Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							2efe7928c0
							
						
					 | 
					
						
						
							
							more concise than previously
						
						
						
						
						
					 | 
					
						2011-01-02 17:06:13 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							a56934e68b
							
						
					 | 
					
						
						
							
							one more MSSQL/ASPX error banner regex
						
						
						
						
						
					 | 
					
						2011-01-02 15:36:57 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							e6f0c4d857
							
						
					 | 
					
						
						
							
							minor update
						
						
						
						
						
					 | 
					
						2011-01-02 15:32:35 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							c1d0dde769
							
						
					 | 
					
						
						
							
							added support for .NET banners (http://msdn.microsoft.com/en-us/library/system.data.sqlclient.aspx)
						
						
						
						
						
					 | 
					
						2011-01-02 14:46:31 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							93cb75ff65
							
						
					 | 
					
						
						
							
							added Nginx
						
						
						
						
						
					 | 
					
						2011-01-02 08:50:27 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							ded9798e3d
							
						
					 | 
					
						
						
							
							minor bug fix
						
						
						
						
						
					 | 
					
						2011-01-01 23:07:50 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							c3065f6ecc
							
						
					 | 
					
						
						
							
							minor fix
						
						
						
						
						
					 | 
					
						2010-12-29 20:38:56 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							96c3ffd3d7
							
						
					 | 
					
						
						
							
							changing risk level to 0 - lots of MySQL databases around have information_schema unreadable, thus disabling first AND based error payload
						
						
						
						
						
					 | 
					
						2010-12-27 19:02:13 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							2c8115eed9
							
						
					 | 
					
						
						
							
							further improvement for ms access table dumping
						
						
						
						
						
					 | 
					
						2010-12-26 01:04:30 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							fb099615e2
							
						
					 | 
					
						
						
							
							minor update
						
						
						
						
						
					 | 
					
						2010-12-25 11:16:35 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							272476773f
							
						
					 | 
					
						
						
							
							getPageTextWordsSet on tableExists is pretty powerful stuff
						
						
						
						
						
					 | 
					
						2010-12-25 09:37:33 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							706d8e0b88
							
						
					 | 
					
						
						
							
							development update (basic ms access dumping implemented)
						
						
						
						
						
					 | 
					
						2010-12-24 19:53:11 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							edcf1a0872
							
						
					 | 
					
						
						
							
							few bug fixes
						
						
						
						
						
					 | 
					
						2010-12-24 18:40:48 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							3043ed095a
							
						
					 | 
					
						
						
							
							bug fix (those two regexes where too generic making false MS ACCESS positives here and there)
						
						
						
						
						
					 | 
					
						2010-12-24 00:11:10 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							5a0aef0f33
							
						
					 | 
					
						
						
							
							fix for a case: Microsoft OLE DB Provider for ODBC Drivers error '80040e14' [MySQL][ODBC 3.51 Driver][mysqld-5.1.31-community] - it was wrongly error message recognized as MS SQL Server
						
						
						
						
						
					 | 
					
						2010-12-23 09:53:13 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							8fc60215ed
							
						
					 | 
					
						
						
							
							lol. this was a pesky bug. heuristic wasn't working on one mssql test site and i couldn't find why. at end the problem was that when the HTTP code was raised (like 500) no parseResponse was called.
						
						
						
						
						
					 | 
					
						2010-12-22 19:12:46 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Bernardo Damele
							
						 
					 | 
					
						
						
						
						
							
						
						
							c9ab8ae60e
							
						
					 | 
					
						
						
							
							Bug fix to properly identify if current user is DBA (--is-dba) on MySQL
						
						
						
						
						
					 | 
					
						2010-12-22 14:06:01 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Bernardo Damele
							
						 
					 | 
					
						
						
						
						
							
						
						
							e791f8f2b7
							
						
					 | 
					
						
						
							
							Minor fix
						
						
						
						
						
					 | 
					
						2010-12-20 10:33:24 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							bfdc4fa000
							
						
					 | 
					
						
						
							
							new error vector for MS SQL (from David Guimaraes' mail)
						
						
						
						
						
					 | 
					
						2010-12-17 19:00:20 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							3ee44584d4
							
						
					 | 
					
						
						
							
							i've found a way! thank you hesus! fyea (ASC(MID) was just crashing when MID returned 'empty string')
						
						
						
						
						
					 | 
					
						2010-12-14 12:57:59 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Bernardo Damele
							
						 
					 | 
					
						
						
						
						
							
						
						
							207f63cebc
							
						
					 | 
					
						
						
							
							Prepare for UNION query tests at detection phase
						
						
						
						
						
					 | 
					
						2010-12-13 21:31:34 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							33639578ee
							
						
					 | 
					
						
						
							
							minor update for MS Access
						
						
						
						
						
					 | 
					
						2010-12-12 15:25:19 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							b1babeefe5
							
						
					 | 
					
						
						
							
							update regarding dumping of tables with blind on Sqlite
						
						
						
						
						
					 | 
					
						2010-12-11 22:00:16 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							acc7d6d40c
							
						
					 | 
					
						
						
							
							fix
						
						
						
						
						
					 | 
					
						2010-12-11 11:03:32 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							ac9080c07b
							
						
					 | 
					
						
						
							
							update
						
						
						
						
						
					 | 
					
						2010-12-11 08:24:29 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							fe2039f5ba
							
						
					 | 
					
						
						
							
							coollyy little commits
						
						
						
						
						
					 | 
					
						2010-12-10 11:32:46 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							7e2984b4b6
							
						
					 | 
					
						
						
							
							added stacked query support for Oracle
						
						
						
