Skip to content

Commit aad3940

Browse files
tanaydinclaude
andcommitted
Fix heuristicCheckDbms() False/None inconsistency corrupting kb.reduceTests
heuristicCheckDbms() returned False instead of None on failure, breaking the is None convention used elsewhere and producing nonsensical "could be 'False'" log messages. Separately, the kb.reduceTests fallback assignment ignored injection.dbms even though the guarding condition and prompt message both accounted for it, causing kb.reduceTests to become [None] and wrongly skip all DBMS-specific tests when no DBMS was actually identified. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
1 parent 3cfba46 commit aad3940

2 files changed

Lines changed: 15 additions & 5 deletions

File tree

‎lib/controller/action.py‎

Lines changed: 13 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -103,9 +103,19 @@ def action():
103103
errMsg += ". You can try to rerun without using optimization "
104104
errMsg += "switch '%s'" % ("-o" if conf.optimize else "--null-connection")
105105

106-
raise SqlmapUnsupportedDBMSException(errMsg)
107-
108-
conf.dumper.singleString(conf.dbmsHandler.getFingerprint())
106+
if kb.injection and kb.injection.place is not None:
107+
# An injection point WAS already found during detection (kb.injection.place is set,
108+
# e.g. via a generic, DBMS-agnostic boolean-based/UNION test), but the LATER, separate
109+
# fingerprint-confirmation phase (conf.dbmsHandler / checkDbms()) failed to pin down
110+
# which DBMS it actually is - e.g. a flaky target where a DBMS-specific
111+
# self-comparison probe intermittently comes back false. Warn instead of aborting, so
112+
# the scan continues; Backend.getDbms() stays None, so any later "back-end DBMS: %s"
113+
# report legitimately prints 'None' despite an injection having been detected earlier.
114+
logger.warning(errMsg)
115+
else:
116+
raise SqlmapUnsupportedDBMSException(errMsg)
117+
118+
conf.dumper.singleString(conf.dbmsHandler.getFingerprint() if conf.dbmsHandler else "back-end DBMS: %s" % Backend.getDbms())
109119

110120
kb.fingerprinted = True
111121

‎lib/controller/checks.py‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -183,7 +183,7 @@ def checkSqlInjection(place, parameter, value):
183183
if kb.reduceTests is None and not conf.testFilter and (intersect(Backend.getErrorParsedDBMSes(), SUPPORTED_DBMS, True) or kb.heuristicDbms or injection.dbms):
184184
msg = "it looks like the back-end DBMS is '%s'. " % (Format.getErrorParsedDBMSes() or kb.heuristicDbms or joinValue(injection.dbms, '/'))
185185
msg += "Do you want to skip test payloads specific for other DBMSes? [Y/n]"
186-
kb.reduceTests = (Backend.getErrorParsedDBMSes() or [kb.heuristicDbms]) if readInput(msg, default='Y', boolean=True) else []
186+
kb.reduceTests = (Backend.getErrorParsedDBMSes() or [kb.heuristicDbms] if kb.heuristicDbms else injection.dbms if isinstance(injection.dbms, list) else [injection.dbms]) if readInput(msg, default='Y', boolean=True) else []
187187

188188
# If the DBMS has been fingerprinted (via DBMS-specific error
189189
# message, via simple heuristic check or via DBMS-specific
@@ -925,7 +925,7 @@ def heuristicCheckDbms(injection):
925925
may be
926926
"""
927927

928-
retVal = False
928+
retVal = None
929929

930930
if conf.skipHeuristics:
931931
return retVal

0 commit comments

Comments
 (0)