├── .gitattributes
├── .idea
├── misc.xml
├── modules.xml
├── sqldump.iml
└── workspace.xml
├── README.md
├── Service.py
├── Service.pyc
├── __pycache__
└── Service.cpython-36.pyc
└── main.py
/.gitattributes:
--------------------------------------------------------------------------------
1 | # Auto detect text files and perform LF normalization
2 | * text=auto
3 |
--------------------------------------------------------------------------------
/.idea/misc.xml:
--------------------------------------------------------------------------------
1 |
2 |
3 |
4 |
--------------------------------------------------------------------------------
/.idea/modules.xml:
--------------------------------------------------------------------------------
1 |
2 |
3 |
4 |
5 |
6 |
7 |
8 |
--------------------------------------------------------------------------------
/.idea/sqldump.iml:
--------------------------------------------------------------------------------
1 |
2 |
3 |
4 |
5 |
6 |
7 |
8 |
9 |
10 |
11 |
--------------------------------------------------------------------------------
/.idea/workspace.xml:
--------------------------------------------------------------------------------
1 |
2 |
3 |
4 |
5 |
6 |
7 |
8 |
9 |
10 |
11 |
12 |
13 |
14 |
15 |
16 |
17 |
18 |
19 |
20 |
21 |
22 |
23 |
24 |
25 |
26 |
27 |
28 |
29 |
30 |
31 |
32 |
33 |
34 |
35 |
36 |
37 |
38 |
39 |
40 |
41 |
42 |
43 |
44 |
45 |
46 |
47 |
48 |
49 |
50 |
51 |
52 |
53 |
54 |
55 |
56 |
57 |
58 |
59 |
60 |
61 |
62 |
67 |
68 |
69 |
70 |
71 |
72 |
73 |
74 |
75 |
76 |
77 |
78 |
79 |
80 |
81 |
82 |
83 |
84 |
85 |
86 |
87 |
88 |
89 |
90 |
91 |
92 |
93 |
94 |
95 |
96 |
97 |
98 |
99 |
100 |
101 |
102 |
103 |
104 |
105 |
106 |
107 |
108 |
109 |
110 |
111 |
112 |
113 |
114 |
115 |
116 |
117 |
118 |
119 |
120 |
121 |
122 |
123 |
124 |
125 |
126 |
127 |
128 |
129 |
130 |
131 |
132 |
133 |
134 |
135 |
136 |
137 |
138 |
139 |
140 |
141 |
142 |
143 |
144 |
145 |
146 |
147 |
148 |
149 |
150 |
151 |
152 |
153 |
154 |
155 |
156 |
157 |
158 |
159 |
160 |
161 |
162 |
163 |
164 |
165 |
166 |
167 |
168 |
169 |
170 |
171 |
172 |
173 |
174 |
175 |
176 |
177 |
178 |
179 |
180 |
181 |
182 |
183 |
184 |
185 |
186 |
187 |
188 |
189 |
190 |
191 |
192 |
193 |
194 |
195 |
196 |
197 |
198 |
199 |
200 |
201 |
202 |
203 |
204 |
205 |
206 |
207 |
208 |
209 |
210 |
211 |
212 |
213 |
214 |
215 |
216 |
217 |
218 |
219 |
220 |
221 |
222 |
223 |
224 |
225 |
226 |
227 |
228 |
229 |
230 |
231 |
232 |
233 |
234 |
235 |
236 |
237 |
238 |
239 |
240 |
241 |
242 |
243 |
244 |
245 |
246 |
247 |
248 |
249 |
250 |
251 |
252 |
253 |
254 |
255 |
256 |
257 |
258 |
259 |
260 |
261 |
262 |
263 |
264 |
265 |
266 |
267 |
268 |
269 |
270 |
271 |
272 |
273 | 1556687180004
274 |
275 |
276 | 1556687180004
277 |
278 |
279 |
280 |
281 |
282 |
283 |
284 |
285 |
286 |
287 |
288 |
289 |
290 |
291 |
292 |
293 |
294 |
295 |
296 |
297 |
298 |
299 |
300 |
301 |
302 |
303 |
304 |
305 |
306 |
307 |
308 |
309 |
310 |
311 |
312 |
313 |
314 |
315 |
316 |
317 |
318 |
319 |
320 |
321 |
322 |
323 |
324 |
