You can not select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
This file contains ambiguous Unicode characters that may be confused with others in your current locale. If your use case is intentional and legitimate, you can safely ignore this warning. Use the Escape button to highlight these characters.
#!/usr/bin/env python
"""
Copyright (c) 2006-2024 sqlmap developers (https://sqlmap.org/)
See the file ' LICENSE ' for copying permission
"""
import string
from lib . core . enums import PRIORITY
__priority__ = PRIORITY . LOWEST
def dependencies ( ) :
pass
def tamper ( payload , * * kwargs ) :
"""
Converts all (non-alphanum) characters in a given payload to overlong UTF8 (not processing already encoded) (e.g. ' -> % C0 % A7)
Reference:
* https://www.acunetix.com/vulnerabilities/unicode-transformation-issues/
* https://www.thecodingforums.com/threads/newbie-question-about-character-encoding-what-does-0xc0-0x8a-have-in-common-with-0xe0-0x80-0x8a.170201/
>>> tamper( ' SELECT FIELD FROM TABLE WHERE 2>1 ' )
' SELECT % C0 % A0FIELD % C0 % A0FROM % C0 % A0TABLE % C0 % A0WHERE % C0 % A02 % C0 % BE1 '
"""
retVal = payload
if payload :
retVal = " "
i = 0
# 遍历payload中的每个字符
while i < len ( payload ) :
# 如果当前字符是%,并且后面两个字符是十六进制数字,则认为这是一个已经编码的字符
if payload [ i ] == ' % ' and ( i < len ( payload ) - 2 ) and payload [ i + 1 : i + 2 ] in string . hexdigits and payload [ i + 2 : i + 3 ] in string . hexdigits :
retVal + = payload [ i : i + 3 ]
i + = 3
else :
# 如果当前字符不是字母或数字, 则将其转换为overlong UTF8编码
if payload [ i ] not in ( string . ascii_letters + string . digits ) :
# 计算并添加overlong UTF8编码
retVal + = " %% %.2X %% %.2X " % ( 0xc0 + ( ord ( payload [ i ] ) >> 6 ) , 0x80 + ( ord ( payload [ i ] ) & 0x3f ) )
else :
# 如果是字母或数字,则直接添加到结果中
retVal + = payload [ i ]
i + = 1
return retVal