Linux tsuru-no-tsurugi 5.15.0-186-generic #196-Ubuntu SMP Sat Jun 20 16:09:34 UTC 2026 x86_64
Apache/2.4.52 (Ubuntu)
Server IP : 192.168.0.18 & Your IP : 216.73.217.105
Domains :
Cant Read [ /etc/named.conf ]
User : www-data
Terminal
Auto Root
Create File
Create Folder
Localroot Suggester
Backdoor Destroyer
Readme
/
usr /
share /
nmap /
nselib /
Delete
Unzip
Name
Size
Permission
Date
Action
data
[ DIR ]
drwxr-xr-x
2024-08-29 14:21
afp.lua
71.48
KB
-rw-r--r--
2023-01-13 02:40
ajp.lua
16.77
KB
-rw-r--r--
2023-01-13 02:40
amqp.lua
10.41
KB
-rw-r--r--
2023-01-13 02:40
anyconnect.lua
4.31
KB
-rw-r--r--
2023-01-13 02:40
asn1.lua
14.57
KB
-rw-r--r--
2023-01-13 02:40
base32.lua
7.36
KB
-rw-r--r--
2023-01-13 02:40
base64.lua
5.83
KB
-rw-r--r--
2023-01-13 02:40
bin.lua
12.99
KB
-rw-r--r--
2023-01-13 02:40
bitcoin.lua
18.25
KB
-rw-r--r--
2023-01-13 02:40
bits.lua
2.54
KB
-rw-r--r--
2023-01-13 02:40
bittorrent.lua
35.76
KB
-rw-r--r--
2023-01-13 02:40
bjnp.lua
9.55
KB
-rw-r--r--
2023-01-13 02:40
brute.lua
50.64
KB
-rw-r--r--
2023-01-13 02:40
cassandra.lua
5.48
KB
-rw-r--r--
2023-01-13 02:40
citrixxml.lua
16
KB
-rw-r--r--
2023-01-13 02:40
coap.lua
75.1
KB
-rw-r--r--
2023-01-13 02:40
comm.lua
11.03
KB
-rw-r--r--
2023-01-13 02:40
creds.lua
18.26
KB
-rw-r--r--
2023-01-13 02:40
cvs.lua
3.05
KB
-rw-r--r--
2023-01-13 02:40
datafiles.lua
11.05
KB
-rw-r--r--
2023-01-13 02:40
datetime.lua
7.5
KB
-rw-r--r--
2023-01-13 02:40
dhcp.lua
28.57
KB
-rw-r--r--
2023-01-13 02:40
dhcp6.lua
19.86
KB
-rw-r--r--
2023-01-13 02:40
dns.lua
51.07
KB
-rw-r--r--
2023-01-13 02:40
dnsbl.lua
19.01
KB
-rw-r--r--
2023-01-13 02:40
dnssd.lua
12.61
KB
-rw-r--r--
2023-01-13 02:40
drda.lua
24.08
KB
-rw-r--r--
2023-01-13 02:40
eap.lua
7.54
KB
-rw-r--r--
2023-01-13 02:40
eigrp.lua
12.98
KB
-rw-r--r--
2023-01-13 02:40
formulas.lua
5.68
KB
-rw-r--r--
2023-01-13 02:40
ftp.lua
9.03
KB
-rw-r--r--
2023-01-13 02:40
geoip.lua
1.71
KB
-rw-r--r--
2023-01-13 02:40
giop.lua
18.42
KB
-rw-r--r--
2023-01-13 02:40
gps.lua
3.38
KB
-rw-r--r--
2023-01-13 02:40
http.lua
117.07
KB
-rw-r--r--
2023-01-13 02:40
httpspider.lua
36.65
KB
-rw-r--r--
2023-01-13 02:40
iax2.lua
9.58
KB
-rw-r--r--
2023-01-13 02:40
idna.lua
17.14
KB
-rw-r--r--
2023-01-13 02:40
ike.lua
14.63
KB
-rw-r--r--
2023-01-13 02:40
imap.lua
9.59
KB
-rw-r--r--
2023-01-13 02:40
informix.lua
39.93
KB
-rw-r--r--
2023-01-13 02:40
ipOps.lua
29.06
KB
-rw-r--r--
2023-01-13 02:40
ipmi.lua
8.08
KB
-rw-r--r--
2023-01-13 02:40
ipp.lua
12.57
KB
-rw-r--r--
2023-01-13 02:40
irc.lua
757
B
-rw-r--r--
2023-01-13 02:40
iscsi.lua
21.38
KB
-rw-r--r--
2023-01-13 02:40
isns.lua
14.98
KB
-rw-r--r--
2023-01-13 02:40
jdwp.lua
43.52
KB
-rw-r--r--
2023-01-13 02:40
json.lua
11.62
KB
-rw-r--r--
2023-01-13 02:40
knx.lua
2.42
KB
-rw-r--r--
2023-01-13 02:40
ldap.lua
31.94
KB
-rw-r--r--
2023-01-13 02:40
lfs.luadoc
1.68
KB
-rw-r--r--
2023-01-13 02:40
libssh2-utility.lua
4.69
KB
-rw-r--r--
2023-01-13 02:40
libssh2.luadoc
4.75
KB
-rw-r--r--
2023-01-13 02:40
listop.lua
4.66
KB
-rw-r--r--
2023-01-13 02:40
lpeg-utility.lua
5.64
KB
-rw-r--r--
2023-01-13 02:40
lpeg.luadoc
351
B
-rw-r--r--
2023-01-13 02:40
ls.lua
10.96
KB
-rw-r--r--
2023-01-13 02:40
