diff --git a/README.md b/README.md index 05a3c9c0e56..f5edd06c53b 100644 --- a/README.md +++ b/README.md @@ -48,6 +48,7 @@ Links * X: [@sqlmap](https://x.com/sqlmap) * Demos: [https://www.youtube.com/user/inquisb/videos](https://www.youtube.com/user/inquisb/videos) * Playground: https://sekumart.sekuripy.hr +* Research: https://www.sekuripy.hr/labs/sqlmap/#research * Screenshots: https://github.com/sqlmapproject/sqlmap/wiki/Screenshots Translations diff --git a/doc/translations/README-ar-AR.md b/doc/translations/README-ar-AR.md index 8343e7dc86e..2b68044ba00 100644 --- a/doc/translations/README-ar-AR.md +++ b/doc/translations/README-ar-AR.md @@ -66,4 +66,5 @@ * تويتر: [@sqlmap](https://x.com/sqlmap) * العروض التوضيحية: [https://www.youtube.com/user/inquisb/videos](https://www.youtube.com/user/inquisb/videos) * ساحة التدريب: https://sekumart.sekuripy.hr +* الأبحاث: https://www.sekuripy.hr/labs/sqlmap/#research * لقطات الشاشة: https://github.com/sqlmapproject/sqlmap/wiki/Screenshots diff --git a/doc/translations/README-bg-BG.md b/doc/translations/README-bg-BG.md index fd07d52dbe3..38fcc2a526f 100644 --- a/doc/translations/README-bg-BG.md +++ b/doc/translations/README-bg-BG.md @@ -48,4 +48,5 @@ sqlmap работи самостоятелно с [Python](https://www.python.or * X: [@sqlmap](https://x.com/sqlmap) * Демо: [https://www.youtube.com/user/inquisb/videos](https://www.youtube.com/user/inquisb/videos) * Площадка за упражнения: https://sekumart.sekuripy.hr +* Изследвания: https://www.sekuripy.hr/labs/sqlmap/#research * Снимки на екрана: https://github.com/sqlmapproject/sqlmap/wiki/Screenshots diff --git a/doc/translations/README-bn-BD.md b/doc/translations/README-bn-BD.md index 23af4f763d2..309ae05952f 100644 --- a/doc/translations/README-bn-BD.md +++ b/doc/translations/README-bn-BD.md @@ -59,5 +59,6 @@ SQLMap-এর সম্পূর্ণ ফিচার, ক্ষমতা, এ * X: [@sqlmap](https://x.com/sqlmap) * ডেমো ভিডিও: [https://www.youtube.com/user/inquisb/videos](https://www.youtube.com/user/inquisb/videos) * অনুশীলন সাইট: https://sekumart.sekuripy.hr +* গবেষণা: https://www.sekuripy.hr/labs/sqlmap/#research * স্ক্রিনশট: https://github.com/sqlmapproject/sqlmap/wiki/Screenshots diff --git a/doc/translations/README-ckb-KU.md b/doc/translations/README-ckb-KU.md index 70a23c6ed9f..ed5cfb07d79 100644 --- a/doc/translations/README-ckb-KU.md +++ b/doc/translations/README-ckb-KU.md @@ -63,6 +63,7 @@ sqlmap لە دەرەوەی سندوق کاردەکات لەگەڵ [Python](https * X: [@sqlmap](https://x.com/sqlmap) * دیمۆ: [https://www.youtube.com/user/inquisb/videos](https://www.youtube.com/user/inquisb/videos) * گۆڕەپانی تاقیکردنەوە: https://sekumart.sekuripy.hr +* توێژینەوە: https://www.sekuripy.hr/labs/sqlmap/#research * وێنەی شاشە: https://github.com/sqlmapproject/sqlmap/wiki/وێنەی شاشە وەرگێڕانەکان diff --git a/doc/translations/README-de-DE.md b/doc/translations/README-de-DE.md index e55a43b53bf..56d09a9b0db 100644 --- a/doc/translations/README-de-DE.md +++ b/doc/translations/README-de-DE.md @@ -47,4 +47,5 @@ Links * X: [@sqlmap](https://x.com/sqlmap) * Demonstrationen: [https://www.youtube.com/user/inquisb/videos](https://www.youtube.com/user/inquisb/videos) * Spielwiese: https://sekumart.sekuripy.hr +* Forschung: https://www.sekuripy.hr/labs/sqlmap/#research * Screenshots: https://github.com/sqlmapproject/sqlmap/wiki/Screenshots diff --git a/doc/translations/README-es-MX.md b/doc/translations/README-es-MX.md index d3ca9c9acf5..3dd7c490065 100644 --- a/doc/translations/README-es-MX.md +++ b/doc/translations/README-es-MX.md @@ -47,4 +47,5 @@ Enlaces * X: [@sqlmap](https://x.com/sqlmap) * Demostraciones: [https://www.youtube.com/user/inquisb/videos](https://www.youtube.com/user/inquisb/videos) * Campo de pruebas: https://sekumart.sekuripy.hr +* Investigación: https://www.sekuripy.hr/labs/sqlmap/#research * Imágenes: https://github.com/sqlmapproject/sqlmap/wiki/Screenshots diff --git a/doc/translations/README-fa-IR.md b/doc/translations/README-fa-IR.md index c3647b0aacb..99d2b844bd9 100644 --- a/doc/translations/README-fa-IR.md +++ b/doc/translations/README-fa-IR.md @@ -82,4 +82,5 @@ * توییتر: [@sqlmap](https://x.com/sqlmap) * رسانه: [https://www.youtube.com/user/inquisb/videos](https://www.youtube.com/user/inquisb/videos) * زمین تمرین: https://sekumart.sekuripy.hr +* پژوهش: https://www.sekuripy.hr/labs/sqlmap/#research * تصاویر: https://github.com/sqlmapproject/sqlmap/wiki/Screenshots diff --git a/doc/translations/README-fr-FR.md b/doc/translations/README-fr-FR.md index d63177afa9d..1fa4879f793 100644 --- a/doc/translations/README-fr-FR.md +++ b/doc/translations/README-fr-FR.md @@ -47,4 +47,5 @@ Liens * X: [@sqlmap](https://x.com/sqlmap) * Démonstrations: [https://www.youtube.com/user/inquisb/videos](https://www.youtube.com/user/inquisb/videos) * Terrain de jeu: https://sekumart.sekuripy.hr +* Recherche: https://www.sekuripy.hr/labs/sqlmap/#research * Les captures d'écran: https://github.com/sqlmapproject/sqlmap/wiki/Screenshots diff --git a/doc/translations/README-gr-GR.md b/doc/translations/README-gr-GR.md index 53b4f774988..71b771a209c 100644 --- a/doc/translations/README-gr-GR.md +++ b/doc/translations/README-gr-GR.md @@ -48,4 +48,5 @@ * X: [@sqlmap](https://x.com/sqlmap) * Demos: [https://www.youtube.com/user/inquisb/videos](https://www.youtube.com/user/inquisb/videos) * Χώρος δοκιμών: https://sekumart.sekuripy.hr +* Έρευνα: https://www.sekuripy.hr/labs/sqlmap/#research * Εικόνες: https://github.com/sqlmapproject/sqlmap/wiki/Screenshots diff --git a/doc/translations/README-hr-HR.md b/doc/translations/README-hr-HR.md index a3807d50c5f..3b7772ce8b3 100644 --- a/doc/translations/README-hr-HR.md +++ b/doc/translations/README-hr-HR.md @@ -48,4 +48,5 @@ Poveznice * X: [@sqlmap](https://x.com/sqlmap) * Demo: [https://www.youtube.com/user/inquisb/videos](https://www.youtube.com/user/inquisb/videos) * Vježbalište: https://sekumart.sekuripy.hr +* Istraživanje: https://www.sekuripy.hr/labs/sqlmap/#research * Slike zaslona: https://github.com/sqlmapproject/sqlmap/wiki/Screenshots diff --git a/doc/translations/README-id-ID.md b/doc/translations/README-id-ID.md index fdcaaaadf4d..68e28de16c4 100644 --- a/doc/translations/README-id-ID.md +++ b/doc/translations/README-id-ID.md @@ -51,4 +51,5 @@ Tautan * X: [@sqlmap](https://x.com/sqlmap) * Video Demo [#1](https://www.youtube.com/user/inquisb/videos) dan [#2](https://www.youtube.com/user/stamparm/videos) * Arena latihan: https://sekumart.sekuripy.hr +* Riset: https://www.sekuripy.hr/labs/sqlmap/#research * Tangkapan Layar: https://github.com/sqlmapproject/sqlmap/wiki/Screenshots diff --git a/doc/translations/README-in-HI.md b/doc/translations/README-in-HI.md index a259e694352..7b147b75d4d 100644 --- a/doc/translations/README-in-HI.md +++ b/doc/translations/README-in-HI.md @@ -47,5 +47,6 @@ sqlmap [Python](https://www.python.org/download/) संस्करण **2.7** * ट्विटर: [@sqlmap](https://x.com/sqlmap) * डेमो: [https://www.youtube.com/user/inquisb/videos](https://www.youtube.com/user/inquisb/videos) * अभ्यास स्थल: https://sekumart.sekuripy.hr +* अनुसंधान: https://www.sekuripy.hr/labs/sqlmap/#research * स्क्रीनशॉट: https://github.com/sqlmapproject/sqlmap/wiki/Screenshots * diff --git a/doc/translations/README-it-IT.md b/doc/translations/README-it-IT.md index 32333ea4804..50cc806369b 100644 --- a/doc/translations/README-it-IT.md +++ b/doc/translations/README-it-IT.md @@ -48,4 +48,5 @@ Link * X: [@sqlmap](https://x.com/sqlmap) * Dimostrazioni: [https://www.youtube.com/user/inquisb/videos](https://www.youtube.com/user/inquisb/videos) * Campo di prova: https://sekumart.sekuripy.hr +* Ricerca: https://www.sekuripy.hr/labs/sqlmap/#research * Screenshot: https://github.com/sqlmapproject/sqlmap/wiki/Screenshots diff --git a/doc/translations/README-ja-JP.md b/doc/translations/README-ja-JP.md index 4f968607d65..e6a577d34d3 100644 --- a/doc/translations/README-ja-JP.md +++ b/doc/translations/README-ja-JP.md @@ -49,4 +49,5 @@ sqlmapの概要、機能の一覧、全てのオプションやスイッチの * X: [@sqlmap](https://x.com/sqlmap) * デモ: [https://www.youtube.com/user/inquisb/videos](https://www.youtube.com/user/inquisb/videos) * プレイグラウンド: https://sekumart.sekuripy.hr +* 研究: https://www.sekuripy.hr/labs/sqlmap/#research * スクリーンショット: https://github.com/sqlmapproject/sqlmap/wiki/Screenshots diff --git a/doc/translations/README-ka-GE.md b/doc/translations/README-ka-GE.md index 63d52b2d917..042ffeb5de5 100644 --- a/doc/translations/README-ka-GE.md +++ b/doc/translations/README-ka-GE.md @@ -47,4 +47,5 @@ sqlmap ნებისმიერ პლატფორმაზე მუშ * X: [@sqlmap](https://x.com/sqlmap) * დემონსტრაციები: [https://www.youtube.com/user/inquisb/videos](https://www.youtube.com/user/inquisb/videos) * სავარჯიშო სივრცე: https://sekumart.sekuripy.hr +* კვლევა: https://www.sekuripy.hr/labs/sqlmap/#research * ეკრანის ანაბეჭდები: https://github.com/sqlmapproject/sqlmap/wiki/Screenshots diff --git a/doc/translations/README-ko-KR.md b/doc/translations/README-ko-KR.md index f282f5dccec..e40265e686f 100644 --- a/doc/translations/README-ko-KR.md +++ b/doc/translations/README-ko-KR.md @@ -48,4 +48,5 @@ sqlmap의 능력, 지원되는 기능과 모든 옵션과 스위치들의 목록 * 트위터: [@sqlmap](https://x.com/sqlmap) * 시연 영상: [https://www.youtube.com/user/inquisb/videos](https://www.youtube.com/user/inquisb/videos) * 플레이그라운드: https://sekumart.sekuripy.hr +* 연구: https://www.sekuripy.hr/labs/sqlmap/#research * 스크린샷: https://github.com/sqlmapproject/sqlmap/wiki/Screenshots diff --git a/doc/translations/README-nl-NL.md b/doc/translations/README-nl-NL.md index 0d7be77106f..8e22c888cf9 100644 --- a/doc/translations/README-nl-NL.md +++ b/doc/translations/README-nl-NL.md @@ -48,4 +48,5 @@ Links * X: [@sqlmap](https://x.com/sqlmap) * Demos: [https://www.youtube.com/user/inquisb/videos](https://www.youtube.com/user/inquisb/videos) * Speeltuin: https://sekumart.sekuripy.hr +* Onderzoek: https://www.sekuripy.hr/labs/sqlmap/#research * Screenshots: https://github.com/sqlmapproject/sqlmap/wiki/Screenshots diff --git a/doc/translations/README-pl-PL.md b/doc/translations/README-pl-PL.md index 466165e6d8f..0808dd2179d 100644 --- a/doc/translations/README-pl-PL.md +++ b/doc/translations/README-pl-PL.md @@ -48,4 +48,5 @@ Odnośniki * X: [@sqlmap](https://x.com/sqlmap) * Dema: [https://www.youtube.com/user/inquisb/videos](https://www.youtube.com/user/inquisb/videos) * Piaskownica: https://sekumart.sekuripy.hr +* Badania: https://www.sekuripy.hr/labs/sqlmap/#research * Zrzuty ekranu: https://github.com/sqlmapproject/sqlmap/wiki/Screenshots diff --git a/doc/translations/README-pt-BR.md b/doc/translations/README-pt-BR.md index c3f65cfbb9b..06d5e361a4e 100644 --- a/doc/translations/README-pt-BR.md +++ b/doc/translations/README-pt-BR.md @@ -48,4 +48,5 @@ Links * X: [@sqlmap](https://x.com/sqlmap) * Demonstrações: [#1](https://www.youtube.com/user/inquisb/videos) e [#2](https://www.youtube.com/user/stamparm/videos) * Playground: https://sekumart.sekuripy.hr +* Pesquisa: https://www.sekuripy.hr/labs/sqlmap/#research * Imagens: https://github.com/sqlmapproject/sqlmap/wiki/Screenshots diff --git a/doc/translations/README-rs-RS.md b/doc/translations/README-rs-RS.md index 3494f6d8856..5f6e20dff3e 100644 --- a/doc/translations/README-rs-RS.md +++ b/doc/translations/README-rs-RS.md @@ -48,4 +48,5 @@ Linkovi * X: [@sqlmap](https://x.com/sqlmap) * Demo: [https://www.youtube.com/user/inquisb/videos](https://www.youtube.com/user/inquisb/videos) * Poligon: https://sekumart.sekuripy.hr +* Istraživanje: https://www.sekuripy.hr/labs/sqlmap/#research * Slike: https://github.com/sqlmapproject/sqlmap/wiki/Screenshots diff --git a/doc/translations/README-ru-RU.md b/doc/translations/README-ru-RU.md index d9b9307a7c6..c3a77c10c00 100644 --- a/doc/translations/README-ru-RU.md +++ b/doc/translations/README-ru-RU.md @@ -48,4 +48,5 @@ sqlmap работает из коробки с [Python](https://www.python.org/d * X: [@sqlmap](https://x.com/sqlmap) * Демки: [https://www.youtube.com/user/inquisb/videos](https://www.youtube.com/user/inquisb/videos) * Песочница: https://sekumart.sekuripy.hr +* Исследования: https://www.sekuripy.hr/labs/sqlmap/#research * Скриншоты: https://github.com/sqlmapproject/sqlmap/wiki/Screenshots diff --git a/doc/translations/README-sk-SK.md b/doc/translations/README-sk-SK.md index a67d2882617..6f813c15772 100644 --- a/doc/translations/README-sk-SK.md +++ b/doc/translations/README-sk-SK.md @@ -48,4 +48,5 @@ Linky * X: [@sqlmap](https://x.com/sqlmap) * Demá: [https://www.youtube.com/user/inquisb/videos](https://www.youtube.com/user/inquisb/videos) * Cvičisko: https://sekumart.sekuripy.hr +* Výskum: https://www.sekuripy.hr/labs/sqlmap/#research * Snímky obrazovky: https://github.com/sqlmapproject/sqlmap/wiki/Screenshots diff --git a/doc/translations/README-tr-TR.md b/doc/translations/README-tr-TR.md index bfc433fb7e2..f19ac8d2e3d 100644 --- a/doc/translations/README-tr-TR.md +++ b/doc/translations/README-tr-TR.md @@ -51,4 +51,5 @@ Bağlantılar * X: [@sqlmap](https://x.com/sqlmap) * Demolar: [https://www.youtube.com/user/inquisb/videos](https://www.youtube.com/user/inquisb/videos) * Deneme alanı: https://sekumart.sekuripy.hr +* Araştırma: https://www.sekuripy.hr/labs/sqlmap/#research * Ekran görüntüleri: https://github.com/sqlmapproject/sqlmap/wiki/Screenshots diff --git a/doc/translations/README-uk-UA.md b/doc/translations/README-uk-UA.md index 9470a527302..8849d95f6dd 100644 --- a/doc/translations/README-uk-UA.md +++ b/doc/translations/README-uk-UA.md @@ -48,4 +48,5 @@ sqlmap «працює з коробки» з [Python](https://www.python.org/dow * X: [@sqlmap](https://x.com/sqlmap) * Демо: [https://www.youtube.com/user/inquisb/videos](https://www.youtube.com/user/inquisb/videos) * Пісочниця: https://sekumart.sekuripy.hr +* Дослідження: https://www.sekuripy.hr/labs/sqlmap/#research * Скриншоти: https://github.com/sqlmapproject/sqlmap/wiki/Screenshots diff --git