Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Commit a8cb14e

Browse files
committed
Minor patch (disable tamper script usage in WAF/IDS/IPS check phase)
1 parent c634f0b commit a8cb14e

4 files changed

Lines changed: 7 additions & 7 deletions

File tree

lib/controller/checks.py

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1359,7 +1359,7 @@ def checkWaf():
13591359
conf.timeout = IDS_WAF_CHECK_TIMEOUT
13601360

13611361
try:
1362-
retVal = Request.queryPage(place=place, value=value, getRatioValue=True, noteResponseTime=False, silent=True)[1] < IDS_WAF_CHECK_RATIO
1362+
retVal = Request.queryPage(place=place, value=value, getRatioValue=True, noteResponseTime=False, silent=True, disableTampering=True)[1] < IDS_WAF_CHECK_RATIO
13631363
except SqlmapConnectionException:
13641364
retVal = True
13651365
finally:

lib/core/settings.py

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@
1919
from lib.core.enums import OS
2020

2121
# sqlmap version (<major>.<minor>.<month>.<monthly commit>)
22-
VERSION = "1.2.4.12"
22+
VERSION = "1.2.4.13"
2323
TYPE = "dev" if VERSION.count('.') > 2 and VERSION.split('.')[-1] != '0' else "stable"
2424
TYPE_COLORS = {"dev": 33, "stable": 90, "pip": 34}
2525
VERSION_STRING = "sqlmap/%s#%s" % ('.'.join(VERSION.split('.')[:-1]) if VERSION.count('.') > 2 and VERSION.split('.')[-1] == '0' else VERSION, TYPE)

lib/request/connect.py

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -770,7 +770,7 @@ class _(dict):
770770

771771
@staticmethod
772772
@stackedmethod
773-
def queryPage(value=None, place=None, content=False, getRatioValue=False, silent=False, method=None, timeBasedCompare=False, noteResponseTime=True, auxHeaders=None, response=False, raise404=None, removeReflection=True):
773+
def queryPage(value=None, place=None, content=False, getRatioValue=False, silent=False, method=None, timeBasedCompare=False, noteResponseTime=True, auxHeaders=None, response=False, raise404=None, removeReflection=True, disableTampering=False):
774774
"""
775775
This method calls a function to get the target URL page content
776776
and returns its page ratio (0 <= ratio <= 1) or a boolean value
@@ -817,7 +817,7 @@ def queryPage(value=None, place=None, content=False, getRatioValue=False, silent
817817
conf.httpHeaders.append((HTTP_HEADER.CONTENT_TYPE, contentType))
818818

819819
if payload:
820-
if kb.tamperFunctions:
820+
if not disableTampering and kb.tamperFunctions:
821821
for function in kb.tamperFunctions:
822822
try:
823823
payload = function(payload=payload, headers=auxHeaders)

txt/checksum.md5

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,7 @@ c88d66597f4aab719bde4542b0a1a6e0 extra/shutils/regressiontest.py
2121
1e5532ede194ac9c083891c2f02bca93 extra/sqlharvest/__init__.py
2222
b3e60ea4e18a65c48515d04aab28ff68 extra/sqlharvest/sqlharvest.py
2323
0f581182871148b0456a691ae85b04c0 lib/controller/action.py
24-
5084b16b037ed8d29f594f6113fe78e3 lib/controller/checks.py
24+
56d325f83671146c28ac300ff553420f lib/controller/checks.py
2525
c414cecdb0472c92cf50ed5b01e4438c lib/controller/controller.py
2626
c7443613a0a2505b1faec931cee2a6ef lib/controller/handler.py
2727
1e5532ede194ac9c083891c2f02bca93 lib/controller/__init__.py
@@ -46,7 +46,7 @@ c9a56e58984420a5abb7a3f7aadc196d lib/core/optiondict.py
4646
0c3eef46bdbf87e29a3f95f90240d192 lib/core/replication.py
4747
a7db43859b61569b601b97f187dd31c5 lib/core/revision.py
4848
fcb74fcc9577523524659ec49e2e964b lib/core/session.py
49-
16bc4ff0ccd5121f1b90016b5d759ef6 lib/core/settings.py
49+
8a247c468eef23045b8537d4ff98d823 lib/core/settings.py
5050
0dfc2ed40adf72e302291f6ecd4406f6 lib/core/shell.py
5151
a7edc9250d13af36ac0108f259859c19 lib/core/subprocessng.py
5252
a35efa7bec9f1e6cedf17c9830a79241 lib/core/target.py
@@ -68,7 +68,7 @@ ec4e56bbb1349176b2a22e0b99ba6a55 lib/parse/payloads.py
6868
30eed3a92a04ed2c29770e1b10d39dc0 lib/request/basicauthhandler.py
6969
7e8e0a3fdebbe443832c1bab2f8d3869 lib/request/basic.py
7070
c0cabedead14b8a23353b606672cff42 lib/request/comparison.py
71-
18052b8924b77eb2e772350b262aae88 lib/request/connect.py
71+
1865164621eb94c9c231006765065c17 lib/request/connect.py
7272
dd4598675027fae99f2e2475b05986da lib/request/direct.py
7373
2044fce3f4ffa268fcfaaf63241b1e64 lib/request/dns.py
7474
eee965d781546d05f36cfd14af050913 lib/request/httpshandler.py

0 commit comments

Comments
 (0)