INNER CODE UNIT · Java

query

ron190/jsql-injection · model/src/main/java/com/jsql/model/InjectionModel.java:453

            query = paramLeadFixed;  // Just pass parameters without any transformation
        } else if (
            // If method is selected by user and URL does not contain injection point
            // but parameters contain an injection point
            // then replace injection point by SQL expression in this parameter
            paramLeadFixed.contains(InjectionModel.STAR)
        ) {
            query = this.initStarInjection(paramLeadFixed, isUsingIndex, sqlTrail);
        } else {
            query = this.initRawInjection(paramLeadFixed, isUsingIndex, sqlTrail);
        }
        query = this.cleanQuery(methodInjection, query);  // Remove comments except empty /**/
        // Add empty comments with space=>/**/
        if (this.mediatorUtils.connectionUtil().getMethodInjection() == methodInjection) {
            query = this.mediatorUtils.tamperingUtil().tamper(query);
        } else {  // remove tags added on non injection point like headers 'Accept: */*'
            String regexToRemoveTamperTags = String.format("(?i)%s|%s", TamperingUtil.TAG_OPENED, TamperingUtil.TAG_CLOSED);
            query = query.replaceAll(regexToRemoveTamperTags, StringUtils.EMPTY);

View source record →

📰 Research Paper
Loading…
⏳ Fetching content…