INNER CODE UNIT · Java

query

ron190/jsql-injection · model/src/main/java/com/jsql/model/InjectionModel.java:464

        query = this.cleanQuery(methodInjection, query);  // Remove comments except empty /**/
        // Add empty comments with space=>/**/
        if (this.mediatorUtils.connectionUtil().getMethodInjection() == methodInjection) {
            query = this.mediatorUtils.tamperingUtil().tamper(query);
        } else {  // remove tags added on non injection point like headers 'Accept: */*'
            String regexToRemoveTamperTags = String.format("(?i)%s|%s", TamperingUtil.TAG_OPENED, TamperingUtil.TAG_CLOSED);
            query = query.replaceAll(regexToRemoveTamperTags, StringUtils.EMPTY);
        }
        return this.applyEncoding(methodInjection, query);
    }

    private String initRawInjection(String paramLead, boolean isUsingIndex, String sqlTrail) {
        String query;
        // Method is selected by user and there's no injection point
        if (!isUsingIndex) {
            // Several SQL expressions does not use indexes in SELECT,
            // like Boolean, Error, Shell and search for character insertion,
            // in that case concat SQL expression to the end of param.

View source record →

📰 Research Paper
Loading…
⏳ Fetching content…