| 
							
							
								 Miroslav Stampar | 0f7bce5c66 | fixing a huge mess going on because of counting on error and union techniques | 2011-03-23 11:36:40 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 5a1aaecf16 | minor fix so concatenated queries could be run in Oracle --sql-shell (e.g. select NAME||chr(58)||OWNER FROM ALL_SOURCE WHERE TYPE='FUNCTION') | 2011-03-22 13:07:37 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 7613134515 | it was a real pain in the ass to have SELECT COUNT(*) for all rows (it was processed by a limit logic) | 2011-03-22 12:37:05 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 9479a68eb5 | minor fix regarding last commit | 2011-03-22 12:21:56 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | c24ed6e622 | minor fix related to a bug reported by warninggp@gmail.com | 2011-03-22 09:22:48 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | cbfb10cbd1 | fix of a minor bug reported by syssecurity7@googlemail.com (missing iso-8858...) | 2011-03-21 16:43:46 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | b5c9ccb755 | Oracle XML based error payload has problems with char $ as with space | 2011-03-21 13:13:12 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 1abcd507b8 | hidding --group-concat switch | 2011-03-21 12:13:21 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 19e2ed9803 | Layout fix | 2011-03-21 00:40:25 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 3ca5cddca7 | massive BUG FIX (if NULL is one of dumping values it will screw everything in corner cases because "SELECT 1 WHERE NULL IN (NULL)" and "SELECT 1 WHERE NULL NOT IN (NULL)" will always return nothing/nadda/zero/not even NULL) | 2011-03-20 23:54:56 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 9b1f2d82d0 | minor update (that .strip() was a leftover) | 2011-03-20 23:20:47 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | db992a0a86 | mssql likes to htmlescape error reports | 2011-03-20 23:16:34 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 088c815567 | minor update (exposing --tor switch) | 2011-03-19 18:28:51 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 2cc91b8470 | minor fix | 2011-03-19 17:44:34 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 7c2b3afafb | minor fix (-r required Content-Length which is a part of Burp log and as we share the parsing logic this was a headache for -r) | 2011-03-19 17:37:26 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 139448eeb9 | little stabilization regarding POST url(de/en)coding | 2011-03-19 16:53:14 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 0fcd999e51 | fix for a bug reported by malice | 2011-03-18 16:52:46 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 58e9a074d3 | masking some more command line arguments | 2011-03-18 16:47:18 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 36233fac42 | update regarding a feature request from andyroyalbattle@yahoo.it | 2011-03-18 16:35:30 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 00b9d85ffc | fix regarding bug report from andyroyalbattle@yahoo.it | 2011-03-18 16:26:39 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 4e300baaf2 | minor cosmetics | 2011-03-18 14:09:18 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 3628887110 | los cosmeticados | 2011-03-18 14:08:36 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 75c0e09f43 | little refactoring | 2011-03-18 13:46:51 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | c301b245a9 | adding default value for referer in case --referer was not defined and --level>=3 used (so it could be tested with default value) | 2011-03-18 13:39:51 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | b53c9a2599 | minor fix and some refactoring | 2011-03-18 00:24:02 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 9526f0c4c2 | Minor layout adjustments | 2011-03-17 12:35:40 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 03fac62592 | Minor code restyle | 2011-03-17 12:34:29 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | cbdd9e921e | minor cosmetics | 2011-03-17 12:23:56 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 6607a240cf | added logging to redirecthandler | 2011-03-17 12:21:27 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 9a513198dd | minor fix regarding last couple of commits | 2011-03-17 11:25:37 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 970cde5a8a | minor update regarding last commit | 2011-03-17 09:23:46 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | beba69faa9 | implementation of request from Santiago (look for error based responses in redirects) | 2011-03-17 09:12:28 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 847ce863e3 | refactoring | 2011-03-17 08:54:20 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | fbd0cfda29 | minor update toward the implementation of request from Santiago | 2011-03-17 06:39:05 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | f00aff5303 | -v 0 shows both error, critical and raw_input messages | 2011-03-11 22:02:38 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | d7d47b6257 | Minor bug fix (revert) | 2011-03-11 21:56:45 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | e64f225e65 | minor refactoring | 2011-03-11 20:16:34 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 2fd3f0d7b2 | minor update (added comment) | 2011-03-11 20:07:52 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 6cc745f789 | removal of deprecated piece of code (replaced later with that getCurrentThreadData().disableStdOut) | 2011-03-11 20:04:15 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 5eae525010 | this was bothering me for some time (POST and/or GET payloads needs to be urlencoded throughly) | 2011-03-11 19:57:44 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | d8a76ebe34 | Minor bug fix for counting of entries for error-based and partial UNION query SQL injection techs | 2011-03-11 16:03:19 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 3cb0ca4b63 | Minor bug fix for --privileges on PgSQL with error-based SQL inj technique | 2011-03-11 15:24:25 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 5af7410cb1 | Another bug fix for --privileges on PgSQL with UNION query technique | 2011-03-11 15:13:09 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 74ef1e53c7 | Minor bug fixes to --privileges for PostgreSQL query (corner case) | 2011-03-11 14:54:41 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 1879a49506 | fix for a bug reported by andreoaz@gmail.com | 2011-03-10 20:40:12 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | eb1cda7065 | minor refactoring (more consistent) | 2011-03-09 12:06:32 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 62e3510387 | minor refactoring | 2011-03-09 11:37:37 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 5c97f9a496 | improvement of url encoding technique (implemented failsafe routine for shortening too long GET queries) | 2011-03-09 09:36:56 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 9b2962ff1c | now when we don't urlencode whole URI using : and \ as safe chars is not a good idea | 2011-03-09 08:56:29 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 30619c599b | minor update regarding encoding (adding few safe chars for e.g. CHR(50)|...) | 2011-03-08 11:53:59 +00:00 |  |