|
15 | 15 | from extra.beep.beep import beep |
16 | 16 | from lib.core.agent import agent |
17 | 17 | from lib.core.common import Backend |
| 18 | +from lib.core.common import arrayizeValue |
18 | 19 | from lib.core.common import extractRegexResult |
19 | 20 | from lib.core.common import extractStructuralTokens |
20 | 21 | from lib.core.common import extractTextTagContent |
@@ -183,7 +184,11 @@ def checkSqlInjection(place, parameter, value): |
183 | 184 | if kb.reduceTests is None and not conf.testFilter and (intersect(Backend.getErrorParsedDBMSes(), SUPPORTED_DBMS, True) or kb.heuristicDbms or injection.dbms): |
184 | 185 | msg = "it looks like the back-end DBMS is '%s'. " % (Format.getErrorParsedDBMSes() or kb.heuristicDbms or joinValue(injection.dbms, '/')) |
185 | 186 | msg += "Do you want to skip test payloads specific for other DBMSes? [Y/n]" |
186 | | - kb.reduceTests = (Backend.getErrorParsedDBMSes() or [kb.heuristicDbms]) if readInput(msg, default='Y', boolean=True) else [] |
| 187 | + # mirror msg's fallback chain (error-parsed -> heuristic -> injection.dbms) - falling |
| 188 | + # back only through the first two (as before) left kb.reduceTests as [None] whenever |
| 189 | + # injection.dbms alone satisfied the 'if' above, silently skipping every DBMS-specific |
| 190 | + # test payload for the rest of the scan |
| 191 | + kb.reduceTests = (Backend.getErrorParsedDBMSes() or ([kb.heuristicDbms] if kb.heuristicDbms else arrayizeValue(injection.dbms))) if readInput(msg, default='Y', boolean=True) else [] |
187 | 192 |
|
188 | 193 | # If the DBMS has been fingerprinted (via DBMS-specific error |
189 | 194 | # message, via simple heuristic check or via DBMS-specific |
@@ -925,7 +930,9 @@ def heuristicCheckDbms(injection): |
925 | 930 | may be |
926 | 931 | """ |
927 | 932 |
|
928 | | - retVal = False |
| 933 | + # None (not False) on failure - every caller gates re-running this on 'kb.heuristicDbms is |
| 934 | + # None', and a stale False from an earlier parameter's failed check would wrongly block that |
| 935 | + retVal = None |
929 | 936 |
|
930 | 937 | if conf.skipHeuristics: |
931 | 938 | return retVal |
|
0 commit comments