Miroslav Stampar
|
4ba9e9397c
|
One more update of DBMS error messages
|
2018-12-16 16:24:01 +01:00 |
|
Miroslav Stampar
|
eedfa8c888
|
Another update of DBMS error messages
|
2018-12-16 16:00:04 +01:00 |
|
Miroslav Stampar
|
c224ea0e37
|
Update of DBMS error messages
|
2018-12-16 15:20:46 +01:00 |
|
nil0x42
|
83a1b9b2e7
|
errors.xml: detect mysqli_*() errors. (#3407)
MySQL injection error message often happen with
mysqli_*() functions nowadays.
POC: https://duckduckgo.com/?q=%22warning..mysqli
|
2018-12-14 10:08:52 +01:00 |
|
Miroslav Stampar
|
f04584bb68
|
Update of error message regexes
|
2018-12-07 11:22:53 +01:00 |
|
Miroslav Stampar
|
dc65afe65a
|
Minor update related to the #3283
|
2018-10-24 16:33:23 +02:00 |
|
Miroslav Stampar
|
0d2db32539
|
Finalizing #3283
|
2018-10-16 14:47:09 +02:00 |
|
Miroslav Stampar
|
77f4fd93e7
|
Minor leftover
|
2018-10-16 13:27:31 +02:00 |
|
Miroslav Stampar
|
68f5597b4a
|
Some cleaning up for #3283
|
2018-10-16 13:26:55 +02:00 |
|
Miroslav Stampar
|
411f56e710
|
Initial implementation for #3283
|
2018-10-16 12:23:07 +02:00 |
|
Miroslav Stampar
|
e005ba3f77
|
Minor patch
|
2018-10-11 23:59:09 +02:00 |
|
Miroslav Stampar
|
79e45bd8d7
|
Minor update
|
2018-10-02 15:10:31 +02:00 |
|
Miroslav Stampar
|
ed5f4abebd
|
Minor updates
|
2018-10-02 14:56:20 +02:00 |
|
Miroslav Stampar
|
245c5e64e9
|
Minor cleanup
|
2018-09-19 11:13:59 +02:00 |
|
Miroslav Stampar
|
cd08d13647
|
Adding a generic parameter replace payload
|
2018-09-19 11:05:55 +02:00 |
|
Miroslav Stampar
|
35d9ed8476
|
Cleaning a mess with stacked queries and pre-WHERE boundaries
|
2018-09-14 10:30:58 +02:00 |
|
Miroslav Stampar
|
ec253dd5bd
|
Support for table name retrieval from mysql.innodb_table_stats (fallback if primary fails)
|
2018-09-07 11:53:43 +02:00 |
|
Miroslav Stampar
|
2b56bdfaa6
|
Patch for MsSQL column name injection
|
2018-09-06 13:59:07 +02:00 |
|
Miroslav Stampar
|
349e9b9fa5
|
Minor commit related to the #120
|
2018-09-06 00:16:59 +02:00 |
|
Miroslav Stampar
|
ac481492c0
|
Final commit for #120
|
2018-09-05 23:29:52 +02:00 |
|
Miroslav Stampar
|
91c5151770
|
Another update related to the #120
|
2018-09-05 00:56:39 +02:00 |
|
Miroslav Stampar
|
ad5a731999
|
First commit for Issue #120
|
2018-09-05 00:16:35 +02:00 |
|
Miroslav Stampar
|
ad11749b15
|
One more payload (requires usage of --code or similar)
|
2018-08-09 16:21:35 +02:00 |
|
Miroslav Stampar
|
3c439c3929
|
Known cause of majority of false-positives (Issue #3176)
|
2018-07-11 16:12:57 +02:00 |
|
Miroslav Stampar
|
25369ca591
|
Adding new payload (HAVING boolean-based blind)
|
2018-06-05 00:59:47 +02:00 |
|
Miroslav Stampar
|
d5627fdf1b
|