325 |
326 |
327 |
328 |
329 |
330 |
331 |
332 |
333 |
334 |
335 |
336 |
337 |
338 |
339 |
340 |
341 |
342 |
343 |
344 |
345 |
346 |
347 |
348 |
349 |
350 |
351 |
352 |
353 |
354 |
355 |
356 |
357 |
358 |
359 |
360 |
361 |
362 |
363 |
364 |
365 |
366 |
367 |
368 |
369 |
370 |
371 |
372 |
373 |
374 |
375 |
376 |
377 |
378 |
379 |
380 |
381 |
382 |
383 |
384 |
385 |
386 |
387 |
388 |
389 |
390 |
391 |
392 |
393 |
394 |
395 |
396 |
397 |
398 |
399 |
400 |
401 |
402 |
403 |
404 |
405 |
406 |
407 |
408 |
409 |
410 |
411 |
412 |
413 |
414 |
415 |
416 |
417 |
418 |
419 |
420 |
421 |
422 |
423 |
424 |
425 |
426 |
427 |
428 |
429 |
430 |
431 |
432 |
433 |
434 |
435 |
436 |
437 |
438 |
439 |
440 |
441 |
442 |
443 |
444 |
445 |
446 |
447 |
448 |
449 |
450 |
451 |
452 |
453 |
454 |
455 |
456 |
457 |
458 |
459 |
460 |
461 |
462 |
463 |
464 |
465 |
466 |
467 |
468 |
469 |
470 |
471 |
472 |
473 |
474 |
475 |
476 |
477 |
478 |
479 |
480 |
481 |
482 |
483 |
484 |
485 |
486 |
487 |
488 |
489 |
490 |
491 |
492 |
493 |
494 |
495 |
496 |
497 |
498 |
499 |
500 |
501 |
502 |
503 |
504 |
505 |
506 |
507 |
508 |
509 |
510 |
511 |
512 |
513 |
514 |
515 |
516 |
517 |
518 |
519 |
520 |
521 |
522 |
523 |
524 |
525 |
526 |
527 |
528 |
529 |
530 |
531 |
532 |
533 |
534 |
535 |
536 |
537 |
538 |
539 |
540 |
541 |
542 |
543 |
544 |
545 |
546 |
547 |
548 |
549 |
550 |
551 |
552 |
553 |
554 |
555 |
556 |
557 |
558 |
559 |
560 |
561 |
562 |
563 |
564 |
565 |
566 |
567 |
568 |
569 |
570 |
571 |
572 |
573 |
574 |
575 |
576 |
577 |
578 |
579 |
580 |
581 |
582 |
583 |
584 |
585 |
586 |
587 |
588 |
589 |
590 |
591 |
592 |
593 |
594 |
595 |
596 |
597 |
598 |
599 |
600 |
601 |
602 |
603 |
604 |
605 |
606 |
607 |
608 |
609 |
610 |
611 |
612 |
613 |
614 |
615 |
616 |
617 |
618 |
619 |
620 |
621 |
622 |
623 |
624 |
625 |
626 |
627 |
628 |
629 |
630 |
631 |
632 |
633 |
634 |
635 |
636 |
637 |
638 |
639 |
640 |
641 |
642 |
643 |
644 |
645 |
646 |
647 |
648 |
649 |
650 |
651 |
652 |
653 |
654 |
655 |
656 |
657 |
658 |
659 |
660 |
661 |
662 |
663 |
664 |
665 |
666 |
667 |
668 |
669 |
670 |
671 |
672 |
673 |
674 |
675 |
676 |
677 |
678 |
679 |
680 |
681 |
682 |
683 |
684 |
685 |
686 |
687 |
688 |
689 |
690 |
691 |
692 |
693 |
694 |
695 |
696 |
697 |
698 |
699 |
700 |
701 |
702 |
703 |
704 |
705 |
706 |
707 |
708 |
709 |
710 |
711 |
712 |
713 |
714 |
715 |
716 |
717 |
718 |
719 |
720 |
721 |
722 |
723 |
724 |
725 |
726 |
727 |
728 |
729 |
--------------------------------------------------------------------------------
/README.md:
--------------------------------------------------------------------------------
1 | # sqlmap_api_demo
2 |
--------------------------------------------------------------------------------
/Service.py:
--------------------------------------------------------------------------------
1 | #!/usr/bin/python
2 | # -*- coding:utf-8 -*-
3 | # wirter:En_dust
4 | import requests
5 | import json
6 | import time
7 |
8 | class Client():
9 | def __init__(self,server_ip,server_port,admin_token="",taskid="",filepath=None):
