0]!=" " else "", " " if word[-1]!=" " else "")
41+
word = "%sLIKE%s" % (" " if word[0] != " " else "", " " if word[-1] != " " else "")
4242

4343
return word
4444

tamper/ifnull2ifisnull.py

Lines changed: 8 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -36,27 +36,27 @@ def tamper(payload):
3636
if payload and payload.find("IFNULL") > -1:
3737
while payload.find("IFNULL(") > -1:
3838
index = payload.find("IFNULL(")
39-
deepness = 1
39+
depth = 1
4040
comma, end = None, None
4141

4242
for i in xrange(index + len("IFNULL("), len(payload)):
43-
if deepness == 1 and payload[i] == ',':
43+
if depth == 1 and payload[i] == ',':
4444
comma = i
4545

46-
elif deepness == 1 and payload[i] == ')':
46+
elif depth == 1 and payload[i] == ')':
4747
end = i
4848
break
4949

5050
elif payload[i] == '(':
51-
deepness += 1
51+
depth += 1
5252

5353
elif payload[i] == ')':
54-
deepness -= 1
54+
depth -= 1
5555

5656
if comma and end:
57-
A = payload[index + len("IFNULL("):comma]
58-
B = payload[comma + 1:end]
59-
newVal = "IF(ISNULL(%s),%s,%s)" % (A, B, A)
57+
_ = payload[index + len("IFNULL("):comma]
58+
__ = payload[comma + 1:end]
59+
newVal = "IF(ISNULL(%s),%s,%s)" % (_, __, _)
6060
payload = payload[:index] + newVal + payload[end+1:]
6161
else:
6262
break

tamper/randomcase.py

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -43,11 +43,11 @@ def tamper(payload):
4343
word = match.group()
4444

4545
if word.upper() in kb.keywords:
46-
newWord = str()
46+
_ = str()
4747

4848
for i in xrange(len(word)):
49-
newWord += word[i].upper() if randomRange(0, 1) else word[i].lower()
49+
_ += word[i].upper() if randomRange(0, 1) else word[i].lower()
5050

51-
retVal = retVal.replace(word, newWord)
51+
retVal = retVal.replace(word, _)
5252

5353
return retVal

tamper/randomcomments.py

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -29,12 +29,12 @@ def tamper(payload):
2929
continue
3030

3131
if word.upper() in kb.keywords:
32-
newWord = word[0]
32+
_ = word[0]
3333

3434
for i in xrange(1, len(word) - 1):
35-
newWord += "%s%s" % ("/**/" if randomRange(0, 1) else "", word[i])
35+
_ += "%s%s" % ("/**/" if randomRange(0, 1) else "", word[i])
3636

37-
newWord += word[-1]
38-
retVal = retVal.replace(word, newWord)
37+
_ += word[-1]
38+
retVal = retVal.replace(word, _)
3939

4040
return retVal

tamper/space2mssqlblank.py

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -53,7 +53,7 @@ def tamper(payload):
5353
# CR 0D carriage return
5454
# SO 0E shift out
5555
# SI 0F shift in
56-
blanks = ['%01', '%02', '%03', '%04', '%05', '%06', '%07', '%08', '%09', '%0B', '%0C', '%0D', '%0E', '%0F', '%0A']
56+
blanks = ('%01', '%02', '%03', '%04', '%05', '%06', '%07', '%08', '%09', '%0B', '%0C', '%0D', '%0E', '%0F', '%0A')
5757
retVal = payload
5858

5959
if payload:

0 commit comments

Comments
 (0)