2019-05-08 12:47:52 +02:00
|
|
|
#!/usr/bin/env python
|
2008-10-15 15:38:22 +00:00
|
|
|
|
|
|
|
|
"""
|
2026-01-01 19:12:07 +01:00
|
|
|
Copyright (c) 2006-2026 sqlmap developers (https://sqlmap.org)
|
2017-10-11 14:50:46 +02:00
|
|
|
See the file 'LICENSE' for copying permission
|
2008-10-15 15:38:22 +00:00
|
|
|
"""
|
|
|
|
|
|
2012-04-03 14:34:15 +00:00
|
|
|
import re
|
|
|
|
|
|
2008-10-15 15:38:22 +00:00
|
|
|
from xml.sax.handler import ContentHandler
|
|
|
|
|
|
2011-01-28 16:36:09 +00:00
|
|
|
from lib.core.common import Backend
|
2010-04-16 19:57:00 +00:00
|
|
|
from lib.core.common import parseXmlFile
|
2008-10-15 15:38:22 +00:00
|
|
|
from lib.core.common import sanitizeStr
|
2008-11-15 23:41:31 +00:00
|
|
|
from lib.core.data import kb
|
|
|
|
|
from lib.core.data import paths
|
2010-11-08 09:20:02 +00:00
|
|
|
from lib.core.enums import DBMS
|
2008-11-18 17:42:46 +00:00
|
|
|
from lib.parse.handler import FingerprintHandler
|
2008-11-15 23:41:31 +00:00
|
|
|
|
|
|
|
|
class MSSQLBannerHandler(ContentHandler):
|
|
|
|
|
"""
|
|
|
|
|
This class defines methods to parse and extract information from the
|
|
|
|
|
given Microsoft SQL Server banner based upon the data in XML file
|
|
|
|
|
"""
|
|
|
|
|
|
2009-04-22 11:48:07 +00:00
|
|
|
def __init__(self, banner, info):
|
2011-01-15 12:53:40 +00:00
|
|
|
ContentHandler.__init__(self)
|
|
|
|
|
|
2021-01-05 13:36:04 +01:00
|
|
|
self._banner = sanitizeStr(banner or "")
|
2012-02-16 13:46:01 +00:00
|
|
|
self._inVersion = False
|
|
|
|
|
self._inServicePack = False
|
|
|
|
|
self._release = None
|
|
|
|
|
self._version = ""
|
|
|
|
|
self._versionAlt = None
|
|
|
|
|
self._servicePack = ""
|
|
|
|
|
self._info = info
|
|
|
|
|
|
|
|
|
|
def _feedInfo(self, key, value):
|
2008-11-17 17:41:02 +00:00
|
|
|
value = sanitizeStr(value)
|
|
|
|
|
|
2013-01-09 15:38:41 +01:00
|
|
|
if value in (None, "None"):
|
2008-11-17 17:41:02 +00:00
|
|
|
return
|
|
|
|
|
|
2012-02-16 13:46:01 +00:00
|
|
|
self._info[key] = value
|
2008-11-15 23:41:31 +00:00
|
|
|
|
2008-10-15 15:38:22 +00:00
|
|
|
def startElement(self, name, attrs):
|
|
|
|
|
if name == "signatures":
|
2012-02-16 13:46:01 +00:00
|
|
|
self._release = sanitizeStr(attrs.get("release"))
|
2008-10-15 15:38:22 +00:00
|
|
|
|
|
|
|
|
elif name == "version":
|
2012-02-16 13:46:01 +00:00
|
|
|
self._inVersion = True
|
2008-10-15 15:38:22 +00:00
|
|
|
|
|
|
|
|
elif name == "servicepack":
|
2012-02-16 13:46:01 +00:00
|
|
|
self._inServicePack = True
|
2008-10-15 15:38:22 +00:00
|
|
|
|
2019-05-30 22:40:51 +02:00
|
|
|
def characters(self, content):
|
2012-02-16 13:46:01 +00:00
|
|
|
if self._inVersion:
|
2019-05-30 22:40:51 +02:00
|
|
|
self._version += sanitizeStr(content)
|
2012-02-16 13:46:01 +00:00
|
|
|
elif self._inServicePack:
|
2019-05-30 22:40:51 +02:00
|
|
|
self._servicePack += sanitizeStr(content)
|
2008-10-15 15:38:22 +00:00
|
|
|
|
|
|
|
|
def endElement(self, name):
|
|
