网站sql注入自动检测工具测试版(仅限get请求)

1.开启sqlmapapi

  root@kali:/usr/share/golismero/tools/sqlmap# python sqlmapapi.py -s

2.运行程序

 记得改url
#!/usr/bin/python

# -*- coding: utf-8 -*-

#author:Erie



import re

import sys

import requests

import Queue

import threading

from bs4 import BeautifulSoup

from urlparse import urljoin

from urlparse import urlparse

from urlparse import urlunparse

from posixpath import normpath

import json

import time



reload(sys)

sys.setdefaultencoding('utf-8')

sys.setdefaultencoding('gbk')



VisitedUrl = Queue.Queue()

VisitedLinks = []



#linkder Function()

class Spider(threading.Thread):

def __init__ (self,queue,links):

threading.Thread.__init__(self)

tmp = urlparse(links)

self.queue = queue

self.host = tmp.netloc

self.pro = tmp.scheme

self.path = tmp.path

def  TaskNew(self,urllink):

r = requests.get('http://127.0.0.1:8775/task/new')

r = r.json

taskid = r['taskid'] 

print taskid

r = requests.post("http://127.0.0.1:8775/scan/"+taskid+"/start",data=json.dumps({'url':urllink}),headers = {'Content-Type':'application/json'})

r = r.json

if r['success'] :

while  True:

time.sleep(20)

r = requests.get("http://127.0.0.1:8775/scan/"+taskid+"/status")

r = r.json

if r['returncode'] == 0  :

r = requests.get("http://127.0.0.1:8775/scan/"+taskid+"/data")

r = r.json

print r['data']

print len(r['data'])

if len(r['data']) == 0:

print urllink+'-------------------------->'+'NO'

else:

print urllink+'-------------------------->'+'Yes'

#chongzu Url

def myjoin (self,base, url):

url1 = urljoin(base, url)

arr = urlparse(url1)

path = normpath(arr[2])

return urlunparse((arr.scheme, arr.netloc, path, arr.params, arr.query, arr.fragment))

def getpage (self,url):

Response = requests.get(url)

try:

Htmlpage = Response.content

soup = BeautifulSoup(Htmlpage)

all_href = soup.findAll("a")

for href in all_href:

tmp = str(href)

if tmp.find('href') != -1:

if href['href'].find("http://") != -1:

if urlparse(href['href']).hostname==self.host:

UnvisitedHref = href['href']

if UnvisitedHref not in VisitedLinks:

self.queue.put(UnvisitedHref)

else:

UnvisitedHref = self.myjoin(url,href['href'])

if UnvisitedHref not in VisitedLinks and urlparse(UnvisitedHref).hostname==self.host  and (urlparse(UnvisitedHref).path.count('/')-self.path.count('/'))<=3 and UnvisitedHref.find('#') == -1 and UnvisitedHref.find('.js' )== -1 and UnvisitedHref.find('.jpg') == -1 and UnvisitedHref.find('bmp') == -1 and UnvisitedHref.find('.png') == -1 and UnvisitedHref.find('.gif') == -1:

self.queue.put(UnvisitedHref)

except :

pass



def run (self):

while True:

Urling =self.queue.get()

tempurl = urlparse(Urling)

if tempurl.query != '':



self.TaskNew(Urling)

else:

print Urling



VisitedLinks.append(Urling)

self.getpage(Urling)

self.queue.task_done()

#main Function()

def main(Url):

#Url = sys.argv[1]

for i in range(5):

spider = Spider(VisitedUrl,Url)

spider.start()

VisitedUrl.put(Url)

VisitedUrl.join()

if __name__ == "__main__":

main('http://)

最后编辑于
©著作权归作者所有,转载或内容合作请联系作者
平台声明:文章内容(如有图片或视频亦包括在内)由作者上传并发布,文章内容仅代表作者本人观点,简书系信息发布平台,仅提供信息存储服务。

推荐阅读更多精彩内容