10 | self.server = "http://" + server_ip + ":" + server_port
11 | self.admin_token = admin_token
12 | self.taskid = taskid
13 | self.filepath = ""
14 | self.status = ""
15 | self.scan_start_time = ""
16 | self.scan_end_time = ""
17 | self.engineid=""
18 | self.headers = {'Content-Type': 'application/json'}
19 |
20 |
21 |
22 | def create_new_task(self):
23 | '''创建一个新的任务,创建成功返回taskid'''
24 | r = requests.get("%s/task/new"%(self.server))
25 | self.taskid = r.json()['taskid']
26 | if self.taskid != "":
27 | return self.taskid
28 | else:
29 | print("创建任务失败!")
30 | return None
31 |
32 | def set_task_options(self,url):
33 | '''设置任务扫描的url等'''
34 | self.filepath = url
35 |
36 |
37 |
38 | def start_target_scan(self,url):
39 | '''开始扫描的方法,成功开启扫描返回True,开始扫描失败返回False'''
40 | r = requests.post(self.server + '/scan/' + self.taskid + '/start',
41 | data=json.dumps({'url':url,'getCurrentUser':True,'getBanner':True,'getCurrentDb':True}),
42 | headers=self.headers)
43 | if r.json()['success']:
44 | self.scan_start_time = time.time()
45 | #print(r.json())
46 | #print(r.json()['engineid'])
47 | return r.json()['engineid']
48 | else:
49 | #print(r.json())
50 | return None
51 |
52 | def get_scan_status(self):
53 | '''获取扫描状态的方法,扫描完成返回True,正在扫描返回False'''
54 | self.status = json.loads(requests.get(self.server + '/scan/' + self.taskid + '/status').text)['status']
55 | if self.status == 'terminated':
56 | self.scan_end_time = time.time()
57 | #print("扫描完成!")
58 | return True
59 | elif self.status == 'running':
60 | #print("Running")
61 | return False
62 | else:
63 | #print("未知错误!")
64 | self.status = False
65 |
66 |
67 |
68 | def get_result(self):
69 | '''获取扫描结果的方法,存在SQL注入返回payload和注入类型等,不存在SQL注入返回空'''
70 | if(self.status):
71 | r = requests.get(self.server + '/scan/' + self.taskid + '/data')
72 | if (r.json()['data']):
73 | return r.json()['data']
74 | else:
75 | return None
76 |
77 | def get_all_task_list(self):
78 | '''获取所有任务列表'''
79 | r = requests.get(self.server + '/admin/' + self.admin_token + "/list")
80 | if r.json()['success']:
81 | #print(r.json()['tasks'])
82 | return r.json()['tasks']
83 | else:
84 | return None
85 |
86 | def del_a_task(self,taskid):
87 | '''删除一个任务'''
88 | r = requests.get(self.server + '/task/' + taskid + '/delete')
89 | if r.json()['success']:
90 | return True
91 | else:
92 | return False
93 |
94 | def stop_a_scan(self,taskid):
95 | '''停止一个扫描任务'''
96 | r = requests.get(self.server + '/scan/' + taskid + '/stop')
97 | if r.json()['success']:
98 | return True
99 | else:
100 | return False
101 |
102 | def flush_all_tasks(self):
103 | '''清空所有任务'''
104 | r =requests.get(self.server + '/admin/' + self.admin_token + "/flush")
105 | if r.json()['success']:
106 | return True
107 | else:
108 | return False
109 |
110 | def get_scan_log(self):
111 | '''获取log'''
112 | r = requests.get(self.server + '/scan/' + self.taskid + '/log')
113 | return r.json()
114 |
115 |
116 | ######测试代码######
117 | # my_client = Client("127.0.0.1","5557","26902b3dcd85e2da1be7251a76c5ee74")