a/doc/translations/README-vi-VN.md b/doc/translations/README-vi-VN.md index b8ec43379a1..f9d68901313 100644 --- a/doc/translations/README-vi-VN.md +++ b/doc/translations/README-vi-VN.md @@ -50,4 +50,5 @@ Liên kết * X: [@sqlmap](https://x.com/sqlmap) * Demo: [https://www.youtube.com/user/inquisb/videos](https://www.youtube.com/user/inquisb/videos) * Sân tập: https://sekumart.sekuripy.hr +* Nghiên cứu: https://www.sekuripy.hr/labs/sqlmap/#research * Ảnh chụp màn hình: https://github.com/sqlmapproject/sqlmap/wiki/Screenshots diff --git a/doc/translations/README-zh-CN.md b/doc/translations/README-zh-CN.md index 511409fa44d..59843e97264 100644 --- a/doc/translations/README-zh-CN.md +++ b/doc/translations/README-zh-CN.md @@ -47,4 +47,5 @@ sqlmap 可以运行在 [Python](https://www.python.org/download/) **2.7** 和 * X: [@sqlmap](https://x.com/sqlmap) * 教程: [https://www.youtube.com/user/inquisb/videos](https://www.youtube.com/user/inquisb/videos) * 靶场: https://sekumart.sekuripy.hr +* 研究: https://www.sekuripy.hr/labs/sqlmap/#research * 截图: https://github.com/sqlmapproject/sqlmap/wiki/Screenshots diff --git a/lib/core/settings.py b/lib/core/settings.py index d86cc6dd44c..aeb1ac42aa0 100644 --- a/lib/core/settings.py +++ b/lib/core/settings.py @@ -20,7 +20,7 @@ from thirdparty import six # sqlmap version (...) -VERSION = "1.10.8.35" +VERSION = "1.10.8.36" TYPE = "dev" if VERSION.count('.') > 2 and VERSION.split('.')[-1] != '0' else "stable" TYPE_COLORS = {"dev": 33, "stable": 90, "pip": 34} VERSION_STRING = "sqlmap/%s#%s" % ('.'.join(VERSION.split('.')[:-1]) if VERSION.count('.') > 2 and VERSION.split('.')[-1] == '0' else VERSION, TYPE) @@ -1707,6 +1707,24 @@ # Length used while checking for existence of Suhosin-patch (like) protection mechanism SUHOSIN_MAX_VALUE_LENGTH = 512 +# Multi-bit blind inference ("row multiplexing"): one rendered row carries one bit, so a single +# response yields whole characters instead of a single boolean. Needs '--risk=3' (it widens the +# result set with OR) and proves every value back against the target before returning it. +MAX_MULTIBIT_LENGTH = 8192 # hard ceiling when the value length is unknown (anti-runaway) +MAX_MULTIBIT_PAGE = 1048576 # response bytes parsed for repeated row markup (larger pages are truncated) +MULTIBIT_BITS_PER_CHAR = 8 # one whole byte per character, one row per bit +MULTIBIT_PLANES = 7 # bit planes used to map rows in bulk (i.e. a window of 2**7 identifiers) +MULTIBIT_CANDIDATE_COLUMNS = 3 # row identifier candidates tried before giving up on a parameter +MULTIBIT_SAMPLES = 3 # repeats used to separate stable row markers from per-response junk +MULTIBIT_CALIBRATION_ROUNDS = 5 # random subsets checked before superposition is trusted +MULTIBIT_CONFIRM_CHUNK = 64 # characters proven back per confirmation request +MULTIBIT_MAX_FAILURES = 3 # unconfirmed values in a row before the channel is abandoned +MULTIBIT_MAX_PLANES = 12 # planes used to place the page's own (not necessarily consecutive) rows +MULTIBIT_MIN_BITS = 2 # bits per request below which there is nothing to gain +MULTIBIT_NARROW = "narrow" # AND-ed onto the live value: the page's own rows, any risk level +MULTIBIT_WIDEN = "widen" # OR-ed against a negated one: the whole table, asked for below its risk +MULTIBIT_WIDEN_RISK = 3 # risk the widen channel amounts to (OR payloads, boolean_blind.xml) + # Minimum size of an (binary) entry before it can be considered for dumping to disk MIN_BINARY_DISK_DUMP_SIZE = 100