Skip to content

Commit 3ace495

Browse files
committed
Add tests for SqlAlchemy modeling library
After researching SqlAlchemy and it's various query methods, I discovered several types of SQL injection possibilities. The SQLExecution.py file contains these examples and can be broken up into two types of injections. Injections requiring the text() taint-step and injections NOT requiring the text() taint step.
1 parent c5fbbc0 commit 3ace495

File tree

2 files changed

+58
-0
lines changed

2 files changed

+58
-0
lines changed
Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,2 @@
1+
import python
2+
import experimental.meta.ConceptsTest
Lines changed: 56 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,56 @@
1+
import sqlalchemy
2+
from sqlalchemy import Column, Integer, String, ForeignKey, create_engine
3+
from sqlalchemy.ext.declarative import declarative_base
4+
from sqlalchemy.pool import StaticPool
5+
from sqlalchemy.orm import relationship, backref, sessionmaker, joinedload
6+
from sqlalchemy.sql import text
7+
8+
engine = create_engine(
9+
'sqlite:///:memory:',
10+
echo=True,
11+
connect_args={"check_same_thread": False},
12+
poolclass=StaticPool
13+
)
14+
15+
Base = declarative_base()
16+
17+
class User(Base):
18+
__tablename__ = 'users'
19+
20+
id = Column(Integer, primary_key=True)
21+
name = Column(String)
22+
23+
Base.metadata.create_all(engine)
24+
25+
Session = sessionmaker(bind=engine)
26+
session = Session()
27+
28+
ed_user = User(name='ed')
29+
ed_user2 = User(name='george')
30+
31+
session.add(ed_user)
32+
session.add(ed_user2)
33+
34+
session.commit()
35+
36+
# Injection without requiring the text() taint-step
37+
session.query(User).filter_by(name="some sql") # $getSql="some sql"
38+
session.scalar("some sql") # $getSql="some sql"
39+
engine.scalar("some sql") # $getSql="some sql"
40+
session.execute("some sql") # $getSql="some sql"
41+
42+
with engine.connect() as connection:
43+
connection.execute("some sql") # $getSql="some sql"
44+
45+
with engine.begin() as connection:
46+
connection.execute("some sql") # $getSql="some sql"
47+
48+
# Injection requiring the text() taint-step
49+
session.query(User).filter(text("some sql")) # $getSql="some sql"
50+
session.query(User).group_by( User.id ).having(text("some sql")) # $getSql="some sql"
51+
session.query(User).group_by(text("name='some sql'")).first() # $getSql="some sql"
52+
session.query(User).order_by(text("name='some sql'")).first() # $getSql="some sql"
53+
54+
query = select(User).where(User.name == text("some sql")) # $getSql="some sql"
55+
with engine.connect() as conn:
56+
conn.execute(query)

0 commit comments

Comments
 (0)