118 | # print("taskid:" + my_client.create_new_task())
119 | # my_client.set_task_options("http://192.168.0.221/sql/sql/post.php","keyword=1")
120 | # print("扫描id:" + str(my_client.start_target_scan()))
121 | # while(True):
122 | # if(my_client.get_scan_status()==True):
123 | # print(my_client.get_result())
124 | # print(my_client.scan_end_time)
125 | # break
126 | # print(my_client.get_all_task_list())
127 | # my_client.del_a_task("332ff999962ef9f4")
128 | # print(my_client.get_all_task_list())
129 | # my_client.flush_all_tasks()
130 | # print(my_client.get_all_task_list())
131 |
132 |
133 |
134 |
135 |
136 |
137 |
138 |
139 |
140 |
141 |
142 |
143 |
--------------------------------------------------------------------------------
/Service.pyc:
--------------------------------------------------------------------------------
https://raw.githubusercontent.com/FiveAourThe/sqlmap_api_demo/f62dda25365c26c36f9cd388c89b1c70e820287c/Service.pyc
--------------------------------------------------------------------------------
/__pycache__/Service.cpython-36.pyc:
--------------------------------------------------------------------------------
https://raw.githubusercontent.com/FiveAourThe/sqlmap_api_demo/f62dda25365c26c36f9cd388c89b1c70e820287c/__pycache__/Service.cpython-36.pyc
--------------------------------------------------------------------------------
/main.py:
--------------------------------------------------------------------------------
1 | #!/usr/bin/python
2 | # -*- coding:utf-8 -*-
3 | # wirter:En_dust
4 | from Service import Client
5 | import time
6 | from threading import Thread
7 |
8 | def main():
9 | '''实例化Client对象时需要传递sqlmap api 服务端的ip、port、admin_token和HTTP包的绝对路径'''
10 | print("————————————————Start Working!—————————————————")
11 | target = input("url:")
12 | task1 = Thread(target=set_start_get_result,args=(target,))
13 | task1.start()
14 |
15 |
16 |
17 | def time_deal(mytime):
18 | first_deal_time = time.localtime(mytime)
19 | second_deal_time = time.strftime("%Y-%m-%d %H:%M:%S", first_deal_time)
20 | return second_deal_time
21 |
22 |
23 | def set_start_get_result(url):
24 | #/home/cheng/Desktop/sqldump/1.txt
25 | current_taskid = my_scan.create_new_task()
26 | print("taskid: " + str(current_taskid))
27 | my_scan.set_task_options(url=url)
28 | print("扫描id:" + str(my_scan.start_target_scan(url=url)))
29 | print("扫描开始时间:" + str(time_deal(my_scan.scan_start_time)))
30 | while True:
31 | if my_scan.get_scan_status() == True:
32 | print(my_scan.get_result())
33 | print("当前数据库:" + str(my_scan.get_result()[-1]['value']))
34 | print("当前数据库用户名:" + str(my_scan.get_result()[-2]['value']))
35 | print("数据库版本:" + str(my_scan.get_result()[-3]['value']))
36 | print("扫描结束时间:" + str(time_deal(my_scan.scan_end_time)))
37 | print("扫描日志:\n" + str(my_scan.get_scan_log()))
38 | break
39 |
40 |
41 |
42 |
43 | if __name__ == '__main__':
44 | my_scan = Client("127.0.0.1", "8775", "c88927c30abb1ef6ea78cb81ac7ac6b0")
45 | main()
46 |
--------------------------------------------------------------------------------