						
						
					 | 
					
						2010-12-09 15:24:48 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Bernardo Damele
							
						 
					 | 
					
						
						
						
						
							
						
						
							4bb40c0a06
							
						
					 | 
					
						
						
							
							Higher the level for Oracle stacked tests just in case the SQL inj is within a PL/SQL function ('cause of no support for stacked queries by design on Oracle)
						
						
						
						
						
					 | 
					
						2010-12-09 15:14:18 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							d8edc5b244
							
						
					 | 
					
						
						
							
							adding stacked-query vector for Firebird
						
						
						
						
						
					 | 
					
						2010-12-09 15:11:21 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Bernardo Damele
							
						 
					 | 
					
						
						
						
						
							
						
						
							13b522efc2
							
						
					 | 
					
						
						
							
							Added error-based support for MySQL < 5.0 - closes #14
						
						
						
						
						
					 | 
					
						2010-12-09 15:09:03 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							5aafd19957
							
						
					 | 
					
						
						
							
							added vector for SQLite's stacked query payload
						
						
						
						
						
					 | 
					
						2010-12-09 15:06:40 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							71761ba9a5
							
						
					 | 
					
						
						
							
							another fix for another beautiful heavy query payload which took a few 100 megs and 5 mins to run
						
						
						
						
						
					 | 
					
						2010-12-09 10:35:18 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							094baadc5b
							
						
					 | 
					
						
						
							
							bug fix (in SELECT based heavy queries COUNT(*) should be used; otherwise multiple row error happens without proper delay)
						
						
						
						
						
					 | 
					
						2010-12-09 10:17:04 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Bernardo Damele
							
						 
					 | 
					
						
						
						
						
							
						
						
							3b293c4ea7
							
						
					 | 
					
						
						
							
							Added possible stacked queries time-based blind vector for MSSQL
						
						
						
						
						
					 | 
					
						2010-12-08 23:55:42 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Bernardo Damele
							
						 
					 | 
					
						
						
						
						
							
						
						
							f5ce739bdf
							
						
					 | 
					
						
						
							
							Added support for time-based blind SQL injection via stacked queries too. Need to add vectors for some DBMS yet.
						
						
						
						
						
					 | 
					
						2010-12-08 23:52:31 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							69c4f94980
							
						
					 | 
					
						
						
							
							update
						
						
						
						
						
					 | 
					
						2010-12-08 15:40:01 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							ad00fe13c1
							
						
					 | 
					
						
						
							
							another fix for MySQL time based payloads
						
						
						
						
						
					 | 
					
						2010-12-08 12:00:27 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							8227e6d3cf
							
						
					 | 
					
						
						
							
							bug fix for BENCHMARK time-based vectors
						
						
						
						
						
					 | 
					
						2010-12-08 11:49:55 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Bernardo Damele
							
						 
					 | 
					
						
						
						
						
							
						
						
							8ff7c9a5a1
							
						
					 | 
					
						
						
							
							Works on Oracle's GROUP BY too
						
						
						
						
						
					 | 
					
						2010-12-07 17:17:01 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							4f01d4c109
							
						
					 | 
					
						
						
							
							number crunching based time payloads are now affected by conf.timeSec
						
						
						
						
						
					 | 
					
						2010-12-07 13:24:18 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							d0936bc8ed
							
						
					 | 
					
						
						
							
							adding vectors for SQLite time-based payloads
						
						
						
						
						
					 | 
					
						2010-12-07 13:14:56 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Bernardo Damele
							
						 
					 | 
					
						
						
						
						
							
						
						
							54b8cb76a1
							
						
					 | 
					
						
						
							
							Messed up with my last merge, all fixed now
						
						
						
						
						
					 | 
					
						2010-12-07 12:59:53 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							b38a634d95
							
						
					 | 
					
						
						
							
							bug fix
						
						
						
						
						
					 | 
					
						2010-12-07 12:55:31 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Bernardo Damele
							
						 
					 | 
					
						
						
						
						
							
						
						
							7c32db6e9d
							
						
					 | 
					
						
						
							
							Forgot when merged with my last commit
						
						
						
						
						
					 | 
					
						2010-12-07 12:52:09 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Bernardo Damele
							
						 
					 | 
					
						
						
						
						
							
						
						
							acac0d346f
							
						
					 | 
					
						
						
							
							Minor bug fixes and adjustments
						
						
						
						
						
					 | 
					
						2010-12-07 12:45:45 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							2b2b7dc3a6
							
						
					 | 
					
						
						
							
							added vectors for time-based Firebird payloads
						
						
						
						
						
					 | 
					
						2010-12-07 12:20:48 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							36a7fca8d5
							
						
					 | 
					
						
						
							
							added time-based payload vector for MSSQL
						
						
						
						
						
					 | 
					
						2010-12-07 12:06:25 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							485981c619
							
						
					 | 
					
						
						
							
							added vectors for PostgresSQL time-based payloads
						
						
						
						
						
					 | 
					
						2010-12-07 11:57:33 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							f9085e01e7
							
						
					 | 
					
						
						
							
							added vectors for Oracle time-based payloads
						
						
						
						
						
					 | 
					
						2010-12-07 11:47:29 +00:00 | 
					
					
						
						
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Miroslav Stampar
							
						 
					 | 
					
						
						
						
						
							
						
						
							3d87489de5
							
						
					 | 
					
						
						
							
							minor update
						
						
						
						
						
					 | 
					
						2010-12-07 08:05:03 +00:00 | 
					
					
						
						
							
							
							
						
					 |