Fixes #3099
|
2018-05-15 12:15:47 +02:00 |
|
Miroslav Stampar
|
44f6951dfe
|
Update of xml/banner files
|
2018-04-10 11:35:39 +02:00 |
|
Miroslav Stampar
|
4528cb014d
|
Minor just in case patch
|
2018-04-09 12:05:08 +02:00 |
|
Miroslav Stampar
|
fd8bbaff9f
|
Minor update of error regexes
|
2018-01-31 00:15:11 +01:00 |
|
Miroslav Stampar
|
5d6b972002
|
Switching Informix dump from regular to pivotdumptable
|
2017-12-11 14:49:30 +01:00 |
|
Miroslav Stampar
|
116c1c8b5c
|
Minor refactoring
|
2017-09-20 15:49:18 +02:00 |
|
Miroslav Stampar
|
afc2a42383
|
Revisiting regexes for DBMS errors
|
2017-09-20 15:28:33 +02:00 |
|
Miroslav Stampar
|
6a8ea0557c
|
Minor update
|
2017-09-15 14:23:55 +02:00 |
|
Miroslav Stampar
|
3f40bf1101
|
Fixes #2387
|
2017-07-06 11:44:18 +02:00 |
|
Miroslav Stampar
|
9da8d55128
|
Implements #2557
|
2017-06-07 11:22:06 +02:00 |
|
Miroslav Stampar
|
eb098f6527
|
Fixes #2268
|
2016-11-09 12:27:10 +01:00 |
|
Miroslav Stampar
|
d605b3af3c
|
Revisiting banner xmls (Issue #2239)
|
2016-10-21 13:01:28 +02:00 |
|
Miroslav Stampar
|
ae465bbaf8
|
Minor revert of leftover
|
2016-10-11 01:09:30 +02:00 |
|
Miroslav Stampar
|
1b95dd2d9d
|
Fix for a bug reported privately by user (in some cases data has not been retrieved)
|
2016-10-11 01:07:31 +02:00 |
|
Miroslav Stampar
|
7f416846b7
|
Minor revisit of MsSQL error-based payloads
|
2016-10-06 23:50:32 +02:00 |
|
Miroslav Stampar
|
af1c9c7fb2
|
Related to the last commit
|
2016-10-04 23:48:09 +02:00 |
|
Miroslav Stampar
|
06b54ab134
|
Better choice of used table (INFORMATION_SCHEMA.CHARACTER_SETS can also be found in MsSQL and PgSQL; mysql.db can have permission problems)
|
2016-10-04 23:43:00 +02:00 |
|
Miroslav Stampar
|
fee5c7bd7c
|
Adding two new payloads and minor cosmetics
|
2016-10-04 23:39:18 +02:00 |
|
Miroslav Stampar
|
fb8afc6add
|
Adding a new payload (Oracle boolean based on error response)
|
2016-10-04 22:12:00 +02:00 |
|
Miroslav Stampar
|
3409953538
|
Revisiting default level 1 payloads (MySQL stacked queries are as frequent as double rainbows)
|
2016-09-29 12:59:51 +02:00 |
|
Miroslav Stampar
|
e77126e847
|
Removing obsolete functionality
|
2016-09-28 15:00:26 +02:00 |
|
Miroslav Stampar
|
d36b5c0a4b
|
Adding time-based blind (heavy query) payloads for Informix (Issue #552)
|
2016-09-28 10:30:09 +02:00 |
|
Miroslav Stampar
|
5079c42788
|
Adding Informix parameter replacement payloads (Issue #552)
|
2016-09-27 14:39:17 +02:00 |
|
Miroslav Stampar
|
bc7ab01066
|
Bug fix for generic parameter replacement (CASE)
|
2016-09-27 14:29:18 +02:00 |
|
Miroslav Stampar
|
978f56ad10
|
One more commit for #552 (--passwords)
|
2016-09-26 16:38:03 +02:00 |
|