| 
							
							
								 Miroslav Stampar | 5c97f9a496 | improvement of url encoding technique (implemented failsafe routine for shortening too long GET queries) | 2011-03-09 09:36:56 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 9b2962ff1c | now when we don't urlencode whole URI using : and \ as safe chars is not a good idea | 2011-03-09 08:56:29 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | eedd6a990d | removing space after , for our payloads | 2011-03-08 14:29:22 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 3dc31f6273 | removing spaces after , in our queries | 2011-03-08 14:07:26 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 30619c599b | minor update regarding encoding (adding few safe chars for e.g. CHR(50)|...) | 2011-03-08 11:53:59 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 68c7247ee4 | bug fix (pgsql drop function requires input arguments - at cleanup() in plugins/generic/misc.py it's already fixed before) | 2011-03-08 10:46:23 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 99adbbeaa3 | los cosmeticados | 2011-03-07 22:04:17 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | cc0306044c | adding SVN revision number support for non SVN client platforms | 2011-03-07 21:54:30 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 8e7c3b4666 | update of THANKS file | 2011-03-07 21:29:06 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 154d947c62 | minor update | 2011-03-07 10:15:41 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 16b286982d | fix for a bug reported by nightman (AttributeError: 'list' object has no attribute 'split') | 2011-03-07 09:50:43 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 7524a0c0cf | Proper error message | 2011-03-04 11:59:09 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 8edc3b3302 | further update regarding last commit | 2011-03-03 10:39:04 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | bc50387a17 | possible fix for a bug reported by Black Zero (UnicodeDecodeError for --forms) | 2011-03-03 09:42:50 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 3a1f5744be | minor update to make counting variable totally independent of the urllib2's self.retried | 2011-03-02 10:42:17 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | a010386a23 | finally a proper fix for that annoying recursive bug | 2011-03-02 10:29:38 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | f27f05308a | minor update for masking sensitive data in error report (added aCred too) | 2011-03-02 10:09:17 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | ad2e4002ea | minor improvement | 2011-03-01 10:38:27 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 0f3cc153a3 | fix for --technique | 2011-03-01 09:54:06 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 9856cb71de | redo of the last commit with comments added | 2011-02-28 18:58:05 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | ade31b2cb0 | removal of obsolete item | 2011-02-28 18:49:25 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | da6a87af43 | update | 2011-02-28 16:59:39 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 50ba0fa955 | More adjustments | 2011-02-28 16:14:09 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 021fce5601 | Should be done with the ChangeLog - ready for 0.9. Minor adjustments to user's manual too. | 2011-02-28 15:23:05 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 2bf212ffa9 | minor minor update | 2011-02-27 20:43:38 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 7036190e8e | minor improvement of regular expression | 2011-02-27 17:58:01 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 21041f8b90 | further reflective value handling improvement | 2011-02-27 17:43:41 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | b47d3e1da3 | Huge update to user's manual. A lot to be done yet. | 2011-02-27 12:19:32 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 6e8ebd35f4 | Hide switch -x (XML output format) as it is incomplete and bugged and won't make it for 0.9 stable | 2011-02-27 12:17:41 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 60605b6e7c | Major bug fix to make --first and --last apply only to --dump's entries dump phase (in either of the blind SQL injection techs only) | 2011-02-27 12:14:13 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 88faedc0fe | fix for a bug reported by -insane- | 2011-02-26 17:48:19 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 11996ce12e | bug fix for international encoded letters | 2011-02-25 22:43:01 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 63b8156c00 | some update (if header key is non-unicode comformant) | 2011-02-25 09:43:04 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 2bbbc9a41e | few updates | 2011-02-25 09:35:24 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | aa88361ab1 | incorporation of method for neutralization of reflective values | 2011-02-25 09:22:44 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 708ddf5608 | added protection mechanism against reflected values | 2011-02-24 16:52:46 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 38dc82e13e | If no Accept header field is present, then it is assumed that the client accepts all media types. | 2011-02-22 22:26:22 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 13f0d5ce00 | minor bug fix | 2011-02-22 14:51:42 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | d05bd75068 | adding experimental for --group-concat | 2011-02-22 14:35:38 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 640ba5d744 | minor refactoring | 2011-02-22 14:19:39 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 12ede1e5de | minor JIC (just-in-case) update | 2011-02-22 13:18:47 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 3f8eadf4fe | minor refactoring | 2011-02-22 13:00:58 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | dcad5410fe | minor refactoring | 2011-02-22 12:54:22 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 17c39fe231 | fix for that non-HTML stuff | 2011-02-22 11:32:55 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | ff9080de48 | MaxDB always precalculates values for both TRUE and FALSE, hence we can't trick him to run any "faulty" command (e.g. 1/0). This payload is fairly ok because in case of FALSE --> something=NULL is always NULL | 2011-02-21 20:59:34 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 08697e60a9 | added some Microsoft Access payloads | 2011-02-21 20:04:50 +00:00 |  | 
			
				
					| 
							
							
								 Bernardo Damele | 3e8c204121 | Major bug fix to properly prepare UNION technique statement for --os-pwn and --is-dba | 2011-02-21 16:00:56 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 90582ed7dc | minor change | 2011-02-21 11:35:21 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | 68a95fd1b1 | minor update | 2011-02-20 22:45:23 +00:00 |  | 
			
				
					| 
							
							
								 Miroslav Stampar | aac817935a | further improvement of MaxDB support | 2011-02-20 22:41:42 +00:00 |  |