Fix heuristicCheckDbms() False/None inconsistency corrupting kb.reduceTests, wrongly skipping DBMS-specific tests - #6132
Closed
tanaydin wants to merge 1 commit into
Conversation
…eTests heuristicCheckDbms() returned False instead of None on failure, breaking the is None convention used elsewhere and producing nonsensical "could be 'False'" log messages. Separately, the kb.reduceTests fallback assignment ignored injection.dbms even though the guarding condition and prompt message both accounted for it, causing kb.reduceTests to become [None] and wrongly skip all DBMS-specific tests when no DBMS was actually identified. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Member
|
this whole process doesn't work this way. there is not original issue, there is no "grace period" for ME to actually fix something, and i am here presented with something that i just have to merge because of "fixes". nope |
Contributor
Author
|
Well actually it is happening in real life, servers can crash and sqlmap thinks databases name is "None" or "False". |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Two related bugs in
lib/controller/checks.pycombine to make sqlmap skip legitimateDBMS-specific test payloads (logged as
"...the heuristic tests showed that the back-end DBMS could be 'False'"or'...None'), even though no DBMS was actually determined.Bug 1 —
heuristicCheckDbms()returnsFalseinstead ofNoneon failureheuristicCheckDbms()(lib/controller/checks.py:920) initializes:and returns this unchanged when no candidate DBMS matches. Every other consumer of
kb.heuristicDbmsin the file checks it withis None(e.g. lines 166, 175, 183), notfalsiness. Since
False is Noneevaluates toFalse, a prior failed heuristic call leaveskb.heuristicDbms = False, which then:kb.heuristicDbms or ...) as "no value", whilesimultaneously failing the
is Noneguards that gate re-running the heuristic for adifferent parameter later in the same scan,
"could be '%s'" % kb.heuristicDbms,producing the nonsensical
could be 'False'log line.Fix
Change the initial/failure value to
None:This matches the
is Noneconvention used by every caller.Bug 2 —
kb.reduceTestsfallback ignores which value actually triggered the branchAt
lib/controller/checks.py:183-186:The guarding
ifcan be satisfied by any of three truthy signals:Backend.getErrorParsedDBMSes(),kb.heuristicDbms, orinjection.dbms. The prompt message(
msg = ...) correctly falls back through all three. But the actual assignment on the next lineonly falls back through the first two —
Backend.getErrorParsedDBMSes() or [kb.heuristicDbms]—ignoring
injection.dbmsentirely.Concretely: when the branch is entered because
injection.dbmsis truthy whileBackend.getErrorParsedDBMSes()is empty andkb.heuristicDbmsisNone(a real scenario: ageneric/DBMS-agnostic test confirmed the injection, and the heuristic separately failed), the
assignment becomes:
kb.reduceTestsis then a truthy list ([None]), so later at line 323:every DBMS-specific test gets skipped ("could be 'None'"), even though no DBMS was actually
determined — the opposite of the intended behavior (only skip once a DBMS is known).
Fix
Make the assignment mirror the message's fallback order, deriving from whichever signal actually
satisfied the guard:
After lines 873. it's starting to printing 'False' which is causing detected database name lost and not executing injections on the server. If verbosity level is 1 or 2 it's not visible to user.
Here is my scan output on vulnserver
out.txt
To reproduce I need to make some changes on vulnserver, which is returning "Network Error" random, that make sqlmap to fail. Which happened me before... here is changed file, I didn't want to put in the changes...
vulnserver.py