match.lua
2.05
KB
-rw-r--r--
2023-01-13 02:40
membase.lua
9.93
KB
-rw-r--r--
2023-01-13 02:40
mobileme.lua
8.46
KB
-rw-r--r--
2023-01-13 02:40
mongodb.lua
21.3
KB
-rw-r--r--
2023-01-13 02:40
mqtt.lua
28.86
KB
-rw-r--r--
2023-01-13 02:40
msrpc.lua
190.07
KB
-rw-r--r--
2023-01-13 02:40
msrpcperformance.lua
29.65
KB
-rw-r--r--
2023-01-13 02:40
msrpctypes.lua
168.52
KB
-rw-r--r--
2023-01-13 02:40
mssql.lua
109.43
KB
-rw-r--r--
2023-01-13 02:40
multicast.lua
5.97
KB
-rw-r--r--
2023-01-13 02:40
mysql.lua
16.03
KB
-rw-r--r--
2023-01-13 02:40
natpmp.lua
5.11
KB
-rw-r--r--
2023-01-13 02:40
nbd.lua
16.04
KB
-rw-r--r--
2023-01-13 02:40
ncp.lua
35.64
KB
-rw-r--r--
2023-01-13 02:40
ndmp.lua
11.43
KB
-rw-r--r--
2023-01-13 02:40
netbios.lua
14.44
KB
-rw-r--r--
2023-01-13 02:40
nmap.luadoc
40.34
KB
-rw-r--r--
2023-01-13 02:40
nrpc.lua
4.46
KB
-rw-r--r--
2023-01-13 02:40
nsedebug.lua
3.49
KB
-rw-r--r--
2023-01-13 02:40
omp2.lua
4.78
KB
-rw-r--r--
2023-01-13 02:40
oops.lua
3.61
KB
-rw-r--r--
2023-01-13 02:40
openssl.luadoc
7.5
KB
-rw-r--r--
2023-01-13 02:40
ospf.lua
15.29
KB
-rw-r--r--
2023-01-13 02:40
packet.lua
36.18
KB
-rw-r--r--
2023-01-13 02:40
pcre.luadoc
6.79
KB
-rw-r--r--
2023-01-13 02:40
pgsql.lua
20.6
KB
-rw-r--r--
2023-01-13 02:40
pop3.lua
5.74
KB
-rw-r--r--
2023-01-13 02:40
pppoe.lua
29.42
KB
-rw-r--r--
2023-01-13 02:40
proxy.lua
11.37
KB
-rw-r--r--
2023-01-13 02:40
punycode.lua
11.5
KB
-rw-r--r--
2023-01-13 02:40
rand.lua
2.7
KB
-rw-r--r--
2023-01-13 02:40
rdp.lua
14.73
KB
-rw-r--r--
2023-01-13 02:40
re.lua
8.22
KB
-rw-r--r--
2023-01-13 02:40
redis.lua
3.61
KB
-rw-r--r--
2023-01-13 02:40
rmi.lua
47.77
KB
-rw-r--r--
2023-01-13 02:40
rpc.lua
107.64
KB
-rw-r--r--
2023-01-13 02:40
rpcap.lua
11.08
KB
-rw-r--r--
2023-01-13 02:40
rsync.lua
5.22
KB
-rw-r--r--
2023-01-13 02:40
rtsp.lua
8.62
KB
-rw-r--r--
2023-01-13 02:40
sasl.lua
16.51
KB
-rw-r--r--
2023-01-13 02:40
shortport.lua
11.99
KB
-rw-r--r--
2023-01-13 02:40
sip.lua
30.07
KB
-rw-r--r--
2023-01-13 02:40
slaxml.lua
17.9
KB
-rw-r--r--
2023-01-13 02:40
smb.lua
173.22
KB
-rw-r--r--
2023-01-13 02:40
smb2.lua
15.34
KB
-rw-r--r--
2023-01-13 02:40
smbauth.lua
37.33
KB
-rw-r--r--
2023-01-13 02:40
smtp.lua
19.85
KB
-rw-r--r--
2023-01-13 02:40
snmp.lua
16
KB
-rw-r--r--
2023-01-13 02:40
socks.lua
8.25
KB
-rw-r--r--
2023-01-13 02:40
srvloc.lua
10.99
KB
-rw-r--r--
2023-01-13 02:40
ssh1.lua
9.15
KB
-rw-r--r--
2023-01-13 02:40
ssh2.lua
11.73
KB
-rw-r--r--
2023-01-13 02:40
sslcert.lua
33.35
KB
-rw-r--r--
2023-01-13 02:40
sslv2.lua
9.68
KB
-rw-r--r--
2023-01-13 02:40
stdnse.lua
32.64
KB
-rw-r--r--
2023-01-13 02:40
strbuf.lua
4.52
KB
-rw-r--r--
2023-01-13 02:40
strict.lua
2.53
KB
-rw-r--r--
2023-01-13 02:40
stringaux.lua
4.32
KB
-rw-r--r--
2023-01-13 02:40
stun.lua
11.08
KB
-rw-r--r--
2023-01-13 02:40
tab.lua
3.35
KB
-rw-r--r--
2023-01-13 02:40
tableaux.lua
2.06
KB
-rw-r--r--
2023-01-13 02:40
target.lua
3.93
KB
-rw-r--r--
2023-01-13 02:40
tftp.lua
9.41
KB
-rw-r--r--
2023-01-13 02:40
tls.lua
58.05
KB
-rw-r--r--
2023-01-13 02:40
tn3270.lua
46.99
KB
-rw-r--r--
2023-01-13 02:40
tns.lua
64.16
KB
-rw-r--r--
2023-01-13 02:40
unicode.lua
14.23
KB
-rw-r--r--
2023-01-13 02:40
