INNER CODE UNIT · Java
query
ron190/jsql-injection · model/src/main/java/com/jsql/model/InjectionModel.java:464
query = this.cleanQuery(methodInjection, query); // Remove comments except empty /**/
// Add empty comments with space=>/**/
if (this.mediatorUtils.connectionUtil().getMethodInjection() == methodInjection) {
query = this.mediatorUtils.tamperingUtil().tamper(query);
} else { // remove tags added on non injection point like headers 'Accept: */*'
String regexToRemoveTamperTags = String.format("(?i)%s|%s", TamperingUtil.TAG_OPENED, TamperingUtil.TAG_CLOSED);
query = query.replaceAll(regexToRemoveTamperTags, StringUtils.EMPTY);
}
return this.applyEncoding(methodInjection, query);
}
private String initRawInjection(String paramLead, boolean isUsingIndex, String sqlTrail) {
String query;
// Method is selected by user and there's no injection point
if (!isUsingIndex) {
// Several SQL expressions does not use indexes in SELECT,
// like Boolean, Error, Shell and search for character insertion,
// in that case concat SQL expression to the end of param.