Bug 2022657 - Review Request: sqlmap - detecting and exploiting SQL injection
Summary: Review Request: sqlmap - detecting and exploiting SQL injection
Keywords:
Status: CLOSED NOTABUG
Alias: None
Product: Fedora
Classification: Fedora
Component: Package Review
Version: rawhide
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Nobody's working on this, feel free to take it
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2021-11-12 10:10 UTC by Sandipan Roy
Modified: 2022-12-21 04:35 UTC (History)
2 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2022-12-21 04:35:22 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Sandipan Roy 2021-11-12 10:10:03 UTC
Spec URL: https://github.com/ByteHackr/sqlmap-fedora-rpm/blob/main/sqlmap.spec
SRPM URL: https://github.com/ByteHackr/sqlmap-fedora-rpm/blob/main/sqlmap-1.5.11-master.src.rpm
Description: sqlmap is an open source penetration testing tool that automates the process of detecting and exploiting SQL injection flaws and taking over of database servers. 
Fedora Account System Username: bytehackr

https://koji.fedoraproject.org/koji/taskinfo?taskID=78738525

Comment 1 Ben Beasley 2021-11-12 18:52:16 UTC
As far as I can tell, the packaging of pre-compiled (perhaps hand-crafted) exploit binaries does not fall under any established exception to the general ban on pre-compiled binaries or libraries (https://docs.fedoraproject.org/en-US/packaging-guidelines/what-can-be-packaged/#prebuilt-binaries-or-libraries).

If you think this case merits an exception, I think the next step would be for you to raise an issue with the Fedora Packaging Committee (https://pagure.io/packaging-committee/issues) explaining the situation and asking whether an exception can be granted.

Comment 2 Sandipan Roy 2021-12-03 11:29:46 UTC
Updated srpm and .spec according guidelines.

Spec URL: https://github.com/ByteHackr/sqlmap-fedora-rpm/blob/main/sqlmap.spec
SRPM URL: https://github.com/ByteHackr/sqlmap-fedora-rpm/blob/main/sqlmap-1.5.12-dev.src.rpm
Description: sqlmap is an open-source penetration testing tool that automates the process of detecting and exploiting SQL injection flaws and taking over of database servers. 
Fedora Account System Username: bytehackr

https://copr.fedorainfracloud.org/coprs/bytehackr/Security-Tools/package/sqlmap/

Comment 3 Package Review 2022-12-04 00:45:24 UTC
This is an automatic check from review-stats script.

This review request ticket hasn't been updated for some time. We're sorry
it is taking so long. If you're still interested in packaging this software
into Fedora repositories, please respond to this comment clearing the
NEEDINFO flag.

You may want to update the specfile and the src.rpm to the latest version
available and to propose a review swap on Fedora devel mailing list to increase
chances to have your package reviewed. If this is your first package and you
need a sponsor, you may want to post some informal reviews. Read more at
https://fedoraproject.org/wiki/How_to_get_sponsored_into_the_packager_group.

Without any reply, this request will shortly be considered abandoned
and will be closed.
Thank you for your patience.


Note You need to log in before you can comment on or make changes to this bug.