unittest.lua
12.41
KB
-rw-r--r--
2023-01-13 02:40
unpwdb.lua
10.42
KB
-rw-r--r--
2023-01-13 02:40
upnp.lua
11.18
KB
-rw-r--r--
2023-01-13 02:40
url.lua
16.7
KB
-rw-r--r--
2023-01-13 02:40
versant.lua
8.58
KB
-rw-r--r--
2023-01-13 02:40
vnc.lua
25.54
KB
-rw-r--r--
2023-01-13 02:40
vulns.lua
76.45
KB
-rw-r--r--
2023-01-13 02:40
vuzedht.lua
16.21
KB
-rw-r--r--
2023-01-13 02:40
wsdd.lua
11.98
KB
-rw-r--r--
2023-01-13 02:40
xdmcp.lua
12.09
KB
-rw-r--r--
2023-01-13 02:40
xmpp.lua
15.91
KB
-rw-r--r--
2023-01-13 02:40
zlib.luadoc
4.88
KB
-rw-r--r--
2023-01-13 02:40
Save
Rename
--- -- Simple MySQL Library supporting a very limited subset of operations. -- -- https://dev.mysql.com/doc/internals/en/client-server-protocol.html -- -- @copyright Same as Nmap--See https://nmap.org/book/man-legal.html -- -- @author Patrik Karlsson <patrik@cqure.net> local nmap = require "nmap" local stdnse = require "stdnse" local string = require "string" local table = require "table" local math = require "math" _ENV = stdnse.module("mysql", stdnse.seeall) -- Version 0.3 -- -- Created 01/15/2010 - v0.1 - created by Patrik Karlsson <patrik@cqure.net> -- Revised 01/23/2010 - v0.2 - added query support, cleanup, documentation -- Revised 08/24/2010 - v0.3 - added error handling for receiveGreeting -- fixed a number of incorrect receives and changed -- them to receive_bytes instead. local tab = require('tab') local HAVE_SSL, openssl = pcall(require,'openssl') Capabilities = { LongPassword = 0x1, FoundRows = 0x2, LongColumnFlag = 0x4, ConnectWithDatabase = 0x8, DontAllowDatabaseTableColumn = 0x10, SupportsCompression = 0x20, ODBCClient = 0x40, SupportsLoadDataLocal = 0x80, IgnoreSpaceBeforeParenthesis = 0x100, Speaks41ProtocolNew = 0x200, InteractiveClient = 0x400, SwitchToSSLAfterHandshake = 0x800, IgnoreSigpipes = 0x1000, SupportsTransactions = 0x2000, Speaks41ProtocolOld = 0x4000, Support41Auth = 0x8000 } ExtCapabilities = { SupportsMultipleStatments = 0x1, SupportsMultipleResults = 0x2, SupportsAuthPlugins = 0x8, } Charset = { latin1_COLLATE_latin1_swedish_ci = 0x8 } ServerStatus = { InTransaction = 0x1, AutoCommit = 0x2, MoreResults = 0x4, MultiQuery = 0x8, BadIndexUsed = 0x10, NoIndexUsed = 0x20, CursorExists = 0x40, LastRowSebd = 0x80, DatabaseDropped = 0x100, NoBackslashEscapes = 0x200 } Command = { Query = 3 } local MAXPACKET = 16777216 local HEADER_SIZE = 4 --- Parses a MySQL header -- -- @param data string of raw data -- @return response table containing the fields <code>len</code> and <code>packetno</code> local function decodeHeader( data, pos ) local response = {} local pos, tmp = pos or 1, 0 tmp, pos = string.unpack( "<I4", data, pos ) response.len = ( tmp & 255 ) response.number = ( tmp >> 24 ) return pos, response end --- Receives the server greeting upon initial connection -- -- @param socket already connected to the remote server -- @return status true on success, false on failure -- @return response table with the following fields <code>proto</code>, <code>version</code>, -- <code>threadid</code>, <code>salt</code>, <code>capabilities</code>, <code>charset</code> and -- <code>status</code> or error message on failure (status == false) function receiveGreeting( socket ) local catch = function() socket:close() stdnse.debug1("receiveGreeting(): failed") end local try = nmap.new_try(catch) local data = try( socket:receive_bytes(HEADER_SIZE) ) local pos, response, tmp, _ pos, response = decodeHeader( data, 1 ) -- do we need to read the remainder if ( #data - HEADER_SIZE < response.len ) then local tmp = try( socket:receive_bytes( response.len - #data + HEADER_SIZE ) ) data = data .. tmp end local is_error is_error, pos = string.unpack("B", data, pos) if ( is_error == 0xff ) then response.errorcode, pos = string.unpack( "<I2", data, pos ) response.errormsg = data:sub(pos) return false, response.errormsg end response.proto = is_error response.version, response.threadid, pos = string.unpack( "<zI4", data, pos ) if response.proto == 10 then response.salt, response.capabilities, pos = string.unpack("<c8xI2", data, pos) local auth_plugin_len if pos < #data then response.charset, response.status, response.extcapabilities, -- capabilities, upper 2 bytes auth_plugin_len, tmp, pos = string.unpack( "<BI2 I2 Bc10", data, pos ) if tmp ~= "\0\0\0\0\0\0\0\0\0\0" then stdnse.debug2("reserved bytes are not nulls") end if response.capabilities & Capabilities.Support41Auth > 0 then tmp, pos = string.unpack("c" .. (math.max(13, auth_plugin_len - 8) - 1) .. "x", data, pos) response.salt = response.salt .. tmp end if response.extcapabilities & ExtCapabilities.SupportsAuthPlugins > 0 then response.auth_plugin_name = string.unpack("z", data, pos) end end elseif response.proto == 9 then response.auth_plugin_data, pos = string.unpack( "z", data, pos ) else stdnse.debug2("Unknown MySQL protocol version: %d", response.proto) end response.errorcode = 0 return true, response end --- Creates a hashed value of the password and salt according to MySQL authentication post version 4.1 -- -- @param pass string containing the users password -- @param salt string containing the servers salt as obtained from <code>receiveGreeting</code> -- @return reply string containing the raw hashed value local function createLoginHash(pass, salt) local hash_stage1 local hash_stage2 local hash_stage3 local reply = {} local pos, b1, b2, b3, _ = 1, 0, 0, 0 if ( not(HAVE_SSL) ) then return nil end hash_stage1 = openssl.sha1( pass ) hash_stage2 = openssl.sha1( hash_stage1 ) hash_stage3 = openssl.sha1( salt .. hash_stage2 ) for pos=1, hash_stage1:len() do b1 = string.unpack( "B", hash_stage1, pos ) b2 = string.unpack( "B", hash_stage3, pos ) reply[pos] = string.char( b2 ~ b1 ) end return table.concat(reply) end --- Attempts to Login to the remote mysql server -- -- @param socket already connected to the remote server -- @param params table with additional options to the loginrequest -- current supported fields are <code>charset</code> and <code>authversion</code> -- authversion is either "pre41" or "post41" (default is post41) -- currently only post41 authentication is supported -- @param username string containing the username of the user that is authenticating -- @param password string containing the users password or nil if empty -- @param salt string containing the