|
|
|
if name == "signature":
|
2012-02-16 13:46:01 +00:00
|
|
|
for version in (self._version, self._versionAlt):
|
2021-01-05 13:36:04 +01:00
|
|
|
if version and self._banner and re.search(r" %s[\.\ ]+" % re.escape(version), self._banner):
|
2012-02-16 13:46:01 +00:00
|
|
|
self._feedInfo("dbmsRelease", self._release)
|
|
|
|
|
self._feedInfo("dbmsVersion", self._version)
|
|
|
|
|
self._feedInfo("dbmsServicePack", self._servicePack)
|
2010-03-01 10:33:36 +00:00
|
|
|
break
|
2008-10-15 15:38:22 +00:00
|
|
|
|
2012-02-16 13:46:01 +00:00
|
|
|
self._version = ""
|
|
|
|
|
self._versionAlt = None
|
|
|
|
|
self._servicePack = ""
|
2008-10-15 15:38:22 +00:00
|
|
|
|
|
|
|
|
elif name == "version":
|
2012-02-16 13:46:01 +00:00
|
|
|
self._inVersion = False
|
|
|
|
|
self._version = self._version.replace(" ", "")
|
2010-05-21 14:42:59 +00:00
|
|
|
|
2012-04-03 14:34:15 +00:00
|
|
|
match = re.search(r"\A(?P<major>\d+)\.00\.(?P<build>\d+)\Z", self._version)
|
2012-02-16 13:46:01 +00:00
|
|
|
self._versionAlt = "%s.0.%s.0" % (match.group('major'), match.group('build')) if match else None
|
2008-10-15 15:38:22 +00:00
|
|
|
|
|
|
|
|
elif name == "servicepack":
|
2012-02-16 13:46:01 +00:00
|
|
|
self._inServicePack = False
|
|
|
|
|
self._servicePack = self._servicePack.replace(" ", "")
|
2008-10-15 15:38:22 +00:00
|
|
|
|
2008-11-15 23:41:31 +00:00
|
|
|
def bannerParser(banner):
|
2008-10-15 15:38:22 +00:00
|
|
|
"""
|
|
|
|
|
This function calls a class to extract information from the given
|
|
|
|
|
DBMS banner based upon the data in XML file
|
|
|
|
|
"""
|
|
|
|
|
|
2010-03-18 17:20:54 +00:00
|
|
|
xmlfile = None
|
2010-10-29 16:11:50 +00:00
|
|
|
|
2011-04-30 14:54:29 +00:00
|
|
|
if Backend.isDbms(DBMS.MSSQL):
|
2008-11-15 23:41:31 +00:00
|
|
|
xmlfile = paths.MSSQL_XML
|
2011-04-30 14:54:29 +00:00
|
|
|
elif Backend.isDbms(DBMS.MYSQL):
|
2008-11-15 23:41:31 +00:00
|
|
|
xmlfile = paths.MYSQL_XML
|
2011-04-30 14:54:29 +00:00
|
|
|
elif Backend.isDbms(DBMS.ORACLE):
|
2008-11-15 23:41:31 +00:00
|
|
|
xmlfile = paths.ORACLE_XML
|
2011-04-30 14:54:29 +00:00
|
|
|
elif Backend.isDbms(DBMS.PGSQL):
|
2008-11-15 23:41:31 +00:00
|
|
|
xmlfile = paths.PGSQL_XML
|
|
|
|
|
|
2010-03-18 17:20:54 +00:00
|
|
|
if not xmlfile:
|
|
|
|
|
return
|
2010-10-29 16:11:50 +00:00
|
|
|
|
2011-04-30 14:54:29 +00:00
|
|
|
if Backend.isDbms(DBMS.MSSQL):
|
2009-04-22 11:48:07 +00:00
|
|
|
handler = MSSQLBannerHandler(banner, kb.bannerFp)
|
2010-04-16 19:57:00 +00:00
|
|
|
parseXmlFile(xmlfile, handler)
|
2008-11-18 17:42:46 +00:00
|
|
|
|
|
|
|
|
handler = FingerprintHandler(banner, kb.bannerFp)
|
2010-04-16 19:57:00 +00:00
|
|
|
parseXmlFile(paths.GENERIC_XML, handler)
|
2008-11-15 23:41:31 +00:00
|
|
|
else:
|
2008-11-18 17:42:46 +00:00
|
|
|
handler = FingerprintHandler(banner, kb.bannerFp)
|
2010-04-16 19:57:00 +00:00
|
|
|
parseXmlFile(xmlfile, handler)
|
|
|
|
|
parseXmlFile(paths.GENERIC_XML, handler)
|