servers salt as received from <code>receiveGreeting</code> -- @return status boolean -- @return response table or error message on failure function loginRequest( socket, params, username, password, salt ) local catch = function() socket:close() stdnse.debug1("loginRequest(): failed") end local try = nmap.new_try(catch) local packetno = 1 local authversion = params.authversion or "post41" local username = username or "" if not(HAVE_SSL) then return false, "No OpenSSL" end if authversion ~= "post41" then return false, "Unsupported authentication version: " .. authversion end local clicap = Capabilities.LongPassword clicap = clicap + Capabilities.LongColumnFlag clicap = clicap + Capabilities.SupportsLoadDataLocal clicap = clicap + Capabilities.Speaks41ProtocolNew clicap = clicap + Capabilities.InteractiveClient clicap = clicap + Capabilities.SupportsTransactions clicap = clicap + Capabilities.Support41Auth local extcapabilities = ExtCapabilities.SupportsMultipleStatments extcapabilities = extcapabilities + ExtCapabilities.SupportsMultipleResults local hash = "" if ( password ~= nil and password:len() > 0 ) then hash = createLoginHash( password, salt ) end local packet = string.pack( "<I2I2I4B c23 zs1", clicap, extcapabilities, MAXPACKET, Charset.latin1_COLLATE_latin1_swedish_ci, string.rep("\0", 23), username, hash ) local tmp = packet:len() + ( packetno << 24 ) packet = string.pack( "<I4", tmp ) .. packet try( socket:send(packet) ) packet = try( socket:receive_bytes(HEADER_SIZE) ) local pos, response = decodeHeader( packet ) -- do we need to read the remainder if ( #packet - HEADER_SIZE < response.len ) then local tmp = try( socket:receive_bytes( response.len - #packet + HEADER_SIZE ) ) packet = packet .. tmp end local is_error is_error, pos = string.unpack( "B", packet, pos ) if is_error > 0 then local has_sqlstate response.errorcode, has_sqlstate, pos = string.unpack( "<I2B", packet, pos ) if has_sqlstate == 35 then response.sqlstate, pos = string.unpack( "c5", packet, pos ) end response.errormessage, pos = string.unpack( "z", packet, pos ) return false, response.errormessage else response.errorcode = 0 response.affectedrows, response.serverstatus, response.warnings, pos = string.unpack( "<BI2I2", packet, pos ) end return true, response end --- Decodes a single column field -- -- http://forge.mysql.com/wiki/MySQL_Internals_ClientServer_Protocol#Field_Packet -- -- @param data string containing field packets -- @param pos number containing position from which to start decoding -- the position should point to the data in this buffer (ie. after the header) -- @return pos number containing the position after the field was decoded -- @return field table containing <code>catalog</code>, <code>database</code>, <code>table</code>, -- <code>origt_table</code>, <code>name</code>, <code>orig_name</code>, -- <code>length</code> and <code>type</code> function decodeField( data, pos ) local _ local field = {} field.catalog, field.database, field.table, field.orig_table, field.name, field.orig_name, _, -- should be 0x0C _, -- charset, in my case 0x0800 field.length, field.type, pos = string.unpack( "<s1s1s1s1s1s1BI2I4c6", data, pos ) return pos, field end --- Decodes the result set header packet into its sub components -- -- ref: http://forge.mysql.com/wiki/MySQL_Internals_ClientServer_Protocol#Result_Set_Header_Packet -- -- @param socket socket already connected to MySQL server -- @return table containing the following <code>header</code>, <code>fields</code> and <code>data</code> function decodeQueryResponse( socket ) local catch = function() socket:close() stdnse.debug1("decodeQueryResponse(): failed") end local try = nmap.new_try(catch) local data, header, pos local rs, blocks = {}, {} local block_start, block_end local EOF_MARKER = 254 data = try( socket:receive_bytes(HEADER_SIZE) ) pos, header = decodeHeader( data, pos ) -- -- First, Let's attempt to read the "Result Set Header Packet" -- if data:len() < header.len then data = data .. try( socket:receive_bytes( header.len - #data + HEADER_SIZE ) ) end rs.header = data:sub( 1, HEADER_SIZE + header.len ) -- abort on MySQL error if rs.header:sub(HEADER_SIZE + 1, HEADER_SIZE + 1) == "\xFF" then -- is this a 4.0 or 4.1 error message if rs.header:find("#") then return false, rs.header:sub(HEADER_SIZE+10) else return false, rs.header:sub(HEADER_SIZE+4) end end pos = HEADER_SIZE + header.len + 1 -- Second, Let's attempt to read the "Field Packets" and "Row Data Packets" -- They're separated by an "EOF Packet" for i=1,2 do -- marks the start of our block block_start = pos while true do if data:len() - pos < HEADER_SIZE then data = data .. try( socket:receive_bytes( HEADER_SIZE - ( data:len() - pos ) ) ) end pos, header = decodeHeader( data, pos ) if data:len() - pos < header.len - 1 then data = data .. try( socket:receive_bytes( header.len - ( data:len() - pos ) ) ) end if header.len > 0 then local b = string.unpack("B", data, pos ) -- Is this the EOF packet? if b == EOF_MARKER then -- we don't want the EOF Packet included block_end = pos - HEADER_SIZE pos = pos + header.len break end end pos = pos + header.len end blocks[i] = data:sub( block_start, block_end ) end rs.fields = blocks[1] rs.data = blocks[2] return true, rs end --- Decodes as field packet and returns a table of field tables -- -- ref: http://forge.mysql.com/wiki/MySQL_Internals_ClientServer_Protocol#Field_Packet -- -- @param data string containing field packets -- @param count number containing the amount of fields to decode -- @return status boolean (true on success, false on failure) -- @return fields table containing field tables as returned by <code>decodeField</code> -- or string containing error message if status is false function decodeFieldPackets( data, count ) local pos, header local field, fields = {}, {} if count < 1 then return false, "Field count was less than one, aborting" end for i=1, count do pos, header = decodeHeader( data, pos ) pos, field = decodeField( data, pos ) table.insert( fields, field ) end return true, fields end -- Decodes the result set header -- -- ref: http://forge.mysql.com/wiki/MySQL_Internals_ClientServer_Protocol#Result_Set_Header_Packet -- -- @param data string containing the result set header packet -- @return number containing the amount of fields function decodeResultSetHeader( data ) if data:len() ~= HEADER_SIZE + 1 then return false, "Result set header was incorrect" end local fields = string.unpack( "B", data, HEADER_SIZE + 1 ) return true, fields end --- Decodes the row data -- -- ref: http://forge.mysql.com/wiki/MySQL_Internals_ClientServer_Protocol#Row_Data_Packet -- -- @param data string containing the row data packet -- @param count number containing the number of fields to decode -- @return status true on success, false on failure -- @return rows table containing row tables function decodeDataPackets( data, count ) local pos = 1 local rows = {} while pos <= data:len() do local row = {} local header pos, header = decodeHeader( data, pos ) for i=1, count do row[i], pos = string.unpack("s1", data, pos) end table.insert( rows, row ) end return true, rows end --- Sends the query to the MySQL server and then attempts to decode the response -- -- @param socket socket already connected to mysql -- @param query string containing the sql query -- @return status true on success, false on failure -- @return rows table containing row tables as decoded by <code>decodeDataPackets</code> function sqlQuery( socket, query ) local catch = function() socket:close() stdnse.debug1("sqlQuery(): failed") end local try = nmap.new_try(catch) local packetno = 0 local querylen = query:len() + 1 local packet, packet_len, pos, header local status, fields, field_count, rows, rs packet = string.pack("<I4B", querylen, Command.Query) .. query -- -- http://forge.mysql.com/wiki/MySQL_Internals_ClientServer_Protocol#Result_Set_Header_Packet -- -- (Result Set Header Packet) the number of columns -- (Field Packets) column descriptors -- (EOF Packet) marker: end of Field Packets -- (Row Data Packets) row contents -- (EOF Packet) marker: end of Data Packets try( socket:send(packet) ) -- -- Let's read all the data into a table -- This way we avoid the hustle with reading from the socket status, rs = decodeQueryResponse( socket ) if not status then return false, rs end status, field_count = decodeResultSetHeader(rs.header) if not status then return false, field_count end status, fields = decodeFieldPackets(rs.fields, field_count) if not status then return false, fields end status, rows = decodeDataPackets(rs.data, field_count) if not status then return false, rows end return true, { cols = fields, rows = rows } end --- -- Formats the resultset returned from <code>sqlQuery</code> -- -- @param rs table as returned from <code>sqlQuery</code> -- @param options table containing additional options, currently: -- - <code>noheaders</code> - does not include column names in result -- @return string containing the formatted resultset table function formatResultset(rs, options) options = options or {} if ( not(rs) or not(rs.cols) or not(rs.rows) ) then return end local restab = tab.new(#rs.cols) local colnames = {} if ( not(options.noheaders) ) then for _, col in ipairs(rs.cols) do table.insert(colnames, col.name) end tab.addrow(restab, table.unpack(colnames)) end for _, row in ipairs(rs.rows) do tab.addrow(restab, table.unpack(row)) end return tab.dump(restab) end return _ENV;